Privacy Policy
Last updated: 22 April 2026
1. About this policy
Jimmy Pour ("we", "our", "the app") helps adults plan and capture whisky and cigar sessions with friends. This policy describes how we handle information when you use the mobile app and our hosted API and related services.
2. Information we collect
- Account and profile. When you create an account we collect your email address and a password (stored as a one-way hash on our servers). We may collect display name, first and last name, optional profile photo (avatar), optional partner contact details (e.g. email or phone for notifications you choose to send), and optional hangout or default location (name and coordinates) if you provide them.
- Sign in with Apple or Google. We receive an identifier from the provider (subject ID), your email when the provider shares it (it may be a private relay address), and name fields. If you use Google sign-in, we may store your Google profile picture as your avatar.
- Session and library content (server-side when you are signed in). Content you create in the app—including live and planned sessions (titles, notes, scheduled times, location text and coordinates where you add them), session attendees, bottles and cigars you log or bring to sessions, tasting captures (notes, ratings, reactions, and related metadata), user reviews, friends and invite flows, and your bottle library and cigar inventory—is stored in a local database on your device and synchronized to our servers (PostgreSQL) when you use the app while signed in, so it is available across devices and for features that rely on the backend. It is not limited to the device only.
- Photos and images. Images you attach (for example session or capture photos, avatars, bottle or cigar images) are uploaded to our media storage and associated with your account.
- Voice and AI. If you use voice input or dictation, audio is sent to our servers and then to OpenAI (e.g. Whisper) for transcription. If you use AI-assisted features (such as identifying cigars from a photo), the image or text needed for that request is sent to our servers and to OpenAI; we may also use optional alternative AI providers (e.g. xAI) where configured. We log minimal usage metadata (such as user id, request type, and timing) for rate limiting, abuse prevention, and service improvement.
- Music (optional). If you connect Spotify, tokens and credentials for Spotify are stored on your device. If you use Apple Music features, our servers may obtain a short-lived developer token and proxy catalog search requests to Apple on your behalf.
- Subscriptions. We use RevenueCat to manage in-app purchases and entitlements. RevenueCat receives an app-specific user identifier we associate with your account. We do not receive your full payment card number from Apple or Google; those platforms process payments.
- Imports and third-party sites. If you import bottle information from a URL (for example Whiskybase), our servers may fetch that URL to retrieve the content you asked to import.
- Technical and security data. We use HTTPS for data in transit. Our servers process IP addresses, HTTP metadata, and similar information as part of normal operation, security, and rate limiting (including behind a reverse proxy).
3. How we use your information
- To provide and operate the service: authentication, syncing your data, showing sessions and plans to you and people you invite, and storing media you upload.
- To send transactional and service emails (for example welcome messages, password reset, email verification, friend and session invites, partner notifications, plan changes, and session-related summaries) through our email provider.
- To provide optional features such as voice transcription, AI identification, Apple Music search, and subscription status.
- To protect the service, enforce limits (including on AI features for subscribers), debug issues, and comply with law.
4. Sharing and processors
We do not sell your personal information. We share data with service providers only as needed to run the app, including for example:
- Hosting and database (e.g. Railway) for our API, PostgreSQL, and application storage.
- Email (Resend) for outbound email.
- Apple and Google for sign-in, app distribution, and platform services.
- OpenAI (and optionally other AI vendors we configure) for transcription and image or text analysis you request.
- RevenueCat for subscriptions.
- Spotify and Apple (Apple Music) when you use those integrations as described above.
- Whiskybase or similar sites only when you initiate an import by URL.
We may disclose information if required by law or to protect our rights, users, or safety.
5. Media and links
Uploaded images and other media may be available at URLs that can be opened by anyone who has the link. We do not operate a public gallery or search index of your media; treat shared links as sensitive.
6. Friends, invites, and social features
When you invite someone or connect as friends, we use the information you provide (such as email or invite codes) to deliver invites and link accounts. Other users may see your display name, avatar, and content you share with them in the app (for example session or plan details).
7. "Use backend data" (sync)
The app may offer a setting to control background synchronization of certain local data to our servers. Turning that option off stops that sync behaviour; it does not make the app fully "offline-only" while you remain signed in. Account sign-in, profile and media APIs, friend actions, email flows, AI features, and other requests may still use our servers as needed for those features.
8. Retention and deletion
We retain your information for as long as your account is active and as needed to provide the service. You can delete your account and associated personal data in two ways:
- In the app: open Profile and tap Delete account. Email and password accounts confirm with their password; Apple or Google accounts confirm with an explicit prompt.
- From a browser: visit the public deletion page at /account-deletion, or email support@jimmypour.com from the address on your account.
On deletion we remove or anonymize your profile, sessions, plans, captures, library, friends, uploaded media, and refresh tokens in active systems. Encrypted backups continue to roll off within approximately 30 days, and we may retain de-identified logs and records required by law. See /account-deletion for the full table of what is deleted or kept.
9. Security
- Passwords are hashed on the server; we do not store plain-text passwords.
- Access tokens are sent over HTTPS; the app stores session tokens in secure storage on the device where the platform supports it.
- We apply reasonable administrative and technical safeguards; no method of transmission or storage is 100% secure.
10. Who may use the app
Jimmy Pour is intended for adults who are of legal drinking age in their jurisdiction (for example 21 or older where US alcohol laws apply, or the legal age where you live). The app is not directed at children, and we do not knowingly collect personal information from anyone under the legal drinking age.
11. Diagnostics
We do not run our own in-app analytics or crash-reporting SDK in the app codebase. Apple, Google, and your device platform may still collect crash reports, diagnostics, or usage statistics according to their own policies when you install or use the app.
12. International users
Our servers and subprocessors may be located in the United States or other countries. By using Jimmy Pour you understand your information may be processed in those locations.
13. Changes
We may update this policy from time to time. We will post the revised policy in the app and on this page and update the "Last updated" date.
14. Contact
For privacy questions, contact us through the app, or email support@jimmypour.com. For account deletion, see section 8 above or visit /account-deletion.
← Back to Jimmy Pour