Pint Pinger Privacy Policy
Last updated: 9 August 2026
This policy explains what Pint Pinger does with your information. It is written to be read, not to be survived.
Who is responsible
Pint Pinger is operated by Sebastian Belfiore ("the operator", "we"), an individual, not a company. For anything in this policy, including any request about your data, write to Seb@belfiore.io.
What the app collects
Pint Pinger stores your content in Apple's iCloud (CloudKit), in a container tied to this app. That content is:
- Photos you attach to posts, and any photos you add to your profile.
- Location of a post, only when you tag one: the coordinates, a place name, and a country code, captured once at the moment you post. The app never tracks your location in the background, and never collects location outside posting.
- Your display name and the optional profile details you fill in (favourite beers, free-text answers).
- Post details: beer names, styles, notes, timestamps, and which group the post belongs to.
- Reactions and votes: clinks, comments, views, and Hall of Fame or Gutter votes, including the short written reasons attached to votes.
- Group membership records: which groups (by invite code) your account belongs to, and when you joined.
- Safety records: reports you submit, users you block, and content hidden for you.
- An account identifier created by CloudKit for your iCloud account. This is an opaque string. The app never sees your Apple ID email address, your password, or your real name unless you type it as your display name.
- A push notification token for each device you use, stored so notifications can reach you.
A note on the word "public": CloudKit's public database means the data sits in the app's shared container rather than inside your personal iCloud storage. It does not mean the content is published. In the app, a post is only ever shown to members of the group it was posted to.
Why we collect it, and the legal basis
Everything above exists to make the app function: to show your posts to your group, to deliver notifications, and to keep the group safe. Where the UK and EU General Data Protection Regulation applies, the legal bases are:
- Performance of a contract (these are the app's terms, and this data is what makes the app work) for your posts, photos, profile, group memberships, reactions, and notification tokens.
- Consent for location, camera, photo library, microphone, and notifications. Each is requested by iOS at the point of use, each is optional, and each can be withdrawn at any time in iOS Settings.
- Legitimate interests for safety records (reports and blocks), in keeping the service usable and its users protected from abuse.
Who processes it
- Apple (iCloud/CloudKit) stores all app content and provides the account identity. Apple's own privacy policy applies to its handling.
- Google (Firebase Cloud Messaging) delivers push notifications. To do that, a device push token, the notification text, the sender's display name, and content identifiers pass through Google's servers.
- The website host for the pages you are reading now keeps standard server logs, as any web host does.
- Cloudflare and Anthropic, only if the optional beer-identification feature is switched on. It is switched off in the current version. If it is ever enabled, a downscaled copy of a pint photo would be sent to a Cloudflare Worker operated for this app, which forwards it to Anthropic to guess the beer, and the photo would not be retained by either. With the feature off, no photo leaves Apple's systems.
We do not sell your data, and we do not share it with anyone beyond the processors listed above.
International transfers
These providers operate globally and your data may be processed outside your country, including in the United States. Apple, Google, and Cloudflare each publish the safeguards they use for such transfers, including the European Commission's Standard Contractual Clauses.
What is NOT collected
No advertising identifiers. No analytics or attribution SDKs. No tracking of you across other companies' apps or websites. No contacts upload. No background location. No microphone recording outside the moment you hold the button to dictate a vote reason, which is transcribed by Apple's speech recognition and not stored as audio.
If your device has Apple's Sensitive Content Warning switched on, photos are checked for explicit content on the device itself before posting. That check runs entirely on your iPhone; no photo is uploaded for it, and we receive no result from it.
How long it is kept, and how to delete it
Content stays until you delete it.
- Deleting a post removes the post and its photos.
- Deleting your account (Settings, then Delete My Account) permanently removes your posts, photos, comments, reactions, group memberships, profile, reports, and blocks. It cannot be undone.
- Vote outcomes that form part of a group's history remain after account deletion, with your name no longer attached and any written reasons blanked.
- Blocks that other people placed against your account remain, because they belong to those people and continue to protect them.
Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or stop processing it. We do not restrict these rights to one region.
The app gives you most of this directly: you can edit your profile and your posts, delete individual posts, and delete your entire account from Settings. For anything else, including a portable copy of your data, email Seb@belfiore.io and we will respond within 30 days.
If UK or EU data protection law applies to you, those rights are legal entitlements rather than a courtesy, and they also include the right to object to or restrict processing. If you believe your data has been handled improperly, you can complain to your national data protection authority.
Security
Data in transit is encrypted (HTTPS/TLS). Content is stored in Apple's CloudKit and secured by Apple's infrastructure. Access to a group's content requires being a member of that group. No system is perfectly secure, and we do not claim otherwise.
Children
Pint Pinger is for people of legal drinking age in their country and is not directed at children. The app asks you to confirm your legal drinking age before you can use it. If you believe a child has provided us with personal data, write to Seb@belfiore.io and we will delete it.
This website
These pages exist to describe the app and to publish this policy and the terms. There is no account, no login, and no app data here. The collection described above happens inside the app.
Changes to this policy
If this policy changes materially, the updated date at the top changes and the app asks you to accept the change before you continue using it.