Legal document

Privacy Policy — Drink Radar

In force since August 13, 2026 (updated: August 25, 2026) · The Polish version of this document prevails in legal matters

This Privacy Policy sets out the rules for processing and protecting the personal data of Users of the Drink Radar mobile application, available on iOS and Android platforms and at drinkradar.net.

1. Data controller

The controller of personal data is Kamila Franz, operating the Drink Radar application, contact: drinkradar@drinkradar.net.

The controller processes data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and the Polish Act of 10 May 2018 on the Protection of Personal Data.

2. Scope of data collected

While using the app, we collect the following data:

We do not collect data on exact legal identity (e.g. ID card scans) — age verification is based on the user's declaration and the date of birth provided at registration.

Data visible publicly in the App. Your name or nickname, age, profile photo, bio, interests and approximate position on the map (depending on the chosen visibility mode) are visible to other logged-in users. Your e-mail address and phone number are never visible to other users. Event declarations ("Interested" / "I'm going") are shown publicly only as aggregate counts on the given event — your individual declaration is not shown to other users.

Device local storage. The app (including the browser version) uses the device's local storage (localStorage, IndexedDB) and — in the web version — cookie-like mechanisms, solely for technical purposes: maintaining the login session, remembering settings and the map view. We do not use these mechanisms for advertising or marketing tracking. You can clear them at any time in your browser or device settings, which will log you out.

3. Purpose and legal basis of processing

We process data in order to:

4. Age verification

The app is intended exclusively for persons aged 18 or over. On first launch, the user makes an explicit declaration of being an adult, which is a condition of further use of the app, and at registration provides their date of birth — the system automatically calculates the age and rejects accounts of minors. In justified cases of doubt about the data provided, the controller may request additional verification.

5. Location

Location data is processed only when the user gives explicit, separate consent — independent of accepting the Terms and this Policy. Consent is requested with a clear explanation of the purpose (showing nearby people and places on the map). The user may withdraw consent at any time in the device or app settings — withdrawal does not affect the ability to keep using the app's other features. Once consent is given, the approximate location is visible to other logged-in users on the map. Location is also used to filter content relative to your position — e.g. the events list within a chosen radius in kilometres; this filtering happens on your device and does not share your position with other users.

Location is also used to confirm presence at clubs (check-in) and at club and ticketed events (the "I'm at the event" button). A club check-in itself does not award any points — it is used solely for the venue's attendance stats; radar points are awarded only for your first confirmed attendance at an event (one-time). Verification is one-time and voluntary: the app only checks whether you are near the venue while the event is taking place — your exact position from this feature is never shown to other users. The record of awarded points (including confirmed attendances with dates) is kept in the account's radar points history until the account is deleted.

Friends and per-friend visibility. A friendship requires mutual consent (a request and an acceptance). For each friend you choose one of three visibility modes for your position: “real” — the friend always sees your exact position, including when you use ghost mode (public invisibility) or safe mode, and during temporary inactivity they see your last known position; “safe” — the friend always sees your position with an offset (approx. 1 km); “off” — the friend sees you under the general rules, like any other user. The setting works independently in each direction and you can change it at any time in the Friends tab.

“Walk me home”. You can one-time share your exact live position with a selected friend (or several friends) for 1 hour — regardless of the visibility mode you have set — so they can check that you reached your destination safely. The feature expires automatically after one hour, and you can end it earlier with a single button. After it expires or ends, the friend returns to the standard visibility settings, and the exact position from this feature is not recorded or stored anywhere.

“Background signal” (Android and iOS). In the Profile you can enable the optional “Background signal”. It is off by default and works only after your explicit activation. When enabled, the app sends your position about every 35 seconds even while it is minimized — so friends can see your current position on the map and meetups and check-ins do not stop when you put the phone away. While the feature is active, the system shows a persistent notification (Android) or the system location-use indicator (iOS). You can turn it off anytime in the Profile; logging out also stops it. The setting is remembered separately for each account on the device.

