In force since August 13, 2026 (updated: October 10, 2026) · The Polish version of this document prevails in legal matters
This Privacy Policy sets out the rules for processing and protecting the personal data of Users of the Drink Radar mobile application, available as a mobile app and at drinkradar.net.
The controller of personal data is Patryk Franz, operating the Drink Radar application, contact: drinkradar@drinkradar.net.
The controller processes data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and the Polish Act of 10 May 2018 on the Protection of Personal Data.
While using the app, we collect the following data:
We do not collect data on exact legal identity (e.g. ID card scans or verification photos) — age verification is based on the user's declaration and the date of birth provided at registration.
Data visible to other users. Your name or nickname, age, profile photo, gender (if you provide it — it affects the look of your pin and other users may use it in map filters), interests and your position on the map (according to the chosen visibility mode — section 5) are visible to other logged-in users; accepted friends additionally see up to 5 photos from your gallery. Your e-mail address and phone number are never visible to other users. Event declarations ("Interested" / "I'm going") are shown publicly only as aggregate counts on the given event — your individual declaration is not shown to other users. A "Going out today" plan (day, time slot, activities, radius, meeting time and place, and the number of free spots) is visible to other users on the map and in the Announcements tab until it expires or is withdrawn; in "Ghost" mode it is visible only to friends you share your position with. The plan itself does not change the visibility settings of your position. Details of joining plans — section 5.
Device local storage. The app (including the browser version) uses the device's local storage (localStorage, IndexedDB) and — in the web version — cookie-like mechanisms, solely for technical purposes: maintaining the login session, remembering settings and the map view. We do not use these mechanisms for advertising or marketing tracking. You can clear them at any time in your browser or device settings, which will log you out.
We process data in order to:
The app is intended exclusively for persons aged 18 or over. On first launch, the user makes an explicit declaration of being an adult, which is a condition of further use of the app, and at registration provides their date of birth — the system automatically calculates the age and rejects accounts of minors. In justified cases of doubt about the data provided, the controller may request additional verification.
Location data is processed only when the user gives explicit, separate consent — independent of accepting the Terms and this Policy. Consent is requested with a clear explanation of the purpose (showing nearby people and places on the map). The user may withdraw consent at any time in the device or app settings — withdrawal does not affect the ability to keep using the app's other features. Location is also used to filter content relative to your position — e.g. the events list within a chosen radius in kilometres; this filtering happens on your device and does not share your position with other users.
Visibility modes. What other logged-in users see on the map depends on the mode you choose, which you can change at any time in the Profile tab: "Real" — other logged-in users see your exact position; "Safe" (the default for new accounts, chosen consciously when setting up the profile) — others see your position shifted by approx. 1 km; "Ghost" — you are not visible on the map to other users unless you set an active status — then, for as long as it lasts, others see you at an approximate position (shifted by approx. 1 km), never your exact one. Per-friend settings and the "Walk me home" feature (described below) can change this only towards the friends you choose.
Location is also used to confirm presence at clubs (check-in) and at club and ticketed events (the "I'm at the event" button). A club check-in itself is used solely for the venue's attendance stats. Verification is voluntary: the app only checks whether you are near the venue while the event is taking place — your exact position from this feature is never shown to other users. The record of confirmed attendances (including dates) is kept on the account until the account is deleted.
"Going out today" and joining plans. You may publish a "Going out today" plan voluntarily; it is visible as described in section 2. Other users can join your plan with the "I'm in" button — as the organizer you see the list of people who joined and can message them; others see only the number of people who joined. Exception: if your accepted friends join someone's plan, you will see their first names on the plan card (and in the evening push summary), e.g. "Kuba and 2 others" — and likewise your friends may see your name next to a plan you join (not in "Ghost" mode); people outside your friends are always shown only as a number. The organizer and the people who joined the current plan can use the plan's group chat — leaving the plan removes access to the chat. When a plan gathers several people, we may send a general push notification to people within its radius whose interests match the plan's activities (without the organizer's name and without the exact place; distance is calculated only from positions shifted by approx. 1 km; at most one such notification per day; you can turn it off in the nearby-notification settings). The organizer may also receive a reminder when nobody has joined their plan.
Friends and per-friend visibility. A friendship requires mutual consent (a request and an acceptance). For each friend you choose one of three visibility modes for your position: “real” — the friend always sees your exact position, including when you use ghost mode (public invisibility) or safe mode, and during temporary inactivity they see your last known position; “safe” — the friend always sees your position with an offset (approx. 1 km); “off” — the friend sees you under the general rules, like any other user. The setting works independently in each direction and you can change it at any time in the Friends tab.
“Walk me home”. You can one-time share your exact live position with a selected friend (or several friends) for 1 hour — regardless of the visibility mode you have set — so they can check that you reached your destination safely. The feature expires automatically after one hour, and you can end it earlier with a single button. In the mobile app (Android, iOS), for as long as the session lasts the app sends your position every few seconds even while minimized — the system then shows a persistent notification or the system location-use indicator; if background sending is not possible, you can choose to share your position only while the app is open. Ending the session or letting it expire also stops the background sending. After it expires or ends, the friend returns to the standard visibility settings, and the exact position from this feature is not recorded or stored anywhere.
“Background signal” (mobile version). In the Profile you can enable the optional “Background signal”. It is off by default and works only after your explicit activation. When enabled, the app sends your position about every 35 seconds even while it is minimized — so friends can see your current position on the map and meetups and check-ins do not stop when you put the phone away. While the feature is active, the operating system shows a persistent notification or the system location-use indicator. You can turn it off anytime in the Profile; logging out also stops it. The setting is remembered separately for each account on the device. The “Background signal” is not required for “Walk me home” (described above) — an active walk-home session sends your position in the background for the duration of the session regardless of this setting.
