Direct product policy. This Privacy Policy applies only to Vintrove (com.cellarsomm.swift). It directly states the app’s data practices and is not an owner-site redirect or a portfolio-wide substitute.
Scope, controller, and contact
UNCOMMON WEATHER LLC, 1212 N Walker Ave Apt 207, Oklahoma City, OK 73103, United States, is responsible for the information described here. Contact team@uncommonweather.com for privacy questions, rights requests, or support.
Information Vintrove handles
- Account identifiers and authentication data, including email address where provided, Sign in with Apple identifiers, and Supabase user ID
- Profile name, handle, optional biography, manually entered city, avatar, friendship state, and sharing choices
- Cellar inventory, bottle and storage records, values, drinking windows, journal and palate records, dinners, wish lists, vows, and preferences
- Label, bottle, profile, and menu images, barcode data, imported CSV content, exports, and user-entered text
- Explicitly selected AI request content, responses, the off-by-default provider-level allowsOpenAIProcessing permission, category-specific AI consent settings, and linked operational records including endpoint, payload field names, image technical properties, model, timestamps, provider response identifiers and statuses, token counts, and quota and cost records
- Cellar Circle reviews, friend relationships, and the cellar fields deliberately published to approved friends
- Notification, widget, Live Activity, device-cache, and synchronization state
- App Store purchase and entitlement metadata linked to an anonymous or signed-in app user identifier, plus one-way receipt-family allowance and hashed alias records
- Privacy-minimal legal-choice evidence and request-audit metadata, including request identifier, route, response status, and time
- Operational network and security metadata, such as IP address or IP-derived coarse region, user agent, route, response status, and timing, where retained by a provider
Product-specific practices
Guest use, accounts, local cache, and cloud cellar
Vintrove can be used as a guest with a local SQLite cache. A user can optionally sign in with Apple or supported Supabase email authentication for private cloud recovery, synchronization, Cellar Circle, and authenticated AI features. Supabase processes the authentication identifier, email address where provided, access and refresh tokens, and account user ID. Session tokens are protected in the iOS Keychain.
For a signed-in user, Vintrove synchronizes user-owned cellar inventory, bottle and storage records, values and drinking windows, journal and palate records, dinners, wish lists, vows, preferences, and other cloud-snapshot fields to Supabase. Row-level security is designed to restrict private account rows to their owner, but no networked service can promise perfect security or uninterrupted recovery.
Profile, Cellar Circle, and sharing
A signed-in user who separately creates a Cellar Circle profile can provide a display name, unique handle, optional biography, manually entered city, and avatar. Vintrove does not use Core Location to obtain that city. Member profile fields are readable by signed-in Vintrove members. Profile avatars are stored in a public Supabase Storage bucket and can be viewed by anyone who has the object URL, so an avatar should not contain sensitive information. Creating an account alone does not create this social profile.
Creating an account does not automatically publish the private cellar. Profile information, reviews, and selected cellar fields become visible only through the sharing controls shown in the app. A shared cellar intentionally excludes private notes and price fields. Users must not publish unlawful content or content that violates another person’s rights.
Camera, photos, labels, menus, and imports
With permission or a user-selected photo, Vintrove can capture or import label, bottle, barcode, menu, and profile images. Bottle-label image files are stored on the device and deliberately omitted from the cloud cellar snapshot. A profile avatar deliberately uploaded for Cellar Circle is stored in the public Supabase Storage location described above. CSV imports and exports contain the cellar fields selected by the import or export flow.
Label and menu images leave the device for an OpenAI scan only after the provider-level OpenAI permission and the corresponding image category are both enabled and the user invokes that feature. Copies deliberately saved, exported, uploaded as an avatar, or shared remain wherever the user or selected service stores them.
