Privacy Policy
Effective date: August 13, 2026
1. Who we are
The Split ("the service", "we") is a cocktail recipe sharing website operated by its owner. For any privacy matter, write to us through the contact page.
2. Data we collect
- Account data. Email address, a cryptographic hash of your password (never the password itself), and the display name you choose.
- Google sign-in. If you sign in with Google, we receive and store your Google account identifier, your email address, and the name suggested by your Google profile. We request no other Google data and have no access to your Google account.
- Content you create. Cocktails, collections, pantry contents, favorites, and appearance preferences.
- Technical data. A session cookie when you sign in; application logs (request path, status, timestamp, and your account's numeric identifier — not your IP address) kept briefly for operations and security; standard server logs (including IP address) retained by our hosting provider; and error reports your browser sends us when a page malfunctions (the error message and page address — never keystrokes or page contents).
- Usage records. When you take an account action — signing up or in, creating or deleting a cocktail or collection, adding a new ingredient, sending an invitation — we record the action, its time, and your account's numeric identifier.
3. How we use data
Solely to provide the service: authenticating you, storing and displaying your content, sending the transactional emails described below, and protecting the service against abuse (for example, rate-limiting failed sign-ins). We also collect aggregate usage statistics (pages viewed, referrer, country, browser type) with a self-hosted, cookie-less analytics tool (Umami) that stores no personal data; see section 6. The usage records described in section 2 are kept first-party, on our own servers, to understand how the service is used as a whole. We do not sell personal data or serve advertising.
4. Legal bases
Where the GDPR or similar law applies: performance of a contract (providing the account and service you request) and legitimate interest (security, abuse prevention, and aggregate privacy-preserving usage statistics).
5. Email
We send transactional email only: address verification, password reset, and invitations. Delivery is performed by Resend (resend.com), which processes the recipient address and message for delivery. Messages you send through the contact page are delivered the same way, to the operator's mailbox, and are not stored by the service. We do not send marketing email.
6. Cookies and local storage
- sid — session cookie, set on sign-in, expires after 90 days. Essential.
- gstate, gpending — short-lived (10–15 minute) cookies used only during Google sign-in. Essential.
- Local storage — appearance preferences (theme, texture, reading order), stored in your browser only.
Our analytics (self-hosted Umami) sets no cookies and stores nothing on your device: visits are counted from a salted hash that rotates and cannot be linked back to you. There are no advertising or third-party tracking cookies.
7. Third parties
- Railway (railway.com) — application hosting and database.
- Resend (resend.com) — transactional email delivery.
- Google — optional sign-in (see section 2); page fonts are served from Google Fonts, which discloses your IP address to Google when the font files load.
8. Public content
Cocktails and collections are public by default and are displayed together with your display name; you can mark them private when creating or editing them. Your display name and public content are visible to anyone, including search engines. Your email address is never displayed.
9. Retention
Account data and content are retained until you delete them or ask us to. Sessions expire after 90 days. Application logs are kept for a matter of days; hosting and email providers retain operational logs under their own policies. Usage records are kept for the life of the service; when your account is deleted they are retained only in de-identified form, under a numeric identifier no longer linked to any account.
10. Your rights
You may access, correct, or delete your content directly in the service. To request account deletion, a copy of your data, or any other data right available under applicable law (including under the GDPR: access, rectification, erasure, restriction, portability, and objection), write to us through the contact page. You may also lodge a complaint with your local supervisory authority.
11. Security
Passwords are stored only as salted scrypt hashes. Traffic is encrypted in transit (TLS). No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
12. Children
The service describes alcoholic beverages and is not directed at children, nor at any person below the age at which their jurisdiction permits the relevant data processing. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.
13. Changes
We may update this policy. The effective date above reflects the latest revision; material changes will be reflected on this page.