Degustation Privacy Policy

Effective date: 2026-08-28

Degustation (the "Service") complies with applicable privacy laws and processes personal data lawfully and transparently. This policy applies to the Service website, the mobile app, and all related features.

1. Purpose of Processing Personal Data

  1. Member administration: account registration and identity verification, social login integration, account maintenance, abuse prevention, and customer support.
  2. Service operation: storing/displaying content such as coffee records and memos, and collecting/sharing guest tasting inputs through tokenized guest links created by members.
  3. AI-assisted input and summarization: extracting coffee details from product pages and uploaded images, suggesting wording during the guest tasting flow, and generating the summary line on tasting scorecards.
  4. Service improvement and analytics (only with optional consent): usage analysis, error diagnostics, and statistics for feature improvement (Google Analytics 4).
  5. Mobile app quality and error diagnostics: analyzing in-app usage events and diagnosing abnormal terminations (crashes) (Android app only)

Guest tasting links may expire after 7 days by default (subject to policy changes).

2. Categories of Personal Data We Process

2.1 Members (email signup)
Required: email, password (stored in encrypted form), account identifier, signup/access logs
Optional: display name (if provided)

2.2 Members (social login)
Required: social provider identifier, email (within provider scope), signup/access logs
Optional: profile information (within provider scope)
Supported providers: Google, Kakao

2.3 Guests (token-link users)
Required: tasting inputs (scores/keywords/comments), token identifier (random string), access logs

Guests are asked not to include personal information (for example, contact details) in comments. If personal data is included, it may be deleted or masked as needed. Memos and 'what fell short' notes left by guests may be transmitted to the AI inference providers listed in Section 5 when the summary line is generated, which can happen automatically when a member closes the session or when the session expires.

2.4 Automatically collected data
IP address, access logs, device/browser information, cookie/session identifiers, error logs
(with optional consent) GA4 event data and cookie identifiers (for example, _ga)

2.5 Automatically collected data (mobile app)
Android app: in-app usage events (sign-in, coffee saved, session created, insights viewed, and similar) and their parameters (sign-in method, language, internal coffee/session numbers), device/app information (device model, OS version, app version, app instance identifier), error and crash logs
iOS app: does not include analytics or crash-reporting tooling and does not collect the items above.

In-app usage analytics can be turned off at any time under "Share usage data" in the Account tab (on by default). Account identifiers and email addresses are never sent.

Error and crash records cannot be turned off, as they are required to diagnose failures; they are collected only to the extent needed to maintain service quality.

Some in-app usage events are also recorded on the Service's own servers, stored together with the account identifier.

3. Retention Period

  • Member data: until account deletion. Once deletion is requested we wait three days and then erase the account; signing in during those three days cancels the request
  • Guest tasting data: kept while the account of the member who created the link remains, and erased when that member deletes the record or closes their account
  • Guest personal result links: no separate expiry is set; they stop working when the tasting data above is erased
  • Access/error logs: retained for up to 1 year, then deleted (operational policy)
  • Dispute response / abuse prevention records: retained for up to 1 year, then deleted (operational policy)

4. Provision to Third Parties

The Service does not provide personal data to third parties in principle. However, data may be provided where required by law or where separate user consent is obtained.

5. Outsourcing / Processors

  • Infrastructure/hosting/server operation: Oracle Cloud
  • Social login providers: Google, Kakao
  • AI inference (assisted input and summarization): OpenRouter and the AI model providers reached through it (for example, OpenAI, Google)
  • Web analytics (with optional consent): Google Analytics 4 (Google)
  • Mobile app analytics and crash reporting: Google (Firebase Analytics, Firebase Crashlytics) — Android app only
  • Email delivery: Mailgun (service emails such as password resets only)

The Service currently does not provide payment functionality.

Uploaded images are used only for temporary coffee information parsing. They are transmitted to the AI inference providers listed above for that parsing, are not stored on the Service's servers, and are discarded immediately after processing. Each transmission carries a constraint that routes it only to providers that do not retain transmitted data or use it for model training, and the data is used only for as long as the request takes to process.

6. Cross-Border Transfer of Personal Data

The Service transfers personal data abroad as follows.

