This text has not been legally reviewed yet; some details are still to be added.
This English version is a translation for your information. Only the German version is legally binding.
Privacy policy
Last updated: 2 October 2026
This policy explains which data Wine Circle processes, why, who else receives it, how long we keep it and what rights you have. It covers the app at app.winecircleapp.com (for a transition period also uncorkd.fly.dev), the iOS app and the waiting list. The app shows no advertising, contains no ad trackers and sets no cookies itself.
1. Controller
to be added
to be added
Email: to be added
Full details about the operator are in the legal notice.
2. What data we process and why
Account
For your account we store your email address, your display name, your password (only as a non-reversible check value), a profile picture if you add one, your app language, your founding number (if you came through the waiting list), how you signed up, when you created the account and last used it, and whether your email address is confirmed. We send you codes by email to sign in and confirm; they are valid for 10 minutes. Purpose: running your account and signing you in securely.
Wine Circle is for adults only. You answer the question “Are you 18 or older?” on your device; the answer stays there and is not sent to us.
Sign in with Google or Apple
The server is prepared for signing in with Google or Apple. If you use it, we verify the sign-in with Google or with Apple’s public keys and take over your email address, and with Apple on your first sign-in also your name if you share it.
Phone number (optional)
You can add your phone number in your profile so that friends who have you in their contacts can find you. We store the number; other members never see it. Matching uses check values (hashes) instead of the numbers themselves: numbers from other people’s address books only leave their device as check values, and we use these check values only for matching; they are not stored.
Cellar
Whatever you enter or import into your cellar (for example from Vivino, CellarTracker or a CSV file): wines, producers, vintage, bottle size, quantity, price paid, drinking window, notes and your wish list, plus the history of your cellar (bottles added and removed, value over time). Purpose: managing your cellar and calculating values and drinking readiness. By default your cellar is visible to nobody; in Privacy you can show it to your friends with “Cellar visible to friends”.
Posts, comments and cheers
When you uncork a bottle, a post is created: the wine, a photo and a caption if you add them, the time and – only if you agreed to the map – the place (see “Location”). Comments, reactions (“cheers”) and tags of other members come on top.
Who sees your posts:
- your friends, except posts you open privately;
- members with whom you share at least one friend, as a labelled suggestion in the feed. You can turn this off in Privacy with “Appear in others' suggestions”;
- all signed-in members if you set your profile to “public”. The default is “friends only”.
So that we do not show you the same suggestions again and again, we remember for 90 days which suggestion cards you have seen.
Photos
We store post photos, your profile picture, wine photos and marketplace photos on our server. Every image is re-created on upload, which removes embedded metadata such as the location (GPS) and camera data. The originals are stored under a random address that cannot be guessed.
Wine photos for retouching
With “Suggest wine image” in a wine’s view you send us a photo of the bottle. The same applies to the photo sent with “Suggest a new wine” once we add the wine. We do not publish this photo. It is stored on our server without a public address, and only the team can download it. The team edits it with an AI image tool (background, light, perspective; the label stays as it is) and uploads the result. The app shows this finished image to everyone as the wine’s picture; you get a notification once it is live. For the process we store your account, the wine, the time and the processing status.
Your photo stays stored on our server until the team has processed it. If the team discards it, we delete the file there immediately; after retouching we delete it there after 30 days. Copies the team downloads for editing or uploads to the AI tool are deleted by the team after editing. The details of the process stay without the photo until you delete your account, and they are part of your data export. The finished image is the team’s work and stays as the wine’s picture, even if you delete your account.
Location (only with your consent)
We only store a location if you agreed to “Post on the map”. It is off by default. If you agreed, we record where you are when you uncork (coordinates and place name). Your bottles appear on your friends’ map for 7 days; the place stays with your post permanently and is visible to everyone who can see the post. Our server looks up the place name for the coordinates using OpenStreetMap’s Nominatim service; only the coordinates go there, not your name and not your IP address.
Without consent we store no location, not even in the background. The map may still use your location to centre on you; that happens only on your device. You can withdraw your consent in Privacy at any time.
Friends and invitations
We store your friendships, open requests, hidden suggestions and your invitation link, including who joined through which link and whether an account received the “KOG” badge that way. Purpose: mapping your circle, counting the invitation quota and awarding this badge: anyone who creates a new account through the link of one of the members it was originally given to carries it as well.
Messages and marketplace (beta)
There is no free chat. Messages only exist for a marketplace deal. The marketplace is a beta and not yet open to everyone. People who use it create listings with photos, description and price; for a purchase we store buyer, seller, amount, status, delivery address, tracking number, messages and ratings. Payment runs through Stripe (see “Recipients”). You enter your card details directly with Stripe; they never reach our server.
