Privacy Policy
How WineDNA collects, uses, shares and deletes your personal data — and how you take control of it.
1. Who is responsible for your data
The data controller for the personal data described in this policy is Andrey Goleta, a natural person established in Warsaw, Poland (referred to below as "WineDNA", "we" or "us"). WineDNA is run by that one person and not by a company, so there is no company name and no registration number to give you — the controller is the individual named here.
Because the controller is established inside the European Union, Article 27 GDPR does not apply and there is no EU representative to name. Polish law and directly applicable EU law govern this processing.
Privacy questions and requests: support@icoffio.com. That inbox is read by the controller himself, and a request sent to it is treated as validly made. Where a supervisory authority or a court needs a postal address, it is given to them.
No data protection officer has been appointed, and none is required. Article 37(1) GDPR obliges a controller to appoint one only where it is a public authority, where its core activities require regular and systematic monitoring of data subjects on a large scale, or where its core activities involve large-scale processing of special-category or criminal-conviction data. None of the three applies: WineDNA is a private one-person service, it processes no special-category data — expressly no health data — and it monitors nobody on a large scale. We will reassess this if the service grows, and this paragraph will change on the day it does.
2. The short version
The parts most people care about, in one place. The detail follows below and takes precedence over this summary.
- Your Taste DNA and your ratings are yours. We never sell identifiable taste history, and we do not share it with advertisers.
- Conversations with the AI sommelier are processed by Anthropic on our behalf. They are not used to train anybody's models, and you can delete them.
- We collect no location data at all. One photograph can leave your device, and only in one situation: if the words your phone reads off the label match no bottle we know, the app sends that one label picture to be read and looked up on the web, and says so on the screen with the result. A bottle we recognise sends no picture. The camera is the only permission the app asks for; choosing a picture needs no permission at all.
- You can export everything from inside the app, and close your account from the app or by asking us. Closing it is immediate and irreversible.
- WineDNA is an 18+ service. We do not knowingly collect data from minors.
- Analytics are privacy-safe: counts and outcomes, never your notes and never your searches. No advertising identifier, no cross-site tracking, no IDFA, no advertising cookies.
3. What data we collect
We collect only what the product actually needs. Where something is optional, it is marked as such.
You can also browse without an account. Guest mode creates no account and no profile, and a guest scan is a pure read that stores nothing on our side. Nothing measures a guest either: the product analytics described below need an account, and the endpoint that receives them refuses a request that does not carry one. The only thing kept on the device is the 18+ confirmation you give, held in memory for that session and written nowhere; the only thing kept on ours is the short-lived server access log described in section 9.
Two things we want to state as plainly as possible. We collect no location data of any kind: WineDNA never asks for location permission and contains no location code, so there is no coarse location, no precise location and no coordinates to switch off. Photographs are a different matter, and here is exactly when one is collected. A bottle we recognise sends no picture at all: you point the camera at a bottle, or hand the app one you already have, your own phone reads the label, and only the recognised words leave the device. When that fails to match a bottle in our catalogue, that one label photograph is sent to us and on to OpenAI, the AI provider that reads it and searches the web for the bottle — and the screen with the result says so. Before it leaves, your phone resizes it and strips its location and capture time, so no coordinates and no timestamp travel with it. We do not store it: it is used to identify the bottle and discarded within the same request. This happens only when you are signed in and only after the words your phone read have failed to match a bottle in our catalogue; each account has a small number of such lookups a day. As a guest, no photograph of yours is ever sent.
- Account data — your email address, plus a WineDNA account identifier and your language and region settings.
- Age verification — we ask for your date of birth to confirm you are of legal drinking age. We store only the resulting yes/no flag; the date of birth itself is discarded immediately after the check.
- Ratings and tasting notes — the scores you give, the structured answers in guided rating, and any free-text notes you write.
- Label text — the words the scanner reads off a bottle or a wine list, so we can identify the wine. Read on your own phone; only the text is sent.
- Taste DNA — the taste profile we derive from your ratings across six axes (body, tannin, acidity, sweetness, oak, fruit), plus confidence values.
- Cellar, wishlist and history — the wines you save, own or have looked at.
- AI conversations — the messages you send to the AI sommelier and the answers it returns, if you keep conversation history switched on.
- Technical data — device type, operating system version, app version, IP address and security logs. WineDNA ships no crash-reporting SDK, so we receive no crash reports.
- Product interaction — which screens you open, which features you use and whether they worked: a scan that found nothing, a search that returned nothing, a rating you started and did not finish. Counts and outcomes only. Never a rating you gave, never a note you wrote, never a word you typed into search or into the sommelier.
- Support correspondence — the messages you send us and our replies.
- Sign-in failure diagnostics — if a sign-in attempt fails on your device, the app sends us the error codes the system produced, the lines the system frameworks wrote to this app's own log about that attempt, your device model, iOS version, app build and language. It is sent only on a failure, never on a success, and never when you simply cancel. It carries no email address, no account identifier and no sign-in token.
