100 Million Beers · The Official Registry

Privacy Policy — 100 Million Beers

Version 0.6 · Effective: August 8, 2026

In plain words: We collect very little. Your beer photos are seen by your own Team with your name on them, and anonymously — photo, number, and time, with no name attached — by anyone who opens the feed for the city the beer was counted in. The photo file itself is delivered from an unguessable web address: anyone holding that address can open that one photo — still with no name attached — until the photo is deleted. They are automatically deleted after the season ends. We never ask for your exact (GPS-precise) location, your contacts, your phone number, or a password; if you sign in by email we keep that email so you can get your count back. We do record the country and city your connection appears to be in when you count a beer, and keep it with that beer. If you allow it when the app asks — once, and only after your first beer — your phone can instead tell us roughly which city you are in: a position your phone's own operating system deliberately blurs to about neighborhood-to-city size, never your street. We convert it to a city name on your phone and keep only the name, never coordinates. Saying no changes nothing; the connection's guess is used instead. If you choose to scan the code in a bar or shop that has joined the count, we record that place too, and its name shows on the beer — the place never learns anything about you. There are no ads and no trackers, and we never sell personal information. The only things we keep long-term are numbers: the world's count and anonymous statistics (like "Guinness was photographed 40,000 times in 23 countries"), which may be shared with sponsors — never anything about you personally. An AI briefly checks each photo to confirm it's a beer. You can delete your account and data any time.

Who is responsible for your data ("controller"): CAMMY LLC, a Florida limited liability company, 1738 SW 57th Ave, Unit # A505, Miami, FL 33155, USA. 100 Million Beers is a product of CAMMY LLC. Contact for all privacy matters: support@100millionbeers.com.

This policy covers the 100 Million Beers app, the websites 100millionbeers.com and 100million.app (and their www forms), our former addresses theworldrace.app and worldrace.app which now redirect to them, and related services (the "Service").

