Privacy policy

Your data,
plainly.

Last updated: May 2025

The short version

FLTRD is a small, independent app. We collect what we need to make it work, we don't sell your data, we don't run ads, and we don't share your information with anyone except the infrastructure services required to run the platform.

What we collect

Account information

When you create an account we store your email address, username (handle), and display name. You can optionally add a profile photo and bio.

Content you create

Reviews, ratings, tasting notes, recipes, photos, comments, and lists you post on FLTRD are stored in our database. This content is public by default — anyone can read it, including people without an account.

Activity

We record which beans, roasters, cafes, and users you follow, save, or interact with. This powers your personalised feed, taste recommendations, and the "People you might know" feature.

Usage analytics

We log anonymous events (e.g. "review logged", "search used") to understand how the app is used. These events include your user ID but are never shared externally and are used only to improve the product.

Push notification subscriptions

If you enable push notifications, we store your browser's push subscription endpoint. This is used only to send notifications you've opted into.

Location

If you use the "Near me" or map feature, your device's GPS coordinates are used in-session to sort nearby cafes. We never persist or log your location.

How we use it

  • To run your account and show your content in the feed
  • To personalise your Discover page and taste recommendations
  • To send notifications you've opted into (likes, comments, new beans, weekly digest)
  • To improve the app based on aggregate usage patterns
  • To send transactional emails (password reset, email confirmation) via Resend

We do not use your data for advertising, sell it to third parties, or share it with data brokers.

Third-party services

FLTRD uses the following infrastructure providers. Each processes data only as needed to deliver the service:

  • Supabase — database, authentication, and file storage (hosted in the US)
  • Vercel — hosting and edge delivery
  • Resend — transactional email (password resets, digest emails)

No analytics tools (Google Analytics, Mixpanel, etc.) are installed. Usage events go directly into our own database.

Data retention

Your account and content remain until you delete them. Deleted reviews are soft-deleted (hidden from the UI) and fully purged within 30 days. If you delete your account, all associated data is removed from our systems.

Your rights

You can:

  • Edit or delete any review, comment, or list at any time
  • Update your profile information and photo
  • Export your data — email us and we'll send a copy
  • Delete your account — this removes all your content permanently
  • Opt out of all notification types individually in your profile settings

Cookies

FLTRD uses a single session cookie managed by Supabase for authentication. No advertising or tracking cookies are set. No cookie consent banner is needed because we don't use third-party tracking.

Children

FLTRD is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a minor has created an account, contact us and we will remove it.

Changes to this policy

If we make material changes to how we handle your data, we'll note the updated date at the top of this page. Continued use of FLTRD after changes constitutes acceptance.

Contact

Questions or requests: hello@fltrd.social