Privacy Policy
How WineDNA collects, uses, shares and deletes your personal data — and how you take control of it.
1. Who is responsible for your data
The data controller for the personal data described in this policy is [TODO: legal entity], registered at [TODO: registered address], company registration number [TODO: company registration number] (referred to below as "WineDNA", "we" or "us").
Privacy questions and requests: [TODO: privacy contact email]. Our data protection contact is [TODO: DPO or privacy officer — state whether a DPO is formally appointed under GDPR Art. 37].
If and while the controller is established outside the European Union or the European Economic Area, our representative in the Union under Article 27 GDPR is [TODO: EU representative — name and address]. If the controller is established inside the EU/EEA, this section is not applicable and must be removed before publication.
2. The short version
The parts most people care about, in one place. The detail follows below and takes precedence over this summary.
- Your Taste DNA and your ratings are yours. We never sell identifiable taste history, and we do not share it with advertisers.
- Conversations with the AI sommelier are processed by Anthropic on our behalf. They are not used to train anybody's models, and you can delete them.
- Precise location is optional, off by default, and only used to find shops near you.
- You can export everything and delete everything, from inside the app or from this website.
- WineDNA is an 18+ service. We do not knowingly collect data from minors.
- Analytics are privacy-safe: no advertising identifiers, no cross-site tracking, no IDFA, no advertising cookies.
3. What data we collect
We collect only what the product actually needs. Where something is optional, it is marked as such.
- Account data — your email address, or the Apple relay address if you use Sign in with Apple, plus a WineDNA account identifier and your language and region settings.
- Age verification — we ask for your date of birth to confirm you are of legal drinking age. We store only the resulting yes/no flag; the date of birth itself is discarded immediately after the check.
- Ratings and tasting notes — the scores you give, the structured answers in guided rating, and any free-text notes you write.
- Photos — label photos you take for recognition, and any photos you attach to a rating.
- Taste DNA — the taste profile we derive from your ratings across six axes (body, tannin, acidity, sweetness, oak, fruit), plus confidence values.
- Cellar, wishlist and history — the wines you save, own or have looked at.
- AI conversations — the messages you send to the AI sommelier and the answers it returns, if you keep conversation history switched on.
- Precise location — optional and off by default. Used only to show wine shops and restaurants near you at the moment you ask.
- Subscription and purchase status — whether you have an active subscription. Payments are handled by Apple; we never see your card details.
- Technical data — device type, operating system version, app version, IP address, crash reports and security logs.
- Support correspondence — the messages you send us and our replies.
4. Why we use it, and on what legal basis
Under the GDPR we must name a legal basis for each purpose. Ours are as follows.
- Providing the service — running your account, recognising wines, computing Wine Match, keeping your cellar in sync across devices. Legal basis: performance of our contract with you (Art. 6(1)(b)).
- Personalisation — building and updating your Taste DNA from your ratings. Legal basis: performance of our contract, because personalisation is the product.
- AI sommelier — answering your questions with context from your profile. Legal basis: performance of our contract; your consent (Art. 6(1)(a)) where you switch on the "use my data" option that shares your Taste DNA with the assistant.
- Precise location — finding shops near you. Legal basis: your consent, which you can withdraw at any time in your device settings.
- Age verification — meeting our legal obligations around alcohol-related services. Legal basis: legal obligation (Art. 6(1)(c)) and our legitimate interest in not serving minors.
- Security, abuse prevention and moderation — keeping accounts and user-generated content safe. Legal basis: our legitimate interests (Art. 6(1)(f)).
- Product analytics — understanding which features work, in aggregate. Legal basis: our legitimate interests, using privacy-safe measurement only.
- Billing and tax records — legal basis: legal obligation.
5. How AI processing works
WineDNA uses Claude, a large language model provided by Anthropic, to explain wines, answer questions and generate recommendations. Anthropic acts as our processor under a data processing agreement.
What we send: the wine or wines in question, catalogue information, and — only if you have the "use my data" option switched on — a summary of your Taste DNA. We do not send your email address, your name, your payment details or your precise location to the model.
Your conversations are not used to train Anthropic's models or ours. This is contractually excluded.
You can switch conversation history off, delete individual conversations, or delete all AI data without deleting your account. Deleting your account deletes it too.
AI output is generated text and can be wrong. It is guidance, not professional advice, and it is never used to make a decision that produces a legal effect for you.
We do not carry out automated decision-making within the meaning of Article 22 GDPR. A Wine Match score is a recommendation you are free to ignore.
6. What we never do
Some commitments are easier to state as absolutes.
