Draft. 12 details on this page are still being finalized (highlighted below).
Drinkyin Privacy Policy
Effective date: [[EFFECTIVE_DATE]]
Last updated: [[EFFECTIVE_DATE]]
Version: 1.0
This Privacy Policy explains how [[LEGAL_ENTITY]] ("Drinkyin," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use:
- the Drinkyin mobile app for iOS and Android;
- the Drinkyin web app / installable PWA at https://drinkyin.com;
- the Drinkyin Business Console — Business Accounts, currently in beta — used by shops and brands; and
- any related websites, emails, and support channels (together, the "Service").
Washington and Nevada residents: some of the information you enter into Drinkyin — hydration, nutrition intake, caffeine, alcohol, and the allergy or "watch out for" tags you save — is treated as consumer health data under the Washington My Health My Data Act and Nevada SB 370. Those rights and our specific commitments are described in our separate Consumer Health Data Privacy Policy, which forms part of this Policy.
0. The short version
This summary is for orientation only; the numbered sections below control.
| Question | Answer |
|---|---|
| Do I need an account? | No. Drinkyin works fully offline with no account. In that mode your drink log never leaves your device. |
| What happens if I sign in? | Your logs, profile, and app settings sync to our cloud so you can use more than one device. |
| Can other people see my profile? | Not in this version. Our database lets a signed-in account read only its own profile row, so your username, display name, and avatar are not visible to other users. The one exception is a Business Account: the @username and verified badge of the account that publishes a menu are shown with it. |
| Is my drink log public? | No, private by default. A log becomes public only when you mark it public, which is possible only in versions of Drinkyin that include the community feed. Public check-ins are readable by anyone using Drinkyin, not only your followers. |
| Do you sell my data? | No. We do not sell personal information, do not "share" it for cross-context behavioral advertising, and run no advertising or analytics SDKs. |
| Do you track me across other apps and sites? | No. There is no ad identifier collection, no App Tracking Transparency prompt, no third-party trackers or advertising cookies. |
| Where is my location stored? | We do not store your device's location. Coordinates are sent to mapping and weather providers only at the moment you search for shops or load the weather. Shops you save to your wishlist (name, address, and the shop's coordinates) sync with your account. |
| Can I delete everything? | Yes. Delete your account and everything synced to it in the app (Settings → Account → Delete account), clear a device with Settings → Data → Clear data / Reset, or email us. See §11, §13, and our account deletion page. |
| Who can see my data at a shop or brand? | Businesses see counts of public check-ins only (how many public check-ins, how many distinct people). They never see private logs or identify individuals. |
| Can I add a business? | Yes — Business Accounts are in beta. Sign in to a personal account, then add one in Settings. The business's name, menu, and shops are public; your own drink log stays private. To confirm you own the business we check a public channel it controls, never ID documents (§3). |
1. Scope and roles
This Policy applies to personal information we control as a business (under US state privacy laws) and as an organization (under Canadian privacy law).
- Consumers. If you use Drinkyin to log drinks, you are a consumer/user.
- Business accounts (beta). A Business Account is added to an existing personal account: you sign in and choose a username first, then add a shop or brand. This Policy also covers the information you give us about the business, its locations, and how you show that you control it. Your own drink logs stay private exactly as they are for any other user.
- Not covered. This Policy does not apply to third-party services you reach through Drinkyin (for example a map opened in Google Maps), or to information you post publicly, which by definition is no longer private.
We are not a HIPAA covered entity or business associate, and Drinkyin is not a medical device or a healthcare service. See §15.
2. Two ways to use Drinkyin
Drinkyin is designed local-first, and the difference matters for your privacy.
2.1 Local mode (no account)
You can install and use Drinkyin without creating an account, without giving us an email address, and without any of your drink data reaching our servers.
In this mode, everything — your logs, favorites, wishlist, ratings, settings, profile name and avatar — is stored only in your device's local storage (AsyncStorage on iOS/Android, localStorage in the browser). We cannot read it, cannot recover it, and cannot delete it for you. Uninstalling the app or clearing your browser's site data deletes it permanently.
Even in local mode, certain features reach the internet when you use them (searching the drink database, looking up a barcode, finding nearby shops, loading weather, loading brand logos, loading a map thumbnail). Those requests are described in §5 and §8.
