← Back to the app
Draft, not yet approved

This text has not been legally reviewed yet; some details are still to be added.

This English version is a translation for your information. Only the German version is legally binding.

Privacy policy

Last updated: 2 October 2026

This policy explains which data Wine Circle processes, why, who else receives it, how long we keep it and what rights you have. It covers the app at app.winecircleapp.com (for a transition period also uncorkd.fly.dev), the iOS app and the waiting list. The app shows no advertising, contains no ad trackers and sets no cookies itself.

1. Controller

to be added
to be added
Email: to be added

Full details about the operator are in the legal notice.

2. What data we process and why

Account

For your account we store your email address, your display name, your password (only as a non-reversible check value), a profile picture if you add one, your app language, your founding number (if you came through the waiting list), how you signed up, when you created the account and last used it, and whether your email address is confirmed. We send you codes by email to sign in and confirm; they are valid for 10 minutes. Purpose: running your account and signing you in securely.

Wine Circle is for adults only. You answer the question “Are you 18 or older?” on your device; the answer stays there and is not sent to us.

Sign in with Google or Apple

The server is prepared for signing in with Google or Apple. If you use it, we verify the sign-in with Google or with Apple’s public keys and take over your email address, and with Apple on your first sign-in also your name if you share it.

Phone number (optional)

You can add your phone number in your profile so that friends who have you in their contacts can find you. We store the number; other members never see it. Matching uses check values (hashes) instead of the numbers themselves: numbers from other people’s address books only leave their device as check values, and we use these check values only for matching; they are not stored.

Cellar

Whatever you enter or import into your cellar (for example from Vivino, CellarTracker or a CSV file): wines, producers, vintage, bottle size, quantity, price paid, drinking window, notes and your wish list, plus the history of your cellar (bottles added and removed, value over time). Purpose: managing your cellar and calculating values and drinking readiness. By default your cellar is visible to nobody; in Privacy you can show it to your friends with “Cellar visible to friends”.

Posts, comments and cheers

When you uncork a bottle, a post is created: the wine, a photo and a caption if you add them, the time and – only if you agreed to the map – the place (see “Location”). Comments, reactions (“cheers”) and tags of other members come on top.

Who sees your posts:

So that we do not show you the same suggestions again and again, we remember for 90 days which suggestion cards you have seen.

Photos

We store post photos, your profile picture, wine photos and marketplace photos on our server. Every image is re-created on upload, which removes embedded metadata such as the location (GPS) and camera data. The originals are stored under a random address that cannot be guessed.

Wine photos for retouching

With “Suggest wine image” in a wine’s view you send us a photo of the bottle. The same applies to the photo sent with “Suggest a new wine” once we add the wine. We do not publish this photo. It is stored on our server without a public address, and only the team can download it. The team edits it with an AI image tool (background, light, perspective; the label stays as it is) and uploads the result. The app shows this finished image to everyone as the wine’s picture; you get a notification once it is live. For the process we store your account, the wine, the time and the processing status.

Your photo stays stored on our server until the team has processed it. If the team discards it, we delete the file there immediately; after retouching we delete it there after 30 days. Copies the team downloads for editing or uploads to the AI tool are deleted by the team after editing. The details of the process stay without the photo until you delete your account, and they are part of your data export. The finished image is the team’s work and stays as the wine’s picture, even if you delete your account.

Location (only with your consent)

We only store a location if you agreed to “Post on the map”. It is off by default. If you agreed, we record where you are when you uncork (coordinates and place name). Your bottles appear on your friends’ map for 7 days; the place stays with your post permanently and is visible to everyone who can see the post. Our server looks up the place name for the coordinates using OpenStreetMap’s Nominatim service; only the coordinates go there, not your name and not your IP address.

Without consent we store no location, not even in the background. The map may still use your location to centre on you; that happens only on your device. You can withdraw your consent in Privacy at any time.

