Tassea
Privacy Policy
Last updated: August 27, 2026
Want to delete your account? Submit an account deletion request.
This Privacy Policy explains how Tassea ("Tassea", "we", "us", or "our") collects, uses, shares, and protects personal information when you use our website, application, and related services (collectively, the "Service").
1. Information we collect
Depending on how you use the Service, we may collect:
- Photos and reading information: photos of a coffee cup and grounds, the reading you request, and the reading results we generate.
- Account and session identifiers: a temporary Tassea account and session identifier created to provide the Service. If you choose Google Sign-In, we also receive and store your Google account subject identifier, email address, and email-verification status.
- Purchase and subscription information: purchase token, product and plan identifiers, order and subscription status, expiry, renewal, and entitlement information when you purchase through Google Play.
- Usage, device, and diagnostic information: IP address; app version, device type, operating system, locale, and timestamps; feature and network-performance information; crash reports; and diagnostic logs. Firebase Crashlytics and Firebase Performance Monitoring collect Firebase installation or Crashlytics identifiers and technical information needed to provide crash reporting and performance monitoring.
- Communications: information you send when you contact us, including a request to access or delete your information.
You can use the Service with a temporary Tassea account; Google Sign-In is optional. We do not collect marketing email lists or use advertising tracking.
2. How we use information
We use personal information to:
- provide, operate, and improve the Service and generate the reading you request;
- maintain your account, session, reading history, and access to purchased entitlements;
- keep the Service secure, prevent fraud, and troubleshoot technical issues;
- reply to your questions and handle privacy requests; and
- comply with legal obligations and enforce our terms.
We do not use your cup photos or reading content for advertising or marketing.
3. Legal bases for processing
Where data-protection laws such as the GDPR apply, we process information to perform our contract with you, pursue our legitimate interests in operating and securing the Service, comply with legal obligations, or with your consent where required. You may withdraw consent at any time; this does not affect processing already carried out before withdrawal.
4. How we share information
We may share information with:
- DigitalOcean and Amazon Web Services (AWS), which may provide cloud hosting, infrastructure, database, and photo-storage services on our behalf;
- Google, including Google Sign-In if you choose it, Google Play for purchase and subscription processing, and Firebase Crashlytics and Firebase Performance Monitoring for crash reporting and app-performance monitoring;
- OpenAI, which processes submitted cup photos and related prompts to help generate the reading you request;
- Grafana Cloud, which provides centralized application logging and may process diagnostic logs, request and IP metadata, app, user, or reading identifiers, and error details contained in those logs;
- professional advisers, regulators, law enforcement, or other parties where required by law or necessary to protect rights, safety, and security; and
- a buyer or successor in connection with a merger, financing, acquisition, or sale of company assets.
We do not sell personal information or share it for third parties’ own direct-marketing purposes.
5. Retention
We retain account and session data, uploaded photos, readings, and subscription records until you ask us to delete them or they are no longer needed to provide and secure the Service, subject to any retention required by law. To request deletion of your Tassea account and associated data, visit our account-deletion page. We may need information to verify your identity and locate the relevant account. After verification, we delete or de-identify data associated with the account in our active systems within 30 days. Remaining backup copies expire within 90 days. Diagnostic records held through Firebase and Grafana Cloud follow the retention settings configured for those services and may remain until their normal expiry where individual deletion is not available. Some purchase records may need to be retained where required by law.
6. Security
We use reasonable technical and organizational measures designed to protect personal information. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.
7. International transfers
We may process information in countries other than the country where you live, including where our service providers operate. When required, we use appropriate safeguards for international transfers of personal information.
8. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal information, and to object to certain processing. You may also have the right to withdraw consent and to complain to your local data-protection authority. To exercise a right, contact us using the details below. We may need to verify your request before responding.
9. Cookies and similar technologies
We use essential cookies, local app storage, and similar technologies needed to run the Service, including session identifiers used to keep you signed in and show your reading history. We do not currently use advertising tracking or marketing cookies. If we introduce optional analytics, advertising, or similar cookies, we will provide any notice and obtain consent required by applicable law. You can also manage browser cookies through your settings, although this may affect Service functionality.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.
11. Where we offer the Service
We currently intend to offer the Service in Turkey and selected countries in North Africa and the Middle East. This policy does not limit any privacy rights you may have under the laws that apply where you live.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the "Last updated" date. If a change is material, we will provide additional notice when required by law.
13. Contact us
For questions, requests, or complaints about this Privacy Policy, contact:
Codebase OÜ
Kuldnoka tn 6-142
10619 Tallinn, Estonia
[email protected]