2.2 Account mode (optional cloud sync and community)
If you create an account, we store a copy of your data on our servers ([[HOSTING_REGION]], operated by Supabase) so that you can:
- sync between devices and restore after reinstalling;
- claim a
@username(not shown to other users in this version — see §8.1); - run a Business Account, whose business name, shops, and menu are public;
- and, in versions of Drinkyin that include the community feed, follow other people and see a feed of public check-ins.
Signing in is the moment your data starts leaving your device. You can sign out at any time, and you can ask us to delete the cloud copy (§16). Signing out does not delete the local copy on that device; Settings → Reset does.
3. Information you provide
| What | When | Where it goes |
|---|---|---|
| Email address | Sign-up and sign-in | Our servers (authentication). Also used to send you a one-time sign-in code. |
| Password | Sign-up, sign-in, password reset | Stored only as a salted cryptographic hash by our authentication provider. We never see your plaintext password. |
Username (@handle) | When you claim one | Our servers. Not visible to other users in this version (§8.1); if you run a Business Account it is shown next to that business's menu items. |
| Display name and avatar | Profile setup | Our servers, so they follow you across your devices. Not visible to other users in this version (§8.1). An avatar can be a built-in shape or a photo you choose from your device. |
| Drink logs | Every time you log a drink | Device always; our servers if you are signed in. Each log contains: the drink name and emoji, category (including Beer and Alcohol), volume in ml, price if you enter one, the timestamp, a public/private flag, and a nutrition snapshot taken at log time (calories, sugar, caffeine, sodium, and, where known, fat, saturated and trans fat, carbohydrates, fiber, protein, ABV, electrolytes, potassium, calcium, iron, added sugar, magnesium, taurine, and vitamins B3, B6, B12, C and D). |
| Hydration and nutrition goals | Settings → Personal | Device; our servers if signed in. |
| Taste preferences | Onboarding and Settings | Device; our servers if signed in. |
| Allergy / "watch out for" tags (e.g. caffeine, dairy, nuts) | Settings → Personal | Device; our servers if signed in. Treated as sensitive information — see §6. |
| Favorites, wishlist, star ratings, collection, badges | As you use the app | Device; our servers if signed in. |
| Saved places ("shops I want to visit") | When you save a place from Discover | Device; our servers if signed in. Includes the place name, category, address, and its coordinates. |
| Drinks you create (manual entry or barcode scan) | When you add one | Device; our servers if signed in. If you add a drink as a business, it is published to the shared drink database. |
| Reminder settings and alarms | Settings | Device; our servers if signed in. |
| Routines (a drink, its volume, and the time and weekdays to log it automatically) | Settings → Routines | Device; our servers if signed in. The drinks a routine logs are ordinary drink logs (see above). |
| Appearance and privacy preferences | Settings | Device; our servers if signed in. |
| Business application details | Adding a Business Account | Our servers: business name, business type (independent spot or brand), a contact phone or email you provide, and any note you write to support a brand application. Not shown to other users. |
| Business ownership verification | When you ask for the verified badge, or apply as a brand | Our servers: the channel you choose (the business's website, its social account, or the phone number on its public map listing), the public link you give us, the verification code we issue to your account, and our decision with any note explaining it. We look at the public page you link to; with the phone method we call the number shown on that public listing, never one you give us, and we do not record the call. We do not ask for ID or business documents. Not shown to other users — they only see the verified badge. |
| Business locations and menus | Business Console | Our servers; publicly visible in the app: the business name, the account's @username and whether it is verified, shop names, addresses, opening hours, and phone numbers, and menu items with their sizes, prices, nutrition values, ingredients, and photo links. |
| Support correspondence | When you email us | Our email systems: your address, message, and anything you attach. |
We do not ask for and do not want: government ID numbers, payment card numbers, precise health records, biometric identifiers, or your contacts list. Drinkyin has no in-app purchases and processes no payments as of this version.
4. Information collected automatically
- Local storage. We store the app's state on your device as described above. On the web this uses
localStorageplus a service worker cache so the app works offline. These are strictly necessary storage mechanisms, not advertising or analytics cookies. We set no advertising cookies and no third-party tracking pixels. - Authentication session token. When signed in, a session token is stored on your device so you stay signed in.
- Server logs. Our hosting and database providers automatically record ordinary technical request data — IP address, timestamp, user agent, requested path, and error codes — for security, abuse prevention, and debugging. These logs are retained for a short period (30 days) and are not used to build a profile of you.
