Product-specific document. This schedule applies only to Vintrove (com.cellarsomm.swift). It supplements the separate Vintrove Terms of Service and Privacy Policy, each with its own immutable version and SHA-256 hash.
Product purpose
Vintrove is an adult wine-cellar inventory, journal, storage, serving, sharing, and optional AI-assistance app with an offline device cache and optional account-backed cloud cellar.
Adults and responsible use
Vintrove is intended only for adults age 18 or older who have also reached the legal drinking age in their location. It is an inventory, education, storage, pairing, and serving-planning app. It must not be used to encourage unsafe or unlawful alcohol consumption, purchase by a minor, drinking and driving, or any other violation of law.
AI, wine, value, and safety boundaries
AI output, label extraction, wine identity, estimated values, drinking windows, pairings, readiness, storage guidance, allergy-related text, and recommendations are estimates for informational use. They may be wrong, incomplete, delayed, or based on incomplete cellar data. Users must confirm important label, ingredient, allergy, value, storage, purchase, and consumption information independently.
Vintrove does not provide medical, legal, financial, intoxication, driving, or other safety-critical advice. A wine value is not an appraisal or an offer to buy or sell. The app does not sell or deliver alcohol.
Accounts and user content
The user is responsible for account credentials, accurate profile information, cellar and journal content, images, reviews, and anything shared through Cellar Circle. The user keeps ownership of that content and grants Uncommon Weather and its providers the limited permission needed to store, synchronize, process, generate requested output from, and display it for the selected features.
Users may not upload unlawful, infringing, abusive, deceptive, or privacy-invasive content; scrape other members; bypass account, membership, request, or cost limits; or interfere with the service. Shared content may be removed and access may be restricted when reasonably necessary to enforce these terms, protect another person, or comply with law.
Availability, synchronization, and recovery
Network sync, AI providers, account services, community features, and third-party wine data can be unavailable or change. Vintrove does not promise uninterrupted service, recovery of data that was never successfully synchronized, or permanent availability of a provider. Users should export or independently record irreplaceable cellar information.
Free, Cellar, and Pro
Free supports up to 10 bottles and no remote generative AI. Cellar is an auto-renewable membership that removes the bottle limit and includes the complete non-generative-AI feature set shown in the app. Pro adds up to 50 quick AI requests and 8 combined deep-analysis or vision requests per calendar month. Limits reset on the schedule shown in the product and do not create a cash balance. Apple handles payment, cancellation, refunds, and subscription management; RevenueCat supplies entitlement state to the app. A downgrade does not silently delete existing records, but creating additional records or using paid features can remain unavailable until the applicable limit or membership is restored.
Limited mode
After a decline or withdrawal, limited mode preserves access needed to read local cellar, journal, and dinner records; export available data; delete the account or local records; sign out; review legal and support information; and manage or restore an Apple purchase. Remote writes and synchronization, AI processing and uploads, Cellar Circle and social actions, new purchases, and feature notifications or widgets may remain unavailable until the current product documents are affirmatively accepted. A durably saved local acceptance unlocks the main app while signed-receipt delivery retries; a non-terminal network or service outage does not return the main app to limited mode. Widgets, Live Activities, and other extension surfaces that require a verifiable cross-process receipt may wait until the server-signed receipt is received and verified.
Current product data boundary
The following categories and operational boundaries are specific to Vintrove and form part of this schedule.
