Decaf Privacy Policy
How Decaf separates private local tracking from optional backups and its signed-in community.
This policy explains Decaf's local records, synchronized community, account services, backups, exports and privacy choices in plain language.
Overview
Blue Sparrow is a solo developer based in India and operates Decaf, a caffeine-reduction, self-tracking and peer-support app. This policy explains what information Decaf handles, why it is needed, where it goes and the choices available to you. Decaf is designed around data minimisation, purpose limitation, transparency and rights supported by the EU General Data Protection Regulation and other applicable privacy laws.
Decaf is local-first for your private caffeine journey, but it is not an entirely offline or all-local app. Core profile, check-in, symptom, note and preference records are stored on your device by default. If you sign in and use the community, that community identity and activity are sent to and synchronized with the Blue Sparrow-operated Decaf API. Account, purchase, push, support, backup and update features also use the connections described below.
Data we handle
Decaf may handle the following categories:
- Private journey records such as quit or reduction dates, caffeine history, source and amount, method, goals, motivation, streaks, custom milestones and progress.
- Check-ins and wellness observations such as caffeine intake, headache severity, fatigue, anxiety, nausea, irritability, insomnia, brain fog, energy, mood, cravings, stress, sleep quality and optional notes.
- Preferences such as theme, colour, reminders, notification timing, quiet hours, accessibility choices, local-only mode and saved diagnostic-control preferences.
- Optional Google and Firebase account information, including Firebase user identifier, email address, display name and profile image URL.
- Limited Firestore account and entitlement records, such as profile fields, account timestamps, subscription or VIP status, product and expiry information, and a last-backup timestamp.
- Community information handled by the Decaf API, including Firebase identifier, email, display name, optional avatar or profile fields, posts, replies, reactions, view and activity counts, reports and report details, notification preferences, push token and device label. Locally cached posts, saved-post identifiers, hidden-member choices and queued offline actions support the same feature on your device.
- Purchase and entitlement information handled by Google Play and RevenueCat, including product, receipt, transaction, renewal and subscription status. Blue Sparrow does not receive your full payment-card details.
- Information you deliberately submit through support or feedback, including reply email, optional name and subject, message, app version, platform and locale.
- Technical authentication, security and delivery information used by Firebase Authentication, Firebase App Check, Google Play Integrity, the Decaf API and notification services.
- Files you choose for restore and exports you ask Decaf to create or share.
Decaf does not need precise location, contacts, SMS content, call history, camera images, photo-library access, microphone recordings or browsing history for its current features. Android device backup is disabled for the app. Decaf does not display targeted advertising or build a cross-app advertising profile.
Health and wellness observations may be sensitive. Decaf does not intentionally add those private tracking records to the community, Firestore profile, RevenueCat or support service. They can be included in a backup or export that you request.
How we use data
Information is used only as reasonably necessary to:
- Provide caffeine tracking, check-ins, symptom views, timelines, insights, milestones, reminders, recaps, exports and restore tools.
- Authenticate an optional account and associate connected features and premium access with the correct user.
- Operate the signed-in community, synchronize content and interactions, cache the feed for offline reading, queue supported actions, deliver activity updates and review reports.
- Process purchases, restore entitlements and reduce misuse of paid or connected features.
- Create a backup or export when you request it and restore supported records when you select a copy.
- Deliver local or remote notifications after the relevant permission and app setting are enabled.
- Receive and answer support or feedback that you choose to send.
- Secure, maintain and improve Decaf and its connected services, and meet applicable operational, privacy and consumer obligations.
Decaf does not sell or rent personal information and does not use it for targeted advertising. The current app dependency set does not include Firebase Analytics or Firebase Crashlytics, and Decaf does not intentionally send usage events or crash reports to those products. The Usage analytics and Crash reporting switches currently save preferences on the device; they do not by themselves activate an analytics or crash-reporting SDK. This may change only with an updated disclosure and any control required for the new processing.
Local insights and statistics are calculated from your records on the device. They support self-reflection and do not make decisions with legal or similarly significant effects about you.
Storage and residency
Private journey records are stored in Decaf's app-private Drift database on your device. Community content is synchronized with the Decaf API and cached locally for stale-while-revalidate and offline use. Offline community actions may remain queued locally until they are delivered or discarded. The server creates an account-linked community record from verified Firebase identity details when you first use an authenticated endpoint.
Blue Sparrow-controlled Decaf community data is intended to remain in European Union infrastructure. Production datacentre location, database backups and retention operations must be verified before this is treated as an unconditional residency promise. Provider-controlled Firebase, Google, RevenueCat, notification and support data can follow each provider's disclosed infrastructure and transfer arrangements.
Community posts and replies are visible to other authenticated members with the display name and profile information supplied for that community identity. A custom community display name can reduce direct exposure, but the service links activity to the signed-in Firebase account for authentication, safety and moderation. Decaf does not promise that community participation is anonymous to Blue Sparrow.
Cloud and backups
Google Drive backup is optional and requires Google sign-in plus the Drive app-data permission. When you request a cloud backup, Decaf creates a supported archive of profile and check-in records, encrypts it on the device using AES-256-GCM with a key derived from the Firebase user identifier, and uploads it to Decaf's hidden app-data area in your own Google Drive. Decaf requests the app-data scope rather than general access to visible Drive files.
