PRIVACY

Beisl Privacy Policy

Effective date: 12 May 2026
Last updated: 25 July 2026

This Privacy Policy describes how Timmo Caspar Achsel (“Beisl”, “we”, “us”, or “our”), as the operator of the Beisl mobile application and the website at beisl.pub (together, the “Service”), collects, uses, shares, and protects personal data.

We are the data controller for the personal data processed through the Service within the meaning of the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR, and equivalent laws.

1. Who we are and how to reach us

Controller:
Timmo Caspar Achsel
Stockholm, Sweden
Email: hello@beisl.pub

Beisl is currently operated as a sole proprietorship. If you have questions, want to exercise a privacy right, or wish to lodge a complaint with us before approaching a supervisory authority, please email us at the address above. We aim to respond to verifiable requests within 30 days.

We have not appointed a Data Protection Officer because we are not legally required to do so, but the email above reaches the person responsible for privacy at Beisl.

2. Scope of this Policy

This Policy applies to:

  • the Beisl iOS app (bundle identifier pub.beisl.app) distributed through the Apple App Store; and
  • the Beisl website at beisl.pub, including invite landing pages, the Apple App Site Association file used for universal links, and any associated subdomains we operate (e.g. api.beisl.pub).

This Policy does not apply to third-party services that you reach from links inside the Service (for example, Apple Maps directions to a bar, or another user's external website). Their privacy policies govern your use of those services.

3. Summary at a glance

TopicShort answer
Account creationSign in with Apple only. We never see your real Apple ID password.
What you must give usA persistent Apple identifier (“Apple sub”) and a unique handle (your @username). We never ask you for your name: a display name is optional, and if you do not set one we use your handle.
EmailWe do not store your email address.
LocationCoarse location (used on-device only) for nearby-bar suggestions. While you are in an active crawl, your precise location is shared with the other members of that crawl, and — if you are also visible there — with your friends on the friends map. This continues while the app is in the background and your screen is locked; iOS shows its background-location indicator throughout. One switch stops all of that sharing: "Share my live location" in the crawl's ⋯ menu. Turning it off stops transmission immediately and deletes the position points we still hold for that crawl; your friends then see only the bar you last checked into, and only for a while — that fades to “last seen” after 30 minutes and disappears from the map two hours after the check-in. Switch Visible on the friends map off to remove it at once. You can also revoke the Location permission in iOS Settings for the whole app. Live position points are deleted from our server within ~60 seconds in any case.
FriendsYour handle, display name, premium status, and limited activity (e.g. whether you are currently in a crawl) are visible to people who add you as a friend. Your bar ratings are visible to friends only if you enable “Share ratings”.
Third-party processorsApple (Sign in with Apple, push notifications, in-app purchases) and our hosting provider Hetzner Online GmbH (Germany). A transactional-email provider (Brevo, France) is planned for moderation emails but not currently in use.
AnalyticsWe do not use third-party analytics, attribution, advertising, or crash-reporting SDKs.
ChildrenThe Service is intended for adults. You must be at least the legal drinking age of your jurisdiction (and in any case at least 18) to use it.
Your rightsAccess, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint. You can delete your account from inside the app at any time.

The summary is provided for convenience. The detailed sections below are legally controlling.

4. Personal data we collect

4.1 Data you provide directly

When you sign in to Beisl using Sign in with Apple, Apple sends us a signed identity token from which we extract a stable, opaque user identifier (the “Apple sub”). The Apple sub is unique to your Apple ID and to the Beisl Services ID; it cannot be linked back to your Apple ID by us. Apple may also include an email address in that token (your real address, or a relay address of the form <random>@privaterelay.appleid.com). We do not store the email address. It is read once, in memory, only to validate the token; we then discard it.

After signing in for the first time, the only thing you must choose is:

  • a handle — a unique short username, displayed as @yourhandle, that other people use to find and add you.

