Legal
Privacy Policy
Short version. The app keeps your bottles and your check-ins in a database in the EU, on an account that starts out anonymous. Three things leave your device and go to companies outside our systems: the photograph you take when you scan a bottle label or a cocktail menu goes to Google, your coordinates go to a mapping provider when you look for the bar you are in, and a barcode you scan goes to whichever external barcode database answers first. Usage analytics are off until you turn them on in Profile. Crash reports are always on. Your bottles sit in one inventory shared with My Whiskey Shelf on the same account, so deleting your account deletes them in both. We do not sell any of it. You can export or delete all of it yourself, in the app or on this site.
What changed in version 2.0, and why. Version 1.0 said your location was stored on your device only. That was false: the app sends your coordinates to a mapping provider to find the bar you are in. It said camera images were processed instantly and not stored. That was false: the photograph goes to Google, and a saved photograph goes to a storage area that needs no sign-in to read. It listed five outside services and promised we would update this page before adding anything new. RevenueCat shipped, and receives your account identifier every time the app starts, and the page did not change. It said you withdraw analytics consent by contacting us, when there is a switch in the app. And it said deletion removes all your personal data, when several things survive it. Every one of those is corrected below. Section 20 lists the changes.
1. Who we are
My Bar Shelf is a product of Nisshagen Advisory AB (Org.nr 559526-6742), a company registered in Stockholm, Sweden. We are the data controller for personal data collected through the My Bar Shelf app on iOS and Android and through the mybarshelf.com website.
Contact hello@mybarshelf.com for any privacy question, including requests under the GDPR. We have not appointed a data protection officer and are not required to.
This policy covers both the app and the website. Where a section applies to only one of them, it says so.
2. Your account
The app creates an anonymous account the first time you open it. That account holds no email address and no name. It is a random identifier that lets your own shelf come back to you the next time you open the app. You are not asked to sign up, and you can use the app indefinitely without ever creating a real account.
An anonymous account is still a real record in our database. Everything you enter is stored against it, exactly as described in section 3, and unlike some of the other Shelf apps, an anonymous account here can turn on usage analytics and is identified to our subscription provider.
If you create a real account so your shelf survives a new phone, we store what you give us for that:
- Email and password: your email address, and a password we never see in readable form. It is hashed by our authentication provider.
- A one-time sign-in link: your email address, so we can send the link to it.
- Sign in with Google: your email address and the account identifier Google returns. We do not receive your Google password, your contacts or anything else in your Google account.
- Sign in with Apple: the account identifier Apple returns, and the email address you choose to share. If you use Apple's Hide My Email, we only ever see the relay address, never your real one.
Signing up from an anonymous account keeps the same account and the same shelf. It is the same record with an email attached, not a new one.
On your device the app stores your sign-in session, a cached copy of your shelf and shopping list, your unit and volume preferences, four flags recording which walkthroughs you have seen, and the home location described in section 4. Deleting your account clears all of them.
3. What you record, and who it is shared with
Everything in the app besides the reference catalogue is content you create, stored against your account:
- Bottles: name, category, strength, volume, barcode, how much is left, when you opened it, whether you filed it as Bar Stock or as rare, and any notes you write.
- Check-ins: the date, a rating, how you made or drank it, your notes, a photograph if you add one, and a location, which section 4 sets out in full.
- Shopping list, bookmarks and the recipes you build, including any photograph on a recipe.
- Feedback on recommendations, meaning which suggestions you kept and which you dismissed.
- Cocktail menus you scan, as a list of drinks read off the menu.
This is private to your account. There is no social feed and no public profile. Database access rules restrict every row to the account that created it. There are three exceptions, and each is set out where it belongs: the shared barcode table in section 6, the pooled venue list in section 4, and a recipe you choose to publish to the shared cocktail catalogue, which is public by design.
Your bottles are shared with My Whiskey Shelf. Bottles live in a single inventory used by both My Bar Shelf and My Whiskey Shelf, so one bottle you own is one record rather than two. If you are signed in to the same real account in both, a bottle added in one appears in the other, editing it in one edits it in both, and deleting it in one deletes it in both. Deleting a bottle here also destroys the whiskey-side details on it and every whiskey pour recorded against it. Deleting your account does that wholesale. This is between two apps you control, under your own account. Nothing is shared with anyone else.
While you are anonymous you have a different account in each app, so nothing is shared until you sign in with a real account in both.
Some things on your account reach past My Bar Shelf. They do not all reach the same distance, so each one is named with the apps it actually touches rather than described as portfolio-wide:
- Your analytics choice is one row on your account, read and written by My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf and My Cigar Shelf. It does not cover My Coffee Shelf, which keeps its own answer in its own table. My Supply Shelf sends no analytics at all. Section 8.
- The shared barcode table is shared with My Whiskey Shelf, which reads and writes the same table. Section 6.
- Your subscription is held against your account identifier at RevenueCat, so an entitlement bought in one Shelf app can be seen by another asking about the same account. What it unlocks depends on which subscription you bought. Section 11.
