Legal

Privacy Policy

Version 2.4  ·  Effective date: 5 September 2026

Short version. The catalogue pages are built on our servers and sent to you finished, so reading them makes no request from your browser to our database. The search box is the exception: it runs in your browser, so what you type there travels to our database in the EU. No page sets a cookie and no analytics script runs. One kind of file does load from someone else's server: the bottle photographs, which come straight from the Swedish retail catalogue. Earlier versions of this page said the catalogue had no pictures, and section 11 records the correction. Signing in is optional and gets you one page, your cellar, which reads what the app holds against your account: your bottles and your tasting notes. It reads and never writes. Nothing here is for sale by us. Some pages carry links to wine accessories on Amazon.se, marked Ad: a purchase through one pays us a commission, the price you pay does not change, and no link leads to wine. We do not sell your data. You can delete all of it with the button in the account panel, which works; version 2.0 of this policy said it returned an error, and it does not. The app is a separate surface, and one thing it does sends more away from your phone than anything on this site does: the label scan photographs a wine label and sends the picture to Google. Section 5 sets it out. Version 2.1 of this policy said the app took no photographs and that its two outside services were the whole set. Both statements were false.

1. Who we are

My Wine Shelf is a product of Nisshagen Advisory AB (Org.nr 559526-6742), a company registered in Stockholm, Sweden. We are the data controller for personal data collected through the mywineshelf.com website.

Contact hello@mywineshelf.com for any privacy question, including data subject requests under the GDPR.

This policy covers the website, including the cellar page you reach by signing in.

About the app. The My Wine Shelf app is in internal TestFlight, which means invited testers, and it is not on any public store. Calling it “still being built” undersells it: it has sign-in, a cellar, a tasting log, an AI label scan and an analytics switch that is off until you turn it on. What it does not have is a Delete account button. Section 8 says what that means and what to use instead. It will carry its own policy for what happens on your phone before it reaches a store, and this page will point to it. The four outside services it uses are named in section 5 anyway, because they outlive a deletion and you should learn about them here rather than later.

2. Reading the site

The pages themselves

The front page, the region pages and the four style pages are assembled on our servers and sent to your browser as finished HTML, then held for up to 24 hours before they are rebuilt. Reading them involves no request from your browser to our database, no form and no sign-up. There is nothing on those pages to fill in.

No page on this site sets a cookie. There is no analytics: no page-view counter, no session recording, no product analytics and no tracking pixel belonging to us or to anyone else. Vercel Web Analytics is not switched on for this project, and the script it would inject is not in any page we serve. Our host keeps the request logs any web server keeps, and section 6 covers those.

The search box, which works differently

Find a wine is an interactive page, and it searches from your browser rather than from our servers. Type two characters or more, stop for a third of a second, and your browser sends what you typed to our database and asks for up to 40 matching rows. That happens whether or not you are signed in. Every request to any server reveals the IP address it came from, and this one is no different.

We keep no search history. There is no table on this site's side that records what anyone looked for, and we searched this site's code for anything that would write one and found nothing. Our database provider keeps its own API request logs on its own schedule, the same way our web host keeps request logs, and neither is read to build a picture of a reader.

We describe the search box separately because it is the one part of reading this site that talks to our database, and you can see it in your own network log. Saying the catalogue is server-rendered and stopping there would leave it out.

No pictures, and no typefaces from anyone else

Nothing on this site loads a file from another company's server. The catalogue table has no image column, so there are no bottle photographs to fetch, and no page here contains an image tag at all. The two typefaces are served from this domain rather than from a font CDN, and this policy and the terms use the fonts already on your device. Your browser contacts our host, and our database when you search or sign in. That is the whole list.

3. Signing in, and your cellar

Your account

Most of the site needs no account. One page, your cellar, does, and there is a Sign in button in the navigation on every page. Sign-in runs on Supabase, our database and authentication provider, hosted in the EU. What we hold depends on how you sign in:

If you type a name when you create the account, we store it and use it to greet you in the account panel. Nothing else about you is asked for.

One login across the shelf apps

The account is the ShelfHub account, and it is one login across My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf, My Cigar Shelf, My Coffee Shelf and My Supply Shelf. Signing in here signs you in with the same credentials you use there. The login is shared. The shelves are not: your cellar is not visible to those apps, and what you keep in them is not visible here. This matters most when you delete something, so section 8 sets it out in full.

