Sejdel App
Privacy Policy.
Effective: 5 July 2026 · Last updated: 14 August 2026
This policy explains what information Sejdel collects, why, how long it lives, and the choices you have. Sejdel is a social blood-alcohol-content (BAC) estimation and drink-tracking app: you log your night, see live estimates, and share it — only as much as you choose — with friends and your group.
01Who we are
Sejdel App is operated by an individual developer (sole proprietor) enrolled in the Apple Developer Program.
Contact: contact@sejdel.com
02Information we collect
We only collect what the app needs to function.
Information you provide
- Account details: your email address, to create and authenticate your account, and a unique @username other users can search to find and friend you.
- Profile information: display name, age, biological sex, and body weight. Sex and weight are required inputs to the Widmark BAC calculation; age confirms you meet the legal drinking age. Your sex and weight are never shown to other users — shared BAC values are computed on our servers so those inputs never leave the database (see section 06).
- Optional profile photo (avatar): if you choose to add one, it is stored on our servers and shown to other users alongside your name.
- Drink and session data: drinks you log (type, volume, ABV, timestamp), live sessions and plans you start or join, groups, shared rounds, and manually added guests (name, sex, age, weight you enter for them).
- Friends and invites: friend requests you send or accept, and session invites between you and other users.
- Photos you choose to share (see section 05 for exactly who sees
what and for how long):
- Night schnaps — photos of your own night stay on your device unless you share them one of the ways below.
- Squad schnaps — photos you take in the squad card are uploaded and visible to your group for the night, then deleted.
- Live stories — photos you post to the Tonight strip are uploaded and visible to your accepted friends for 24 hours, then deleted. A story can include a caption and, if you leave them attached, your estimated BAC and current location label at the moment of posting.
- Posted nights — recaps you explicitly post to the Nightline feed (photos, stops, stats) are uploaded and visible to your friends until you delete the post.
Information collected with your permission
- Location (while using the app): used to find nearby bars and venues, to check in, and — if you opt to mark one — to save a pre-game or between-bars spot. Exact marked-spot coordinates live in your on-device journey; when you are in a group session, check-ins and spots you add for the group are shared with that group so everyone's recap shows the night's route. Location is never used for background tracking and never sold.
- Camera & photo library: used to scan beverage barcodes (processed on-device, never uploaded) and to take or pick the photos described above. Photos are only ever uploaded through the explicit share features.
- Push notification token: if you enable notifications, a device token is stored so we can notify you about likes, comments, friend requests, and session invites.
- Contacts (finding friends): if you tap “find friends from contacts” and grant access, the app reads your address book on your device to work out which of your contacts already use Sejdel. We never upload your contacts. Each phone number and email address is normalised, combined with a fixed app value and turned into an irreversible SHA-256 digest on the device; only those digests are sent. They are compared against digests of registered users in a single query and then discarded — we store nothing whatsoever about people who do not have a Sejdel account, including no record that they appeared in anyone's contacts. Names and numbers of contacts who are not users never leave your phone; when you invite someone, the message is composed in Apple's own Messages sheet and sent by you, not by us.
- Your own phone number (optional): if you add a number so friends can find you, we store only its digest — computed the same way, on your device. We do not store your phone number itself, anywhere. You can remove your digests at any time with “Remove my codes” in your profile, which stops you being discoverable without affecting your account. The digest of your account email is stored for the same purpose.
A note on what digests can and cannot do: hashing is one-way, so a digest cannot be turned back into a phone number by reading it. It is not magic, though — because there are a limited number of possible phone numbers, someone who obtained our database could test candidate numbers against a digest. That is why we never store raw numbers, why the digest table is readable by no one but its owner, and why matching happens inside a restricted database function that returns profiles and never digests.
Information shared while you're live
- Live pulse: while a live session of yours is running, your accepted friends can see that you're out, your estimated BAC, your drink count, the venue you're checked into, and — in a group session — who you're with and their estimated BAC. This presence record is deleted when your night ends.