- We do not sell identifiable taste history — not your ratings, not your Taste DNA, not your cellar, to anyone, at any price.
- We do not share your data with advertising networks or data brokers, and we do not build advertising profiles.
- We do not use the Advertising Identifier (IDFA) and we do not ask for App Tracking Transparency permission, because we do not track you across other companies' apps and websites.
- We do not market to anyone under the legal drinking age.
- We do not make claims about health benefits of alcohol, and we do not process health data.
8. International transfers
Some of the providers above process data outside the European Economic Area, in particular in the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses, on an adequacy decision where one applies, and on additional technical measures such as encryption in transit and at rest.
[TODO: confirm the transfer mechanism relied on for each sub-processor and record it here before publication.]
You can request a copy of the relevant safeguards from [TODO: privacy contact email].
9. How long we keep things
We keep personal data only as long as it serves the purpose it was collected for. Our current schedule:
- Account data — for as long as your account exists, then deleted within 30 days of a confirmed deletion request.
- Ratings, Taste DNA, cellar and wishlist — for as long as your account exists, or until you delete the individual entries.
- AI conversations — 12 months on a rolling basis, or until you delete them, whichever comes first.
- Label photos used for recognition — 30 days after the recognition request, unless you attached the photo to a rating, in which case it lives with the rating.
- Age verification flag — for as long as your account exists. The underlying date of birth is never stored.
- Security and access logs — 90 days.
- Analytics — aggregated and no longer linked to an identifiable person after 14 months.
- Moderation records for reported content — 12 months after the report is closed, so that repeat abuse can be detected.
- Billing, invoicing and tax records — [TODO: statutory retention period for billing records — confirm the applicable accounting-law period for the controller's jurisdiction].
- Backups — encrypted backups roll off within 35 days, so deleted data can persist in a backup for that window before being overwritten.
10. Your rights
If the GDPR applies to you, you have the right to: access your data; correct it; delete it; restrict or object to processing; withdraw a consent you previously gave (without affecting what happened before you withdrew it); and receive your data in a portable, machine-readable format.
You also have the right to lodge a complaint with a supervisory authority — the one where you live, where you work, or where the alleged infringement took place. Our lead supervisory authority is [TODO: supervisory authority — e.g. the Polish UODO if the controller is established in Poland].
11. How to make a request (DSAR)
Send your request to [TODO: privacy contact email] from the email address on your account, or use the in-app export and delete tools, which handle the two most common requests automatically.
We will acknowledge your request and respond within one month of receiving it. If your request is complex, or if you have made several, we may extend that by up to two further months and will tell you why within the first month.
Requests are free. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse it, and we will explain our reasoning.
If we cannot identify you from the request we may ask for information that lets us verify you own the account. We will not ask for more identification than we need, and we will not use what you send for anything else.
Requests are handled by [TODO: named role responsible for DSARs, e.g. Data Protection Contact].
12. Export and deletion
You can export a machine-readable copy of your account data — ratings, Taste DNA, cellar, wishlist and AI conversations — from the app at any time.
You can delete your account from inside the app, or from this website. Deleting the account removes your ratings, Taste DNA, conversations, photos and saved wines. See the account deletion page for exactly what is removed, what is retained and why.
14. Age and children
WineDNA is an 18+ service and is rated accordingly on the App Store. Where the legal drinking age in your country is higher than 18, that higher age applies to you.
We verify age at sign-up by asking for a date of birth and storing only the resulting flag. We do not knowingly collect personal data from anyone below the legal drinking age. If you believe a minor has created an account, write to [TODO: privacy contact email] and we will delete it.
15. Security
Data is encrypted in transit (TLS) and at rest. Access to production data is restricted to the people who need it and is logged. Database and cache services are not reachable from the public internet. Session cookies are HttpOnly and Secure, and state-changing requests carry CSRF protection.
No system is perfect. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and, where the risk is high, notify you directly.
16. Reporting content and abuse
Reviews, tasting notes and photos written by other people are user-generated content. Every review can be reported and every author can be blocked from inside the app.
You can also report content by email to [TODO: abuse report email]. We aim to review reports within 24 hours.
17. Changes to this policy
If we change this policy in a way that materially affects you, we will tell you in the app or by email before the change takes effect, and we will update the date at the top of this page. Older versions are kept and can be requested.
18. Contact
Privacy and data protection: [TODO: privacy contact email]
General support: [TODO: support contact email]
Reporting abuse or unlawful content: [TODO: abuse report email]
Postal address: [TODO: legal entity], [TODO: registered address]