Privacy Policy
ETHANOL is a drink journal: it logs what you pour, the chemistry of the beverage, and how a session unfolds. It is built privacy-first: your drinking history never leaves your device. This policy explains, in plain terms, exactly what data the app handles, what stays only on your phone, the narrow set of things sent to our servers, and the choices you have.
- Your drink logs, sessions, and health readings stay on your device. We never receive them in identifiable form.
- No tracking, no ads, no analytics or advertising SDKs, no advertising identifier (IDFA). We do not sell or share your data with data brokers.
- There are no accounts and no login — no profile on our servers tied to your identity.
- Menu and bottle photos are sent for one-time scanning, then discarded — never stored on our servers.
- Anonymous, aggregated menu data, and (for Premium users) summary statistics for the AI Coach, are the only behavioral data that leave the device — both designed to be unlinkable to you. Anonymous sharing is opt-out.
01 // Data that stays on your device
The following is stored locally on your iPhone — and, when you pair an Apple Watch, mirrored to it over Apple's encrypted device-to-device channel — and is never transmitted to our servers:
- Your drink logs, drinking sessions, and session history
- Your profile and preference settings
- Dry-streak counts, insights, taste ratings, the molecule compendium, and badges
- Apple Health readings the app uses for correlation (such as sleep and resting heart rate)
- "Specimen" photos you compose in the app — these stay on-device, and are only saved to your Photos library or shared if you explicitly tap save or share
- Venue history and the personal map
Because this data is local, uninstalling the app deletes it.
02 // Data that leaves your device
A deliberately small set of data is sent to our backend (hosted on Cloudflare) or to our AI provider (Anthropic). Here is all of it.
Menu & bottle photos (scanning)
When you scan a drink menu or a bottle label, the image is uploaded so it can be read by Anthropic's vision model and turned into structured text. The image is discarded immediately after the parsed result is returned — we never store these images in any database, file store, or log. Anthropic retains API submissions for a limited period for safety review under its standard policy and does not use them to train its models.
AI Coach & insights (Premium)
If you subscribe to Premium and use the AI Coach or weekly insight feature, the app sends aggregate statistics about your drinking — for example, total drinks in the last 30 days, average drinks per week, most-logged drink types, dry-day counts, and goal summaries. These aggregates contain no raw timestamps, no location, and no payment information. They are processed by Anthropic to generate the response and are not used to train models. Free users never trigger this feature.
Anonymous menu & benchmark aggregates (opt-out)
If anonymous data sharing is enabled — it is on by default, and you can turn it off any time in Settings → Privacy — parsed menu items, observed prices, and observed ABVs you scan are contributed to a venue-keyed aggregate pool that powers features like "popular at this venue." These contributions carry no user ID, no session ID, only day-level dates, and at most a coarse geohash (~5 km precision). The pool is only queryable above a k-anonymity floor of three distinct contributors. Turning the toggle off immediately discards any pending contributions; menu scanning continues to work.
Install identifier
A random identifier is generated on first launch and stored in your device Keychain. It is used only to (1) meter and rate-limit backend requests per install to prevent abuse, and (2) deduplicate anonymous aggregate contributions. It is not linked to your identity, is never used for tracking, and never syncs across devices via iCloud.
Coarse location (opt-in)
If you allow it, the app uses your location to suggest nearby venues when you start a session and to tag where a session occurred. Only a coarse geohash (~5 km precision) is ever used or transmitted — never your precise latitude/longitude. Location is entirely optional, can be declined per session, and can be disabled in Settings; no core feature requires it.
Purchases
Subscriptions and scan-credit purchases are processed entirely by Apple through StoreKit. We receive Apple's signed receipt token to verify your entitlement on our backend. We never receive or store your credit card or Apple ID credentials.
03 // Third parties
- Apple — HealthKit (on-device), StoreKit (purchases), and device-to-device sync are governed by Apple's Privacy Policy.
- Anthropic — processes menu/bottle images and AI Coach aggregates to return scan results and coaching. Submissions are not used for model training.
- Cloudflare — hosts our backend (rate-limit counters and the anonymous aggregate pool). No identifiable drinking data is stored there.
We do not use any advertising networks, analytics SDKs, or data brokers.
04 // Apple Health (HealthKit)
With your permission, ETHANOL reads sleep and heart-rate data to correlate with your drinking, and writes the alcohol you log to Apple Health so it is part of your overall health record. Health data is used solely to provide app features. We do not use HealthKit data for advertising or marketing, and we do not share it with third parties for those purposes. Your raw Health readings stay on your device.
05 // What we never do
- No advertising, ad networks, or ad identifiers (IDFA / App Tracking Transparency tracking).
- No third-party analytics or tracking SDKs.
- No selling or sharing of your personal data with data brokers.
- No linking of your data across other apps or companies.
- No accounts — so no identity-linked profile on our servers.
06 // Data retention
- On-device data — retained until you delete it in the app or uninstall.
- Scan images — not retained by us; discarded immediately after parsing (Anthropic retains briefly for safety review).
- Rate-limit counters — short-lived, keyed to the install identifier.
- Anonymous aggregates — retained as pooled, non-identifiable data; by design not linked to any individual.
07 // Your choices & rights
- Stop anonymous sharing any time in Settings → Privacy.
- Delete your data in the app via Settings → Erase All Data, which clears all local drinking data. Uninstalling also removes it.
- Revoke permissions (Health, Location, Camera, Notifications) any time in iOS Settings.
- Manage subscriptions in your Apple ID settings.
08 // Age
ETHANOL is intended for adults of legal drinking age (21+ in the United States) and presents an age gate on first launch. It is not directed to children, and we do not knowingly collect personal information from anyone under 13.
09 // Security
All network requests use HTTPS/TLS. The install identifier is stored in the device Keychain. Because the most sensitive data — your drinking history and health readings — never leaves your device, the primary protection for it is your device's own passcode and encryption.
10 // International users
Our backend and AI processing occur in the United States. If you use the app from outside the U.S., the limited data described above is processed in the U.S.
11 // Changes to this policy
If we change how the app handles data, we will update this policy and revise the "Last updated" date above. Material changes will be reflected here or in the App Store listing.
12 // Contact
Questions about this policy: hello@ethanol.app. ETHANOL is operated by Azeotropic, LLC.
ETHANOL reports counts, not verdicts. It is not a medical device, not a breathalyzer, and not a legal measure of fitness to drive.