BarKeep Privacy Policy
Last updated September 2, 2026
BarKeep is a personal home-bar inventory app for iPhone. It has no user accounts, no advertising SDKs of any kind. It uses one privacy-focused analytics SDK, which you can turn off, and it operates one small server used by a single optional feature — both are described in full below. This page explains, in plain terms, exactly what data the app touches and where it goes.
What stays on your device
Your bottle collection, glassware, cocktail recipes, ratings, and notes are stored locally on your iPhone using Apple's SwiftData framework. None of it is uploaded anywhere, synced to a server, or shared with anyone as a matter of course.
Two things are worth stating plainly, because "all of it stays on your phone" would not be quite true:
- If you turn on iCloud Backup in BarKeep's Settings, your bar syncs between your own devices through your personal iCloud account, using Apple's CloudKit. That is your iCloud, not ours — we cannot see it.
- If you ask BarKeep to write a tasting note for a recipe you imported, that one recipe leaves your device. See "Written tasting notes" below.
Camera & Photos
BarKeep asks for camera access to photograph bottles and menus for identification, and photo library access to attach an existing photo to a bottle. Photos you add are stored locally in the app's own storage on your device.
By default, identifying a bottle or menu from a photo runs entirely on-device, using Apple's on-device Apple Intelligence models. In this mode, the photo never leaves your phone.
Optional: Claude Cloud identification
Settings offers an optional alternative: identifying bottles/menus using Anthropic's Claude API instead of the on-device model. This is off by default and only activates if you turn it on yourself and supply your own Anthropic API key.
If you turn this on:
- The specific photo you're identifying is sent directly to Anthropic's API to generate a result.
- Your API key is stored in your device's Keychain and is never sent to us — it's sent only to Anthropic, as standard API authentication, directly from your device.
- Anthropic's own privacy practices govern data sent to their API — see Anthropic's Privacy Policy.
Recipe lookup & import
BarKeep's recipe book is seeded from a bundled dataset. If you search for additional recipes or import one from a URL you paste in, that request (a cocktail name, or the URL you provided) is sent directly from your device to the relevant public source — TheCocktailDB for search, or the specific page you asked to import from. No other personal data is included in these requests.
Barcode product lookup
If you scan a bottle's barcode and it doesn't match anything already in your inventory, BarKeep sends the scanned code (only the barcode number itself — no photo, no other personal data) directly from your device to UPCitemdb and, if that doesn't find a match, to Open Food Facts, to try to pre-fill the new bottle's brand, name, and category. This is one of only two requests BarKeep makes to an external service without you first entering an API key — the other being written tasting notes, below. Any details found this way are clearly marked as coming from a product lookup and remain fully editable before you save the bottle.
Usage analytics
BarKeep uses TelemetryDeck, a privacy-focused analytics service, to understand which features actually get used — which tabs get opened, whether a bottle scan or menu scan or recipe import completed successfully, whether the "Ask the Barkeep" chat gets used. This is on by default and can be turned off at any time from Settings → Privacy & Legal, with no effect on anything else the app does.
What this does and doesn't include:
- An anonymous identifier, generated per install, not tied to your name, email, or Apple ID — TelemetryDeck's own design goal is to collect the minimum needed to distinguish one install's behavior from another's, nothing more.
- Never the contents of your bar — no bottle names, brands, photos, or recipe text are ever sent as analytics. Only which screens/actions were used and simple outcome labels (like "scan succeeded" or "scan failed"). The one exception is the separate, off-by-default Chat Transcript Logging setting described next.
- Not used for advertising, not sold, not shared with data brokers — see TelemetryDeck's own privacy FAQ for their side of this.
- No App Tracking Transparency prompt, because this isn't cross-app tracking — nothing here follows you into any other app.
Chat transcript logging
Separate from usage analytics, and off by default — a real opt-in, not something you have to turn off. If you turn on Settings → Privacy & Legal → Chat Transcript Logging, each "Ask the Barkeep" question and reply is sent to a private database (hosted on Supabase) so real conversations can be reviewed to find and fix bad or confusing responses — the same reason this setting exists at all was a real quality bug found this way.
- Sent alongside each exchange: a random ID generated fresh every time you start a conversation — not your name, device, Apple ID, or anything that identifies you, and not reused between conversations.
- Also sent: if the reply mentioned any drinks from your recipe book, their names, and whether your current bottles could make them. This is what makes a bad answer diagnosable — a reply recommending something you plainly can't make is invisible in the text alone. Your bottle list itself is never sent.