The handle is the only thing required to finish creating your account. We never ask you for your name. Your account also carries a display name — a free-text name shown to your friends and crew — but we do not ask you for it: it is seeded from your handle, and setting or changing it is entirely optional. You can change your handle or your display name at any time from the Profile screen, subject to the handle remaining unique.

When you create or interact with content in the app, you may also provide:

  • bar entries (a venue name, optional area label, an optional latitude/longitude, and a colour hue);
  • ratings and notes about a bar (eight scores from 1–5 covering atmosphere, music, selection, quality, price, staff, toilets, and “linger”; an optional drink-kind text; an optional free-text note up to 1,000 characters);
  • visits (timestamped records of when you arrived at a bar);
  • crawls (a name, planned date and time, mode of transport, and an ordered list of stops);
  • try-lists and bar lists (custom personal lists of bars; bar lists with multiple lists are a Premium feature);
  • friend relationships (you choose whom to invite, accept, or block);
  • moderation reports (a target type, target ID, and a free-text reason capped at 500 characters); and
  • a logbook caption (a short text persisted with a completed crawl, sometimes called the “verdict”).

4.2 Data collected automatically

When you use the Service we automatically collect:

  • a persistent user record identifier generated by us (a UUID stored on our server and tied to your Apple sub);
  • session tokens (JSON Web Tokens issued by us, stored in your device's iOS Keychain);
  • APNs device tokens issued to your device by Apple's Push Notification service so we can deliver notifications to you, together with the APNs environment (sandbox or prod) and the date the token was registered or revoked;
  • Live Activity tokens issued per active crawl so we can update your iOS Live Activity / Dynamic Island banner;
  • a record of your premium subscription status (the product identifier and an expiry timestamp), kept in sync with Apple's StoreKit;
  • the App Store Server Notifications that Apple sends us about your subscription (we keep the signed JWS message we receive from Apple as an audit record of the transaction);
  • crawl event records (arrived, left, rated, deviated, completed, reminded, position) generated as you participate in a crawl; and
  • standard server log information for each request to our API: a request identifier, the requesting user identifier (when authenticated), the HTTP method and path, the response status, error messages, and a high-resolution timestamp. These logs are written to standard output on our servers and rotated by the host operating system. They are not exported to a third-party log aggregator.

We do not collect:

  • your real name, postal address, or phone number;
  • your email address (Apple's identity token contains it, but we discard it as described above);
  • contacts from your address book;
  • photographs, video, audio, microphone input, motion or fitness data, or HealthKit data;
  • a device advertising identifier (IDFA), and we do not use Apple's App Tracking Transparency framework because we do not track you across apps or websites;
  • any biometric, government-issued, financial, employment, or health information; or
  • anything from a “Sensitive Personal Information” category under California or EU law.

4.3 Location data

Location is the most privacy-significant category we handle. It deserves a careful description.

Coarse “When in Use” location. When you grant the iOS When In Use location permission, the Beisl app uses an on-device coarse-location reading (kilometre-scale accuracy) to suggest bars near you when you search and to label your area in the app. This coarse reading stays on your device. It is not transmitted to our servers.

Precise “Always” location during an active crawl. When you start or join a crawl, we ask for the iOS Always location permission. We then run two location-based services on your device, only while a crawl is in the active state and you are a member of it:

  1. Geofencing. The app registers a circular geofence of roughly 100 metres around each stop in the crawl, with a small hysteresis band — entry at about 95 metres, exit at about 120 metres — so a noisy GPS reading near the boundary does not flip you in and out repeatedly. When you arrive at a stop, the app fires a local arrival prompt and writes an arrived crawl event; when you leave, it writes a left event. The geofence runs locally on your device using Apple's CoreLocation region monitoring, which iOS can wake the app for while the app is in the background.
  2. Live position broadcast. While a crawl you are in is active and you have Share my live location switched on for that crawl, the app sends your latitude, longitude, and horizontal accuracy to our server every 30 seconds, or whenever you have moved more than 50 metres, with a minimum 5-second floor between transmissions. These points are written to a crawl_events row of kind position. They reach two audiences:
  • The other members of your crawl. The points are streamed live to them over a server-sent events connection so they can see the crew's positions on the active-crawl map. This is what the switch is for.
  • Your friends, on the friends map — but only if you have also left Visible on the friends map on for that crawl. That map shows friends who are out tonight: your position, the bar you last checked into, and how far through your crawl you are. It never shows your planned route to someone who is not on the crawl.