Notifications and push
In the app you receive notifications, for example when a friend opens a bottle; we keep the latest 100. We only send push messages if you allow them on your device. For that we store the push address your browser gives us and your push settings.
Reporting problems and feedback
In your profile settings you can “Report a problem” or “Give feedback”. We store your text, the type of message, your account, the view you came from, the app version and your device’s browser identifier, but no IP address. Only the team can read it, in the admin area; no email is sent. The messages stay until you delete your account and are included in your data export.
Label scanner
When you scan a label, the photo goes to our server (reduced to 640 pixels). We compare it with known labels and store the photo, the recognised wine and the text read, to improve recognition. The photo is only accessible internally and is deleted after 30 days unless it serves as a reference image; at the latest it goes with your account.
If AI recognition is switched on, our server also sends the photo to Anthropic so that an AI model can read brand, vintage and wine type from the label. Before that we re-create the image without metadata and without GPS.
Waiting list
When you join the waiting list we store your email address, your language, your founding number, which link or page you came from, and your IP address and browser identifier at the time of sign-up (protection against abuse). We write to you when it is your turn, and sometimes with news about the waiting list. Every one of these emails contains an unsubscribe link; it deletes your entry immediately.
Security and abuse protection
- To slow down attacks on sign-in, sign-up and other functions, we count attempts per IP address or per account within a time window. Entries outside the window are removed at the next check.
- After you sign in, your device gets a device token (valid for 180 days) so that failed attempts from other devices do not lock your account.
- Our server keeps a technical log of requests: time, address requested and result. Access codes in addresses are masked first.
- We protect sign-up in the app against automated sign-ups with Turnstile, Cloudflare’s bot check; the waiting-list form on winecircleapp.com gets the same check once we have switched it over. When you open a form with the check, your browser loads a check program from challenges.cloudflare.com. According to Cloudflare it evaluates technical signals: your IP address, the TLS fingerprint of your connection, your browser identifier and the page the check runs on. According to Cloudflare, it does not read what you type into the form. If you pass, Cloudflare gives your browser a check token that works once. When you submit, our server has Cloudflare confirm it and sends your IP address along. If the check does not load, for example in the iOS app or with a content blocker, we accept a limited number of sign-ups per hour without it. The legal basis is our legitimate interest in protecting accounts, founding numbers and our email sending against automated sign-ups (Art. 6(1)(f) GDPR). We use Turnstile only against bots; it sets no advertising cookies (see “Storage on your device”). According to its own statement, Cloudflare also uses the signals to improve its bot detection and is responsible for that itself.
Usage analytics
We want to know which features are used. For this, our server reports to PostHog (EU cloud, Frankfurt) what happens in the app: app opened, signed up, bottle opened, cellar import started and finished, friendship requested and accepted, move to the new address, and from the app tab changes, search used (without the search term) and marketplace viewed. The identifier is your internal account ID, plus role and sign-up day. Individual events only carry numbers, yes/no values or fixed keywords (app or iOS shell, sign-up method, whether an import file was readable, number of imported entries, tab opened, whether a search filter was set). Email address, name, IP address and free text are not transmitted.
Measurement runs for all accounts that have not objected. You can object at any time: switch “Usage analytics” in Profile → Privacy. The objection takes effect immediately on all devices, is never limited, and we have the data measured so far deleted at PostHog.
Recording of app sessions (test group only)
For accounts created before 26 September 2026 (test group), we also record app sessions in the browser, never in the iOS app. For this the app loads a script from PostHog that transmits the screen content to PostHog. PostHog technically sees your device’s IP address; according to the project setting it is discarded.
The recordings show the content of the app, including that of other members: names, posts, captions, comments, photos and wines. Hidden are all inputs, email addresses, phone numbers, contact details and addresses in the marketplace, payment data, codes, passwords, notices (such as invitation links) and your QR code; the marketplace chat, the message list and the payment areas are not recorded at all.
If you are a member, your content may therefore appear in recordings of other test group members. Your objection and your account deletion only cover your own recordings; in other people’s recordings your content remains until the retention period of at most 30 days expires.
Error reports
If something crashes or a request fails on the server, server and app report the error to Sentry (EU region, Frankfurt): error message, code location, shortened address, browser and operating system, and at most your account ID. Before sending we redact email addresses, IP addresses, credentials, passwords, codes, inputs, search texts, location data and push addresses; Sentry additionally discards IP addresses according to the project setting. There is no session recording and no performance measurement. The Sentry script in the app stores nothing on your device.
The “Usage analytics” switch does not stop error reports. You can object by email (see Your rights).
