Privacy Policy

Last updated: 20 July 2026 Effective date: 10 May 2026


1. Introduction

Chintha Sai Teja Reddy, an individual proprietor trading as Studio Twenty Three ("we", "our", "us"), operates the Qoffee mobile application (the "App"), a daily reading and podcast experience. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over your data.

By installing or using Qoffee, you agree to the practices described here. If you do not agree, please do not use the App.

This policy applies to the Qoffee mobile app on Android and iOS, the website at getqoffee.com, and any related services we provide.

2. Information we collect

2.1 Information you provide

2.2 Information collected automatically

2.3 Information we do not collect

3. How we use your information

PurposeLawful basis (DPDP / GDPR)
Authenticate you and keep you signed inPerformance of contract
Curate your For You feed and reading statsPerformance of contract
Process subscription purchases and renewalsPerformance of contract
Send you the daily briefing push notificationConsent (you can disable in Settings)
Detect crashes and improve stabilityLegitimate interest
Render contextual ads in the free tierLegitimate interest
Respond to support requestsPerformance of contract
Comply with legal obligationsLegal compliance

4. Who we share your information with

We share data only with the service providers required to operate the App:

ProviderWhat they receiveWhy
Google Firebase (Auth, Analytics, Cloud Messaging, installation identifiers)Account email, Firebase user ID, device identifiers, app events, push tokensAuthentication, analytics, push notifications, install identifiers
Google Sign-InGoogle account email, display name, profile pictureAccount sign-in
Sign in with AppleApple user identifier, email and name when sharedAccount sign-in on Apple platforms
Supabase Postgres and StorageAccount data, bookmarks, reading history, offline article links, media filesPrimary application database and media storage
RevenueCatPseudonymous user ID, subscription state, store transaction metadataSubscription management
Google Play BillingAndroid purchase tokens and transaction statusAndroid payment processing
Apple App StoreiOS purchase and renewal status through RevenueCatiOS payment processing
Google AdMobGAID on Android; app instance, device, ad request, and SKAdNetwork attribution data on iOSNative feed ads in the free tier
RailwayServer-side request metadataBackend hosting
SentryCrash/error diagnostics, stack traces, app/backend metadata, request IDs, and backend user ID context for authenticated server errorsReliability and debugging
Google Vertex AI/Gemini, Exa Search, and Google Search groundingPublic source material, source URLs, article text, and editorial promptsSeparate editorial research and drafting workflow, not the production app API; your personal account data is not sent to these tools

We do not authorise these providers to use your information for any purpose other than delivering Qoffee's service to you.

5. International data transfers

Some of our service providers are located outside India. When we transfer your data internationally, we rely on the standard contractual safeguards required under DPDP and GDPR, including data processing agreements with each provider.

6. How long we keep your data

Data typeRetention period
Account profile (email, display name)For as long as your account is active. Deleted within 30 days of account deletion.
Reading and listening historyFor as long as your account is active. Removed from active systems after account deletion, except for backups or records we must retain.
BookmarksUntil you remove them, or 30 days after account deletion.
Subscription and payment recordsQoffee subscription cache and user links are removed on account deletion. Apple, Google, and RevenueCat may retain transaction records under their own legal, tax, accounting, and anti-fraud obligations.
Crash logs, diagnostics, and analytics eventsProvider/configured retention. We may keep aggregate or de-identified analytics.
FCM push tokenRemoved when you sign out or delete your account. Tokens not refreshed for 90 days are cleaned up as inactive.

7. Your rights

Depending on where you live, you have the following rights:

To exercise any of these rights, email support@getqoffee.com. We respond within 30 days.

8. Children

Qoffee is rated 13+ and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us and we will delete it.

9. Security

We protect your data with industry-standard measures including TLS encryption in transit, provider-managed encryption at rest, principle-of-least-privilege access controls for our team, and Firebase App Check to deter abuse. No system is perfectly secure; if you discover a vulnerability, please contact us at support@getqoffee.com.

10. Third-party services

The App may contain links to external websites (e.g., publishers we cite), the Google Play Store, or the Apple App Store. We are not responsible for the privacy practices of third-party services. Please review their privacy policies separately.

11. Advertising

The free tier of Qoffee shows native ads inside the feed via Google AdMob. Qoffee configures native ad requests as non-personalized at launch.

Premium subscribers do not see ads in the App. After premium status is known, the app does not initialize the Mobile Ads SDK for premium users.

On Android, AdMob may receive the Google Advertising ID (GAID). You can reset or limit the GAID from Android Privacy or Ads settings.

On iOS, Qoffee does not request App Tracking Transparency permission or IDFA access for launch. AdMob uses non-personalized ad requests and Apple's SKAdNetwork attribution where applicable. You can manage Apple advertising and privacy controls from iOS Privacy & Security settings.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you in the App and update the "Last updated" date at the top. Your continued use of the App after the change takes effect constitutes acceptance of the updated policy.

13. Contact us

For privacy questions, requests, or complaints:

If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Board of India under the DPDP Act, or with your local supervisory authority under the GDPR.