- Crash and diagnostic data. Apple and Google may provide us aggregated crash reports if you have enabled sharing with them at the OS level. That sharing is controlled by your device settings, not by us.
We do not use any advertising SDK, attribution SDK, or third-party product analytics SDK. We do not collect the IDFA, the Android Advertising ID, or any cross-app identifier, and we therefore do not present an App Tracking Transparency prompt.
5. Device permissions and what each one actually does
Drinkyin asks for a permission only at the moment the matching feature is used, and every one of them is optional — declining disables that feature and nothing else.
| Permission | Why | What leaves your device |
|---|---|---|
| Location (approximate or precise) | Find drink shops near you; show local weather so the app can nudge you to drink more on a hot day | For search and weather: coordinates are sent at that moment to the mapping and weather providers in §8 to get results back. We do not store your device's location on our servers. |
| Camera | Scan a product barcode | The camera image is processed on your device. Only the decoded barcode number is sent to the product database (Open Food Facts). We never upload camera frames. |
| Photo library | Choose an avatar image | The image you pick is stored on your device, and is uploaded to our servers only if you are signed in, so that it follows you to your other devices. In this version it is not shown to other users. |
| Motion sensors | Tilt the water surface animation on the home screen | Nothing. Sensor readings are used in the render loop and are never stored or transmitted. |
| Notifications | Drink reminders you configure | Nothing. Reminders are local notifications scheduled on your device. We operate no push-notification service and collect no push token. |
| Health Connect (Android, optional) | Mirror how much you drank into Google Health Connect so other health apps you use can count it toward your water intake. Only the volume is written — calories, sugar, caffeine and sodium never leave Drinkyin | Data is written to Health Connect on your device, under permissions Android grants you and you can revoke in system settings. We do not read anything back from Health Connect, and we never share Health Connect data with third parties or use it for advertising. |
You can change or revoke any of these at any time in your device's system settings. Revoking one does not delete data already saved.
6. Sensitive personal information
Some of what Drinkyin holds is more sensitive than the rest, and we treat it accordingly:
- Health-adjacent information — hydration and nutrition intake, caffeine, alcohol consumption, your allergy or "watch out for" tags, and your personal intake goals. Under Washington's My Health My Data Act and Nevada's SB 370 this is consumer health data; under several US state laws it can be sensitive personal data; under Canadian law it attracts a higher standard of consent. See the Consumer Health Data Privacy Policy.
- Precise geolocation — used only as described in §5, and never stored on our servers.
- Account credentials — your email and password hash.
We use sensitive information only to provide the features you asked for, to keep your account secure, and for the limited purposes permitted by Cal. Civ. Code § 1798.121(a) (such as security and preventing fraud). We do not use it to infer characteristics about you, and we do not use or disclose it for any purpose that would give you a right to limit that use. We do not sell it, share it for advertising, or use it to train machine-learning models.
We do not collect biometric identifiers, genetic data, immigration status, racial or ethnic origin, religious beliefs, union membership, or the contents of your mail, email, or messages.
7. How we use information
We use personal information only for these purposes:
- To run the Service — save and display your logs, calculate your hydration ring and daily nutrition totals, build your collection and badges, and show your history and weekly report.
- To sync your data across your devices when you sign in, and to restore it after a reinstall.
- To operate the community, in versions of Drinkyin that include it — show your public check-ins in the feed, let people find your profile by username, and maintain the follow graph. This version does none of that: the feed is turned off and profiles are readable only by their owner.
- To answer your requests — support email, privacy rights requests, and confirming that a Business Account controls the business it names (§3).
- To keep the Service safe — detect and prevent abuse, spam, credential stuffing, and fraudulent business claims; enforce our terms.
- To improve the Service — diagnose bugs and fix them, using error logs and what you tell us. We do not run behavioral analytics on your drink log.
- To comply with law — respond to lawful requests, keep required records, and establish or defend legal claims.
- To send service messages — sign-in codes, security notices, and material changes to this Policy. We send marketing email only if you opt in, and every marketing email carries a working unsubscribe link (§17.4).
Automated decision-making. Drinkyin makes no decision about you that produces a legal or similarly significant effect. The reminders, nudges, and goal alerts you see are simple rules applied to numbers you entered, and you can turn all of them off.
