Beans Note Privacy Policy
This is an English translation of the Japanese Beans Note Privacy Policy (https://beansnote.com/privacy/). In case of any discrepancy, the Japanese version prevails.
South Side Labs (the "Operator"), the operator of Beans Note (the "App"), handles information about users of the App as follows.
1. Basic approach
- The App has no accounts. We do not collect your name, email address, phone number or address.
- Recipes, beans, equipment and brew records are stored on your device. They are not sent to the Operator's servers.
- Information is sent outside your device only when you use the features described in Section 2 below.
2. Information we collect and how we use it
2.1 Information stored only on your device
| Information | Examples | Use |
|---|---|---|
| Recipes | Name, coffee dose, water amount, water temperature, grind size, grinder and grind setting, steps, version, description, your own notes, reason for changing a version (free text), reference mark | Brewing guidance, AI consultation (the grinder and grind setting, description and your own notes are not sent to AI consultation) |
| Beans | Name, roast level, roast date, purchase date, origin, variety, process, notes | Bean list, showing when beans are at their best, conditions for AI consultation |
| Your equipment | Drippers (name, size, maximum dose, material, notes), grinders (name, notes) | Conditions for AI consultation, warnings about the coffee dose (grinders are not sent to AI consultation) |
| Brew records | Date and time, recipe and beans used, star rating, taste rating, impressions, brew time | Showing your records, AI consultation |
| Settings | Language, color theme, sounds, keeping the screen on, backup location | Operation of the App |
None of this reaches the Operator. If you set up backups, the data is written to a folder you choose. If you delete the App, the data on your device is deleted (backups you have exported remain).
2.2 Information sent when you use AI consultation
When you use AI consultation (recipe suggestions and improvements), the following information is sent to the Operator's AI server. The first time you use AI consultation, we show you what will be sent and ask for your consent before sending it. You can withdraw your consent from "What we send to the AI" in Settings (if you withdraw it, we will ask again the next time you consult).
| Information | Details |
|---|---|
| Consultation conditions | Bean name, origin, variety and process; roast level; equipment name, brew method, shape and equipment notes; coffee dose or the amount you want to make; hot or iced; the taste you are aiming for; preferences and follow-up requests (free text) |
| When asking for an improvement | The current recipe's water temperature, grind size, coffee-to-water ratio, ice proportion and target drawdown time; this brew's star rating and taste impressions (including free text); the brew time (only for brews where the "Measure drawdown time" setting is on and you pressed "Drained"); your answer to whether water was left above the grounds at the drawdown time; settings, star ratings and impressions of past brews of the same recipe (up to 5); and, if you rewrote the current version of the recipe yourself, the "Why did you change it?" you wrote (free text; only if you wrote one) |
| Device identifier | A value used to count AI consultations per day. On Android, a hashed value of the device identifier (ANDROID_ID) (the original value is not sent); on iOS, a value the App creates and stores in the device's Keychain; in the browser version, a random value stored in the browser |
| Other | Display language, the time zone used to reset the daily count, and your IP address when communicating |
Uses:
- To create recipe suggestions and improvements
- To count AI consultations per day
- To check and improve the quality of suggestions (see the stored information below)
Processing on the AI server:
- The AI server runs on Supabase (Supabase, Inc.). The server is located in Japan (Tokyo) (Supabase, Inc. is a US company).
- To create suggestions, the information above is sent to Google's generative AI (Gemini API, Google LLC). We use it under a tier (the paid tier) in which the content sent is not used to improve Google's products.
Information stored on the AI server:
- Count management: the device identifier, the day's count, the total count, the plan, and the last date counted. For the browser version (and older versions of the App that do not send a device identifier), the IP address of the connection is also used to check the count (only a hashed value of the IP address is stored; the original value is not stored)
- Suggestion records: language, roast level, equipment name, coffee dose, the taste you are aiming for, hot or iced, and the recipe created (not linked to the device identifier)
- Retention period: count management information is deleted 30 days after the last use. Created recipes are kept for up to 2 years without being linked to the device identifier and are used to improve suggestions. The names and descriptions of created recipes may include the bean names and other things you entered.
Please do not write information that can identify a person, such as your name or contact details, in the free-text fields (impressions, preferences, notes, reasons for changing a version). In AI consultation, they are sent outside as they are.
2.3 Origin map
The origin map is drawn on your device and does not communicate. The names, origins and other details of your beans are not sent outside your device.
2.4 App crash reports
When the App crashes or stops responding, information about the situation is sent to Firebase Crashlytics (Google LLC).
