Legal
Privacy Policy
Short version. The catalogue pages are built on our servers and sent to you finished, so reading them makes no request from your browser to our database. The search box is the exception: it runs in your browser, so what you type there travels to our database in the EU. No page sets a cookie and no analytics script runs. One kind of file does load from someone else's server: the bottle photographs, which come straight from the Swedish retail catalogue. Earlier versions of this page said the catalogue had no pictures, and section 11 records the correction. Signing in is optional and gets you one page, your cellar, which reads what the app holds against your account: your bottles and your tasting notes. It reads and never writes. Nothing here is for sale by us. Some pages carry links to wine accessories on Amazon.se, marked Ad: a purchase through one pays us a commission, the price you pay does not change, and no link leads to wine. We do not sell your data. You can delete all of it with the button in the account panel, which works; version 2.0 of this policy said it returned an error, and it does not. The app is a separate surface, and one thing it does sends more away from your phone than anything on this site does: the label scan photographs a wine label and sends the picture to Google. Section 5 sets it out. Version 2.1 of this policy said the app took no photographs and that its two outside services were the whole set. Both statements were false.
1. Who we are
My Wine Shelf is a product of Nisshagen Advisory AB (Org.nr 559526-6742), a company registered in Stockholm, Sweden. We are the data controller for personal data collected through the mywineshelf.com website.
Contact hello@mywineshelf.com for any privacy question, including data subject requests under the GDPR.
This policy covers the website, including the cellar page you reach by signing in.
About the app. The My Wine Shelf app is in internal TestFlight, which means invited testers, and it is not on any public store. Calling it “still being built” undersells it: it has sign-in, a cellar, a tasting log, an AI label scan and an analytics switch that is off until you turn it on. What it does not have is a Delete account button. Section 8 says what that means and what to use instead. It will carry its own policy for what happens on your phone before it reaches a store, and this page will point to it. The four outside services it uses are named in section 5 anyway, because they outlive a deletion and you should learn about them here rather than later.
2. Reading the site
The pages themselves
The front page, the region pages and the four style pages are assembled on our servers and sent to your browser as finished HTML, then held for up to 24 hours before they are rebuilt. Reading them involves no request from your browser to our database, no form and no sign-up. There is nothing on those pages to fill in.
No page on this site sets a cookie. There is no analytics: no page-view counter, no session recording, no product analytics and no tracking pixel belonging to us or to anyone else. Vercel Web Analytics is not switched on for this project, and the script it would inject is not in any page we serve. Our host keeps the request logs any web server keeps, and section 6 covers those.
The search box, which works differently
Find a wine is an interactive page, and it searches from your browser rather than from our servers. Type two characters or more, stop for a third of a second, and your browser sends what you typed to our database and asks for up to 40 matching rows. That happens whether or not you are signed in. Every request to any server reveals the IP address it came from, and this one is no different.
We keep no search history. There is no table on this site's side that records what anyone looked for, and we searched this site's code for anything that would write one and found nothing. Our database provider keeps its own API request logs on its own schedule, the same way our web host keeps request logs, and neither is read to build a picture of a reader.
We describe the search box separately because it is the one part of reading this site that talks to our database, and you can see it in your own network log. Saying the catalogue is server-rendered and stopping there would leave it out.
No pictures, and no typefaces from anyone else
Nothing on this site loads a file from another company's server. The catalogue table has no image column, so there are no bottle photographs to fetch, and no page here contains an image tag at all. The two typefaces are served from this domain rather than from a font CDN, and this policy and the terms use the fonts already on your device. Your browser contacts our host, and our database when you search or sign in. That is the whole list.
3. Signing in, and your cellar
Your account
Most of the site needs no account. One page, your cellar, does, and there is a Sign in button in the navigation on every page. Sign-in runs on Supabase, our database and authentication provider, hosted in the EU. What we hold depends on how you sign in:
- Email and password: your email address, and a password we never see in readable form. It is hashed by Supabase.
- A magic link: your email address. We send you a link, and following it signs you in.
- Sign in with Google: your email address and the account identifier Google returns. We do not receive your Google password, your contacts or anything else in your Google account.
- Sign in with Apple: the account identifier Apple returns, and the email address you choose to share. If you use Apple's Hide My Email, we only ever see the relay address, never your real one.
