Privacy
What data SnapDial processes on the website and in the iOS/Android app. Clear, short, no tracker theatre. Processors named below are the ones actually wired in the product — optional services only run when configured.
1. Controller
Boris Fründt, Carl-Adam-Petri-Str. 44, 14469 Potsdam, Germany. Contact: hello@snapdial.app. Further details in the legal notice.
2. This website (snapdial.app)
This site is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When you visit, Vercel processes technically necessary data (e.g. IP address, time, page requested, browser identifier) in log files to provide and secure the service (Art. 6 Abs. 1 lit. f GDPR). The site sets no cookies and uses no third-party analytics or advertising trackers.
3. Waitlist
If you sign up for early access, we process your email address and the time of signup to contact you once when SnapDial launches (Art. 6 Abs. 1 lit. a GDPR). Entries are written to our server logs and, if configured, forwarded to an optional webhook URL controlled by us. They are not stored in the app database and are not shared for advertising. You can request deletion at any time by email.
4. SnapDial mobile app
The app talks to our API at api.snapdial.app (same Vercel project as this site). Application data that we persist lives in Neon Postgres (Neon, Inc.), connected via Vercel Storage, when the database is configured.
4.1 Device identity
On first use the app registers an anonymous device. The client stores a device token in the OS secure store; the server stores a public device id, a hash of the secret, optional platform string, and timestamps. No name or email is required for scanning or recipes (Art. 6 Abs. 1 lit. f GDPR — providing the service and metering free scans).
4.2 Bag scans and photos
When you photograph a bag, the image is sent once to POST /scan so we can extract label fields. The photo is forwarded to OpenRouter, Inc. (vision model API) for that extraction and is not retained in our database. We store only scan metering metadata (device id, month period, optional bean hash, timestamps) and — after you confirm a scan — structured bean fields (e.g. roaster, coffee name, origin, process, roast) in a shared bean cache keyed by a hash of roaster + name. Bag photos that stay on your phone remain local and are never synced to our servers.
4.3 Optional account (Clerk)
Sign-in is optional. When enabled, authentication is provided by Clerk, Inc. (Sign in with Apple and/or email code). We may link your anonymous device to your Clerk user id and store a small settings blob plus Pro sync data (bags and equipment setups withoutphotos) for signed-in Pro users (Art. 6 Abs. 1 lit. b / a GDPR). Sync requires Pro on the server.
4.4 Optional Pro purchases (RevenueCat / Apple)
In-app purchases go through Apple's App Store. Entitlement events can be mirrored to us via RevenueCat, Inc. webhooks so scan quotas and Pro features stay consistent across devices. We store entitlement tier, source, optional product id, and expiry keyed to your device public id and/or Clerk user id — not your payment card details (those stay with Apple).
4.5 Community dial-in telemetry (opt-in)
Sharing is off by default. If you opt in under Settings, the app may upload anonymized dial-in reports (bean hash, equipment ids, numeric recipe tuples, grind delta, shots to dial-in). No names, no free text, no photos (Art. 6 Abs. 1 lit. a GDPR). You can turn this off anytime; new uploads then stop.
4.6 On-device data
Recipes, shot history, equipment setups, calibration, taste profile, language preference, and bag photos live primarily on your device (local app storage). The app works offline for everything except scanning and optional sync/community calls.
5. Deletion and your choices
- This device: Settings → Your data → Delete data on this device calls DELETE /device, which removes the device row (cascading scan metering and dial-in reports) and any entitlement keyed to that device id, then clears local app storage and the device token.
- Signed-in account: use Delete account in the app Account screen (or ask us by email). Clerk emits user.deleted; we then remove the user row, user-keyed sync data (cascade), and user-keyed entitlements. This does not cancel an App Store subscription — manage that in Apple subscriptions.
- Waitlist / other requests: email hello@snapdial.app.
6. Recipients / processors
- Vercel Inc. — website and API hosting
- Neon, Inc. — Postgres database (when connected)
- OpenRouter, Inc. — bag-label vision extraction (image in transit; not stored by us)
- Clerk, Inc. — optional authentication
- RevenueCat, Inc. — optional purchase entitlement events
- Apple Inc. — App Store billing / Sign in with Apple (when you use those features)
7. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection (Art. 15–21 GDPR), as well as the right to lodge a complaint with a supervisory authority. Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.