Privacy policy
Your bar stays yours.
Last updated August 25, 2026
Kokto can be used without an account. Core bar and recipe data stays on your device. Signing in alone does not upload your local workspace.
Data stored on your device
Kokto stores your bar inventory, shopping list, favorites, tried recipes, taste preferences, tasting activity, notes, settings, custom recipes, and locally selected photos on your device. Allergy preferences stay local and are not included in account synchronization.
Optional account
If you create or use a Kokto account, we process your email address, display name, account identifier, sign-in provider, and confirmation that you meet the applicable age requirement. Kokto supports email/password and Google sign-in through Supabase. Authentication and security logs may also include device, network, country, route, and diagnostic information.
Cloud backup and synchronization
Signing in does not automatically upload your guest workspace. When you choose Back up this device or Sync now, supported bar inventory, shopping, personal lists, taste data, activity, notes, preferences, custom recipes, and selected private recipe media are sent to owner-restricted account storage in Supabase.
Ratings and app activity
If you rate a cocktail while signed in, Kokto stores the rating with your account so it can be updated and included in aggregate community results. Account-linked sync and feature actions may be processed to provide the requested functionality and personalize your experience.
AI-assisted features
When you explicitly use an AI-assisted feature, your prompt or ingredient search is sent through protected Supabase functions to OpenAI to generate the requested result. Requests use provider controls intended not to store model input for training. Kokto may retain limited hashed safety, quota, and operation records for abuse prevention, reliability, and support.
Photos and camera access
Kokto accesses the camera or a photo only after you choose a feature that needs it. Local custom-recipe images stay on your device unless you explicitly synchronize them. When private media backup is used, the image is stored in owner-restricted Supabase storage.
Service providers and sharing
We use Supabase for authentication, database, private storage, and protected functions; OpenAI for user-requested AI processing; and Google for Google sign-in and Google Play services. These providers process data for us to operate requested features. We do not sell personal data, use it for cross-app behavioral advertising, or include advertising or third-party analytics SDKs in Kokto.
Security
Data sent to service providers is encrypted in transit. Account data uses owner-scoped access controls and private storage. No system is perfectly secure, so please use a unique password and protect access to your device.
Retention and deletion
Local data remains until you erase it in Kokto, clear the app's storage, or uninstall the app. Android backup is disabled for Kokto. Account and synchronized data remains while your account is active and is removed through the account-deletion process, except for limited records that must be retained for security, fraud prevention, legal compliance, or reliable cleanup. Service-provider logs follow the applicable provider and security retention settings.
See Delete your Kokto data for in-app and external request instructions.
Age requirement
Kokto is intended only for people aged 18 or older who also meet the legal drinking age in their location. It is not directed to children.
Website operation
This legal-information site does not use advertising cookies or behavioral analytics. Its hosting provider may process basic network and security logs to deliver and protect the site.
Changes and contact
We will update this policy when Kokto's enabled features or data practices materially change. For privacy questions, rights requests, or complaints, email lokaliapps@gmail.com.