If you type a name when you create the account, we store it and use it to greet you in the account panel. Nothing else about you is asked for.
One login across the shelf apps
The account is the ShelfHub account, and it is one login across My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf, My Cigar Shelf, My Coffee Shelf and My Supply Shelf. Signing in here signs you in with the same credentials you use there. The login is shared. The shelves are not: your cellar is not visible to those apps, and what you keep in them is not visible here. This matters most when you delete something, so section 8 sets it out in full.
Where your session is kept
Nothing on this site sets a cookie. When you sign in, one entry goes into your browser's local storage, named sb-tlqlbnhaqpqgaxfihdlj-auth-token after our database project, holding the token that keeps you signed in. Signing out removes it. If you sign in with Google or Apple, the token comes back in the address bar and is moved into that same entry.
While that entry exists, your browser checks in with Supabase on every page to keep the token fresh. A signed-in reader's browser therefore talks to our database on pages where a signed-out reader's browser does not.
That entry is the only thing this site stores on your device, and it is there because you asked to be signed in. Storage that is strictly necessary for something you requested does not require consent under the ePrivacy rules, which is why you are not looking at a cookie banner. If we ever add storage that is not necessary, you will be given a real choice about it and this policy will say so first.
What the cellar page shows
It reads two tables, user_wines and tastings, and shows:
- Your bottles: which wine from the catalogue it is or the name you typed yourself, the vintage, how many you have, whether one is open, where you keep it, and when the record was made. The producer, region and country beside each one come from the public catalogue.
- Your last 20 tastings: the wine, the date you drank it, a rating out of five, and your note.
Those two tables carry more columns than this page displays, and the app is what fills them: the bottle size, the purchase date, what you paid and in what currency, where you bought it, a drinking window, and for a tasting the flavour notes, the food you had with it, the occasion and where you were. Whatever is sitting in those columns is covered by the deletion in section 8, whether this page shows it or not. Both tables also carry an unused column for a photograph. Nothing fills it: we checked every use of that column in the app and all of them read, none writes, and there is no file storage area for wine for a file to land in. So no photograph of yours is stored against a bottle or a tasting. That is not the same as saying the app takes no photographs. It has a label scan, the picture it takes leaves your device, and section 5 sets out where it goes. Version 2.1 of this policy said there were no photographs at all, which was false.
Read as a run, those records are a dated list of what someone owns, what they paid for it and when they opened it. We would rather say what it amounts to than file it under “your data”. It is private to your account: the database restricts every row in those tables to the account that created it, and that restriction lives in the database rather than in this website's code, so it holds no matter what this page asks for.
This page reads and does not write
Nothing you do on this website changes your cellar. Adding a bottle, logging a tasting and editing anything happen in the app. There is not one write to wine data anywhere in this site's code. The only things this site can change are the account itself: creating it, resetting the password, and the deletion described in section 8.
What this site does not do
Every line below is about this website. Some of them do not hold for the app, and where that is so the line says which section covers the app instead.
- No ad networks, no advertising identifiers, no advertising scripts. The links marked Ad in the last point of this list are the one piece of advertising here, and they are ordinary links.
- No analytics, no page-view counting, no session recording, no third-party trackers.
- No location. No page here asks your browser for a position, and we found no geolocation call anywhere in this site’s code. The app does not ask for it either: we searched the app for every way a position can be read and found none, and the location library is not among the app’s dependencies at all.
- No camera and no photographs of yours on this website, and no contacts or calendar anywhere. The app does use the camera, for the label scan, and section 5 says where the picture goes.
- No selling, renting or sharing of personal data with data brokers, ever.
- No purchases. There is no subscription, no in-app purchase and no paywall on this site, and the app has no paywall either. That is not the same as no subscription provider being involved, and section 5 explains the difference.
- No shop of ours, and no wine for sale anywhere. Nothing on this site is sold by us and no page shows a price. Some pages link to wine accessories on Amazon.se: glasses and tools, never wine. The links carry our Amazon Associates code and are marked Ad. If you buy something through one, Amazon pays us a commission. The price you pay does not change. No page here loads anything from Amazon, and your browser never contacts Amazon unless you click one.
If any of that changes, we will update this policy before the change goes live rather than after, and analytics in particular would stay switched off until you consent to it.
4. Legal basis for processing
Version 2.2 of this policy gave a basis for the website and none for the app, while section 5 described the app's processing in full. That left the largest things this policy describes with no lawful basis attached to them. Both are covered here.
