legal

privacy policy

last updated september 2026 · human made things

the short version

your bags, your notes and every shot you log stay on your iPhone. the app has no account, no advertising and no tracking. it records a few usage events, such as which onboarding step you reached, tied to a random identifier and never to you (section 11).

three things can send something off the phone, and only when you use them. scanning a bag sends the text printed on it to be looked up on the web. on some iPhones, a label the phone struggles to read is re-read by Apple’s Private Cloud Compute, which is sent the photographs and never reaches us. making a bag 3D sends a picture of that bag to be turned into a model.

one thing leaves without a tap: those usage events, which say what happened in the app and never what you photographed or typed (section 11).

buying the app or a pack of renders goes through Apple and RevenueCat under a random identifier, never your name.

on this website, the only thing we ever collected was an email address, from people who asked to hear when beans was out. that list was used once and deleted (section 12).

1. what stays on your phone

everything you make in beans is stored on your iPhone, using Apple’s SwiftData framework: the photograph of each bag and its cut-out, the details read off the label, anything you type, every dial-in attempt (grind, dose, yield, time, water temperature, your rating and notes), your equipment setup, and your settings. we do not run a sync service and we cannot read any of it.

reading a label starts on the phone, with Apple’s Vision text recognition and Apple’s on-device model. section 3 covers the one case where a label leaves the phone for a second reading.

if you have iCloud device backups turned on, your beans data may be part of that backup. that is Apple’s backup of your phone, and we have no access to it.

2. what we never collect

the app never sends us your name, email address, phone number or contacts, and Apple’s Private Cloud Compute (section 3) is between you and Apple, not us. the app asks for the camera and nothing else: no location, no photo library, no microphone, no contacts, no notifications. we do not use Apple’s advertising identifier, so beans shows no tracking prompt. there is no crash-reporting service in the app, the few usage events it records (section 11) carry nothing you photographed or typed, we do not track you across other apps or websites, and nothing is sold or shared for advertising.

your dial-in attempts, notes and equipment never leave the phone, on any path.

3. a second reading by Apple

if the on-device reading of a label leaves gaps, and your iPhone supports it, beans asks Apple’s Private Cloud Compute to read it again. this is a larger Apple model that runs on Apple’s servers instead of your phone. it is sent both photographs of the bag and the text the scan read off them, and it is the only place a photograph of a bag leaves your phone without you asking for a 3D render.

it happens automatically when the label needs it, and it is Apple’s system end to end: the request goes from your phone to Apple and the answer comes back, and none of it passes through us. Apple states that Private Cloud Compute does not store what it is sent and that it cannot be accessed even by Apple; that is Apple’s claim to make, and their terms govern it. nothing depends on it, and if it is unavailable the form simply keeps the on-device reading.

their description: security.apple.com/blog/private-cloud-compute

4. looking a coffee up on the web

after you scan a bag, beans can research it, so the form fills in what the label did not say: the roaster’s own description, the origin, the producer. this is the one thing beans sends to us.

what is sent

your photographs are never part of this lookup, and neither is anything you typed, any attempt you logged, or anything that says who you are. beans works without the lookup: it never blocks saving, it never overwrites something you typed, and with no signal you simply fill the form in yourself.

who handles it

the request is signed by Apple’s App Attest (section 7) and goes to a small server we run on Cloudflare Workers. that server holds the credentials, so they are never in the app, and forwards the request to OpenRouter, a service that passes it to a language model with web search. at the time of writing that model is DeepSeek’s V4 Flash, run by whichever provider OpenRouter routes to, and the searches the model makes, built from the names on your bag, go to a web-search service OpenRouter connects it to.

OpenRouter says it does not use your inputs or outputs for model training. it also says the model providers behind it process inputs under their own terms and may retain them, and we have not restricted routing to providers that keep nothing. the text in a lookup is printed on a coffee bag and not linked to you, but it is a transcript of your photograph, so treat it that way.

our server keeps a log line for each request: a random key identifier, how long it took, which fields came back filled and which web pages the model read. it does not log the transcript. Cloudflare keeps those logs for a few days.

their policies: openrouter.ai/privacy · cloudflare.com/privacypolicy

5. making a bag 3D

a render turns your bag into a 3D model for the shelf. it only happens when you ask for it, and it is the one thing beans sends that is a picture: a picture of the front of the bag. that is the cut-out, the bag with its background removed, or, when no cut-out could be made, the whole photograph.

if it is the whole photograph, it includes whatever was behind the bag, so keep anyone and anything private out of frame when you photograph one you mean to render.

the picture goes through our server to Meshy, which builds the model and sends it back to be stored on your phone. our server does not keep the picture. it keeps a task record: Meshy’s task number, your random device key and customer identifier, an identifier for the bag, timestamps, and whether the render was charged. that record is what stops anyone spending a render that is not theirs.

what Meshy does with it is Meshy’s to say, and we would rather quote them than paraphrase. Meshy’s documentation says generated models are deleted from its servers after three days. its privacy policy says it may use a limited selection of customer inputs and outputs to evaluate and test the quality, safety and performance of its models, and it is a US company that may process information anywhere in the world. we could not confirm how long it keeps the picture you upload, and we cannot opt you out. if that is not acceptable for a picture of your bag, do not make it 3D: the shelf works with the photograph, and nothing else in beans needs this feature.

their policy: meshy.ai/privacy-policy

6. buying the app and renders

payment is handled by Apple. beans uses RevenueCat to know what you own and how many renders you have left.