No AI training on your data. We do not use your logs, profile, photos, or health-adjacent data to train, fine-tune, or evaluate machine-learning models, and we do not send them to any third-party AI service.
Legal bases (where required). For users in jurisdictions that require them, we rely on: performance of our agreement with you (running the Service); your consent (optional permissions, health-adjacent data, marketing, and any public posting); our legitimate interests (security, debugging, preventing abuse); and compliance with legal obligations.
8. When information leaves your device
We disclose personal information only in the situations below. We never sell it, and we never disclose it to data brokers or advertisers.
8.1 To other users — because you chose to publish it
- A drink log is private by default, and this version gives you no way to make one public: the community feed is turned off, so the app records every log as private, including any older log of yours that was public before. In versions that include the feed, a log you mark public is readable by anyone using Drinkyin, not only by people who follow you, and it contains the drink, volume, nutrition snapshot, time, and your profile.
- Your profile — username, display name, and avatar — is not readable by other users in this version. Our database rules let a signed-in account read only its own profile row, and no screen shows anyone else's profile. (Until 2026-09-19 profiles were readable by anyone; they are not any more.) If we re-enable the community feed, we will update this Policy first, and only the columns the feed needs — username, display name, avatar — would become readable.
- Your follower and following lists are readable only by you and by the other person in each pair.
- Business listings — a Business Account's business name,
@username, verified status, shops (name, address, hours, phone), and menu — are readable by anyone using Drinkyin. Its application and verification records are not. - The place attached to a log is never published, even for a public log.
- Making a log private again removes it from the feed going forward, but we cannot recall copies other people already saw or captured.
8.2 To businesses — aggregate counts of public check-ins only
If a shop or brand operates a Business Console, it can see, for its own menu items: how many public check-ins those items received in a recent window, and how many distinct people made them. This is enforced at the database level so that private logs are invisible to businesses by construction. Businesses do not receive your identity, your email, your other drinks, your location, or any private log.
8.3 To service providers who process data on our behalf
| Provider | What it does | What it receives |
|---|---|---|
| Supabase (US, [[HOSTING_REGION]]) | Authentication and database | Your email, password hash, profile, synced logs, synced app state, business records, and request metadata including IP address |
| Vercel | Hosting for the web app / PWA | Standard request logs: IP address, user agent, requested path |
| Expo (Expo Application Services) | Builds and signs the mobile app | Build artifacts; no end-user personal information |
| [[EMAIL_PROVIDER]] | Sends sign-in codes and service email | Your email address and the message content |
These providers act as our service providers / processors: they are bound by contract to use the information only to perform services for us, and never for their own purposes.
8.4 To independent third parties whose services you invoke
When you use certain features, your device contacts these services directly. They are independent controllers of what they receive, under their own policies, and we receive nothing back about you.
| Service | Triggered by | What it receives |
|---|---|---|
| Open Food Facts | Scanning a barcode | The barcode number and your IP address |
| OpenStreetMap (Overpass, Nominatim) | Searching for nearby shops; naming a saved place | Approximate coordinates or your search term, and your IP address |
| Open-Meteo | Weather-based hydration advice | Coarse coordinates and your IP address |
| Google Places API (Text Search) | Searching for nearby shops, in builds configured with a Google key | Your search term, coarse coordinates, and your IP address. When Google is unavailable the search falls back to OpenStreetMap |
| Google Maps Static API | The map thumbnail on a place card | Coordinates and your IP address |
| Google favicon service | Fetching a brand logo | The brand's website domain and your IP address |
| Google Health Connect (Android) | Turning on health mirroring | Hydration records — volume only — written locally on your device |
| Apple App Store / Google Play | Installing and updating | Handled entirely by Apple and Google under their own policies |
If you would rather not contact these services, do not use the corresponding feature; the rest of Drinkyin continues to work.
8.5 Legal, safety, and corporate events
We may disclose information if we reasonably believe it is required to comply with a law, subpoena, warrant, or court order; to enforce our terms; to investigate fraud or abuse; or to protect the rights, safety, or property of anyone. Where we are legally permitted to, we will tell you first.
If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy, and you will be able to delete your account first.
9. We do not sell or share your personal information
We have not sold personal information, and have not shared it for cross-context behavioral advertising, in the twelve months before the effective date of this Policy, and we do not do so now. This includes the personal information of consumers we know to be under 16, for which US state laws would require opt-in consent — we do not have such a program at all.