Emails
We send you emails that belong to the app: codes to sign in and confirm, notices after a change of your email address, invitations and admission from the waiting list, and your data export on request. For each email we log recipient address, purpose, time and whether it was delivered, so that we can find delivery problems.
3. Recipients and processors
We do not sell your data. These service providers process data on our behalf or receive it because you use a feature:
- Fly.io – hosting of server, database and photos, data centre in Frankfurt am Main.
- PostHog – usage measurement and, in the test group only, recording of app sessions; EU cloud, Frankfurt.
- Sentry (Functional Software, Inc.) – error reports; EU region, Frankfurt.
- Resend – sending the app’s emails.
- Zoho – mailboxes at @winecircleapp.com when you write to us.
- Cloudflare – name resolution (DNS) for winecircleapp.com. Since 28 September 2026 every request to app.winecircleapp.com also passes through Cloudflare’s network (proxy). Cloudflare receives the request, sees your IP address and the request data (address called, time, browser identifier) and passes them on to our server. To do so, Cloudflare decrypts the connection and encrypts it again for the way to our server, so it also sees the content transmitted. Purpose: delivering the app and fending off attacks before they reach our server. In addition there is the Turnstile bot check for sign-up and the waiting list (see “Security and abuse protection”). For the proxy and the check, Cloudflare acts as our processor. Cloudflare also keeps copies of our database backups in its R2 storage service, in data centres in the EU (EU jurisdiction). We encrypt every copy before it leaves our server; Cloudflare does not have the key to decrypt it. We delete the copies there after at most 30 days (see “How long we keep data”).
- Hetzner Online – our test machine in Germany. Once a month we restore a backup there as a trial, to check that it can be recovered, and delete it again straight afterwards.
- Anthropic – AI recognition for the label scan (photo without metadata), USA.
- AI image tool for retouching wine photos – receives the photo you send with “Suggest wine image” or with a wine suggestion (without metadata) when the team edits it.
- OpenFreeMap – map tiles. Your browser loads them directly from tiles.openfreemap.org; OpenFreeMap sees your IP address and the map area you are looking at.
- OpenStreetMap Foundation (Nominatim) – place name for the coordinates of a post, only with map consent; only coordinates are sent, and our server makes the request.
- Push services of Apple, Google or Mozilla, depending on your browser – only if you allow push. The content of the message is encrypted; the service only sees the push address, time and size.
- Google or Apple – only if you sign in with Google or Apple (see above).
- Stripe – payments and payouts in the marketplace (beta). You enter card and account details directly with Stripe; the payment form loads from js.stripe.com for this.
- Vercel – runs the website winecircleapp.com and forwards links shared there to the app.
No data about you goes to SerpAPI: when searching for bottle images, our server only sends the wine name. We serve fonts and program libraries from our own server; the app does not use Google Fonts. It loads exactly two programs from third-party servers: Stripe’s payment form when you pay in the marketplace, and Cloudflare’s bot check in the sign-up form. The waiting-list form on winecircleapp.com loads the same check once we have switched it over.
Within Wine Circle, other members see what you share with them (see above). The team sees accounts and content as far as needed for approvals, moderation, retouching wine photos and support.
4. Transfers outside the EU
Anthropic is based in the USA. PostHog, Sentry and other service providers process your data in the EU but belong to companies based in the USA or are based there themselves.
Cloudflare, Inc. is based in the USA. Our backup copies stay with Cloudflare in the EU (see above). Requests to the app and the bot check, however, are received by a data centre in Cloudflare’s worldwide network, which can also be outside the EU. In its data processing addendum, Cloudflare states that it complies with the EU-US Data Privacy Framework and agrees to the European Commission’s standard contractual clauses for transfers.
5. How long we keep data
- Account and content: until you delete your account.
- Unconfirmed sign-ups without posts and cellar: after 7 days.
- Email codes: valid for 10 minutes. Sign-in: up to 30 days, then you sign in again. Device token: 180 days.
- Seen suggestions: 90 days. Notifications: the latest 100.
- Label photos: 30 days, unless used as a reference image.
- Wine photos for retouching: until the team has processed them; deleted immediately if discarded, 30 days after retouching.
- Waiting list: until you unsubscribe.
- Email delivery log: until your account is deleted.
- PostHog: events at most 365 days, recordings at most 30 days.
- Backups: we back up the database at least once a day and keep the latest 7 backups on our server. Once the copy at Cloudflare R2 is set up, we back up every hour and also store every backup there in the EU, encrypted; we delete it there after at most 30 days. In addition the host takes a storage snapshot every day and keeps it for 30 days. Deleted data therefore remains in older backups until they expire, at most 30 days.
