Privacy Policy
Effective Date: April 12, 2026
Introduction
2manybeans ("the App," "we," "us," or "our") is a specialty coffee inventory and AI tasting coach developed by Super X LLC, a California limited liability company. This Privacy Policy explains how we collect, use, store, and protect your information when you use the 2manybeans iOS app and web application at 2manybeans.vercel.app.
By using 2manybeans, you agree to the practices described in this policy. If you do not agree, please do not use the App.
What We Do Not Collect
We want to be clear about what we do not do:
- No advertising SDKs or ad tracking
- No behavioral analytics or usage profiling
- No device advertising identifiers
- No location data (GPS or IP-based geolocation)
- No sale, rental, or trading of your personal information to third parties
- No cookies or web tracking pixels
Information We Collect
Account Information
When you sign in with Google or Apple, we receive and store:
- Your email address
- Your display name
- Your profile photo URL (if provided by Google; Apple sign-in may use a relay address)
- A unique user identifier (Firebase UID)
We use Firebase Authentication to manage sign-in. We never receive or store your Google or Apple password.
Content You Create
Everything you add to the App is stored in your account:
- Coffee bean entries (roaster, origin, variety, process, roast date, tasting notes, ratings, scores)
- Bean photos you upload or capture with your camera
- AI-generated product images of your beans
- Share card images you create
- Preferences (grinder model, brew method, canister count)
- Chat messages with AI features
- Marketing email consent preference
Automatically Collected Information
- Device and app version: Collected by Capgo to deliver over-the-air updates to the iOS app. This is limited to device type, OS version, and app version.
- Subscription status and purchase history: Collected by RevenueCat for managing in-app subscriptions. RevenueCat receives purchase transaction data and, if you are signed in, your Apple ID identifier.
Information Processed by AI Services
When you use AI-powered features (tasting coach, brew recipes, bean scanning, chat), relevant data from your request is sent to our server-side AI providers for processing:
- Anthropic (Claude): Tasting notes, bean details, chat messages
- OpenAI (GPT): Brew recipe generation, tasting score extraction, story content
- Google (Gemini): Bean photo analysis, web search enrichment for bean information, image analysis in chat
All AI requests are routed through our secure server-side proxies hosted on Vercel. We send only the specific information needed to process your request, never your full account data. Your API keys and credentials are never exposed on your device.
AI providers may process your data according to their respective policies. We do not use your data to train AI models, and our API agreements with these providers are configured for zero-retention where available.
Device Permissions
The App may request the following device permissions:
- Camera: Used to photograph coffee bean bags for AI scanning and identification. Photos are uploaded to Firebase Storage for your account and sent to Gemini for analysis. You can deny camera access and still use all other features.
- Photo Library: Used to select existing photos of coffee beans. Same processing as camera photos.
Permissions are requested at the time of use and can be revoked at any time in your device settings.
How We Use Your Information
- Provide and maintain the App's core features (inventory tracking, tasting notes, AI recommendations)
- Authenticate your identity and secure your account
- Process your subscription and manage billing through Apple and RevenueCat
- Deliver over-the-air app updates via Capgo
- Send marketing emails (only if you have opted in)
- Improve the App and fix bugs
How We Store and Protect Your Data
- Account data and content are stored in Google Firebase (Firestore database and Firebase Storage), hosted in the United States
- All data transmission uses HTTPS/TLS encryption
- AI requests are routed through server-side proxies on Vercel, so credentials are never exposed on-device
- Access to production systems is restricted to the developer
- Firebase security rules enforce per-user data isolation (you can only access your own data)
We take reasonable measures to protect your data, but no method of electronic storage or transmission is 100% secure.
Third-Party Services
We use the following third-party services, each governed by their own privacy policies:
| Service |
Purpose |
Privacy Policy |
| Google Firebase (Auth, Firestore, Storage) |
Account management, data storage, file storage |
View |
| Anthropic (Claude) |
AI tasting coach, chat |
View |
| OpenAI (GPT) |
AI brew recipes, score extraction, stories |
View |
| Google Gemini |
Bean photo scanning, search enrichment, image analysis |
View |
| RevenueCat |
Subscription management, purchase validation |
View |
| Capgo |
Over-the-air app updates (iOS) |
View |
| Vercel |
Web hosting, server-side API proxies |
View |
| Apple |
Sign in with Apple, subscription billing |
View |
| Google (Sign-In) |
Authentication |
View |
Data Retention
- Account data and content: Retained as long as your account is active. If you delete your account, we will delete your data within 30 days.
- AI processing: Data sent to AI providers is subject to their respective retention policies. We do not maintain separate logs of AI requests beyond what is needed for error handling.
- Subscription records: Retained by RevenueCat and Apple per their policies. We retain subscription status for the duration of your account.
- Update delivery data: Capgo retains device information per their retention policy.
Your Rights and Choices
All Users
- Access: All your content is visible within the App at any time.
- Export: Contact us to request a full export of your account data in a machine-readable format.
- Delete: Use the "Delete Account" option in Settings, or contact us. Deletion is completed within 30 days.
- Opt out of marketing: Toggle marketing email consent off in Settings, or contact us.
- Revoke permissions: Camera and photo library access can be revoked in your device settings at any time.
California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act provide you with specific rights:
- Right to know: Request disclosure of what personal information we collect, use, and share.
- Right to delete: Request deletion of your personal information.
- Right to correct: Request correction of inaccurate personal information.
- Right to opt out of sale or sharing: We do NOT sell or share your personal information for cross-context behavioral advertising.
- Right to non-discrimination: We will not discriminate against you for exercising your rights.
To exercise any right, contact us at the email below. We will respond within 45 days.
European Economic Area (GDPR)
If you are in the EEA, the General Data Protection Regulation provides additional rights:
- Access: Request a copy of all personal data we hold about you.
- Rectification: Request correction of inaccurate personal data.
- Erasure: Request deletion of your personal data.
- Data portability: Receive your data in a structured, machine-readable format.
- Restrict processing: Request that we limit how we use your data.
- Object: Object to our processing of your personal data.
- Withdraw consent: Withdraw consent for any consent-based processing at any time.
Legal bases for processing: (a) performance of a contract (providing the App's services), (b) your consent (marketing emails), and (c) legitimate interests (improving the App, security).
To exercise any GDPR right, contact us at the email below. We will respond within 30 days.
International Data Transfers
Your information may be processed, stored, and used in the United States, where our servers and service providers are located. Data privacy laws vary across jurisdictions. By using the App, you consent to the transfer of your information to the United States and processing there.
Children's Privacy
2manybeans is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the date at the top of this page. For significant changes, we will notify you through the App. Your continued use of the App after changes are posted constitutes your acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy, want to exercise your data rights, or need to report a concern:
Super X LLC
Email: admin@superxmusic.com