The record of AI scans is not on that list, and version 2.1 of this policy put it there. There is a shared ledger, one row per scan, and section 15 describes it. But it is a record rather than a limit, and it is not what meters your scanning in this app. My Bar Shelf's free limit counts bottles, not scans: the label scan and the menu scan stay free until your shelf holds 20 bottles, not counting the ones you filed as Bar Stock, and after that they are for subscribers. Version 2.1 described the scan record as one of four things “set once and applied across the Shelf apps”, which was wrong about this app's own gate. Section 5 now states it.
4. Location, and where your coordinates go
Version 1.0 of this policy said your location was stored on your device only. That was wrong, and this section replaces it.
When the app reads your location
Two places, both only after you tap something, and both foreground only. The app never reads your location in the background.
- Step three of a check-in, where the app offers to find the bar or restaurant you are in.
- Profile, then Home Bar, then Set current location as Home, where you save the place you drink at home so the app stops asking.
The app asks the operating system for balanced accuracy, which is roughly a city block. It is not a coarse or country-level reading.
What happens on your device first
The reading is compared against the home location you saved, which is stored in the app's own storage on your phone and is never sent to us. If you are within about 200 metres of it, the check-in location is set to the word Home and the app stops there. Nothing is sent anywhere.
What leaves your device, and who receives it
Otherwise the coordinates are sent to one of our own server functions, which looks up bars nearby. That function then forwards them to an outside mapping provider. There are two, and which one is used depends on our server configuration rather than on anything you do, so both are named here:
- Geoapify, a mapping company in the European Union, when our Geoapify key is configured. It receives your latitude and longitude twice, once as the centre of a search circle and once as a proximity bias, along with a radius and a list of venue categories.
- Overpass, the query service over OpenStreetMap data, run by community mirrors in Europe, when the Geoapify key is not configured. It receives the same coordinates inside a search query, along with the radius and the venue types.
Both have handled live requests from this app. Neither receives your account identifier, your email or anything from your shelf. Because the request is made by our server and not by your phone, the provider sees our server's network address, not yours.
What is stored
- A shared venue cache, keyed to a map tile of roughly 1.1 kilometres, holding the list of venues found there, which provider answered and when. There is no account identifier on those rows, and the same tile is reused for anyone searching in it for seven days. Rows are not pruned after that; they are simply refreshed when next used.
- A pooled venue list, if you confirm a bar the provider suggested. The row holds the venue's own name, city, type and coordinates, and has no user column at all, so it cannot be traced back to you. That list is readable by anyone holding the app's public key, which ships inside the app and is not a secret.
- Your check-in, which stores the venue name, or the word Home, or whatever you typed, plus the venue's coordinates. These are the venue's coordinates, not your device reading. This row is private to your account.
Your device reading itself is never written to a row keyed to you. What we will not claim is that the reading is unlinked at the moment it arrives: the call to our function carries your sign-in token, so our server knows whose request it is while it is handling it.
If usage analytics are on, the only thing recorded about a check-in location is which of the three routes you used, automatic, nearby or typed by hand. No coordinates and no venue names go to our analytics provider. Section 8 covers a separate and unrelated matter: our analytics provider deriving an approximate town from the network address of the request.
The permission text the app shows on iOS says location is used only while checking in a drink, to suggest the bar you are in, and never in the background. That is true. What it does not say is that the coordinates are forwarded to an outside provider, and that is being corrected in the app.
5. Photographs, and what goes to Google
This is the part of the app that sends the most away from your device, so it is set out in full.
The bottle label scan
When you scan a label, the app resizes the picture on your device to 768 pixels on its long edge, re-encodes it as a JPEG, and sends it to one of our own server functions, which runs on our database provider's infrastructure in the EU. Your sign-in token goes with it. That function forwards the image and a fixed instruction to Google, to the Gemini API, which reads the label and returns text. Nothing else is sent to Google: not your account identifier, not your email, not your device identifier, and nothing from your shelf.
The same resized image is also uploaded to our file storage at that moment, before you have seen the form, before we know whether the reading worked, and whether or not you go on to save the bottle. Cancelling the form does not undo the upload.
The cocktail menu scan
Photographing a cocktail menu works the same way, with the same resize and the same route to Google, and a different instruction asking it to list every drink on the menu. This photograph is not uploaded to our storage. If other people appear in the frame of a menu photograph, they go to Google with it.
Photographs you attach
A photograph you attach to a bottle, to a check-in or to a recipe is resized to 800 pixels wide and uploaded to the same storage area. A recipe you publish to the shared cocktail catalogue makes its photograph visible to other people, which is the point of publishing it.
What the scans cost you, and what gets recorded
Both scans are free until your shelf reaches 20 bottles, not counting anything you filed as Bar Stock. Past that they are a subscriber feature. It is a limit on the size of your shelf rather than on how many scans you have run, so it does not reset and there is no daily count to wait out. Subscribers are not limited at all.
