← cuppa

Privacy Policy

last updated 16 August 2026

This Privacy Policy explains what personal data Cuppa collects, why, and how it's used. Oliver Blowers is the data controller responsible for your data under UK GDPR. If you have questions, email hello@cuppasocial.com.

1. What we collect

  • Account data: your email address and username.
  • Content: posts, comments, images, and likes you create.
  • Social settings: your close friends list and notification history.
  • Preferences: your email digest settings (on/off, frequency).
  • Push notifications: if you enable them, a browser-generated subscription endpoint and encryption keys — not readable by us, only used to route notifications through your browser's push service.
  • Billing data: your Stripe customer ID, subscription status, and trial/renewal dates. We never see or store your card number — Stripe collects that directly.

2. How we use it

  • To create and run your account, and show your posts, comments, and notifications to the right people.
  • To process your subscription payments and manage billing, via Stripe.
  • To send you email digests, if you’ve opted in, and essential account or billing emails (e.g. payment failed) via Resend.
  • To send push notifications, if you’ve enabled them.
  • To keep the Service secure and prevent abuse.

Our legal bases are: performing our contract with you (account, content, billing), your consent (optional email digests and push notifications), and our legitimate interest in keeping the Service secure.

3. Who we share it with

We use a small number of service providers ("subprocessors") to run Cuppa:

  • Supabase — hosts our database, authentication, and image storage.
  • Stripe — processes payments and stores your card details directly; we only receive a customer ID and subscription status back.
  • Resend — delivers digest and account emails on our behalf.
  • Your browser's push service (e.g. Apple, Google, or Mozilla) — routes push notifications to your device, if enabled.

We don't sell your data, and we don't share it with anyone for advertising purposes. Some of these providers may process data outside the UK/EEA; where they do, they rely on standard contractual clauses or equivalent safeguards.

4. Cookies

We use one essential cookie to keep you signed in (set by Supabase Auth). We don't use any third-party advertising or analytics cookies.

5. How long we keep it

We keep your account data for as long as your account is active. If you delete your account, we delete your posts, comments, and profile within 30 days, except where we're required to keep billing records for longer (UK tax law requires us to retain financial records for up to 6 years).

6. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data.
  • Object to or restrict certain processing.
  • Receive your data in a portable format.

To exercise any of these, email hello@cuppasocial.com. You can also complain to the UK Information Commissioner's Office (ico.org.uk) if you're unhappy with how we've handled your data.

7. Children

Cuppa isn't intended for anyone under 16, and we don't knowingly collect data from children under that age.

8. Changes to this policy

If we make material changes to this policy, we'll notify you by email or in-app before they take effect.

terms of serviceprivacy policy