Fake location detection (Android version). The app may read from the operating system a technical signal indicating that the position comes from a mock location provider; we process this signal solely to ensure community safety and prevent abuse (anti-fraud) — it is visible only to the Administrator and does not affect the app's functionality or your visibility (basis: Art. 6(1)(f) GDPR — legitimate interest).
Photos uploaded by users (profile photo and gallery, club photos) and text content entered in the app (messages in 1:1 chat and plan chat, name and nickname, the place name in a "Going out today" plan and club content, e.g. event descriptions) are automatically checked by content moderation services (OpenAI Moderation API, and for photos also Google Cloud Vision) before publication or sending, in order to detect prohibited content (e.g. violence, explicitly sexual content, hate speech, unlawful materials). Content flagged as prohibited is not published or sent. More information in section 8 below (data processors).
Moderation is automated, but at the user's request (Art. 22 GDPR) every decision to reject content will be reviewed by a human on the controller's side — just write to drinkradar@drinkradar.net.
The profile photo is stored on the app's server and shown to other logged-in users. The photo is served under a hard-to-guess web address — anyone who learns this address can open it without logging in. When the account or the photo is deleted, the file is permanently erased. Messages in 1:1 chat are stored in the app's database until one of the participants deletes their account — deleting an account immediately erases all of that person's conversations (for both participants) together with their photos and profile data.
Messages in a "Going out today" plan chat are visible to the organizer and the people who joined the plan. They are kept for approx. 7 days after the plan expires or is replaced and are then deleted automatically; deleting an account immediately erases all messages sent by that person.
Automatic system entries may appear in chats (e.g. a notice that the other person changed their name or nickname) — they serve conversation transparency and are stored under the same rules as messages.
We do not sell users' personal data. Data may be transferred only to trusted technical service providers acting as processors on our behalf:
Sign in with Google and Apple. If you choose to sign in with a Google account ("Sign in with Google") or an Apple account ("Sign in with Apple"), the authentication process takes place on the side of Google Ireland Limited or Apple Distribution International Ltd., which in this respect act as separate data controllers under their own privacy policies (policies.google.com/privacy and apple.com/legal/privacy). After a successful sign-in they pass to us only the data listed in section 2. The legal basis for processing is Art. 6(1)(b) GDPR (performance of a contract — enabling sign-in). You can unlink your Google account in your Google account settings, and your Apple account in the Apple ID settings (Sign in with Apple); deleting your Drink Radar account also deletes the data originating from these services that we have stored.
Automated content moderation (OpenAI) and SMS code verification (Telnyx) are external services — in rare cases of their temporary unavailability, the given operation (e.g. sending a message) may be processed without full automated review, so that users are not locked out of the app. This does not, however, release users from the obligation to follow the Terms — reported violations are always reviewed manually by the Drink Radar team.
Data may be disclosed to the competent public authorities (Police, prosecutors, courts) at their request or when necessary to report a suspected crime, or to establish, pursue or defend claims. This applies in particular to e-mail address, phone number, location data, content of reported messages and information about contacts between users — to the extent such data is actually stored (see section 9).
Important — the scope of anonymity. The app lets you appear to other users under a chosen name and does not disclose your surname, e-mail address or phone number to them, and in "Safe" and "Ghost" modes not your exact position either. This does not, however, mean anonymity from the administrator or from state authorities — data necessary to identify the account is stored and may be handed over to authorized authorities in the cases described above. We do not offer and cannot guarantee full anonymity.
Data is stored for as long as the user has an active account in the app. After account deletion, personal data, photos and messages are erased immediately; they disappear from database backups as the backups rotate, no later than within 30 days. Product events (usage analytics) are not erased but permanently anonymized — after the account is deleted they cannot be linked to you.
A "Going out today" plan is kept on the account until it is replaced, withdrawn or the account is deleted (once expired it is not visible to others); joins to plans and plan chat messages are deleted automatically approx. 7 days after the plan expires or is replaced.
We keep longer only the data necessary to ensure user safety, prevent abuse and establish, pursue or defend claims (basis: Art. 6(1)(f) GDPR — legitimate interest):
We do not keep persistent IP address logs or login history — the IP address is used only in transient request limits (rate limiting) and stored for no longer than 24 hours.
Every user has the right to:
Downloading a copy of your data. A copy of your data in a machine-readable format (JSON) is prepared and sent personally by the data controller — upon request sent to drinkradar@drinkradar.net from the e-mail address linked to your account. We respond without undue delay and in any case within one month of receiving the request.
Deleting your account. You can delete your account together with its data yourself at any time: in the Profile tab choose "Delete account" and confirm. A club account is deleted in the club panel with the "Delete club account" option. The detailed scope of deleted data is described at drinkradar.net/account-deletion.
Requests concerning the remaining rights can be sent to: drinkradar@drinkradar.net. We respond to requests without undue delay, no later than within one month of receiving the request.
We apply technical and organizational data protection measures, including transmission encryption (HTTPS/TLS), secure authentication mechanisms and restricted access to sensitive data. Despite the safeguards applied, we cannot guarantee absolute security of data transmitted over the Internet.
The controller is not liable for the use of the App by users in a manner contrary to the law or to the Terms — liability for such actions rests solely with their perpetrators. This disclaimer does not limit the controller's obligations arising from personal data protection laws, which cannot be contractually excluded.
The app is not intended for persons under 18 years of age and does not knowingly collect personal data of such persons. If the controller becomes aware that personal data of a minor has been collected without an appropriate legal basis, such data will be deleted immediately.
The controller reserves the right to make changes to this Privacy Policy. Users will be informed of material changes via the app or by e-mail, with appropriate notice before they enter into force.
For matters related to personal data protection, please contact: drinkradar@drinkradar.net