- Performance of a contract, Article 6(1)(b): creating and holding your account; reading your cellar back to you on this site; and, in the app, storing your bottles, your tastings, your shopping list and the barcodes you scanned and confirmed, running a label scan or a barcode lookup when you ask for one, and honouring a subscription bought on the same account. Without this there is no service to provide.
- Consent, Article 6(1)(a): the app's usage analytics, and nothing else. Off until you switch it on yourself in the app, withdrawable in the same place at any time, and withdrawal does not affect what was processed before. Nothing on this website relies on consent: there is no marketing list, no newsletter and no non-essential storage. Version 2.2 said consent was relied on for nothing at all, which was true of the site and not of the app.
- Legitimate interests, Article 6(1)(f): keeping the site working and secure, and serving the public catalogue to the people searching it; crash and error reporting from the app, so that we find out when it is broken; and the AI scan ledger and the subscription check that goes with it, so that the free allowance in section 5 can be counted and not circumvented. The interest in that last one is plain: a scan costs us money on every call, and without a count that holds across a re-registered account there is no free tier to offer. Against that, the ledger row carries the app, the kind of scan and the time, and nothing you wrote or photographed.
Giving us this data is not a statutory requirement. It is what the app needs in order to be a cellar: without an account there is nowhere to put a bottle. There is no automated decision-making that produces legal or similarly significant effects and no profiling. A label reading is a machine guess that fills a form, and you review and edit every field before anything is saved.
5. Third parties we use
- Supabase – the database and the sign-in system, holding the catalogue, your account and your cellar records. Hosted in the EU. The sign-in emails (confirmation, password reset, magic link) are sent through it, and the search box queries it directly from your browser.
- Vercel – hosting for this website. No analytics product is switched on for this project, so Vercel sees the server-side request logs any host sees and nothing beyond them.
- Google and Apple – only if you choose to sign in with one of them, and only for that sign-in. Choosing one sends your browser to them. Not choosing one means your browser never contacts them.
- Amazon – only if you click a link marked Ad. Those links go to Amazon.se and carry our Amazon Associates code, which is how a purchase pays us a commission. Clicking one sends your browser to Amazon; not clicking one means your browser never contacts it. Amazon reports to us what was bought through the links, never who bought it.
That is the entire list for this website, and one more company is involved without working for us: the bottle photographs load straight from the Swedish retail catalogue's image server, so opening a photographed page sends that server the request any image fetch sends, from your IP address like any request. No script of theirs runs here. Beyond that there is no font CDN, no error-reporting service and no tag manager on any page.
The wine catalogue comes from the LWIN database published by Liv-ex Ltd, under a Creative Commons Attribution 4.0 licence. We hold a copy of it, so Liv-ex receives nothing from your browser and learns nothing about who reads this site. The credit at the foot of every page is a term of that licence rather than a link we chose to add. Section 5 of the Terms of Service covers what the licence means for you.
We do not sell your data to any third party. Supabase and Vercel are the two companies we contract with to run this site, and neither uses your data for advertising. If we ever add a provider that would, we will update this policy before the arrangement starts.
Google and Apple are not working for us, so we will not make a promise on their behalf. What their servers do with a request they receive is governed by their own policies. What we control is how little we hand them, and section 3 says exactly what that is.
Four more that belong to the app
None of these is contacted by this website. They are named here because the app hands them things this site never touches, and because the deletion in section 8 does not reach them, so they outlive it however you ask. Version 2.1 of this policy listed two and said there was no third. There are four.
- Sentry – crash and error reports from the app, on Sentry’s German service. We switch off the sending of personal data and we never attach an account to a report. The honest limit is that the library keeps a trail of the network requests leading up to a fault, and some of our database requests carry your account identifier in the address, so a report can contain it. We are not going to claim a crash report holds nothing about you.
- Mixpanel – usage events from the app, on Mixpanel’s EU service, and only if you turned analytics on yourself in the app. It is off until you do, and while it is off the library is never started at all. The events are keyed to your account identifier rather than your name or your email, which makes them pseudonymous rather than anonymous. Your answer is one row on your account, and five apps read and write that row: My Wine Shelf, My Bar Shelf, My Whiskey Shelf, My Beer Shelf and My Cigar Shelf. So it is the same answer in all five. It is not the answer in My Coffee Shelf, which keeps a separate one in its own table and asks you again there. My Supply Shelf sends no analytics at all.
