Back

Privacy Policy

Last updated: 28 September 2026

1. Data Controller

Vinoary is operated by:
Rehland ApS
CVR: 46212606
Email: support@vinoary.com
Copenhagen, Denmark

2. What data do we collect?

We collect the following personal data when you use Vinoary:

  • Account information: Email, name (optional)
  • Wine data: Your cellar collection, ratings, notes, scan history
  • Technical data: IP address, browser type, device info (via hosting provider)
  • Images: Photos of wine labels you upload for scanning
  • Notification data: Push subscription and notification history
  • Purchase data: Purchase history, subscription status and app user ID (when purchasing a subscription)

2a. Android waiting list

If you sign up to be notified when the Android app is released, we store your email address and the language the page was in. It is not an account — no profile is created, and the list is not linked to any wine data.

  • Purpose: one message, when the Android app becomes available. We use it for nothing else.
  • Legal basis: your consent, given by signing up (GDPR art. 6(1)(a)).
  • Retention: the address is deleted once the Android app has been released and the message sent — or earlier, if you ask us to.
  • Deletion: write to support@vinoary.com and we will remove you from the list.

3. Purpose of data processing

We use your data to:

  • Create and manage your account
  • Store and display your wine collection
  • Recognise wines from images via AI (Anthropic Claude)
  • Enrich wine data with AI-generated estimates (price, drinking window)
  • Send service-related emails about your account (e.g. password reset, or when your trial ends and your access changes)
  • Improve our service
  • Analyse use of the service (product and business analytics) to improve and further develop Vinoary
  • Send marketing about Vinoary and related offers (only if you have given separate consent)

4. Legal basis

We process your data on the following grounds:

  • Contract: To deliver the service you signed up for, including processing purchases and subscriptions
  • Consent: For AI analysis of your wine images, email notifications and marketing
  • Legitimate interest: To improve and further develop the service (including product and business analytics on pseudonymised or aggregated data) and to prevent misuse

5. Data processors

We share data with the following third parties who process data on our behalf:

  • Supabase (USA): Database and authentication
  • Anthropic (USA): AI image recognition and enrichment of wine data (drinking window, tasting profile)
  • Perplexity (USA): AI search for wine data enrichment
  • Resend (USA): Transactional emails (password reset, notifications)
  • Sentry (USA): Error tracking and performance monitoring
  • Vercel (USA): Hosting, server infrastructure and anonymised usage statistics
  • RevenueCat Inc. (USA): In-app purchase management and subscription verification

All data processors comply with the EU-US Data Privacy Framework or use EU-approved Standard Contractual Clauses (SCC) as the transfer mechanism.

6. Sharing you enable yourself

You can choose to share your wine cellar, or a single event from your wine journal, via a link. Sharing is off by default. If you turn it on, anyone with the link can see the shared information without signing in:

  • A shared cellar shows: cellar name, producer, wine, vintage, wine type, country, region, appellation, grape varieties, your label photo, our AI description, drinking window, maturity phase, price estimate and number of bottles
  • A shared journal event shows: the event title and date, plus producer, wine, vintage, wine type, country, region, your label photo and maturity phase
  • NEVER shared: your own notes, your purchase and sale prices, your email address and your user ID

Note that the price estimate and bottle count are included in a shared cellar, so its total value can be inferred by anyone holding the link. The link cannot be searched for and appears in no public listing, but the recipient can pass it on. You can turn sharing off again in the app, after which the link stops working. Be aware that the SAME link becomes active again if you later re-enable sharing — to make a link permanently unusable, contact us.

7. Retention

We retain your data for as long as your account is active. Upon account deletion:

  • Account data is deleted within 30 days
  • Wine data and scan history are permanently deleted
  • Backups are deleted within 90 days

8. Your rights

You have the following rights under GDPR:

  • Access: View your data
  • Rectification: Correct inaccurate data
  • Erasure: Have your data deleted ("right to be forgotten")
  • Data portability: Export your data (CSV export available)
  • Objection: Object to certain types of data processing
  • Withdrawal: Withdraw your consent

Contact us at support@vinoary.com to exercise your rights.

9. Account deletion

You can delete your account and all associated data via Settings in the app. Deletion is permanent and cannot be undone.

If you cannot sign in, or you want to see exactly what is deleted and what is kept anonymised, it is set out at /delete-account.

10. Cookies and analytics

Vinoary only uses technically necessary cookies for authentication and session management. The website does not use tracking or marketing cookies. Ad measurement in the app happens only with your consent and is described in section 10a.

We collect two forms of usage statistics: (1) anonymised, cookieless statistics via Vercel Analytics with no personal data, and (2) product analytics of your in-app interactions (e.g. viewing subscription screens) that are linked to your account and used to improve and further develop the service. The latter is not shared with third parties for their own marketing.

10a. Ad measurement in the app (only with consent)

We advertise Vinoary on Facebook and Instagram. If you say yes in the app, it sends information to Meta Platforms Ireland Ltd. so we can see which ads lead to new users. If you say no or do not answer, nothing is sent — Meta’s software is not started at all.

  • What is sent: that the app was installed and opened (and, when a subscription is bought, that a purchase took place), a random identifier generated by Meta’s software, and technical details about the device: app version, operating system version (iOS or Android), language and region, time zone, screen size and mobile carrier. Meta also receives your IP address when the connection is made.
  • What is not sent: your wine collection, notes, photos, email address or name. We do not show Apple’s tracking prompt (App Tracking Transparency), so Meta does not receive your advertising identifier (IDFA). The Android app does not read your Android advertising ID either.
  • Legal basis: your consent (GDPR Article 6(1)(a) and the Danish Cookie Order, section 3).
  • Responsibility: we are joint controllers with Meta for the collection and transfer. Meta’s further use of the information is as an independent controller under Meta’s own privacy policy (facebook.com/privacy/policy). Meta may transfer information to the USA under the EU-US Data Privacy Framework.
  • Withdrawal: you can withdraw your consent at any time under Settings → Ads in the app. From the next app start, nothing is sent.

11. Security

We protect your data with:

  • Encrypted connection (HTTPS/TLS)
  • Encrypted database
  • Access control and authentication
  • Regular security updates

12. Changes

We may update this privacy policy. For material changes, we will inform you by email. The latest version is always available on this page.

13. Children and age requirement

Vinoary is not intended for children under 18. We do not knowingly collect data from individuals under 18. If we discover that a user is under 18, we will delete the account and associated data.

14. Complaints

If you believe we are not handling your data correctly, you may file a complaint with the Danish Data Protection Agency: www.datatilsynet.dk

15. Contact

Questions about the privacy policy can be directed to:
Email: support@vinoary.com