Last updated: 31 Aug 2026

Privacy Policy

This Privacy Policy explains how Whisky Label Scanner (“the App”, “we”, “us”) collects, uses, shares, and deletes information.

At a glance: We do not sell personal data. Account, scan, purchase, and optional advertising-measurement data are used to provide and improve the App. Advertising measurement is disabled unless you explicitly allow it in the App.

Information We Collect

Account and profile information

If you create or use an account, Firebase Authentication and Firebase services process identifiers and profile information needed to authenticate you, synchronize your data, protect the service, and support account deletion.

Scans, analyses, and images

When you choose to analyze a whisky label, the selected image and related scan data may be uploaded to Firebase and our processing providers to produce and store the result. This information can include the image, recognized label text, analysis results, timestamps, and saved journal data. Camera preview frames are not uploaded merely because the camera is open.

Editorial reviews

The App displays read-only editorial whisky reviews sourced from The Whisky Edition. Viewing a feed or review may create a product-interaction event if you have allowed advertising measurement. Editorial reviews are external content and are not user endorsements.

Purchases

Apple processes payments. RevenueCat processes transaction identifiers, product identifiers, entitlement and subscription status, purchase dates, renewal, cancellation, expiration, and billing-status events. We do not receive your full payment-card number.

Optional advertising measurement

After you choose “Allow measurement,” AppsFlyer may process device identifiers, attribution data, and limited product-interaction events such as tutorial completion, first scan, review views, paywall views, and checkout initiation. Revenue events are sent server-to-server by RevenueCat to avoid duplicate reporting. We do not send scan contents, review text, email addresses, or other free-form personal content in these events.

If you decline the in-app choice, AppsFlyer does not start and no AppsFlyer identifier is sent to RevenueCat. If you allow measurement but deny or restrict Apple’s App Tracking Transparency permission, advertising identifiers and partner sharing are disabled and measurement is limited to privacy-preserving methods supported by Apple. You can withdraw the in-app choice in Settings; Apple’s system permission is managed in iOS Settings.

Diagnostics and support

Apple and our service providers may process crash, device, operating-system, app-version, and security diagnostics. If you contact support, we process your email address and the information you include in the request.

How We Use Information

Service Providers and Sharing

We use Apple, Firebase/Google, RevenueCat, and—only after measurement consent—AppsFlyer. These providers process data under their own terms and privacy commitments to deliver authentication, hosting, storage, purchases, subscriptions, diagnostics, security, and attribution services. AppsFlyer may provide permitted attribution results to enabled advertising partners such as Meta or X under the consent and ATT choices described above.

We do not sell personal data. We may disclose information when required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards.

Retention and International Processing

Account, analysis, image, and purchase records are retained while needed to provide the App and for security, fraud prevention, accounting, legal obligations, and dispute handling. Provider records and backups may remain for a limited period after deletion. Service providers may process data outside your country using contractual safeguards and other lawful transfer mechanisms.

Account and Data Deletion

You can request permanent account deletion in the App under Settings → Delete My Account. The process removes your Firebase profile, analyses, and uploaded files; removes personal fields from or hides eligible legacy community contributions; queues connected-provider deletion requests; and deletes the Firebase Authentication account. Some provider operations complete asynchronously, and limited records may be retained where legally required. You may also contact us for access, correction, deletion, or objection requests.

Device Permissions

Security

We use reasonable technical and organizational safeguards, but no transmission or storage method is completely secure.

Age Restrictions

The App is intended only for people at or above the legal drinking age in their jurisdiction. We do not knowingly collect information from people below that age.

Changes

We may update this policy as the App or legal requirements change. The date above identifies the latest version.

Contact

For privacy questions or requests, email hpapphelp@gmail.com.