CoffeeTalk← Back to home

Privacy Policy

Last updated: August 22, 2026

This Privacy Policy explains how CoffeeTalk Inc. (“CoffeeTalk”, “we”, “us”) collects, uses and protects your information when you visit https://www.coffee-talk.net (the “Site”) and when you use the CoffeeTalk mobile app (the “App”). CoffeeTalk Inc. is a Delaware corporation with its principal office at 8 The Green, Suite 15796, Dover, DE 19901, United States. We are the data controller for the personal information described below.

The Site and the App collect different things through different providers. Where the difference matters, a section says Site or App explicitly.

1. Site: what we collect

When you sign up for the beta or browse the Site we collect:

  • Contact details — your name, email address and any optional messenger handle you add (Instagram, WhatsApp, Telegram, KakaoTalk).
  • Optional feedback — anything you write in the signup form.
  • Technical data — IP address, browser and device type, language and referring URL, collected by the analytics and advertising services in section 6 and only after you accept them in the cookie banner.

2. App: what we collect

  • Account — your email address, or the identifier returned by Apple, Google or Naver if you use social sign-in, plus the account id we generate.
  • Profile — display name, @handle, photo, bio, gender, date of birth, the languages you speak and are learning, interests, country and city. Other users see your age, never your date of birth.
  • Content — chat messages, photos, videos, files, voice notes, stories, posts, reactions and read receipts.
  • Calls — who called whom, when a call started and how long it lasted. Call audio is never recorded.
  • Verification results — liveness and face-match scores and the pass/fail verdict, described in section 3.
  • Device data — push notification tokens, app and iOS version and language, and the diagnostics attached to a support request.
  • Approximate location — only if you turn on nearby sorting; see section 7.
  • Product analytics — in-app events and session recordings, described in section 6.

3. Identity verification and biometric data

CoffeeTalk checks that a profile belongs to a real, unique person. When you verify, the App takes a selfie and our server passes it to Didit (didit.me), our verification provider, for up to three checks:

  • Passive liveness — is this a living person in front of the camera rather than a photo, a mask or a screen?
  • Face match (1:1) — if you supplied a reference photo, does the selfie match it?
  • Face search (1:N) — is this face already registered to a different CoffeeTalk account? A match against another account blocks verification, because it indicates a duplicate or impersonated account.

The 1:N check works because verified faces are enrolled in a gallery. That gallery is held by Didit, not by us, and each enrolment is tagged with your CoffeeTalk account id. It holds mathematical face templates derived from your selfie, not browsable pictures.

On our own servers we keep only the outcome — the liveness and match scores, whether the check passed, and the id of any account your face matched. We do not store the selfie or the reference photo. They exist in memory for the length of the request and are then discarded.

Under the GDPR a face template is biometric data used to identify you, a special category under Article 9. We process it on the basis of your explicit consent, which you give by starting verification, and we use it for one purpose only: keeping fake and duplicate accounts out of the community. Verification is optional — you can decline, and an unverified account simply has lower limits and no verified badge. To withdraw consent, write to help@coffee-talk.net: we will delete the verification records on our side and ask Didit to delete your enrolment.

An earlier version of this check used Amazon Rekognition Face Liveness. The App still creates an anonymous Amazon Cognito guest identity at launch as a leftover of that integration; no selfie, face template or verification result is sent to Amazon Web Services.

4. Messages, calls and machine translation

Messages, stories and posts are stored so that we can deliver them and show them to you again later. Text lives in our database at Supabase; photos, videos, files and voice notes live in Cloudflare R2 and are served through short-lived signed links.

  • Translation. When you translate a message, its text is sent to OpenRouter, which routes it to a language model. We pin that routing to providers that run under zero-data-retention terms and deny use of the text for training.
  • Voice notes. If you translate a voice note, the audio is sent to OpenRouter for transcription, and the transcript is then translated the same way. The transcript is cached with the message.
  • Calls. Call audio flows through LiveKit in real time and is not recorded or stored. Live subtitles are produced by speech recognition on your iPhone; only the resulting text is sent for translation, under the same terms as above.

Everything is encrypted in transit with TLS. CoffeeTalk is not end-to-end encrypted: we are technically able to read stored content, and we do so only for the reasons in section 5 or where the law requires it.

5. Safety, reports and moderation

  • Reports. When you report a message, profile, story or post, our server stores its own copy of the reported content, so that the report stays reviewable even if the content is later edited or deleted.
  • Deleted messages. When you delete a message for everyone, both participants see a tombstone in the chat, but the original text is copied into an append-only moderation archive. This exists so that abuse cannot be erased before the person on the receiving end reports it. The archive currently has no automatic expiry.
  • Moderator access. Our staff moderators can open reported chats, media, stories and profiles through a separate, login-gated console. Each time a moderator opens a case, an audit record is written.
  • Outcomes. A case can end in dismissal, removal of the content, a warning (strike), or a temporary or permanent ban. Every action is recorded in an append-only log.

