1. Who We Are
Shotbook is a craft coffee journaling app developed and operated by Michael Timofeev.
Website: theshotbook.app
Contact: privacy@theshotbook.app
2. Data We Collect
In the app — no collection. All brew data you enter (recipes, ratings, notes, photos) is stored exclusively on your device using local storage. We do not transmit, sync, or have access to your brew journal in any way.
On the website — waitlist only. If you voluntarily submit your email address via the waitlist form on our website, we collect:
- Email address — to notify you when Shotbook Pro launches and to send relevant product updates.
- Submission timestamp — for internal record-keeping.
- Source field — which page or form you submitted from (e.g. "landing_page").
We do not collect your name, payment information, device identifiers, or browsing behaviour on our website.
3. How We Use Your Data
We use email addresses collected via the waitlist solely to:
- Notify you when Shotbook Pro becomes available.
- Send occasional product announcements directly related to Shotbook (e.g. major new features, iOS launch).
- Respond to support requests you initiate by emailing us.
We will never sell, rent, or share your email address with third parties for marketing purposes.
4. Data Storage & Security
Waitlist email addresses are stored in Supabase — a GDPR-compliant database platform hosted in the EU (AWS eu-central-1 region). Supabase applies industry-standard encryption at rest and in transit (TLS/HTTPS).
Access to the database is restricted by Supabase Row Level Security policies. Only the app developer has administrative access.
5. Data Retention
We retain waitlist email addresses until:
- You request deletion (see Section 7), or
- 12 months after Shotbook Pro has launched and the waitlist is no longer active.
Brew data in the app is retained on your device until you delete the app or clear its data. We have no access to it and cannot delete it remotely.
6. Third-Party Services
We use the following services:
- Supabase (privacy policy) — database for waitlist emails.
- Cloudflare (privacy policy) — website hosting and CDN. Cloudflare may log IP addresses for security purposes as per their standard terms.
- Google Play (privacy policy) — app distribution. Google collects crash reports and aggregate install statistics as described in their developer policy.
We do not use analytics trackers, advertising networks, or social media pixels on our website.
7. Your Rights (GDPR)
If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation:
- Right to access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate data.
- Right to erasure — request deletion of your data ("right to be forgotten").
- Right to restriction — request that we restrict processing of your data.
- Right to object — object to processing of your data for direct marketing.
- Right to data portability — receive your data in a structured, machine-readable format.
To exercise any of these rights, email privacy@theshotbook.app with the subject "Privacy Request". We will respond within 30 days.
8. Children's Privacy
Shotbook is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has submitted their email via our waitlist, please contact us immediately and we will delete it.
9. Google Play — Data Safety Declaration
In line with Google Play's data safety requirements, here is a summary of data practices for the Shotbook Android app:
- Data collected: Email address (optional, waitlist only — collected on website, not in-app).
- Data shared: None. We do not share personal data with third parties.
- Security practices: Data is encrypted in transit.
- Data deletion: Users can request deletion by emailing privacy@theshotbook.app.
- In-app data: All brew data is stored locally on-device. The app does not collect or transmit brew data.
10. Changes to This Policy
We may update this privacy policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify waitlist subscribers by email. Continued use of the app or website after changes constitutes acceptance of the updated policy.
11. Legal Basis for Processing (GDPR)
We process your email address on the legal basis of consent (Art. 6(1)(a) GDPR) — you voluntarily submit your email to join the waitlist. You may withdraw consent at any time by emailing us to be removed.
Contact & Data Requests
For any privacy-related questions, data access requests, or deletion requests:
Email: privacy@theshotbook.app
Subject line: "Privacy Request"
We will respond within 30 days. For urgent matters, please indicate this in your subject line.