Legal
Privacy Policy
Effective Date: May 13, 2026
Cellar & Table ("Company," "we," "our," or "us") provides a personalized wine discovery and pairing experience. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (the "Service").
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy.
1. Eligibility and Age Verification
Cellar & Table is intended solely for individuals of legal drinking age in their jurisdiction (21 years of age or older in the United States; 18 years of age or older in many other countries). By using the Service, you represent that you meet this requirement. We do not knowingly collect personal information from individuals below the legal drinking age.
Before accessing the Service, users are presented with an age confirmation screen and must affirm that they are of legal drinking age. This confirmation is stored locally on your device only (using your device's local app storage) as a boolean flag indicating that age confirmation was completed. We do not collect, transmit, or store your date of birth or any age-specific personal information on our servers as part of this process. If you delete and reinstall the app, you will be asked to confirm your age again.
2. Information We Collect
A. Information You Provide
We may collect information you voluntarily provide through the Service, including:
- Account information (such as your name, email address, and login credentials)
- Wine-related activity (including wine logs, ratings, tasting notes, cellar entries, food pairings, occasion notes, and purchase information)
- Photos you choose to upload (including wine labels, bottles, shelves, wine lists, food, or dining settings)
- Feedback and support messages you submit
- Optional location information you enter directly (such as ZIP or postal code)
- Derived preference data, including a personalized taste profile generated from your activity within the Service
Taste profiles are generated automatically from your activity within the Service and are used solely to personalize recommendations, educational insights, and experiences within the app.
B. Automatically Collected Information
When you use the Service, we may automatically collect certain technical and usage information, including:
- Device and app information (device type, operating system, app version)
- Usage activity (screens viewed, features used, interactions taken)
- Performance and diagnostic data (crashes, load times, errors)
- Approximate location information derived from your network connection's IP address
Approximate location lookups are performed automatically at sign-in using a third-party geolocation provider (ipinfo.io). We store only the derived country, region, and city information — not your raw IP address. We do not collect precise GPS coordinates. This information is used to provide regionally relevant recommendations and improve the Service.
See Section 7 for additional information regarding IP address handling by infrastructure providers.
C. Photos, Text, and AI Processing
Content you submit through the Service — including photos and text — may be processed to provide wine identification, tasting insights, pairing recommendations, moderation, and related AI-powered features.
- AI processing is performed by Anthropic PBC as our AI service provider
- Anthropic does not use your submitted content to train AI models
- Anthropic is contractually obligated to protect submitted data
- Uploaded images may be temporarily cached or processed in transient memory or temporary storage solely to fulfill your request and are automatically deleted after processing is complete
- We do not persistently store raw uploaded images on our servers
- Your submitted content is not used for advertising or marketing purposes
D. Content Moderation
User-submitted text and images may be evaluated by automated safety systems to detect content that violates our Terms of Service or applicable law, including harmful, abusive, fraudulent, or illegal content.
When content is flagged, we may log limited metadata about the event (such as classification category and timestamp) for trust and safety review. Raw submitted content is not retained in these moderation logs.
This processing is carried out under our legitimate interest in maintaining a safe and lawful service.
3. Legal Basis for Processing (EEA/UK Users)
If you are located in the European Economic Area or United Kingdom, we process your personal data under one or more of the following legal bases:
- Performance of a contract: processing necessary to provide the Service you signed up for, including account management, recommendations, and personalized experiences
- Legitimate interests: product improvement, usage analytics, fraud prevention, content moderation, safety monitoring, and regionally relevant recommendations, conducted in a proportionate manner designed to minimize personal data collection where reasonably possible
- Consent: for optional features where consent is requested, such as voluntarily entered postal code information
You may withdraw consent at any time without affecting prior lawful processing.
4. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Generate personalized wine and food pairing recommendations
- Build and refine your taste profile
- Deliver educational insights and personalized experiences
- Process payments and manage subscriptions
- Understand usage trends and improve features
- Monitor performance and resolve technical issues
- Enforce our Terms of Service and maintain platform safety
- Prevent fraud, abuse, and unauthorized access
- Communicate with you about your account or the Service
- Comply with legal obligations
Subscriptions purchased through the Apple App Store or Google Play may be processed by the applicable platform provider and are subject to their respective billing terms and privacy practices.
5. Sharing and Disclosure
We do not sell, rent, or share your personal information for cross-context behavioral advertising or targeted advertising purposes.
We share information only with trusted service providers necessary to operate and improve the Service. These providers are contractually obligated to protect your information and may use it only for authorized business purposes.
