Privacy Policy
Last updated: 5 October 2026
1. About this policy
Jimmy Pour ("we", "our", "the app") helps adults plan and capture whisky and cigar sessions with friends. This policy describes how we handle information when you use the mobile app, our hosted API, our website and related services.
The short version: we do not sell your personal information. Some features send information to service providers who run parts of the app for us, and our AI features send information, including content your friends posted, to our AI providers. Section 4 explains exactly what goes to AI providers, and section 5 lists every service that handles your data.
2. Information we collect
- Account and profile. When you create an account we collect your email address and a password (stored as a one-way hash on our servers). We may collect a display name, first and last name, @handle, optional profile photo (avatar), optional partner contact details (for example an email or phone number for notifications you choose to send), and an optional hangout or default location (name and coordinates) if you provide them.
- Sign in with Apple or Google. We receive an identifier from the provider (subject ID), your email when the provider shares it (it may be a private relay address), and name fields. If you use Google sign-in, we may store your Google profile picture as your avatar.
- Session and library content. Content you create in the app is stored in a local database on your device and synchronized to our servers when you use the app while signed in, so it is available across devices and for features that rely on our servers. It is not limited to the device only. This includes live and planned sessions (titles, notes, scheduled times, location text and coordinates where you add them), session attendees, bottles, cigars and beers you log or bring, tasting captures (notes, ratings, reactions and related details), comments and likes, pour ratings, reviews, golf scores, friends and invites, crew newsletters you set up, your bottle library, your cigar inventory, the bottles and cigars you mark Had It, and your humidors and their readings.
- Taste Preferences and Taste Profile. Your Taste Preferences are what you tell us you like (for example favourite distilleries, bottles and cigars, dislikes, bucket list, hot take and price comfort). Your Taste Profile is our read of your taste, worked out from what you rate, review and write. Both are stored on our servers.
- Photos and images. Images you attach (for example session or capture photos, avatars, and bottle or cigar images) are uploaded to our media storage and associated with your account. Some features send photos to AI providers or to Replicate; see sections 4 and 5.
- Voice. If you use voice input or dictation, audio is sent to our servers and then to OpenAI for transcription. We do not retain the audio. Audio is processed only for as long as the transcription takes and is not stored in our database or media storage; only the resulting text is saved, as part of the note you were writing.
- Music recognition (iOS). If you use music recognition, Apple's ShazamKit listens through the microphone for up to 20 seconds and matches the sound with Apple's Shazam service. We do not receive the audio; we save only the song you choose to add.
- Location. If you allow it, the app reads your device's location once, while you are using it, to fill in a hangout or plan address. We do not track your location in the background. When you search for a place, the text you type is looked up through Google Places.
- Time zone. Each time the app syncs, it tells our servers your phone's time zone (for example America/Toronto). We keep the zones we've seen and when, to time reminders and recaps to your day and to choose your Include Me in Trends starting point.
- Humidor sensors. If you pair a Bluetooth humidity sensor, the app reads it directly over Bluetooth. Readings are stored with your humidor and synchronized to our servers. The sensor's maker receives nothing from us.
- Music (optional). If you connect Spotify, tokens for Spotify are stored on your device and the app talks to Spotify directly. If you use Apple Music features, our servers obtain a short-lived developer token and pass your catalog searches to Apple on your behalf.
- Subscriptions. We use RevenueCat to manage in-app purchases and entitlements. RevenueCat receives an app-specific user identifier we associate with your account. We do not receive your payment card details; Apple and Google process payments.
- Notifications. If you allow push notifications, we store your device's push token and send notifications through Expo's push service, which passes them to Apple or Google for delivery.
- Imports, catalog search and third-party sites. If you import bottle information from a URL (for example Whiskybase), our servers fetch that URL to retrieve the content you asked to import. When you search the cigar catalog, our servers send the cigar or brand name you typed to the Cigars API on RapidAPI; your name and account are not sent. Cigar imports can open Cigar Chief or Cigar Aficionado in an in-app browser, and those sites see your visit and search as they would from any browser.
