Got a cocktail of your own?Build it, share it, and see what everyone else is pouring.
BarflowBarflow

Privacy Policy

Version 2026-09-05 · Last updated September 5, 2026

1. Who we are and what this covers

Barflow is a cocktail reference and home-bar tool operated by an individual based in Missouri, United States. This policy covers barflow.app and the Barflow API. It explains what personal information we collect, why we collect it, and what you can do about it.

Cocktail and ingredient data itself is not personal information. This policy is about the information that identifies you.

2. Information we collect

Information you give us. When you create an account we collect your email address, the username you choose, and your password, which is stored only as an Argon2 hash and never in a readable form. As you use Barflow we store the ingredients you add to your shelf, the cocktails you favorite, and any cocktail recipes you create. If you request API access, the message you write is emailed to the site operator; it is not stored with your account.

Information we collect automatically. Our servers log the IP address and browser user-agent of requests, along with the path requested and the time. We keep short-lived counters keyed to IP address to rate-limit sign-in and registration attempts, which is what stops someone brute-forcing an account. If you accept analytics cookies, Google Analytics collects usage information about your visit; details are in section 6.

Information from other sources. None. We do not buy personal data, and we do not receive it from data brokers, advertising networks, or social platforms.

3. How and why we use information

  • To provide the service — signing you in, remembering your shelf and favorites, and showing you the recipes you have saved or written.
  • To send you transactional email: password resets, and messages about your account or API access. We do not send marketing email.
  • To keep the service secure and available — rate limiting, abuse investigation, and diagnosing errors.
  • To understand how the site is used in aggregate, so we can improve it.
  • To comply with the law and to enforce our Terms of Service.

Legal bases (GDPR). Where the GDPR applies, we rely on: performance of a contract for the account features you asked for; our legitimate interests in keeping the service secure and working; your consent for analytics cookies, which you can withdraw at any time; and legal obligation where a law requires us to act.

4. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We use the following service providers, each of which processes data on our behalf:

  • Vercel — hosts the website and provides cookieless traffic and performance measurement.
  • Fly.io — hosts the Barflow API.
  • Neon — hosts the database where your account and saved data live.
  • Resend — delivers transactional email, and therefore processes your email address.
  • Google Analytics — usage analytics, loaded only if you accept analytics cookies.

We may also disclose information if we are legally required to, or where we believe it is necessary to protect someone's safety or to investigate fraud or abuse. If Barflow is ever transferred to someone else, account information would transfer with it, and we would tell you before that happened.

What is public. Your username, and any cocktail recipe you publish to the community section, are visible to anyone. Your email address, your shelf, and your favorites are not. Treat a published recipe as public and permanent — others may have copied it before you delete it.

One thing worth knowing. When a new account is created, we send an internal notification to the site operator that includes the new account's email address. This is how we notice abuse early.

5. How long we keep it

Account information is kept for as long as your account exists. Server request logs are kept for a short operational period and then discarded. Rate-limiting counters expire within hours. Password reset tokens expire shortly after they are issued and are unusable afterward.

Deleting your account removes your account record, your shelf, your favorites, and every recipe you created — including any you published to the community. Deletion is immediate and cannot be undone, so export anything you want to keep first.

6. Cookies and local storage

Essential cookies are set only when you sign in and cannot be switched off without breaking the service: access_token and refresh_token keep you signed in and are not readable by JavaScript, and session_user holds your display details so the interface knows who you are. They last one hour, seven days, and seven days respectively.

Analytics cookies are set by Google Analytics and only after you accept them. Declining is a single tap, and nothing is set if you decline. You can change your mind at any time here:

Local storage. Barflow keeps some things in your browser rather than on our servers: the shelf of a signed-out visitor, shopping-list checkboxes, whether you have dismissed a hint, your cookie choice, and your answer to the age question. This never reaches our servers. You can clear it through your browser at any time.

7. Security

Passwords are hashed with Argon2 and never stored or logged in readable form. Session cookies are HTTP-only and, in production, sent only over HTTPS. Changing your password invalidates every existing session. Sign-in and registration are rate-limited.

No service can promise perfect security, and we do not. If we discover a breach affecting your personal information, we will notify you as required by law.

8. Your choices and rights

You can update your email address, change your password, and delete your account from your account page, and decline analytics cookies at any time.

Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a portable copy, object to or restrict certain processing, and withdraw consent you previously gave. These rights come from the GDPR in the EU and UK, and from state privacy laws including the CCPA in California. We do not charge for exercising them and we will not treat you differently for doing so.

To make a request, email privacy@barflow.app. We will respond within the period the applicable law requires — generally 30 days under the GDPR and 45 days under the CCPA. If you are in the EU or UK and are unhappy with our response, you may complain to your national data protection authority.

9. International transfers

Barflow is operated from the United States and our providers store data there. If you use Barflow from outside the US, your information will be transferred to and processed in the US, where privacy law differs from your own.

10. Age

Barflow is about alcoholic drinks and is not intended for anyone under 21. We do not knowingly collect personal information from children. If you believe a child has given us information, email privacy@barflow.app and we will delete it.

11. Changes and contact

If we change this policy materially, we will update the version and date at the top, email account holders, and ask you to accept the updated policy the next time you use your account. Questions go to privacy@barflow.app.