Privacy Policy
Last updated: October 4, 2026
About this policy
DeCaf is operated by Tom McLaughlin, operating DeCaf as a sole proprietor. This policy describes information handled by DeCaf for iOS, Android and related services. For privacy questions or deletion requests, contact support@decaff.app.
Information handled by DeCaf
- Your entries: drink names, caffeine amounts and times; bedtime settings; daily goals and taper plans; and optional sleep check-ins, including the date, a rating from 1 to 5 or a skipped entry. Manual sleep ratings are entered by you and remain separate from optional imported sleep records described below.
- Preferences: reminders, notification history and saved drink favorites. The app also keeps data on your device.
- Your account: email address, account identifiers and authentication information. The server stores a password hash rather than your plain-text password.
- Product interaction on iOS: the iOS app sends first-party events such as screens viewed and features used, event properties, session identifiers, app version, platform and timestamps. Events may be associated with your account when you are signed in. They are not necessarily anonymous.
- Support: your email address and information you choose to include in a support message.
- Purchase information, where applicable: product, provider, transaction identifiers, dates and entitlement status. Payment providers handle payment card details.
Optional sleep import
This section describes optional Health Connect sleep import in the upcoming Android closed-test build 0.2.26 (38). Availability to eligible testers is pending; this feature is not available in the current Android 37 release. Earlier Android versions and the current iPhone testing version do not include this feature. Public store downloads are not available yet.
If you connect Health Connect, DeCaf requests read-only access to sleep records. This includes record identifiers, sleep and wake times, time-zone offsets, source app identifiers and names, and sleep stages where your source provides them. DeCaf uses these records to show sleep timing, duration and available stages alongside your caffeine entries. You can use DeCaf without connecting a health source. Your manual 1–5 sleep ratings remain separate.
Imported sleep is stored on this device for the current DeCaf account. It is excluded from app backups and is not sent to DeCaf cloud sync or analytics. DeCaf does not write sleep or caffeine records to Health Connect. These statements concern DeCaf’s imported copy; your source app and Health Connect manage their own records.
In the app’s Sleep data screen, choose Disconnect and remove imported sleep to stop importing and remove the saved imported sleep for the current account on this device. If removal fails, the app asks you to retry. This does not delete records from Health Connect or your source app, and does not itself revoke the system permission. Use Manage Health Connect access to change that permission. When DeCaf detects that sleep permission has been revoked, it hides imported records and attempts to clear the saved copy. A storage failure can leave that copy on disk. Detection requires the app to check access; revocation alone does not guarantee immediate erasure. Successful local removal is required to clear the saved copy.
Account-deletion requests
The support form stores your email address, request wording/version and request time on our DigitalOcean-hosted service so the operator can review it. It does not look up whether an account exists, send an email or delete an account. Request records remain stored until removed; they are separate from app-account records. Access to request details is restricted to an authenticated operator. Ownership must be verified before any account deletion.
Launch-notification waitlist
If you join the waitlist, we store your email address, optional platform choice, and the wording, version and time of your consent on our DigitalOcean-hosted service. The unchecked consent box asks only for a DeCaf availability notification, not general marketing. Joining does not create an app account or grant testing access. No email is sent when this form is submitted.
We store a keyed digest of the submitting network address to limit repeated waitlist and deletion requests; these website forms do not retain the raw address. Rate-limit counters older than 48 hours are removed when later requests are processed. Your email and consent record remain on the list until removed. To request removal or ask about a saved request, contact support@decaff.app. Requests are not automatically processed by this page.
How information is used
We use this information to provide tracking and account features, process optional cloud synchronization, respond to support requests, verify access to paid features where enabled, and understand and improve product use. Cloud synchronization, where available, depends on your settings and entitlement; it is not a guarantee that every local entry has been backed up. Product interaction analytics are separate from your tracking-data sync setting.
Storage and service providers
DeCaf stores app data locally and operates a self-hosted service on DigitalOcean. Connections to the production service use HTTPS. Account access is authenticated. These protections do not amount to a claim of end-to-end encryption.
Service providers process information needed to operate the service: DigitalOcean provides hosting, and Resend handles transactional account email when enabled. Apple and Google handle their respective app distribution and store services. Stripe handles web payments where those features are enabled. Apple and Google purchases are currently disabled in the beta. Your email provider also handles messages you send to support.
We do not sell your personal information or use it for advertising. Sharing needed to operate these services is different from selling data. Store and payment providers handle their own records under their privacy policies.
Your choices and deletion
You can review and edit your tracking entries in the app. Cloud sync settings, where available, let you control that feature. To request a copy of your data or ask about a stored record, email support@decaff.app; this does not imply an in-app export tool.
On iPhone, you can request account deletion in Settings → Delete Account. The upcoming Android closed-test build 0.2.26 (38) includes Settings → Delete Account; availability to eligible testers is pending. The current Android 37 release does not complete in-app account deletion. For help, use the account-deletion request form. A saved request does not confirm that an account exists or delete it. Ownership must be verified before any account deletion. Successful account deletion removes the account and its server-side tracking and sync records. Some analytics, audit and transaction records can remain after their direct database account association is removed. Retained event properties and audit details may still contain identifiers; removing the account link does not necessarily anonymize those records. Deleting an account does not itself cancel a store subscription or erase records held by a store, payment provider or an email recipient.
For questions about retained records, backups or a specific deletion request, contact support. We do not promise that all copies in every system disappear immediately.
Children’s privacy
DeCaf is not intended for users under the age of 13. We do not knowingly collect personal information from children.
Policy updates
Updates will be posted here with a revised date.