- Connected AI assistants. If you connect an AI assistant to your account under Connected Agents, it can read and change your Jimmy Pour data within the access you grant. We keep a log of each action it takes (which tool it used, whether it succeeded, when, and a short summary of the request and result), which you can see on that screen. The assistant's own provider receives whatever the assistant reads, under that provider's terms.
- Activity history. We keep a history of what happens in your account, for example a pour logged, a rating saved or a session ended, with the time and the item it concerns, never the text you write. We use it to understand how the app is used and whether it works, and to build features from it. Whether it also counts in anonymous trends is your Include Me in Trends choice (section 11). It's deleted with your account.
- Crash and error reports. The app and our servers send crash and error reports to Sentry; see section 12.
- Technical and security data. We use HTTPS for data in transit. Our servers process IP addresses, HTTP metadata and similar information as part of normal operation, security and rate limiting (including behind a reverse proxy). For each AI request we log your user ID, the request type, when it happened and how much it used, for rate limits, cost control and abuse prevention.
3. How we use your information
- To provide and operate the service: authentication, syncing your data, showing sessions and plans to you and the people you invite, and storing media you upload.
- To send transactional and service emails (for example welcome and getting-started messages, password reset, email verification, friend and session invites, partner notifications, plan changes, session recaps and crew newsletters) through our email provider.
- To provide the AI features you and your friends use, as described in section 4.
- To work out anonymous trends, such as which whiskies and cigars are rising, from the ratings, pairings and Taste Preferences picks of people who chose Include Me in Trends (section 11).
- To provide optional features such as Apple Music search, place search, golf course details and subscription status.
- To find and fix crashes and errors, protect the service, enforce limits (including on AI features), and comply with law.
4. AI features and your data
We use two AI providers: OpenAI and xAI (Grok). When you use an AI feature, our servers send the information that feature needs to the provider, and store the result. The providers process that information to return a result to us.
- OpenAI handles voice transcription (the audio) and tidying dictated notes into fields (the transcript); reading a whisky label or cigar band from a photo, including the first step of the Shopping Companion (the photo); finding which end of a cigar is the head during cigar photo clean-up (the photo); filling in details for bottles and cigars you import (the product details); session names and plan themes (what you wrote for the plan); your Taste Profile read (a summary of your Taste Profile); and photo descriptions for sessions (see below).
- xAI handles session recaps, crew newsletters, the Shopping Companion's price and review search (the bottle name; xAI searches the web for it), Build A Flight, and partner messages (your name, the name you gave your partner, and the session's title, place, time and drink count).
- If xAI is unavailable, OpenAI may handle those requests instead.
Recaps and crew newsletters include your friends' content. To write a session recap, we send the AI provider what happened at the session: the names of the people there; the session's title, place and times; the bottles, cigars and beers; captures, tasting notes, ratings, reviews and comments; golf scores; and the descriptions of the session's photos. This includes content your friends posted, and content you post can appear in recaps your friends ask for. Crew newsletters work the same way across a crew's recent sessions, plus a rough home area worked out from recent plan locations so the newsletter can look up nearby events.
Session photos are sent to an AI vision model. When the host of a session has Jimmy Pour Pro, the photos posted in that session are sent to OpenAI's vision model, which writes a short caption and a description of what is in the frame (how many people, what they are holding, the setting and any readable text). This happens to every photo in the session, whoever posted it. The caption and description are stored with the photo and used in recaps, crew newsletters and moment labels.
Build A Flight sends the bottles in the libraries you choose to pour from (only libraries their owners share with friends), with each owner's own rating and the community's tasting tags for those bottles.
Use My Taste in Friends' Plans. Your taste profile (your Taste Preferences, such as favourite distilleries, bottles and cigars, dislikes, bucket list, hot take and price comfort) is only sent to an AI provider for someone else's request if you allow it. The setting is in Settings › Privacy, and it is off until you turn it on:
- Use My Taste in Friends' Plans: "Lets recaps, Build A Flight and your crew's newsletter send your taste profile to our AI providers when friends plan with you."
