Cellaire Privacy Policy
Last updated: June 11, 2026
Cellaire (“we”, “the app”) is a personal wine and spirits inventory tool. This policy describes what data the app handles and where it goes. Plain English, no dark patterns.
TL;DR
- No accounts. We don’t ask for your name, email, or any login.
- Your bottle collection lives on your device. It is stored in a local database on your phone and never uploaded to our servers.
- Photos you scan are sent to our server so that an AI service (Anthropic Claude) can read the label and return structured info. We don’t keep them.
- Chat messages are sent to our server and forwarded to Anthropic Claude along with a short summary of your collection.
- If you subscribe to Cellaire Plus, Apple processes the payment and shares the receipt with RevenueCat (our subscription-management provider) so we can verify your subscription status.
- No analytics, no tracking, no ads.
What data the app handles
1. Bottle inventory (stored on your device)
When you add a bottle, the app stores it in a local SQLite database inside the app’s private sandbox on your iPhone. This includes: bottle name, producer, vintage, category, region, ABV, your notes, estimated value, rarity score, the photo you took, and whether the bottle is in your collection or on your wishlist.
This data is never uploaded to our servers and is not backed up to iCloud unless you have iCloud Backup enabled for the device generally (in which case iOS handles it the same way it handles all app data).
If you delete the app, this data is deleted with it.
2. Photos you scan
When you take a photo of a bottle label, the app sends the image to our backend server (stockroom-production.up.railway.app), which forwards it to Anthropic’s Claude API for label recognition. The Claude model returns structured fields (name, producer, vintage, etc.) which the app then stores locally.
- We do not store the photo on our server. It is held only in memory long enough to forward it to Anthropic and return the result.
- Anthropic’s data handling is governed by Anthropic’s Privacy Policy and Commercial Terms. Per Anthropic’s policy, API inputs are not used to train their models.
3. Chat messages
When you use the Chat tab to ask questions, the app sends your typed message plus a short text summary of your collection and wishlist (bottle names, categories, vintages, rarity, estimated value) to our backend, which forwards it to Anthropic Claude. The streamed response is shown to you and not retained on our server.
- The summary does not include photos, your notes, or any free-text you have added.
- We do not store chat messages on our server.
4. Subscription receipts (only if you subscribe)
Cellaire Plus is a paid subscription sold through Apple’s In-App Purchase. If you subscribe:
- Apple processes the payment. We never see your credit card or any payment detail.
- Apple shares the subscription receipt with RevenueCat (revenuecat.com), our subscription-management provider. RevenueCat validates the receipt and tells our backend whether your subscription is active.
- RevenueCat receives: an anonymous identifier (the same device UUID described above) and the Apple-provided receipt (product, expiration date, renewal state). No personal data (name, email, etc.) is shared with RevenueCat.
- Our backend stores a minimal record: your device UUID, which product you bought, when it expires, and a monthly count of AI scans and chat messages (used to enforce the free-tier limit for non-subscribers).
5. What we do NOT collect
- No name, email, phone, or account information
- No location data
- No contacts, calendar, or other device data
- No analytics, crash reporting, or behavioral tracking
- No advertising identifiers
Permissions
- Camera — required so you can photograph bottle labels. You can revoke this in iOS Settings at any time.
Data retention and deletion
- On your device: data persists until you delete the bottle or uninstall the app.
- On our backend: photos and chat messages are not persisted — they pass through in memory only. We do persist a small per-device record of monthly AI usage counts (so the free-tier reset works) and your subscription state (if you subscribe). Both records are keyed by the anonymous device UUID and contain no personal information.
- At Anthropic: governed by their commercial API retention policy (currently 30 days for abuse monitoring, then deleted).
- At RevenueCat: governed by RevenueCat’s privacy policy. Subscription records persist for as long as needed to manage your subscription.
Children
Cellaire is not intended for use by anyone under 17. The App Store age rating reflects references to alcoholic beverages.
Changes
If this policy changes, the “Last updated” date at the top will change and a notice will appear in the app’s About screen.
Questions about this policy? Email clayms99@gmail.com.