Version 0.6 · Effective: August 8, 2026
In plain words: We collect very little. Your beer photos are seen by your own Team with your name on them, and anonymously — photo, number, and time, with no name attached — by anyone who opens the feed for the city the beer was counted in. The photo file itself is delivered from an unguessable web address: anyone holding that address can open that one photo — still with no name attached — until the photo is deleted. They are automatically deleted after the season ends. We never ask for your exact (GPS-precise) location, your contacts, your phone number, or a password; if you sign in by email we keep that email so you can get your count back. We do record the country and city your connection appears to be in when you count a beer, and keep it with that beer. If you allow it when the app asks — once, and only after your first beer — your phone can instead tell us roughly which city you are in: a position your phone's own operating system deliberately blurs to about neighborhood-to-city size, never your street. We convert it to a city name on your phone and keep only the name, never coordinates. Saying no changes nothing; the connection's guess is used instead. If you choose to scan the code in a bar or shop that has joined the count, we record that place too, and its name shows on the beer — the place never learns anything about you. There are no ads and no trackers, and we never sell personal information. The only things we keep long-term are numbers: the world's count and anonymous statistics (like "Guinness was photographed 40,000 times in 23 countries"), which may be shared with sponsors — never anything about you personally. An AI briefly checks each photo to confirm it's a beer. You can delete your account and data any time.
Who is responsible for your data ("controller"): CAMMY LLC, a Florida limited liability company, 1738 SW 57th Ave, Unit # A505, Miami, FL 33155, USA. 100 Million Beers is a product of CAMMY LLC. Contact for all privacy matters: support@100millionbeers.com.
This policy covers the 100 Million Beers app, the websites 100millionbeers.com and 100million.app (and their www forms), our former addresses theworldrace.app and worldrace.app which now redirect to them, and related services (the "Service").
| What | Details | Why we use it | Legal basis (GDPR/UK) |
|---|---|---|---|
| Beer photos | Live-captured photos you submit. Shown to your Team with your name, and anonymously in the city feed for the city the beer was counted in — there, only the photo, its sequence number, and how long ago it was counted; never your name, Team, profile, or other beers, and with no way to browse from the photo back to you. Not published anywhere else. The photo file is served from a content-delivery network at a permanent, unguessable web address that works without signing in while the photo stands on the record; the address carries no identity, is not listed anywhere, and stops working when the photo is hidden, struck, or deleted (network caches may take a short time to clear). | Operating the count; verification (incl. AI check); moderation; aggregate statistics; limited promotion per the Terms | Contract; legitimate interests (fraud prevention) |
| Identity | An anonymous device/browser identity; if you "claim" your history, either your Sign in with Apple identifier (and, if Apple shares it, a relay email) or an email address you give us, to which we send a six-digit sign-in code. The email is stored so you can recover your count on a new device. No passwords, no phone numbers, no contact uploads. | Keeping your contributions attached to you; letting you sign back in | Contract |
| Declared allegiance | The home country and city you pick from a fixed list ("I drink for Lisbon"). A declaration — not tracked location. | Country/city rankings | Contract |
| Profile & your people | An optional display name you choose, shown to members of your Teams (on the wall, in the room's tallies, and in the notifications your teammates receive — e.g. "Name raised one"), printed on cards you yourself export, and never shown to strangers. Friendships: if you send or accept a friend request (possible only between people who already share a Team), we store who asked, who answered, and when — mutual or nothing, never a follower count. Blocks: who you have blocked, so their content stays hidden from you. | Operating Teams and the friends lens; keeping blocked content hidden | Contract |
| Coarse location — checked at every request | Derived by our hosting provider (Cloudflare) from your connection's IP address each time you use the Service: your country (for the age gate), and — on fixed-line connections — the region/city guess used in the moment for the suggestion and per-beer rows below. Your network operator's name is also evaluated, in memory only, to detect mobile-carrier connections (whose city guesses are unreliable — see the next row); it is never stored. We never request precise (GPS-grade) location, and we do not store your IP address as location data — the only device-location permission the app can ask for is the optional OS-blurred approximate grade, described in its own row below. | The age gate; regional availability; making the count geographic | Legal obligation / legitimate interests (age law compliance) |
