Privacy policy
The short version: Bierfux has no account, no sign-up and no tracking. Everything you enter stays on your device. The app makes exactly one kind of network request, and it fetches exchange rates. This website sets no cookies and loads nothing from anyone else, which is why it does not ask you anything.
1. Who is responsible
The controller for this processing, in the sense of Art. 4(7) GDPR, is:
- Name
- Roman Flatscher
- hello@bierfux.at
- Application
- Bierfux for Android, application id
at.bierfux.app
Bierfux is a private project, not a company. There is no data protection officer, and none is required under Art. 37 GDPR. Questions about this policy or about your rights go to the address above and are answered by us.
2. The app: what is stored, and where
Everything you record in the app is written to a database inside the app’s own private storage on your device. Other apps cannot read it, and neither can we.
- Database
bierfux-app.db, in the app’s private directory at/data/data/at.bierfux.app/databases/- Contents
- Beer name, note, quantity, size and unit, price and currency, alcohol content, country, type of seller, labels, the date of a history entry and the exchange rate frozen with it, the Bierdeckel’s drink lines including the time each drink was counted, and your settings.
- Not included
- No identifier, no account, no device ID, no advertising ID, no location data, no photos, no contacts.
None of it is transmitted anywhere. It leaves your device only if you export a backup yourself — see section 6.
All the permissions, in full
The published release build requests exactly these three, and none of them concerns location, storage, the camera or your contacts:
android.permission.INTERNET— to fetch exchange rates.android.permission.ACCESS_NETWORK_STATE— to tell whether there is a connection, so that with none the app carries on with the rates it already has instead of waiting.at.bierfux.app.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION— an app-internal signature permission that one of the libraries declares for its own broadcast receiver. It grants access to nothing and nobody is asked to grant it.
Android’s automatic Google backup is switched off
By default Android copies app databases to the user’s Google Drive. That
would have made “stays on your device” untrue, so
android:allowBackup is set to false in the app. The
same flag also governs device-to-device transfer when setting up a new phone.
If you want to take your entries with you, the export in section 6 is how —
deliberately a step you take yourself.
There are no analytics, crash-reporting, advertising or attribution libraries in the app. No Firebase, no Crashlytics, no ad SDKs.
3. The one network request
Prices in different currencies can only be compared if the app knows exchange rates. For that — and only for that — it asks a server:
- Endpoint
GET https://www.bierfux.at/api/rates?base=XXX, and for a particular day additionally&date=YYYY-MM-DD- What the request contains
- One header (
Accept: application/json), the base currency you asked for, and possibly a calendar date. No body, no cookies, no sign-in, no identifier. - How often
- For current rates, at most once in 24 hours. Plus once per date for which no rates are stored yet.
Two things that ought to be said plainly.
First, every web request reveals your device’s IP address to the server, and this one is no exception. It ends up in the access log of the same host that serves this website (section 4).
Second: when you file a price into the history, the app freezes the rate for that entry’s date, so an old price does not drift as the rate moves. To get that rate, the date is sent along. A calendar date is therefore the only value derived from anything you typed that ever reaches the server. It is not attached to a beer, a price or a place — but it is not nothing, which is why it is written down here.
Legal basis: Art. 6(1)(b) GDPR. The conversion is the feature you asked the app for, and without this request there is no such feature. The app works without it too: with no rates, prices are simply compared in the currency you entered them in.
4. This website
No cookies, no tracking, nothing from anyone else
This website sets no cookies. That is not a promise but a property of the site: session handling is switched off for these pages, because they have no form and no login. That is also why there is no cookie banner — there would be nothing to ask about.
No analytics or statistics service is embedded. The fonts, images, stylesheet and script are all served from this server; nothing is loaded from a content delivery network, from Google Fonts, or from anywhere else. Opening this page therefore makes your browser contact no third party at all.
One value in local storage
If you switch the appearance above to light or dark, that choice is stored in
your browser’s localStorage under the key
bierfux-theme, so the page does not flash white on your next
visit. The value is light or dark, it is never
transmitted, and choosing “Follow the system” deletes it. Legal basis:
Art. 6(1)(a) GDPR — you cause it by using the switch.
Server logs
Like every web server, this one logs requests. That covers both the pages you read here and the app’s rate requests from section 3.
- Recorded
- IP address, timestamp, the address requested, HTTP status, bytes transferred, and — if your browser sends them — the user agent and the referring page.
- Purpose
- Running and securing the server: finding faults, spotting abuse, keeping the service up.
- Legal basis
- Art. 6(1)(f) GDPR. The legitimate interest is operating a server that works and is not being abused.
- Analysis
- These logs are not analysed, not built into profiles, and not combined with any other data.
- Retention
- We do not archive them. How long the log files are kept on the server follows the hosting provider’s own rotation; they are not retained beyond that.
- Recipients
- The hosting provider that runs the server, as a processor under Art. 28 GDPR. Nothing is passed on beyond that.
5. Links to other services
Two links on this website lead to providers with rules of their own. They are only contacted when you click — nothing is preloaded, and before a click neither of them learns that you were here.
- PayPal (“Invite us for a beer”). If you click it, PayPal processes your data under its own privacy policy. Nothing is given in return for a payment, and nothing is unlocked or recorded in the app.
- Google Play, once the app is published there. The download, and whatever Google collects during it, is governed by Google’s terms.
The app itself opens only two outbound addresses, and both only when you tap
them: the PayPal link, and your mail app with
hello@bierfux.at as the recipient. It sends nothing of its own
accord.
6. Backups you export yourself
The app can export your entries as a JSON file. That happens only when you ask for it, and you choose where it goes: the file is handed to your system’s share dialog. From then on it lives wherever you put it and follows that place’s rules — a cloud drive, a messenger or a mailbox is a third party even when the file came from you. The file does not come to us, and it contains no identifier, only your entries.
You can delete everything in the app itself, under More → Data → Clear all data, section by section. And because nothing is ever transmitted, uninstalling the app is a complete deletion: there is no copy elsewhere that could be left behind.
7. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Any consent can be withdrawn at any time (Art. 7(3)).
In practice there is little to do about the app’s contents: we do not have them, so we can neither hand them over nor delete them — you have direct access yourself, and the export already puts portability in your hands. For the server logs in section 4, write to the address in section 1; include the rough time if you can, because without something to go on an IP address in a log cannot be matched to you.
If you think something about this processing is wrong, you can complain to the supervisory authority:
- Austrian Data Protection Authority
- Barichgasse 40–42, 1030 Vienna, Austria · dsb.gv.at
You may also complain to the authority in your own EU country of residence.
8. Children
The app is not aimed at children. By its subject it has to do with alcohol, and it deliberately collects nothing about the person using it — including no age. Anyone who had to create an account would have to give something away; here there is no account.
9. Changes
If what the app stores or transmits changes, this policy changes with it and the date above moves. The disclaimer bundled inside the app carries the same date; if the two dates disagree, the version here is the newer one.
In case of doubt the German version of this policy governs, since it is the one written first.
Questions or concerns: hello@bierfux.at · Terms · Imprint