Two records are written when a scan runs. One is a counter on your account holding how many scans and searches you have made, which section 15 covers and which is removed when you delete your account. The other is a row on the shared AI scan ledger, holding your account identifier, which Shelf app ran the scan, the kind of scan and the time. That row is written whether or not you are a subscriber, and it outlives a deletion in the one case section 17 sets out. Neither record holds the photograph or anything read off it.
Before running a scan our server asks RevenueCat whether your account holds an active subscription, which sends your account identifier to RevenueCat. Section 11 covers that.
That storage area is not access controlled
Every file above sits at a long random web address, and anyone who has that address can open it without signing in. The address does not expire. It is only ever stored on your own rows and we do not publish it, but we are not going to describe the file as private, because it is not.
There is a second consequence. A file is only reachable by our deletion routine if a bottle row still points at it. A label scan you cancelled, and a photograph whose record was later deleted, has nothing pointing at it, so the deletion routine cannot find it and it stays where it is. Photographs attached to check-ins are not collected by the deletion routine either. Section 17 repeats this and section 15 says what to do about it.
What we cannot tell you
We call Google's general endpoint and have not pinned it to a European region, so you should assume the photograph is processed outside the EU. We do not control what Google does with the image after it has read it, and we are not going to state a retention period we cannot verify. Google's own terms for that API govern it. If that is not acceptable to you, do not use the label scan or the menu scan. Adding a bottle by barcode, by catalogue search or by hand never sends a photograph anywhere.
The camera permission text the app shows says the camera is used to scan barcodes on your bottles. Barcode scanning does happen on your device and sends no image anywhere, but that text does not describe the label scan or the menu scan, and it is being corrected in the app. This section describes what the app actually does.
6. Barcode scanning, and the shared barcode table
Reading the barcode happens on your device. Looking up what it means does not.
The digits are first checked against our own shared table of barcode-to-product mappings. If that misses, the app asks up to six outside services in order and stops at the first one that returns a usable answer:
- Open Food Facts and Open Products Facts, run by the same non-profit in France
- UPCitemdb, in the United States
- Vinmonopolet, the Norwegian state retailer
- Brocade, in the United States
- and last, a plain web search on DuckDuckGo. This one is not a barcode service. The app runs a search for the barcode digits against DuckDuckGo's HTML results page and reads a product name out of the page, sending a browser-style identification along with the request.
These are called from your phone, so each one receives the barcode digits and your device's network address. None of them receives your account identifier, your email, a photograph or anything from your shelf. If Vinmonopolet answers, the app then loads the product picture from Vinmonopolet's image server, so your address reaches it a second time.
If you confirm that a barcode belongs to a particular catalogue product, the app saves that mapping to a table shared with My Whiskey Shelf, so the next person who scans that bottle gets an answer immediately. The saved row holds the barcode, the product, and the account identifier of whoever contributed it.
That table is readable by anyone holding the app's public key, which is embedded in the app and is not a secret. So the contributor identifier on a barcode mapping is not private. It is a random identifier and carries no name, no email and nothing from your shelf, but it is one of the few places where a row of yours is not restricted to your account, and you should know it. Your contributions are deleted when you delete your account.
7. The AI cocktail search, shared recipe links, and tasting text
Three more features send something to an AI service. None of them sends your account identifier.
- The AI cocktail search. The words you type are normalised and sent to one of our server functions and on to Google, to an embedding model that turns the text into numbers we can match against our catalogue. The normalised text is kept in a shared cache so the same search does not have to be sent twice. That cache has no account identifier on it, cannot be attributed to anyone, is not readable by the app, and is not deleted. Free accounts get three AI searches a week; see section 11.
- A recipe page you share into the app. If you share a cocktail recipe from a website into My Bar Shelf, our server fetches that page and sends its text to Google to turn into a structured recipe. The page address and its contents go to Google. Nothing of yours goes with them.
- Tasting text on a catalogue bottle. When a bottle on your shelf is matched to the Swedish retail catalogue and its tasting description is only in Swedish, our server sends that description to Anthropic, in the United States, for an English version, which is stored on the bottle record. The text is the retailer's own catalogue prose, not anything you wrote, and nothing identifying you is sent with it.
8. Usage analytics, which are off until you turn them on
The app can send product analytics to Mixpanel, on its EU service. It does not do so unless you switch it on.
Before you consent
The setting is off by default and off for every new account. While it is off, the analytics library is never started, no analytics identifier is generated, no events are queued, and no connection to Mixpanel is opened at all. It is not a filter applied to data collected anyway. Nothing is collected.
Turning it on and off
There is an unticked box at signup, and there is a switch in the app: Profile, then Data, then Usage data. The switch takes effect immediately, without restarting the app, and you do not have to give a reason. Version 1.0 of this policy said you withdraw consent by contacting us. That was wrong.
Unlike My Whiskey Shelf, an anonymous account in this app can turn analytics on. The switch is offered whether or not you have signed up.
