fikalog Privacy Policy
fikalog (the "Service") respects your privacy. This policy explains what information the Service collects and how it is used.
1. Information we collect
1.1 Information you provide
| Type | Details |
|---|---|
| Account | Email address, username, display name, profile photo, bio |
| Posts | Photos, comments, ratings, bean name, roaster, origin, roast level, and other log entries |
| Cafe input | Visits, reviews, lists, attribute votes (power outlets, Wi-Fi, and similar) |
| Social | Follows, likes, comments, blocks |
If you use Sign in with Apple, we receive only the identifier and email address Apple provides, including Apple's private relay address if you choose it.
1.2 Information collected automatically
| Type | Details | Purpose |
|---|---|---|
| Location | Approximate current location | Finding nearby cafes and stations |
| Device | OS version, app version, device model | Diagnosing problems |
| Push token | A token identifying your device | Delivering like and comment notifications |
| Usage | Screen navigation, context when errors occur | Quality improvement |
| Purchases | Subscription status and expiry | Providing Premium features |
About location: Location is used only to find nearby cafes and stations. It is not continuously stored or used to track you. You can revoke permission at any time in iOS Settings.
1.3 What we do not collect
- Payment card details — these are handled by Apple and never reach the Service
- Your contacts, calendar, or entire photo library — only the photos you select when posting
2. How we use information
- To provide, maintain, and improve the Service
- To generate core features such as your feed, statistics, and badges
- To deliver Premium features and manage subscription status
- To investigate bugs and analyse crashes
- To detect and prevent abuse, spam, and breaches of the Terms
- To respond to your enquiries
- To comply with legal obligations
3. Third-party services
The Service relies on the providers below. Their privacy policies also apply.
| Provider | Role | What they receive |
|---|---|---|
| Supabase | Database and authentication | Account information, posts |
| Cloudflare R2 | Image storage | Posted photos |
| Apple | Billing, sign-in, notifications | Purchase information, Apple ID identifier |
| RevenueCat | Subscription management | Purchase information, pseudonymous user ID |
| Google Places | Cafe data | Search terms, approximate location |
| Sentry | Crash and error monitoring | Device information, error context |
Advertising
The Service does not currently serve advertising. If that changes we will update this policy and give notice in the app beforehand. Should we use the advertising identifier (IDFA) for personalised ads, we will request permission through iOS App Tracking Transparency. Premium subscribers do not see advertising.
4. Sharing with third parties
We do not share your personal information with third parties except:
- Where required by law
- Where necessary to protect someone's life, safety, or property and consent cannot reasonably be obtained
- With the processors listed in section 3, limited to what is needed to run the Service
5. Information visible to others
fikalog is a social service. The following is visible to other users — please consider this before posting.
- Username, display name, profile photo, bio
- Photos, comments, ratings, and the cafes you have visited
- Follows and followers, likes, comments
- Any statistics you choose to pin to your profile
Your email address, precise location, and purchase information are never shown to other users.
6. Where data is stored
Data is stored on Supabase and Cloudflare infrastructure, which may be located outside your country of residence, including outside Japan. By using the Service you consent to this transfer.
7. Retention
- Account information and posts: for as long as the account exists
- On account deletion: posts and photos are deleted promptly
- Error logs: up to 90 days
8. Your choices
- Delete a post — from the menu on each post
- Delete your account — Settings → Delete account. Related data (posts, photos, lists, follow relationships) is deleted with it
- Revoke location access — iOS Settings → fikalog
- Turn off notifications — in the app's Settings or in iOS Settings
For access, correction, or deletion requests, contact us at the address below.
9. Children's privacy
The Service is not directed at children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly.
10. Security
We use encrypted transport (HTTPS), row-level security for access control, and the system Keychain for credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Changes to this policy
We may update this policy. Material changes will be announced in the app or on this page before taking effect.