We honor the Global Privacy Control (GPC) and other browser-level opt-out preference signals on our web app. Because we do not sell or share information in the first place, an opt-out signal produces no change in what we do; we recognize it as a valid opt-out request regardless.
10. Security
We protect personal information with measures appropriate to its sensitivity, including:
- TLS encryption in transit for every network request, with a hard timeout on cloud calls;
- Encryption at rest for our database and file storage;
- Row-Level Security in the database, so a signed-in account can read and write only its own logs, its own app state, and rows explicitly marked public;
- Salted password hashing by our authentication provider — we never store or see plaintext passwords;
- Account-switch isolation on shared devices, so one account's local data cannot be merged into another account's cloud data;
- Least-privilege access — administrative access is limited to personnel who need it, and privileged database keys are never shipped in the app.
No system is perfectly secure. Please use a strong, unique password and keep your device locked. If we become aware of a security incident affecting your personal information, we will notify you and the relevant regulators as required by applicable US state breach-notification laws, Canadian federal and provincial law (including reporting to the Office of the Privacy Commissioner of Canada where there is a real risk of significant harm), and, for Québec residents, the Commission d'accès à l'information.
11. Retention and deletion
| Data | How long we keep it |
|---|---|
| Local, on-device data (no account) | Until you delete it — Settings → Data → Clear data / Reset, clearing site data, or uninstalling. We never have a copy. |
| Account and profile | While your account exists |
| Synced logs and app state | While your account exists, or until you delete the individual entries |
| Public check-ins in the feed | Shown in the feed for 24 hours; the underlying log is kept until you delete it or make it private |
| Business application and ownership-verification records | While the business account exists. Deleting your account deletes them immediately, together with your shop locations and menu items (see below). |
| Server and security logs | 30 days |
| Support email | 24 months |
| Backups | Rolling backups are overwritten within 30 days |
You can delete your account yourself at any time in the app (Settings → Account → Delete account). That removes your profile, logs, synced state, follows, and business records from our live systems immediately. If you ask us by email instead, we do the same within 30 days of verifying the request. Either way, copies in backups are removed as the backups cycle out. We may retain a minimal record that a deletion request was made and fulfilled, which the law requires us to keep, and anything we must keep to comply with a legal obligation or to resolve a dispute.
12. Children and teens
Drinkyin is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has given us personal information, contact us at [[PRIVACY_EMAIL]] and we will delete it promptly.
Users between 13 and 15 may use Drinkyin, but should do so with a parent's involvement. We do not sell or share the personal information of any user, and specifically not of any user we know to be under 16.
Alcohol. Beer and Alcohol are categories in the drink database. Drinkyin does not sell alcohol or facilitate its purchase. Alcohol logging and alcohol-related content are intended only for users who are of legal drinking age where they live — 21 in the United States, and 18 or 19 depending on the province in Canada. By logging an alcoholic drink you confirm you are of legal drinking age in your jurisdiction. Do not use Drinkyin to encourage anyone under legal drinking age to drink.
13. Your controls inside the app
You do not need to email us to exercise most of your choices:
- Delete a log — from Today's list or from History.
- Keep logs private — logs are private by default. In versions of Drinkyin that include the community feed, every log also has a privacy toggle, Settings lets you make private the default for new logs, and you can hold a public log back by one day.
- Turn off Health Connect mirroring — Settings → Privacy & Health, or revoke it in Android system settings.
- Turn off reminders — Settings → Drink Reminders.
- Pause or delete a routine — Settings → Routines. Drinks it already logged stay in your history until you delete them.
- Edit or remove your profile, allergy tags, and goals — Settings → Personal.
- Sign out — stops syncing on that device and clears Drinkyin's data there.
- Clear local data — Settings → Data → Clear data / Reset. This clears the copy on that device; if you are signed in, your synced data returns on the next sync.
- Delete your account — Settings → Account → Delete account permanently deletes your account and everything synced to it, immediately. See our account deletion page.
- Revoke any OS permission — your device's system settings.
14. Not medical, nutrition, or safety advice
Drinkyin is a self-tracking and social tool for general wellness. Its hydration goals, nutrition totals, weather nudges, and goal alerts are informational only. They are not medical advice, not a diagnosis, and not a substitute for a qualified professional. Nutrition values are snapshots taken from public databases and from businesses, and may be incomplete or inaccurate. Never disregard professional medical advice because of something you saw in Drinkyin, and consult a professional before changing your fluid, caffeine, or alcohol intake — particularly if you are pregnant, have a medical condition, or take medication.