It is a single setting, stored as one row on your account, and it covers My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf and My Cigar Shelf. Turning it on here turns it on in those, and the other way round. It does not cover My Coffee Shelf, which keeps its own separate answer and asks you again there, so turning it on here leaves coffee where you set it. My Supply Shelf sends no analytics at all. Version 2.0 of this policy said the setting covered every Shelf app you use, which was wrong about coffee. The switch inside the app says the same thing and is being corrected.
What is sent once it is on
Around 68 named events, covering: which screens you open, adding, opening, editing and deleting a bottle, barcode and label scans, starting and completing a check-in, searching and filtering cocktails, opening a recipe, building and submitting one, bookmarking, shopping list changes, notification permission steps, paywall and purchase steps, restoring a purchase, language and unit changes, signing up, signing in and signing out.
Each event carries short labels from a fixed list: which category a bottle is, which route you added it by, which screen you were on, a rating, how many results a search returned, how many characters you typed, whether a search used AI, and an error code when a purchase fails. Attached to every event: how many bottles you hold, whether you have a subscription, whether you have made a first check-in, and which sign-in method you use. The Mixpanel library also attaches your operating system and version and your device manufacturer and model.
Never sent: bottle names, tasting notes, venue names, the words you typed into a search, your coordinates, photographs, your email address, or anything else you typed.
Events are identified by your account identifier, not by your name or your email address. The switch in the app calls this anonymous usage data. Pseudonymous is the accurate word, and that wording is being corrected in the app.
Approximate location. We do not suppress the network address on these events, so Mixpanel resolves it to an approximate town, region and country and stores that against the event and the profile. This is derived from the address the request came from, not from the location reading in section 4, and it happens on every event once analytics are on. If you would rather it did not happen, leave the switch off.
9. Crash and error reports
The app reports crashes and errors to Sentry, on its German service. This is always on and is not covered by the analytics switch, because it is how we find out that the app is broken.
Sending personal data is switched off in our configuration, and we do not attach an account to reports as a matter of course, so a report normally carries no account identifier, no email, no username, no network address and no cookies. A report contains the error and its message, where in the code it happened, the device model, the operating system and version, the app version, the device locale and timezone, memory, storage, battery and orientation, and the list of loaded modules. Screenshots, view hierarchies, session replay and performance profiling are all switched off.
The honest limit, in three parts.
- Two places in the app do attach your account identifier on purpose: when registering or unregistering a notification token fails. Those reports carry your identifier in a field, not by accident.
- The Sentry library records a breadcrumb trail of network requests, storing the method, the address and the status of each. Some of our database requests carry your account identifier in the address.
- When a database write fails, the error we attach is the database's own message, and a database message can quote the value that caused the failure, which can be a bottle name.
We are not going to claim that a crash report contains nothing about you. The previous version of our deletion page said crash logs contained no personal identifiers. That was wrong.
10. Notifications
If you allow notifications, the app registers a push token with Expo's push service and stores that token against your account. When we have something to tell you, our server sends the notification title and body to Expo, which relays it through Apple's or Google's delivery service to your phone.
Those messages are about your own bottles, and they say so by name, for example that a named bottle is winding down. So a bottle name leaves our systems through Expo, Apple and Google when a notification is delivered. On Android the app also ships Google's Firebase messaging configuration, which is how Android delivery works.
Turn notifications off in your device settings at any time. Deleting your account removes your token and your pending notifications for this app and for My Whiskey Shelf.
11. Subscriptions and purchases
Some parts of the app are reserved for subscribers.
We do not take your money and we never see your payment details. Subscriptions are sold and billed by Apple on the App Store or by Google on Google Play. Your card, bank details and billing address are held by them, not by us, and are never sent to us.
We use RevenueCat to keep track of whether a subscription is active. RevenueCat receives your account identifier as soon as the app identifies you on launch, whether or not you ever buy anything, and whether your account is anonymous or real. It also receives your platform and the network address of the request, from which it derives an approximate country. If you do buy or restore a subscription, it additionally receives the purchase and receipt information the store issues and the country of your store account. Our server also asks RevenueCat about your account before running a label scan, a menu scan or an AI search, to decide whether to meter it.
RevenueCat processes this in the United States. Section 18 covers that transfer.
What a subscription lifts. AI label and menu scanning is free while your shelf holds fewer than 20 bottles that are not filed as Bar Stock. Past that, scanning is for subscribers. AI cocktail search is free for three searches a week. Both counts are kept on a row against your account. Everything else, adding bottles by hand, by barcode or from the catalogue, check-ins, recipes, the shopping list and the cocktail library, is not metered.
Every successful AI scan also writes one row to a shared ledger recording your account identifier, which Shelf app ran it and when. That ledger is written for subscribers too. Some other Shelf apps count a free-scan allowance against that same ledger. Bar does not: bar's free tier is the 20-bottle shelf cap described above, so a row here is a record rather than a meter for this app.
