← Back to home

Privacy Policy

Last updated: March 2026

1. Introduction

Koliko ("we", "us") provides beverage inventory by weight for bars and individuals. This policy describes how we collect, use, and protect your information when you use our website, API, and related services.

2. Data we collect

We collect information you provide when creating an account or using the service: email address, name, and password (stored in hashed form). When you use Koliko for inventory and measurements, we store data such as bar and shelf information, drink definitions, inventory quantities, and measurement logs (e.g. weight in grams, volume) associated with your account and, if applicable, your linked bar. If you upload photos of bottle labels to speed up drink setup, we process those images only to help populate your catalog (e.g. name and specs); avoid uploading images that contain unrelated personal or sensitive information.

3. How we use your data

We use your data to provide and operate the service (authentication, inventory management, logs, and reporting), to communicate with you about your account or support, and to improve our services. We do not sell your personal data to third parties.

4. Storage and security

Your data is stored on secure servers. We use industry-standard practices to protect your information. Passwords are hashed; we do not store plain-text passwords.

5. Cookies and sessions

We use session cookies to keep you logged in on the web. The mobile app may use tokens for authentication. These are necessary for the service to function.

6. Subprocessors & third parties

Typical subprocessors include: cloud database/hosting (e.g. MongoDB Atlas, Vercel), transactional email (e.g. Resend), file storage (e.g. S3-compatible object storage), and payment processing (Stripe) when you use billing. Those providers process data as instructed by us. We do not sell personal data for marketing. B2B customers may request a DPA: see Data Processing Agreement (template).

7. Your rights

You may access, correct, or delete your account and associated data:

  • Data export: Download a copy of your data (profile, linked bar, your weigh-in logs, shelves, inventory, scales) from Account → Profile (Export my data) or GET /api/v1/me/export when logged in.
  • Account deletion: Delete your account via account settings or DELETE /api/v1/me. Your profile is removed; your weigh-in logs are anonymized (no longer linked to you).
  • For other requests (e.g. restrict processing), contact us.

Our data retention and deletion behaviour is described in the project documentation (Data retention & GDPR, docs/DATA_RETENTION_GDPR.md).

8. Contact

For privacy-related questions or requests, contact us via the contact form on our website or at the email address provided there.

This is a summary intended for clarity. We recommend legal review for your jurisdiction before relying on this policy in a formal context.