Privacy Policy

Dial-In — effective September 11, 2026.

Dial-In is an espresso shot tracking app operated and published by PierDo, the developer entity named in its Google Play listing. Free Core shot logging, CSV tools, and the deterministic Dial-In Coach work locally without an account. Dial-In Lab is an optional permanent local-toolkit purchase. Remote Coach is optional and is disabled unless the app has verified Production service bindings.

Local data

Espresso shot logs, bean profiles, equipment settings, preferences, deterministic Coach state, and Coach results are stored locally on your device using IndexedDB. If used, Dial-In Lab also stores recipe revisions, controlled-session pull snapshots and recaps, optional temperature/pressure/preinfusion/basket/puck-prep/water/roast/open-date/gear fields, multiple gear and maintenance profiles, and the last generated consistency/freshness report locally in IndexedDB. The free local Coach and every Free Core feature work without Google, RevenueCat, an account, or a remote service.

Lab consistency and freshness outputs are descriptive local summaries, not scientific or safety measurements. When active Lab ownership is later refunded or revoked, existing Lab artifacts remain readable and exportable, but the app blocks new premium creation/editing and does not recompute new Lab analytics from later Free Core shots.

Dial-In excludes all app data from Android cloud backup and device-to-device transfer. Deleted local records, Lab artifacts, scoped Remote Coach sessions, deletion tombstones, and pending purchase/request state are therefore not restored through Android backup or migration.

Optional Remote Coach

Remote Coach is not chat. When you explicitly request a Remote Coach plan, data leaves the device for the dedicated Worker as a bounded decision envelope containing numeric dose and yield, whether yield is adjustable, bounded grinder controls (whether it is adjustable, its direction convention, and its numeric current/minimum/maximum index when available), closed taste/equipment fact IDs, a random request ID, and four or six app-approved option IDs/definitions. The Worker sends Fireworks AI's MiniMax M3 only the closed fact IDs and option IDs/definitions—not the numeric dose/yield or bounded grinder context. The model may choose only one offered option. Dial-In computes targets, applies numeric and equipment safety limits, and reviews the result locally.

Remote Coach does not send notes, bean/roaster/origin names, CSV exports, full shot history, contacts, location, direct hardware identifiers, arbitrary prompt text, rendered numeric targets, or model prose. The current Production contract routes the bounded envelope through a dedicated Cloudflare Worker to Fireworks AI's MiniMax M3 model. If the service is unavailable, invalid, unsafe, abstains, or is not configured, Dial-In keeps the free local Coach plan and makes no local entitlement grant.

Production Remote Coach requests require explicit Google sign-in and an available account balance. Dial-In does not create or send an anonymous install proof. The Worker—not the app—owns access, request reservations, acknowledgement, and remaining request counts.

Google sign-in and optional purchases

Google sign-in starts only when you tap Sign in and check Coach access. The app sends the Google ID token to the Worker immediately for signature, audience, subject, and nonce verification, then discards it. Depending on Google's token claims, the token may contain your Google user ID, email address, name, or profile fields. The Worker uses only the subject, does not retain the token or profile fields, and derives a stable opaque RevenueCat App User ID, so Dial-In does not give RevenueCat your Google name, email address, or profile.

The opaque ID is not the only information processed by RevenueCat. When you check Remote Coach access, use the optional Coach Pack, or discover/purchase/restore Dial-In Lab, the RevenueCat SDK and Google Play process purchase history and transaction information (including Google purchase tokens and last-seen purchase/service time), device type and operating system, and locale/currency as needed for purchase functionality, balance accounting, fraud prevention, and RevenueCat service analytics. RevenueCat does not receive Dial-In notes, bean/roaster/origin names, CSV or Lab export files, full shot history, Lab recipes/sessions/advanced fields, Google profile fields, or Remote Coach decision envelopes. Purchase history is encrypted in transit, is not processed only ephemerally, and is required only when you enter an optional commerce path.

