Privacy Policy
Last updated: May 30, 2026
This Privacy Policy explains how VAST FLOW ("we", "us") handles information in connection with the website trackcaffeine.com (the "Site") and the iOS application CoffeeLog (the "App"). It applies to both. By using the Site or the App you agree to this Policy.
1. Who we are
The data controller is VAST FLOW. For any privacy question or request, contact us at [email protected].
2. Scope
This Policy covers the CoffeeLog iOS app and the TrackCaffeine website. CoffeeLog is a caffeine-tracking app: you log drinks and set a profile (such as body weight, caffeine half-life and a sleep goal). CoffeeLog does not use your camera, does not take photos, and does not send your data to any third-party AI service.
3. App data stays on your device
Your drink log and profile are stored locally on your device. There is no account and no sign-up, and this information is not transmitted to our servers. If you delete the App, this data is removed with it. You can also clear entries within the App at any time.
4. Apple Health (HealthKit)
With your explicit permission, CoffeeLog can write dietary caffeine to Apple Health and read sleep data to help you see how caffeine relates to your rest. Health data is used only to provide these in-app features. It is never sold, never used for advertising, and never shared with third parties, and it is processed on your device. You can revoke Health permissions at any time in the iOS Settings app, and we do not receive Health data on our servers.
5. Subscriptions (RevenueCat)
CoffeeLog offers a free tier and an optional paid subscription. Subscription status and an anonymous identifier are processed by RevenueCat, our subscription-management provider, and by Apple. Your actual payment details are handled solely by Apple and are never seen by us. See the RevenueCat Privacy Policy.
6. Analytics and diagnostics (Firebase)
The App uses Google Firebase for anonymized usage analytics and crash diagnostics — for example, a device/installation identifier and crash reports — to keep the App stable and improve it. This data does not identify you personally. We do not use App Tracking Transparency tracking and do not track you across other companies' apps or websites. See the Firebase Privacy and Google Privacy policies.
7. Website data
The Site uses privacy-respecting analytics (such as Google Analytics 4 and Microsoft Clarity) to understand aggregate usage — pages viewed, approximate region, device type and similar. These tools may set cookies and process truncated IP addresses. We use this only to improve the Site.
8. How we use information
We use the limited information above to operate and improve the Site and App, provide subscription features, maintain stability and security, and respond to your requests. We do not sell your personal data.
9. Third parties we rely on
- Apple — app distribution, in-app purchases, HealthKit.
- RevenueCat — subscription management.
- Google / Firebase — app analytics and crash diagnostics.
- Google Analytics — website analytics.
- Microsoft Clarity — website usage insights.
- Hetzner — website hosting and delivery.
This is the full list of categories of third parties that receive data through normal operation.
10. Cookies and consent
The Site uses cookies for analytics. Where required (for example, in the EU/UK under GDPR), we ask for your consent before setting non-essential cookies, and you can withdraw it at any time through your browser settings.
11. Data retention and deletion
App log and profile data live on your device until you delete them or remove the App. Aggregated website and app analytics are retained only as long as needed for the purposes above and then deleted or anonymized. To request deletion of any data associated with you, email [email protected].
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, object to or restrict processing, and to data portability (GDPR), and rights to know, delete and opt out of the "sale" of personal information (CCPA). We do not sell personal information. To exercise any right, email [email protected] and we will respond as required by law.
13. Children
The Site and App are not directed to children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
14. International transfers
Our service providers may process data in countries other than yours. Where required, such transfers are covered by appropriate safeguards (for example, Standard Contractual Clauses).
15. Health and medical disclaimer
TrackCaffeine and CoffeeLog provide general information and estimates about caffeine. They are not medical advice and are not a substitute for professional care. Caffeine values are estimates, not exact measurements.
16. Changes to this Policy
We may update this Policy from time to time. We will revise the "last updated" date above and, for material changes, provide a more prominent notice. Questions: [email protected].
What exactly does the website collect?
The Site collects only limited session analytics via Microsoft Clarity and standard aggregate analytics and sets cookies or local storage where needed to support those analytics and site features. No user accounts are created on the Site, there are no advertising networks embedded, and we do not sell personal data.
Microsoft Clarity is a session analytics service used to measure how people interact with pages so we can improve navigation and content. This Site does not collect contact form submissions, payment details, or any account credentials because there are no Site accounts to log in to.
Fact: Microsoft Clarity and other analytics help identify broken pages, mobile layout issues, and which internal links such as the dataset, the caffeine calculator and the about page are most visited, enabling prioritization of fixes. Caveat: when you follow links to third-party sites (for example a source listed on the Site), that third-party may collect its own analytics independently.
What does Microsoft Clarity capture and what does it not capture?
Clarity captures anonymized session events such as pages visited, device type, browser, clicks, scrolls and session recordings that represent the visual interaction on a page; it may also process truncated IP addresses. Clarity does not provide us with your full IP address, your payment card details, or the contents of encrypted fields that you type into secure external services.
Clarity is a tool for session analytics and heatmap-style visualizations, not a personal profile repository. Mechanism: Clarity aggregates client-side events sent from your browser and associates them with a session identifier; we use that aggregated information only to fix usability problems and to improve pages like the drink index and the comparison tool.
