Privacy Policy
Last updated: 7 August 2026
This policy covers two separate things that share a name: vinsip.app, the website you are reading, and VinSip, the iOS and Android app. They are operated by the same company, Vast Flow LLP, and they collect different data for different reasons. The website sections below apply to you right now; the app sections apply only if you have installed it.
What the website collects
The website has no accounts, no login, no comment field and no form that asks for your name. Nothing you do here is tied to an identity, because there is no identity to tie it to.
Two third-party scripts run on every page, and they are the whole of the website's data collection:
- Google Tag Manager, which loads Google Analytics. It records page views, referrer, approximate location derived from IP, device type and browser, and it sets cookies to distinguish one visit from another.
- Microsoft Clarity, project wa08gogd3b. Clarity records how a page is used — scrolling, clicks, mouse movement and rage-clicks — and replays those sessions to us as anonymised recordings and heatmaps. It masks text input by default. We use it to find pages that are broken or unreadable on a phone.
We do not run advertising pixels, retargeting tags, affiliate trackers or fingerprinting scripts, and we do not sell or share website analytics data with anybody.
Map tiles on directory pages are fetched from CARTO and OpenStreetMap when you open a page with a map. Your browser requests those tiles directly, which means your IP address is visible to those providers in the same way it is to any site you visit.
Cookies, and how to refuse them
The cookies set on this site come from Google Analytics and Microsoft Clarity. There are no cookies of our own beyond the banner's own record of your choice, and nothing on this site stops working if you block all of them.
You can refuse them in three ways: decline in the cookie banner, block third-party cookies in your browser, or install the Google Analytics opt-out add-on. Browser-level blocking is the one we would recommend, because it applies everywhere rather than on this site alone.
What the app collects
The VinSip app collects only what the features need, and it works without an account:
- Taste preferences — wine types, sweetness, budget band and occasions you set during onboarding. Stored on the device and sent with a recommendation request.
- Wine diary entries — the wines you save, your ratings and your tasting notes. Stored on the device.
- Photos you scan — sent to the recognition service, used to identify the label, and not retained on our servers afterwards.
- Sommelier chat messages — sent to the AI service to generate a reply.
- Approximate location, only if you grant the permission, and only to sort venues by distance.
- Device and diagnostic data — device model, OS version, crash reports and feature usage.
Who processes data on our behalf
These are the processors, what each one receives, and why:
- RevenueCat — subscription state. Receives an anonymous, app-generated subscriber identifier and the store receipt. It never receives your name or email.
- Firebase — analytics and crash reporting for the app.
- OpenRouter and the underlying model providers — the scanned photo and the chat message, for identification and recommendation.
- Google Analytics and Microsoft Clarity — website usage, as described above.
- Hetzner — hosting for the website and the backend, in Germany.
We do not sell personal information, and we have never received a payment for access to it.
Legal basis and retention
Under the GDPR we rely on legitimate interest for security, fraud prevention and aggregate analytics; on consent for cookies, analytics scripts and location; and on contract for subscription handling. Where consent is the basis you can withdraw it at any time, and doing so does not affect processing that already happened.
Retention is short by design. Scanned photos are processed and discarded rather than stored. Website analytics follow the provider defaults — Google Analytics retains event data for 14 months, Clarity for 30 days. Diary entries live on your device until you delete them or remove the app.
What we deliberately do not collect
This list is as much a part of the policy as the one above, and it is the part most policies leave out:
- No name, email address or phone number is required to use the website or the app. There is no signup.
- No precise GPS trace. The app asks for approximate location only, and only when you use a feature that sorts by distance.
- No contacts, photo library scan, microphone access or clipboard reading.
- No advertising identifier, no cross-app tracking, no data broker enrichment, no purchase of third-party audience data.
- No storage of the photographs you scan. The image is sent, identified and discarded.
- No profile linking your app activity to your website visits. The two systems do not share an identifier, because there is no identifier to share.
What happens to a scanned photograph, step by step
You point the camera at a bottle or a shelf and the app captures a frame. That frame is sent over TLS to our backend, which forwards it to the model that reads the label. The model returns text — producer, wine, vintage where legible — and the backend returns that text to your phone.
The image is held in memory for the duration of that request. It is not written to a database, not put in object storage, not used to train anything, and not retained after the response is sent. What persists is what you choose to save: the identified wine in your diary, on your device.
The consequence worth knowing is that we cannot show you your scan history from our side, because we do not have it. If you delete the app, the diary goes with it.
Transfers outside the EEA, and automated decisions
The website and the backend are hosted in Germany. Some processors — the analytics providers and the model providers — operate in the United States, and those transfers rely on the EU–US Data Privacy Framework or on standard contractual clauses, depending on the provider.
There is no automated decision-making with a legal or similarly significant effect anywhere in this service. Wine recognition is a suggestion about a bottle; nothing here decides anything about you.
How to check any of this for yourself
None of the claims above need to be taken on trust. Open your browser's developer tools on any page of this site, go to the network tab and reload: every request the page makes is listed there, and the only third-party hosts you will see are googletagmanager.com, clarity.ms, and — on a page with a map — the CARTO tile servers. If you find a host we have not named on this page, that is a mistake on our part and we want to hear about it.
The same check answers the question people usually mean when they ask about privacy: not "what does the policy say" but "what does the page actually do". A policy is a promise; the network tab is a measurement.
For the app, the equivalent check is a proxy: point the phone at a debugging proxy and watch what leaves it. You will see the scan request to our backend, the store receipt validation, and the analytics batch, and nothing else. We would rather you verified than believed us.
Security, and what a breach here would and would not expose
Traffic to this site and to the backend is encrypted in transit with TLS. The backend runs on a hardened host with key-only administrative access, and the website itself is a set of static files with no database behind it and no form that writes anything.
The honest version of the security section is about blast radius rather than about the word "industry-standard". Because the website holds no user data at all, a compromise of it would expose no personal information — there is none there to take. Because scanned photographs are not stored, a compromise of the backend would not expose a photo archive, because no archive exists. The data most at risk in a service like this is the data we chose not to keep.
Your rights
Depending on where you live you may ask us to give you a copy of the personal data we hold, correct it, delete it, restrict or object to a particular use, or export it. Write to us and we will answer within 30 days. We do not require you to create an account to exercise a right, which would be a strange thing to demand from a site that has no accounts.
If you are in the EU or the UK and you are unhappy with our answer, you may complain to your national data protection authority.
Age
This site is about where wine is sold and how it is regulated. It is intended for people of legal purchase age in their own country, which is 21 in the United States, 16 for wine in Germany and 18 in most of the rest of the countries we cover. We do not knowingly collect data from children under 13.
Changes and contact
When this policy changes materially we change the date at the top and describe the change in the app or on the site. We do not backdate it.
Questions about this policy, or a request to exercise a right, go to the address on our contact page.