Share my live location governs both. With it off, no position is sent at all — not to your crew, not to the friends map, and nothing is written to our server.

What sharing off does not hide is the bar you checked into. Beisl shows two different things about you, and they have two different switches:

  • Your live position — a moving dot, updated continuously from your phone's GPS. Governed by Share my live location.
  • The bar you last checked into — a single place you published deliberately, by tapping "I'm here" (or confirming an arrival). Governed by Visible on the friends map.

So with sharing off but friends-map visibility on, your friends see that you are out and which bar you last checked into — not where you are now, and not where you go next until you check in again. To show your friends nothing at all, switch Visible on the friends map off; that is what that switch is for, and it works independently of the other one.

The bar you checked into does not stay there all night. It ages, in two steps, measured from the moment you checked in:

  • For the first 30 minutes your friends see it as where you are — “At Ginsberg”.
  • From 30 minutes to two hours it dims and reads in the past tense — “Last seen at Ginsberg · 45 min ago”. It says you were there, not that you are.
  • Two hours after the check-in it is gone. You disappear from the friends map entirely until you check in somewhere again (or switch live sharing back on). Checking in somewhere new starts the clock over at that bar.

That bound exists because a check-in is a statement about a moment, and it stops being true when you walk out. It applies to what your friends can see; your own crawl history is unaffected. If you are still broadcasting your live position, the two-hour rule does not remove you — your live dot is its own thing, and it expires on its own schedule (about 60 seconds; see Retention of live position points).

Background position broadcasting. Position broadcasting continues while the Beisl app is in the background and while your screen is locked. That is deliberate: a crawl is mostly spent walking between bars with the phone in a pocket, and a foreground-only broadcast made your dot disappear from your crew's map exactly when they needed it. Three things about how we run it:

  • It is visible. While background broadcasting is active, iOS shows its system background-location indicator (the coloured status-bar pill). Beisl deliberately leaves that indicator switched on rather than suppressing it, so you can always tell at a glance that the app is transmitting.
  • It is bounded to an active crawl and to your consent. The app asks iOS for background location only while a crawl is active and you have Share my live location on — not merely because some part of the app wants a location reading. It disarms when the crawl ends (immediately, not when you dismiss the end-of-crawl summary), when you leave the crawl, and when you switch sharing off. Outside those conditions the app requests no background location updates at all, and the system indicator is the honest signal of that: if it is showing, we are transmitting.
  • It is throttled, and it does not pretend. In the background the app drops from best-available GPS accuracy to roughly 10-metre accuracy, which is where the battery saving comes from. Your position expires on our server after about 60 seconds, so a timer wakes roughly every 20 seconds and re-sends your most recent reading if the 30-second interval described above has already passed — a check every 20 seconds, not a transmission every 20 seconds. That keeps the gap between transmissions under about 50 seconds even while you are sitting still and nothing new is being measured. It re-sends only while that reading is less than 45 seconds old: if your phone genuinely stops producing readings, your dot goes dark rather than being kept alive artificially at a place you may have left.

How to stop location sharing. There are two routes, and the in-app one is the one we recommend.

