Privacy Policy
Effective date: June 26, 2026 Last updated: June 26, 2026
The app is called "Mellow" in most regions and "Qahwati" in the Gulf / Middle East region. Both names refer to the same application operated by Delphi合同会社 (Delphi LLC).
This Privacy Policy describes how Delphi合同会社 (Delphi LLC) ("we", "us", or "our") handles information when you use the Mellow mobile application ("the App"). This Privacy Policy, together with our Terms of Use, governs your use of the App.
Mellow is an independent drink discovery application and is not affiliated with, endorsed by, or connected to Starbucks Corporation.
We believe in collecting as little personal data as possible. This policy explains what we collect, why, and how it is stored.
1. Business operator information (個人情報取扱事業者)
| Item | Detail |
|---|---|
| Business name | Delphi合同会社 (Delphi LLC) |
| Representative | Felix Winkler |
| Address | EX Ebisu-Nishi Bldg. 5F, 2-8-4 Ebisu-Nishi, Shibuya-ku, Tokyo 150-0021, Japan |
| Contact | support@delphigk.com |
2. Information we collect and purposes of use (利用目的)
2.1 Information stored only on your device
The following information is stored locally on your device and is never transmitted to our servers:
- Country selection — the country you choose during onboarding
- Language preference — the language you choose during onboarding or in Settings
- Theme / seasonal preference — your appearance choice
- Favourite recipes — the list of recipes you have marked as favourite
- Liked recipes — the list of recipes you have liked
- Submission rate limit counter — a counter tracking how many recipes you have submitted this week (resets weekly, used to prevent spam)
This information is stored on your device, using the device's secure storage where available (Keychain on iOS, EncryptedSharedPreferences on Android). However, not all data types are guaranteed to be encrypted — favourites and likes may be stored in standard device storage depending on data size. This information is never sent to our servers. Clearing the app data or uninstalling the app will permanently remove it.
2.2 Information sent to our backend
Mellow uses Supabase as its database provider. The following information is sent to our Supabase backend:
| Data | Purpose of use (利用目的) | When transmitted |
|---|---|---|
| Anonymous like counts | Display aggregate recipe popularity. We do not record who liked what — only an anonymous total. | When you tap the like button |
| Community recipe submissions (name, description, ingredients, categories) | Display your recipe to other users after moderation approval | When you submit a recipe |
| Optional email address | Send you a yearly subscription coupon as a thank-you for your recipe contribution. We will never use your email for marketing, sell it, or share it with third parties. | When you submit a recipe |
| Optional recipe image | Display alongside your recipe after moderation review. Submissions with images always go through manual moderation. | When you submit a recipe |
| Recipe reports (recipe ID + reason) | Moderate community-submitted recipes. No personal information is attached to reports. | When you submit a report |
| Feedback reports (text) | Improve the App and address reported problems. No personal information is attached unless you include it in your message. | When you submit feedback |
2.3 Subscription and purchase information
Mellow offers optional in-app subscriptions and one-time recipe package purchases. All payment processing is handled entirely by Apple (App Store) or Google (Play Store). We do not collect, store, or have access to your payment details (credit card number, billing address, etc.).
Subscription status is managed by RevenueCat, a third-party subscription management service. RevenueCat receives:
- An anonymous app user ID (generated by the SDK, not linked to your personal identity)
- A device identifier (iOS IDFV — Identifier for Vendor, scoped per device and vendor, not used for cross-app advertising)
- Device attributes (OS version, app version, country code)
- Purchase receipts from Apple/Google (containing transaction data linked to your Apple ID or Google account)
RevenueCat does not receive your name or email address. See Section 5 for cross-border transfer details.
2.4 Infrastructure logging
Our backend providers (Supabase, Netlify) may transiently log IP addresses of incoming API requests for security and abuse prevention purposes. These logs are managed by the providers according to their own retention policies and are not accessed or stored by us for the purpose of identifying individual users.
2.5 Information we do not collect
We do not collect any of the following:
- Your name (unless you voluntarily put it in an email or feedback field)
- Your precise or approximate location — the country you choose during onboarding is a preference, not device-derived (GPS) location
- Your contacts
- Advertising IDs (e.g. IDFA) or cross-app tracking identifiers — we do not run ads and do not track you across other apps or websites
- Your web browsing history
We use a privacy-conscious product-analytics service (PostHog) and a crash-reporting service (Sentry), as described in Section 3. These receive only an anonymous, per-device identifier and non-identifying technical data (such as event names, OS version, and crash traces) — never your name, email, advertising ID, or cross-app tracking signals. We do not use advertising SDKs. If we materially change the third-party services we use, we will update this policy.
