Na pivo
Privacy Policy
Last updated: 23 August 2026
This is an English translation for convenience. The Czech version is the binding one.
Who we are
The Na pivo app is operated by a natural person (a solo developer), referred to below as âweâ or âthe operatorâ. This policy explains what data the app processes, what it uses the data for and what rights you have when it comes to privacy. We try to collect as little data as possible: we do not store continuous GPS history or your movement route, and we use no advertising or external analytics tools.
What data we process
Location
The app uses your current location to find pubs nearby, to point the direction arrow at the pub you picked (the compass) and to show the surroundings on the map. Your current or approximate location can be sent to our own server, which searches a local directory of pubs. We do not store continuous GPS history, individual GPS points or your movement route.
One thing to watch out for, though: the records you create in the app yourself (beers logged, pub visits, ratings, plans) contain the specific pub including its location and the time of the record. Those records therefore build up a history of the venues you visited tied to your account, but not the route you took between them. More detail in the âBeer Diary and your recordsâ section.
Background location (pub reminders)
The optional reminder feature (âarenât you in a pub right now?â) uses geofencing: the app sets small zones around up to 20 of the nearest pubs, and your phoneâs system tells it when you enter or leave one. This needs background location permission (âAlwaysâ on iOS). The feature is off by default; you switch it on and off yourself in settings.
Zones are evaluated on the phone itself. No coordinates are sent to the server when you enter a zone or leave it; the reminder appears locally. When the app refreshes the list of nearby pubs for the zones while in the foreground, it sends your current location to the server just as it does with an ordinary search for pubs nearby. We do not track or store continuous background location.
Motion sensors
The app reads data from the motion sensors (compass and accelerometer) so it can turn the direction arrow correctly as you turn your phone. This data is processed only on the device and is not sent anywhere.
We also store the total number of metres walked in the app against your anonymous account. The total is counted on the phone itself and only the increments in metres are sent to the server, never GPS points, a route or location history.
Searching for and adding pubs
Ordinary search for pubs nearby uses our own local directory of venues. When you add a missing venue, we search for the name in that directory and can add results from Google Places. When you pick a point on the map or use your current location, the server can turn its coordinates into an address through Google Geocoding. What gets sent is the name searched for or the point you confirmed, not your identity. Venues you add are shown publicly to other users.
Anonymous device account
On first launch the app creates a random anonymous device identifier (a random UUID) and sends it to our own server, so that every device has a temporary anonymous account. The identifier contains no personal data and only serves to tell devices apart.
User account (optional sign-in)
Signing in is optional: the core features (compass, counter, diary) can be used anonymously. Some community features (public profile, Crew, community meet-ups) need an account you are signed in to. If you decide to create one, we process the following, depending on the sign-in method you choose:
- Email and password: we store your email address, and your password only in an unreadable (hashed) form, never in plain text.
- Sign-in with Google or Apple: from the provider we get a stable account identifier and an email address (with Apple this can be a hidden relay address), and possibly a name. We never see your password at the provider.
When you sign in, the anonymous device data you have so far is attached to your account so that it stays with you. One account can be linked to several sign-in methods and you can unlink them in settings at any time.
Public profile (nickname and profile photo)
When you create an account, you can choose a nickname and upload a profile photo. We store them on our server and they make up your profile in the app. A profile with a nickname and a photo is visible to other users: it is part of the community and discovery side of the app. The first time you sign in with Google, we can take your profile photo from your Google account. You can change or completely delete the nickname and the photo at any time.
Beer Diary and your records
What you record in the app syncs to our server under your account (anonymous or signed in), so that it stays with you after a reinstall and across devices. This covers:
- beers and other drinks you log: the type and name of the drink, the price, the volume, how it was served, the time and the pub including its location;
- pub visits: the pub, the start and the end of the visit;
- pub ratings: the rating, tags and your own free-form notes;
- beer check-ins: the beer, brewery, style, rating, note;
- evenings: a summary of the evening (date, drink counts, pubs visited, town).
These records do not show up publicly anywhere on their own. Some of them are shared with your Crew (the friends you accepted) unless you turn sharing off, see the next section. And if you post the summary of an evening yourself, it shows up to your Crew or publicly, depending on the visibility you choose.
Crew: sharing with friends
When you add friends in the app (your Crew), we store your friend list, friend requests, invitations (including QR codes and links), plans and the messages attached to them, reactions and any blocks on the server.