  1. In the app, per crawl (recommended). Open the active crawl, open the ⋯ menu, and switch Share my live location off. Four things happen: the app stops transmitting immediately on your device, without waiting for our server to confirm; as soon as the instruction reaches us, our server refuses any further position you send for that crawl; the position points we still hold for that crawl are deleted. Your live dot is gone from both audiences; your friends still see the bar you last checked into — for up to two hours after that check-in, dimmed to “last seen” after the first 30 minutes, and then not at all. Switching Visible on the friends map off removes it immediately rather than waiting for that. Both switches behave the same way when we cannot be reached. The change takes effect on your device straight away — transmission stops, or you leave the friends map — without waiting for our server; the instruction is stored on the device, survives closing the app, and is sent to us as soon as you are back online, however long that takes. Neither switch turns itself back on because a request to us failed. The one thing that discards a pending instruction is signing out of Beisl on that device before it has been sent: your device's pending changes are cleared with the rest of your session, because we will not replay one account's instruction under another account's sign-in. Signing out also stops all transmission, and the points we already hold stop being shown to anyone after 60 seconds and are deleted automatically (see Retention of live position points below), so nothing keeps being shared either way. Arrival detection keeps working, and you can switch sharing back on in the same place.
  2. In iOS Settings, for the whole app. Revoke the app's Location permission in Settings → Privacy & Security → Location Services → Beisl. This route is all-or-nothing: it also disables the arrival detection described above, so the app will no longer notice when you reach a stop.

Retention of live position points. A background job on our server runs every 30 seconds and deletes every position event older than 60 seconds. The worst-case lifespan of a single position point on our server is therefore approximately 90 seconds. That prune is automatic. In addition, switching Share my live location off for a crawl (see above) deletes your remaining position points for that crawl immediately.

How long a check-in stays visible to your friends. Separately from the live position above: the bar you checked into is shown to your friends for 30 minutes as where you are, then in the past tense until two hours after the check-in, after which you are no longer on the friends map at all. This is a visibility bound rather than a deletion: the check-in itself stays in your own crawl history and in the crawl's timeline for the members of that crawl, exactly as it did before — what expires is what your friends can see on the map.

No background location outside an active crawl. When no crawl is active, we do not run background location updates and we do not register geofences. The app declares the iOS location background mode in Info.plist and enables background location updates, but only for the duration of an active crawl in which you are sharing your position; the moment that ends, the app disables background location updates again. Arrival detection itself relies on CoreLocation region monitoring, which requires the iOS Always permission and works independently of background broadcasting — so revoking sharing in the app does not stop arrivals, and declining the Always permission does not stop sharing while you are using the app.

Bar coordinates. When you create a new bar entry, the latitude and longitude you supply (typically picked from Apple Maps) are stored as part of the bar record so it can be shown on a map and used for proximity searches. Bar coordinates are not personal data on their own, but a bar you created remains attributed to you (subject to anonymisation on account deletion — see Section 9).

4.4 Data we receive from third parties

  • Apple sends us your Apple sub, and may send us your email address (which we discard), through the Sign in with Apple flow.
  • Apple's StoreKit sends us signed transaction information when you start, renew, refund, or cancel a Premium subscription, both when your device submits the receipt and when Apple's App Store Server Notifications service posts a webhook to our /v1/premium/notifications endpoint.
  • Other Beisl users can attach you to a crawl by inviting you (using your user identifier), or send you a friend request, in which case our server stores the relationship between your account and theirs.

We do not buy personal data from data brokers, and we do not enrich your profile from advertising networks, social-media graphs, public records, or generative-AI providers.

5. How we use personal data, and the legal bases we rely on

We only process personal data for the purposes listed below. For users in the European Economic Area, the United Kingdom, and Switzerland, the table identifies the legal basis under Article 6(1) of the GDPR.