- Account identifiers and authentication data, including email address where provided, Sign in with Apple identifiers, and Supabase user ID
- Profile name, handle, optional biography, manually entered city, avatar, friendship state, and sharing choices
- Cellar inventory, bottle and storage records, values, drinking windows, journal and palate records, dinners, wish lists, vows, and preferences
- Label, bottle, profile, and menu images, barcode data, imported CSV content, exports, and user-entered text
- Explicitly selected AI request content, responses, the off-by-default provider-level allowsOpenAIProcessing permission, category-specific AI consent settings, and linked operational records including endpoint, payload field names, image technical properties, model, timestamps, provider response identifiers and statuses, token counts, and quota and cost records
- Cellar Circle reviews, friend relationships, and the cellar fields deliberately published to approved friends
- Notification, widget, Live Activity, device-cache, and synchronization state
- App Store purchase and entitlement metadata linked to an anonymous or signed-in app user identifier, plus one-way receipt-family allowance and hashed alias records
- Privacy-minimal legal-choice evidence and request-audit metadata, including request identifier, route, response status, and time
- Operational network and security metadata, such as IP address or IP-derived coarse region, user agent, route, response status, and timing, where retained by a provider
Guest use, accounts, local cache, and cloud cellar
Vintrove can be used as a guest with a local SQLite cache. A user can optionally sign in with Apple or supported Supabase email authentication for private cloud recovery, synchronization, Cellar Circle, and authenticated AI features. Supabase processes the authentication identifier, email address where provided, access and refresh tokens, and account user ID. Session tokens are protected in the iOS Keychain.
For a signed-in user, Vintrove synchronizes user-owned cellar inventory, bottle and storage records, values and drinking windows, journal and palate records, dinners, wish lists, vows, preferences, and other cloud-snapshot fields to Supabase. Row-level security is designed to restrict private account rows to their owner, but no networked service can promise perfect security or uninterrupted recovery.
Profile, Cellar Circle, and sharing
A signed-in user who separately creates a Cellar Circle profile can provide a display name, unique handle, optional biography, manually entered city, and avatar. Vintrove does not use Core Location to obtain that city. Member profile fields are readable by signed-in Vintrove members. Profile avatars are stored in a public Supabase Storage bucket and can be viewed by anyone who has the object URL, so an avatar should not contain sensitive information. Creating an account alone does not create this social profile.
Creating an account does not automatically publish the private cellar. Profile information, reviews, and selected cellar fields become visible only through the sharing controls shown in the app. A shared cellar intentionally excludes private notes and price fields. Users must not publish unlawful content or content that violates another person’s rights.
Camera, photos, labels, menus, and imports
With permission or a user-selected photo, Vintrove can capture or import label, bottle, barcode, menu, and profile images. Bottle-label image files are stored on the device and deliberately omitted from the cloud cellar snapshot. A profile avatar deliberately uploaded for Cellar Circle is stored in the public Supabase Storage location described above. CSV imports and exports contain the cellar fields selected by the import or export flow.
Label and menu images leave the device for an OpenAI scan only after the provider-level OpenAI permission and the corresponding image category are both enabled and the user invokes that feature. Copies deliberately saved, exported, uploaded as an avatar, or shared remain wherever the user or selected service stores them.
Optional and bounded AI processing
Remote generative AI is unavailable on Free and Cellar. For Pro, the provider-level allowsOpenAIProcessing permission is off by default and must be affirmatively enabled before any Vintrove endpoint sends selected typed conversation or import text, an image, or an enabled cellar or journal category through Vintrove’s service to OpenAI. Separate switches for label images, menu images, cellar metadata, and journal-derived palate information also remain off by default. The master permission does not override those switches: a request that uses one of those categories requires both the master permission and its applicable category switch. When the required permissions are enabled, an authenticated request may include only the user-selected text or image and the enabled cellar fields, meal description, or journal-derived information needed for the requested label scan, pairing, import, sommelier, readiness, shop, or palate feature.
The master OpenAI permission and each category switch can be withdrawn in Settings. Withdrawing allowsOpenAIProcessing stops all future remote OpenAI processing; withdrawing a category stops future transmission of that category. Withdrawal does not erase information already processed or records that remain under the retention boundaries stated below, and it does not disable available on-device features.
The app sends an authorized request through authenticated Supabase Edge Functions, which enforce membership, request, cost, and calendar-month limits before forwarding it to OpenAI. At launch Pro includes up to 50 quick requests and 8 combined deep-analysis or vision requests per calendar month, subject to the current purchase disclosure. OpenAI credentials are not embedded in the app, requests are made with provider storage disabled where supported, and Uncommon Weather does not opt API content into model training. Provider security and abuse-monitoring retention may still apply under the provider’s terms. AI output may be incomplete or inaccurate.
