OpenBrew

Coffee, paid in Pi.

Find cafes that accept Pi, browse their menu, and pay in Pi.

  • Discover cafes

    Browse coffee shops by country and see what they are serving today.

  • Pay with Pi

    Check out in Pi — no cards, no currency conversion.

  • Open your own shop

    Register your cafe, list your menu, and start accepting Pi.

    Privacy Policy

    Privacy Policy

    OpenBrew — a Pi Network ecosystem app

    Last updated: 2026-08-27

    The short version

    • OpenBrew works only inside Pi Browser. Signing in with your Pi account is the only way to log in, and only Pi users who have completed Pi Network KYC can place orders or run a store.
    • We never receive, ask for, or store your Pi passphrase, private key, or recovery phrase — and we never see your KYC documents. From Pi we receive only your Pi user ID, username, wallet address, and a yes/no verification flag.
    • We do not sell your data, and we run no advertising or analytics trackers.

    1. Who we are

    OpenBrew ("OpenBrew", "we", "us") is an independent third-party application built on the Pi Network platform. It lets Pi users discover coffee shops and pay for orders in Pi. This Privacy Policy explains what personal information we handle, why we handle it, and what you can ask us to do with it.

    OpenBrew is not operated, sponsored, endorsed, or reviewed by the Pi Core Team. Information you provide directly to Pi Network — including anything submitted during KYC — is handled by Pi Network under its own privacy policy, not this one.

    2. Conditions of access

    These conditions shape everything in this Policy, so we state them first:

    • Pi Browser only. OpenBrew is designed to run inside Pi Browser. Outside it, Pi authentication and Pi payments are unavailable.
    • Pi login only. Pi Network authentication is the only sign-in method. There are no OpenBrew passwords, email sign-ups, or social logins, so we hold no credentials for you.
    • KYC-verified users only. Placing an order, registering a store, or receiving payments requires a completed Pi Network KYC verification.

    3. Information we receive from Pi Network

    When you sign in, the Pi SDK asks for your permission for the scopes username, payments, and wallet_address. If you grant it, we receive:

    • Your Pi user ID (uid) — a stable identifier we use as your account key.
    • Your Pi username — shown to a coffee shop so it can match an order to the person collecting it.
    • Your Pi wallet address — used to route payments.
    • A short-lived access token — used to verify the request came from you.
    • Your KYC verification status — a true/false flag we read from the Pi Platform API.

    We never receive or ask for your Pi passphrase, private key, or recovery phrase, and we never see your KYC documents, legal name, ID number, or date of birth. No OpenBrew screen, email, or support message will ever request them. Anyone who does is attempting fraud.

    4. Information you give us

    • As a buyer: cart contents, orders and order items, order history, and the payment records tied to them (amount in Pi, Pi payment identifier, blockchain transaction hash, status).
    • As a coffee shop owner: store name, store address (including the structured components returned by address search), contact email, phone number, the Pi wallet address that receives your payments, store photos, and menu names, descriptions, prices, and photos.
    • If you contact us through an inquiry form: business name, email, phone number, address, and your message.
    • Your language preference.

    5. Information collected automatically

    • Account timestamps: when your account was created and when you last signed in.
    • Server and error logs: request time, path, status, and diagnostic details, including the IP address seen by our hosting and security providers. These exist to keep the service running and to investigate abuse.

    We use no advertising trackers, no analytics cookies, and no third-party marketing pixels. Browser storage is used only for what the service needs to function: keeping you signed in, remembering your cart, and remembering your language.

    6. Why we use your information

    • To sign you in and keep your session active.
    • To confirm that you meet the KYC requirement for ordering or selling.
    • To create, approve, and complete Pi payments through the Pi Platform Payments API, and to match a completed payment to the right order.
    • To pass your order to the coffee shop so it can be prepared and collected.
    • To review store registrations before they are listed, and to detect fraud, abuse, and manipulated transactions.
    • To answer inquiries and provide support.
    • To meet legal, accounting, and tax obligations.

