Cellar Dweller

Privacy Policy

Cellar Dweller is a small, personally-run wine cellar tracker. This page describes exactly what it stores, who else sees it, and how to get it back or remove it. It is a description of how the software behaves rather than a lawyer’s document.

What we collect

Only what the app needs to work. There is no analytics, no advertising and no tracking of any kind.

Your account

  • Your email address, and your first name and surname if you provide them.
  • How you sign in — a password, a link emailed to you, or a Google account. Passwords are stored hashed by our authentication provider and are never visible to us.
  • If you sign in with Google we receive your email address, name and profile picture URL from Google. We do not request access to anything else in your Google account.

Your collection

  • The wines you record against yourself: price paid, rating, whether it is a favourite, a website link, and any notes you write.
  • Your cellar: which bottles are in which storage slot, and your history of adding and drinking them.
  • Your storage locations, including any address you choose to enter.
  • A per-day count of update requests you send, used only to stop the feature being abused.

What we never collect

No payment details — the app does not take payments. No location data. No cookies beyond the one that keeps you signed in.

Shared catalogue vs. your own records

The app deliberately separates the two, and it affects your privacy directly.

The catalogue is shared. The objective facts about a bottle — producer, grape, vintage, region — are visible to every signed-in member. If you add or correct a wine or a winery, that contribution is visible to everyone, and your user account is recorded against it so changes can be attributed.

Your records are yours. What you paid, how you rated something, your notes, your cellar contents and your storage locations are visible only to you. This is enforced twice over: every query is scoped to your account, and the database itself carries row-level security policies that return nothing if that scoping is ever omitted.

Who else processes it

We use a small number of services to run the app. We do not sell or share your data with anyone else.

  • Supabase — authentication and the database where everything is stored.
  • Vercel — hosting and delivery of the site.
  • Resend — sending sign-in links, confirmations and password resets. Receives your email address.
  • Google — only if you choose to sign in with Google, and only for map embeds on region and winery pages.
  • OpenStreetMap — map tiles, and looking up the coordinates of a wine region or winery by name. Place names are sent; nothing about you is.
  • OpenAI — generating background write-ups about regions and producers. Only an administrator can trigger this, and only public place and producer names are sent. Your own wines, notes and cellar are never sent to OpenAI.

Where it is stored

The database is hosted in Sydney, Australia (AWS ap-southeast-2). Some of the services above operate globally, so email and page delivery may be processed elsewhere.

How long we keep it

Your account and collection are kept until you delete them. Delete your account and your records go immediately — see below. Rate-limit counters are disposable and hold nothing but a number.

Getting your data out, and deleting it

Both live on your Account Management page, and neither requires asking us:

  • Export downloads everything you own as a single JSON file — your wines with their catalogue details, your cellar, your history and your locations.
  • Delete your account removes your account and, with it, your wines, cellar, history, locations and rate-limit counters. It is immediate and cannot be undone.

One thing deletion does not remove: wines and wineries you contributed stay in the shared catalogue, because other members may hold those bottles and their own records reference them. Your name is detached from those contributions when you leave, so they remain but are no longer attributed to you.

Security

  • All traffic is encrypted in transit.
  • Your records are isolated per account in the application and again by database policy.
  • The app connects to the database with a restricted account that cannot alter the database structure or read the authentication tables.
  • Changing your password requires re-entering your current one.

No system is perfectly secure, and this one is run by an individual rather than a company with a security team. Please bear that in mind when deciding what to record.

Children

The app is about alcohol and is not intended for anyone under the legal drinking age in their country.

Changes

If this page changes materially, the date below changes with it. Continuing to use the app after a change means accepting it.

Contact

For anything about your data — including a request we have not automated — contact the administrator at teamdb.ai@outlook.com.

Last updated 27 July 2026.