4. Why we use it, and on what legal basis
Under the GDPR we must name a legal basis for each purpose. Ours are as follows.
- Providing the service — running your account, recognising wines, computing Wine Match, keeping your cellar in sync across devices. Legal basis: performance of our contract with you (Art. 6(1)(b)).
- Personalisation — building and updating your Taste DNA from your ratings. Legal basis: performance of our contract, because personalisation is the product.
- AI sommelier — answering your questions with context from your profile. Legal basis: performance of our contract. The "use my data" option decides whether your Taste DNA travels with the question. It is on by default and you can switch it off at any time, so it is a control you opt out of, not a consent we ask you for — and we do not rely on Art. 6(1)(a) for it.
- Age verification — meeting our legal obligations around alcohol-related services. Legal basis: legal obligation (Art. 6(1)(c)) and our legitimate interest in not serving minors.
- Security, abuse prevention and moderation — keeping accounts safe and handling reports about the Taste Neighbours surface. Legal basis: our legitimate interests (Art. 6(1)(f)).
- Product analytics — understanding which features work, in aggregate, from the interaction data already listed above. Legal basis: our legitimate interests. The measurement is first-party and privacy-safe: no analytics SDK ships in this release, no third party receives any of it, and the in-app privacy settings switch it off.
- Billing and tax records — legal basis: legal obligation. Nothing is billed and nothing is earned today, so nothing is actually processed on this basis yet.
- Diagnosing sign-in failures — finding out why a sign-in did not work, so it can be fixed. Legal basis: our legitimate interests (Art. 6(1)(f)) in a working sign-in, balanced by sending diagnostics only when an attempt fails and by stripping anything identifying before it leaves your device.
5. How AI processing works
WineDNA uses Claude, a large language model provided by Anthropic, to explain wines, answer questions and generate recommendations. Anthropic acts as our processor under a data processing agreement.
What we send: the question you typed, word for word; the wine or wines it concerns; catalogue information about the bottles under consideration; and — unless you switch the "use my data" option off — a summary of your Taste DNA, which covers the six taste axes, your grape and region preferences, and the characteristics you have told us you dislike. If you ask about a dish, the dish goes too. We do not send your email address, your name or your payment details to the model, and there is no location data to send. Type into the assistant only what you are content to have processed this way.
Your conversations are not used to train Anthropic's models or ours. This is contractually excluded.
You can switch conversation history off, delete individual conversations, or delete all AI data without deleting your account. Deleting your account deletes it too.
AI output is generated text and can be wrong. It is guidance, not professional advice, and it is never used to make a decision that produces a legal effect for you.
We do not carry out automated decision-making within the meaning of Article 22 GDPR. A Wine Match score is a recommendation you are free to ignore.
6. What we never do
Some commitments are easier to state as absolutes.
- We do not sell identifiable taste history — not your ratings, not your Taste DNA, not your cellar, to anyone, at any price.
- We do not share your data with advertising networks or data brokers, and we do not build advertising profiles.
- We do not use the Advertising Identifier (IDFA) and we do not ask for App Tracking Transparency permission, because we do not track you across other companies' apps and websites.
- We do not market to anyone under the legal drinking age.
- We do not make claims about health benefits of alcohol, and we do not process health data.
8. International transfers
Four of the providers named above are established in the United States: Anthropic PBC, OpenAI, L.L.C., Plus Five Five, Inc. (Resend) and Apple Inc. Sending data to them is a transfer outside the European Economic Area, and each one needs a safeguard under Chapter V of the GDPR. Hosting is not one of them — Hetzner keeps your account and your ratings in Germany.
For Anthropic and for Resend the safeguard is the European Commission's Standard Contractual Clauses, Module Two (controller to processor), as approved by Implementing Decision (EU) 2021/914 of 4 June 2021. Both providers incorporate those clauses into the data processing agreement that governs our account, so the clauses are already in force rather than something still to be signed. Apple states in its own privacy policy that its transfers of personal data collected in the EEA, the United Kingdom and Switzerland are governed by Standard Contractual Clauses.
The clauses are not the whole of it. Data is encrypted in transit and at rest, and what each provider is given is kept to the minimum its job needs: Resend gets an address and a code, and the AI model gets no email address and no name.
You can request a copy of the relevant safeguards from support@icoffio.com.
9. How long we keep things
We keep personal data only as long as it serves the purpose it was collected for.
One note before the schedule, because this is the paragraph a regulator can check against a database in minutes: the periods below are now enforced by a job that runs every 24 hours on the server, not only by us honouring them. It sweeps deleted accounts, AI conversations, access logs, moderation records and spent sign-in codes, and de-links analytics from the person they came from. Until 14 August 2026 this paragraph said the opposite — that no automated purge existed — and it was true when it was written.
The schedule we are committing to:
- Account data — for as long as your account exists. Closing the account cuts off access to it immediately; erasing what is stored behind it follows within 30 days of the request.
- Ratings, Taste DNA, cellar and wishlist — for as long as your account exists, or until you delete the individual entries.