Friends and invitations

We store your friendships, open requests, hidden suggestions and your invitation link, including who joined through which link and whether an account received the “KOG” badge that way. Purpose: mapping your circle, counting the invitation quota and awarding this badge: anyone who creates a new account through the link of one of the members it was originally given to carries it as well.

Messages and marketplace (beta)

There is no free chat. Messages only exist for a marketplace deal. The marketplace is a beta and not yet open to everyone. People who use it create listings with photos, description and price; for a purchase we store buyer, seller, amount, status, delivery address, tracking number, messages and ratings. Payment runs through Stripe (see “Recipients”). You enter your card details directly with Stripe; they never reach our server.

Notifications and push

In the app you receive notifications, for example when a friend opens a bottle; we keep the latest 100. We only send push messages if you allow them on your device. For that we store the push address your browser gives us and your push settings.

Reporting problems and feedback

In your profile settings you can “Report a problem” or “Give feedback”. We store your text, the type of message, your account, the view you came from, the app version and your device’s browser identifier, but no IP address. Only the team can read it, in the admin area; no email is sent. The messages stay until you delete your account and are included in your data export.

Label scanner

When you scan a label, the photo goes to our server (reduced to 640 pixels). We compare it with known labels and store the photo, the recognised wine and the text read, to improve recognition. The photo is only accessible internally and is deleted after 30 days unless it serves as a reference image; at the latest it goes with your account.

If AI recognition is switched on, our server also sends the photo to Anthropic so that an AI model can read brand, vintage and wine type from the label. Before that we re-create the image without metadata and without GPS.

Waiting list

When you join the waiting list we store your email address, your language, your founding number, which link or page you came from, and your IP address and browser identifier at the time of sign-up (protection against abuse). We write to you when it is your turn, and sometimes with news about the waiting list. Every one of these emails contains an unsubscribe link; it deletes your entry immediately.

Security and abuse protection

Usage analytics

We want to know which features are used. For this, our server reports to PostHog (EU cloud, Frankfurt) what happens in the app: app opened, signed up, bottle opened, cellar import started and finished, friendship requested and accepted, move to the new address, and from the app tab changes, search used (without the search term) and marketplace viewed. The identifier is your internal account ID, plus role and sign-up day. Individual events only carry numbers, yes/no values or fixed keywords (app or iOS shell, sign-up method, whether an import file was readable, number of imported entries, tab opened, whether a search filter was set). Email address, name, IP address and free text are not transmitted.

Measurement runs for all accounts that have not objected. You can object at any time: switch “Usage analytics” in Profile → Privacy. The objection takes effect immediately on all devices, is never limited, and we have the data measured so far deleted at PostHog.

Recording of app sessions (test group only)

For accounts created before 26 September 2026 (test group), we also record app sessions in the browser, never in the iOS app. For this the app loads a script from PostHog that transmits the screen content to PostHog. PostHog technically sees your device’s IP address; according to the project setting it is discarded.

The recordings show the content of the app, including that of other members: names, posts, captions, comments, photos and wines. Hidden are all inputs, email addresses, phone numbers, contact details and addresses in the marketplace, payment data, codes, passwords, notices (such as invitation links) and your QR code; the marketplace chat, the message list and the payment areas are not recorded at all.

If you are a member, your content may therefore appear in recordings of other test group members. Your objection and your account deletion only cover your own recordings; in other people’s recordings your content remains until the retention period of at most 30 days expires.

Error reports

If something crashes or a request fails on the server, server and app report the error to Sentry (EU region, Frankfurt): error message, code location, shortened address, browser and operating system, and at most your account ID. Before sending we redact email addresses, IP addresses, credentials, passwords, codes, inputs, search texts, location data and push addresses; Sentry additionally discards IP addresses according to the project setting. There is no session recording and no performance measurement. The Sentry script in the app stores nothing on your device.

The “Usage analytics” switch does not stop error reports. You can object by email (see Your rights).

Emails

We send you emails that belong to the app: codes to sign in and confirm, notices after a change of your email address, invitations and admission from the waiting list, and your data export on request. For each email we log recipient address, purpose, time and whether it was delivered, so that we can find delivery problems.