- The database only accepts new entries from the app — it cannot be used to read, edit, or delete anyone's logged conversations, including yours, enforced by the database itself, not just app behavior.
- Turning this off at any time stops it immediately, including mid-conversation; nothing sent before that point can be pulled back.
- With this setting off, each reply also has its own "Flag this reply" option — a one-time, explicit way to send just that specific question and answer, for a single bad reply, without turning on logging for every future conversation.
Written tasting notes
The cocktail recipes BarKeep ships with already have tasting notes, written in advance and included in the app. Recipes you import don't. If you subscribe to BarKeep Pro, you can tap "Write one for me" on a recipe and have a note written for it.
This is the only feature where BarKeep sends something on your behalf and pays for it, so it is worth spelling out exactly.
- It only happens when you tap that button. Nothing is sent in the background, and nothing is sent for recipes you don't ask about.
- What is sent: that recipe's ingredient list — and nothing else. Not the recipe's name, not your inventory, not your other recipes, not your name, device, or Apple ID.
- Where it goes: to a small BarKeep server (hosted on Supabase), which passes it to Anthropic to write the note and hands the result back. Anthropic's own privacy practices govern what they do with it.
- Writing your own note instead never leaves your phone, is free, and needs no subscription.
What that server keeps, and for how long:
- The finished note and the ingredient list it was written from, so the same drink isn't paid for twice and so the quality of what BarKeep writes can actually be checked. The recipe's name never leaves your phone at all, so if you named a drink something private, that name is not sent anywhere and is not in our database.
- A count of how many notes your installation of the app has asked for today, to stop the feature being abused. It is a random identifier the app made up, not tied to you or your device, and it is deleted automatically every night.
Subscriptions & payment
BarKeep Pro is an optional auto-renewing subscription. Purchases are handled entirely by Apple through the App Store — BarKeep never receives, sees, or stores your payment details, card number, or billing address. All the app gets from Apple is a signed confirmation of whether an active subscription exists, which it reads on your device to unlock Pro features. That check happens through Apple's StoreKit framework and involves no server of ours.
You can view, change, or cancel your subscription at any time in Settings › your Apple Account › Subscriptions. Apple's own privacy policy governs the purchase itself, including any payment or billing data you provide to them.
Notifications
Low-stock reminders are scheduled entirely on your device using Apple's local notification system. Nothing about them leaves your phone, and BarKeep has no server capable of sending you a message — you will never receive a notification written by us.
One technical exception, named here because the app's entitlements declare it and
accuracy matters more than a tidy claim: if you turn on iCloud Backup, Apple's
CloudKit service sends your device silent background notifications to tell
it that data changed on another one of your devices, so the two can sync. These carry
no content, are never displayed, and come from Apple — not from us. They're the
reason the app declares the remote-notification background mode.
What we don't do
- No accounts, no sign-in, no passwords to manage.
- No advertising SDKs of any kind, and no crash-reporting SDK bundled in the app (crash reports come from Apple's own TestFlight feedback tools, not a third-party crash SDK).
- No marketing or promotional notifications of any kind — see "Notifications" above for the one silent, contentless exception iCloud sync relies on.
- No advertising identifiers (IDFA), no cross-app or cross-site tracking — see "Usage analytics" above for the one analytics SDK the app does use, and how to turn it off.
- No selling or sharing of your data with data brokers — what little reaches our own server (see "Written tasting notes") isn't tied to you, so there would be nothing to sell even if we wanted to.
Data you can delete
Almost everything BarKeep stores lives on your device, so deleting the app deletes it. You can also delete your stored Anthropic API key individually at any time from Settings without deleting anything else, or turn off usage analytics or chat transcript logging at any time from Settings → Privacy & Legal.
The exceptions are the ones described above, and none of them is a record of you: logged chat transcripts, if you turned that on; anonymous usage events, if you left those on; and, if you used written tasting notes, the finished notes plus a request count that deletes itself nightly. All of it is anonymous by design, so there is no per-person record for us to look up, hand over, or delete on request — not as a policy choice, but because it was never collected in a form that could be traced to anybody.
Changes to this policy
If this policy changes, the "Last updated" date above will change too. Material changes (anything that changes what data leaves your device, or introduces accounts/tracking) will also be reflected in the app's own release notes.
Support
Help, bug reports and feature requests: BarKeep Support.
Contact
Questions about this policy: support@homebarkeep.com