Privacy policy
Coffee Quest is an app for finding hidden-gem cafes and rating them. This policy explains exactly what the app collects, what it doesn't, and why. It describes the app as it actually works — not a generic template.
The short version: there is no named account or sign-up, we never ask for your email or password, and we don't track you, advertise to you, or sell anything about you. The app automatically creates an anonymous identity so one person cannot cast unlimited ratings. Most of what you do in the app never leaves your phone at all.
1. Who we are
Coffee Quest ("we", "us") is operated by Latitude 34 Media Group, based in Australia.
Questions, requests, or complaints: privacy@coffeequest.cafe
2. What stays on your phone
The following is stored in the app's private storage on your device. We cannot see it, and the app's clear-local-data control removes it:
- Your case notes — the private notes you write about a cafe
- Your approved list — the cafes you've bookmarked
- A local copy of your own ratings, as shown back to you in the app
- Your filter preferences and last suburb or city search
- Your optional display name
An anonymous user ID and refresh token are stored separately in protected device storage so the app can maintain the same anonymous identity. On iOS, they are held in the non-migrating Keychain; on Android, they are encrypted with a non-exportable Android Keystore key and excluded from app backups. See section 7 for deleting the associated server-side data.
3. What the app does send
Location — requested when the iPhone app opens
On iPhone, Coffee Quest asks for foreground location permission when the app opens. If you grant permission, it requests one location fix to find cafes near you and show distances. You control whether iOS gives the app your Precise Location or a reduced-accuracy location in Settings. On Android, location is requested only when you choose a location search, and the app requests approximate location only. Neither app accesses your location in the background.
The coordinates supplied by your phone are sent over HTTPS to our shared Places service so it can look up cafes near you. The service passes the search location to Google Places (see section 5). Search results are cached against a coordinate rounded to two decimal places — a grid of roughly one kilometre — and are treated as stale after about 12 hours. The cache is not linked to your anonymous user ID.
The app keeps the current device location only in memory for the active app session. It does not write that exact location to app storage or backups, and removes location values saved by older versions. Your exact device fix therefore does not survive an app relaunch. A suburb or city that you type manually is retained so the app can restore that chosen search area.
You can decline the permission, or search by suburb or city name instead — the app works either way.
An anonymous identity, with your ratings
The first time you open the app, our authentication service automatically
creates an anonymous identity and issues a random user
identifier (for example,
f47ac10b-58cc-4372-a567-0e02b2c3d479). This happens without an
email address, password, name, or sign-up screen. The identifier is not
derived from your phone's hardware or advertising ID and does not tell us
who you are. Short-lived access credentials verify requests; the refresh
token and user ID are held in protected device storage as described above.
We describe it as pseudonymous rather than anonymous, because it is stored alongside your ratings and is consistent over time. That is the correct term under the GDPR, and it is why you can ask us to delete everything filed under it (see section 7).
When you rate a cafe, the app sends a signed anonymous session to our Judge service. The service verifies it and stores: your pseudonymous user ID, which cafe, your score (1–5), and the time. We use the ID to make sure each anonymous identity counts once per cafe, so ratings cannot be stacked to inflate a score. If you re-rate a cafe, your earlier rating is replaced.
Ratings are combined into the public average shown as "Quests say …". Individual ratings are never displayed to other users.
Cafes you judge from the discovery list
When you rate a cafe you found through discovery (one not yet in our catalogue), that rating also nominates it. We record the cafe's public details — its name, address, Google Place ID, Google rating and review count when available — plus the optional display name described below. The nomination record is information primarily about the cafe; the signed anonymous session authorises and rate-limits the request.
The member name you choose, if you set one
The app lets you set a display name on your Quest Card. It is optional, it defaults to empty, and it is stored on your device. When you nominate a cafe by rating it from discovery, that name is sent with the cafe's details and stored as the "suggested by" credit, so it is visible to us alongside the nomination.
Please don't put your real name, email address, or anything else identifying in that field unless you're comfortable with it leaving your phone. A nickname is very much in the spirit of the thing.
Listing problems you report
If you report that a recommended venue is a chain or franchise, permanently closed, not a cafe, duplicated, or incorrectly described, the app sends a signed anonymous session to our Judge service. We store your pseudonymous user ID, the venue's public name, address and Google Place ID, the report reason, your app locale, the country and registry version when available, and any optional detail you enter. Do not include your name, contact details, or other personal information in that optional field.
