Privacy
MyCup Privacy Policy
Last updated July 16, 2026. This policy describes the current production behavior of the MyCup iPhone app and MyCup API.
1. Information kept on your device
Drink records, daily goals, reminders, cup names, cup capacity, display units, and locally saved cup images are stored on your device by default. Optional Sign in with Apple does not automatically upload this local hydration data.
2. Optional photo and AI generation
Only after you choose a cup photo and explicitly agree, the photo is sent through the MyCup API to Volcengine Ark in the Beijing region to create a personalized cup image.
The MyCup server processes the original photo in memory and does not write it to persistent server storage. After the request completes or fails, MyCup does not continue storing the original photo.
The generated cup image is temporarily stored so the app can download it. It is retained for about one hour, and automated cleanup runs every five minutes. The app then keeps the downloaded image locally until you replace or delete it.
Do not upload faces, identity documents, bank cards, private screenshots, home addresses, photos of children, or other sensitive information.
3. AI training and third-party processing
MyCup does not use uploaded photos or generated images to train a MyCup-owned model. Volcengine Ark's published service terms state that submitted content and service output are not used to train, retrain, or improve foundation models unless the customer actively accepts a separate data-authorization agreement or participates in a collaboration reward program. The developer is verifying the production account's specific authorization status. Until account-level written evidence is archived, MyCup does not make an unconditional claim that Volcengine never retains or uses input or output for model improvement.
4. Anonymous quota and technical logs
To enforce daily generation limits and prevent abuse, MyCup processes an anonymous installation credential and network address. The server stores only a one-way hash of the anonymous credential for up to 180 days. Daily usage records and keyed IP hashes are retained for seven days.
Nginx access logs may contain the raw IP address, request time, route, status code, and basic technical information for security and troubleshooting. These logs are retained for no more than seven days. They do not record photo contents, raw anonymous credentials, or API keys.
5. Optional account and deletion
The current App Store build does not open new account creation. If you previously signed in on an earlier test build, you can still sign out or delete the online account inside the app.
Account login description (applies once re-enabled): If you choose Sign in with Apple, MyCup processes the Apple account identifier and the name you choose to provide to create and restore the online account. MyCup does not request or store your Apple email address. For new sign-ins, MyCup encrypts and stores an Apple refresh token only so it can revoke Sign in with Apple authorization when you delete the account.
You can delete the online account inside the app. Deletion revokes that authorization and removes the server account, login identities, generation records, quota records, related subscription records, account-linked generated images, and the encrypted token. Local drink records, goals, reminders, and cup images remain on the device until you delete them separately.
6. Contact
For privacy questions, server-side deletion requests, or account issues, email support@mycup.online.