- Information sent: the date and time it happened, the error details, the device model and OS version, the App version, an identifier created by Firebase, and a record of recent screen operations
- Use: to find and fix bugs
- The record of recent screen operations is collected with Google Analytics for Firebase (Google LLC) only when the measurement in 2.5 is on. Advertising identifiers are not used, and it is not used for advertising. When this happens, Google Analytics for Firebase derives an approximate region (country and region) from the IP address
- In the web version (when used in a browser), reports are sent not to Firebase Crashlytics but to PostHog (PostHog, Inc., USA), the same as in 2.5. The information sent is only the type of error and where it happened (the place in the program), the browser type, the App version, and the identifier used for the measurement in 2.5. The error text is not sent. If you turn off the measurement in 2.5, nothing is sent
- When you photograph a bean bag (Android), Google's ML Kit (Google LLC), which reads text on the device, sends device information, the App version, and reading speed and errors to Google to check for problems and for usage statistics. The photo and the text read are not sent
2.5 Usage measurement
To improve the App, we measure which screens and features are used.
- Sent to: PostHog (PostHog, Inc., USA)
- Information sent: screens opened, buttons pressed, start and completion of brews, the number of stars given and the taste tags chosen (only fixed words such as "Thin"), your answer to the drawdown question, the time the brew took (again, only for brews where you pressed "Drained"), the recipe category (hot or iced, the coffee dose range and whether you changed the amount in the timer, the taste preference level, whole beans or ground coffee, whether it is decaf, the type of milk), the kinds of items changed by AI suggestions and the waiting time, whether you used AI consultation, that an AI consultation did not succeed and its type (daily limit, network, AI failure, etc.; the text of errors and consultations is not sent), the recipe type (default, your own, AI), whether you wrote a reason when changing a version (the text of the reason is not sent), the equipment type, the roast level category, a random identifier for measurement (separate from the identifier for counting AI consultations), the App version, and the device type (Android, etc.). We do not build profiles of individuals
- Information not sent: names of beans or recipes, free text such as impressions and notes, the text of your consultations with the AI
- The first time you open the App, we ask whether we may send this. Nothing is sent until you answer.
- You can stop it at any time with "Anonymous usage analytics" in Settings. Once stopped, nothing more is sent.
- The web version (when used in a browser) sends the same information (the device type is "web"). The identifier for measurement is stored in the browser (that site's storage), and this measurement does not use cookies (for the site's access analytics, see 2.6)
2.6 Site access analytics (Google Analytics)
On beansnote.com (the landing pages (Japanese at / and English at /en/), the public recipe pages (Japanese at /recipes/ and English at /en/recipes/), this policy, the terms of service, and the browser version), we use Google Analytics (Google LLC, USA) to learn where visitors came from and which pages they viewed.
- Information sent: the pages viewed, the buttons pressed on the landing pages (store buttons and "Open the web app"), "Set this recipe on the timer" pressed on the public recipe pages (which equipment the recipe is for), where you came from (referrer), approximate region, the browser and device type, and the identifier assigned by Google Analytics
- Information not sent: names of beans or recipes, free text such as impressions and notes, the text of your consultations with the AI, operations inside the browser version (operations inside the browser version are covered by the measurement in 2.5)
- Google Analytics uses cookies (it stores an identifier in your browser). Google Signals and ad personalization are not used, and it is not used for advertising
- In the browser version, if you turn off "Anonymous usage analytics" in 2.5, nothing is sent to Google Analytics either
- How to opt out: refuse cookies in your browser settings, or use the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout). For how Google handles information, see Google's page (https://policies.google.com/technologies/partner-sites)
3. Provision to third parties
We do not provide the information we collect to third parties, except in the following cases.
- When it is processed by the external services described in Section 2 (AI processing, usage measurement, crash reports, site access analytics)
- When required by law
Handling by businesses located in foreign countries
Supabase's business is located in the United States, but the stored information is kept on servers in Japan (Tokyo). AI processing (Google's Gemini API) may take place outside Japan. Usage measurement (PostHog) and site access analytics (Google Analytics) are processed in the United States. Information about the personal information protection system of the United States can be found in the information on foreign systems published by the Personal Information Protection Commission of Japan.
4. Security measures
- Communication is encrypted (HTTPS).
- The AI server's database is restricted so that it cannot be read or written directly from the App.
- Data on your device is protected by your device's protection mechanisms (such as the screen lock).
5. Age
The App is not intended for people under 18 (as stated in the Terms of Service, it is intended for people aged 18 and over).
6. Requests for disclosure or deletion of information
Count management information is deleted automatically 30 days after the last use. Created recipes are not linked to a device, so they cannot be individually identified and deleted. For any other questions, please contact us at the address below.
Data on your device is deleted when you delete it in the App or delete the App.
7. Changes to this policy
When we change this policy, we will announce it in the App or on this page. Major changes (such as adding a new destination for information) will also be announced in the App.
8. Contact
- Operator: South Side Labs
- Contact: [email protected]
Established: October 2, 2026