RevenueCat receives your App Store purchase receipt, basic device information such as model, iOS version and country, and an App User ID: a random identifier the app creates the first time it runs and keeps in your iPhone’s Keychain. it is kept there rather than with the app so a delete and reinstall keeps your renders. an iCloud backup restore or a phone-to-phone transfer carries it too; a phone set up as new does not, and starts a fresh identity. it never receives your name, your email address or your Apple ID.

the same identifier is how our server finds the balance to spend a render from. RevenueCat acts as our data processor, is based in the USA, and holds this data under a data processing agreement.

the welcome offer’s countdown is kept on your phone, in the Keychain beside that identifier, and is not sent anywhere. if you redeem an offer code, the redemption sheet is Apple’s.

their policy: revenuecat.com/privacy

7. proving the app is genuine

our server costs money to run, so it only answers a genuine copy of beans on a genuine iPhone. it asks Apple’s App Attest service, which makes a cryptographic key in your phone’s Secure Enclave. the key cannot leave the phone and every request is signed with it.

our server stores the key’s public half, a counter that stops a request being replayed, the app version, and the receipt Apple issues. none of it identifies you, and none of it carries a request’s contents. deleting the app and reinstalling makes a new key.

8. children

beans is not directed at children under 13 and we do not knowingly collect anything from them. nothing in the app asks for a name or an age.

9. lawful basis and where data goes

for the lookup and the render we rely on performing the service you asked for by tapping the button. for keeping the service secure, and for the server logs, our legitimate interest in running it safely. for usage analytics, our legitimate interest in understanding which parts of the app work (section 11). PostHog processes those events in the European Union; the other services above are based in the USA and elsewhere, and where personal data leaves the UK or the EU, they rely on standard contractual clauses and the UK addendum to them, or on Apple’s and RevenueCat’s own frameworks. for the launch waitlist, which has closed, the consent of the people who joined it (section 12).

10. your rights

everything you make in beans is on your phone, so deleting the app removes it, permanently and with no way for us to recover it. export or photograph anything you want to keep first.

the data we and our processors hold is keyed to random identifiers, not to you, and that is the direct cost of not knowing who you are. an email address cannot be matched to a customer identifier, so we cannot look you up from one. the identifier is shown nowhere in the app, so write to us and we will work out with you what can be found and removed, including asking RevenueCat to erase a customer record, deleting the usage events PostHog holds, and removing our own task and key records.

for that, or any question about this policy, email help@humanmadethings.co.uk. the data controller is human made things, in the United Kingdom. if you are in the UK or the EU you may also complain to your data protection authority, which in the UK is the Information Commissioner’s Office.

11. usage analytics in the app

beans records a small number of events: which onboarding step you reached, whether a bag was photographed and saved, whether the paywall was shown, whether a 3D render or a dial-in attempt was started, how a 3D render ended and how long it took, when you open, remove or save a recipe for a bag, how many bags are on your shelf, the type of equipment you set up (such as your portafilter size and whether you use a puck screen, never a name), when you leave a paywall without buying, whether looking up a bag found anything, whether you said you would rate the app, and when something failed, including the errors the app recovers from on its own, such as a save that did not complete or a 3D model that would not load. these events carry no coffee names, roasters, notes, photographs or anything you type: only a step name, a count or a yes/no, and for an error, which operation failed and the system’s numeric error code. they are tied to the same random identifier described in section 6, created on your device, never to your name, email or Apple Account. they are processed by PostHog on servers in the European Union, and client IP addresses are discarded on arrival. purchase events from RevenueCat are joined to the same random identifier. we do not use any of this for advertising and we do not share it with data brokers.

their policy: posthog.com/privacy

12. the launch waitlist

this part is about the website, not the app. before beans launched, this site’s beans page had a form where you could leave your email address to get a single email when beans was out on the App Store. the addresses were used for nothing else, and were never shared or sold.

the form was stored by Netlify, which hosts this website, in the USA. with each submission Netlify also recorded the time, the page the form was sent from and, for spam filtering, your IP address and browser details, which it passed to Akismet to check the submission was not spam. the launch email went out on 26 September 2026 from our iCloud Mail address, through Apple. after that we deleted every submission in Netlify, including any held as spam, the list we exported to send it, and the sent message. we keep no copy.

the waitlist ran on the consent of the people who joined it, given by sending the form. it has closed, the form is gone, and there is nothing left to withdraw.

their policy: netlify.com/privacy · automattic.com/privacy (Akismet)

13. changes

if this policy changes in a way that affects what leaves your phone, we will update the date at the top and say what changed. the version you are reading is the current one.