Ashbook

Privacy Policy

Privacy Policy

Effective date: October 9, 2026

Overview

Ashbook ("Ashbook," "the App") is developed by Adelyons Software LLC ("we," "us," or "our"). Ashbook is a premium, local-first, no-account cigar humidor, collection tracker, and tasting journal. It lets you catalog every cigar, monitor each humidor's climate, track aging and peak-window timelines, follow your collection's value, and keep a structured tasting journal. This policy explains how the App handles your information.

The short version: Ashbook is local-first. There is no account and no login. Everything you enter — your cigars, humidors, climate logs, tasting notes, and value/manifest data — is stored on your device and stays there unless you choose to pair two of your devices (see Sync Between Your Devices). If you never pair, nothing you enter leaves the device. Optional humidor sensors follow the same rule: a Bluetooth sensor is read on the phone, and a sensor maker's cloud can be connected only to a list you have already chosen to sync. There are two other narrow exceptions, neither of which involves your data: purchase and subscription data, which is handled by Apple, Google, and RevenueCat solely to validate an optional Ashbook+ purchase. The second is the optional invite feature (see Invite a Friend), which sends only a random installation identifier and an invite code. We never sell your collection data, and we do not look at it. It reaches our sync service only if you pair devices, and only so those devices can keep the same list.

For adults of legal smoking age. Ashbook is an inventory and journaling tool for personal cigar collections. It does not sell tobacco, facilitate any purchase, or provide health advice. It is intended for adults of legal smoking age.

Information Stored On Your Device

The following is created and stored locally on your device only, in a private database (SQLite) within the App. It is not transmitted to us or to any server:

Because this data lives only on your device, it is removed when you delete an entry in the App, clear the App's data, or uninstall the App.

No Account Required. No Cloud Unless You Pair Devices or Sign In

Google Sign-In (Optional)

Since version 1.3.0 you may choose to sign in with Google, on the phone or at ashbook.adelyons.com, to keep one or more "books" (a humidor, store or location each) in an account and have them on every device you sign in on. If you do, we hold:

Signing out keeps the local copy on that device. Deleting the account — Settings → Account & sync → Delete account on the phone, or Account → Delete account on the web — erases every book in the account from our servers, cancels any subscription bought on the web, and removes the account itself. See Delete Account.

Sync Between Your Devices (Optional)

Ashbook can keep the same list on more than one of your devices: the phone app (Android 1.3.0 and later) and Ashbook on the web at ashbook.adelyons.com. It is off until you turn it on by pairing two devices with a code, and it never needs an account, an email address, or a name.

What is sent when you pair, and after. To keep paired devices in step, each device sends the changes you make to our sync service (hosted on Supabase, in the United States), which stores them as a log the other devices read:

What is not sent. No name, email address, phone number, contacts, location, or payment information. A device that has not been paired sends nothing.

Who can read it. Only devices you have paired, each holding its own secret token (we store only a one-way hash of it). The data is sent over encrypted (TLS) connections and stored on Supabase's servers; it is not end-to-end encrypted, so it is technically readable by us as the operator. We do not read it, use it for any other purpose, sell it, or share it.

How long it is kept, and how to delete it.

Ashbook on the web stores your list in your browser's own storage on that computer. Clearing the browser's site data erases it there, which is why the web edition offers a backup file you can download.

Humidor Sensors (Optional)

From version 1.4.0, Ashbook can log a humidor's humidity and temperature from a sensor instead of from your typing. It is off until you add a sensor, and there are three ways to do it.

A Bluetooth hygrometer, read by the phone app. On Android, Climate → Add a sensor listens for the readings that nearby hygrometers broadcast. Ashbook does not pair with or connect to the sensor, and it does not use Bluetooth to work out where you are. It asks for Android's Nearby devices permission (on Android 11 and earlier, Android requires the location permission for any Bluetooth scan; Ashbook does not read or store your location). What it hears is used on the phone to show the sensor's reading; the sensor's Bluetooth address stays in the phone's private database and is never sent anywhere, synced, or included in a backup. If you turn on Read while Ashbook is closed on the sensor's page (off by default), Android runs the same short listen in the background about once per interval, for the sensors you added and nothing else; it makes no network call and can be turned off on the same page. With Humidor reminders also on, the phone may show a notification when such a reading is off your target or the sensor has gone quiet; the notification is made on the phone and sent nowhere. The readings it keeps are ordinary climate readings: they stay on the phone, and are synced only if you have paired devices or signed in, exactly like a reading you typed. Each carries the name you gave the sensor.

