Trust and safety
Privacy policy
Effective July 23, 2026. Scotchy is a bottle recommendation and taste-journal app for adults who are 21 or older.
Information you provide
New profiles in the Scotchy web app require an email account, and setup does not finish until that email is verified. Scotchy stores your email address, display name, age confirmation, bottle statuses, dislike reasons, and personal bottle notes so your profile can synchronize between devices. Existing on-device profiles remain cached locally; if you sign in, that local data can also synchronize to the account.
Local and cloud storage
Profile data remains cached on the device so the app can work with unreliable connectivity. On the web, Scotchy hides that cache while no verified account is signed in and while a different account is loading. The cache remains in the browser's site data until it is cleared, so people who control the same operating-system or browser profile may still be able to inspect that local storage. Signed-in profile data is also stored in Scotchy's managed database. Passwords are handled by the authentication provider and are not available to Scotchy.
Network requests
Scotchy connects to its authentication, profile-synchronization, and feedback-email services and loads bottle photos from HTTPS image hosts. Those providers may receive normal request information such as IP address and browser or device details.
Sharing and selling
Scotchy does not sell personal information. Profiles are private by default. If you choose to share a member profile, Scotchy creates a separate sanitized snapshot that only verified signed-in Scotchy members can view. It contains only your display name, chosen member username, favorites, and up to eight recommendations. It does not include your email, account ID, age confirmation, personal notes, passed bottles, dislike reasons, or private journal history.
Verified members can become mutual friends. Friend requests use an exact member username rather than a searchable public directory. New accounts begin with Ben as a welcome friend; either member can remove that friendship. Friendships and pending requests are visible only to the members involved.
Being friends does not expose either person's private journal, ratings, notes, email address, account ID, or other synchronized profile data. A friendship only links the separate member profiles that each person has chosen to share. Sharing remains optional, and a shared member profile is available to verified Scotchy members rather than becoming public on the open web.
You can stop sharing your member profile at any time. That removes access through Scotchy, but Scotchy cannot revoke screenshots or information another member already copied. A profile export is separate and contains more of your private profile data; it is an uncontrolled copy chosen by you and cannot be revoked after someone else receives it.
Data is shared with service providers only as needed to host the website, authenticate accounts, synchronize profiles, provide member profiles you explicitly share, and deliver account or feedback email.
Feedback
When a signed-in user submits feedback directly in the app, Scotchy sends the message, feedback type, the display name associated with the account (when available), verified account email, app version, and basic device or browser details through Supabase and Resend to the developer's support inbox. Copied and email-draft reports include the diagnostic details, but Scotchy does not add your display name or account email to the report body. Scotchy does not automatically attach profile ratings, bottle lists, dislike reasons, or personal notes; anything you type in the message is included.
Supabase does not store the plaintext feedback message in Scotchy's database. To prevent duplicate delivery and abuse, it stores the account ID, an opaque submission ID, a SHA-256 fingerprint of the feedback type and message, delivery state and provider ID, timestamps, and attempt and rate-limit counts. That metadata is deleted with the account. Resend retains sent email data for 30 days by default, and the receiving support inbox retains the delivered email according to its own settings. If direct submission is unavailable, Scotchy may open a draft in the user's email app instead.
Export and deletion
You can export a readable copy of your profile from the app. Import replaces the current profile; when you are signed in, it also replaces the account's synchronized profile and updates its other devices. Signed-in users can delete their account in the Profile tab or through the account deletion page. Account deletion removes the cloud account, private profile, shared member profile, friendships, and pending friend requests. Local exports must be deleted separately.
Contact
For privacy questions, contact [email protected].