Privacy

Roastbook privacy policy

Roastbook is a coffee journal that lives on your device. This page explains exactly what it stores, what can leave your device, and when.

Last updated .

Roastbook is made by Merriment Labs, an independent app studio run by Jesse Johnston (“we”, “us”). This policy applies to the Roastbook app for Android phones and tablets.

The short version

Your coffee journal stays on your device. Roastbook has no accounts, no ads, no analytics, and no servers of ours. We, the developer, receive nothing from the app.

Your photos and journal leave your device only in these cases: you add your own Gemini API key, open a link, save photos to your photo library, or back up (through your device’s backup setting or to a folder you choose). Separately, Google’s on-device reading components send Google diagnostic and usage metrics, which do not include your photos or text. Each case is explained below.

What stays on your device

Roastbook keeps everything in its private app storage on your device:

  • Photos you take or pick for each coffee (resized copies of the originals, plus a square crop and a small thumbnail of the main photo).
  • Details read from the bag or typed by you: roaster, coffee name, origin, process, tasting notes, descriptions, and similar fields.
  • Your ratings, notes, buy-again flags, where you bought the coffee, and the price if you enter it.
  • Reminder times you choose, and your app settings.
  • Colors sampled from the main photo, used to tint your journal.

Other apps cannot read this storage. Nothing here is sent anywhere unless you use one of the optional features below.

Permissions

PermissionWhy Roastbook asks
CameraTo photograph coffee bags inside the app. You can pick existing photos instead and never grant it.
NotificationsTo deliver the rating reminders you ask for (at most two per coffee: the reminder you choose when you add it, and one “second look” a few days after you first rate it), and to show the progress of the optional on-device reader download.
Run at startupTo put your scheduled reminders back in place after the device restarts.
Foreground service (data sync), keep awake, network stateTo run the optional on-device reader download and scheduled backups reliably, and to wait for Wi-Fi when you ask it to. These run only for those tasks.
On-device AI serviceTo use Gemini Nano through Android’s AICore service, on devices that have it. It runs on the device.
InternetFor your own Gemini API key if you add one, to download the optional on-device reader if you choose to, and for the diagnostic and usage metrics that Google’s ML Kit components send (described below). The journal itself works offline.

Reading the bag on your device

Roastbook reads bag text with Google’s ML Kit (text recognition and subject segmentation, for the auto-crop) and, on devices that support it, Gemini Nano through Android’s on-device AI service. Your photos and the text read from them are processed on your device and are not sent to Google or to us by these features.

Google provides these components through Google Play services, which may download or update the models they use. According to Google’s ML Kit data disclosure, ML Kit also sends Google diagnostic and usage information such as device model, Android version, app package name and version, performance measurements, and API settings. Google states this does not include the images or text being processed. We do not receive this information.

The optional on-device reader

On devices without a built-in AI model, Settings offers an optional on-device reader: an open AI model (Google’s Gemma) that you can choose to download. The download comes from Hugging Face, which receives the request, including your IP address, under its own privacy policy. After that, the model runs entirely on your device, and your photos and text are not sent anywhere. The model file is not included in any backup. You can delete it in Settings at any time.

Your own Gemini API key (optional)

Roastbook works without any key. If you choose to paste your own Google Gemini API key into Settings, two extra features turn on, and both send data directly from your device to Google’s Gemini API under your key:

  • Cloud reading, as a fallback. When on-device reading is unavailable or can’t finish, Roastbook sends the coffee’s photos (as freshly encoded images) and a prompt containing the text already read from them, and gets the extracted details back.
  • Roaster lookup. Roastbook sends the roaster’s name and the coffee’s name, asking Gemini for the roaster’s website, the product page, and the roaster’s city, using Google Search grounding when your key allows it. It runs after a coffee is read, and again whenever you tap to look it up.

These requests go to Google, not to us. Google’s handling of them is governed by the Gemini API Additional Terms of Service and Google’s Privacy Policy. Please read them: on Google’s unpaid tier, Google says it may use submitted content and responses to improve its products and that human reviewers may read them. Paid-tier usage is handled differently. Which tier applies depends on how your key’s Google Cloud project is set up.

Your key is encrypted on your device with a key held by Android’s Keystore. It is never written to logs, never included in any backup, and never sent anywhere except to Google’s Gemini API with your requests. Remove it in Settings at any time; the cloud features switch off immediately.

Roaster and product links, and the “search for this roaster” button (which opens a Google web search for the roaster and coffee name), open in your browser. The sites you visit receive what any browser visit sends them, under their own privacy policies.

Backups

Android backup

If your device’s backup setting is on (on many devices it is by default), Android can copy a snapshot of your journal database, the small thumbnails, and your app preferences to your Google account, and can restore them when you set up a new device. Full-size photos and your Gemini API key are excluded. This is Android’s own backup system, operated by Google under your account; you control it in your device’s backup settings.

Backup to a folder you choose

You can have Roastbook write backup files (your journal plus full photos) to a folder you pick, on a daily schedule and whenever you tap “Back up now”. By default Roastbook keeps the seven most recent files and removes older ones. The files go only where you point them. If that folder belongs to a cloud storage app, that provider stores the files under its own terms.

Saving squares to your photo library

An optional setting saves each coffee’s square photo to your device’s photo library. Once there, the photos are handled like any other photo on your device, including by any photo backup app you use.

How your data is protected

  • Your journal and photos sit in Roastbook’s private app storage, which Android keeps out of reach of other apps.
  • Everything Roastbook sends over the network (requests to Google’s Gemini API with your key, the optional model download) travels over encrypted HTTPS connections.
  • Your Gemini API key is encrypted with a key held by Android’s Keystore and is excluded from every backup.
  • The optional on-device reader is checked against a published checksum before it is used, so a damaged or altered download is thrown away.

How long data is kept

Your journal stays on your device until you delete it. Backup files you ask for are kept in your folder, seven by default, with older ones removed automatically. We hold no copy of anything, so there is nothing on our side to retain or delete. Data you send to Google under your own key is kept according to Google’s terms for your key.

What we receive

Nothing. Roastbook has no accounts, no analytics, no advertising, and no crash reporting, and there is no server of ours for it to talk to. We cannot see your journal, your photos, or your key. If you contact us through this website, we receive only what you choose to write; see the website privacy policy.

Deleting your data

  • Delete a single coffee in the app, and its photos go with it.
  • Clear Roastbook’s storage in Android settings, or uninstall the app, to erase everything on the device.
  • Delete any backup files from the folder you chose.
  • Manage or delete Android backups in your device’s backup settings or your Google account.
  • Remove your Gemini API key in Settings, and revoke it in Google AI Studio if you no longer want it to work anywhere.

Children

Roastbook is made for adults who enjoy coffee and is not directed at children under 13. It does not knowingly collect personal information from anyone, including children.

Changes to this policy

If Roastbook starts handling data differently, this page will be updated before that version is released, with a new date at the top. Meaningful changes will also be called out in the release notes.

Contact

Questions about privacy are welcome. Use the contact form and choose Roastbook.