A sensor maker's cloud. In Ashbook on the web (Devices & backup → Sensors) or in the phone app (Settings → Sync → Wi-Fi sensors and built devices) you can connect a Govee or SwitchBot account so that your Wi-Fi sensors report about once an hour. This works only for a list that is already synced (paired or signed in), because our server does the reading. When you connect one:

Govee and SwitchBot handle your account with them under their own privacy policies. Ashbook is not affiliated with either.

A device you build. The same page can make a token for a sensor of your own (for example an ESP32). The token is shown once; we store only a one-way hash of it. The device sends a humidity and temperature reading with that token, and the reading is added to your synced list. Revoke ends it.

Keeping and deleting. Sensor readings are part of your list, so everything under Sync Between Your Devices applies to them: stopping sync, deleting the shared copy, the 180-day removal of an idle group, and deletion by email. Deleting the shared copy also deletes any stored maker key and every sensor record. To keep the history small, sensor readings older than 30 days are reduced to one a day; a reading you typed is never removed that way.

Insights Are Deterministic & On-Device — No AI Model

Every insight in Ashbook — humidor drift status, aging/peak-window status, collection value, your palate profile, and flavor affinities — is produced by deterministic, rule-based logic that runs entirely on your device. Identical input always produces identical output. There is no language model, no AI model, and no model download anywhere in the App, and these features require no network connection and no API key. Nothing about your collection is sent anywhere to compute an insight.

Optional Purchases (Ashbook+)

Ashbook's core is free, with an optional Ashbook+ upgrade. Apart from optional sync and the optional invite feature, purchases are the only feature that involves any data leaving your device, and they are handled by trusted providers:

If you never make a purchase, no purchase-related data is sent. Subscription terms (including the 7-day annual trial and auto-renewal) are described in our Terms of Service and EULA, and are also governed by Apple's Media Services Terms and Google Play's Terms of Service.

Invite a Friend (Optional)

Ashbook includes an optional invite feature: if a friend enters your invite code, you both receive 30 days of Ashbook+ at no charge. It is entirely optional, and the rest of the App never needs a connection.

When — and only when — you open the invite screen or enter a code, the App sends the following to our invite service (hosted on Supabase) so the free month can be granted through RevenueCat:

That is the entire payload. It does not include your humidor, collection, or tasting notes — none of your humidor data is involved in the invite feature in any way. We do not learn your name, email address, contacts, or location, and there is still no account and no login. Records of invite codes and redemptions are kept only to grant the reward, to prevent abuse, and as an audit trail; email us and we will delete yours.

What We Do NOT Collect

Data Retention & Deletion

Your cigars, humidors, climate logs, tasting notes, value data, and backups are stored on your device, so you control them directly and they are kept for as long as you keep them:

Security

Your data stays within the App's private storage on your device, protected by your device's operating system. Communication with the App Store, Google Play, RevenueCat, and (if you pair devices) our sync service uses encrypted (TLS) connections. No system can guarantee absolute security. If you do not pair devices, there is no copy of your collection anywhere but your device.

Children's Privacy

Ashbook is an adult product, intended only for adults of legal smoking age. It is not directed to children, and it does not request that children provide information to us. We do not knowingly collect personal information from children. If you believe a child has used the App's optional sync, contact us using the details below and we will help.

Your Rights

Privacy laws such as the GDPR (EU/EEA/UK) and CCPA/CPRA (California) give you rights to access, correct, delete, and port your personal data, and to opt out of its sale. Unless you have paired devices or signed in, we hold nothing about you to disclose, correct, or sell. If you have, what we hold is the synced content described above, tied to random device identifiers and not to your identity; you can export it from any paired device and delete the server's copy as described above, or ask us to. For any purchase data held by Apple, Google, or RevenueCat, contact those providers or reach us using the details below and we will help.

Changes to This Policy

We may update this policy as the App evolves. Material changes will be reflected by updating the "Effective date" above and, where appropriate, through an in-app notice. Continued use of the App after changes take effect constitutes acceptance of the updated policy.

Contact Us

Questions about this policy or your data? Email dev@adelyons.com.

Adelyons Software LLC
https://adelyons.com