What a subscription unlocks depends on which one you bought. RevenueCat holds your entitlements against your account identifier, so an entitlement bought in one Shelf app is visible to another asking about the same account. There are two kinds. A bundle subscription is honoured by the Shelf apps that check for it, so it unlocks more than the app you bought it in. A single-app subscription, which is what most current subscribers hold, unlocks the app it was bought for and is not honoured by the others. Version 2.1 of this policy said one subscription covers every Shelf app on the same real account. That is true of the bundle and not of the rest, and it should not have been written as a flat rule.
Either way it needs a real account: while you are anonymous your identifier differs per app, so nothing carries across.
Cancel in your App Store account settings or your Google Play subscriptions. We cannot cancel or refund it for you. Deleting your My Bar Shelf account does not cancel a subscription, so cancel it in the store first or billing continues. The Terms of Service set out the renewal and cancellation terms in full.
12. The website
Reading pages on mybarshelf.com does not require an account and we do not ask you for anything.
The site uses Vercel Web Analytics for aggregate traffic measurement: page views, referrer, country, device, operating system and browser, with a visitor identifier that is hashed and rotates daily. It is cookieless, it does not follow you across sites, and it does not build a profile of you. When you use the install link, the site records one event saying which store it sent you to. There are no other pixels and no non-essential cookies, so there is no cookie banner.
Some pages carry gear links to Amazon.se, marked Ad, or Annons on the Swedish pages. They are Amazon Associates links: if you buy something after following one, Amazon pays this site a commission. The price you pay does not change. Nothing loads from Amazon while you read, so nothing about you reaches Amazon until you follow one. Following one opens amazon.se, which sends Amazon your network address and a tag naming this site, and records one analytics event here, of the same kind as the install event, saying which item and which page. On Amazon's site Amazon's own privacy policy applies.
You can sign in on this website with the same account as the app, using an email address and password, a one-time link, Google or Apple. Signing in stores a session in your browser. That is functional storage, not tracking, and it is cleared when you sign out. The account panel also has a Delete account button, and it runs the same deletion described in section 17, including the shared bottle inventory.
Catalogue pages load data straight from our database, so your browser's network address reaches our database provider in the EU. Catalogue images are served through this site's own domain from that same provider. Typefaces are served from this site and are not requested from an outside font service.
One page is an exception. The password reset page loads the sign-in library from the jsDelivr content delivery network, so opening that page sends your network address to jsDelivr.
Version 1.0 of this policy described a waitlist signup form on this site and the rate limiting on it. There is no such form. The app is on both stores and the waitlist page was retired.
13. Who processes your data
| Who | What they receive | Why | Where |
|---|---|---|---|
| Supabase | Your email address and sign-in, everything on your shelf, your uploaded photographs, and the network address of each request | The database, the sign-in system, file storage and our own server functions | EU, Frankfurt |
| Google, Gemini API | Bottle label photographs, cocktail menu photographs, the text you type into AI search, and the contents of a recipe page you share in. No account identifier, no email, nothing from your shelf | Reading labels and menus, matching a search, turning a shared page into a recipe | Not pinned to a region. Assume outside the EU |
| Anthropic | The Swedish retail catalogue's own tasting description for a bottle on your shelf. Nothing identifying you | Translating that description into English | United States |
| Geoapify | Your coordinates, a search radius and venue categories, sent by our server. No account identifier, and not your network address | Finding the bar or restaurant you are checking in at | European Union |
| Overpass, over OpenStreetMap data | The same coordinates, radius and venue types, sent by our server when Geoapify is not configured. No account identifier, and not your network address | The same lookup, from community map data | Community-run mirrors in Europe |
| Mixpanel | Only if you consented: the events in section 8, your account identifier, device and operating system, and an approximate location derived from your network address | Understanding which parts of the app get used | EU |
| Sentry | Crash and error reports, with the three limits stated in section 9 | Finding and fixing faults | EU, Germany |
| RevenueCat | Your account identifier, platform, request network address, and on a purchase the store receipt data and store country | Knowing whether a subscription is active, across the Shelf apps | United States |
| Expo | Your device push token, and the title and body of each notification, which name your own bottles | Delivering notifications | United States |
| Apple and Google, as stores and delivery services | Your payment details, which go to them and not to us. Your sign-in identifier if you use Sign in with Apple or Google. The notification payload, for delivery to your phone | Selling and billing the subscription, distributing the app, signing you in, delivering notifications | Global, per their own terms |
| Open Food Facts and Open Products Facts | A scanned barcode and your device's network address | Looking up a bottle we do not hold | France |
| Vinmonopolet | A scanned barcode and your device's network address, and your address again when its product picture loads | Looking up a bottle we do not hold | Norway, EEA |
| UPCitemdb and Brocade | A scanned barcode and your device's network address | Looking up a bottle we do not hold | United States |
| DuckDuckGo | A web search for the barcode digits and your device's network address | The last-resort barcode lookup, when the five above all miss | United States |
| Systembolaget | Your device's network address when a catalogue product picture loads in the app, and when you open a product page the app links to | Showing the packshot, and taking you to the product | Sweden |
| Unsplash | Your device's network address when a cocktail with no picture of its own falls back to a stock photograph | Showing something rather than a blank card | United States |
| Amazon | Your browser's network address and a tag naming this site, only when you follow a gear link on the website to amazon.se. Nothing before you click | Showing you the product, and crediting the commission described in section 12 | EU, Luxembourg entity, for amazon.se |
| Vercel | Website requests, and the aggregate analytics in section 12 | Hosting this website | United States company |
| jsDelivr | Your browser's network address when the password reset page loads its script | Serving that one script | Global content delivery network |
We do not sell your data, we do not rent it, and we do not share it with data brokers. None of the parties above is an advertising network, and we do not send any of them data to advertise to you. The gear links to Amazon in section 12 are advertising, and they are marked, but nothing goes to Amazon until you choose to follow one. We are describing our own configuration and our contracts with them, not making a promise on their behalf about their other business.