    We do not use your information for automated decision-making that produces legal effects, and we send no marketing messages.

    7. Legal bases (EEA/UK users)

    • Performance of a contract — signing you in, processing orders and payments, listing a store.
    • Legal obligation — retaining transaction and tax records.
    • Legitimate interests — service security, fraud and abuse prevention, and protecting the integrity of the Pi ecosystem.
    • Consent — where local law requires it, including the consent recorded in our Terms of Service. You may withdraw consent at any time, which means closing your OpenBrew account.

    8. Who we share it with

    • The coffee shop you order from: your Pi username, the items ordered, the amount, and the order time. The shop needs this to prepare and hand over your order.
    • Pi Network: payment identifiers we submit to the Pi Platform API to approve and complete a payment.
    • Service providers acting on our instructions: Supabase (database hosting), Amazon Web Services S3 (image storage, Asia Pacific / Seoul), Google Places API (address lookup when a seller searches for a store address), and Slack (operational alerts to our own team). They may process personal information only to provide these services to us.
    • Authorities or affected parties, where disclosure is required by law or necessary to investigate fraud, abuse, or a threat to safety.

    We do not sell, rent, or trade your personal information, and we do not share it for advertising or profiling.

    9. Payments are recorded on a public blockchain

    Pi payments settle on the Pi blockchain. Once a transaction is confirmed, the wallet addresses, the amount, and the timestamp are recorded publicly and permanently. We cannot edit, hide, reverse, or delete an on-chain record — not at your request, and not at our own. Treat a wallet address as public information.

    10. International transfers

    OpenBrew serves Pi users worldwide, so your information may be stored and processed outside your country of residence — including in the Republic of Korea and the United States, where our infrastructure providers operate. Where required, we rely on recognised transfer mechanisms such as the European Commission’s standard contractual clauses.

    11. How long we keep it

    DataRetention
    Account record (Pi uid, username, KYC flag, login timestamps)Until you close your account; deleted within 30 days of a verified request
    Order, payment, and tax recordsUp to 5 years, as required by applicable commercial and tax law
    Store and seller recordsWhile the store is listed, then 30 days after removal
    Inquiry submissionsUp to 3 years
    Server and error logsUp to 90 days

    Where law requires us to keep a record longer than the period above, we keep only that record, only for that purpose, and delete it when the obligation ends.

    12. Your rights

    Subject to your local law, you may ask us to give you a copy of your information, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. You may also withdraw consent where we rely on it.

    To make a request, email pifromuser@gmail.com from an address we can tie to your account, or contact us from within the app while signed in with Pi so we can confirm it is really you. We answer within 30 days. If we cannot verify that the request comes from the account holder, we will decline it — that protection is the point.

    • Closing your OpenBrew account does not close, affect, or delete your Pi Network account.
    • Deletion cannot remove transactions already recorded on the Pi blockchain, and does not erase records we are legally required to retain.

    You may also complain to your local data protection authority — in the Republic of Korea, the Personal Information Protection Commission (privacy.go.kr, 118).

    13. Security

    • All traffic is encrypted in transit with TLS.
    • Our database denies all access by default; the application reaches it only through server-side keys that are never exposed to the browser.
    • Pi access tokens are used to verify a request and are not retained beyond what a session requires. Privileged actions are re-verified against the Pi Platform API.
    • We hold no passwords, passphrases, private keys, or KYC documents — the safest way to protect data is not to have it.

    No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authority as required by law.

    14. Children

    OpenBrew is for adults. You must be at least 18 years old, or the age of majority where you live, and eligible to use Pi Network under its terms. We do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will delete it.

    15. Changes to this Policy

    We may update this Policy. The date at the top always reflects the current version, and we announce material changes in the app before they take effect. Continuing to use OpenBrew after a change means you accept the updated Policy.

    16. Contact

    Questions, requests, or complaints about this Policy: openbrew.team@gmail.com

    The English version of this document is the controlling version.