For Wine Cellar Manager & Tracker
Effective Date: October 2, 2026 · Last Updated: October 2, 2026
Wine Cellar Manager is published by an independent Apple platforms developer (referred to in this policy as "we", "our", or "us"). You can reach us by email at [email protected].
This Privacy Policy describes how the Wine Cellar Manager & Tracker application for iPhone, iPad and Mac, together with its widgets (the "App"), handles information.
Short version: your cellar, notes and photos are stored on your device and, if you turn on iCloud sync, in your own private iCloud database, which we cannot read. Label photos are processed on your device. On devices without Apple Intelligence, the text recognized on a label may be sent to our label service to fill in the fields; you can turn that off. The App has no accounts and contains no analytics or advertising.
We do not sell or share personal information, and we do not collect:
The only data that reaches a server we operate is described under Label Service below: recognized label text, a random device identifier used for a usage counter, and the App version.
Everything in the App is entered by you or read from labels you scan. This includes wines, producers, vintages, regions and grapes, bottles and their sizes, racks, fridges, cases and slots, purchase prices and values, drink windows, tasting notes with scores, food pairings, companions and tags, photos you attach, and the history of each bottle (drunk, gifted, sold).
This data is stored in a database inside the App's own container on your device, shared only with the App's widgets through an Apple App Group. It is not sent to us.
The App asks for camera access to read wine labels and barcodes. Photos are processed on your device with Apple's Vision framework. You can also pick a photo with Apple's system photo picker, which gives the App only the images you select and does not grant access to your photo library. Photos you attach to a bottle or note are stored with your cellar data and are never uploaded to us. You can change or revoke camera access at any time in the system Settings.
After a scan, the App turns the recognized text into fields such as producer, wine, vintage and region. How this happens depends on your device and your settings:
The label service runs on Cloudflare Workers. It forwards the label text and producer hints to Anthropic's Claude API to structure the fields and returns the result to the App. It does not store label text or results. The only thing it keeps is a monthly scan counter linked to the random identifier, so it can apply a fair-use quota; the counter expires automatically after about two months. The random identifier is not linked to your name, Apple Account, or device hardware, and is deleted when you uninstall the App. Cloudflare and Anthropic process the request on our behalf under their own terms and privacy policies, and as with any web request, Cloudflare receives your IP address as part of the connection.
iCloud sync is a Cellar Pro feature and is off unless you turn it on in the App's settings. When it is on, your App data, including attached photos, is stored in the private database of your own iCloud account using Apple's CloudKit, so it can appear on your other devices signed in to the same Apple Account. Apple may send silent push notifications to the App so it knows when data changed on another device.
Data in your private iCloud database belongs to your Apple Account. We, as the developer, cannot access, read, or export it. You can turn sync off at any time in the App, and manage or delete iCloud data in your device settings.
If you turn on drink-window reminders and allow notifications, the App schedules local notifications on your device when a bottle's window opens. They are never sent through a server. You can change or revoke notification permission at any time in the system Settings.
The App downloads a small configuration file through the same Cloudflare service. It contains non-personal settings such as the free-tier bottle limit, the length of the free trial and whether the label service is enabled. If the request fails, the App uses built-in defaults. Other network traffic is handled by Apple: App Store purchases through StoreKit and, if it is on, iCloud sync through CloudKit.
Cellar Pro subscriptions and the lifetime purchase are sold and managed by Apple through the App Store. Apple is the merchant of record. We do not see your payment details, Apple Account, billing address, or full name. The App receives from Apple only a confirmation of which purchase, if any, is active. Apple's own privacy policy applies to App Store purchases, subscription management, iCloud and CloudKit, Apple Intelligence, the camera and photo picker, notifications, Siri and Shortcuts, widgets, the share sheet, and other system services.
Used only when the label service is on and the on-device model is not available, as described above. They receive the recognized label text and producer hints, never photos or the rest of your cellar.
The catalogue of grapes, regions and appellations is derived from Wikidata (CC0) and bundled with the App. The App does not contact Wikidata.
The App does not include any third-party SDKs. There are no analytics, crash reporting, advertising, attribution, or tracking SDKs. The App sells no alcohol, has no marketplace and links to no store.
The App contains alcohol references and is rated 17+ on the App Store. It is intended for adults of legal drinking age in their country and is not directed at children. We do not knowingly collect personal information from anyone, including children.
Depending on where you live, you may have privacy rights under laws such as the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and similar laws. The only data our label service holds is an anonymous monthly counter linked to a random identifier, which expires on its own. Everything else stays under your control:
California residents: we do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA.
The App relies on security features built into iOS, iPadOS and macOS, including app sandboxing, data protection for files on your device, an App Group container shared only with the App's own widgets, Apple's protection of iCloud data, and Apple's StoreKit transaction verification. Requests to the label service use HTTPS. No method of electronic storage or transmission can be guaranteed to be perfectly secure.
We may update this Privacy Policy from time to time, for example to reflect new App functionality or legal requirements. When we do, we will update the "Last Updated" date at the top. The basic commitment that the App does not collect your personal data will not change without clear notice.
If you have any questions about this Privacy Policy or the way the App handles data, please write to [email protected].