Privacy Policy

Effective Date: June 29, 2026 Package: com.yashasreddyk.brew

Executive Summary: Brew ("CoffeeChat") is designed to foster authentic nearby coffee meetups with a privacy-first architecture. One-to-one direct messages are protected by client-side End-to-End Encryption (E2EE). On-device neural translation models operate locally without sending message text to external cloud APIs. This policy outlines our data collection, processing, retention, and user deletion rights in full compliance with Google Play Store User Data Policies.

1. Information We Collect

1.1 Account & Authentication Data

When you sign in using Google Sign-In or Apple Sign-In, we collect your display name, email address, and profile photo URL via Firebase Authentication. This information is used exclusively to create, authenticate, and secure your Brew account.

1.2 Profile & Customization Data

To facilitate meaningful coffee chat matching, you provide the following profile information during onboarding:

1.3 Location Data (Geohash Prefixing)

With your explicit runtime permission, Brew accesses your device's approximate geolocation to discover nearby users and coffee spots. Coordinates are processed into a coarsened Geohash prefix grid cell. We do not track continuous GPS movements or store your exact longitude and latitude. Location queries execute only while actively using matchmaking or map features.

1.4 Ephemeral Face Verification (Identity Badge)

Brew offers an optional Identity Verification badge. To verify your profile, you take a real-time verification selfie. This image is securely transmitted to our backend where Google Cloud Vision API analyzes face placement. Verification selfies are processed ephemerally in memory and permanently deleted immediately after check completion. We never retain verification images or build biometric facial templates.

1.5 In-App Purchases & Supporter Badges

If you purchase optional supporter tips or badges (e.g., Espresso, Coffee & Croissant, Roaster Supporter), all payment processing is handled directly by the Google Play Store Billing System. Brew receives only purchase receipt tokens to activate supporter features. We never collect, process, or store credit card, banking, or billing details.

1.6 Messages & E2EE Key Vault

One-to-one messages are encrypted locally on your device using ECDH (Elliptic Curve Diffie-Hellman) key exchange and AES-256-GCM. Only encrypted ciphertext is stored in Firebase Firestore. Optionally, you can encrypt your private key with a password to back it up in your cloud vault (`users/{uid}/private/vault`). Activity group chats do not use E2EE encryption; please avoid sharing sensitive information in public groups.

1.7 Push Notifications & Device Tokens

We collect your Firebase Cloud Messaging (FCM) token to send push notifications for incoming chat requests, matches, and meetup updates. We do not harvest device IMEI, advertising IDs (GAID), or hardware identifiers.

1.8 Voice Dictation & Speech Recognition (Microphone Access)

When you use the Voice Dictation feature in the Standalone Translator or Interpreter screens, Brew requests optional runtime Microphone permission (android.permission.RECORD_AUDIO). Spoken audio is captured only while actively dictating and is processed ephemerally on-device by local speech recognition engines to transcribe speech into text. Audio recordings are never recorded in the background, stored on remote servers, analyzed for voice biometrics, or shared with third parties.

2. How We Use Your Information

3. Third-Party Service Providers

We work with trusted service providers to run our backend infrastructure under strict data protection terms:

Provider Purpose Data Handled Privacy Reference
Google Firebase Auth, Database, Storage, Functions, Push Notifications Account ID, Email, Profile, Encrypted Messages, FCM Token Firebase Privacy
Google Cloud Vision API Ephemeral Identity Verification Temporary selfie image (processed in memory, immediately deleted) Google Cloud Privacy
Google Play Billing In-App Purchases & Supporter Badges Purchase receipt tokens Google Privacy Policy

4. Data Retention & Cleanup Schedule

5. Your Rights & Account Deletion

You maintain full control over your personal data:

6. International Privacy Rights

Brew respects privacy rights under global frameworks including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and Australian Privacy Principles (APP). You have the right to access, export, rectify, or request deletion of your personal data by contacting us.

7. Children's Privacy

Brew is strictly intended for individuals aged 18 and older. We do not knowingly collect information from minors. Accounts identified as belonging to users under 18 will be terminated and deleted immediately.

8. Contact & Developer Information

If you have any questions or privacy inquiries regarding Brew, please contact the developer:

Developer: Yashas Reddy K

App Name: Brew (CoffeeChat)

Package Identifier: com.yashasreddyk.brew

Contact Email: brewapp.support@gmail.com