Sharing your evening with your Crew is on by default. The friends you accepted can therefore see that you are in a pub right now (including which one), how many beers you have and what you logged last. You can turn sharing off in the Crew settings at any time, or use ghost mode, where you are temporarily invisible to your Crew. This information is not shared with anyone other than the friends you accepted.
If you report someone, we store your comment and a snapshot of the reported content with the report, so that we can assess the report even if the author changes the content in the meantime.
Photos
You can add photos to the beers and evenings you log. We store them on our server; before storing we convert them to a compact format and strip their metadata, GPS location included. A photo is visible to your Crew by default; if you enter it into the photo contest, it is publicly visible, voting included. You can delete photos at any time.
Beer menu scan (AI)
The âSnap the menuâ feature lets you photograph a beer menu and have the list of beers pulled out of it automatically. The photo is sent through our server for processing by an AI model (currently Google Gemini) via the OpenRouter service. We do not store the photo on our server: we only shrink it, strip the metadata and pass it on for processing, and we require the provider not to use the data for training models. You always use the feature deliberately, no photos are sent automatically.
Community meet-ups
If you create a community meet-up, we store its description, time, capacity and exact place including the address. The exact address is visible to the host and to approved attendees; people interested in coming send the host a request with a short message. To find meet-ups nearby, your current location is sent to the server just as it is when searching for pubs.
Leaderboards and gamification
The app has leaderboards and badges (beer counts, pubs visited, experience points for mapping pubs and so on). Leaderboards show your public profile and a derived score. To keep leaderboards fair, we use simple automatic anti-cheating rules: a record that looks implausible (for example going over the daily limit, or a suspiciously fast series of records) stays in your private diary but does not count towards public leaderboards and statistics. The rules delete nothing of yours and have no effect other than visibility in the leaderboards.
Push notifications
If you allow notifications, the app obtains a push token and sends it to our server together with the platform and the app version. We deliver notifications (friend requests, what is happening in your Crew, reactions) through the Expo Push Service, which processes the token and the message content for that purpose. Pub reminders from geofencing appear on the phone itself and pass through no external service.
Feedback
When you send us feedback, we store its text, any contact details you give in it yourself, the attached screenshot and basic technical details (app version, platform). We can copy feedback into a task management tool (Linear) so that we do not forget to sort it out. When an account is permanently deleted, we delete the message, the attachment and any copy of it in Linear.
Operational and product statistics and technical errors
The app sends a limited set of events to our own server, so that we can tell whether it works and which parts people use. This covers opening the app, returning to the foreground, views of the main screens, use of the main buttons and controls, the result of selected actions, the app version, the platform and the status codes of selected requests. We can attach an event to an anonymous or a signed-in account. We use only a fixed allowed list of event names and coarse categories. We do not send pub or beer names, text entered by users, identifiers of the profiles or posts being viewed, search queries, GPS points, a route or precise location into product events.
Technical error reports also contain the error message and part of the technical output (a stack trace). Before sending, we automatically strip email addresses, tokens and account identifiers from them. We do not use this data for advertising, for tracking across apps, or for anything other than fixing bugs and improving the app.
What we do NOT collect
- Signing in is optional; we collect neither an email address nor a name until you voluntarily create an account.
- We use no advertising SDKs, no external analytics tools and no tracking across apps or websites.
- We do not store a continuous history of your location, GPS points or your movement route.
- We do not read your contacts, your photo library or other data on your phone; we only get to a photo when you pick it or take it yourself.
How we use data
The data we process serves only to run the app:
- Location and motion sensors: finding pubs nearby, the direction arrow, the map and the optional pub reminders.
- Anonymous device account: telling individual devices apart without personal registration.
- User account (email / Google / Apple): signing in and carrying your data between devices.
- Beer Diary, visits, ratings, photos: your personal record of your evenings and your statistics.
- Public profile, Crew and community features: sharing with friends, leaderboards, discovery and community meet-ups.
- Operational and product statistics and technical errors: finding out how many accounts use the app, which features are useful and where the app fails.
We do not use data for ad targeting or for tracking across services. The only automation that assesses your records is the leaderboard fairness rules described above; no automated decision-making with legal effects takes place.