1. What we collect, why, and on what legal basis

WhatDetailsWhy we use itLegal basis (GDPR/UK)
Beer photosLive-captured photos you submit. Shown to your Team with your name, and anonymously in the city feed for the city the beer was counted in — there, only the photo, its sequence number, and how long ago it was counted; never your name, Team, profile, or other beers, and with no way to browse from the photo back to you. Not published anywhere else. The photo file is served from a content-delivery network at a permanent, unguessable web address that works without signing in while the photo stands on the record; the address carries no identity, is not listed anywhere, and stops working when the photo is hidden, struck, or deleted (network caches may take a short time to clear).Operating the count; verification (incl. AI check); moderation; aggregate statistics; limited promotion per the TermsContract; legitimate interests (fraud prevention)
IdentityAn anonymous device/browser identity; if you "claim" your history, either your Sign in with Apple identifier (and, if Apple shares it, a relay email) or an email address you give us, to which we send a six-digit sign-in code. The email is stored so you can recover your count on a new device. No passwords, no phone numbers, no contact uploads.Keeping your contributions attached to you; letting you sign back inContract
Declared allegianceThe home country and city you pick from a fixed list ("I drink for Lisbon"). A declaration — not tracked location.Country/city rankingsContract
Profile & your peopleAn optional display name you choose, shown to members of your Teams (on the wall, in the room's tallies, and in the notifications your teammates receive — e.g. "Name raised one"), printed on cards you yourself export, and never shown to strangers. Friendships: if you send or accept a friend request (possible only between people who already share a Team), we store who asked, who answered, and when — mutual or nothing, never a follower count. Blocks: who you have blocked, so their content stays hidden from you.Operating Teams and the friends lens; keeping blocked content hiddenContract
Coarse location — checked at every requestDerived by our hosting provider (Cloudflare) from your connection's IP address each time you use the Service: your country (for the age gate), and — on fixed-line connections — the region/city guess used in the moment for the suggestion and per-beer rows below. Your network operator's name is also evaluated, in memory only, to detect mobile-carrier connections (whose city guesses are unreliable — see the next row); it is never stored. We never request precise (GPS-grade) location, and we do not store your IP address as location data — the only device-location permission the app can ask for is the optional OS-blurred approximate grade, described in its own row below.The age gate; regional availability; making the count geographicLegal obligation / legitimate interests (age law compliance)
Coarse location — kept with each beerWhen a beer is counted we record the country, region, and city your connection appears to be in at that moment and store it on that contribution ("where the beer was poured"). It is city-level at best, derived from your network rather than your device, and often reflects your provider rather than your exact whereabouts. On a mobile-data connection we keep only the country — a carrier routes its subscribers through regional gateways, so the town and even the state it reports are frequently wrong, and we would rather record nothing than record somewhere you have never been. It drives the globe, the city feeds, and city statistics. If you would rather not have this recorded, do not count a beer. If you have granted approximate device location (next row), the phone's word is used instead of this network guess.Placing beers on the globe; city feeds; city/region statisticsContract; legitimate interests (making the count geographic)
Approximate device location — optionalOnly if you say yes to the system permission prompt, which the app shows once, after your first beer — never at install. Your phone then shares a position deliberately blurred by iOS/Android to roughly 1–20 km ("approximate" / "reduced accuracy" mode). We never request the precise grade, and because we never request it, the operating system itself prevents the app from receiving your exact location. On your device we convert the blurred position to the nearest city name from our fixed atlas and discard the coordinates: no latitude or longitude is ever sent to us, stored, or logged. Where granted, this city name replaces the network guess above as "where the beer was poured" (a scanned House still takes precedence). You can withdraw permission any time in your phone's Settings; the network guess simply resumes.Placing beers on the globe more truthfully; city feeds; city/region statisticsConsent (withdrawable any time in device Settings)
The House you tell us you're inOptional and only if you scan. Bars, restaurants and shops that join the count ("Houses") display a code. If you scan one, we record that House on the beers you count for the rest of that session, and we use the House's own business address as the place those beers were poured, instead of the network guess above. This is more precise than the network guess — but it comes from the business telling us where it is, not from your device: we still never request precise (GPS-grade) location, and scanning is always your choice. The House's name (and its logo, where it has given us one) is shown on that beer's card and on any card you choose to share, marking where the beer was poured. The House itself only ever sees counts — never who you are, what you drank, or anything else about you.House boards and the House's place on the globe; marking where a beer was pouredContract; legitimate interests (making the count geographic)
Age-gate confirmationA record that you confirmed being 18+ and of legal drinking age, with date and country.Proving we checkedLegal obligation / legitimate interests
Team & activity dataTeam membership, your contributions' sequence numbers, timestamps, beer brand (from barcode or label — matched against the Open Food Facts catalog through our own servers: your device never contacts the catalog and no identity accompanies the lookup), cheers (ephemeral reactions that auto-delete within 7 days and are never totaled), a technical fingerprint (hash) of each photo used only to catch duplicates, correction stamps when you use "Correct the record," and milestone badges earned on your private shelf. Within a Team's room, members see each other's tallies (tonight and season) in seat order — never ranked, never outside the room.Operating the Service; fraud prevention (duplicate detection)Contract; legitimate interests (fraud prevention)
Push tokensA device token if you enable notificationsSending the notifications you enabledConsent (you can disable any time)
Moderation recordsReports you make or receive, hidden-content states, appeals, fraud strikes, bansKeeping the count honest and users safeLegitimate interests; legal obligation
Crash & error dataTechnical crash reports via Sentry (device model, OS, app state at crash)Fixing bugsLegitimate interests

What we deliberately do NOT do: no ads or ad trackers; no analytics SDKs beyond the above; no sale or sharing of personal information for advertising; no precise (GPS-grade) location, ever — the only location permission the app can even ask for is the OS-blurred approximate grade; no contact-list access; no public profiles; and we never publish any individual's consumption — no public surface ranks or shows how much any person drank. (Your own record is visible to you and to your Team's room; cards you yourself export are shared by your act, not published by us.)

2. The AI photo check

Every submitted photo is automatically reviewed by an AI model (currently OpenAI's, acting as our processor) to confirm it shows a beer and to read the beer's brand from the label. The AI sees the photo only for this check; OpenAI is contractually barred from using it to train models under our API terms. Photos the AI can't confirm are hidden and reviewed by a human, with an appeal path — no count is ever finally removed by a machine alone.

When the AI concludes a photo is not a beer, it also records a few plain words naming what the photo mainly showed (for example, "a laptop") — this label is kept with the moderation record and included in the rejection notice we send you, so a mistaken rejection is easy to spot and appeal. It is never shown to anyone else.

3. Aggregate brand statistics (the sponsor data)

We compute aggregate statistics and may share or sell them to sponsors and partners. Two kinds exist: brand-level ("Brand X was photographed 40,000 times across 23 countries") and place-level (daily counts by country, region, or city — "Miami counted 7,000 beers in August"). These statistics are not personal data: they never identify you, your consumption, or any individual; the underlying place-level table contains only a date, a place name, and a number — no account, contribution, or connection identifiers of any kind. Before any statistic is shared externally, small cells are rolled up so no figure could describe fewer than a meaningful minimum of people. Individual-level data is never shared. This is a hard product rule.

