Caipi Counter is operated by Marcelo de Barros Taube. This notice explains how we use personal information to provide the app. Providing account information is voluntary, but the required fields are needed to create an account. You can use alcohol-free choices and leave optional event details and moods blank.
What we collect and why
- Your name, nickname and email to maintain your profile and account. Supabase Auth handles your password securely; the application does not store a readable copy. Your chosen language helps us display Caipi in your preferred language.
- Your optional avatar choice or cropped profile photo, to help your event companions recognize you. Photos are resized to 256 × 256 pixels, re-encoded without embedded location metadata, and stored in a private bucket. We save at most one small photo per account; replacing it overwrites the previous photo. Choosing a sticker hides your photo but keeps that single storage slot until you remove your photo, replace it or delete your account.
- Session records to keep you signed in, and the version and time of your Terms and Privacy acknowledgements and adult attestation.
- Events, participant labels, dates, optional location or map coordinates, drink entries, mood check-ins, timestamps, invitation requests and membership decisions to provide the shared diary.
- Privacy requests and contact details to handle access, correction, deletion and other support requests.
- Limited technical information processed by our hosting providers to operate and secure the service. We use a hashed request-address identifier for short-lived abuse limits.
Who can see it
Your nickname, avatar and activity are visible to approved members of the events you join. Hosts can manage events, invitations and participant records. Your account email and private profile name are not included in event member lists or public link previews. Anyone with an invitation can request to join, but approval is required to view the event’s history. Be mindful when recording moods or locations and obtain permission before recording someone else.
We use Supabase for authentication and database services and Vercel for hosting. Service providers may process information outside your country. The configured database is in Frankfurt, Germany; that does not mean all provider processing remains there. If you choose WhatsApp sharing, WhatsApp receives the message and link you send under its own terms. We do not sell personal information or use the app to deliver targeted advertising.
Trying Caipi without an account
Sample drink entries on the public website stay in memory and disappear when you reload. Game preferences can be stored on your device. If you choose to save a drink, we keep that single selection in this tab’s session storage for up to 24 hours so it can follow you through signup or login. You still choose an event and participant and confirm before it is logged. You can discard the selection. Demo participants and sample events are never copied into your account.
Cookies and your phone
Essential cookies maintain your session. Remember me keeps a session for up to 45 days; otherwise the cookie lasts for the browser session, with a server limit of 12 hours. Browsers may restore sessions after reopening. Local storage and IndexedDB keep cached events, preferences and pending offline changes on your device. Shared devices may expose previously loaded information. Logging out clears the active profile’s cached diary after pending changes have been synchronized.
Product statistics and owner support
The authorized owner and administrators can review account, event, drink, invitation and saved place records through a protected console to understand adoption, maintain the service and respond to support or privacy requests. Statistics use the diary records already needed to provide the app. Restricted support views can include individual account and event records; administrator access and changes are recorded in a security audit trail.
Optional feature usage statistics
We also collect optional observations such as game starts and completions, replay and recap use, sharing actions, water-reminder impressions and shortcuts, and demo-to-signup activity. These observations contain an allowlisted feature or action, a timestamp and limited numeric measurements. Signed-in app observations are linked to your account. Public demo observations use random identifiers kept within this browser tab’s session, rather than a persistent device fingerprint. Coarse campaign names are accepted from a fixed list; raw page URLs, search text, invitation links and referrer URLs are not collected.
This optional tracking does not copy drink names, drink history, mood values, precise coordinates, private profile names, emails, passwords or messages into the observation stream. Offline observations use a separate bounded device queue for up to 72 hours. Raw observations are normally removed after 90 days by scheduled cleanup. We may record limited server-confirmed synchronization outcomes and timing when optional statistics are enabled; these contain operation totals and failures, without diary payloads.
You can turn optional statistics off here or in Profile. We also respect your browser’s Do Not Track and Global Privacy Control signals. Turning tracking off clears queued observations on this browser and stops new optional observations; it does not erase already received observations or alter your shared diary. You can request deletion of previously collected personal data using the privacy form below. Essential authentication, abuse limits, administrative security logs and statistics calculated from the records required to run your diary continue independently of this option.
Help shape Caipi
Optional statistics show which games and features people use. We never include drink names, moods, messages, exact locations or credentials in this tracking. Your choice applies on this browser.
Your drink diary and essential security logs work independently of this setting.
Retention and removal
We keep account and diary information while it is needed to provide the service, unless you request deletion or another legitimate requirement applies. Archiving an event does not delete it. Removing a member stops new access but preserves the event’s historical records. Account deletion requests require manual review, including how to remove or anonymize your contribution in shared events without deleting other people’s records. Copies saved by other participants cannot be recalled, and backup copies may remain until normal provider retention expires.
Your choices and requests
You can edit your profile, choose whether to log moods or location, export the events available to you, and request access, correction or deletion. Depending on applicable law, additional rights may apply. Requests are reviewed manually; we may need proof of identity, particularly because email addresses are not currently verified. You may contact the competent privacy authority if you believe your rights have been infringed.
Contact & privacy requests
Use this form or Profile → Privacy & deletion requests. Do not include passwords, identity-document scans or payment information.
Updates
We will date changes to this notice and seek new consent where required. Account acknowledgement does not authorize unrelated marketing.
Optional public event pages and reactions
Hosts can enable a public, view-only event link. Anyone with that link can see the event name, place and dates, participant names or nicknames and avatars, latest self-reported moods, drink counts and summary statistics. Hosts should check participants are comfortable with this before enabling it. Exact map coordinates, emails, invitation codes and detailed activity logs are not included.
If a host enables public join requests, signed-in visitors may ask to join. Their nickname and request are visible to the host; event membership requires the host’s approval. Hosts can stop new requests while continuing to review existing requests. Signed-in visitors may send one love and one cheers per event. Reaction totals appear publicly; the sender’s nickname appears to event participants. We store reactions and each participant’s acknowledgement so greetings are not repeated after dismissal. Turning sharing off blocks subsequent access and invalidates the link, but cannot recall screenshots or previously viewed information.
