Blind Wine Notes Privacy Policy
Last updated: September 13, 2026
Blind Wine Notes is built so that your records stay on your device. This policy explains what the app handles and what it does not.
1. No account
Blind Wine Notes requires no sign-up. It collects no name, email address, phone number, date of birth or postal address. There is no login.
2. What stays on your device
All of the following is stored in an on-device database and files, and never leaves the device unless you act to send it:
- Tasting notes (appearance, aroma, palate, conclusion, ratings, memos)
- Wine details and label photos
- Blind deductions, revealed answers and scores
- Your edits to the aroma vocabulary and any expressions you add
- Learning progress, quiz history, app settings and display language
3. What is sent when you use an AI feature
When you use AI feedback, label reading, aroma look-up, chat, hints or aroma-icon generation, the content needed for that request is sent through our server (Cloudflare Workers) to the API of OpenAI, L.L.C. No transmission occurs if you do not use an AI feature.
What is sent
- The content of the record the action targets (appearance, aroma, palate, conclusion, blind deductions and answers)
- The label photo, if you use label reading
- Free text you type (chat, aroma look-up)
- Your display-language setting
- The anonymous user ID described below
What is not sent
- Any other record, photo, contact data, location data, or device identifier
Storage on our server
Our server does not store the request content or the AI response. It stores only the ledger needed to manage your AI allowance (usage amount per anonymous user ID, paid-plan status, and transaction IDs used to prevent duplicate credit grants). Operational logs contain usage amounts, cost, the anonymous user ID, and — on failure — an error message (up to 300 characters). They do not contain the body of your notes or your photos.
Handling at OpenAI
Under OpenAI's policy, data sent through the API is not used to train their models by default. It may be retained for a limited period (up to 30 days) for abuse monitoring.
4. Anonymous user ID
To count AI usage, we use an anonymous ID generated by our purchase-management provider (RevenueCat, Inc.). It is not linked to a name or email address. Deleting and reinstalling the app produces a different ID.
5. Purchases
In-app purchases are processed by Apple. Payment details such as card numbers never reach this app. To determine paid-plan status and to support "restore purchases", purchase and subscription state is processed by RevenueCat, Inc. (United States).
6. IP address
To prevent abuse of the AI features (mass acquisition of free allowances, excessive requests), the connecting IP address is used to count requests when an AI feature is called. Those counters are cleared when the UTC date changes. They are not used for advertising or for tracking behaviour.
7. Advertising measurement
To measure whether an install came from an Apple ad, the app may obtain an attribution token via Apple's AdServices framework. This token does not use the advertising identifier (IDFA) and does not identify a person or a device.
8. Usage analytics (you can turn this off)
To learn which screens are used and where people drop off, we collect anonymous usage analytics. Processing is carried out by PostHog (PostHog, Inc., United States).
What is sent
- Events with pre-defined names representing use of a screen or feature (for example: the paywall was shown, an onboarding step was passed, the low-credit notice was shown)
- Short identifier-only values attached to those events (for example: which plan was chosen, which screen showed the offer)
- App version, OS name and version, device model, display language, time zone
- Success, latency and route of AI calls (recorded on the server side)
What is never sent
- The content of your tasting records, notes, free text, wine names or label photos
- Name, email address, phone number or other contact details (we never collect these)
- Location data or advertising identifiers (IDFA)
- IP addresses (explicitly excluded from the server-side events, and discarded on the PostHog side for events sent from the app; they are not used to infer location either)
About identifiers
Analytics uses an anonymous, analytics-only ID generated on your device. It is separate from the purchase-management anonymous ID (section 4), and the two are never joined. Server-side records use a one-way transformed value of the purchase-management ID rather than the ID itself.
How to turn it off
Open Settings → Privacy → Usage analytics and switch it off. Nothing further is sent, including app-launch events. It is on by default.
9. What we do not do
- Sell or rent personal information to third parties
- Show advertisements (this version serves no ads)
- Track your activity across other companies' apps or websites
10. Backup and export
Device backups (such as iCloud) may include this app's data. That is an operating-system feature and is governed by Apple's policies. You can also export your records to a JSON file yourself; managing an exported file is up to you.
11. Deleting your data
Removing the app from your device deletes the on-device data. If you want the usage ledger on our server deleted, contact us at the address below.
12. Age
Because Blind Wine Notes deals with alcoholic beverages, it is not intended for people under 17.
13. Changes to this policy
If this policy changes we will update the "Last updated" date on this page. Significant changes will be announced in the app.
14. Contact
For questions about this policy or the app, contact us at:
Analytics on the official website
With permission, the official website uses Google Analytics 4 (Google LLC) and cookies to measure page views and App Store link clicks. Google signals and advertising personalization are disabled. Permission can be changed at any time using Cookie settings. Wine records, photos, and free text are not sent.
Google privacy policy: https://policies.google.com/privacy