4. Who processes data for us (subprocessors)

ProviderRoleWhere
SupabaseDatabase, authentication, photo storageHosted in London, UK (eu-west-2)
CloudflareWebsite hosting, email forwarding for our support addresses, country/city detection, photo storage and delivery (R2 + CDN) — edge caches worldwide hold copies of on-the-record photos while they standGlobal network
ResendDelivering the six-digit sign-in codes to your email addressUS
ExpoPush notification delivery (receives notification content, which can include a teammate's display name and a beer's number) and app-update delivery (the app checks Expo's servers for updates at launch)US
OpenAIAI photo check (Section 2)US
SentryCrash reportingUS
AppleSign in with AppleUS

We have (or will sign before launch — see checklist) data-processing agreements with each. We also disclose data if legally compelled (court order, valid legal process) and in a merger/acquisition, in which case this policy continues to apply to data transferred.

5. International transfers

Your data is primarily stored in the UK/EU (London). Because CAMMY LLC is a US company and some processors are US-based, data is transferred to the US under appropriate safeguards (EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework, per each processor's DPA).

EU/UK representative: CAMMY LLC has not yet appointed representatives under GDPR Art. 27 / UK GDPR.

6. How long we keep things (retention)

DataKept for
Beer photosThe current Season, then automatically deleted no later than 60 days after the Season ends — or immediately when you delete them or your account
Contribution ledger (sequence number, timestamp, team, brand, declared country/city, and the coarse country/region/city the beer was counted in — whether from the network guess or the phone's approximate word; never coordinates)Kept as the permanent historical record of each Season — pseudonymous once your account is deleted
Email address (if you signed in by email)Until you delete your account
CheersEphemeral by design — auto-deleted within 7 days
Display name, friendships, blocks, badgesUntil you delete your account
Account/identityUntil you delete your account
Push tokensUntil you disable notifications, uninstall, or delete your account
Age-gate confirmationLife of the account/guest identity
Moderation & fraud recordsUp to 2 years, or as long as legally required
Crash reports (Sentry)90 days
Server/security logsUp to 30 days

When you delete your account, your photos, your identity (including any email address you gave us), your team memberships, and your push tokens are deleted; your contributions' numbers, their timestamps, and the coarse place they were counted in remain in the season archive without any link to you (like a marathon result with the name removed).

7. Your rights

Everyone: you can access, correct, or delete your data, or ask questions — in the App (Passport → settings) or by emailing support@100millionbeers.com. We respond within 30 days and never charge for a first request. We may need to verify you control the account — by a confirmation from within the App, by your sign-in, or by a code sent to the email address on the account. For guest identities that have never been claimed we hold no name or email at all, so the only way we can verify you is from within the App on the device that holds the identity.

EEA/UK/Switzerland: you additionally have the rights to restrict or object to processing, to data portability, to withdraw consent (e.g., disable push) without affecting prior processing, and to complain to your data-protection authority (in the UK, the ICO).

California: we do not "sell" or "share" personal information as the CCPA/CPRA defines those terms, and we collect no "sensitive personal information" categories requiring a limitation right. You have rights to know, delete, correct, and to non-discrimination. We honor Global Privacy Control signals where legally required.

Other countries (Canada, Brazil, Australia, and others): we apply this same policy globally — minimal collection, no selling, deletion on request — which we believe meets or exceeds PIPEDA, LGPD, and the Australian Privacy Principles at our scale.

8. Age

The Service is restricted to people 18 or older who are at or above legal drinking age where they are — there is no under-18 access of any kind, so the Service is not directed to children and we do not knowingly collect children's data (COPPA and GDPR parental-consent regimes are not engaged by design). If we learn an under-age person used the Service, we delete their data and remove their counts. Report suspected under-age use to support@100millionbeers.com.

9. Security

Photos and data are protected by access controls enforced at the database and storage layer. A photo is readable by your Team; once it is standing on the record it is additionally served, anonymously per Section 1, at a permanent unguessable delivery address that works for anyone holding it — such addresses are random, unlisted, carry no identity, and are revoked by removal or deletion (edge caches may take a short time to clear). A hidden, struck, or removed photo is withdrawn from delivery and readable by no one outside our moderation desk. Data is encrypted in transit and secrets are managed outside the codebase. No system is perfectly secure; if a breach affects you, we will notify you and regulators as the law requires.

10. Changes

We'll post changes here with a new version and date, and announce material changes in the App or on the Site at least 14 days before they take effect. Prior versions are available on request.

Contact: CAMMY LLC · 1738 SW 57th Ave, Unit # A505, Miami, FL 33155, USA · support@100millionbeers.com