Privacy Policy
BeDrink · Last updated: October 8, 2026 · Versión en español
BeDrink is a social app for sharing moments from your nights out with friends: photos, drinks, places and events. This policy explains what data we process, what for, and how you can exercise your rights.
1. Data controller
The data controller is Mario Pacheco Galvin, owner of the BeDrink project (bedrink.app), Calle Torres Quevedo 10, Chiclana de la Frontera, Spain. Contact: contact@bedrink.app.
2. What data we collect
- Account: email address, password (encrypted by the authentication system), username, display name, date of birth and profile photo (optional). If you sign in with Google or Sign in with Apple, the provider gives us your verified email (and your name the first time, for Apple).
- Content you create: photos and videos of your moments (dual camera: environment + selfie), stories (they delete themselves), comments, reactions, associated drink and mood, friends and friend requests.
- Location: optional. The location stored in your moments is coarsened to ~1 km. Your position is used at the moment of querying nearby events and naming your city — that lookup is resolved on our own server, with no third parties — and to record requests to index events in your area, which are stored without being linked to your account.
- Technical data: push notification token, device type and operating system, first-party technical usage events (e.g. whether you enabled notifications) tied to your account and deleted with it, and error logs. No third-party analytics or tracking.
3. What we use it for
- Providing the service: account, friends feed, moments, stories, events, map and social features.
- Sending you push notifications you enable (you can turn them off per category in Settings).
- Moderation and security: blocks, reports and abuse prevention.
- Improving the app: aggregated usage metrics and error diagnostics.
We do not sell data, there is no advertising or ad tracking, and we do not share your data with third parties for commercial purposes.
4. Legal basis (GDPR)
- Performance of a contract (art. 6.1.b): account, feed, moments, stories and social features.
- Consent (art. 6.1.a): approximate location, camera, push notifications. You can withdraw it at any time from the app or device settings.
- Legitimate interest (art. 6.1.f): security, moderation, fraud prevention and service improvement.
5. Where data is stored and processors
Own server (OVH, EU): the database and API are hosted on our dedicated server in the EU. Images are stored on Cloudflare R2 and push notification tokens go through Firebase.
Cloudflare (CDN + R2 storage): images and app traffic pass through Cloudflare's network; photos are stored encrypted on Cloudflare R2.
Google Firebase (FCM): your device push token and an installation identifier, to deliver notifications on Android and iOS.
Google / Apple (sign-in): if you use "Continue with Google" or "Sign in with Apple", the provider verifies your identity and tells us your email (and, the first time for Apple, your name).
Sentry (EU ingest): technical error reports, without user content.
When a provider processes data outside the EU (Google, Cloudflare), it does so under GDPR-recognised mechanisms (standard contractual clauses / EU-US Data Privacy Framework).
6. How long we keep it
- Stories: they expire after 12 hours and the file is permanently deleted after ~24 hours.
- Moments and comments: until you delete them or delete your account.
- Account: while it is active. When deleted, your personal data and content are removed; technical records may remain in backups for a maximum of 7 days, after which they are deleted. Deleting your account also removes your files stored on Cloudflare R2.
- Push tokens: automatically deleted when the device is no longer valid.
7. Who can see your content
By default your moments are only visible to accepted friends. Stories are limited to friends. If you post a moment with "public" visibility, any registered user can see it. We never show or store your exact location in your content: the map only displays an approximate ~1 km point.
8. Deleting your account and data
You can delete your account from the app itself: Profile → Settings → Delete account. Deletion removes your profile, moments, stories, friendships, associated files (including those on Cloudflare R2) and linked technical records; if you signed in with Google or Apple, the connection to that provider stops being valid (and you can also revoke it from your Google account or appleid.apple.com). You can also request deletion by email to contact@bedrink.app from your account email.
9. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, and to withdraw consent at any time. Write to us at contact@bedrink.app. If you are not satisfied, you can file a complaint with the Spanish Data Protection Agency (aepd.es).
10. Minors
BeDrink is intended for people aged 18 and over. We do not knowingly collect data from minors; if we detect an account belonging to a minor, we delete it.
11. Security
We use TLS on all traffic, row-level security (RLS) in the database, short-lived signed URLs for private media and encrypted passwords. No system is infallible, but we continuously review access.
12. Local storage
The app stores your session and preferences locally on your device. No third-party or advertising cookies or trackers are used.
13. Changes to this policy
If anything substantial changes, we will notify you inside the app and update the date on this page.