Reports are visible only to our moderators. A report does not automatically change a recommendation. If evidence confirms a chain, the venue is blocked through our audited franchise registry; dismissed reports remain recorded as moderation evidence.
Technical information
Like any app that connects to the internet, our hosting provider and the image service automatically receive your IP address and basic connection details as part of delivering the request. We do not use these to build a profile of you.
4. What we never collect
To be explicit, the app does not collect, and has no ability to collect:
- Your email address, phone number, or date of birth
- Any named account, email login, password, or social sign-in
- Your contacts, photos, files, calendar, microphone, or camera
- Any location while the app is closed
- Your advertising ID, or any cross-app or cross-site tracking
The app contains no advertising, no analytics, and no crash-reporting or tracking SDKs. We do not sell, rent, or trade any data, ever.
5. Who else is involved
Two third parties are necessarily involved in running the app:
Our backend hosting provider supplies the anonymous identity service, hosts our database, and runs our server functions in a data centre in Sydney, Australia. It processes anonymous identifiers, authentication credentials, ratings, nominations, listing reports, search requests and related connection information on our behalf.
Google Places supplies cafe information — names, addresses, opening hours, and photographs. When our server searches for cafes near you, the location supplied for that search is sent to Google Places. Cafe photographs load in the app directly from Google's servers, which means Google receives your IP address when a photo is displayed. Google's handling of this data is governed by the Google Privacy Policy.
We may also disclose information if required by Australian law.
6. How long we keep things
The anonymous identity, its user ID, ratings, cafe nomination records and pending or reviewed listing reports are kept for as long as the app operates, because they enforce fair voting and form the community scores and rankings that make the app work. The app keeps its refresh token in protected device storage until it is replaced or removed by the operating system. Search results and opening-hours cache entries are treated as stale after about 12 hours; operational records may remain until refreshed or deleted.
The app's exact device-location fix lasts only for the current app session and is not restored after the app relaunches. Infrastructure providers may retain limited request and security logs under their own operational retention practices.
7. Your choices, deletion, and rights
- Stop sharing location — revoke the permission any time in your phone's settings (Android: Settings → Apps → Coffee Quest → Permissions; iPhone: Settings → Coffee Quest → Location). On iPhone you can also turn Precise Location off and continue with reduced accuracy. The app continues to work, including by suburb or city search.
- Erase local app data — use the app's clear-local-data control or clear the app's storage. Uninstalling removes Android app data; iOS Keychain credentials can have a separate lifecycle. In either case, use the request below to erase associated server-side records.
- Ask us about your data, or ask us to delete it — email privacy@coffeequest.cafe with your anonymous user ID (shown in the app under Quest Card → About) and we will locate and delete the ratings associated with it. We'll respond within 30 days.
Australian users may complain to the Office of the Australian Information Commissioner if unsatisfied with our response. If you are in the UK or European Economic Area, you also have rights of access, correction, erasure, restriction, and objection under the GDPR; our lawful basis for the limited data we process is our legitimate interest in operating a fair, community-rated cafe guide.
8. Children
Coffee Quest is not directed at children and we do not knowingly collect information from anyone under 13. We do not ask for age or direct contact details, so we generally cannot tell a user's age; if you believe a child's data has been submitted, contact us and we will remove it.
9. Security
All communication between the app and our servers uses encrypted HTTPS connections. Rating, nomination and listing-report writes require a signed anonymous session and pass through a rate-limited server function; the app cannot write directly to those tables. Database row-level security prevents the app from reading other users' individual ratings, and our internal tables are not reachable from the app. Secret API keys for third-party services are held on our server and are never included in the app.
No system is perfectly secure, but the safest data is the data never collected — which is why we collect so little.
10. Changes to this policy
If we change what the app collects, we'll update this policy and the "last updated" date above. Material changes will be highlighted in the app.
“Coffee Quest judges cafes, not people.”
Your next coffee could be
a little adventure.
There is no named account or sign-up, we never ask for your email or password, and we don't track you, advertise to you, or sell anything about you.The app automatically creates an anonymous identity.
Café information and photography in the app come from Google Places.
Coffee Quest is independent and has no affiliation with any café it lists.