There is no advertising in the app, no advertising identifier, and nothing that Apple defines as tracking, so the app does not show the tracking permission prompt.
14. Lawful basis for each purpose
- Performance of a contract, Article 6(1)(b): creating and holding your account, storing your shelf, check-ins, notes, shopping list, bookmarks and recipes, running a label scan, a menu scan, a barcode lookup, an AI search or a nearby-venue lookup that you asked for, delivering the notifications you turned on, and managing a subscription you bought. Without this there is no service to provide.
- Consent, Article 6(1)(a): usage analytics, and nothing else. Off by default, withdrawable at any time in Profile, and withdrawal does not affect what was processed before.
- Legitimate interests, Article 6(1)(f): crash and error reporting, so the app keeps working; the AI scan and search counters and the shared scan ledger, so the free limit can be applied and not circumvented and so we know what the AI calls are costing; the shared barcode table, the pooled venue list and the venue cache, so a lookup that works for one person works for the next and we do not pay for the same query twice; the AI search text cache, for the same reason; and aggregate website analytics.
Giving us this data is not a statutory requirement. It is what the app needs in order to be a shelf: without an account there is nowhere to put a bottle.
There is no automated decision-making that produces legal or similarly significant effects, and no profiling. A label reading is a machine guess that fills a form, and you review and edit every field before anything is saved.
15. How long we keep things
- Your account and your shelf: until you delete it. There is no expiry and no automatic clear-out.
- Anonymous accounts: the same, indefinitely. We do not run any job that removes an abandoned anonymous account. If you delete the app without ever signing up, the record stays in our database and there is no way for you or for us to get back to it.
- Data export files: pressing Export writes a file to private storage and gives you a link that expires after seven days. The link expires; the file does not. Nothing deletes it today. It contains your email address, your account identifier, your sign-in timestamps, your whole shelf, your check-ins, your bookmarks, the cocktails you created, your recipes, your shopping list, your barcode contributions, your scan counters and your notifications. If you want an export file removed, write to us and we will remove it.
- Photographs with no record pointing at them, meaning a cancelled label scan or a photograph whose record was deleted, and photographs attached to check-ins: these stay in storage, at their permanent addresses, because our deletion routine finds files only through your bottle rows. Write to us and we will remove them.
- The venue cache and the pooled venue list: kept as reference data. Neither carries an account identifier, so neither can be attributed to you or found on your behalf.
- The AI search text cache: normalised search text kept indefinitely, with no account identifier on it. It cannot be attributed to anyone, including by us.
- Barcode contributions: deleted when you delete your account.
- Your scan and search counters: one row holding how many AI scans and how many searches you have run. It is deleted whether or not your sign-in record is kept.
- The shared AI scan ledger: one row per scan, recording which Shelf app ran it, what kind of scan it was and the time. This is a different record from the counters above, and it behaves differently: it is removed only when your sign-in record itself is deleted. If your sign-in survives because you hold data in another Shelf app, the ledger survives with it.
- Crash reports: kept by Sentry on the standard retention schedule for our plan and then deleted automatically. Most are not filed under your account, so there is no reliable way to find yours; the two notification-token reports described in section 9 are the exception. If you tell us roughly when a crash happened we will look and remove what we can find.
- Analytics already sent to Mixpanel: deleting your account does not delete them, because we do not run a Mixpanel deletion step today. They are keyed to your account identifier. Ask us and we will delete them by hand.
- Your RevenueCat record: the subscriber record keyed to your account identifier stays with RevenueCat after you delete your account. Ask us and we will remove it.
- Cocktails you submitted to the shared catalogue: kept, because other people's check-ins reference them. Your account identifier stays on the row for as long as your sign-in record does, and both go together when the sign-in is deleted.
- Backups: deleted rows can remain in our database provider's routine backups for a period set by that provider until those backups age out. We are not going to quote a number for it.