Where your session is kept

Nothing on this site sets a cookie. When you sign in, one entry goes into your browser's local storage, named sb-tlqlbnhaqpqgaxfihdlj-auth-token after our database project, holding the token that keeps you signed in. Signing out removes it. If you sign in with Google or Apple, the token comes back in the address bar and is moved into that same entry.

While that entry exists, your browser checks in with Supabase on every page to keep the token fresh. A signed-in reader's browser therefore talks to our database on pages where a signed-out reader's browser does not.

That entry is the only thing this site stores on your device, and it is there because you asked to be signed in. Storage that is strictly necessary for something you requested does not require consent under the ePrivacy rules, which is why you are not looking at a cookie banner. If we ever add storage that is not necessary, you will be given a real choice about it and this policy will say so first.

What the cellar page shows

It reads two tables, user_wines and tastings, and shows:

Those two tables carry more columns than this page displays, and the app is what fills them: the bottle size, the purchase date, what you paid and in what currency, where you bought it, a drinking window, and for a tasting the flavour notes, the food you had with it, the occasion and where you were. Whatever is sitting in those columns is covered by the deletion in section 8, whether this page shows it or not. Both tables also carry an unused column for a photograph. Nothing fills it: we checked every use of that column in the app and all of them read, none writes, and there is no file storage area for wine for a file to land in. So no photograph of yours is stored against a bottle or a tasting. That is not the same as saying the app takes no photographs. It has a label scan, the picture it takes leaves your device, and section 5 sets out where it goes. Version 2.1 of this policy said there were no photographs at all, which was false.

Read as a run, those records are a dated list of what someone owns, what they paid for it and when they opened it. We would rather say what it amounts to than file it under “your data”. It is private to your account: the database restricts every row in those tables to the account that created it, and that restriction lives in the database rather than in this website's code, so it holds no matter what this page asks for.

This page reads and does not write

Nothing you do on this website changes your cellar. Adding a bottle, logging a tasting and editing anything happen in the app. There is not one write to wine data anywhere in this site's code. The only things this site can change are the account itself: creating it, resetting the password, and the deletion described in section 8.

What this site does not do

Every line below is about this website. Some of them do not hold for the app, and where that is so the line says which section covers the app instead.

If any of that changes, we will update this policy before the change goes live rather than after, and analytics in particular would stay switched off until you consent to it.

4. Legal basis for processing

Version 2.2 of this policy gave a basis for the website and none for the app, while section 5 described the app's processing in full. That left the largest things this policy describes with no lawful basis attached to them. Both are covered here.

Giving us this data is not a statutory requirement. It is what the app needs in order to be a cellar: without an account there is nowhere to put a bottle. There is no automated decision-making that produces legal or similarly significant effects and no profiling. A label reading is a machine guess that fills a form, and you review and edit every field before anything is saved.

5. Third parties we use

That is the entire list for this website, and one more company is involved without working for us: the bottle photographs load straight from the Swedish retail catalogue's image server, so opening a photographed page sends that server the request any image fetch sends, from your IP address like any request. No script of theirs runs here. Beyond that there is no font CDN, no error-reporting service and no tag manager on any page.

The wine catalogue comes from the LWIN database published by Liv-ex Ltd, under a Creative Commons Attribution 4.0 licence. We hold a copy of it, so Liv-ex receives nothing from your browser and learns nothing about who reads this site. The credit at the foot of every page is a term of that licence rather than a link we chose to add. Section 5 of the Terms of Service covers what the licence means for you.

We do not sell your data to any third party. Supabase and Vercel are the two companies we contract with to run this site, and neither uses your data for advertising. If we ever add a provider that would, we will update this policy before the arrangement starts.

Google and Apple are not working for us, so we will not make a promise on their behalf. What their servers do with a request they receive is governed by their own policies. What we control is how little we hand them, and section 3 says exactly what that is.

Four more that belong to the app

None of these is contacted by this website. They are named here because the app hands them things this site never touches, and because the deletion in section 8 does not reach them, so they outlive it however you ask. Version 2.1 of this policy listed two and said there was no third. There are four.

Sentry and Mixpanel stay inside the EU. Google and RevenueCat do not, and section 10 covers both.

The label scan sends a photograph to Google

The app has an AI label scan. You photograph a wine label, or pick a picture of one from your photo library, and the image leaves your device. This is the part of the app that sends the most away from your phone, so it is set out in full.