Optional and bounded AI processing
Remote generative AI is unavailable on Free and Cellar. For Pro, the provider-level allowsOpenAIProcessing permission is off by default and must be affirmatively enabled before any Vintrove endpoint sends selected typed conversation or import text, an image, or an enabled cellar or journal category through Vintrove’s service to OpenAI. Separate switches for label images, menu images, cellar metadata, and journal-derived palate information also remain off by default. The master permission does not override those switches: a request that uses one of those categories requires both the master permission and its applicable category switch. When the required permissions are enabled, an authenticated request may include only the user-selected text or image and the enabled cellar fields, meal description, or journal-derived information needed for the requested label scan, pairing, import, sommelier, readiness, shop, or palate feature.
The master OpenAI permission and each category switch can be withdrawn in Settings. Withdrawing allowsOpenAIProcessing stops all future remote OpenAI processing; withdrawing a category stops future transmission of that category. Withdrawal does not erase information already processed or records that remain under the retention boundaries stated below, and it does not disable available on-device features.
The app sends an authorized request through authenticated Supabase Edge Functions, which enforce membership, request, cost, and calendar-month limits before forwarding it to OpenAI. At launch Pro includes up to 50 quick requests and 8 combined deep-analysis or vision requests per calendar month, subject to the current purchase disclosure. OpenAI credentials are not embedded in the app, requests are made with provider storage disabled where supported, and Uncommon Weather does not opt API content into model training. Provider security and abuse-monitoring retention may still apply under the provider’s terms. AI output may be incomplete or inaccurate.
Speech, notifications, widgets, and Live Activities
Apple speech recognition converts an optional dictated meal into text. If the user submits that text to a Pro sommelier feature while the master OpenAI permission and the relevant category switch are enabled, the transcript is included in the AI request. Vintrove does not store microphone audio as a product recording.
Vintrove uses local notifications, an App Group widget, a Live Activity, and background refresh for account features such as friend-request checks. It does not use advertising push notifications or a third-party analytics SDK. System surfaces may display selected cellar information according to the user’s device settings.
Purchases, membership enforcement, and legal choices
Apple processes App Store purchases and payment credentials. RevenueCat receives an anonymous app-user identifier and, after sign-in, the Supabase user identifier, plus limited app, device, transaction, purchase, subscription, and entitlement metadata needed to present offerings, restore purchases, and determine Cellar or Pro access. RevenueCat does not receive private cellar content merely to verify an entitlement.
For Pro, user-linked Supabase operational records can retain the invoked endpoint and usage class; payload field names; image MIME type and dimensions; model; reservation creation, provider-start, and expiration times; provider response identifier, response status, and HTTP status; input, cached-input, and output token counts; and reserved, estimated, or charged cost. Those operational fields do not retain the full prompt, generated response prose, image bytes, or private cellar content. They remain linked while the account is active and are deleted with the account. A separate one-way receipt-family allowance ledger and hashed RevenueCat alias mapping can remain after account deletion; they contain a hashed membership or alias key, environment, usage class, reservation and provider state, timestamps, and bounded cost amounts, but no user UUID, email, prompt, response, image, or cellar content. They are retained as needed to enforce recurring allowances, reconcile purchase lifecycle and transfers, prevent deletion and recreation from resetting limits, and address fraud, security, and legal claims.
The separate Uncommon Weather legal-choice service receives signed, privacy-minimal evidence of an acceptance, decline, or withdrawal, including product and document identifiers, versions and hashes, the choice, adult age band and acceptor role, pseudonymous installation and request identifiers, app version and build, timestamps, locale, source and sequence, security proof, and receipt linkage. Its immutable request-audit ledger also records a request identifier, route, response status code, and creation time under the service’s security and legal-claims schedule. The service does not receive the user’s Vintrove email, Supabase account ID, wine records, images, journal, or AI request content.
Retention and deletion
Private account and product records remain while the account is active or as needed to provide a requested feature. Settings includes an account-deletion action backed by a server function that removes the user’s stored profile avatar from the public avatar bucket, removes the Supabase auth user, and cascades deletion through user-owned account rows. Local cached records and Keychain sessions are cleared by the app’s sign-out or deletion flow as implemented. Exported files, deliberately shared records, and content another person legitimately received may remain outside the account.