PurposeData usedLegal basis
Create and authenticate your account; keep you signed inApple sub, our user UUID, JWT session tokensPerformance of a contract (Art. 6(1)(b))
Show your handle and display name to your friends and crewHandle, display name, premium status flagPerformance of a contract; legitimate interests in operating a social feature you opted into (Art. 6(1)(f))
Suggest nearby bars and label your current areaCoarse on-device location (not transmitted)Performance of a contract; the processing happens locally on your device
Detect arrivals and departures at crawl stopsPrecise device location (geofencing); crawl event recordsPerformance of a contract; consent for the iOS Always permission
Show crew members each other's live position on the active-crawl map, and — where you are also visible there — show your friends that you are out on the friends mapLatitude, longitude, accuracy, while you are in an active crawl — including while the app is in the background and your screen is lockedConsent (Art. 6(1)(a)); you withdraw either in the app, per crawl, via "Share my live location" in the crawl's ⋯ menu (which stops the live position immediately for both audiences, deletes the points we still hold, and leaves arrival detection working — the bar you last checked into stays visible to friends for up to two hours after that check-in, or until you switch off "Visible on the friends map", the separate consent for that, whichever comes first), or for the whole app by revoking the Location permission in iOS Settings (which is all-or-nothing and also disables arrival detection)
Deliver push notifications (arrival prompts, crawl invites and reminders, friend requests, friend-at-bar, crawl completion)APNs device tokens, Live Activity tokens, notification payload dataConsent for the iOS notifications permission; performance of a contract
Fulfil and verify Premium subscriptionsStoreKit transaction identifiers, signed JWS receipts, product IDs, premium expiry timestampPerformance of a contract
Operate community-safety and moderation features (reports, hide / delete)Reporter ID, target type and ID, free-text reason; admin actionsLegitimate interests in keeping the Service safe and accurate, and in some jurisdictions a legal obligation under online-safety laws
Diagnose errors and protect against abuseServer logs (request IDs, user IDs, error messages)Legitimate interests in operating a secure Service
Comply with legal obligations (tax records on Premium revenue, lawful requests)Whatever subset of the above is strictly necessaryLegal obligation (Art. 6(1)(c))
Send a service email if you contact usYour email address (only because you used it to write to us)Performance of a contract or legitimate interests in answering you

We do not use your data for advertising, profiling that produces legal effects on you, or automated decision-making within the meaning of Article 22 of the GDPR.

6. How we share personal data

We share personal data only with the categories of recipient described below, and only to the extent necessary for the purposes in Section 5.

6.1 Other Beisl users

The whole point of Beisl is to share a night out with the people you invite. Specifically:

  • Anyone who looks you up in the friends search can see your handle, display name, and an indication of whether you are currently in an active crawl.
  • Your friends can additionally see, on your friend profile, the bars you have visited (count and list) and your bar ratings and notes — but only if you have enabled the “Share ratings” switch in your Profile. By default, ratings are visible to friends; you can turn this off at any time.
  • The members of a crawl you are in can see your handle and display name, your current stop, your arrival and departure events, and the drink kind you logged, for as long as that crawl exists in their app. While the crawl is active and you have "Share my live location" on, they can also see your live position on the map — including while the app is in the background and your screen is locked.
  • A person who holds a friend-invite link generated by you can call our public preview endpoint and see the inviter's handle and display name. They cannot see your user identifier from this endpoint.

If you block another user, the app stops showing them your activity and stops showing you theirs.

6.2 Service providers (data processors)

We use the following third parties to operate the Service. Each of them processes personal data on our instructions and is bound by a written contract (a Data Processing Agreement, or equivalent terms in their standard developer or hosting agreement) that meets the requirements of Article 28 of the GDPR.

  • Apple Inc. (One Apple Park Way, Cupertino, CA 95014, USA) — provides Sign in with Apple identity verification, the Apple Push Notification service, the StoreKit in-app purchase platform, App Store Server Notifications, the iOS operating system, and distribution through the App Store. Apple's privacy policy is available at https://www.apple.com/legal/privacy/.
  • Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) — provides the virtual machine on which our API, database, and web server run. All Beisl databases and application servers are physically located in Germany. Hetzner's data-protection information is available at https://www.hetzner.com/legal/privacy-policy/.
  • Brevo (Sendinblue SAS) (106 boulevard Haussmann, 75008 Paris, France) — planned transactional-email provider. Once configured, Brevo will deliver moderation report emails from our backend to our admin address when you file a report. Brevo is established in France and processes data within the EEA. Brevo's privacy policy is available at https://www.brevo.com/legal/privacypolicy/. At the time of writing, no SMTP relay is configured, and moderation reports are reviewed only via direct database access by Beisl personnel; no third-party email processor handles them. We will update this Policy before Brevo is enabled.

