Privacy Policy
Last updated: September 2026
The Beer App ("we", "us") respects your privacy. This policy explains what personal information we collect, how we use it, the automated systems we apply to it, and the specific third parties we share it with.
The data controller is the operator of The Beer App. You can reach us about anything in this policy at support@thebeerapp.app.
The person responsible for protecting your personal information is our Privacy Officer, who is also our data protection contact, our encarregado in Brazil and our grievance officer in India. Write to them at the same address.
Age: this is an app about alcohol and is only for people of legal drinking age. We ask for your country and date of birth at sign-up and refuse accounts under the drinking age there (19 in Canada, 21 in the US, 18 in most places). We do not knowingly collect anything from a child; if you believe we have, write to us and we will delete it.
Information we collect
We collect the following personal information:
- Account details you provide: your username, first and last name, email address, and a password. (Earlier versions of the app asked for an optional phone number. Nothing ever used it, so we stopped asking; if you gave one, only you can see it, and we will delete it if you ask.) The password goes to our sign-in provider, Auth0, which stores it only as a salted secure hash; it never reaches our own servers.
- Content you create: beer photos, captions, comments, direct messages, group posts, and beer submissions.
- Profile details: profile photo, bio, and the country/state/city you choose to share.
- Usage & device data: your streak and activity counts, timezone, and — if you enable reminders — a device push-notification token.
- Purchase data: your subscription plan and status. Payment card details are collected and processed by our payment providers (below); we never receive or store your full card number.
- Face ID: if you turn on Unlock with Face ID in Settings (it is off unless you do), your iPhone checks your face and tells the app only whether it matched. Your face data, and any other biometric data, never leaves your phone and we never receive, see or store it.
- Launch list: if you give us your email address on our website to hear when the app launches, we keep it with a record of what you agreed to, when, and that you told us you are of drinking age. We use it only to send you that news and never share it. Every one of those emails has a one-click unsubscribe; when you use it we delete your address and keep only a scrambled fingerprint of it, so we never email it again by mistake.
- Location: the region you choose to set for rankings and regional groups; and, only when you choose to pin a beer to the map, the position of the place you name, read from your phone at that moment with your permission and stored with that post. You choose who can see a pinned location. We never track your location in the background.
How we use it
To operate the app: to create and secure your account, show your posts, run feeds, rankings and groups, deliver messages and notifications, process subscriptions, moderate content, and respond to support requests. We do not sell your personal information, and we do not use it for third-party advertising.
Why we are allowed to use it
Where the UK/EU GDPR applies, our lawful bases are:
- Performance of a contract — your account, your posts, feeds, groups, messages, rankings and subscriptions. Without this data there is no service to give you.
- Legitimate interests — keeping the service secure, preventing abuse and fraud, moderating content, and answering support requests. We have weighed these against your rights and limited what we collect accordingly.
- Legal obligation — keeping records we are required to keep, and responding to lawful requests.
- Consent — push notifications, and access to your camera, photos or location. You give it in the operating system, you can withdraw it at any time in Settings, and withdrawing it does not affect anything we did beforehand.
We do not rely on consent for the rest, and we do not use your data for automated decisions that produce legal effects about you.
How long we keep it
- Your account and content — while your account is open. Deleting your account removes your profile, posts, comments and uploaded photographs, including from our image host.
- Messages you sent — a message belongs to the other person's conversation as well as yours, so when you delete your account the messages you sent (including photos) stay with the people you sent them to, shown as coming from a deleted account. A conversation is deleted entirely once nobody is left in it.
- Content under a safety report — content that has been reported or removed for breaking our rules, and the reports about it, can be kept after it or your account is deleted, for as long as we need to investigate and to meet our legal obligations (for example, preserving and reporting material that endangers a child), and then deleted.
- Support messages — deleted with your account.
- Password reset links — issued and expired by Auth0; they stop working after a short time.
- Backups — copies persist in routine backups that are overwritten on a rolling basis after deletion.
- Records we must keep by law — for example transaction records for tax and accounting purposes — for as long as the law requires, and no longer.
Where your data goes
We are based in Canada and our providers operate in Canada, the United States and the European Union, so your information may be processed outside the country you live in. Where data is transferred out of the UK or EEA, we rely on the European Commission's adequacy decision for Canada and, for other providers, on Standard Contractual Clauses.
Automated processing & content moderation
To keep the community safe, we use automated systems to review text and other content you submit. These systems screen for prohibited content (such as harassment, slurs, and sexually explicit or other objectionable material) and may automatically block a submission before it is posted. Automated processing may also detect messages that suggest self-harm so we can show you supportive crisis resources. Automated decisions can be wrong; you can report content, appeal, or contact us for a human review at any time. We will notify you here if we introduce artificial-intelligence features that make automated decisions about your content or account.
Public content
The Beer App is a social app. Your username, profile photo, bio, and the posts, photos, and comments you publish are visible to other users as you choose (globally, by region, or within groups). Images you post are served from a public content-delivery network, which means anyone with the image link can view that image while it exists. Please do not post anything you would not want to be public. Direct messages are visible only to the participants of that conversation.