| Coarse location — kept with each beer | When a beer is counted we record the country, region, and city your connection appears to be in at that moment and store it on that contribution ("where the beer was poured"). It is city-level at best, derived from your network rather than your device, and often reflects your provider rather than your exact whereabouts. On a mobile-data connection we keep only the country — a carrier routes its subscribers through regional gateways, so the town and even the state it reports are frequently wrong, and we would rather record nothing than record somewhere you have never been. It drives the globe, the city feeds, and city statistics. If you would rather not have this recorded, do not count a beer. If you have granted approximate device location (next row), the phone's word is used instead of this network guess. | Placing beers on the globe; city feeds; city/region statistics | Contract; legitimate interests (making the count geographic) |
| Approximate device location — optional | Only if you say yes to the system permission prompt, which the app shows once, after your first beer — never at install. Your phone then shares a position deliberately blurred by iOS/Android to roughly 1–20 km ("approximate" / "reduced accuracy" mode). We never request the precise grade, and because we never request it, the operating system itself prevents the app from receiving your exact location. On your device we convert the blurred position to the nearest city name from our fixed atlas and discard the coordinates: no latitude or longitude is ever sent to us, stored, or logged. Where granted, this city name replaces the network guess above as "where the beer was poured" (a scanned House still takes precedence). You can withdraw permission any time in your phone's Settings; the network guess simply resumes. | Placing beers on the globe more truthfully; city feeds; city/region statistics | Consent (withdrawable any time in device Settings) |
| The House you tell us you're in | Optional and only if you scan. Bars, restaurants and shops that join the count ("Houses") display a code. If you scan one, we record that House on the beers you count for the rest of that session, and we use the House's own business address as the place those beers were poured, instead of the network guess above. This is more precise than the network guess — but it comes from the business telling us where it is, not from your device: we still never request precise (GPS-grade) location, and scanning is always your choice. The House's name (and its logo, where it has given us one) is shown on that beer's card and on any card you choose to share, marking where the beer was poured. The House itself only ever sees counts — never who you are, what you drank, or anything else about you. | House boards and the House's place on the globe; marking where a beer was poured | Contract; legitimate interests (making the count geographic) |
| Age-gate confirmation | A record that you confirmed being 18+ and of legal drinking age, with date and country. | Proving we checked | Legal obligation / legitimate interests |
| Team & activity data | Team membership, your contributions' sequence numbers, timestamps, beer brand (from barcode or label — matched against the Open Food Facts catalog through our own servers: your device never contacts the catalog and no identity accompanies the lookup), cheers (ephemeral reactions that auto-delete within 7 days and are never totaled), a technical fingerprint (hash) of each photo used only to catch duplicates, correction stamps when you use "Correct the record," and milestone badges earned on your private shelf. Within a Team's room, members see each other's tallies (tonight and season) in seat order — never ranked, never outside the room. | Operating the Service; fraud prevention (duplicate detection) | Contract; legitimate interests (fraud prevention) |
| Push tokens | A device token if you enable notifications | Sending the notifications you enabled | Consent (you can disable any time) |
| Moderation records | Reports you make or receive, hidden-content states, appeals, fraud strikes, bans | Keeping the count honest and users safe | Legitimate interests; legal obligation |
| Crash & error data | Technical crash reports via Sentry (device model, OS, app state at crash) | Fixing bugs | Legitimate interests |
What we deliberately do NOT do: no ads or ad trackers; no analytics SDKs beyond the above; no sale or sharing of personal information for advertising; no precise (GPS-grade) location, ever — the only location permission the app can even ask for is the OS-blurred approximate grade; no contact-list access; no public profiles; and we never publish any individual's consumption — no public surface ranks or shows how much any person drank. (Your own record is visible to you and to your Team's room; cards you yourself export are shared by your act, not published by us.)
Every submitted photo is automatically reviewed by an AI model (currently OpenAI's, acting as our processor) to confirm it shows a beer and to read the beer's brand from the label. The AI sees the photo only for this check; OpenAI is contractually barred from using it to train models under our API terms. Photos the AI can't confirm are hidden and reviewed by a human, with an appeal path — no count is ever finally removed by a machine alone.
When the AI concludes a photo is not a beer, it also records a few plain words naming what the photo mainly showed (for example, "a laptop") — this label is kept with the moderation record and included in the rejection notice we send you, so a mistaken rejection is easy to spot and appeal. It is never shown to anyone else.
