Privacy Policy
Effective date: October 9, 2026
Overview
Ashbook ("Ashbook," "the App") is developed by Adelyons Software LLC ("we," "us," or "our"). Ashbook is a premium, local-first, no-account cigar humidor, collection tracker, and tasting journal. It lets you catalog every cigar, monitor each humidor's climate, track aging and peak-window timelines, follow your collection's value, and keep a structured tasting journal. This policy explains how the App handles your information.
The short version: Ashbook is local-first. There is no account and no login. Everything you enter — your cigars, humidors, climate logs, tasting notes, and value/manifest data — is stored on your device and stays there unless you choose to pair two of your devices (see Sync Between Your Devices). If you never pair, nothing you enter leaves the device. Optional humidor sensors follow the same rule: a Bluetooth sensor is read on the phone, and a sensor maker's cloud can be connected only to a list you have already chosen to sync. There are two other narrow exceptions, neither of which involves your data: purchase and subscription data, which is handled by Apple, Google, and RevenueCat solely to validate an optional Ashbook+ purchase. The second is the optional invite feature (see Invite a Friend), which sends only a random installation identifier and an invite code. We never sell your collection data, and we do not look at it. It reaches our sync service only if you pair devices, and only so those devices can keep the same list.
For adults of legal smoking age. Ashbook is an inventory and journaling tool for personal cigar collections. It does not sell tobacco, facilitate any purchase, or provide health advice. It is intended for adults of legal smoking age.
Information Stored On Your Device
The following is created and stored locally on your device only, in a private database (SQLite) within the App. It is not transmitted to us or to any server:
- Cigars & collection: Brand, line, vitola, ring gauge, length, wrapper, country, quantity, price, where-bought, box code, resting-since date, and notes for each stick.
- Humidors: Your humidor names, capacity, and configuration.
- Climate logs: The RH and temperature readings you record over time, or that a Bluetooth sensor you added reports (and that sensor's name, model and Bluetooth address), plus drift alerts and “check this humidor” reminders computed from them.
- Aging & cellar status: Rest dates and the Resting → Maturing → Prime → Past-prime statuses derived from them.
- Tasting journal: Your ratings, tasting notes, flavor-wheel tags, and the palate profile and flavor affinities (drink pairing, strength profile, and format length) derived from your own entries.
- Value & manifest: Per-stick cost, total humidor value, and any insurance/estate manifest you generate.
- Backups: The automatic on-device backup and any export files you create (JSON backups, and plain-text/CSV insurance manifests) that you save and share yourself.
- App settings & preferences: Your in-app preferences and display choices.
Because this data lives only on your device, it is removed when you delete an entry in the App, clear the App's data, or uninstall the App.
No Account Required. No Cloud Unless You Pair Devices or Sign In
- Ashbook does not require you to create an account, sign in, or provide an email address, phone number, name, or any other identifier. There is no contacts grab. Every feature except multi-device sync works as a guest.
- Unless you pair devices, no server of ours receives, stores, or backs up your data. The App makes no network call with your collection in it.
- Your data is synced between devices only if you pair them yourself (below). Separately, if your device's operating system backs up app data (for example through iCloud or Android backup that you have enabled), that backup is controlled by you and your platform provider under their policies — not by us.
- Ashbook keeps an automatic on-device backup and lets you create your own export (JSON, plus a plain-text/CSV insurance manifest) that you save and share yourself. Backup and restore are free for everyone and are never paywalled.
Google Sign-In (Optional)
Since version 1.3.0 you may choose to sign in with Google, on the phone or at ashbook.adelyons.com, to keep one or more "books" (a humidor, store or location each) in an account and have them on every device you sign in on. If you do, we hold:
- Your Google account's email address, display name and a Google user id, as provided by Google's sign-in, through our authentication provider (Supabase). We never see your Google password.
- The books you put in the account: the synced content described under Sync, tied to that account instead of to a pairing.
- For an Ashbook+ bought on the web: a Stripe customer id and subscription status (see Purchases). Ashbook+ bought on either platform is recognised on the other through RevenueCat, under the same account id.
Signing out keeps the local copy on that device. Deleting the account — Settings → Account & sync → Delete account on the phone, or Account → Delete account on the web — erases every book in the account from our servers, cancels any subscription bought on the web, and removes the account itself. See Delete Account.
Sync Between Your Devices (Optional)
Ashbook can keep the same list on more than one of your devices: the phone app (Android 1.3.0 and later) and Ashbook on the web at ashbook.adelyons.com. It is off until you turn it on by pairing two devices with a code, and it never needs an account, an email address, or a name.