15. Interstate and international transfers
We operate from [[COMPANY_COUNTRY]] and store personal information on servers located in the United States ([[HOSTING_REGION]]). If you use Drinkyin from Canada or elsewhere, your personal information will be transferred to, stored in, and processed in the United States, where privacy laws differ from those in your country and where courts, law enforcement, or national security authorities may be able to obtain access under the laws of that country.
For Québec residents, we have conducted a privacy impact assessment of this transfer as required by Law 25 and have contractual protections in place with our service providers. By using the Service you acknowledge this transfer.
16. Your privacy rights in the United States
16.1 Rights available to you
Depending on where you live, you may have some or all of the following rights. We extend the core rights below to every US user, regardless of state.
- Know / access — what personal information we collect, the categories of sources, the business purposes, the categories of third parties we disclose to, and the specific pieces of information we hold about you.
- Portability — receive your information in a portable, machine-readable format.
- Correct — fix inaccurate personal information.
- Delete — have your personal information deleted, subject to legal exceptions.
- Opt out of sale, of sharing for cross-context behavioral advertising, and of profiling with legal or similarly significant effects. We do none of these.
- Limit the use and disclosure of sensitive personal information. We already use it only for the permitted purposes in §6.
- Withdraw consent, including consent to the processing of consumer health data.
- Non-retaliation / non-discrimination — we will never degrade the Service or charge you differently because you exercised a privacy right.
- Appeal — if we deny a request, you may appeal (§16.4).
These rights come from, among others, the California Consumer Privacy Act as amended by the CPRA, and the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Rhode Island, Indiana, Kentucky, and other states as their laws take effect, plus the Washington My Health My Data Act and Nevada SB 370 for consumer health data.
16.2 California notice at collection
In the twelve months before the effective date, we collected the following statutory categories of personal information, for the business purposes in §7, from the sources in §§3–4, and disclosed them for a business purpose only to the recipients in §8:
| CCPA category | Collected? | Examples in Drinkyin |
|---|---|---|
| A. Identifiers | Yes | Email address, account ID, username, display name, IP address |
| B. Customer records (Cal. Civ. Code § 1798.80(e)) | Yes | Name, email, business contact details |
| C. Protected classifications | No | — |
| D. Commercial information | Limited | Drinks logged, prices you enter, wishlist and favorites |
| E. Biometric information | No | — |
| F. Internet or network activity | Yes | Server request logs, feature usage needed to run the app |
| G. Geolocation data | Yes | Coordinates used at the moment of a search or weather lookup, not stored |
| H. Audio, electronic, visual, thermal, olfactory, or similar | Limited | Avatar photo you upload; camera used locally for barcode scanning |
| I. Professional or employment information | Limited | Business account contact details and ownership-verification records |
| J. Non-public education information | No | — |
| K. Inferences | No | We draw no profile or inference about you |
| L. Sensitive personal information | Yes | Account credentials; precise geolocation (device-only); health-adjacent intake and allergy tags |
We did not sell or share any of these categories. We retain each category for the periods in §11.
California "Shine the Light" (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct marketing purposes.
16.3 How to make a request
Email [[PRIVACY_EMAIL]] with the subject line "Privacy Request", or use the form at [[PRIVACY_REQUEST_URL]]. Tell us which right you want to exercise and which email address your account uses.
- Verification. We verify you by confirming control of the email address on the account, and by matching the details you give us against our records. For deletion and for specific pieces of information we may ask for a second confirmation. We will not create a new account or ask for extra identity documents just to verify you.
- Timing. We confirm receipt within 10 business days and respond within 45 days, extendable once by another 45 days where permitted, with notice to you.
- Authorized agents. An agent may submit a request with your signed written permission; we may still contact you to confirm.
- Deleting your account needs no request. Settings → Account → Delete account does it immediately; see our account deletion page.
- No account? If you have never signed in, we hold nothing about you to access or delete — your data is on your device, and Settings → Data → Clear data / Reset removes it.