Information collected automatically
- Basic technical data needed to operate the service (authentication tokens and timestamps).
We do not use third-party advertising or analytics/tracking SDKs, and we do not use the Apple Advertising Identifier (IDFA).
03How we use your information
- create and secure your account and sign you in;
- calculate and display your estimated BAC and time-to-sober;
- power live sessions, groups, shared rounds, the group route, leaderboards, and recaps (personal and group);
- power the social features you use: friends, invites, the live pulse, stories, squad schnaps, and the Nightline feed;
- show nearby venues and current venue deals when you grant location access;
- look up beverages you scan;
- send notifications you have opted into;
- maintain, debug, and improve the app.
We do not sell your personal information, and we do not use it for third-party advertising.
04How your information is shared
- With your accepted friends: your name, @username, avatar, live pulse (while a night is running), stories you post, and nights you post to the feed.
- With your group: during a group session, members see your name, avatar, estimated BAC, drink count, shared rounds, the group's route (check-ins and stops added for the group), and squad schnaps. The group recap each member keeps includes this shared night.
- Service providers: our backend (database, authentication, storage, and functions) is hosted on Supabase. Push notifications are delivered through Apple's Push Notification service. These providers process data on our behalf and are not permitted to use it for their own purposes.
- Legal: we may disclose information if required by law.
People who are not your friends and not in your group see nothing beyond what's needed to find you: your name and @username in user search.
05How long things live
Sejdel is built around the night — most shared content is deliberately short-lived:
| Data | Visible to | Lifetime |
|---|---|---|
| Live pulse (BAC, venue, drink count) | Accepted friends | until night ends |
| Live stories | Accepted friends | 24 hours |
| Squad schnaps | Your group | until session ends* |
| Group route & session data | Your group | retained |
| Posted nights (feed) | Accepted friends | until you delete |
| Night recaps & journey photos | Only you | on your device |
| Account & profile | — | until account deletion |
| Your contact digests (phone/email) | No one — matching only | until you remove them or delete your account |
| Digests you send when scanning contacts | — | not stored (discarded after the query) |
*Members can save individual squad schnaps into their own recap before the session ends; unsaved copies are purged by a scheduled cleanup (at most 48 hours). Expired stories and schnaps are deleted from storage, not just hidden.
06Security
- All traffic between the app, this website, and our servers is encrypted in transit (HTTPS/TLS).
- Every database table is protected by row-level security: friend-gated and group-gated reads are enforced by the database itself, not just the app.
- Shared BAC values are computed server-side so your body weight and sex are never exposed to other users' devices.
- Ephemeral media (stories, squad schnaps) is removed by automated cleanup jobs.
- On a shared device, each signed-in account's local night data is stored separately.
- Contact matching never transmits a phone number or email address, and the digest table is restricted so no user can read another user's digests.
07Your choices & rights
- Delete content in-app: your own stories, squad schnaps, posted nights, past-night recaps, and journey photos can be deleted from inside the app.
- Permissions: location, camera, photos, and notifications are optional and controlled in iOS Settings; core drink logging works without them.
- Friends: only accepted friends ever see your pulse, stories, or posts — you control who that is.
- Contact discovery: entirely optional. Contacts access can be revoked in iOS Settings, and “Remove my codes” in your profile deletes the digests that make you findable. Neither affects anything else in the app.
- Account & data deletion: email contact@sejdel.com from your account address and we will delete your account and associated server data. Depending on where you live (e.g. EU/EEA under GDPR), you may also have rights to access, correct, or export your data — the same address handles those requests.
08Age
Sejdel is intended only for people of legal drinking age in their country and is rated 17+ on the App Store. We do not knowingly collect information from anyone below the legal drinking age; if you believe we have, contact us and we will delete it.
09Changes to this policy
If we change this policy in a meaningful way, we'll update the date at the top and, for significant changes, note it in the app. Continued use of Sejdel after a change means you accept the updated policy.
Questions? contact@sejdel.com · See also the Terms of Use.
← Back to Sejdel