When you delete your account
You delete your account yourself under Profile → Account & data → Delete account. Deletion happens immediately and cannot be undone. It is not possible while a marketplace deal with an open payment is running.
Deleted are your account, your profile, your posts including photos, your cheers, likes, reactions and tags on other people’s content, your comments without replies, your cellar, your friendships, notifications, push addresses, your phone number, your seen suggestions, your problem reports and feedback, your wine photos for retouching, and your files. At PostHog we have you deleted together with your events and recordings: immediately, again after 24 hours and after 7 days, so that anything another device still sent is also covered. Whatever arrives after that stays at most until the end of the periods above. Account deletion does not cover error reports at Sentry; the account ID stays there until the end of the retention period.
We keep some data without name, email address, place and free text under an internal substitute identifier: a comment someone else has replied to, as an empty line as long as a reply stands below it (the text is deleted), your preferences as a rough summary (for example shares of grape varieties), marketplace transactions without rating texts and message content, your listings hidden and without description and pick-up place, your marketplace saved listings, submitted price and catalogue suggestions, and for scanned labels the match to the wine and the image features computed from it, without the photo and without the text read from it. This is pseudonymisation, not anonymisation.
6. Storage on your device
Wine Circle itself sets no cookies. For the app to work, it stores the following in your browser’s storage (localStorage):
- your sign-in (session key) and your device token;
- the state of your app so that it starts quickly and can be read offline: cellar, feed, wish list and settings, but your last location only with map consent;
- your language, your age confirmation, whether you allowed push and whether we have already asked;
- your last three search terms and a cache of the feed;
- an invitation or waiting-list link until you sign up, an open friend request until you sign in, and the new address after a move;
- the app’s language packs.
In addition, the app uses a service worker to store copies of the app page and of images (wine images, post and profile photos) so that it starts without a network. All these entries are necessary for the feature you use.
If you pay in the marketplace, Stripe’s payment form loads. What Stripe stores on your device in the process is determined by Stripe.
The sign-up form, and after the switch-over also the waiting-list form, loads Cloudflare’s bot check (Turnstile). We use it without its “pre-clearance” mode, which sets a cookie under our address. What the check program reads or stores on your device is determined by Cloudflare.
Only in the test group does PostHog’s recording script load. It stores nothing permanently. Measured, it accesses your device like this: in localStorage it writes the test values __mplssupport__ and test and deletes them again immediately; it reads __mplssupport__, __ph_opt_in_out_ (also with the project identifier appended), ph_debug and _postHogToolbarParams, and deletes ph_debug. In sessionStorage it reads one entry about an identity change and deletes one entry about session properties. It reads cookies but writes none. In the end nothing of this remains on the device.
7. Legal bases
- Contract (Art. 6(1)(b) GDPR): account, cellar, posts, friends, notifications, sending push messages, marketplace, the app’s emails, label scanner, wine photos for retouching, problem reports and feedback.
- Legitimate interest (Art. 6(1)(f) GDPR): security and abuse protection (including the Turnstile bot check), delivery through Cloudflare’s proxy, server logs, backups, error reports, seen suggestions, map tiles and usage measurement. Usage measurement runs without a consent prompt; you can object to it at any time.
- Consent (Art. 6(1)(a) GDPR): location on the map, push messages, the optional phone number and the recording of app sessions in the test group. You can withdraw consent at any time with effect for the future.
- Legal obligations (Art. 6(1)(c) GDPR), for example retention duties for marketplace payments.
8. Your rights
- Access and data portability: under Profile → Account & data → Export my data you receive your data as a machine-readable file (JSON) by email. The export also names PostHog as a recipient and what goes there. It does not contain error reports at Sentry; ask us by email for those.
- Rectification: you change name, email address, phone number, profile picture and cellar yourself in the app, everything else on request.
- Erasure: Profile → Account & data → Delete account (see above).
- Objection (Art. 21 GDPR): to usage measurement with the “Usage analytics” switch in Profile → Privacy, to everything else by email.
- Withdrawal of consent: location with “Post on the map” in Privacy, push in Privacy or in your device settings, the phone number in your profile, recording in the test group with the “Usage analytics” switch.
- Restriction of processing: by email.
- Complaint to a supervisory authority; in Austria the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.
Requests by email to: to be added
9. Do you have to provide data?
For an account we need an email address, a display name and a password. Everything else is optional; without it you only miss the respective features. We make no automated decision that has legal effect on you. The suggestions and recommendations you see are calculated by the app from your circle and your preferences.
10. Changes
If the way we process data changes, we update this policy. The version with the date above applies.