Current service providers include:
- Anthropic PBC — AI processing and moderation
- Stripe, Inc. — payment processing and subscription management
- Supabase, Inc. — database hosting and authentication infrastructure
- PostHog, Inc. — product analytics and usage insights
- ipinfo.io — IP-based approximate geolocation services
- Cloudflare, Inc. — infrastructure, content delivery, and security services
We may also disclose information:
- If required by law, subpoena, or court order
- To protect the rights, property, safety, or security of users, the Company, or the public
- In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets involving all or part of our business
6. International Data Transfers
Your information may be processed and stored in the United States and other jurisdictions where our service providers operate.
If you access the Service from outside the United States, please be aware that your information may be transferred to, stored in, and processed in countries whose data protection laws may differ from those in your jurisdiction.
Where required by applicable law, we rely on appropriate safeguards — including standard contractual clauses or equivalent mechanisms — to govern cross-border transfers of personal data.
7. IP Addresses and Infrastructure Processing
When you sign in to the Service, we use your network connection's IP address to derive an approximate location (country, region, and city) through ipinfo.io. We store only the derived location information in your account profile and do not retain the raw IP address in our application database.
Approximate location data is used to improve the Service and provide regionally relevant recommendations.
Raw IP addresses may be processed transiently by infrastructure providers, including Supabase and Cloudflare, for security, routing, performance optimization, and fraud prevention purposes in accordance with their respective privacy policies.
If you wish to prevent IP-derived location from being associated with your account, you may request account deletion as described in Section 11. Use of a VPN or proxy service may affect the accuracy of inferred location data but does not prevent the lookup itself from occurring.
8. Third-Party Services and Links
The Service may contain links to third-party websites, retailers, wineries, restaurants, reservation systems, or other services that are not operated by us.
We are not responsible for the privacy practices, content, or policies of third-party services. We encourage you to review the privacy policies of any external services you access.
9. Do Not Track
The Service does not respond to "Do Not Track" browser signals.
We do not engage in cross-site tracking or targeted advertising and limit analytics collection to product improvement, operational performance, and security-related purposes described in this Privacy Policy.
10. Data Retention
We retain personal information for as long as necessary to provide the Service, fulfill legitimate business purposes, comply with legal obligations, resolve disputes, and enforce agreements.
When you delete your account, your account information, wine logs, cellar data, taste profile, and associated IP-derived location information are permanently and irreversibly deleted from our active systems.
Certain anonymized or aggregated analytics data, safety event metadata, and legally required records may be retained after deletion where they can no longer reasonably identify you.
11. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding your personal information.
Access and Correction
You may access and update your account information directly through the app settings.
Account Deletion
You may permanently delete your account and associated personal data directly within the app through the account settings. This action is irreversible.
Postal Code Preference
Entering your ZIP or postal code is optional. If provided, it may override IP-derived approximate location information for recommendation purposes.
IP-Derived Location
Approximate location derived from your IP address is collected automatically during sign-in and cannot currently be individually disabled while maintaining an active account. You may delete your account if you do not wish this information to be associated with your profile.
Analytics Opt-Out
You may contact us at privacy@thecellarandtable.com to request opt-out from certain non-essential analytics tracking. Certain analytics related to security, fraud prevention, and core Service functionality may remain necessary for operation of the Service.
Additional Regional Rights
If you are located in the European Economic Area, United Kingdom, California, or another jurisdiction with applicable privacy laws, you may have additional rights including:
- Data portability
- Restriction of processing
- Objection to processing based on legitimate interests
- Access to categories of collected information
- Request for deletion of personal information
To exercise any applicable rights, contact us using the information below.
12. Data Security
We implement reasonable technical, administrative, and organizational safeguards designed to protect your information from unauthorized access, disclosure, alteration, or destruction.
These safeguards include encrypted data transmission, authentication controls, access restrictions, infrastructure security protections, and database-level access controls designed to ensure users may only access their own data.
However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Children's Privacy
The Service is not intended for individuals below the legal drinking age in their jurisdiction, and we do not knowingly collect personal information from minors.
If we become aware that personal information has been collected from an individual below the legal drinking age, we will take reasonable steps to delete that information promptly.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
When changes are made, we will revise the Effective Date at the top of this document. If material changes are made, we will notify you within the app or by email.
Your continued use of the Service after updated terms become effective constitutes acceptance of the revised Privacy Policy.
15. Contact Us
If you have questions, requests, or concerns regarding this Privacy Policy or our privacy practices, please contact us at: