Legal

Privacy Policy

Effective: September 28, 2026 (beta)

Arosti is a personal coffee discovery app. This policy explains what data Arosti handles, where it lives, and what control you have. It is written to be read, not skimmed past.

The short version

What Arosti collects

Account. An email address and password, only if you choose to sign in. You can use Arosti without an account; everything then stays on your device only. We use your email address to run your account — verifying it and resetting your password — and to send you one welcome email after you create an account, with tips for getting started; reply to it to reach us. We don’t add you to a mailing list or send you marketing email.

Your coffee journal. Ratings, reaction tags, notes, favorites, want‑to‑try saves, brewing preferences, coffees you add, and scan records (what was identified, when, and any place or price you attach).

Scan photos. Photos you take in the scan flow are stored with your scans and transmitted for identification. We may keep and use scan photos as described in “Scan photos and the shared catalog” below.

Location. Only if you grant permission. Arosti uses your position in the moment — when you save a scan, to suggest where you found the coffee, and to show you and nearby cafés on the map and on Discover (the distances are worked out on your phone and never sent anywhere) — and stores only a coarse region at each scan: your county‑level area, like the San Francisco metro. When you save a scan, and again once the coffee is identified, your coordinates at that moment are sent through our server to Apple Maps to find businesses near you — the second time together with the roaster’s name, to find the roaster’s own café; Apple Maps answers those lookups, receives no account information, and the coordinates are then discarded. Arosti also checks its own list of roaster-owned cafés on your device. When you search for a place on the map, your search text and the map area you are looking at are sent through our server to Apple Maps for that lookup, and only the store you choose is saved, by name and street address. The suggested store names (never coordinates) stay on your device until you set a place or delete the scan, and are never uploaded. If one store is unmistakably where you are, Arosti fills it in and says so on the scan; you can change it any time, and whether you accept, tap, or type a store, only its name and street address are saved to your scan — never coordinates. When you choose a photo from your library instead of using the camera, Arosti reads the location saved in the photo’s own metadata, if it has any, and uses it the same way — where the photo was taken, not where you are now. Asking for stores near you now sends your current position for that one lookup in the same way. Precise coordinates are never stored: they are used for the lookup or the map view and immediately discarded. Your region keeps recommendations relevant to where you shop (Discover skips coffees known to be unavailable near you) and can contribute to the aggregated, de‑identified regional insights described below. Denying location never blocks anything — you simply get unfiltered recommendations.

Taste model. Arosti computes what you tend to like from your ratings, on your device. It is part of your journal and is deleted with it.

Feedback you send. If you use Send Feedback, we receive your message, the category you pick, and basic device context — app version, device model, and OS version — so we can reproduce issues. Feedback never includes your journal contents, goes only to us, is never shown to other users, and is deleted with your account.

Where your data lives

On your device first. If you sign in, your journal is mirrored to your private space in our database, protected by row‑level security: every request is checked against your identity, and no user can read another user’s rows. Scan photos are mirrored the same way, to private storage only you can access, so they follow you to a new device.

Scan photos and the shared catalog

Arosti’s coffee catalog gets better because people scan coffees. By using the scan feature, you grant Arosti a perpetual, royalty‑free license to use photos you take in the scan flow to operate and improve the product, including:

Two promises bound that license. Anything shown to other users is curated product imagery only — packaging, never people, places, or anything personal that a photo happens to catch. And photos are never attributed to you: nothing shown to anyone links back to your account or identity. Because catalog imagery is unattributed, product images derived from your scans may remain in the catalog after you delete your account; everything linked to you is still deleted as described below.

Photos aren’t the only way scans improve the catalog. A scan can also observe simple facts about the coffee world — that a coffee exists, where it’s sold, and at what price — and those facts may inform the shared catalog, including its availability and price knowledge. Like catalog imagery, these facts are never attributed to you.

Aggregated insights and partners

Arosti may compile statistics and trends from users’ taste data — for example, regional flavor preferences, or how a coffee’s ratings trend over time — and share or sell these insights to partners such as roasters and retailers, whether bundled into a partnership fee or sold as a standalone data product.

These insights are always aggregated across many users and de‑identified: no individual rating, journal entry, taste profile, or preference set is ever included, sold, or reconstructable, and no partner receives anything that identifies you or any other user. This is separate from, and does not change, the promise below that we never sell or share your personal data.

Because aggregated insights don’t identify you, deleting your account does not retroactively remove your past contribution to insights already compiled — the same principle that already covers catalog imagery above.

Services we rely on

What we never do

Your controls

Children

Arosti is not directed at children under 13 and we do not knowingly collect their data.

Changes

If this policy changes materially, the app will tell you before the change applies to you. The effective date above always reflects the current version.

Contact

Questions or requests: [email protected].