Caveat: recordings or event streams may capture anything visible on a page at the time of recording, so avoid typing secrets into web forms while recording is active; the Site does not include sign-in forms so typical sensitive fields are not present here.
What does the CoffeeLog iOS app store and where?
CoffeeLog stores your drink log entries and profile data locally on the device and does not create an account or send your drink history to VAST FLOW servers. There is no server-side log of what you drink maintained by us.
CoffeeLog is a local-first app that keeps user-entered logs and settings on the device only, and those items remain on the device until you delete the App or clear them inside the App. Mechanism: the App reads and writes to device-local storage and, where applicable, to system-managed analytics providers for anonymized diagnostics described elsewhere.
Fact: subscription status is handled by RevenueCat and Apple and those services see an anonymous identifier and payment confirmation; we never receive your payment card details. Caveat: deleting the App removes locally stored entries unless you have separately exported them through iOS tools you control.
What happens if I enable Apple Health integration?
If you grant permission, CoffeeLog can write caffeine as dietary data and read sleep data from Apple Health to show in-app correlations between caffeine intake and sleep. Apple Health is the iOS HealthKit framework that centralizes health-related data on your device.
Mechanism: the App uses HealthKit permissions you explicitly approve in iOS, and those data transfers occur on the device; we do not receive Apple Health data on our servers. Caveat: you can revoke Health permissions at any time in the iOS Settings app and Health data access will stop immediately for the App.
Fact: Health data written by the App to Apple Health remains governed by Apple’s Health privacy controls; if you want to remove entries from Health you can do so from within the Apple Health app itself or revoke write access for CoffeeLog.
How long is anything kept?
App log and profile data remain on your device until you delete them or remove the App; we do not retain a server-side copy of your drink log. Aggregated analytics data used to improve the Site and App are retained only as long as necessary to diagnose issues and make improvements, after which they are deleted or anonymized.
Mechanism: device-stored data follows your device backup and deletion behavior; analytics providers retain aggregated records under their own policies and we limit our storage and use to the minimum needed to operate the Site and App. Caveat: because the App does not create an account, deletion requests for per-device App data are typically handled by you deleting the App or clearing entries within the App itself.
Fact: our open dataset is licensed under CC BY 4.0 and the dataset licensing and distribution are permanent as described on the CC BY 4.0 page; dataset copies you download are subject to that license.
How do I exercise GDPR and CCPA rights and what should I expect?
To exercise rights under GDPR or CCPA, contact support at [email protected] with the details of your request; we will acknowledge receipt and proceed as required by the applicable law. GDPR is the European Union’s General Data Protection Regulation and CCPA is the California Consumer Privacy Act.
Mechanism: after receiving a verifiable request we will identify whether the data we control is personal data and whether it is subject to deletion, correction, access, or portability; because there are no Site accounts and the App stores data locally, many requests will be procedural (for analytics logs we can request deletion from providers where applicable). Caveat: where applicable law allows us to retain limited records for legal compliance, we will notify you of any such retention and the legal basis.
Fact: we do not sell personal information, so CCPA requests to opt out of sale are acknowledged and the Site has no sale to disable; for access or deletion requests please use the contact page or email support.
What cookies and local storage does the Site use, including the theme preference?
The Site uses cookies and browser local storage to support analytics and to remember lightweight preferences such as the visual theme you select. A cookie is a small data file stored by your browser and local storage is a browser-managed key/value store for larger or persistent preferences.
Mechanism: theme preference is stored in local storage so the Site can present your preferred light or dark theme immediately on return visits; analytics cookies are set only where required under regional laws after you give consent. Caveat: if you clear your browser storage or block cookies, the theme preference and any consent choices will be lost and must be reselected.
Fact: you can manage or delete cookies and local storage through your browser settings; see browser documentation and use built-in privacy controls rather than relying on the Site to remove locally stored items for you.
Do you collect children's data?
The Site and App are not intended for children under the minimum legal age and we do not knowingly collect personal data from children. If we learn that we have received data from a child, we will take steps to remove it.
Mechanism: because the App stores logs locally and the Site does not create accounts, there are structural limits to any collection of a child’s data by us, but we will promptly delete any child data brought to our attention. Caveat: parents or guardians who discover a child’s data should contact [email protected] so we can remove it.
How will you announce policy changes?
We will update the Policy text on this page and change the visible "last updated" date in the header for any revision; for material changes we will also post a clear notice on the Site. Because the Site does not require accounts, announcements are made on-site and via the Site’s contact channels rather than by automated email to users.
Mechanism: material policy changes will be marked and explained on the Site and archived versions will be available on request; for corrections or questions about a change you can use the contact form or email support. Caveat: if you rely on the App, please check this page regularly or follow links from the about page and terms of use to see the latest policy text.
Additional resources and links: our open dataset is available at /dataset/ under a CC BY 4.0 license (license text), and for context on recommended daily limits you can refer to the FDA guidance that cites 400 mg/day for healthy adults (FDA). For sleep-related research cited on this Site, see Drake et al. 2013 on caffeine and sleep (Drake et al. 2013).
Internal links you may find useful for tools and reference include Latest cup before bed, Safe daily limit, Caffeine half-life calculator, and the full drink index, which together explain how the Site and App present caffeine estimates and how you can use them responsibly.