Privacy policy
Effective 7 September 2026 · Version 1.0
CoffeX has no accounts and no analytics. Your recipes, brews, ratings and coffee shelf live on your iPhone and are never uploaded. The app makes one outgoing request — it downloads a small file listing the seasonal recipes — and sends nothing about you with it. Delete the app and every trace of your data goes with it.
1. Who is responsible
CoffeX (“the app”) is published by HB ASESORIAS LTDA (“we”, “us”), a company registered in Colombia, D-U-N-S number 880025847, with its registered office at Calle 45 # 23-18, Oficina 301, Bogotá, Distrito Capital, Colombia.
HB ASESORIAS LTDA is the data controller — responsable del tratamiento — for anything described here. Write to [email protected] with any question, correction or request.
This policy covers the CoffeX iPhone app and this website. It is written to be read, not to be survived — if something here is unclear, that is a fault worth reporting to us.
2. What stays on your device
The app stores the following locally, in Apple’s on-device database, and nowhere else:
- Your brews — which recipe, which coffee, the dose, the water, how long it took, your rating, the tasting notes you tapped and the advice the app gave you.
- Your coffee shelf — the name, roaster, origin, roast date and remaining grams of each bag you add.
- A brew in progress — the recipe and the start time, so a cold brew started at midnight is still counting at eight in the morning even if the app was closed in between.
- The cached seasonal list — the last copy of the recipe collection described in section 3, so the app works with no connection.
None of this is transmitted to us or to anyone else. We cannot read it, and we have no server that could receive it. If you have iCloud Backup switched on, your iPhone backup may include this data; that backup is governed by Apple’s terms, not ours.
3. The one network request
Roughly once every six hours, and only when you open the app, CoffeX requests a single static file:
https://omarwhts.app/config/featured.json
That file lists which recipes appear as the seasonal collection and the recipe of the day. It is the same file for everybody. The request is a plain GET: it carries no identifier, no advertising ID, no device fingerprint and nothing about your brews. If the request fails, the app uses its cached copy, and failing that, picks a collection by the current month on the device.
As with any web request, our hosting provider records standard server logs — IP address, timestamp, and the user agent string — for security and troubleshooting. We do not combine these logs with anything else, do not use them to build profiles, and they are retained for no longer than 30 days.
4. What the app does not do
- No account, no sign-in, no email address collected.
- No analytics or crash-reporting SDK of any kind.
- No advertising, no advertising identifier, no ad networks.
- No tracking of you across other apps or websites, and no data shared with data brokers.
- No location access, no contacts, no photo library, no microphone.
- No third-party SDKs whatsoever. The app is built only on Apple’s own frameworks.
- No sale of personal information, under any definition, including the CCPA’s.
5. App Store privacy label
CoffeX declares Data Not Collected on the App Store. That declaration matches the behaviour described above, and we will update both the label and this policy before shipping any release that changes it.
6. Your rights and your data
Because we hold no personal data about you, there is nothing for us to export, correct or erase on request — but the rights still stand, and here is how they resolve in practice:
- Access and portability. Everything the app knows about you is visible inside the app itself, on your device.
- Erasure. Deleting a bag or a brew removes it immediately. Deleting the app removes all of it at once.
- Objection and restriction. Turning off network access for CoffeX in iOS Settings stops the one request in section 3. The app keeps working.
If you are in the EU or the UK, the lawful basis for the request in section 3 is our legitimate interest in delivering the seasonal recipe list, and you may complain to your national data protection authority. If you are in Colombia, see section 7. Wherever you are, the practical answer is the same: we hold nothing about you.
7. Colombian data protection law
We are established in Colombia, so Ley 1581 de 2012 and Decreto 1074 de 2015 apply to us. Because the app collects no personal data, there is normally nothing to authorise, consult or correct — but the rights of the data subject (derechos del titular) stand regardless, and this is how we honour them:
- To know, update and correct your data held by us. Everything the app knows sits on your own device, where you can see and change it directly.
- To request proof of the authorisation given for processing. We ask for none, because we process none.
- To be informed about how your data is used — that is what this page is for.
- To revoke authorisation and request deletion. Deleting the app removes everything at once.
- To complain to the Superintendencia de Industria y Comercio if you believe we have breached the law.
We answer queries (consultas) within 10 business days and complaints (reclamos) within 15 business days, as the law requires. Send either to [email protected].
8. Children
CoffeX is a coffee brewing guide and is not directed at children. It collects no personal data from anyone, of any age. Caffeine figures shown in the app are approximations for guidance and are not medical advice.
9. Changes to this policy
If the app’s behaviour changes, this page changes first, and the version number and effective date at the top change with it. Material changes — anything that would alter the App Store privacy label — will also be described in the release notes of the update that introduces them.
10. Contact
Questions, corrections, or a privacy request: [email protected]. We answer within 10 business working days.