Third parties we share data with
We share the minimum data necessary with the following service providers ("processors") to run the app. Each processes data under its own privacy policy:
- Auth0 (by Okta; sign-in) — holds your email address and password (as a secure hash), checks them when you log in, and sends verification and password-reset emails. Privacy policy
- MongoDB Atlas (database hosting) — stores your account and content. Privacy policy
- Render (application hosting) — runs our servers. Privacy policy
- Cloudinary and/or Cloudflare R2 (image hosting/CDN) — store and deliver the photos you upload. Cloudinary · Cloudflare
- Stripe (payments) — processes card payments and subscriptions for web checkout. Privacy policy
- Apple App Store and Google Play (in-app purchases) — process subscriptions bought inside the app. Apple · Google
- Expo (push notifications) — delivers reminder notifications to your device. Privacy policy
- Resend (email delivery) — sends transactional email: report alerts, and Auth0's verification and password-reset emails. It receives your email address and the contents of that message. Privacy policy
- Sentry (crash reporting) — receives a technical report when the app or our server hits an error: the error itself, where in the code it happened, and your account ID so we can tell one person hitting a bug ten times from ten people hitting it once. It does not receive your name, email, photos, messages, or the contents of your requests, and we have session replay switched off, so it never records your screen. Privacy policy
We may also disclose information if required by law, to enforce our terms, or to protect the rights and safety of our users.
Cookies and this website
This website sets no cookies and loads nothing from any other server — no fonts from a CDN, no embedded video, no advertising, no tracking pixels. There is nothing here to consent to, which is why you are not being shown a banner asking you to.
Your browser stores one thing, and only if you change a setting on this site: a note of that choice, kept on your own device and never sent to us. Our servers keep short-lived request logs (IP address, the page requested, the time) for security and debugging; these are not used to build a profile of you and are not shared.
The app itself does not use cookies either. It signs you in with a token stored in your device’s secure storage, which is not a cookie and is not readable by any website.
If we ever add website analytics, we will ask for your consent before anything loads, and this section will say what it is.
Your choices & rights
You can edit or delete your posts, remove them from groups, block other users, and report content in the app. You can disable notifications at any time in Settings.
Wherever you live, you can ask us to:
- Show you the personal information we hold about you and give you a copy. Settings → Download My Data does it straight away.
- Correct anything that is wrong. Most of it you can edit yourself in the app.
- Delete it: Settings → Delete Account, or ask us.
- Give it to you in a form you can take elsewhere: the download is a machine-readable file.
- Stop or limit how we use it, or withdraw a permission you gave (notifications, camera, photos, location) at any time in your phone’s Settings.
- Tell you who we share it with, where it is stored, and how long we keep it (all set out on this page).
- Have a person review any automated decision about you, and hear your side.
Write to support@thebeerapp.app from the email address on your account, so we know it is you; if you write from another address we may ask you to confirm who you are, and ask for nothing more than we need to. It is free. We answer within 30 days, or sooner where the law where you live says so, and if we ever need longer we will tell you why within that time. If we refuse, we will tell you why and how to complain. You can ask someone to make a request for you if they can show you authorised them.
Complaining: if you think we have handled your data badly, tell us first — we would rather fix it. You also have the right to complain to the data protection authority where you live, for example:
- Canada — the Office of the Privacy Commissioner of Canada; in Quebec, the Commission d’accès à l’information; in Alberta and British Columbia, the provincial Information and Privacy Commissioner.
- United States — your state attorney general; in California, the California Privacy Protection Agency.
- United Kingdom — the Information Commissioner’s Office.
- European Union and EEA — the supervisory authority in your country.
- Australia — the Office of the Australian Information Commissioner. New Zealand — the Privacy Commissioner.
- Anywhere else — your national data protection or privacy authority.
No selling, no sharing for advertising: we do not sell personal information and we do not share it for cross-context behavioural advertising or targeted advertising, as those terms are used in California and other US state laws. There is nothing to opt out of because we do not do it, and we treat a Global Privacy Control signal as that opt-out anyway. We do not collect sensitive information beyond what is described on this page, and we will not discriminate against you for exercising any privacy right.
Deleting your account: you can permanently delete your account and associated data from Settings → Delete Account in the app. When you do, we delete your profile, posts, comments and other account data, and we remove your uploaded images from image storage. Deletion is permanent and cannot be undone. Two things are kept, as set out under How long we keep it: messages you sent stay with the people you sent them to, and content under a safety report is preserved for as long as an investigation or the law requires. Other records are retained only where required by law (for example, transaction records for tax/accounting) or in routine backups that are overwritten on a rolling basis.
Data retention & security
We keep your data while your account is active. When you delete content or your account, the underlying records and uploaded images are removed from our active systems, including from our image storage provider, except as described under How long we keep it. Your password is held by Auth0, never by us, and only as a salted hash; our database is encrypted at rest; traffic is encrypted in transit (HTTPS); and only the people who run the service can reach your data. No method of storage is 100% secure, but we take reasonable measures to protect your information.
If something goes wrong
If a breach of security affects your personal information in a way that is likely to put you at risk, we will tell you and the relevant regulator, without undue delay and within the time the law requires. We keep a record of every breach, whether or not it had to be reported.
Age
This app concerns alcohol and is intended for users of legal drinking age in their jurisdiction. It is not directed to children, and we do not knowingly collect data from anyone under the legal drinking age.
Changes
We may update this policy; material changes will be reflected here with a new date.