- The app also asks you on a card titled Two Privacy Choices: "Your taste profile goes to our AI providers for your friends' recaps, Build A Flight and your crew's newsletter." You can change your answer in Settings at any time.
- When it is off, your taste profile is left out of your friends' recaps, Build A Flight and the crew newsletter. You still appear by name, and what you posted in a shared session is still used as described above.
- Your own taste profile is always used for your own requests, such as a recap you generate or a flight you build.
5. Sharing and processors
We do not sell your personal information. We share data with these service providers only as needed to run the app:
- Railway hosts our API, database and media storage. Everything we store is held there.
- OpenAI and xAI provide our AI features, as described in section 4.
- Replicate runs cigar photo clean-up: a photo you add to a cigar in your inventory is sent to Replicate to cut the cigar out from the background. Your original photo is kept.
- Sentry receives crash and error reports from the app and our servers, as described in section 12.
- Resend sends our emails. It receives the recipient's email address and name and the content of the email.
- RevenueCat manages subscriptions, using an app-specific user identifier.
- Apple and Google provide sign-in, app distribution, payments and push notification delivery. Expo passes push notifications from our servers to Apple and Google.
- Google Maps Platform looks up places you search for (Google Places) and provides satellite images for golf plans (the plan's coordinates).
- GolfCourseAPI provides golf course details (the course name you choose).
- Spotify and Apple (Apple Music and ShazamKit) when you use those integrations as described in section 2.
- Cigars API (RapidAPI) looks up cigars and brands in the catalog. It receives the cigar or brand name you search for, not who you are.
- Whiskybase or similar sites, only when you start an import by URL. Cigar Chief and Cigar Aficionado, only when you open them from a cigar import.
- Amazon, only when you tap a link to buy a humidor sensor. Those links may be affiliate links. We count clicks without recording who you are.
We may disclose information if required by law or to protect our rights, users or safety.
6. Media and links
Uploaded images and other media may be available at URLs that can be opened by anyone who has the link. We do not operate a public gallery or search index of your media; treat shared links as sensitive.
When you share a tasting or a night, anyone with the link can view that page, without an account, until the link expires after 90 days, the session is deleted, or you leave the session. The page shows first names only, names a place only when it is a business, and is not indexed by search engines.
7. Friends, invites, and social features
When you invite someone or connect as friends, we use the information you provide (such as an email address or invite code) to deliver invites and link accounts. Other users may see your display name, avatar and content you share with them in the app (for example session or plan details, captures, comments, ratings and scores). Content in a shared session is also used by the AI features your friends use, as described in section 4.
8. Retention and deletion
Cloud backup window. Free accounts can restore the last 30 days of session history to a new or reinstalled device; Jimmy Pour Pro restores your full history. This limits what a device can restore, not what we keep: we do not delete older history from our servers because of it, and content already on your device is not removed. Upgrading restores your full history. If a Pro subscription lapses, the full window continues for a further 30 days.
Voice recordings are not retained. Dictation audio is used only to produce a transcript and is discarded as soon as that finishes; see section 2.
We retain your information for as long as your account is active and as needed to provide the service. You can delete your account and associated personal data in two ways:
- In the app: open Profile and tap Delete account. Email and password accounts confirm with their password; Apple or Google accounts confirm with an explicit prompt.
- From a browser: visit the public deletion page at www.jimmypour.com/account-deletion, or email support@jimmypour.com from the address on your account.
When you delete your account:
- We delete your profile and sign-in details, your Taste Preferences and Taste Profile, your Had It marks, your uploaded photos, your AI usage records, the log of actions connected AI assistants took for you, your notifications, share links and push tokens, and all sign-in sessions, and we revoke any connected AI assistant's access. Uploaded photos are deleted from storage shortly after you confirm.