This happens before anything is saved, and it happens even if you then discard the reading and add nothing. Cancelling the form does not undo the upload.

We keep no copy of the label photograph. Our function writes it to no storage area and returns nothing but the text, and there is no file storage area for wine for it to land in. What it does write is one row per scan, holding your account identifier, which Shelf app ran the scan, what kind of scan it was and the time.

That row exists to count your free allowance. My Wine Shelf allows three scans in any rolling 24 hours. It is a moving window rather than a reset at midnight: what matters is how many rows sit against your account in the last 24 hours. Subscribers are not metered, and the row is still written either way.

Two things about that count are worth being exact about, because version 2.2 of this policy was not. First, the allowance belongs to your account rather than to this app: the count our function makes is of ledger rows against your account identifier in the window, and it does not filter by which app wrote them. Second, this policy is not going to tell you how the other Shelf apps meter their AI features. They do not all work this way, they are not all three a day, and describing them from here is how the previous two versions of this page got it wrong. Each of their policies says what its own app does.

What we cannot tell you. We call Google’s general endpoint and have not pinned it to a European region, so you should assume the photograph is processed outside the EU. We do not control what Google does with the image after it has read it, and we are not going to state a retention period or a non-use promise we cannot verify. Google’s own terms for that API govern it. If that is not acceptable to you, do not use the label scan. Adding a bottle by barcode, from the catalogue or by hand never sends a photograph anywhere.

The subscription, which is half wired and still reaches RevenueCat

Version 2.1 of this policy said the app carried a subscription library that nothing called, so nothing had ever been sent to a subscription provider from My Wine Shelf. The first half is right and the second half is wrong, and the difference matters.

What is true: the app itself does not start RevenueCat. We searched this build and found no call that configures the library, no call that signs you in to it, and no paywall on any screen. The library ships as a dependency and nothing in this build starts it, so you cannot buy anything in My Wine Shelf.

What is not: before running a label scan, our own server asks RevenueCat whether your account holds a subscription, so that subscribers are not metered against the free allowance. That request carries your account identifier to RevenueCat in the United States. It happens on every scan attempt, whether or not you have ever bought anything and whether or not the scan succeeds. It happens on our server rather than on your phone, which is why looking at the app alone did not show it.

A subscription bought in another Shelf app on the same account is what that lookup can find, because the identifier we hand RevenueCat is your account identifier and RevenueCat holds your entitlements against it. What it finds depends on which subscription you bought. A bundle subscription is honoured by the Shelf apps that check for it. A single-app subscription, which is what most current subscribers hold, unlocks the app it was bought for and is not honoured elsewhere. Version 2.2 of this policy said one subscription covers every Shelf app on the same account, which is true of the bundle and not of the rest. Since My Wine Shelf sells nothing, the only subscription this lookup can ever find is one you bought somewhere else.

6. How long we keep things

7. Your rights under the GDPR

As a user in the European Economic Area you have the right to:

To exercise any of these, write to hello@mywineshelf.com from the address on the account. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority; in Sweden that is Integritetsskyddsmyndigheten (IMY).

8. Deleting your account

The Delete account button in the account panel on this site works. It tells the shared deletion function that it is being called from My Wine Shelf, the function has a My Wine Shelf branch, and that branch removes your tastings, your shopping list, the barcodes you scanned and confirmed, and then your bottles, and nothing belonging to any other shelf app. Version 2.0 of this policy said the function had no branch for wine and came back with an error. That was true when it was written and stopped being true shortly afterwards, and this page is late saying so. Section 11 records it.

The app does not have a delete button yet, and that is a separate thing. It is not that the app tries and fails. There is no such button on any screen, so there is nothing to press. This is the opposite way round from what version 2.0 implied: the website route is the one that works and the app is the one still missing. When the app gets one, this section will say so, and we would rather you held us to that than took it on trust, given the last promise of that shape.

You can also email hello@mywineshelf.com from the address on the account and we will delete it by hand, which is the route to use if you cannot get into the account you want gone. Deletion is permanent and we cannot restore it afterwards. Deleted rows can sit in our database provider’s routine backups until those age out, and we are not going to quote a number for that, because it is our provider’s schedule rather than ours. There is more detail on the deletion page.

One thing to know about the shared login. If the same login is also used for another shelf app, deleting your wine records does not delete the login itself, because that would destroy your account in the other app. The function checks the other shelf apps for you, erases the wine records, and keeps the login. Ask and we will remove the login too.