16.4 Appeals
If we deny your request, we will explain why. You may appeal within 60 days by replying to our decision or emailing [[PRIVACY_EMAIL]] with the subject "Privacy Appeal". We will respond within 45 days with our decision and the reasons for it. If we deny the appeal, we will give you a method to file a complaint with your state Attorney General. California residents may also contact the California Privacy Protection Agency.
17. Your privacy rights in Canada
We handle personal information about Canadian users in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where they apply, Québec's Law 25 (as it amends the Act respecting the protection of personal information in the private sector), Alberta's PIPA, British Columbia's PIPA, and Canada's Anti-Spam Legislation (CASL).
17.1 Consent
We collect, use, and disclose personal information with your knowledge and consent, except where the law permits otherwise. Consent is:
- Express for anything sensitive — health-adjacent data, precise location, publishing a check-in, and marketing email. You give it by an affirmative action, such as turning on a setting or marking a log public.
- Implied for the ordinary operation of a feature you have chosen to use.
You may withdraw consent at any time, subject to legal and contractual restrictions and on reasonable notice. Withdrawing consent may mean a feature can no longer work — for example, withdrawing consent to cloud sync means signing out and using Drinkyin in local mode. To withdraw consent, use the in-app controls in §13 or email [[PRIVACY_EMAIL]].
17.2 Access, correction, and portability
You may ask for access to the personal information we hold about you, an account of how it has been used and to whom it has been disclosed, and correction of anything inaccurate or incomplete. We respond within 30 days of receiving a request, free of charge in ordinary cases; if a request would take longer or require a fee, we will tell you in advance. Where Law 25 applies, you may also ask us to give you your computerized personal information in a structured, commonly used technological format, or to send it to another organization.
17.3 Québec (Law 25)
- Our Privacy Officer is [[PRIVACY_OFFICER_NAME]], [[PRIVACY_OFFICER_TITLE]], reachable at [[PRIVACY_EMAIL]] and [[MAILING_ADDRESS]]. The Privacy Officer is accountable for our compliance.
- Privacy settings by default. Drinkyin's settings are configured for the highest level of confidentiality by default: no account is required, and drink logs are private unless you publish them.
- Technology that identifies, locates, or profiles you. We use none for advertising or profiling. Where a feature uses your location, we tell you before it activates and you can turn it off (§5, §13).
- De-indexing and cessation of dissemination. You may ask us to stop disseminating your personal information, or to de-index a link to it, where the law provides.
- Confidentiality incidents are recorded in a register and reported to the Commission d'accès à l'information and to affected individuals where there is a risk of serious injury.
- Complaints. You may complain to the Commission d'accès à l'information du Québec.
17.4 CASL — commercial email
We send marketing or promotional email only with your express consent, and every such message identifies us, gives our mailing address, and contains a working unsubscribe mechanism that we honour within 10 business days. Transactional messages — sign-in codes, security alerts, and notices about this Policy — are not marketing and are sent as part of the Service.
17.5 Complaints
If you are not satisfied with our response, you may complain to:
- the Office of the Privacy Commissioner of Canada — priv.gc.ca;
- the Commission d'accès à l'information du Québec — cai.gouv.qc.ca;
- the Information and Privacy Commissioner of Alberta or of British Columbia, if you live in those provinces.
18. Other regions
Drinkyin is offered from and directed to the United States and Canada. If you use it from elsewhere, you do so on your own initiative and are responsible for compliance with local law. We may add region-specific terms — for example for the UK, the EEA, or Australia — in a future version of this Policy.
19. Changes to this Policy
We will update this Policy when our practices change. The "Last updated" date at the top always reflects the current version, and we keep prior versions available at [[POLICY_ARCHIVE_URL]].
For material changes — a new category of personal information, a new purpose, a new disclosure, or anything that would reduce your privacy — we will give you notice inside the app and by email (if we have your address) at least 14 days before the change takes effect, and, where the law requires consent, we will ask for it rather than assume it.
20. Contact us
[[LEGAL_ENTITY]]
Attention: Privacy Officer — [[PRIVACY_OFFICER_NAME]]
[[MAILING_ADDRESS]]
Email: [[PRIVACY_EMAIL]]
General support: [[SUPPORT_EMAIL]]
We aim to answer every privacy question within 5 business days, and always within the statutory deadlines in §16 and §17.
This document describes Drinkyin's actual data practices as implemented in version 1.0.0 of the Service. It is not legal advice. Have counsel qualified in your jurisdiction review it before you publish it or submit it to the App Store or Google Play.