6.1 AI inference (assisted input and summarization)

  • Recipient: OpenRouter and the AI model providers reached through it (for example, OpenAI, Google)
  • Country: the United States and other countries where those providers operate
  • Items transferred — coffee registration: the product page URL you enter, the text collected from that page, and images you upload
  • Items transferred — guest tasting flow: coffee details and the selected strength, acidity, bitterness, and body values (free-text entries are not transmitted)
  • Items transferred — summary generation: coffee details, aggregated ratings, and up to two entries from guest memos and 'what fell short' notes (each truncated to 200 characters before transmission)
  • Purpose: extracting coffee details and generating the scorecard summary line
  • Timing and method: transmitted over the network when the relevant feature is used
  • Retention: none. Every request is sent with a constraint that routes it only to providers that do not retain transmitted data or use it for model training, and the data is used only for as long as the request takes to process

6.2 Web analytics (with optional consent)

  • Recipient: Google
  • Country: the United States and others
  • Items transferred: GA4 event data and cookie identifiers
  • Purpose: usage analysis and feature improvement
  • Timing and method: transmitted over the network when the GA4 script runs after consent
  • Retention: per Google Analytics retention settings

6.3 Mobile app analytics and crash reporting (Android app)

  • Recipient: Google (Firebase Analytics, Firebase Crashlytics)
  • Country: United States and others
  • Items: in-app usage events and their parameters, device/app information (device model, OS version, app version, app instance identifier), error and crash logs (account identifiers and email addresses are never sent)
  • Purpose: app quality improvement and error diagnosis
  • Timing and method: transmitted over the network when the app launches and when the relevant events occur
  • Retention: per Google Firebase retention settings
  • The iOS app does not include these tools, so this transfer does not occur

You may enter coffee details manually instead of using AI extraction, and you may withdraw analytics consent in cookie settings. In-app usage analytics can be turned off under "Share usage data" in the Account tab.

7. Destruction Procedure and Method

  • Procedure: when purpose is achieved or retention period ends, data is selected and destroyed under internal policy
  • Method: electronic files are deleted using non-recoverable methods; printed materials are shredded or incinerated

8. User Rights and How to Exercise Them

Users may request access, correction, deletion, and suspension of processing of their personal data at any time.

How to exercise rights: use account/settings features in the Service or contact us.

Service features: account deletion, deletion of records/memos, and guest-link reissuance.

You can request account deletion from both the app and the web. The steps and the scope of what is removed are set out on a separate page. Account deletion guide

9. Security Measures

  • Encrypted storage of key information including passwords
  • Access control and permission management (least-privilege principle)
  • Access log and anomaly monitoring
  • Encryption in transit (HTTPS)

10. Cookies: Use and Refusal

The Service may use required cookies for login persistence and security.

Analytics cookies such as GA4 are used only after consent (optional consent).

You can refuse cookie storage via browser settings; in this case some features (such as persistent login) may be limited.

11. Children's Privacy

The Service is not directed to children, and we do not knowingly collect personal information from children.

  • Republic of Korea: Children under the age of 14 may not create an account.
  • United States: The Service is not directed to children under 13 under the Children's Online Privacy Protection Act (COPPA), and we do not knowingly collect personal information from any user we know to be under 13.
  • Other countries: You may not use the Service if you are below the age at which processing of your personal information requires parental consent in your country.

If we learn that we have collected personal information from a child below these ages, we will delete that account and information without delay. If you believe a child's information has been collected, please notify us using the contact details below.

12. Notice for Users Outside Korea

The Service is operated from the Republic of Korea. Your personal information is stored on servers located in Korea and processed under Korean law. If you use the Service from outside Korea, you consent to the transfer of your personal information to Korea. The following applies in addition to the sections above.

12.1 United States Users

  • We do not sell your personal information, and we do not share it for cross-context behavioral advertising. The Service carries no advertising.
  • Depending on your state of residence, you may have the right to access, obtain a copy of, correct, and delete your personal information, and the right not to be discriminated against for exercising those rights.
  • You may exercise these rights through in-service account features (account deletion, record deletion) or by contacting us at the address below. We will verify that the request comes from you before acting on it.
  • We do not disclose personal information to third parties other than the processors listed in Section 5.

12.2 Japan Users

  • We handle the personal information of users in Japan as a personal information handling business operator under the Act on the Protection of Personal Information (APPI).
  • Our purposes of use are set out in Section 1, the categories handled in Section 2, third-party provision in Section 4, entrustment in Section 5, and provision to third parties in foreign countries in Section 6.
  • Subject to identity verification, you may request notification of the purpose of use, disclosure, correction, addition or deletion, suspension of use or erasure, and suspension of third-party provision of your retained personal data. Requests are received at the contact address below.
  • Because our servers are located in the Republic of Korea, personal information of users in Japan is transferred to and stored in Korea.

12.3 Other Countries

  • If you use the Service from Canada, Australia, Singapore, Taiwan, or elsewhere, you may make the same access, correction, deletion, and suspension requests described in Section 8.
  • We do not currently distribute the app in the European Economic Area or the United Kingdom.

Regardless of country, all requests are received at the single contact address below. We reply in Korean or English.

13. Privacy Contact

Operator: Fount Lab

Data Protection Officer: Fount Lab Privacy Team

Contact email: contact@fountlab.co.kr

14. Policy Changes

This policy may be revised due to legal or service changes. If revised, we will provide notice in the Service or through other appropriate means.