We do not use any third-party advertising network, attribution provider (AppsFlyer, Adjust, Branch, Singular, Kochava, etc.), analytics SDK (Firebase, Mixpanel, Amplitude, Segment, PostHog, etc.), or crash-reporting SDK (Sentry, Crashlytics, Bugsnag, etc.) inside the Service.

6.3 Legal disclosures

We may disclose personal data when we believe in good faith that disclosure is necessary to:

  • comply with a court order, subpoena, search warrant, or other lawful request from a competent authority;
  • enforce our Terms of Service or investigate suspected violations;
  • protect the rights, property, or safety of Beisl, our users, or the public, including action against fraud, abuse, or imminent harm; or
  • effect a corporate transaction such as a merger, acquisition, financing, reorganisation, bankruptcy, or sale of all or part of our assets, in which case the recipient will be bound to honour this Policy or give you notice and a meaningful choice.

If we receive a request from a government or law-enforcement body, we will challenge requests we consider overbroad, and we will tell you about the request unless we are legally prohibited from doing so.

6.4 No sale or sharing for cross-context behavioural advertising

We do not sell your personal data, and we do not share it for cross-context behavioural advertising, within the meaning of the California Consumer Privacy Act (as amended by the California Privacy Rights Act), the Colorado Privacy Act, the Virginia Consumer Data Protection Act, or any similar U.S. state law. We have not done so in the previous twelve months.

7. International data transfers

Our servers and database are located in Germany. Most of your data therefore stays inside the European Economic Area.

A subset of processing necessarily involves transfers outside the EEA:

  • Apple Inc. (USA). Sign in with Apple identity tokens are signed by servers located in the United States, Apple Push Notification service messages are routed through Apple's global infrastructure, and StoreKit transaction verification involves Apple's servers. Apple is, at the time of writing, certified under the EU–U.S. Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection (Commission Implementing Decision (EU) 2023/1795). Where the Data Privacy Framework does not apply, we and Apple rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) as a transfer safeguard.
  • Brevo (Sendinblue SAS, France). Brevo is established in the EEA, so its use does not in itself involve a transfer of personal data outside the EEA. If Brevo subprocesses any portion of the processing to a non-EEA recipient, we and Brevo rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and Brevo's published transfer safeguards. As stated above, the SMTP relay is not currently active.

You can request a copy of the safeguards we rely on by emailing hello@beisl.pub.

8. Security

Sensible security is non-negotiable for an app that touches your real-time location. We implement and maintain technical and organisational measures appropriate to the risks of the processing, including:

  • TLS 1.2 / 1.3 (with certificates issued by Let's Encrypt and renewed automatically) for every connection between the Beisl app, the Beisl website, and our API;
  • session tokens stored in the iOS Keychain with the kSecAttrAccessibleAfterFirstUnlock accessibility class, so they require the device to be unlocked at least once after boot before they can be read;
  • isolated Docker networks for inter-service traffic on our server;
  • a hardened, distroless container image for the API binary;
  • principle-of-least-privilege database roles;
  • bcrypt-equivalent hashing or signed envelopes for any secret material we hold (we do not store passwords, since authentication is delegated to Apple);
  • rate limiting and authentication on every non-public endpoint;
  • automatic deletion of live position points within ~60 seconds (see Section 4.3);
  • no inclusion of personal data in URLs or query strings beyond opaque identifiers; and
  • a strict change-management process whereby every backend change is reviewed and tested in CI before deployment.

No system is perfectly secure. If we become aware of a security incident affecting your personal data that meets the threshold for notification under Article 33 GDPR, we will notify the competent supervisory authority within 72 hours. If the incident is likely to result in a high risk to your rights and freedoms, we will also notify you under Article 34 GDPR using the contact information available to us, which in the absence of an email address will be a notice inside the app.

9. How long we keep your data

We keep personal data only for as long as we need it for the purposes set out in this Policy.