3. Recipients and processors

We do not sell your data. These service providers process data on our behalf or receive it because you use a feature:

No data about you goes to SerpAPI: when searching for bottle images, our server only sends the wine name. We serve fonts and program libraries from our own server; the app does not use Google Fonts. It loads exactly two programs from third-party servers: Stripe’s payment form when you pay in the marketplace, and Cloudflare’s bot check in the sign-up form. The waiting-list form on winecircleapp.com loads the same check once we have switched it over.

Within Wine Circle, other members see what you share with them (see above). The team sees accounts and content as far as needed for approvals, moderation, retouching wine photos and support.

4. Transfers outside the EU

Anthropic is based in the USA. PostHog, Sentry and other service providers process your data in the EU but belong to companies based in the USA or are based there themselves.

Cloudflare, Inc. is based in the USA. Our backup copies stay with Cloudflare in the EU (see above). Requests to the app and the bot check, however, are received by a data centre in Cloudflare’s worldwide network, which can also be outside the EU. In its data processing addendum, Cloudflare states that it complies with the EU-US Data Privacy Framework and agrees to the European Commission’s standard contractual clauses for transfers.

5. How long we keep data

When you delete your account

You delete your account yourself under Profile → Account & data → Delete account. Deletion happens immediately and cannot be undone. It is not possible while a marketplace deal with an open payment is running.

Deleted are your account, your profile, your posts including photos, your cheers, likes, reactions and tags on other people’s content, your comments without replies, your cellar, your friendships, notifications, push addresses, your phone number, your seen suggestions, your problem reports and feedback, your wine photos for retouching, and your files. At PostHog we have you deleted together with your events and recordings: immediately, again after 24 hours and after 7 days, so that anything another device still sent is also covered. Whatever arrives after that stays at most until the end of the periods above. Account deletion does not cover error reports at Sentry; the account ID stays there until the end of the retention period.

We keep some data without name, email address, place and free text under an internal substitute identifier: a comment someone else has replied to, as an empty line as long as a reply stands below it (the text is deleted), your preferences as a rough summary (for example shares of grape varieties), marketplace transactions without rating texts and message content, your listings hidden and without description and pick-up place, your marketplace saved listings, submitted price and catalogue suggestions, and for scanned labels the match to the wine and the image features computed from it, without the photo and without the text read from it. This is pseudonymisation, not anonymisation.

6. Storage on your device

Wine Circle itself sets no cookies. For the app to work, it stores the following in your browser’s storage (localStorage):

In addition, the app uses a service worker to store copies of the app page and of images (wine images, post and profile photos) so that it starts without a network. All these entries are necessary for the feature you use.

If you pay in the marketplace, Stripe’s payment form loads. What Stripe stores on your device in the process is determined by Stripe.

The sign-up form, and after the switch-over also the waiting-list form, loads Cloudflare’s bot check (Turnstile). We use it without its “pre-clearance” mode, which sets a cookie under our address. What the check program reads or stores on your device is determined by Cloudflare.

Only in the test group does PostHog’s recording script load. It stores nothing permanently. Measured, it accesses your device like this: in localStorage it writes the test values __mplssupport__ and test and deletes them again immediately; it reads __mplssupport__, __ph_opt_in_out_ (also with the project identifier appended), ph_debug and _postHogToolbarParams, and deletes ph_debug. In sessionStorage it reads one entry about an identity change and deletes one entry about session properties. It reads cookies but writes none. In the end nothing of this remains on the device.

7. Legal bases

8. Your rights

Requests by email to: to be added

9. Do you have to provide data?

For an account we need an email address, a display name and a password. Everything else is optional; without it you only miss the respective features. We make no automated decision that has legal effect on you. The suggestions and recommendations you see are calculated by the app from your circle and your preferences.

10. Changes

If the way we process data changes, we update this policy. The version with the date above applies.