3. Third-party services and external data transmission (外部送信)
Mellow transmits user data to the following third-party services:
| Service | Data transmitted | Purpose | Destination country |
|---|---|---|---|
| Supabase (database & file storage) | Recipe submissions, like counts, images, feedback reports, optional email | Store and serve app content | United States (headquartered); data stored in Tokyo, Japan region |
| Netlify (serverless functions) | Recipe submissions (name, description, ingredients, optional image, optional email) routed through serverless functions | Process community recipe submissions before storage | United States |
| RevenueCat (subscription management) | Anonymous user ID, device identifier (iOS IDFV), device attributes (OS version, app version, country code), purchase receipts from Apple/Google | Manage subscription status and purchase validation | United States |
| PostHog (product analytics) | Anonymous device UUID generated by the SDK, event names, event properties (region, language, recipe identifiers, paywall triggers) | Measure aggregate usage patterns to improve the App (no individual tracking, no cross-app tracking) | United States |
| Sentry (crash + error reporting) | Error stack traces, JS error messages, native crash reports, device attributes (OS version, app version, device model), anonymous device identifier | Detect and diagnose app crashes and errors so we can fix them quickly. No screenshots, no view hierarchy, no session replay are captured. | United States |
| Expo / Apple Push (APNs) / Google FCM (push notifications) | Expo push token for your device, platform (iOS/Android), anonymous region/language, app version | Deliver opt-in push notifications about new recipes and app updates. You can disable notifications anytime in device Settings. | Expo: US; APNs: US; FCM: US |
| Apple App Store / Google Play Store | Payment information (handled entirely by Apple/Google) | Process subscription and purchase payments | United States (Apple); varies (Google) |
When you tap a link to an external website (e.g. the Privacy Policy or Terms of Use), the link opens in a secure in-app browser (Safari View Controller on iOS, Chrome Custom Tab on Android). We do not track which links you tap.
Privacy policies of our providers:
- Supabase: https://supabase.com/privacy
- Netlify: https://www.netlify.com/privacy/
- RevenueCat: https://www.revenuecat.com/privacy
- PostHog: https://posthog.com/privacy
- Sentry: https://sentry.io/privacy/
3.5 External Transmission of User Information (Disclosure under Telecommunications Business Act Art. 27-12)
Pursuant to Article 27-12 of Japan's Telecommunications Business Act (電気通信事業法), we disclose below the user-related information that is transmitted from your device to external parties when you use the App. This disclosure covers information that is not necessarily personal information — including device attributes, IP addresses, and identifiers — to the extent such information is transmitted to external parties.
| Recipient | Information transmitted | Purpose | Timing | Onward sharing | Recipient disclosure |
|---|---|---|---|---|---|
| Supabase Inc. (US) | API requests to fetch recipe data, like count updates, submission content, feedback, IP address | Deliver and store app content | On app launch and during user interactions (partly automatic) | Per recipient's policy | supabase.com/privacy |
| RevenueCat Inc. (US) | Anonymous user ID, device identifier (iOS IDFV), device attributes (OS version, app version, country code), purchase receipts from Apple/Google | Subscription management and purchase validation | On app launch and during subscription actions (automatic) | Per recipient's policy | revenuecat.com/privacy |
| Netlify Inc. (US) | Recipe submission content, images, optional email, IP address | Process community recipe submissions | Only when you submit a recipe (user-initiated) | Per recipient's policy | netlify.com/privacy |
| PostHog Inc. (US) | Anonymous device UUID, event names and their non-identifying properties (e.g. region, language, recipe identifiers, paywall triggers), device attributes (OS version, app version) | Aggregate product analytics — no cross-app tracking, no individual profiling, no session replay | On app open and during key user interactions (automatic) | Per recipient's policy | posthog.com/privacy |
| Functional Software, Inc. dba Sentry (US) | Error stack traces, JS error messages, native crash reports, device attributes (OS version, app version, device model), anonymous device identifier | Crash and error reporting so we can diagnose and fix issues. No screenshots, no view hierarchy, no session replay. | Only when an error or crash occurs (automatic) | Per recipient's policy | sentry.io/privacy |
| Apple Inc. / Google LLC | Purchase information (including payment details) | Process subscription and package payments | Only when you make a purchase (user-initiated) | Per each company's terms | Apple / Google terms |
These transmissions are required for the App's core functionality. For each recipient's handling of the transmitted information, please consult the disclosure links above.
