Whiskey Library App Privacy
Whiskey Library app privacy
Effective September 30, 2026.
Whiskey Library LLC operates the Whiskey Library app. This notice explains how we handle information when you use the app. It supplements our website privacy policy, which also covers the store and checkout. For privacy questions or requests, email support@whiskeylibrary.com or visit app support.
Your account and email
We use your email address and authentication information to create and secure your account. Supabase provides authentication and the app database. Resend delivers transactional account emails, including six-digit verification, sign-in and password-reset codes. The email provider processes the recipient address, message content and delivery information. A password-reset code must be verified in the app before you can set a new password. Never share your password or verification codes with another person.
Your profile can include your display name, username, profile photo, optional biography and whiskey preferences. We assign a member number that appears in member profiles and community activity. The app owner can correct numbers or swap two members’ numbers; account identity and access rights stay with the account. A member number is not a rating or measure of expertise.
Your private library and custom bottles
Your collection and journal can include bottles you own or want, ratings, purchase details, tasting descriptions, preferences and photos. Private infinity-bottle records include blend names, source bottles and measured pour amounts; recorded pours do not change the source bottle’s fill level. The app stores account data on your device and synchronizes supported records with our Supabase backend when connected. Offline changes may remain on the device until synchronization succeeds. Private collection and journal records use account-based access controls; private tasting photos use account-restricted storage.
When you add a custom bottle, its details and supported photos sync privately with your account. Adding it does not publish it to the shared catalog. Guided bottle drafts automatically save their progress, entered details and selected photos on this device for your signed-in account, including when offline. Supported draft records and four source photos (front, back, top and label close-up) also synchronize to account-restricted hosted storage when saved online. Unsynchronized changes are not a cloud backup and may be lost if the app or its local data is removed. Choosing Build profile sends those photos through our authenticated backend to Google Gemini for bottle-fact extraction and studio-image generation. Product identity text may be sent to Google Search for attributable supporting sources. Generated facts and images can be inaccurate; review them before saving.
Keep private leaves a draft accessible only through your account. Submit for public catalog review explicitly shares its bottle facts, four source photos and studio image with moderators. It does not share purchase information or personal collection notes. Moderators can correct details and approve a public catalog bottle and studio image. Source photos remain restricted to the submitter and reviewers; approved studio images have public links. Canonical catalog linking preserves your private draft and existing collection history. Device backups and photos you separately keep in your photo library are governed by your device and backup settings.
Account-based protection is not end-to-end encryption. Authorized operators and service providers can process hosted data to run and maintain the service.
Community and public images
When you publish a post, comment or bottle review, we store the content and account information needed to display it. Other signed-in members can see your shared content and public profile fields: display name, username, member number, profile photo, collection count, follow counts and follower/following lists. Your private bottle list, journal, purchase details, email and whiskey preferences are not included in the public profile.
Your biography is private by default. To share it, enable “Show bio on my public profile” in Edit profile and save. Turning that setting off removes it from subsequent public-profile responses. Your name and profile photo remain shared profile fields.
Profile photos and some photos published by older app versions have public links. Anyone who obtains those links can view or save the image. New community-post photos use account-restricted storage; access through the app follows post visibility and blocking rules. Replacing a profile photo updates its reference and attempts to remove the old hosted image; an old link can remain available until cleanup succeeds. People may keep copies of content you share.
We store follows, votes, blocks, abuse reports and moderation decisions to operate the community. Authorized moderators and the app administrator can review reports and remove posts or comments. The administrator can inspect an audit log recording the acting moderator or administrator, action, target reference, time and reason. Minimal actor references and labels can remain after account deletion for accountability. We also retain restricted operational records for account-control validation and verification, including actor and target references, action, reason, timestamps, affected storage bucket and object paths, and cache-invalidation acknowledgements. These records are separate from the photo files and can remain after a test account or other account is deleted. The administrator can ban or delete accounts. A ban restricts account access and hides community content; account-owned photos are moved to restricted storage so they can be restored if the ban is lifted. We request invalidation of known hosted image-cache entries and wait for the required propagation interval before confirming completion. Restrictions and cache changes can take time; an interrupted or uncertain action remains pending verification. Deletion is separate from banning and removes the authentication account, linked account data and account-owned hosted photos, subject to the retention details below. A normalized email address remains blocked from registration until the administrator removes its ban, including after account deletion. Members can still use their own Delete Account action described below. Contact support to request review of an account restriction. Copies already downloaded by other people or cached outside the service cannot be recalled. Support and feature requests are used to respond and maintain the app. The app does not access your device address book.
Shared collections, direct messages and activity notifications
The bottle list is private by default. Account settings let you enable “Share my catalog bottles with members.” This shares the catalog bottles you own with signed-in members; custom bottles, quantities, ratings, notes, purchase details and your private photos remain private. Blocked members cannot view the shared collection. Turning sharing off prevents subsequent collection access through the app.