Speech, notifications, widgets, and Live Activities
Apple speech recognition converts an optional dictated meal into text. If the user submits that text to a Pro sommelier feature while the master OpenAI permission and the relevant category switch are enabled, the transcript is included in the AI request. Vintrove does not store microphone audio as a product recording.
Vintrove uses local notifications, an App Group widget, a Live Activity, and background refresh for account features such as friend-request checks. It does not use advertising push notifications or a third-party analytics SDK. System surfaces may display selected cellar information according to the user’s device settings.
Purchases, membership enforcement, and legal choices
Apple processes App Store purchases and payment credentials. RevenueCat receives an anonymous app-user identifier and, after sign-in, the Supabase user identifier, plus limited app, device, transaction, purchase, subscription, and entitlement metadata needed to present offerings, restore purchases, and determine Cellar or Pro access. RevenueCat does not receive private cellar content merely to verify an entitlement.
For Pro, user-linked Supabase operational records can retain the invoked endpoint and usage class; payload field names; image MIME type and dimensions; model; reservation creation, provider-start, and expiration times; provider response identifier, response status, and HTTP status; input, cached-input, and output token counts; and reserved, estimated, or charged cost. Those operational fields do not retain the full prompt, generated response prose, image bytes, or private cellar content. They remain linked while the account is active and are deleted with the account. A separate one-way receipt-family allowance ledger and hashed RevenueCat alias mapping can remain after account deletion; they contain a hashed membership or alias key, environment, usage class, reservation and provider state, timestamps, and bounded cost amounts, but no user UUID, email, prompt, response, image, or cellar content. They are retained as needed to enforce recurring allowances, reconcile purchase lifecycle and transfers, prevent deletion and recreation from resetting limits, and address fraud, security, and legal claims.
The separate Uncommon Weather legal-choice service receives signed, privacy-minimal evidence of an acceptance, decline, or withdrawal, including product and document identifiers, versions and hashes, the choice, adult age band and acceptor role, pseudonymous installation and request identifiers, app version and build, timestamps, locale, source and sequence, security proof, and receipt linkage. Its immutable request-audit ledger also records a request identifier, route, response status code, and creation time under the service’s security and legal-claims schedule. The service does not receive the user’s Vintrove email, Supabase account ID, wine records, images, journal, or AI request content.
Retention and deletion
Private account and product records remain while the account is active or as needed to provide a requested feature. Settings includes an account-deletion action backed by a server function that removes the user’s stored profile avatar from the public avatar bucket, removes the Supabase auth user, and cascades deletion through user-owned account rows. Local cached records and Keychain sessions are cleared by the app’s sign-out or deletion flow as implemented. Exported files, deliberately shared records, and content another person legitimately received may remain outside the account.
Account deletion does not erase Apple or RevenueCat transaction records, provider security records, or the separate privacy-minimal legal ledger where retention is required for integrity, security, legal claims, or compliance. To prevent duplicate allowances, reconcile purchase transfers and refunds, and deter abuse, Supabase intentionally retains an opaque one-way receipt-family usage ledger and hashed RevenueCat alias mapping after account deletion. Those records contain no user UUID, email address, prompt, response, image, or cellar content and cannot restore deleted account data. Those systems follow their own stated retention boundaries.
Legal choices and verification
A decline or withdrawal takes effect locally at once and remains limited without a recurring prompt. A user can review the current documents and affirmatively accept from Legal & Privacy settings. A current affirmative acceptance takes effect after it is durably saved on the device and unlocks main-app access while signed-receipt delivery retries in the background. A non-terminal network, Apple, or service outage does not lock the main app or create another prompt. Widgets, Live Activities, and other extension surfaces that require a verifiable cross-process receipt may wait until the server-signed receipt is received and verified. If the server explicitly rejects the exact saved acceptance as terminal, the client quarantines that failed record and returns to the appropriate decision or limited-state screen. A current choice is not repeatedly requested.
Related documents
Vintrove Terms of Service · Vintrove Privacy Policy · Legal Center