CategoryDefault retention
Account record (Apple sub, handle, display name, settings, premium expiry)Until you delete your account
Bar entries you createdIndefinitely (anonymised on account deletion — see below)
Ratings, notes, visits, try-lists, bar lists, logbook captionsUntil you delete the entry, or until you delete your account
Crawls and crawl membershipUntil the crawl owner deletes the crawl, or until both you and the owner delete your accounts
Crawl event log (arrived, left, rated, deviated, completed, reminded)Lifespan of the crawl
Live position events (kind = 'position')Auto-deleted within ~60 seconds (worst case ~90 s)
APNs device tokensUntil you sign out, until the token is revoked by Apple, or until you delete your account
Live Activity tokensLifespan of the corresponding Live Activity (max 8 hours per Apple's limits) and the underlying crawl
Premium transaction records (signed JWS audit copies)Up to 10 years where required by tax law (Swedish Bokföringslagen 1999:1078, 7 kap. 2 §); otherwise until you delete your account
Moderation reportsUntil resolved, plus a reasonable period (up to 12 months) to detect repeat patterns
Server logs30 days on rotated disk
BackupsUp to 30 days, after which they age out of the backup window

When you delete your account (see Section 10), your record is soft-deleted: the deleted_at field is set and your handle is cleared so it can be reused. Records that depend on you are then handled as follows:

  • Your device tokens, Live Activity tokens, ratings, visits, try-list entries, bar-list entries, friendship rows, crawl-member rows, premium transaction records, and reports you filed are hard-deleted (cascading SQL ON DELETE CASCADE).
  • Bars you created and crawls you owned are anonymised: their creator/owner field is rewritten to a sentinel “deleted user” identifier so the venue or shared crawl history that other people have built on top of your contribution survives, but cannot be traced back to you.
  • Where we are required to retain financial or transactional records (e.g. for tax law), we retain the minimum subset needed and then delete it at the end of the legal retention period.

Where data must be retained for backup or legal reasons after account deletion, it is no longer used for any other purpose and is securely deleted at the end of the retention period.

10. Your privacy rights

Subject to applicable law, you have the following rights with respect to your personal data:

  • Access. You can ask us for a copy of the personal data we hold about you. Most of it is already visible to you in the app: open Profile, your friend profile, the rating sheet for any bar you have rated, and the crawls list. If you would like a structured export beyond what the app shows, email us and we will provide one within 30 days.
  • Rectification. You can update your handle and display name at any time from the Profile screen. For anything else, email us.
  • Erasure (“right to be forgotten”). You can delete your entire account at any time from inside the app: Profile → Account → Delete Account. Deletion takes effect within seconds; the consequences are described in Section 9. You can also email us if you prefer.
  • Restriction. You can ask us to restrict processing in the limited cases set out in Article 18 GDPR.
  • Portability. You can ask us to provide the personal data that you provided to us in a structured, commonly used, machine-readable format.
  • Objection. You can object to processing carried out on the basis of our legitimate interests on grounds relating to your particular situation. If you object, we will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
  • Withdrawal of consent. Where we rely on consent (for example, for the iOS Always location permission, for live position broadcast inside a crawl, or for push notifications), you can withdraw consent at any time. For live position broadcasting there are two independent routes: in the app, per crawl, by switching Share my live location off in the crawl's ⋯ menu — this stops transmission immediately and leaves arrival detection working — or in iOS Settings, by revoking the app's Location permission in Settings → Privacy & Security, which stops sharing for every crawl but is all-or-nothing and also disables arrival detection at your stops. Other iOS permissions (notifications, Always location) are withdrawn in Settings. Withdrawing consent does not affect the lawfulness of processing that took place before you withdrew it.
  • Complaint to a supervisory authority. If you live in the EEA, the United Kingdom, or Switzerland, you have the right to lodge a complaint with your local data protection authority. As Beisl is operated from Sweden, our lead supervisory authority is the Integritetsskyddsmyndigheten (IMY), Drottninggatan 29, plan 5, 104 20 Stockholm, imy@imy.se. If you live in another EEA country, you may also lodge your complaint with the supervisory authority of your habitual residence or place of work.