4. How we use the information
- Country and language preference — to display the right recipe catalogue and language
- Favourites and likes — to let you save and recall your preferred recipes
- Community submissions — to display your recipe to other users after moderation approval
- Optional email — solely to send you a yearly subscription coupon. Never for marketing, never sold, never shared with third parties.
- Reports and feedback — to help us moderate community-submitted recipes and improve the App
- Subscription status — to determine which recipes you can access
- Fraud prevention and legal compliance — to protect the integrity of the App and comply with applicable law
- Aggregate analysis — to understand general usage patterns (e.g. which drink categories are most popular) using non-personal aggregate data. We do not perform individual-level tracking.
We will not use collected information for purposes beyond those stated above without obtaining your consent.
5. Cross-border data transfer (越境移転)
Certain information is transferred to third-party service providers located outside Japan, as described in Section 3 above. In accordance with APPI Article 28, we disclose the following:
United States
Supabase Inc., Netlify Inc., RevenueCat Inc., PostHog Inc., and Functional Software, Inc. dba Sentry are headquartered in the United States. The United States does not have a data protection framework that has been recognized by Japan's Personal Information Protection Commission (PPC) as equivalent to APPI.
About the US data protection regime: The United States does not have a comprehensive federal data protection law. It is regulated sector-by-sector and state-by-state through laws such as HIPAA (health), GLBA (finance), COPPA (children), and state laws including CCPA/CPRA (California). In addition, US government agencies may seek access to data pursuant to warrants or orders under laws such as the CLOUD Act and FISA 702. For further reference, see the PPC's published country surveys of foreign personal information protection regimes.
The status of each recipient is as follows:
- Supabase stores app data in its Tokyo, Japan region. Supabase Inc. (US) may access this data for infrastructure management. Supabase implements standard contractual measures and industry-standard security practices.
- Netlify processes data transiently through US-based serverless functions. Data is not persistently stored by Netlify. Netlify complies with its published privacy policy and DPA.
- RevenueCat processes subscription data in the US. RevenueCat complies with its published privacy policy and implements appropriate security measures.
- PostHog processes anonymous product analytics data in its US cloud region. PostHog does not receive personally identifiable information; the only persistent identifier is an anonymous device UUID generated locally on your device. PostHog complies with its published privacy policy and SOC 2 / HIPAA / GDPR certifications. Session replay is disabled in our implementation.
- Sentry processes error and crash reports in its US cloud region. Reports include stack traces, error messages, and device attributes (OS version, app version, device model). We have explicitly disabled screenshot capture, view hierarchy capture, and session replay in our configuration. The only persistent identifier is an anonymous device UUID. Sentry complies with its published privacy policy and ISO 27001 / SOC 2 certifications.
- Apple / Google: Payment data for App Store / Play Store transactions is processed by Apple and Google in the United States (and other jurisdictions) under their respective privacy policies. We do not handle this payment data.
By using the App, you consent to the transfer of your information to the United States as described above, acknowledging that the data protection standards in the US may differ from those in Japan.
6. Data retention
- Local data (country, favourites, likes, language, theme): retained until you clear it via Settings or uninstall the app.
- Community recipe submissions: recipe content (name, description, ingredients) retained indefinitely as part of our recipe database.
- Optional email addresses: retained for up to 12 months after the subscription coupon has been issued, then deleted. If no coupon is issued, the email is deleted 12 months after submission.
- Recipe and feedback reports: retained for up to 3 years for moderation and abuse prevention purposes, then deleted.
- Like counts: retained indefinitely as aggregate (non-personal) data.
- Subscription status: managed by RevenueCat and Apple/Google. We do not independently store your subscription records.
7. Your rights (開示等の請求)
Under the Act on the Protection of Personal Information (APPI), you have the following rights regarding your personal information held by us:
| Right | Description |
|---|---|
| Disclosure (開示) | Request disclosure of personal information we hold about you |
| Correction (訂正) | Request correction of inaccurate personal information |
| Cessation of use (利用停止) | Request that we stop using your personal information |
| Cessation of third-party provision (第三者提供の停止) | Request that we stop providing your information to third parties |
| Deletion | Request deletion of your personal information |
How to exercise your rights
- No user accounts: The App has no user accounts or login, so there is no account to delete. To delete data you have submitted to our servers (e.g. a community recipe submission or feedback), use the in-app feedback form or email us at support@delphigk.com, and we will delete it.