- Google – the Gemini API, which reads the photograph the label scan takes. This is the largest thing the app sends anywhere, and it has its own subsection below.
- RevenueCat – in the United States. The app itself never contacts it, but our own server does, with your account identifier, every time you run a label scan. The subsection after next explains why, and why it is not the same as the app having a subscription.
Sentry and Mixpanel stay inside the EU. Google and RevenueCat do not, and section 10 covers both.
The label scan sends a photograph to Google
The app has an AI label scan. You photograph a wine label, or pick a picture of one from your photo library, and the image leaves your device. This is the part of the app that sends the most away from your phone, so it is set out in full.
- The app asks for camera or photo library permission, and takes the picture without the camera metadata a phone would normally write into a photo file, so the position tag a photograph can carry does not travel with it.
- The picture is resized on your device to 768 pixels on its long edge and re-encoded as a JPEG, then sent to our own server function, which runs on Supabase in the EU. Your sign-in token goes with it, so the function knows whose allowance to count.
- Our function forwards the image and a fixed instruction to Google, to the Gemini API, which reads the label and returns the producer, the wine name, the vintage, the type, the region, the country and the bottle size. What goes in that request is the picture and the instruction. Your account identifier, your email and everything in your cellar stay here.
- The reading comes back and fills in the add form. You review and edit every field.
This happens before anything is saved, and it happens even if you then discard the reading and add nothing. Cancelling the form does not undo the upload.
We keep no copy of the label photograph. Our function writes it to no storage area and returns nothing but the text, and there is no file storage area for wine for it to land in. What it does write is one row per scan, holding your account identifier, which Shelf app ran the scan, what kind of scan it was and the time.
That row exists to count your free allowance. My Wine Shelf allows three scans in any rolling 24 hours. It is a moving window rather than a reset at midnight: what matters is how many rows sit against your account in the last 24 hours. Subscribers are not metered, and the row is still written either way.
Two things about that count are worth being exact about, because version 2.2 of this policy was not. First, the allowance belongs to your account rather than to this app: the count our function makes is of ledger rows against your account identifier in the window, and it does not filter by which app wrote them. Second, this policy is not going to tell you how the other Shelf apps meter their AI features. They do not all work this way, they are not all three a day, and describing them from here is how the previous two versions of this page got it wrong. Each of their policies says what its own app does.
What we cannot tell you. We call Google’s general endpoint and have not pinned it to a European region, so you should assume the photograph is processed outside the EU. We do not control what Google does with the image after it has read it, and we are not going to state a retention period or a non-use promise we cannot verify. Google’s own terms for that API govern it. If that is not acceptable to you, do not use the label scan. Adding a bottle by barcode, from the catalogue or by hand never sends a photograph anywhere.
The subscription, which is half wired and still reaches RevenueCat
Version 2.1 of this policy said the app carried a subscription library that nothing called, so nothing had ever been sent to a subscription provider from My Wine Shelf. The first half is right and the second half is wrong, and the difference matters.
What is true: the app itself does not start RevenueCat. We searched this build and found no call that configures the library, no call that signs you in to it, and no paywall on any screen. The library ships as a dependency and nothing in this build starts it, so you cannot buy anything in My Wine Shelf.
What is not: before running a label scan, our own server asks RevenueCat whether your account holds a subscription, so that subscribers are not metered against the free allowance. That request carries your account identifier to RevenueCat in the United States. It happens on every scan attempt, whether or not you have ever bought anything and whether or not the scan succeeds. It happens on our server rather than on your phone, which is why looking at the app alone did not show it.
A subscription bought in another Shelf app on the same account is what that lookup can find, because the identifier we hand RevenueCat is your account identifier and RevenueCat holds your entitlements against it. What it finds depends on which subscription you bought. A bundle subscription is honoured by the Shelf apps that check for it. A single-app subscription, which is what most current subscribers hold, unlocks the app it was bought for and is not honoured elsewhere. Version 2.2 of this policy said one subscription covers every Shelf app on the same account, which is true of the bundle and not of the rest. Since My Wine Shelf sells nothing, the only subscription this lookup can ever find is one you bought somewhere else.
