Privacy Policy
1. Who we are
ST Distillery, doing business as Muddler (“Muddler”, “we”, “us”) operates the Muddler mobile application and its backend services. Muddler scans cocktail menus with your camera and uses AI to identify drinks, ingredients, and flavor profiles.
For anything in this policy — questions, complaints, or exercising your rights — contact us at support@muddler.cc. We are the data controller for the personal data described here.
2. What we collect
Information you provide
- Account details — your email address and sign-in credentials, or your Google / Apple sign-in identifier, plus optional profile settings (display name, avatar, measurement units, theme).
- Menu photos and text — the photos you take or upload and the text you type in order to scan a menu. Photos are processed in memory and are not stored on our servers; only the resulting recognized recipes are saved to your account. If you enable “save crops” in Settings, cropped images are kept on your device only.
- Your cocktail data — scan results, saved and favorited cocktails, your bar/shelf inventory, corrections and ingredient submissions you send us.
- Purchase state — whether you have an active Muddler Pro subscription. Payment itself is handled by Apple; we never see your card number.
Information collected automatically
- Device identifier — a per-install identifier (e.g. Apple’s identifier-for-vendor) used for usage limits and abuse prevention.
- Usage counters — how many scans/AI requests you’ve made today, kept to enforce daily limits (deleted after 7 days).
- AI usage records — which AI model served a request, token counts, and cost, kept for accounting and abuse prevention. These records do not contain your photos or menu text.
- Error and crash reports — stack traces, app version, device model, and OS version when something breaks. We configure our error tooling to not capture request contents (your photos and menu text are excluded).
3. How AI processing works
When you scan a menu, your photo (or typed text) is sent over an encrypted connection to our server and then to our AI provider — currently OpenAI — to recognize the drinks and ingredients. Per OpenAI’s API data-usage terms (as of this policy’s date), content sent through the API is not used to train their models and may be retained by OpenAI for up to about 30 days for abuse monitoring, then deleted. If we add or switch AI providers (for example, Anthropic), the same principle applies: your content is used to produce your scan result, not to train models, and we will update this policy.
4. Who processes your data (our service providers)
| Provider | What they do for us | What they receive |
|---|---|---|
| Supabase | Database & authentication hosting (US, us-east-2) | Account data, cocktail data, usage records |
| OpenAI | AI menu analysis | Menu photos and menu text you submit for scanning |
| Fly.io | Server hosting (US) | Traffic passing through our API, including scans in transit |
| Sentry | Error & crash reporting | Crash/error metadata (no photo or menu content) |
| RevenueCat | Subscription management | App Store purchase receipts, subscription status, app user ID |
| Apple | App distribution & payment | Payment and App Store account data (under Apple’s own policy) |
| Google / Apple sign-in | Optional sign-in providers | Your sign-in identifier if you choose them |
These providers process data on our instructions under their own security and data-processing terms. We do not sell your personal data, and we do not use third-party advertising or cross-app tracking.
5. Why we process it (legal bases)
- To provide the service (contract): scanning menus, storing your cocktail data, syncing your shelf, managing your subscription.
- Legitimate interests: enforcing usage limits, preventing abuse and fraud, diagnosing errors, securing the service.
- Legal obligations: accounting records, responding to lawful requests.
- Consent, where required (e.g. camera and photo-library access, which iOS asks for separately) — you can withdraw it in your device settings.
6. Retention
- Account and cocktail data: until you delete your account.
- Menu photos: not stored on our servers (processed in memory); our AI provider may retain API content briefly as described in section 3.
- Daily usage counters: 7 days.
- AI usage/billing records: retained as accounting records (they contain no menu content).
- Error reports: per our error provider’s retention (typically 90 days).
7. Your rights & controls
Built into the app (Account tab):
- Export your data — download a machine-readable copy of your account and cocktail data.
- Delete your account — permanently removes your account and associated data from our systems.
Depending on where you live (including the EU/UK under GDPR and California under CCPA/CPRA), you also have rights to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to complain to your local data-protection authority. Email support@muddler.cc and we will respond within the legally required time. We do not discriminate against you for exercising your rights. Data is processed on servers in the United States; where required, transfers rely on our providers’ standard contractual clauses.
8. Security
All traffic is encrypted in transit (TLS). Access to production data is restricted, row-level security isolates each account’s data, and per-user and global usage limits reduce abuse. No system is perfectly secure, but if we learn of a breach affecting your data we will notify you as required by law.
9. Children
Muddler is about cocktails and is not intended for anyone under 18 (or the legal drinking age where you live, if higher). We do not knowingly collect personal data from minors; if you believe a minor has an account, contact us and we will delete it.
10. Changes
We’ll update this policy as the app evolves and change the “Last updated” date above. For material changes we’ll notify you in the app. The current version always lives at this URL and inside the app under Account → Privacy Policy.