- Local data: Use the "Clear favourites" and "Clear likes" buttons in Settings, or uninstall the App.
- Submitted data: Contact us at support@delphigk.com with your request. Please include sufficient information for us to identify the relevant data (e.g. the email address used for submission, or the recipe name).
- Verification: For requests involving personal data (e.g. email-bearing submissions), we may ask you to verify your identity by confirming the email address associated with the submission.
- Response timeline: We will respond to your request without undue delay, and in any case within 30 days of receiving a verified request.
- Fee: We do not charge a fee for disclosure or other data subject requests.
Because we do not collect identifying information from most users, we generally cannot identify specific users' data to act on requests, except in the narrow case of community submissions made with an email address. Even when identity has been verified, anonymous like records and any local data you have already deleted cannot be recovered or individually identified, because no identifier links that data back to you.
8. International users and your local rights
The app is operated from Japan by Delphi LLC. If you use it from outside Japan, your local data-protection law may also apply and is intended to be read alongside this policy — including, where relevant: Korea (PIPA), Singapore (PDPA), India (DPDP Act 2023), Indonesia (PDP Law), Malaysia (PDPA 2010), Taiwan (PDPA), Hong Kong (PDPO), the Philippines (Data Privacy Act 2012), and the Gulf/Saudi Arabia (PDPL). Where your local law grants you mandatory rights — such as access, correction, deletion, objection, or withdrawal of consent — that go beyond those described above, those rights apply. To exercise them, contact us at support@delphigk.com. You may also lodge a complaint with your local data-protection authority.
9. Children's privacy
You must be at least 13 years old to use the App, as stated in our Terms of Use. We do not knowingly collect personal information from users under 13. If you are under 18, the optional email feature for community recipe submissions should only be used with parental consent.
If we become aware that we have collected personal information from a user under 13, we will promptly delete that information.
10. Security
Data stored on your device is managed using the device's secure storage where available (Keychain on iOS, EncryptedSharedPreferences on Android). Data sent to our Supabase backend is transmitted over HTTPS and stored on Supabase's infrastructure in Tokyo, Japan.
No system is perfectly secure. If we become aware of a data breach that is likely to cause harm to affected individuals or that involves the categories specified under APPI (sensitive information, 1,000+ records, unauthorized access, or high-risk breaches), we will:
- Notify the Personal Information Protection Commission (個人情報保護委員会) as required by law
- Notify affected users promptly through available means (email for users with email on file, in-app notification for others)
- Take immediate steps to contain and remediate the breach
11. Changes to this policy
We may update this Privacy Policy from time to time. For material changes — including changes that expand the purpose of use of your information or affect your data subject rights — we will provide at least 30 days' advance notice via in-app notification or App Store update notice, and obtain your affirmative consent where required by law.
For non-material changes (e.g. clarifications, formatting), the updated policy will take effect on the date posted. The "Last updated" date at the top of this page will reflect when the policy was last changed.
12. Complaints and regulatory contact
If you have concerns about how we handle your personal information, please contact us first at support@delphigk.com.
If you are not satisfied with our response, you may file a complaint with:
Personal Information Protection Commission (個人情報保護委員会) Website: https://www.ppc.go.jp/ Consultation desk: 03-6457-9849
For general consumer-related concerns, you may also contact Japan's Consumer Hotline at 188 (消費者ホットライン).
13. Language
This Privacy Policy is published in Japanese, English, Korean, and Arabic. In the event of any conflict or inconsistency between the versions: the Japanese version shall prevail for users located in Japan; the Arabic version shall prevail for users resident in the Gulf region (including Saudi Arabia (KSA) and the United Arab Emirates (UAE)); the Korean version shall prevail for users located in Korea; and the English version shall prevail for all other users. However, requests made by a data subject under the Act on the Protection of Personal Information (APPI) shall be handled under Japanese law regardless of which language version was consulted.
14. Starbucks disclaimer
Mellow is an independent application. It is not developed by, affiliated with, sponsored by, or endorsed by Starbucks Corporation. "Starbucks" and all related trademarks are the property of Starbucks Corporation. Mellow displays information about how to order customised drinks at Starbucks stores based on publicly available product information. We do not process any payments for drinks; ordering and payment happen directly between you and Starbucks at the store.
15. Contact
If you have questions about this Privacy Policy or your data, please contact us at:
Email: support@delphigk.com