Third-party services
The operatorâs own server
On our own server we process the anonymous device account, any user account and profile, the Beer Diary and your records, photos, the social data of your Crew, community meet-ups, pub details filled in voluntarily, push tokens, feedback and operational and product statistics. This data serves only to run the app, measure usage and improve the app; we send it to no ad network and to no external analytics tool.
Google Maps, Google Places and Google Geocoding
The map screen uses the Google Maps SDK, which talks to Google servers to draw the map (among other things the section of the map being displayed and technical device identifiers). When you add a missing venue, our server can search for the name you entered through the Google Places API and convert the point or address you confirmed through the Google Geocoding API. Google receives the name searched for, the address text or the coordinates of the chosen point, not your identity. Policy: https://policies.google.com/privacy
Menu photo processing (OpenRouter and an AI model)
Our server passes the beer menu photo from the âSnap the menuâ feature to the OpenRouter service, which processes it with an AI model (currently Google Gemini). We do not store the photo, and under our settings the provider must not use it for training. Policy: https://openrouter.ai/privacy
Expo Push Service
We deliver push notifications through the Expo service (Expo Push Service), which processes the device push token and the content of the notification. Policy: https://expo.dev/privacy
Firmy.cz (Seznam.cz, a.s.)
We fill pub opening hours in on the server from the public Firmy.cz directory. Only the name and town of the venue is sent, never any data about you. Policy: https://o.seznam.cz/ochrana-udaju/
Sign-in with Google and Apple
If you choose to sign in with Google or Apple, identity verification happens at that provider under its own policy. From the provider, our app receives only a stable account identifier and an email address (possibly a name, and with Google a profile photo). More: Google, Apple.
Sending emails (Resend)
If you have an account with an email address, we send transactional emails (address verification, password reset, an export of your data, confirmation of account deletion) through the Resend service. To deliver them, it processes your email address and the content of the message, which with a data export means the attached file with your data too. Policy: https://resend.com/legal/privacy-policy
Linear
We can copy feedback from the app into the Linear tool, where we handle it as work items. The text of the message, the contact details given in the feedback and technical details are transferred. Policy: https://linear.app/privacy
Exchange rates (Frankfurter)
If you log the price of a beer in a foreign currency, the app asks the public frankfurter.dev service for the exchange rate. Only the currency code is sent, no location and no personal data.
External navigation
When you ask for navigation to a pub, an external map app opens (Apple Maps, Google Maps or Mapy.cz) and the destination is handed over to it. This only ever happens when you tap.
How long we keep data
Individual operational, product and error events are kept for 90 days at most and then deleted automatically. We delete short-lived social data on an ongoing basis: expired plans and live activities within 7 days of ending, delivered notifications within 45 days, expired invitations and rejected requests within 14 days.
The content of your account (Beer Diary, visits, ratings, photos, evenings, profile) is kept until you delete it yourself or delete the whole account. Third-party services keep any data under their own policies.
Deleting your account
You can delete your account and the data attached to it at any time in the app (Settings â Account â Delete account) or ask for deletion without the app. Once requested, the account is deactivated for 14 days and then permanently deleted; until then it can be restored by signing in again. We permanently remove your identification and profile details (email address, name, nickname, profile photo, password, links to Google and Apple), your private content (Beer Diary, visits, ratings, photos, social connections), your contributions about pubs, the public meet-ups you hosted and the feedback you sent us.
Information about pubs from other people and from independent sources stays, that is not your account data. Without your identity, only the necessary moderation records and parts of other peopleâs shared content can remain, for example the technical history of a shared game. Details and how to do it: Deleting your account.
Your rights
Under the GDPR (the General Data Protection Regulation) you have the right to:
- access the personal data we process about you,
- rectification of inaccurate data,
- erasure (the âright to be forgottenâ),
- restriction of processing,
- data portability,
- object to the processing.
In the app you can request an export of the main content of your account by email (diary, visits, ratings, profile, social data) and also delete the account and its data. When you use the app anonymously, your installation has a temporary device account on our server under a random UUID. The Beer Diary and other content sync to it, but without you signing in we know neither your name nor your email address. With any other question or request, get in touch at the contact address below.
Children
The app is not meant for children. Given the subject (finding pubs) it is meant for adult users and we knowingly collect no data about children.
Changes to this policy
We can update this policy from time to time. We will let you know about material changes by updating this page and changing the âLast updatedâ date in the header. We recommend checking the policy from time to time.
Contact us
If you have any question about privacy or about this policy, write to us at: tomades1@gmail.com