Privacy Policy

Last updated: 27 September 2026

ViNotes ("we", "us") is a wine-cellar management app. This page explains what information we collect when you use it, how we use it, who we share it with, and the choices you have. It applies to the ViNotes web app and the ViNotes mobile app alike.

ViNotes is the data controller for the personal data described here. If you have any question about this policy or about your own data, contact us at support@vin-notes.com.

Account & sign-in

You can create a ViNotes account with an email address and password, by signing in with your Google account, or by signing in with Apple. We don't support signing in with Facebook, a phone number, or as a guest, and we never collect a phone number. When you sign in with Apple, we receive the name you choose to share (if any) and an email address — which may be a private relay address Apple generates for you rather than your real one — and use it only to create and sign in to your account.

Password accounts are required to set up two-factor authentication (an authenticator app code); it's optional for accounts that sign in with Google or Apple. The two-factor secret is stored inside Firebase Authentication, our identity provider — it never enters our own database.

From your Google account we read your display name, email address, and (if you have one) your Google profile photo. We don't copy the photo into our own records — we read it from your Google account each time it's shown — but it is used as your avatar, so it can be visible to other people wherever your name appears, such as on a Marketplace listing or a published tasting.

Your account profile stores your display name, email address, and basic account metadata such as when you signed up and when you confirmed that you are over the legal drinking age. That confirmation is recorded as a timestamp only — we never ask for, and never store, your date of birth.

The cellar data you create

Using ViNotes means storing information about your wine collection. All of it belongs to you and is scoped to your account.

  • Cabinet & inventory: the wines and bottles you add, how your storage is laid out, and any photos you take of a bottle's label.
  • Tasting journal: your tasting notes, ratings, and the date you drank a bottle, plus an optional location for where you drank it — typed as free text, or, if you tap "Use My Location," your device's coordinates, which are stored with the entry.
  • Wishlist, gifted, on-hold, and sold history: the bottles you want, have given away, are holding, or have sold, with their dates.
  • Bottle photos you upload are stored in our Firebase Storage, scoped to your account.

Sharing your cellar with others

If you invite someone to view or manage your cellar, we store the email address you invited so we can match it to their account when they accept.

Once you're sharing a cellar with someone — as the owner or as a collaborator — we keep a record of that connection, which includes the other person's account identifier and email address, so both sides can see who has access.

If you block another user, we store the email address you blocked so we can stop future invitations from it.

Marketplace

A listing you post on the Marketplace is visible to other ViNotes users and shows your display name and your profile photo as the seller.

When a buyer and seller message each other about a listing, we store that conversation, including the message text itself, so both sides can read it.

Published tastings

If you publish a tasting note to the public journal, it becomes visible to other ViNotes users together with your display name and avatar. Any photo attached to a published tasting can be viewed by any signed-in user.

AI services we use to help catalog your wines

When you scan or add a bottle, our server may send information to the three third-party AI services below to help identify and enrich it. We name each one separately because they do not receive the same thing.

  • OpenAI: when we read a bottle label, we send the photo of the label itself to OpenAI so it can extract the text on it (producer, vintage, and similar details).
  • Google Gemini: we send wine details — things like the producer, region, and label text, not the photo — to Gemini for enrichment (filling in facts about the wine) and to power semantic search. Gemini is also used as a fallback for reading a label if OpenAI is temporarily unavailable. These requests are tied to the wine, not to your account.
  • Replicate: when you trim the background from a bottle photo, we send the photo to Replicate, a background-removal service based in the United States, so it can remove the background and return just the bottle. If the photo shows more than one bottle and you pick which one to keep, we send the same photo to Replicate again to detect the bottles in it. Because Replicate is based in the US, the photo is processed outside the EU for this feature.

Push notifications

If you enable notifications, we register your device: we store its Firebase Cloud Messaging push token together with your platform (iOS or Android), your chosen language, and when it was first and last registered. This is scoped to your account like everything else, so deleting your account removes it too.

We use Firebase Cloud Messaging, a Google service, to deliver these notifications. It receives your device's push token and the notification content itself.

A notification can name a wine, a cabinet, or another user's display name — for example, when someone shares a cabinet with you. Notifications are opt-in at the operating-system level: Android asks for permission before sending them (Android 13 and later), and iOS asks through its standard system prompt.

Email

We send email through a third-party SMTP provider for two things: invitations to share a cellar (which includes the inviting user's display name), and account-security messages such as two-factor-authentication reset requests and confirmations.