Direct-message text, participants and timestamps are stored in our backend. App access is limited to conversation participants; sending requires mutual followers, and blocking prevents access through the conversation. This is account-based protection, not end-to-end encryption. Authorized operators and service providers can process hosted data to operate the service. Deleting either participant’s account removes the hosted conversation; other people may retain copies outside the app.
Replies, follows, mentions and direct messages create account-specific in-app notifications. We store event references and read status; access follows current content visibility, conversation membership and blocks. This release does not send push or email notifications for these activities.
Bottle lookup and optional AI photos
Barcode lookup uses available local, online catalog and store records. An attributed offline product reference may help identify a product name and size without sending the code online. Automatic barcode lookup does not ask AI to guess a barcode match. A manual barcode match you confirm is saved for your account on that device; it does not change the shared catalog.
Online name searches may send product names and related text through our authenticated backend to Google Gemini for an unverified name suggestion. You must select an existing catalog bottle before using an AI suggestion. Enter product information only. Remote bottle images are loaded from the image hosts identified in catalog or store results; those hosts receive ordinary connection information such as your IP address.
AI label recognition asks permission before sending your label photo and detected text through our backend to Google Gemini. Photo sharing starts off and can be withdrawn in Profile settings. Declining or withdrawing it prevents future label-photo sharing; it does not disable online name or barcode lookup or recall earlier requests. Avoid including faces, documents or personal information in label photos.
Our recognition endpoint does not save submitted label images or prompts to the app database or photo storage. Google’s processing, retention and use of inputs and outputs depend on its service configuration and Gemini API terms; the app does not promise that Google retains no data or never uses it to improve models. Your email and Supabase account ID are not explicit Gemini prompt fields, but submitted text or photos can contain identifying information. AI results can be inaccurate.
Public store catalog and customer reviews
This release reads public product details and bottle images from Shopify catalog services. Purchasing and checkout are not available in the app. It does not import store orders or subscriptions, or match your app email to Shopify or Recharge customer records. App purchasing and email-based customer linking are disabled for this release.
The app imports Judge.me customer rating summaries supplied with public Shopify catalog products and stores the latest rating/count snapshot with product identity, source and capture time in our database. The app labels these Store customer reviews, separately from app-community ratings. The rating-summary pipeline does not import individual review text or reviewer identity. When a complete published store-review export is available, a separate archive can store the public review rating, title, text, publication date and provider review identifier. It excludes reviewer names, emails and order details. Products without an imported archive continue to show only the summary. Loading these reviews does not submit an app review or your app email to Judge.me.
The separate Whiskey Library website and store use analytics, advertising retargeting and audience synchronization. These services may use contact identifiers, shopping activity and browser or device information to measure advertising or reach customers on other services. Those website pages and checkout use the website’s privacy and cookie controls; they are not an app purchasing flow in this release. See the website policy and Shopify’s privacy policy for these practices and available choices. Deleting your app account does not cancel a paid bottle subscription or erase the store’s transaction records. Manage subscriptions through the store or contact support.
Service activity and security
We record account-linked operation categories, time windows and request counts to enforce service limits and prevent abuse. Authentication, email, hosting and catalog services also process connection, delivery and operational information to provide and troubleshoot their services. The native app contains no advertising SDK or advertising identifier collection; this does not describe the separate store’s cookies or marketing integrations.
We use encrypted network connections and account-based access controls. Access to your device, email account and exported or shared copies also affects your privacy. Service providers may process information in countries different from where you live.
Your choices, deletion and retention
You can edit your profile, control public biography visibility, manage your library and journal, export your collection, edit or delete your own posts and comments, report content, and block or unblock members. iOS controls camera and selected-photo access. AI label-photo sharing has its separate in-app control. Guided draft generation uses the explicit Build profile action and does not silently enable scanner photo sharing. Approved public catalog records and published studio images may remain as shared catalog information after account deletion. The app is intended for adults of legal drinking age. Purchases made separately through the website require the applicable purchase age and shipping eligibility.
To delete your account, open Profile → Account/settings → Delete Account. The service removes account-owned hosted profile, tasting, post and private bottle-draft photo objects before deleting the authentication account and its linked profile, collection, journal and community records. If cleanup cannot finish, the app reports a failure so you can retry or contact support. After successful deletion, that installation clears its account data. Member numbers are not reused.
Active account records remain available to provide your account until you remove them or delete the account. Individual deletions can leave synchronization markers or suppressed records to coordinate changes across devices. Backups, operational logs, email delivery records and moderation records may remain separately from active app data. Transaction records for purchases made separately through the website are governed by the store policy. Unverified custom-bottle metadata can remain in backend storage after its account ownership link is deleted; it is no longer accessible through the former account or the public catalog. Other retained records depend on the service, security, dispute-handling and applicable legal requirements; this notice does not promise immediate erasure of every copy. Other devices, exports and copies saved by other people may also remain.
Contact support@whiskeylibrary.com to ask about your information or request access, correction or deletion. We may need to verify account ownership before acting. Additional rights and choices that apply to you are described in our website privacy policy. We will post updates to this notice with an updated effective date.