Privacy Policy
Last updated: 8 September 2026
The short version: Pucksmith is local-first. Your bags, shots, brew log, equipment, notes and photos stay on your device. There is no account system and no server of ours that stores what you log.
What we collect
Pucksmith has no sign-up and no user account. We do not collect your name, email address, contacts, or any of the content you record in the app. Your coffee bags, shots, ratings, tasting notes, equipment and bag photos are written to a database file on your own device and stay there unless you choose to export or back them up yourself.
We run no advertising, no usage-analytics or tracking SDK, and no tracking pixels. The only technical data that leaves the app is the diagnostics described below, and you can turn those off. We do not sell or rent data to anyone, because we do not hold it.
Reading a label (on-device)
When you photograph a coffee bag, the text is recognised entirely on your device — Apple Vision on iPhone, iPad and Mac, and Google ML Kit on Android. The photograph is not uploaded, and the recognised text is not sent anywhere. The picture is stored locally and belongs to the bag you attached it to.
Scanning a barcode (one third-party lookup)
This is the only feature that sends anything off your device, and only when you use it. If you scan or type a barcode, Pucksmith asks the Open Food Facts open database whether it knows that product. What is sent is the barcode number and an identifying header naming the app, its version and our support address — nothing about you, your device or the rest of your log.
Open Food Facts is an independent, non-profit open database with its own privacy policy. If it has never seen the bag, nothing happens and the form simply opens empty. Product data returned by that lookup is made available under the Open Database Licence, and bags created this way are marked in the app as having come from it.
Diagnostics (on by default, and you can turn them off)
To find and fix crashes and slowdowns, the app sends anonymous diagnostics. This is on by default; you can turn it off at any time from the app's Diagnostics screen, and turning it off stops all of it.
What is sent: the app and its version, your platform (e.g. iOS / macOS / Android) and OS version, the device model, and the error type, message and stack trace when something goes wrong. Since September 2026 the app also sends a small sample of app-start and screen timings, anonymous session health (whether a session ended in a crash), technical logs and counters written by the app itself, the on-screen widget layout at the moment of an error, and on Apple devices a small sample of performance profiles. Screenshots and session replay are off. It includes no device identifier, no user identifier, and none of the content you logged: no bag names, notes, photographs or shot data.
Reports go to two recipients, both controlled by that single toggle:
- A Cloudflare Worker operated by Trueframe Digital — receives the crash report only; your IP address is discarded at ingestion and never stored.
- Sentry (Functional Software, Inc.), running in the EU / Frankfurt region — receives everything listed above, for crash and performance diagnostics.
When diagnostics are off, neither recipient receives anything.
Backups and exports (you choose, every time)
Backup and export are free and entirely under your control. Nothing is backed up automatically and nothing is uploaded in the background.
- iCloud Drive on Apple devices — the file goes to your iCloud account, under your Apple ID. We have no access to it.
- A file you choose on any platform — saved wherever you point it, including a folder, another drive or a service you already use.
- CSV and JSON exports of your own records, any time.
Once a backup leaves the app it is covered by whatever service or storage you sent it to, not by this policy.
Purchases
Pucksmith Pro is a one-time purchase handled entirely by the App Store, Mac App Store, Google Play or the Microsoft Store, depending on where you bought it. Those stores process the payment; we never see your card details, billing address or store account. On iOS, iPadOS, macOS and Android, purchase status is managed through RevenueCat, which records your purchase against an anonymous identifier (no name, no email) so the app can restore it across your devices. Details are in the RevenueCat privacy policy. On Windows the purchase is handled by the Microsoft Store alone, and the app records only whether it is unlocked.
Camera and photo access
The camera is used only when you point it at a bag to read a label or scan a barcode. Photo-library access is used only when you pick an existing picture. The app never opens the camera on its own, and declining either permission leaves everything else working — you can always type a bag in by hand.
Data sharing
We do not share your data, because we do not have it. The only outbound connections the app makes are the optional barcode lookup, optional crash reports, store/RevenueCat purchase processing, and a backup you explicitly ask for.
Your control & deletion
Everything is on your device, so you are in control of all of it. Delete a bag, a shot or a photo in the app and it is gone. Uninstalling Pucksmith removes its database from your device. If you made backups or exports, delete those copies wherever you put them. There is nothing for you to request from us, because there is no account and no server-side copy.
Children
Pucksmith is a tool for brewing coffee and is not directed at children, and we do not knowingly collect anything from anyone.
Changes
If this policy changes, we will update this page and the “last updated” date above.
Contact
Questions about this policy? Email [email protected].