Iss. 001 · Doc 02 · Privacy

What we
know about you.

A plain-language read on what Sipstr collects, what we never collect, and what you can take with you when you leave.

§ 01

TL;DR

Sipstr stores the beers you check in, your ratings and notes, the photos you attach, and the rooms you join. We don't sell any of it. We don't run third-party ad networks against your check-ins. You can delete your account from Settings; the data is hard-deleted from the live database within 24 hours.

§ 02

What we collect

  • Account. Email and a display name. Email is used for one-time login codes, never sold or rented.
  • Sign-in provider. If you sign in with Apple or Google, we store the account identifier they give us and the email address they return. With Apple's Hide My Email that is a relay address, not your real one, and we never learn the real one. We never see or store a password.
  • Check-ins. The beer, brewery, your rating, optional notes and photo, and the time you logged it.
  • Where you drank it, if you say so. Tag a check-in as a bar, brewery or festival and we read the phone's coordinate at that moment and keep it as a place on your own private map. Tag it anything else, or nothing, and no coordinate is read. Places are yours alone: name, rename or delete any of them from the Places screen, and deleting one deletes its coordinate.
  • The map around you. Opening the map sends your current position to our server to find what is near you. It answers and forgets: that position is not written down, not attached to your account, and not passed to anyone else.
  • Profile and gameplay. Level progression, badges, and the flavor profile derived from your check-ins.
  • Tap Rooms. The rooms you join and the messages you post in them.
  • Push token. An APNs or FCM token, used only to deliver notifications you opted in to.
  • Device basics. OS version, app version, device model. Used for crash triage.
  • Anonymous usage events. Screen views and feature taps, via PostHog. No identity attached.
§ 03

What we never collect

  • Your contacts. No prompt, no fetch.
  • Your location in the background. We read the phone's position only while the app is open and only for the two things named above. No background tracking, no geofencing, no location on a check-in you did not tag with a place, and no history of where you were between them.
  • Other apps on your phone. No installed-app lists, no calendar, no health.
  • Advertising IDs. No IDFA, no Google AAID, no fingerprinting.
  • Cross-app tracking. No off-app pixels, no third-party SDKs that phone home.

No ads. No data brokers. The product is paid by Pro.

§ 04

How we use it

Run the app. Render your cellar, sync check-ins, surface the right Tap Room when you level up.

Improve it. Aggregate, anonymous usage stats: how many people made it to a given level, which screens crash. Never tied to a name.

Talk to you. Login codes and service notices always. Occasionally, product news by email: what shipped and what is coming. That one is a switch, in Settings, Privacy, under Email, and turning it off stops it without touching the codes and notices you need. We never sell your address and never hand it to an advertiser.

Stay legal. Respond to lawful requests, prevent abuse, enforce our Legal terms.

§ 05

Who processes it on our behalf

We use a small number of vendors, all bound by data-processing agreements that prohibit secondary use:

  • Supabase (EU region). Database, authentication, file storage.
  • PostHog (EU region). Anonymous product analytics.
  • Sentry. Crash reports.
  • Apple. Sign in with Apple, App Store purchases, and APNs notification delivery.
  • Google. Sign in with Google, and FCM notification delivery.
  • Resend. Email delivery. Your one-time sign-in codes reach you through Resend, so they handle your email address every time you log in. They also carry the moderation alert we receive when someone reports a tap room post, which includes the reported message and the usernames involved.
  • OpenAI and Anthropic. Only when you scan a label, enrich a beer you've logged, or ask for a tasting hint (which sends the beer and your taste profile to write it). No name, email, or account ID is sent.
  • Vercel. Hosts sipstr.app.

That's the entire list. If we add a vendor, we update this page and email anyone with an active account before the change takes effect.

§ 06

Tap Rooms are public to members

Anything you post inside a Tap Room, meaning your messages, is visible to every other member of that room.

Messages are encrypted in transit and stored encrypted on our servers. This isn't end-to-end encryption: we hold the keys, so we can technically read messages to comply with abuse reports or lawful process. We don't read them otherwise, and any such access is logged.

§ 07

Legal drinking age, your country

Sipstr is a beer log. You must be of legal drinking age in your country to use it; 21 in the United States; 18 in Sweden and most of Europe.

If we discover an account belongs to someone under the legal age, we delete it and notify the email on file.

§ 08

You own the data

  • Delete. Settings → Delete account. Removed from the live database within 24 hours; backups roll off according to our hosting provider's retention schedule.
  • Correct. Edit your profile and check-ins directly. Beer catalog corrections can be submitted from the beer page once you reach the correction unlock level.
  • Access, export, object. Download a full copy of your data anytime from the menu → Export beer history. The JSON has your account, every check-in with private notes, your tap room posts, badges, flavour profile and purchases; the CSV is your check-in log. Or email hello@sipstr.app.
  • Complain. EU residents may complain to their national data protection authority.
§ 09

If this changes

We'll email every active account at least 14 days before any material change takes effect. Trivial wording fixes don't need a notice.

§ 10

Talk to a human

All inquiries: hello@sipstr.app

Sipstr · Sweden