The Drive archive is not a complete copy of every Decaf table. In the current implementation it includes supported user-profile, preference and check-in fields; it does not include the synchronized community account or server content, and does not include every separate local table such as custom milestones, symptom-table entries, saved community posts or hidden-member choices. Automatic cloud backup is a premium feature, can be paused with local-only mode and uses best-effort scheduling. Decaf keeps one current backup and may create checkpoint archives; it attempts to retain up to five checkpoints by removing older ones on a best-effort basis.
Device backups and CSV, JSON or PDF exports are created as ordinary, unencrypted files before being passed to the system share or save flow. Their contents and coverage vary by format. You choose the destination and recipient, and the receiving application or storage provider then controls its copy. Do not share an export with someone who should not see your caffeine, symptom or note information.
Google controls the physical location and lifecycle of Drive data. Signing out or enabling local-only mode does not by itself delete an existing Drive archive. The Delete all data flow can attempt to remove Decaf Drive backups if you select that option; it fails closed if the Drive deletion cannot be completed.
Retention
Local records remain until removed with a relevant app control, device clear-storage control or uninstall process. Operating-system and user-created copies can have a separate lifecycle. Community caches can be refreshed from the server while signed in.
Active community profiles, content, replies, reactions, reports, notification settings, delivery records and server security records are retained while needed to operate, secure and moderate the community and then deleted, anonymised or restricted according to the applicable process. A post deleted through the app is soft-deleted on the service along with its visible replies; limited records may remain for integrity, safety, abuse prevention, backup or applicable obligations. No verified fixed production retention period is promised in this policy.
Firebase account and profile data, RevenueCat and Google Play purchase records, Google Drive archives, push delivery data and support messages follow the feature need, applicable requirements and each provider's controls. A store subscription is not cancelled by deleting local data or signing out.
The in-app Delete all data action clears core profile, check-in, symptom, settings, community-cache, queued-action and entitlement-cache tables, optionally attempts to delete Decaf Drive backups, and signs out. It does not call a Decaf API account-erasure endpoint, delete community posts or replies, delete Firebase Authentication or the Firestore profile, remove RevenueCat or Google Play records, cancel a subscription, or erase support messages. The current local wipe also does not explicitly clear the saved-post, hidden-member and custom-milestone tables. Use the device's clear-storage or uninstall controls for a full local reset, and email [email protected] for an account, community and connected-service deletion request.
Security
Decaf uses proportionate safeguards including app-private device storage, HTTPS, verified Firebase identity tokens for authenticated community requests, Firebase App Check for support submissions, scoped Drive permission, encrypted Drive archives, server-side access controls and rate or abuse controls. Push registration tokens are protected in transit; the server schema currently supports an encrypted token envelope while retaining a plaintext rollback representation until live migration acceptance is complete.
The on-device Drift database, device backups and exported CSV, JSON or PDF files are not described as independently encrypted by Decaf. Protect your device, Google account and exported files, install trusted updates and avoid including unnecessary private information in community or support messages. No device, transmission or connected service can be guaranteed completely secure.
Your rights
Depending on where you live and subject to applicable exceptions, you may have rights to know or access personal information, correct it, obtain a portable copy, delete it, restrict or object to processing, and withdraw consent where consent is the basis. You may also have a right to complain to your local data-protection authority. These protections include, where applicable, the EU GDPR and EEA rules, UK GDPR, India's Digital Personal Data Protection framework, California and other US state privacy laws, Brazil's LGPD, Canada's privacy laws, and comparable laws elsewhere.
You can change private tracking records and preferences in the app, disable notifications, enable local-only mode, remove individual community posts that you own, sign out, create exports and clear supported local data. You can optionally remove Decaf Drive backups through the Delete all data flow. Store subscriptions and provider-held copies may need to be managed through Google Play, Google Drive or the provider account.
To exercise a privacy right, email [email protected] with Decaf in the subject and enough detail to identify the relevant account or request. Blue Sparrow may ask for proportionate verification and will respond within the period required where you live. There is no charge for an ordinary request, although clearly excessive or repeated requests may be handled as permitted by applicable law.
Children
Decaf is intended for a general audience managing personal caffeine habits and is not directed to children. Caffeine use and withdrawal can involve health considerations. A parent or guardian should supervise use by anyone who cannot validly make their own account, privacy, purchase or community choices. Do not create an account, enable connected features, purchase a plan or post community content for a child without a valid basis and any permission required where you live. Contact [email protected] if you believe a child's information has been provided inappropriately.
International transfers
Private tracking remains on the device unless you choose a backup, export or share action. Blue Sparrow's synchronized Decaf community is intended to use EU infrastructure, subject to production verification. Google, Firebase, RevenueCat, Google Play, notification, support and user-selected file providers may process limited information outside your country or region.
Where safeguards are required for an international transfer, Blue Sparrow and relevant providers rely on appropriate contractual, adequacy or other lawful mechanisms and apply data-minimisation and security measures. Blue Sparrow does not claim that every item of Decaf information remains exclusively in the European Union. EU users retain the protections required by the EU GDPR even where a necessary provider connection crosses a regional boundary.
Changes
This policy may change when Decaf, its providers or applicable requirements change. Material updates will be presented in the app or at https://bluesparrow.dev where appropriate, and the updated date will be revised. Earlier processing remains governed by the version applicable at that time unless a change must apply sooner for security or legal reasons.
Contact
Blue Sparrow is the developer and privacy contact for Decaf. For privacy questions, rights requests or account and community deletion, email [email protected]. For general help, email [email protected]. Product and policy information is available at https://bluesparrow.dev.