6. Analytics and advertising

Site. With your consent in the cookie banner, the Site loads Google Analytics (usage statistics), the Meta Pixel and the Reddit Pixel (conversion measurement and advertising audiences). Declining the banner stops them from loading at all.

App. The App uses PostHog on its EU cloud (eu.i.posthog.com) for product analytics: named events such as screens opened, buttons tapped and onboarding steps completed, attached to your CoffeeTalk account id. Message content never becomes an event property. Session replay is enabled, and in App Store and TestFlight builds it masks text fields, loaded images and system views. You can turn analytics off in the App’s settings.

The App contains no advertising SDK, does not use the advertising identifier (IDFA) and never asks for App Tracking Transparency permission. Nothing collected in the App is used to track you across other companies’ apps or websites.

7. Notifications, location and device permissions

  • Camera and photo library — used only for the selfie you take during verification and for the photos and videos you choose to send or post.
  • Location — optional. If you enable nearby sorting, the App takes a single fix at about one-kilometre accuracy. We store the coordinates on your profile but never show them: other users only ever see a distance.
  • Speech recognition — runs on your device, to produce live subtitles during a call.
  • Push notifications — delivered through Apple’s push service (APNs). A message notification includes the sender’s name and up to 140 characters of the message, so that the preview is useful on the lock screen. You can turn notifications off in iOS settings or in the App.

8. Service providers

We share personal data only with the providers that operate the service on our behalf, under contracts that limit them to our instructions. We do not sell personal data.

  • Supabase — database, authentication and server functions (the App’s backend, and the beta signup list from the Site).
  • Cloudflare R2 — storage of photos, videos, files, voice notes and avatars.
  • Didit — identity verification and the biometric gallery described in section 3.
  • OpenRouter and the model providers it routes to — translation and voice transcription.
  • LiveKit — real-time audio for calls.
  • PostHog (EU cloud) — product analytics and session replay.
  • Apple — push delivery; Apple, Google and Naver if you use their sign-in.
  • Resend — delivery of account emails such as sign-in codes.
  • Amazon Web Services — the legacy Cognito guest identity described in section 3.
  • Vercel — hosting of the Site.
  • Google, Meta and Reddit — Site analytics and advertising, only after consent.

9. International transfers

CoffeeTalk Inc. is based in the United States and our providers operate in the United States and the European Union, so your data will be processed outside your own country. Where data leaves the European Economic Area or the United Kingdom, we rely on the European Commission’s standard contractual clauses and on our providers’ own transfer frameworks.

10. How long we keep data

  • Account, profile and content — for as long as your account exists (see section 12).
  • Verification records — the scores and verdict, for as long as your account exists; the enrolment held by Didit until you ask us to remove it.
  • Reports, the moderation archive and moderation actions — append-only, with no automatic expiry today, because they are the evidence behind a safety decision.
  • Support requests — kept so that we can answer you and keep a history of the conversation.
  • Analytics — under the retention defaults of PostHog and, for the Site, of Google, Meta and Reddit.

11. Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA and others), you may have the right to:

  • access the personal data we hold about you, and get a copy of it;
  • have inaccurate data corrected, or have your data deleted;
  • object to or restrict certain processing;
  • withdraw a consent you gave — including the consent to biometric verification — without affecting what was lawful before;
  • complain to your local data protection authority.

We do not sell personal information and we do not share it for cross-context behavioural advertising as those terms are defined in California law. To exercise any right, write to help@coffee-talk.net.

12. Deleting your account

You can delete your account from inside the App, in Settings. Deletion is immediate and irreversible — there is no grace period and no way for us to restore the account afterwards.

Deleting removes your profile, the messages you sent, your stories, posts, streaks, reports, push tokens and verification records, together with your avatars and your story and post media. Two things deliberately remain: media you sent inside a conversation, because it was already delivered to the other participant and is not yours alone to erase, and the moderation archive and moderation-action records described in section 5. Analytics events already received by PostHog are not removed automatically — ask us and we will delete them.

13. Children

CoffeeTalk is not intended for anyone under 17, and the App is rated 17+ on the App Store. We do not knowingly collect data from children. If you believe a child has created an account, write to help@coffee-talk.net and we will remove it.

14. Security

Traffic is encrypted with TLS. Access to stored data is restricted by row-level security rules in the database, media is reachable only through short-lived signed links, and credentials for third-party services live in server-side secrets and never in the app binary. No system is completely secure; if you believe your account or data has been compromised, write to help@coffee-talk.net.

15. Changes to this policy

We will update this policy as the product changes. The “Last updated” date at the top always reflects the current version, and we will tell registered users about material changes by email or in the App.

16. Contact

CoffeeTalk Inc., 8 The Green, Suite 15796, Dover, DE 19901, United States.

Questions, requests and complaints about this policy: help@coffee-talk.net.