Privacy

Local by default.

Quiz, recommendations, Pair, Home Bar, Journal, and the free parser work locally by default; deliberate server-assisted features are separate. Quiz answers, palate profile, saved drinks, journal entries, and bars you add stay in this browser unless you deliberately sign in and turn on cloud backup. A cloud backup stores those selected fields with Supabase so they can follow your account; you can turn backup off and request deletion.

Optional analytics.

Consented product analytics use a persistent pseudonymous identifier, not an anonymous identity. Each event records which action you took and a small payload about that action — including text you type into app fields (bar names, neighborhoods, requested cities), quiz answers, dish and drink names, and game scores — plus the route, timestamp, referral ID, palate archetype, proof setting, and coarse location supplied by Cloudflare (country, region, city, and timezone). If you allow analytics, links you share carry your random ID as their referral code, so anyone holding a link you shared can read that code. We do not send your contacts or advertising identifiers. Analytics are used to improve recommendations and learning, are not sold, and are retained for no longer than 12 months. Declining — or withdrawing later — also deletes the stored events tied to your random ID.

Current analytics choice: not chosen

Hosting.

This site runs on Cloudflare. As the hosting and edge provider, Cloudflare carries every request, sees your IP address, and runs our abuse rate limits; it also supplies the coarse location fields above. Edge operational logs do not include your analytics or session identifiers.

Feedback you send.

The “Report a problem” button emails the owner directly through Cloudflare Email Routing. That email carries the words you type and the kind of note you picked; if you leave “include what I was looking at” on, it also carries the page you were on, your browser and device type, and the app build; and it carries your email address only if you add one so we can reply. It never includes your palate profile, journal, saved drinks, allergies, location, or analytics identifiers, and your report is not used for advertising or sold. It stays in the owner’s mailbox for as long as it is useful for fixing the app. If the app itself breaks, it also sends the owner an automatic crash report under the same limits: the technical error message, the page, your browser and device type, and the app build — at most a few per session, and never your palate profile, journal, saved drinks, allergies, or location.

Cloud features you choose.

Menu Scan sends the selected image to Anthropic for transcription; the photo itself is not retained by this app, while a hash and extracted menu may be cached to avoid paying to read the same image twice. Concierge messages are interpreted on your device today; if an optional AI interpretation is enabled later, it will send only the message you choose to Gemini 2.5 Flash-Lite through Cloudflare AI Gateway, plus the current proof and drink-register setting, used only to disambiguate words such as “strong.” Your palate profile, journal, allergies, recommendation history, and drink catalog would not be sent with it, this app would not retain the message, AI Gateway prompt/response payload logging is disabled for that route, and Google would process the inference under its service terms. “Reinterpret in a style” sends the canonical recipe, chosen style, and optional editorial focus to Anthropic. Weather-based suggestions call Open-Meteo directly from your browser, so that request carries your IP address and browser headers along with rounded (two-decimal) coordinates. Push reminders are retired for launch, so this app does not collect push subscriptions. Those processors handle data under their own service terms. When you deliberately use one of these server features, the app uses a separate random operational ID—or your server-verified account ID when signed in—to enforce abuse and cost limits. That identifier is not sent to Gemini, used for analytics, or placed in shared referral links. Quota records are removed 30 days after their window ends; deleting a signed-in account also removes its account-linked quota rows.

Optional community recommendations.

If you explicitly enable this signed-in feature, a copy of your bar ranking and palate is stored under a random pseudonym. A separate, server-private account link makes the copy pseudonymous—not anonymous—and exists so only you can update, export, withdraw, or delete it. Other guests receive only predictions combined from at least five eligible contributors; they never receive your ranking, palate, pseudonym, or similarity score. Turning the feature off deletes every community contribution linked to your account. The feature is off by default and remains unavailable unless the community service is enabled.

Your choices.

You can decline or withdraw analytics without losing the core app; withdrawal deletes the stored events tied to your random ID. Account, cloud-backup, community export, and community withdrawal controls live under Me. To request a copy or deletion of other server-held data, contact us from the account email or through the channel below. Local browser data can be removed by clearing this site's storage.

Contact.

Questions? Reach us at @by_the_glass_stories.

Effective August 20, 2026. This notice covers By the Glass Stories' public web app.

Drink with intention. This product is for people of legal drinking age — and the zero-proof curious.