What is sent when you pair, and after. To keep paired devices in step, each device sends the changes you make to our sync service (hosted on Supabase, in the United States), which stores them as a log the other devices read:
- The content you sync: your humidors, cigars and their details and counts, climate readings, and tasting notes; and, from the web edition, stock movements and deliveries you record.
- A device name and a random device identifier. The name is a generic label such as “Android phone” or “Web browser”. The identifier is a random value made on the device; it is not an advertising ID and is not derived from you or your hardware.
- A pairing code, eight characters, valid for ten minutes and for one use.
What is not sent. No name, email address, phone number, contacts, location, or payment information. A device that has not been paired sends nothing.
Who can read it. Only devices you have paired, each holding its own secret token (we store only a one-way hash of it). The data is sent over encrypted (TLS) connections and stored on Supabase's servers; it is not end-to-end encrypted, so it is technically readable by us as the operator. We do not read it, use it for any other purpose, sell it, or share it.
How long it is kept, and how to delete it.
- A paired group of devices that has not synced for 180 days is deleted from the server automatically.
- The device that started the pairing can erase the server's copy at any time: in Ashbook on the web, Devices & backup → Delete the shared copy from the server. Every device keeps what it holds.
- Stop syncing on any device removes that device from the group and stops it sending or receiving changes.
- Or email dev@adelyons.com with the pairing details and we will delete it for you.
Ashbook on the web stores your list in your browser's own storage on that computer. Clearing the browser's site data erases it there, which is why the web edition offers a backup file you can download.
Humidor Sensors (Optional)
From version 1.4.0, Ashbook can log a humidor's humidity and temperature from a sensor instead of from your typing. It is off until you add a sensor, and there are three ways to do it.
A Bluetooth hygrometer, read by the phone app. On Android, Climate → Add a sensor listens for the readings that nearby hygrometers broadcast. Ashbook does not pair with or connect to the sensor, and it does not use Bluetooth to work out where you are. It asks for Android's Nearby devices permission (on Android 11 and earlier, Android requires the location permission for any Bluetooth scan; Ashbook does not read or store your location). What it hears is used on the phone to show the sensor's reading; the sensor's Bluetooth address stays in the phone's private database and is never sent anywhere, synced, or included in a backup. If you turn on Read while Ashbook is closed on the sensor's page (off by default), Android runs the same short listen in the background about once per interval, for the sensors you added and nothing else; it makes no network call and can be turned off on the same page. With Humidor reminders also on, the phone may show a notification when such a reading is off your target or the sensor has gone quiet; the notification is made on the phone and sent nowhere. The readings it keeps are ordinary climate readings: they stay on the phone, and are synced only if you have paired devices or signed in, exactly like a reading you typed. Each carries the name you gave the sensor.
A sensor maker's cloud. In Ashbook on the web (Devices & backup → Sensors) or in the phone app (Settings → Sync → Wi-Fi sensors and built devices) you can connect a Govee or SwitchBot account so that your Wi-Fi sensors report about once an hour. This works only for a list that is already synced (paired or signed in), because our server does the reading. When you connect one:
- You give us that maker's API key (Govee) or token and secret (SwitchBot). We store it encrypted on our sync service (Supabase, United States) and use it only to ask the maker for the temperature and humidity of the sensors you choose. It is never shown again, shared, or used for anything else.
- We receive from the maker the names and models of the thermometers in that account, so you can say which humidor each one watches, and then each chosen sensor's latest temperature and humidity. We do not request or keep anything else from the account.
- Each reading, with the sensor's name, is added to your synced list as a climate reading.
- Disconnect deletes the stored key and stops the readings. Readings already logged stay in your list until you delete them.
Govee and SwitchBot handle your account with them under their own privacy policies. Ashbook is not affiliated with either.
A device you build. The same page can make a token for a sensor of your own (for example an ESP32). The token is shown once; we store only a one-way hash of it. The device sends a humidity and temperature reading with that token, and the reading is added to your synced list. Revoke ends it.
Keeping and deleting. Sensor readings are part of your list, so everything under Sync Between Your Devices applies to them: stopping sync, deleting the shared copy, the 180-day removal of an idle group, and deletion by email. Deleting the shared copy also deletes any stored maker key and every sensor record. To keep the history small, sensor readings older than 30 days are reduced to one a day; a reading you typed is never removed that way.
Insights Are Deterministic & On-Device — No AI Model
Every insight in Ashbook — humidor drift status, aging/peak-window status, collection value, your palate profile, and flavor affinities — is produced by deterministic, rule-based logic that runs entirely on your device. Identical input always produces identical output. There is no language model, no AI model, and no model download anywhere in the App, and these features require no network connection and no API key. Nothing about your collection is sent anywhere to compute an insight.