6. Content moderation

Photos uploaded by users (profile photos, club photos) and text content entered in the app (profile bio, answers to profile questions, chat messages) are automatically checked by content moderation services (OpenAI Moderation API, and for photos also Google Cloud Vision) before publication or sending, in order to detect prohibited content (e.g. violence, explicitly sexual content, hate speech, unlawful materials). Content flagged as prohibited is not published or sent. More information in section 8 below (data processors).

Moderation is automated, but at the user's request (Art. 22 GDPR) every decision to reject content will be reviewed by a human on the controller's side — just write to drinkradar@drinkradar.net.

7. Photos and messages

The profile photo is stored on the app's server and visible to other logged-in users. Messages exchanged with other users are stored in the app's database without a time limit, until the user deletes their account — at that point all their messages, photos and profile data are permanently erased within a reasonable timeframe, no longer than 30 days from the deletion request.

Automatic system entries may appear in chats (e.g. a notice that the other person changed their name or nickname) — they serve conversation transparency and are stored under the same rules as messages.

8. Data sharing and processors

We do not sell users' personal data. Data may be transferred only to trusted technical service providers acting as processors on our behalf:

Automated content moderation (OpenAI) and SMS code verification (Telnyx) are external services — in rare cases of their temporary unavailability, the given operation (e.g. sending a message) may be processed without full automated review, so that users are not locked out of the app. This does not, however, release users from the obligation to follow the Terms — reported violations are always reviewed manually by the Drink Radar team.

Data may be disclosed to the competent public authorities (Police, prosecutors, courts) at their request or when necessary to report a suspected crime, or to establish, pursue or defend claims. This applies in particular to e-mail address, phone number, IP addresses, login history, location data, content of reported messages and information about contacts between users.

Important — the scope of anonymity. The app lets you appear to other users under a chosen name and does not disclose your surname, e-mail address, phone number or exact address to them. This does not, however, mean anonymity from the administrator or from state authorities — data necessary to identify the account is stored and may be handed over to authorized authorities in the cases described above. We do not offer and cannot guarantee full anonymity.

9. Data retention period

Data is stored for as long as the user has an active account in the app. After account deletion, personal data, photos and messages are permanently erased within 30 days.

The exception is data whose longer retention is required by law or necessary to establish, pursue or defend claims and to ensure user safety. In particular: violation reports together with evidence material (content of reported messages and photos) and identifiers of accounts banned for violating the Terms are kept for up to 3 years from the event, and basic technical logs (IP addresses, login dates) for up to 12 months. Error reports and session recordings (Sentry) are kept for up to 90 days. The legal basis is Art. 6(1)(f) GDPR — legitimate interest consisting in preventing abuse, protecting users and defending against claims.

10. User rights

Every user has the right to:

The account, together with all data (profile, photo, messages), can be deleted by the user at any time in the Profile tab. Requests concerning the remaining rights can be sent to: drinkradar@drinkradar.net. We respond to requests without undue delay, no later than within one month of receiving the request.

11. Security

We apply technical and organizational data protection measures, including transmission encryption (HTTPS/TLS), secure authentication mechanisms and restricted access to sensitive data. Despite the safeguards applied, we cannot guarantee absolute security of data transmitted over the Internet.

The controller is not liable for the use of the App by users in a manner contrary to the law or to the Terms — liability for such actions rests solely with their perpetrators. This disclaimer does not limit the controller's obligations arising from personal data protection laws, which cannot be contractually excluded.

12. Children and minors

The app is not intended for persons under 18 years of age and does not knowingly collect personal data of such persons. If the controller becomes aware that personal data of a minor has been collected without an appropriate legal basis, such data will be deleted immediately.

13. Changes to this Privacy Policy

The controller reserves the right to make changes to this Privacy Policy. Users will be informed of material changes via the app or by e-mail, with appropriate notice before they enter into force.

14. Contact

For matters related to personal data protection, please contact: drinkradar@drinkradar.net

Questions about this policy or want to exercise your rights? Write to drinkradar@drinkradar.net.