Account deletion does not erase Apple or RevenueCat transaction records, provider security records, or the separate privacy-minimal legal ledger where retention is required for integrity, security, legal claims, or compliance. To prevent duplicate allowances, reconcile purchase transfers and refunds, and deter abuse, Supabase intentionally retains an opaque one-way receipt-family usage ledger and hashed RevenueCat alias mapping after account deletion. Those records contain no user UUID, email address, prompt, response, image, or cellar content and cannot restore deleted account data. Those systems follow their own stated retention boundaries.
Service providers and disclosures
Apple provides iOS, App Store billing, and the Apple frameworks identified above. RevenueCat provides subscription-entitlement infrastructure. Supabase provides the separate legal-choice service and, where the product-specific sections say so, account, storage, synchronization, or server-function infrastructure. Cloudflare delivers and protects the public website. Other named providers process only the information needed for the selected function.
Ordinary connection metadata, such as IP address or IP-derived coarse region, user agent, request identifier, route, response status, and execution timing, is processed by network, security, hosting, and server-function providers to deliver and protect a request. Some of it may be retained under provider security and operational schedules. The separate legal-choice service immutably retains request identifier, route, response status code, and creation time in its request-audit ledger under the security and legal-claims schedule stated below. Information may also be disclosed when required by valid legal process, to protect rights or safety, to investigate abuse or security incidents, or in a business transaction with legally required safeguards.
Where a service provider processes Vintrove information on Uncommon Weather’s behalf, Uncommon Weather requires protections consistent with this policy and applicable law through the provider agreement or applicable service terms. Services acting independently, including Apple for App Store transactions, also apply their own privacy terms and legal duties.
Uncommon Weather does not sell personal information, share it for cross-context behavioral advertising, serve third-party ads, or track users across unrelated products.
Retention and deletion
Product data follows the product-specific retention and deletion boundaries above. Copies deliberately exported, uploaded, or shared remain wherever the user, recipient, or selected service saved them. Support correspondence is retained while needed to handle the request and for reasonable operational, security, and legal purposes. Apple, RevenueCat, Supabase, OpenAI where applicable, and other independent providers retain records under their own policies and legal duties.
Legal-choice events and acceptance receipts are append-only evidence retained until the verified relationship ends plus seven years. Related challenge, key-registration, request-audit, signing-key incident, receipt-integrity, and retention-purge records follow their security and legal-claims schedules. Immutable legal evidence may be retained where needed to establish, exercise, or defend legal claims.
Security
The legal-choice system uses HTTPS, P-256 signatures, keyed pseudonyms, replay-resistant single-use challenges, strict product allowlists, rate limits, restricted service credentials, append-only evidence, and signed receipts. Apple security frameworks and the product-specific controls above protect other data where stated. No system is perfectly secure.
Choices and privacy rights
Users can decline, later withdraw to limited mode, review the current documents, or affirmatively accept from Legal & Privacy settings. Available product controls can manage permissions, delete or export product data, manage or restore purchases, and delete an account where applicable. Depending on location, rights may include access, correction, deletion, restriction, objection, appeal, withdrawal, or a regulator complaint.
A current affirmative acceptance takes effect after it is durably saved on the device. Main-app access remains available while signed-receipt delivery retries after a non-terminal network, Apple, or service outage. Widgets, Live Activities, and other extension surfaces that require a verifiable cross-process receipt may wait until the server-signed receipt is received and verified. An explicit terminal rejection of the exact saved acceptance causes the client to quarantine that failed record and return to the appropriate decision or limited-state screen.
Children and eligibility
Vintrove is intended only for adults age 18 or older. The legal flow records only a broad adult age band and acceptor role, not a birth date.
Changes and related documents
Material changes receive a new immutable document version. Previously accepted users are asked to make one new choice for a materially changed family; continued use alone does not silently create acceptance. A stored decline or withdrawal remains limited without a recurring prompt. Read the Vintrove Terms of Service and Vintrove Product Schedule.
UNCOMMON WEATHER LLC
1212 N Walker Ave Apt 207
Oklahoma City, OK 73103
United States
team@uncommonweather.com