To exercise any of these rights, email hello@beisl.pub from the email address associated with your Apple ID, or include enough information for us to confirm that you are the account holder (typically your handle and the approximate date you signed up). We do not charge a fee unless your request is manifestly unfounded or excessive.

10.1 Additional rights for California residents

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), gives you the rights described above and the following additional rights:

  • the right to know the categories and specific pieces of personal information we have collected about you;
  • the right to know the categories of sources from which we collected your personal information, the business or commercial purposes for collecting it, and the categories of third parties with whom we shared it;
  • the right to delete personal information we have collected from you;
  • the right to correct inaccurate personal information;
  • the right to opt out of the sale or sharing of personal information; and
  • the right to limit the use or disclosure of sensitive personal information.

We do not sell or share personal information within the meaning of the CCPA, and we do not collect or use sensitive personal information beyond what is strictly necessary to provide the Service. We will not discriminate against you for exercising any of your CCPA rights.

The categories of personal information we have collected in the previous twelve months, mapped to the categories listed in Cal. Civ. Code § 1798.140, are: identifiers (Apple sub, our user UUID, device tokens), customer-record information (handle, display name), commercial information (Premium subscription status), geolocation data (the live position points described in Section 4.3, retained for ~60 seconds), internet or other electronic-network activity information (server logs, crawl events), and inferences are not drawn.

10.2 Additional rights for residents of other U.S. states

If you live in Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or any other U.S. state with a comprehensive consumer-privacy statute in force, you have rights substantially equivalent to those listed above. To exercise them, email hello@beisl.pub. If we deny your request, you may appeal by replying to our denial; if your appeal is denied you may contact your state Attorney General.

11. Children

Beisl is intended for adults. The Service is built around the social experience of going to bars, and Premium content includes bar-related features. You must be at least the legal drinking age in your jurisdiction (and in any case at least 18 years old) to create an account. We do not knowingly collect personal data from anyone under 18.

If you believe a person under 18 has provided personal data to us, please contact us at hello@beisl.pub and we will delete the account.

In the App Store, Beisl is rated 17+ to reflect this restriction.

12. Changes to this Policy

We may update this Policy from time to time to reflect changes in the Service, in our practices, or in applicable law. When we do, we will:

  • update the “Last updated” date at the top of this document;
  • post the revised Policy at the same URL where you found this one; and
  • if the changes are material — for example, if we add a new category of recipient, a new processing purpose, or a new legal basis — we will give you prominent notice inside the app and, where required by law, ask for your renewed consent before the change takes effect.

Past versions of this Policy are available on request.

13. Definitions and references

  • “Beisl app” — the iOS application distributed under the bundle identifier pub.beisl.app.
  • “Apple sub” — the value of the sub claim in an identity token issued by Apple's Sign in with Apple service. It is unique to a given Apple ID and to a given relying party (here, Beisl); it cannot be used to look up the underlying Apple ID.
  • “Crawl” — a planned sequence of bar visits scheduled in the app, with optional friends.
  • “Crew” — the set of users who are members of a particular crawl.
  • “Geofence” — a virtual circular boundary around a geographic point, monitored by iOS so the operating system can wake the app when the device crosses it.
  • “Live position event” — a row in the crawl_events table of kind position, containing a latitude, a longitude, a timestamp, and the user identifier of the device that produced it.
  • “Premium” — the auto-renewing subscription tier of Beisl, provided through Apple's StoreKit. Product identifiers: pub.beisl.app.premium.annual.v2 and pub.beisl.app.premium.monthly.v2.

This Policy was prepared in English. In case of discrepancy with any translation, the English version controls.


© 2026 Timmo Caspar Achsel. All rights reserved.

© Beisl 2026
Austrian for "neighbourhood pub" · made for the night, anywhere.
Privacy · Terms · Support
hello@beisl.pub