Dial-In Lab is a separate non-consumable product, dial_in_lab_lifetime, with entitlement dial_in_lab. Its purchase and restore path does not require Google sign-in or the Remote Coach Worker. RevenueCat may create or use its normal install-scoped App User ID for that Play flow. Dial-In stores a namespaced SHA-256 binding of the current RevenueCat original App User ID with the exact product ID, schema version, and verification time; it does not persist the raw App User ID in Lab storage. A verified same-owner exact inactive/refund signal removes the cached unlock, while offline/error/unknown or a different RevenueCat owner cannot erase an established grant. An exact active restore may rebind the grant to the current Play purchase owner. Advanced shot context is stored in the local Lab record keyed by shot ID rather than in the Free Core shot record; one generation-checked local write records advanced context and a controlled-session snapshot after the core shot saves.

Dial-In Lab is a one-time local unlock, not a subscription, and includes no Remote Coach requests or AI credits. Google Play supplies the localized runtime price before purchase. The source-owned launch targets are CAD 24.99 in Canada and USD 16.99 in the United States, but the price shown by Google Play for the user's storefront is authoritative.

Ordinary Remote Coach sign-out clears the app/Google scoped session but does not remove Dial-In Lab access or data. It does not call RevenueCat logout or create a new anonymous RevenueCat customer. The next approved Coach account is bound directly to its Worker-derived custom ID.

Because Lab and Coach share one RevenueCat SDK, Dial-In serializes their purchase-owner changes. While a Lab purchase is in progress, unresolved, or awaiting explicit post-deletion restore, a new Remote Coach sign-in/account switch is blocked before Google Credential Manager or a RevenueCat owner change. If a Coach sign-in was already admitted, a new Lab flow waits for it to finish and then reads the live purchase owner. This state is used only to keep optional commerce ownership consistent; it does not link Lab access to the Coach account.

Remote Coach cloud deletion and Lab commerce share the same RevenueCat SDK/customer boundary. If a Lab purchase result is unresolved or any Lab native commerce operation is still running, Dial-In blocks Remote Coach customer deletion and Delete All Data until you use Restore / check or the operation finishes. After RevenueCat customer deletion is exactly confirmed, Dial-In detaches the RevenueCat SDK as required to avoid recreating the deleted custom customer. If that local SDK detach fails, Dial-In keeps a durable deletion fence, blocks all Lab product, purchase, and restore calls as well as Remote Coach commerce, reports deletion as pending on this device, and retries detach after restart. It does not automatically recreate a RevenueCat customer or expose Lab restore until detach succeeds.

Remote Coach deletion keeps the locally verified Lab grant and Lab artifacts. Once SDK detach succeeds, Dial-In marks that cached grant as requiring an explicit Restore Lab purchase ownership check. That user-initiated check can create/use the current install-scoped RevenueCat owner without Google sign-in, then rebind the cached grant only from exact active Play evidence. An authoritative empty restore in this explicit post-deletion state clears an old refunded grant; the user can later repeat restore with the owning Play account. A later exact inactive signal for the rebound owner also relocks Lab. Local artifacts remain readable/exportable in either relocked case.

An eligible account can sign in and check access before any purchase. The optional one-time Coach Pack adds 365 non-expiring Remote Coach requests. The app loads its localized price from Google Play through RevenueCat before opening Play. Dial-In does not bundle a price, create a local grant, or treat an uncertain purchase result as success. A pending purchase refresh stays pinned to the original opaque account to prevent an accidental duplicate purchase. If it remains unresolved for seven days, Dial-In can clear only the local purchase lock after you verify Google Play order history, explicitly confirm recovery, sign in to the same account, and receive fresh successful RevenueCat and Worker checks showing the balance is exactly unchanged. This recovery check does not start, cancel, or refund a purchase; any mismatch remains locked for support or deletion.

Google Play and RevenueCat may retain purchase, fraud, tax, or audit records under their own policies and legal obligations. Deleting Remote Coach data does not erase records those processors must legally retain.

If a Remote Coach Google Play purchase result is still unresolved when you choose deletion, Dial-In warns that deletion does not cancel or refund that transaction. It may still complete and charge through Google Play, and any Remote Coach requests it adds will be permanently forfeited by the deletion. An unresolved Dial-In Lab purchase instead blocks customer deletion until its exact Play status is checked. Cloud deletion is not a purchase-dispute or refund mechanism.