Winery map lookups

The Atlas feature looks up winery locations using OpenStreetMap's Overpass and Nominatim services and, sometimes, a winery's own website. These lookups are about wine and place data, not about you personally. Atlas's "Wineries around me" button uses your device's position only to center the map — it never leaves your device. If you tap "Use My Location" on a tasting, though, your device's coordinates are sent to OpenStreetMap's Nominatim service, run by the OpenStreetMap Foundation in the United Kingdom under its own privacy policy, to convert them into an address.

Why we're allowed to use your data

If you are in the United Kingdom or the European Economic Area, data-protection law requires us to have a legal basis for each use of your personal data. Ours are:

  • To provide the app (performance of a contract): creating and securing your account, storing your cellar, journal, wishlist and history, carrying out the sharing you set up, publishing a listing or a tasting when you ask us to, and delivering the notifications you switched on.
  • To keep ViNotes working and safe (legitimate interests): two-factor authentication, rate limits on the AI features, the blocklist, and the server logs we use to diagnose faults. We rely on this only where it does not override your own rights and freedoms.
  • Where you have given permission (consent): camera and photo-library access, and permission to send notifications. Your device asks for each of these, and you can withdraw either one at any time in your device settings.
  • Where the law requires it (legal obligation): responding to a valid legal request, or keeping records we are obliged to keep.

Where we rely on consent, you can withdraw it at any time. Withdrawing it does not affect anything we did while the consent was in place.

Where your data is stored

ViNotes runs on Google Firebase: Firebase Authentication for sign-in, Cloud Firestore (hosted in the EU, region eur3) for your data, Firebase Storage for photos, Firebase Hosting, and Cloud Functions for our server.

Our server logs can include your account identifier and email address, which helps us diagnose problems. Google Cloud Logging keeps them for a limited period — 30 days by default — and then deletes them automatically.

Sending data outside Europe

Your cellar data is stored in the European Union, in Cloud Firestore's eur3 region. Some of the services we depend on are based in the United States, so a limited amount of data leaves the European Economic Area:

  • OpenAI — the bottle label photo, when you scan a label.
  • Google — parts of Firebase Authentication, Firebase Cloud Messaging (which delivers push notifications) and our diagnostic logs may be processed outside the European Economic Area.

For the transfers to OpenAI and to Google we rely on the European Commission's Standard Contractual Clauses, which both providers include in their data-processing terms. If you tap "Use My Location" on a tasting, your device's coordinates also go to the OpenStreetMap Foundation in the United Kingdom, which the European Commission recognises as providing an adequate level of data protection, so no additional safeguards are required.

No analytics or tracking

ViNotes does not run analytics or tracking, shows no advertising, uses no advertising identifiers, and sets no cookies. We do not sell or share your personal data for advertising purposes.

What we store on your device

Your device keeps a few small things locally: your chosen language and interface preferences, and an offline cache of your own cellar data so the app feels fast. That cache is cleared when you sign out. We don't use cookies.

Data retention & deleting your account

You can delete your account yourself from Settings → Account. Deleting your account removes your cellar, journal, wishlist and history, your profile, your marketplace listings and their photos, your sharing connections in both directions, your registered push-notification devices, and your two-factor reset requests.

Two things are kept rather than deleted, because someone else depends on them: if you've messaged a buyer or seller on the Marketplace, that conversation stays visible to the other person with your messages left exactly as written, though your identity in the thread is anonymized. And if you've published a tasting to the public journal, it stays published — the text and any photo remain, and the entry is marked as belonging to a deleted account rather than removed.

If you're a member of a cabinet someone else owns and you leave or delete your account, that cellar isn't deleted — ownership passes to another member instead.

Your rights

Depending on where you live, you may have the right to access, correct, delete, object to, or receive a copy of your personal data.

  • Access: ask what personal data we hold about you.
  • Correction: ask us to fix inaccurate data — or just edit your profile in the app.
  • Deletion: delete your account yourself in Settings → Account, or ask us to do it.
  • Objection: object to a particular use of your data.
  • Portability: ask for a copy of your data in a portable format.
  • Complaint: if you are in the UK or the European Economic Area, you can complain to your national data-protection authority. We would rather you came to us first so we can put it right.

We don't yet offer an automated "download my data" export. The cabinet CSV export in Settings is an inventory export for backup and re-import — it doesn't include your profile, journal notes, or marketplace messages. For a full copy of your data, or any other request, email support@vin-notes.com.

Children

ViNotes is about wine. It isn't directed to children and isn't intended for anyone under the legal drinking age in their country.

Before you can use the app, we ask you to confirm that you are over the legal drinking age in your country, and we record the date and time of that confirmation on your account. We don't ask for your date of birth, and we don't verify your age against any external source.

Changes to this policy

If we change this policy, we'll update the "Last updated" date above.

Contact us

Questions about this policy or your data? Email support@vin-notes.com.

Loading...