16. Your rights under the GDPR
You have the right to access your data, to rectification of anything inaccurate, to erasure, to restriction of processing, to object to processing based on legitimate interests, to portability, and to withdraw consent at any time.
Three of these are buttons rather than emails, and using the button is faster than writing to us:
- Access and portability: Profile, then Data, then Export my data. It produces a JSON file with everything listed under data export files in section 15, and gives you a link valid for seven days.
- Erasure: Profile, then Account, then Delete Account. Or the account panel on this website. See section 17.
- Withdrawing consent: Profile, then Data, then Usage data.
For anything else, write to hello@mybarshelf.com from the address on the account. We will respond within one month, and it is free of charge. If we cannot identify you from what you send us, we may have to ask for more before we can act.
You also have the right to complain to a supervisory authority. In Sweden that is Integritetsskyddsmyndigheten (IMY), imy.se. You can also complain to the authority where you live.
17. Deleting your account
You can do it yourself. In the app: Profile, then Account, then Delete Account, then confirm twice. On this website: open the account panel, sign in, and press Delete account twice. No email and no asking us first. The account deletion page sets out the steps.
It runs when you confirm and finishes inside that request. There is no 30-day window and no queue. Version 1.0 of this policy said personal data was deleted within 30 days, and also that deletion immediately removed all of it. Neither was right: what is covered goes at once, and several things are not covered.
What is removed: your bottles, from the inventory shared with My Whiskey Shelf, so they disappear from there as well; the whiskey-side details and every whiskey pour attached to those bottles; your check-ins; your bookmarks; your shopping list and its items; your recipes; your recommendation feedback; your scanned cocktail menus; your barcode contributions; your scan and search counters; your profile record, including your analytics consent setting; your whiskey shopping list items and accessories; and your notification token and pending notifications for this app and for My Whiskey Shelf.
Photographs: the files linked from your bottle rows are removed after those rows, on a best-effort basis. If that step fails it is logged and the deletion still completes. Check-in photographs and files with no record pointing at them are not reached; section 15 says what to do about that.
Your sign-in record may stay. It is only deleted if the account holds no data in the other Shelf apps. If you also use My Coffee Shelf, My Wine Shelf, My Cigar Shelf, My Beer Shelf or My Supply Shelf, the sign-in stays so those apps keep working, and only the data listed above is removed. The same happens if we cannot check, which we treat as a reason to keep it rather than risk destroying another app's data. The app tells you the deletion succeeded either way and does not currently distinguish the two cases. Delete your data in the other apps first if you want the sign-in gone, or write to us and we will do it.
Cocktails you submitted to the shared catalogue stay, because other people's check-ins reference them. The record of who submitted a cocktail is cleared before the sign-in record is deleted.
What survives, and how to be rid of it. Saying nothing survives would be easier and it would not be true:
- Any data export file you asked for.
- Check-in photographs, and any photograph with no record pointing at it.
- Analytics events already sent to Mixpanel, keyed to your account identifier.
- Your RevenueCat subscriber record.
- Crash reports, including the two kinds that carry your account identifier.
- When your sign-in record is kept: the AI scan ledger, the log of notifications already sent, and any cocktail you created. Your scan and search counters are not on this list, because they are removed on both paths. Version 2.0 of this policy listed them here as well as among the things deletion removes, which was a contradiction; the counters go, and the ledger is the thing that stays.
- The venue cache, the pooled venue list and the AI search text cache. None of these carries an account identifier, so none can be traced to you, and we cannot find yours to delete on request.
Write to hello@mybarshelf.com and we will remove by hand what the button does not, apart from the last item, which we have no way to identify.
If you have an active subscription, deleting your account does not cancel it. Cancel it in your App Store account settings or your Google Play subscriptions first, or the store will keep billing you.
Deletion is permanent. We cannot restore it afterwards.
18. International transfers
Our database, sign-in, file storage, server functions, crash reporting and analytics are hosted in the European Union: the database and storage in Frankfurt, crash reporting in Germany, analytics on Mixpanel's EU service. Location lookups go to Geoapify in the EU or to Overpass mirrors in Europe. Two of the barcode databases are in France and one is in Norway, inside the EEA.
These leave the EEA:
- Google receives label photographs, menu photographs, AI search text and shared recipe pages, at a general endpoint we have not pinned to a European region.
- Anthropic, in the United States, receives catalogue tasting text.
- RevenueCat, in the United States, receives your account identifier and your subscription state.
- Expo, in the United States, receives your push token and the text of each notification.
- UPCitemdb, Brocade and DuckDuckGo, in the United States, receive a barcode and your device's network address.
- Unsplash, in the United States, receives your device's network address when a fallback cocktail picture loads.
- Vercel, a United States company, hosts this website, and jsDelivr serves one script on it.
- Apple and Google handle distribution, payment, notification delivery and, if you use them, sign-in.
For these we rely on the European Commission's standard contractual clauses, which form part of the data processing terms these providers publish, together with the safeguards described in those terms.