Retention and request recovery

The app stores only the bounded request, selected option ID, locally validated plan, acknowledgement status, access check, opaque scoped session, and deletion/purchase recovery state needed for correct operation. A selected plan and its acknowledgement-attempt marker are stored before the acknowledgement network call. If the balance effect is still being checked or a response was lost, the same request remains blocked for recovery/support; Dial-In does not label it uncharged or create a replacement. A committed but not-yet-delivered plan is recovered with the same request ID and cannot silently create a second charge.

The Production Worker must enforce the reviewed retention contract before activation: a generated selection awaiting acknowledgement for up to 10 minutes; a fixed, non-sliding acknowledgement-recovery record for up to 35 days after the first acknowledgement claim; completed-response replay/no-regeneration state for up to 24 hours; and opaque paid sessions for up to 15 minutes. Minimal exact acknowledgement receipts and cardinality-capped RevenueCat commerce-event, debit, and ambiguity receipts may remain for up to 90 days for idempotent billing and recovery. A pseudonymous deletion/PITR fence remains for 35 days so a stale request or a database recovery within Cloudflare's 30-day recovery window cannot restore deleted access. Production keeps no per-user application audit log. Processor logging, backups, retention controls, and model-training settings must be verified during Production provisioning; Dial-In does not claim zero retention or no training without that verification.

Data deletion and account controls

Deleting one shot, deleting all shots, or replacing shots/beans from CSV also deletes the advanced Lab fields attached to the deleted core shots. Controlled-session recaps intentionally contain their own immutable dose/yield/time/grind/taste pull snapshots, so those saved recap measurements remain after a core shot deletion and are labelled as a deleted-shot saved snapshot in Lab. Delete All Data removes those session snapshots and recaps.

After you confirm deletion, Dial-In first saves a durable account-bound deletion fence before it clears pending plans, purges local data, or contacts the Worker. The fence blocks Lab/Coach commerce and Remote Coach plan/acknowledgement calls. Delete All Data also stores a local-purge-pending marker so an interrupted purge resumes after restart, and atomically advances Lab entitlement/data generations so a late save cannot recreate cleared Lab content. If remote deletion cannot be confirmed, the app says that it is pending and retains on the device only an opaque deletion tombstone plus the valid original scoped credential needed to retry. The Worker immediately fences access and clears pending plans, acknowledgement recovery, and exact acknowledgement/commerce receipts; it retains a pseudonymous external deletion/PITR fence for 35 days. If RevenueCat still reports deletion pending, the Worker retains the minimal commerce tombstone beyond that normal fence deadline only until processor deletion can be retried and confirmed. A different Google account cannot delete or take over that pending state. Only confirmed deletion clears the app's Coach session, access cache, pending plans, purchase refresh state, and tombstone. The app retains only a non-identifying integer deletion generation so an older in-flight operation cannot recreate cleared account state; it contains no account ID, token, balance, or purchase data. Google Play, RevenueCat, or other processors may retain transaction, fraud, tax, audit, or other legally required records even after the customer and remaining request balance are deleted. Clearing app storage or uninstalling removes local Lab data and may remove its cached offline grant; Play ownership can be restored in a configured build.

You can request Remote Coach cloud deletion without reinstalling Dial-In at https://dial-in-coach-api.pierdo.net/delete-data. The page authenticates the original Google account and reports whether deletion is confirmed or pending. This route must be operational and verified before Remote Coach is activated in Production.

Optional tips

Optional tips are repeatable Google Play purchases with preset localized amounts. They add no Lab access, Coach requests or other app features. RevenueCat processes tip transactions using the same purchase data described above. A separate local record stores the product, purchase-owner identifier, pre-purchase transaction identifiers and pending status so an uncertain result cannot start a duplicate payment. Tips are separate from Coach balances and Lab ownership.

Other collection and permissions

Age audience

Dial-In is intended for adults age 18 and older and is not directed to children.

Changes and contact

We may update this policy. Material changes will update the effective date above.

Privacy questions and deletion support: pierdo.dev@gmail.com.

← Back to PierDo