6. How long we keep things
- Your account and your cellar: for as long as the account exists. Delete it and the bottles, the tastings, the shopping list, the barcodes you scanned and confirmed, and anything else the app has recorded against the account go with it. Nothing expires on its own and no clean-up job removes it.
- The barcodes you scanned and confirmed: these are owner-private in this app rather than pooled, so it is worth being exact. They are not a pooled table that everyone reads. Each row is yours: it carries your account identifier, the database restricts it to your own account so nobody else can read it, and the deletion in section 8 removes it outright. Nothing of yours is left in a shared barcode list, because for wine there is no shared barcode list.
- The AI scan ledger: one row for each label scan, holding your account identifier, which Shelf app scanned, the kind of scan and the time. It lives with your sign-in record rather than with your cellar, and it goes when the sign-in record goes. If your sign-in is kept because another Shelf app still holds your data, the ledger is kept with it.
- Crash reports, usage events and the subscription record: Sentry, Mixpanel and RevenueCat keep their own copies on their own schedules, and no deletion of ours reaches them. Section 8 says what to do about it. What Google keeps of a label photograph after reading it is governed by Google’s terms for that API, and we cannot delete it for you.
- The catalogue: kept indefinitely, and not touched when an account is deleted, because it is not about you. We checked the columns on those tables: a catalogue row says a wine exists, not that anyone owns a bottle, and none of them carries a column for a user.
- On your own device: the single sign-in entry described in section 3. Signing out removes it.
- Request logs: our host and our database provider keep server-side request logs on their own operational retention schedules. We do not read them to build a picture of any reader, and there is no tool on this site that would let us.
7. Your rights under the GDPR
As a user in the European Economic Area you have the right to:
- Access: request a copy of the data we hold about you
- Rectification: ask us to correct anything inaccurate
- Erasure: ask us to delete your account and everything in your cellar
- Portability: request your data in a portable format. There is no export button on this site. We assemble the file by hand and send it to you.
- Withdraw consent: tell us to stop at any time, without giving a reason; withdrawal does not affect processing carried out before then
- Object and restrict: object to processing based on legitimate interests, or ask us to restrict it
To exercise any of these, write to hello@mywineshelf.com from the address on the account. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority; in Sweden that is Integritetsskyddsmyndigheten (IMY).
8. Deleting your account
The Delete account button in the account panel on this site works. It tells the shared deletion function that it is being called from My Wine Shelf, the function has a My Wine Shelf branch, and that branch removes your tastings, your shopping list, the barcodes you scanned and confirmed, and then your bottles, and nothing belonging to any other shelf app. Version 2.0 of this policy said the function had no branch for wine and came back with an error. That was true when it was written and stopped being true shortly afterwards, and this page is late saying so. Section 11 records it.
The app does not have a delete button yet, and that is a separate thing. It is not that the app tries and fails. There is no such button on any screen, so there is nothing to press. This is the opposite way round from what version 2.0 implied: the website route is the one that works and the app is the one still missing. When the app gets one, this section will say so, and we would rather you held us to that than took it on trust, given the last promise of that shape.
You can also email hello@mywineshelf.com from the address on the account and we will delete it by hand, which is the route to use if you cannot get into the account you want gone. Deletion is permanent and we cannot restore it afterwards. Deleted rows can sit in our database provider’s routine backups until those age out, and we are not going to quote a number for that, because it is our provider’s schedule rather than ours. There is more detail on the deletion page.
One thing to know about the shared login. If the same login is also used for another shelf app, deleting your wine records does not delete the login itself, because that would destroy your account in the other app. The function checks the other shelf apps for you, erases the wine records, and keeps the login. Ask and we will remove the login too.
What is left afterwards. Saying “nothing” would be easier and it would not be true. Crash reports at Sentry survive, usage events at Mixpanel survive if you ever turned analytics on, and your subscriber record at RevenueCat survives, because no deletion of ours reaches those three. What Google holds of a label photograph after reading it is governed by Google’s own terms, and we cannot reach that either. If you asked by email, that email is kept on purpose as the record that we acted on it, and it identifies you. And if the login is kept because another shelf app holds your data, two shared records are kept with it: your analytics choice, and the AI scan ledger. Write to us and we will remove by hand whatever the button cannot.
