Privacy Policy
Last updated: March 2026
1. Introduction
Whiskd ("we", "our", "us") operates the Whiskd mobile application. This Privacy Policy explains what personal information we collect, how we use it, and your rights regarding that information.
By using Whiskd, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
Account Information
- Email address (for authentication)
- Display name and username (chosen by you)
- Profile photo (optional, uploaded by you)
- Authentication provider data (if signing in via Apple or Google: name and email only)
Content You Create
- Matcha ratings (score, flavour tags, tasting notes, photos)
- Venue additions
- Profile bio
Automatically Collected
- Device type and operating system version
- Approximate location (when you grant permission — used to find nearby venues, not stored as precise GPS coordinates on your profile)
- Anonymised app usage analytics
What We Do Not Collect
- Date of birth
- Phone number
- Payment information
- Precise location history or background tracking
- Contacts or address book
3. How We Use Your Information
- To provide the app's core features: ratings, discovery, and venue search
- To display your profile and ratings to other users (public by design)
- To send push notifications you opt into: likes, badge achievements, and streak reminders
- To improve the app through anonymised analytics
- To enforce our community guidelines and prevent abuse
4. Data Storage and Security
- Data is stored securely in cloud infrastructure hosted in the Asia-Pacific region
- All data is transmitted over HTTPS/TLS encryption
- Authentication tokens are stored using your device's secure keychain (iOS) or keystore (Android)
- Row-level security is enforced at the database level to protect your data
5. Data Sharing
We do not sell your personal data. We do not share your data with third-party advertisers.
We use the following third-party services to operate the app:
- Supabase — database and authentication
- Expo — push notifications
- Google Maps — venue search and mapping
Your ratings and profile are visible to other Whiskd users. This is a core social feature of the app.
6. Your Rights
- Access: You can view all your data in the app (profile, ratings, badges).
- Correction: You can edit your profile and ratings at any time.
- Deletion: You can request deletion of your account and all associated data by contacting hello@getwhiskd.app. We will process requests within 30 days.
- Data portability: Contact us to request an export of your data.
7. Location Data
- Location permission is optional
- Used only to show nearby venues and sort discovery results by distance
- We request "when in use" permission only, not background location
- Your precise coordinates are never stored on your profile or shared with other users
8. Photos
- Photos you upload to ratings are stored in our cloud storage and visible to all users
- Camera permission is optional and only used when you choose to take a photo
- Photo library permission is optional and only used when you choose to pick an existing photo
9. Push Notifications
- Push notifications are optional and can be disabled at any time via device settings
- Used for: likes on your ratings, badge achievements, and streak reminders
- Delivered via the Expo Push Notification service
10. Children's Privacy
Whiskd is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at hello@getwhiskd.app.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the app or email. Your continued use of Whiskd after changes are posted constitutes acceptance of the updated policy.
12. Contact
If you have questions about this Privacy Policy or your data, contact us at:
hello@getwhiskd.app
Melbourne, Australia