We compute aggregate statistics and may share or sell them to sponsors and partners. Two kinds exist: brand-level ("Brand X was photographed 40,000 times across 23 countries") and place-level (daily counts by country, region, or city — "Miami counted 7,000 beers in August"). These statistics are not personal data: they never identify you, your consumption, or any individual; the underlying place-level table contains only a date, a place name, and a number — no account, contribution, or connection identifiers of any kind. Before any statistic is shared externally, small cells are rolled up so no figure could describe fewer than a meaningful minimum of people. Individual-level data is never shared. This is a hard product rule.
| Provider | Role | Where |
|---|---|---|
| Supabase | Database, authentication, photo storage | Hosted in London, UK (eu-west-2) |
| Cloudflare | Website hosting, email forwarding for our support addresses, country/city detection, photo storage and delivery (R2 + CDN) — edge caches worldwide hold copies of on-the-record photos while they stand | Global network |
| Resend | Delivering the six-digit sign-in codes to your email address | US |
| Expo | Push notification delivery (receives notification content, which can include a teammate's display name and a beer's number) and app-update delivery (the app checks Expo's servers for updates at launch) | US |
| OpenAI | AI photo check (Section 2) | US |
| Sentry | Crash reporting | US |
| Apple | Sign in with Apple | US |
We have (or will sign before launch — see checklist) data-processing agreements with each. We also disclose data if legally compelled (court order, valid legal process) and in a merger/acquisition, in which case this policy continues to apply to data transferred.
Your data is primarily stored in the UK/EU (London). Because CAMMY LLC is a US company and some processors are US-based, data is transferred to the US under appropriate safeguards (EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework, per each processor's DPA).
EU/UK representative: CAMMY LLC has not yet appointed representatives under GDPR Art. 27 / UK GDPR.
| Data | Kept for |
|---|---|
| Beer photos | The current Season, then automatically deleted no later than 60 days after the Season ends — or immediately when you delete them or your account |
| Contribution ledger (sequence number, timestamp, team, brand, declared country/city, and the coarse country/region/city the beer was counted in — whether from the network guess or the phone's approximate word; never coordinates) | Kept as the permanent historical record of each Season — pseudonymous once your account is deleted |
| Email address (if you signed in by email) | Until you delete your account |
| Cheers | Ephemeral by design — auto-deleted within 7 days |
| Display name, friendships, blocks, badges | Until you delete your account |
| Account/identity | Until you delete your account |
| Push tokens | Until you disable notifications, uninstall, or delete your account |
| Age-gate confirmation | Life of the account/guest identity |
| Moderation & fraud records | Up to 2 years, or as long as legally required |
| Crash reports (Sentry) | 90 days |
| Server/security logs | Up to 30 days |
When you delete your account, your photos, your identity (including any email address you gave us), your team memberships, and your push tokens are deleted; your contributions' numbers, their timestamps, and the coarse place they were counted in remain in the season archive without any link to you (like a marathon result with the name removed).
Everyone: you can access, correct, or delete your data, or ask questions — in the App (Passport → settings) or by emailing support@100millionbeers.com. We respond within 30 days and never charge for a first request. We may need to verify you control the account — by a confirmation from within the App, by your sign-in, or by a code sent to the email address on the account. For guest identities that have never been claimed we hold no name or email at all, so the only way we can verify you is from within the App on the device that holds the identity.
EEA/UK/Switzerland: you additionally have the rights to restrict or object to processing, to data portability, to withdraw consent (e.g., disable push) without affecting prior processing, and to complain to your data-protection authority (in the UK, the ICO).
California: we do not "sell" or "share" personal information as the CCPA/CPRA defines those terms, and we collect no "sensitive personal information" categories requiring a limitation right. You have rights to know, delete, correct, and to non-discrimination. We honor Global Privacy Control signals where legally required.
Other countries (Canada, Brazil, Australia, and others): we apply this same policy globally — minimal collection, no selling, deletion on request — which we believe meets or exceeds PIPEDA, LGPD, and the Australian Privacy Principles at our scale.
The Service is restricted to people 18 or older who are at or above legal drinking age where they are — there is no under-18 access of any kind, so the Service is not directed to children and we do not knowingly collect children's data (COPPA and GDPR parental-consent regimes are not engaged by design). If we learn an under-age person used the Service, we delete their data and remove their counts. Report suspected under-age use to support@100millionbeers.com.
Photos and data are protected by access controls enforced at the database and storage layer. A photo is readable by your Team; once it is standing on the record it is additionally served, anonymously per Section 1, at a permanent unguessable delivery address that works for anyone holding it — such addresses are random, unlisted, carry no identity, and are revoked by removal or deletion (edge caches may take a short time to clear). A hidden, struck, or removed photo is withdrawn from delivery and readable by no one outside our moderation desk. Data is encrypted in transit and secrets are managed outside the codebase. No system is perfectly secure; if a breach affects you, we will notify you and regulators as the law requires.
We'll post changes here with a new version and date, and announce material changes in the App or on the Site at least 14 days before they take effect. Prior versions are available on request.
Contact: CAMMY LLC · 1738 SW 57th Ave, Unit # A505, Miami, FL 33155, USA · support@100millionbeers.com