There are no push notification records to delete, and an earlier version of this page said there were. Here is exactly what we checked, and it is worth reading as what we checked rather than as a guarantee. The notifications library ships as a dependency of the app, but nothing in the app calls it: there is no notifications service file, no call that asks for notification permission and no call that obtains a device token. The one place a registration would belong is commented out and marked as unbuilt. And the shared token table holds no rows for My Wine Shelf today. Version 2.1 of this policy and the deletion page both listed a device token and sent notifications among the things deletion removes, and there is nothing of that kind to remove.
What version 2.2 said, and what we are withdrawing, is the stronger form: that there is no code in the app that could register for push and that no row for wine can be created. The dependency is present and a future build could use it. If that happens, this policy will say so before the build ships, and the deletion page will list the records again.
It runs the other way as well. If you delete your account in one of the other shelf apps while you still hold bottles here, that app checks for them, keeps the login alive so this shelf keeps working, and leaves your cellar where it is.
9. Age
My Wine Shelf is about wine and the keeping of a cellar, and it is meant for adults who are of legal drinking age where they live: 18 in most of Europe, 20 in Sweden for purchases at Systembolaget, 21 in the United States. It is not directed at anyone below that age, and we do not knowingly hold data about them. If you believe a minor has an account here, write to us and we will delete it.
This site does not put an age prompt in front of you and stores no answer to one.
10. International transfers
Our database, our authentication and everything in your cellar are hosted in the European Union.
Nothing on this website contacts a server outside our two providers, except Sign in with Google and Sign in with Apple if you choose one of those. Those are handled by Google and Apple under their own terms and may involve processing outside the EEA.
The app is where the transfers are, and version 2.1 of this policy said there were none because it counted only the website. These leave the EEA:
- Google receives the label photograph, at a general endpoint we have not pinned to a European region.
- RevenueCat, in the United States, receives your account identifier from our server on every label scan.
- Sign in with Google and Sign in with Apple, if you pick one.
For Google and RevenueCat we rely on the European Commission’s standard contractual clauses, which form part of the data processing terms those providers publish. Crash reporting and usage analytics stay inside the EU: Sentry on its German service, Mixpanel on its EU service.
11. Changes to this policy
If we make material changes we will publish the updated version here and update the version number and effective date at the top of this page. If a change materially affects data we already hold about you, we will tell you before it takes effect.
Version 2.4, 5 September 2026. Two changes: one thing the site now does, and one thing it had already started doing without this page saying so.
- The site carries affiliate links now, and the sentences denying it are gone. Section 3 said there was no affiliate code on this site and no arrangement with any retailer, and the short version said no link leads to a shop. Both were true until this release. What stands instead: some pages link to wine accessories on Amazon.se, marked Ad, carrying our Amazon Associates code; a purchase through one pays us a commission; the price you pay does not change; no link leads to wine. Sections 3 and 5 describe it, and this page changed in the release that turned the links on, before they rendered, as section 3 promised it would.
- The bottle photographs load from someone else's server, and this page said no image did. The catalogue gained photographs from the Swedish retail catalogue on 31 August, hotlinked from its image server. Versions 2.2 and 2.3, published the day after, still said the catalogue had no pictures and that this site loads no file from another company's server. Those sentences were wrong the day they were published. The short version and section 5 now say what loads and from where.
Version 2.3, 1 September 2026. Version 2.2 fixed the errors in version 2.1 and made a new set of its own, all of the same kind: sentences that described the whole Shelf portfolio as though it worked one way, when this policy has only ever verified how My Wine Shelf works. What was wrong, and what replaces it:
- “Three scans in any rolling 24 hours, counted across every Shelf app you use on the same account,” followed by “it is not three per app”. The three in any rolling 24 hours is this app's own limit, and the count our function makes is of ledger rows against your account rather than of wine scans. What was not ours to say is how the other Shelf apps meter theirs. They do not all work this way. Section 5 now describes this app's gate and stops there.
- “One subscription covers every Shelf app on the same account.” True of a bundle subscription and not of a single-app one, which unlocks only the app it was bought for and is what most current subscribers hold. Section 5.
- “There is no code in it that could” register for push, and “none can be created” of a row in the shared token table. Those are claims about what is possible, and we checked what exists. What we can stand behind is that nothing in the app registers for push today and the shared table holds no rows for My Wine Shelf today. The notifications library is an installed dependency. Section 8 now says the checked version and withdraws the rest, and so does the deletion page.