What is left afterwards. Saying “nothing” would be easier and it would not be true. Crash reports at Sentry survive, usage events at Mixpanel survive if you ever turned analytics on, and your subscriber record at RevenueCat survives, because no deletion of ours reaches those three. What Google holds of a label photograph after reading it is governed by Google’s own terms, and we cannot reach that either. If you asked by email, that email is kept on purpose as the record that we acted on it, and it identifies you. And if the login is kept because another shelf app holds your data, two shared records are kept with it: your analytics choice, and the AI scan ledger. Write to us and we will remove by hand whatever the button cannot.

There are no push notification records to delete, and an earlier version of this page said there were. Here is exactly what we checked, and it is worth reading as what we checked rather than as a guarantee. The notifications library ships as a dependency of the app, but nothing in the app calls it: there is no notifications service file, no call that asks for notification permission and no call that obtains a device token. The one place a registration would belong is commented out and marked as unbuilt. And the shared token table holds no rows for My Wine Shelf today. Version 2.1 of this policy and the deletion page both listed a device token and sent notifications among the things deletion removes, and there is nothing of that kind to remove.

What version 2.2 said, and what we are withdrawing, is the stronger form: that there is no code in the app that could register for push and that no row for wine can be created. The dependency is present and a future build could use it. If that happens, this policy will say so before the build ships, and the deletion page will list the records again.

It runs the other way as well. If you delete your account in one of the other shelf apps while you still hold bottles here, that app checks for them, keeps the login alive so this shelf keeps working, and leaves your cellar where it is.

9. Age

My Wine Shelf is about wine and the keeping of a cellar, and it is meant for adults who are of legal drinking age where they live: 18 in most of Europe, 20 in Sweden for purchases at Systembolaget, 21 in the United States. It is not directed at anyone below that age, and we do not knowingly hold data about them. If you believe a minor has an account here, write to us and we will delete it.

This site does not put an age prompt in front of you and stores no answer to one.

10. International transfers

Our database, our authentication and everything in your cellar are hosted in the European Union.

Nothing on this website contacts a server outside our two providers, except Sign in with Google and Sign in with Apple if you choose one of those. Those are handled by Google and Apple under their own terms and may involve processing outside the EEA.

The app is where the transfers are, and version 2.1 of this policy said there were none because it counted only the website. These leave the EEA:

For Google and RevenueCat we rely on the European Commission’s standard contractual clauses, which form part of the data processing terms those providers publish. Crash reporting and usage analytics stay inside the EU: Sentry on its German service, Mixpanel on its EU service.

11. Changes to this policy

If we make material changes we will publish the updated version here and update the version number and effective date at the top of this page. If a change materially affects data we already hold about you, we will tell you before it takes effect.

Version 2.4, 5 September 2026. Two changes: one thing the site now does, and one thing it had already started doing without this page saying so.

Version 2.3, 1 September 2026. Version 2.2 fixed the errors in version 2.1 and made a new set of its own, all of the same kind: sentences that described the whole Shelf portfolio as though it worked one way, when this policy has only ever verified how My Wine Shelf works. What was wrong, and what replaces it:

Version 2.2, 1 September 2026. Version 2.1 described an app that takes no photographs and uses two outside services. The app takes photographs and uses four. What was wrong, and what replaces it:

What we did not change, because we checked it and it held: the catalogue tables carry no column for a user, nothing writes a photograph to a bottle or a tasting, this site loads no file from another company’s server, and neither the site nor the app reads your location. The barcodes you scanned are now described in section 6, because they are private to your account rather than pooled, and that is worth saying plainly.

Version 2.1, 31 August 2026. Version 2.0 promised that section 8 would say so when the Delete account button worked. It works and this page is late saying it. What changed:

Version 2.0 replaced the version dated July 2026. That one opened by saying there was no My Wine Shelf app, no account to create and nothing to log into, and the rest of it described an email interest list. It was written for the earlier mywineshelf.com landing page, which this site replaced, and it was wrong about this one, which has a catalogue, sign-in and a cellar and no form of any kind. Nothing was collected under it: the signup table is empty, and no address was ever submitted to that form on any of our sites.

12. Contact

Questions or concerns about your privacy? Write to hello@mywineshelf.com.

Nisshagen Advisory AB, Stockholm, Sweden.