19. Age
My Bar Shelf concerns collections of alcoholic drinks and is intended solely for adults of legal drinking age in their country of residence. It is not directed at children, and we do not knowingly collect data from anyone below that age. If you believe a minor has given us data, write to us and we will delete it.
20. Changes to this policy
If we make material changes we will publish the updated version here and update the version number and effective date at the top of this page. If a change materially affects data we already hold about you, we will tell you before it takes effect.
Version 2.3, 5 September 2026, added one thing. The website now carries gear links to Amazon.se, marked Ad, or Annons on the Swedish pages. They are Amazon Associates links: a purchase through one pays this site a commission, and the price you pay does not change. The links were live before this page said so, which this version corrects. Section 12 describes what a click sends and records, and Amazon is added to the table in section 13. Nothing loads from Amazon before you click, and the app is unchanged.
Version 2.2, 1 September 2026, corrected three things in version 2.1. All three were written from the shape of the portfolio rather than from what this app does:
- Version 2.1 said four things are “set once and apply across the Shelf apps”, and listed the record of AI scans among them. That was wrong about this app's own limit. The shared ledger exists and section 15 describes it, but it is not what meters scanning here: My Bar Shelf's free limit counts bottles, not scans, and the label and menu scans stay free until your shelf holds 20 bottles, Bar Stock excluded. Section 5 now states the limit and section 3 lists what actually reaches past this app, naming the apps each thing reaches.
- Version 2.1 said “three of those four cover every Shelf app on the account”. None of the three does. The barcode table is shared with My Whiskey Shelf. The analytics row is shared with four named apps. A subscription unlocks what that particular subscription unlocks. Section 3.
- “One subscription covers every Shelf app on the same real account.” True of a bundle subscription and not of a single-app one, which unlocks only the app it was bought for and is what most current subscribers hold. Section 11.
Version 2.1, 1 September 2026, corrected two things in version 2.0:
- Version 2.0 contradicted itself about your scan and search counters. Section 17 listed them among the things deletion removes and, ten lines later, among the things that survive when your sign-in record is kept. Both could not be true. The counters are removed on both paths. The record that survives a kept sign-in is the AI scan ledger, which is a different table: one row per scan rather than one row per account. Sections 15 and 17 now describe the two separately, and the account deletion page says the same.
- Version 2.0 said the analytics setting covers every Shelf app you use. It covers five: My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf and My Cigar Shelf, which share one row on your account. My Coffee Shelf keeps its own separate answer and cannot see this one. My Supply Shelf sends no analytics at all. Sections 3 and 8 are corrected. The wording inside the app makes the same overstatement and is being corrected there too.
Version 2.0, 31 August 2026, replaced version 1.0 in full. Version 1.0 was written in April 2026 and described an app that was still being built. The app changed and the page did not. What changed:
- Removed the claim that location is stored on your device only. The app sends your coordinates to our server, which forwards them to Geoapify or to Overpass. Two outside recipients of your location were undisclosed. Now section 4, which also states what is cached and what is pooled.
- Removed the claim that camera images are processed instantly and not stored. Label photographs go to Google and are also uploaded to a storage area that needs no sign-in to read, before you have saved anything. Now section 5.
- Added the cocktail menu scan, which also sends a photograph to Google and was not mentioned at all.
- Added RevenueCat and the subscription. Version 1.0 named no purchase of any kind and did not list RevenueCat, which receives your account identifier on every launch. Now section 11.
- Removed the statement that analytics consent is withdrawn by contacting us. There is a switch in Profile. Now section 8. Version 1.0 also called the analytics anonymous; they are keyed to your account identifier.
- Removed "all personal data permanently deleted within 30 days" and "immediately removes all your personal data". Both were wrong, in opposite directions. Deletion is immediate for what it covers, and several things survive it. Now sections 15 and 17, with the survivors named and a by-hand removal route.
- Removed the waitlist section and the waitlist rate-limiting row. No such form exists on this site.
- Removed the iOS-only framing. The app is on the App Store and on Google Play.
- Removed the promise that we would update this policy before adding any new tracking. That promise was made before Mixpanel, RevenueCat and the Gemini integrations shipped, and it was not kept. Repeating it would not be worth anything.
- Added, all previously absent: anonymous accounts and the fact that they can consent to analytics; the bottle inventory shared with My Whiskey Shelf and the fact that deletion crosses both; the six outside barcode services, including the DuckDuckGo web search; the shared barcode table and the contributor identifier on it; the AI cocktail search and its text cache; the shared-recipe scrape; Anthropic; Expo, and the fact that notification text names your bottles; the three limits on what a crash report can contain; the approximate location Mixpanel derives from the request address; the free-tier limits; a table of every processor; a section on transfers out of the EEA; and the complaint route to IMY.
21. Contact
Questions or concerns about your privacy? Write to hello@mybarshelf.com.
Nisshagen Advisory AB, Stockholm, Sweden.