- Section 4 gave a lawful basis for the website and none for the app, while section 5 described the label scan, the RevenueCat lookup, the analytics and the crash reports in full. It now assigns Article 6(1)(b) to the account and the features you ask for, Article 6(1)(a) to analytics, and Article 6(1)(f) to crash reporting and the scan allowance, with the interest named. It also said consent was relied on for nothing, which was true of the site and not of the app.
- The Mixpanel entry in section 5 named four apps as sharing your analytics answer. It is five, this one included, and they are now named as five. My Supply Shelf sends no analytics at all, which was also not said.
- “One login for the whole family: My Bar Shelf, My Whiskey Shelf, My Coffee Shelf and the rest.” Section 3 now names all seven apps rather than trailing off.
Version 2.2, 1 September 2026. Version 2.1 described an app that takes no photographs and uses two outside services. The app takes photographs and uses four. What was wrong, and what replaces it:
- “There are no photographs of yours anywhere in this.” The app has a live AI label scan. It photographs a wine label and the picture leaves your device. What is true, and what that sentence should have said, is that no photograph is stored: nothing writes to the photo column on either table and there is no file storage area for wine. Section 3 now draws that line and section 5 describes the scan.
- “Both stay inside the EU. There is no third one.” False twice. There is a third, Google, which receives the label photograph at an endpoint outside the EU, and a fourth, RevenueCat, in the United States. Section 5 now lists four and section 10 lists the transfers.
- “No part of it is wired up and no code in the app calls it.” True of the app and false of the service. The app never starts RevenueCat and has no paywall. Our own server asks RevenueCat about your account, with your account identifier, on every label scan. Section 5 now separates the two.
- There are no push notification records to remove. Section 8 and the deletion page said deletion removes the device token used to send you a push and the notifications sent. Nothing in the app registers for push and the shared token table holds no rows for My Wine Shelf. Those sentences are gone. The wording used here in version 2.2 went further than what we had checked, and version 2.3 above narrows it.
- Section 10 said two things reach past the EEA boundary and named only the two sign-in providers, because it counted the website alone. Rewritten.
- Added: the AI scan ledger and the allowance of three scans in any rolling 24 hours, and the fact that the analytics answer covers five of the Shelf apps rather than all of them. The description of the allowance as counted across every Shelf app was itself an overreach and version 2.3 corrects it.
What we did not change, because we checked it and it held: the catalogue tables carry no column for a user, nothing writes a photograph to a bottle or a tasting, this site loads no file from another company’s server, and neither the site nor the app reads your location. The barcodes you scanned are now described in section 6, because they are private to your account rather than pooled, and that is worth saying plainly.
Version 2.1, 31 August 2026. Version 2.0 promised that section 8 would say so when the Delete account button worked. It works and this page is late saying it. What changed:
- Section 8 no longer says the button is broken. It said the shared deletion function had no branch for wine and returned an error. There is a branch now and the button works. The section also draws the line the old wording blurred: the website button works, and the app is the surface that has no delete button yet.
- Section 1 no longer says the app is still being built. It is a working build in internal TestFlight with sign-in, a cellar and an analytics switch. It is not on a public store, and that is now the claim rather than the vaguer one.
- Sentry and Mixpanel are named for the first time, in section 5. They belong to the app rather than to this website, and they were left out on that reasoning. They should have been in here anyway, because no deletion of ours reaches them. Both are hosted in the EU, so section 10 is unchanged.
- Sections 6 and 8 now name what survives a deletion, including the shared records kept alongside a login that is retained because another shelf app holds your data. The deletion page carried a stronger version of the same error and is corrected in the same pass.
- The barcodes you scanned and confirmed are now named in sections 6 and 8. They were held and deleted before; they were simply not written down.
Version 2.0 replaced the version dated July 2026. That one opened by saying there was no My Wine Shelf app, no account to create and nothing to log into, and the rest of it described an email interest list. It was written for the earlier mywineshelf.com landing page, which this site replaced, and it was wrong about this one, which has a catalogue, sign-in and a cellar and no form of any kind. Nothing was collected under it: the signup table is empty, and no address was ever submitted to that form on any of our sites.
12. Contact
Questions or concerns about your privacy? Write to hello@mywineshelf.com.
Nisshagen Advisory AB, Stockholm, Sweden.