- We remove your content (sessions, plans, captures, reviews, library, cigar inventory, humidors and friends), and golf scores and beer entries about you. It disappears at once from the app, from your devices and from your friends' devices. In our database it is first marked deleted, so your other devices and your friends' devices learn about the deletion when they next sync, and it is no longer linked to your email, name or sign-in details, which are erased. Thirty days later we erase the content itself: the text, notes, names, places and photos you added are wiped. What remains is a placeholder holding dates and figures that no longer identify you, such as ratings, quantities, golf scores and humidor readings.
- We keep, without your name: pour ratings and likes you gave stay as anonymous numbers so your friends' averages don't change; they are no longer linked to you. Comments you left on other people's moments stay as "[deleted]" so their threads have no gaps. Scores and beers you logged for someone else stay in their round with your name removed.
- We also keep a record of past purchases (without the store receipt) for accounting, crew newsletters that were already sent, and notifications friends already received (for example "Eric commented"). If you unsubscribed from our emails, we keep that email address on our unsubscribe list so we never email it again.
- Encrypted backups that include your data roll off on a schedule: database backups within about four weeks, and backups of uploaded photos within about 90 days. Our hosting provider's server logs and Sentry's error reports expire on those providers' own schedules. Records we are required to keep by law are kept as long as the law requires.
See www.jimmypour.com/account-deletion for the full table of what is deleted or kept.
9. Security
- Passwords are hashed on the server; we do not store plain-text passwords.
- Access tokens are sent over HTTPS; the app stores session tokens in secure storage on the device where the platform supports it.
- We apply reasonable administrative and technical safeguards; no method of transmission or storage is 100% secure.
10. Who may use the app
Jimmy Pour is intended for adults who are of legal drinking age in their jurisdiction (for example 21 or older where US alcohol laws apply, or the legal age where you live). The app is not directed at children, and we do not knowingly collect personal information from anyone under the legal drinking age.
11. Analytics
We do not run advertising in the app, and we do not sell or share your data for advertising. We keep the activity history described in section 2 ourselves; no analytics company receives it. Expo, which we use to build and update the app, counts how often the app is opened and which version is running. Apple, Google and your device platform may collect diagnostics or usage statistics according to their own policies when you install or use the app.
Include Me in Trends. If you choose it, your ratings, your pairings and the Taste Preferences answers you pick from our suggestions count in Jimmy Pour's own anonymous trends: statistics worked out across many people, such as which whiskies and cigars are rising. They count only in groups, never with your name, notes, photos or how much you drink, and nothing you type into Taste Preferences counts. The setting is in Settings › Privacy:
- Include Me in Trends: "Your ratings, pairings and preferences count in Jimmy Pour's anonymous trends. Never your name, notes or how much you drink."
- The app also asks you on a card titled Two Privacy Choices: "Anonymous, in groups only. Never your name, notes, photos or how much you drink." You can change your answer in Settings at any time.
- It starts on in the United States and off everywhere else, including when we can't tell your country. To choose that starting point we use the country of your hangout location, or else of your phone's time zone.
- None of your history counts until you've saved that card, and then only while the setting is on. Turning it off later takes all of your history back out.
- We do not sell or share these trends. Brand reports would be a separate opt-in, and there are none today.
12. Crash and error reporting
The app and our servers use Sentry to report crashes and errors so we can fix them. A report includes the error and where in the code it happened, your device model and operating system, the app version, recent in-app events leading up to the error (such as taps, the app moving to the background, network requests and log messages), whether the app session ended in a crash, and your Jimmy Pour user ID. Reports from our servers also include the request that failed (for example its address). We do not attach your email address or name.
13. International users
Our servers and service providers may be located in the United States or other countries. By using Jimmy Pour you understand your information may be processed in those locations.
14. Changes
We may update this policy from time to time. We will post the revised policy in the app and on this page and update the "Last updated" date.
15. Contact
For privacy questions, contact us through the app, or email support@jimmypour.com. For account deletion, see section 8 above or visit www.jimmypour.com/account-deletion.
← Back to Jimmy Pour