Your data
Delete your account
The Delete account button on this site works. Sign in, open the account panel, and press it. It tells the shared deletion function which shelf it is calling from, that function has a My Wine Shelf branch, and the branch removes your wine records and nothing belonging to any other shelf app.
If you would rather ask a person, or you cannot get into the account you want gone, write to hello@mywineshelf.com from the address on the account. We will confirm once, then delete the account and everything held against it. We answer within 30 days, usually much sooner.
This page used to say the button was broken. It said the button returned an error and deleted nothing, and that email was the only route. That was true when it was written and stopped being true shortly afterwards. It promised to say so when the button worked, and this is that. The app is the half that is still missing: it is a working build in internal TestFlight, but it has no Delete account button on any screen, so there is nothing to press there. Use the button here, or email us. When the app gets one, this page will say so.
What gets deleted
- Your bottles. The wine, the vintage, how many, what you paid, where you kept it, the drinking window and your notes.
- Your tasting notes. Date, rating, flavours, food, occasion, where you were.
- Your shopping list.
- The barcodes you scanned and confirmed. These carry your account identifier, and they are yours alone rather than pooled into a shared table: each row is yours, nobody else can read it, and it goes with the rest.
- Your sign-in, unless another Shelf app still holds your data. See below.
There are no push notification records on that list, and an earlier version of this page put them there. It said deletion removed the device token used to send you a push and the notifications sent. Here is what we checked. The notifications library ships as a dependency of the app, but nothing in the app calls it: there is no notifications service file, no call that asks for notification permission and no call that obtains a token, and the one place a registration would belong is commented out and marked as unbuilt. The shared token table holds no rows for My Wine Shelf today. So there is nothing of that kind to delete. An earlier version of this page went further and said no such record could ever exist. That was a claim about what is possible rather than about what we found, and it is withdrawn. If a build ever registers for push, the privacy policy will say so first and these records will go back on the list.
There are no stored photographs on that list either, because there are none to delete: nothing in the app writes a photograph to a bottle or a tasting, and there is no file storage area for wine at all. An earlier version of this page listed them. The label scan is a separate thing and it is real: it photographs a label and sends the picture to Google to be read. We keep no copy, and section 5 of the privacy policy sets out the whole path.
The sign-in is shared
One login covers My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf, My Cigar Shelf, My Coffee Shelf and My Supply Shelf. The deletion checks the other shelf apps before it touches the login. If another app still holds something of yours, it deletes the wine records and leaves the login alone, because deleting it would destroy your account there. If nothing else holds anything, the login goes too.
Want the login gone anyway? Say so in an email. We will tell you what else is there before anything irreversible happens.
It works the other way as well. Deleting your account in another shelf app leaves your cellar here alone.
How long it takes
The deletion runs in one pass, not on a schedule. It happens while you wait, and you are signed out as soon as it finishes.
Deleted rows can sit in our database provider’s routine backups until those age out. We are not going to quote a number for that, because it depends on our provider’s schedule rather than on us. An earlier version of this page said encrypted backups were overwritten within 30 days. We had no basis for that figure and it should not have been written down.
What we keep
An earlier version of this page said “nothing that identifies you”. That was not true, and it is the kind of sentence that is easy to write and hard to stand behind. Seven things outlive the deletion.
- The email you sent us, if you asked by email, and our reply. We keep it on purpose, as the record that we acted on an erasure request, and it identifies you. That is the trade: the proof that we deleted your data is itself a record of you.
- Crash reports. The app sends crashes and errors to Sentry, on its German service, and the deletion does not touch Sentry. We never attach an account to a report, but the library keeps a trail of the network requests leading up to a fault and some of those carry your account identifier, so we will not claim a report holds nothing about you. Tell us roughly when a crash happened and we will look for it.
- Usage events, if you turned analytics on in the app. They sit with Mixpanel on its EU service, keyed to your account identifier, and the deletion does not touch Mixpanel. Ask and we will have them removed.
- Your subscriber record at RevenueCat. The app itself never contacts RevenueCat and has no paywall, but our own server asks it, with your account identifier, every time you run a label scan, so a record can exist there even though you cannot buy anything in this app. The deletion does not touch it. Ask and we will remove it.
- What Google holds from a label scan. The scan sends a photograph of a wine label to Google to be read. We keep no copy, but what Google keeps afterwards is governed by Google’s own terms for that API, and no deletion of ours reaches it.
- Shared records, but only if the login is kept because another shelf app still holds your data: your analytics choice, which is the one row My Wine Shelf, My Bar Shelf, My Whiskey Shelf, My Beer Shelf and My Cigar Shelf all read and write; and the AI scan ledger, which is one row per scan recording your account identifier, which Shelf app scanned, the kind of scan and the time. If the login goes, both go with it.
- Server request logs. Our host and our database provider keep these on their own schedules, tied to no account. We do not read them to reconstruct a reader.
Write to hello@mywineshelf.com and we will remove by hand whatever the button cannot reach. The privacy policy sets all of this out in full.
The wine catalogue is untouched: it says which wines exist. We checked the columns on those tables and none of them carries a column for a user.
What changed on this page
Updated 1 September 2026, alongside version 2.3 of the privacy policy. The previous version said there was no code in the app that could register for push and that no wine row could be created in the shared token table. Those are claims about what is possible; what we checked is what exists, and that paragraph now says so and no more. The sign-in section named three Shelf apps and trailed off with “the rest of the family”, and now names all seven. The shared records that survive a kept login are described as two different things with two different reaches, rather than as one shared set.
Nothing on this site is for sale and the app has no paywall, so we hold no purchase record of yours and neither does a store. That is not the same as no subscription provider being involved: our server asks RevenueCat about your account on every label scan, which is why RevenueCat is on the list above. An earlier version of this page said there was nothing anywhere to keep, which went further than the facts allowed.