Privacy, plainly.
Last updated 31 August 2026. Here is what we collect, why we use it, and how you stay in control of it.
What we store
We store your account details, body settings, drink entries, presets, goals, imported backup information, and subscription status. Alcohol history and body settings can be sensitive, so access is limited to the signed-in account and the services needed to operate Pour.fyi.
Why we use it
We use this information to provide BAC estimates, history, statistics, data exports, account support, fraud prevention, and subscription access. We do not sell alcohol-history data or use it for advertising profiles.
Payments
Stripe processes Pro subscription payments. Pour.fyi stores Stripe customer and subscription identifiers, plan status, and renewal dates, but not complete card details. Stripe handles payment information under its own privacy terms.
Portability and deletion
You can download an AlcoDroid-compatible backup or complete machine-readable JSON export at any time. You can delete your account from its security controls after recent authentication. Active test subscriptions are canceled before local account data is removed. Legal and financial records may need to be retained where required by law.
Security
Passwords are hashed with Better Auth's scrypt implementation. Sessions are stored in D1, use secure cookies, expire after 30 days, and are revoked when a password is reset or changed if other-session revocation is selected. Verification and password-reset links are single-use and expire after one hour. Billing webhooks are signature-verified, and secrets remain server-side.
Pour.fyi sends account verification, password-reset, and security notifications through Cloudflare Email Service from no-reply@pour.fyi. We do not log email tokens or message contents.