- AI conversations — 12 months on a rolling basis, or until you delete them, whichever comes first.
- Label photos — identified and discarded, never stored. A picture is sent only when a bottle is not in our catalogue and needs the web lookup; it lives for the length of that one request, and it is written to no database and no file store, so there is nothing of yours to age out. What OpenAI keeps for its own abuse monitoring is governed by our agreement with them.
- Age verification flag — for as long as your account exists. The underlying date of birth is never stored.
- Security and access logs — 90 days. These cover requests made while browsing without an account too.
- Sign-in failure diagnostics — 90 days, in the same server log as the entries above, and deleted with it.
- Analytics — aggregated and no longer linked to an identifiable person after 14 months.
- Moderation records for reported content — 12 months after the report is closed, so that repeat abuse can be detected.
- Billing, invoicing and tax records — there are none, because there is no revenue to document. Nothing is sold to you: no subscription is on sale, there is no in-app purchase, and no invoice is issued. With no income there is no accounting record and nothing for accounting law to make us keep. On the day that changes — a paid feature — Polish accounting and tax law will require the records it generates to be kept for five years, counted from the start of the year following the financial year each record relates to (ustawa o rachunkowości art. 74; Ordynacja podatkowa art. 86 § 1), and this line will say so before it happens. Those records would concern money moving between us and Apple, and would identify no user.
- Backups — a database dump is taken before each deployment that changes the database schema, and the ten most recent are kept. Deleted data can persist in one of those until it falls out of the set. The dumps are triggered by deployments rather than by a clock, so there is no fixed number of days to quote here: the ten-dump limit is the whole of the rule.
10. Your rights
If the GDPR applies to you, you have the right to: access your data; correct it; delete it; restrict or object to processing; withdraw a consent you previously gave (without affecting what happened before you withdrew it); and receive your data in a portable, machine-readable format.
You also have the right to lodge a complaint with a supervisory authority — the one where you live, where you work, or where the alleged infringement took place. Ours, because the controller is established in Poland, is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland, uodo.gov.pl.
11. How to make a request (DSAR)
Send your request to support@icoffio.com from the email address on your account, or use the in-app export and delete tools, which handle the two most common requests automatically.
We will acknowledge your request and respond within one month of receiving it. If your request is complex, or if you have made several, we may extend that by up to two further months and will tell you why within the first month.
Requests are free. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse it, and we will explain our reasoning.
If we cannot identify you from the request we may ask for information that lets us verify you own the account. We will not ask for more identification than we need, and we will not use what you send for anything else.
Requests are handled by the controller personally, Andrey Goleta. There is no team behind that inbox and no ticket queue to be lost in, which is also why we ask you to write from the address on your account.
12. Export and deletion
You can export a machine-readable copy of your account data — ratings, Taste DNA, cellar, wishlist, AI conversations and the product-interaction events recorded against your account — from the app at any time.
You can delete your account from inside the app. It closes the moment you confirm — there is no confirmation email and no cancellation window, and the deletion cannot be undone. If you cannot reach the app, ask us by email instead. The account deletion page describes both routes, exactly what a deletion covers, how quickly each part happens, and what is retained and why.
14. Age and children
WineDNA is an 18+ service and is rated accordingly on the App Store. Where the legal drinking age in your country is higher than 18, that higher age applies to you.
We verify age at sign-up by asking for a date of birth and storing only the resulting flag. We do not knowingly collect personal data from anyone below the legal drinking age. If you believe a minor has created an account, write to support@icoffio.com and we will delete it.
15. Security
Data is encrypted in transit (TLS) and at rest. Access to production data is restricted to the people who need it and is logged. Database and cache services are not reachable from the public internet. Where the API issues a browser session it is an HttpOnly, Secure cookie and state-changing browser requests carry a double-submit CSRF check; the iOS app authenticates with a bearer token instead.
No system is perfect. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and, where the risk is high, notify you directly.
16. Reporting content and abuse
WineDNA has no reviews and no public posts: nothing another member writes is shown to you, and nothing you write is shown to anybody else. The only place another member appears is Taste Neighbours, and it is anonymised by design — a generated pseudonym, a taste-overlap percentage, the axes where your palates agree, and at most one catalogue wine they rated highly. The pseudonym is a keyed hash that cannot be turned back into an account, and it differs for every viewer.
Every neighbour entry still carries Report and Block, because an anonymised handle can still be offensive. Blocking takes effect immediately and permanently on your device.
You can also report by email to support@icoffio.com. We aim to review reports within 24 hours.
17. Changes to this policy
If we change this policy in a way that materially affects you, we will tell you in the app or by email before the change takes effect, and we will update the date at the top of this page. Older versions are kept and can be requested.
18. Contact
Privacy and data protection, general support, and reports of abusive or unlawful content all reach the same inbox: support@icoffio.com.
Naming the topic in the subject line — privacy, support or report — gets your message to the right person faster.
WineDNA is run by one person in Poland, so there is no switchboard and no ticket queue between you and the controller — the message you send is the message he reads.