Optional Purchases (Ashbook+)
Ashbook's core is free, with an optional Ashbook+ upgrade. Apart from optional sync and the optional invite feature, purchases are the only feature that involves any data leaving your device, and they are handled by trusted providers:
- Apple App Store / Google Play: When you subscribe or make the lifetime purchase, the transaction is processed entirely by Apple or Google under their own privacy policies. We never receive or store your payment-card details.
- RevenueCat: We use RevenueCat to validate and restore your Ashbook+ entitlement. RevenueCat receives a purchase token, an anonymous app-generated user identifier, and basic device and purchase metadata needed to deliver and restore your purchase. It does not receive any of your collection data — no cigars, humidors, climate logs, tasting notes, value figures, or manifests. See RevenueCat's privacy policy.
If you never make a purchase, no purchase-related data is sent. Subscription terms (including the 7-day annual trial and auto-renewal) are described in our Terms of Service and EULA, and are also governed by Apple's Media Services Terms and Google Play's Terms of Service.
Invite a Friend (Optional)
Ashbook includes an optional invite feature: if a friend enters your invite code, you both receive 30 days of Ashbook+ at no charge. It is entirely optional, and the rest of the App never needs a connection.
When — and only when — you open the invite screen or enter a code, the App sends the following to our invite service (hosted on Supabase) so the free month can be granted through RevenueCat:
- A random installation identifier generated on your device the first time the invite screen is used. It is a random value, not a device or advertising ID, and it is not derived from your device or from you.
- Your RevenueCat anonymous customer identifier, so the free month is applied to the right installation.
- The six-character invite code being created or redeemed.
That is the entire payload. It does not include your humidor, collection, or tasting notes — none of your humidor data is involved in the invite feature in any way. We do not learn your name, email address, contacts, or location, and there is still no account and no login. Records of invite codes and redemptions are kept only to grant the reward, to prevent abuse, and as an audit trail; email us and we will delete yours.
What We Do NOT Collect
- We do not collect, upload, or store your collection on any server unless you pair devices to sync them, as described above.
- We do not require an account, email address, phone number, name, or login, and we do not request access to your contacts.
- We do not collect location data.
- We do not use advertising identifiers or any cross-app tracking, and we do not show ads.
- We do not use third-party analytics or crash-reporting SDKs in the App that send your usage or personal data to us.
- We do not sell or rent your personal information to anyone. Your data stays on your devices, and what you choose to sync is used only to sync.
Data Retention & Deletion
Your cigars, humidors, climate logs, tasting notes, value data, and backups are stored on your device, so you control them directly and they are kept for as long as you keep them:
- Delete in-app: Remove individual entries at any time, or clear the App's data from within the App or your device settings.
- Uninstall: Deleting the App from your device permanently removes all of its locally stored data. If you never paired devices, there is no server-side copy to delete. There is never an account to close.
- Synced data: If you paired devices, see Sync Between Your Devices for how the server's copy is deleted, by you or automatically.
- Account: If you signed in with Google, see Delete Account: one action in the app or on the web removes every book and the account.
- Purchase records: Subscription and purchase records held by Apple, Google, or RevenueCat are retained under their respective policies. You can manage or cancel a subscription from your device's store settings.
Security
Your data stays within the App's private storage on your device, protected by your device's operating system. Communication with the App Store, Google Play, RevenueCat, and (if you pair devices) our sync service uses encrypted (TLS) connections. No system can guarantee absolute security. If you do not pair devices, there is no copy of your collection anywhere but your device.
Children's Privacy
Ashbook is an adult product, intended only for adults of legal smoking age. It is not directed to children, and it does not request that children provide information to us. We do not knowingly collect personal information from children. If you believe a child has used the App's optional sync, contact us using the details below and we will help.
Your Rights
Privacy laws such as the GDPR (EU/EEA/UK) and CCPA/CPRA (California) give you rights to access, correct, delete, and port your personal data, and to opt out of its sale. Unless you have paired devices or signed in, we hold nothing about you to disclose, correct, or sell. If you have, what we hold is the synced content described above, tied to random device identifiers and not to your identity; you can export it from any paired device and delete the server's copy as described above, or ask us to. For any purchase data held by Apple, Google, or RevenueCat, contact those providers or reach us using the details below and we will help.
Changes to This Policy
We may update this policy as the App evolves. Material changes will be reflected by updating the "Effective date" above and, where appropriate, through an in-app notice. Continued use of the App after changes take effect constitutes acceptance of the updated policy.
Contact Us
Questions about this policy or your data? Email dev@adelyons.com.
Adelyons Software LLC
https://adelyons.com