Privacy Policy

The Cellar Schematic™

Last updated: 10 August 2026

The Cellar Schematic is a personal wine cellar app, designed and operated as an independent product. This policy explains what data the app handles, where it lives, and what we do — and do not — see. It covers both the iPhone and iPad app and the Android app; where the two differ, the difference is stated.

The short version: we don't collect, store, or analyse your personal information. Your cellar stays in your own hands — in your iCloud account on Apple devices, and on the device itself on Android. The optional AI features call OpenAI directly using a key you supply. We have no servers handling your wines, your photos, your notes, your usage, or anything else about you.

Information we don't collect

We do not collect, store, or transmit:

  • Your name, email address, billing details, or any account information

  • Your location, device identifiers, advertising identifiers, or any analytics

  • Your wines, photos, tasting notes, ratings, prices, or sharing activity

  • Your buying activity — what wines you search for, which retailers you tap, which products you click through to, or which wines you flag on your buying list

  • Any usage data, crash reports, telemetry, or behavioural information

The app contains no third-party analytics, tracking, or advertising SDKs on either platform. Your purchase of the app is handled entirely by Apple or by Google, under their own terms.


Where your cellar data lives

On iPhone and iPad. All of your cellar data — wines, tasting notes, photos, drinking windows, storage locations, vault entries, buying list flags and any shared-cellar participants — is stored in your own iCloud account using Apple's CloudKit framework. It syncs between your Apple devices through Apple's iCloud infrastructure. iCloud sync is governed by Apple's iCloud terms and privacy practices.

On Android. All of your cellar data is stored in a private database on the device itself. There is no cloud sync: the Android app does not copy your cellar to any service of ours, and cellars do not sync between your Android devices.

Because the app permits Android's standard system backup, Android may include the app's data in the automatic backup it makes to your own Google Drive, if you have that turned on for your device. That backup belongs to your Google account, is governed by Google's privacy policy, and is not visible to us. You can turn it off in your device's Settings, under System → Backup. If you have it off, your cellar exists only on the device, and uninstalling the app removes it.

On both platforms we have no servers that hold your cellar. We cannot see your wines, your notes, your photos, your buying activity, or who you share with.

Backups you make yourself

The app can export a full backup of your cellar — including label photos — as a file. That file is written wherever you choose to save it, and from that point it is yours to manage: anything you do with it, such as putting it in a cloud drive or sending it to yourself, is outside the app and outside this policy. The export never passes through us.


The AI features and OpenAI

Several features in the app use AI from OpenAI: label scanning, completing a typed-in wine's details, finding a wine's label image online, the Virtual Sommelier, the Virtual Concierge, the where-to-buy panel, similar-wine suggestions, and buying-list sourcing.

These features require you to supply your own OpenAI API key. On iPhone and iPad the key is stored in the iOS Keychain on the device where you entered it. On Android it is stored on that device encrypted with an AES-256-GCM key held in the Android Keystore, hardware-backed where the device supports it. On neither platform is the key transmitted to us, and on neither is it synced to your other devices.

When you use one of these features, your request — the label image, your Sommelier question, or your Concierge question — is sent directly from your device to OpenAI for processing. The response comes back to your device.

For the three buying features, each request sent to OpenAI includes the wine's identity (producer, name, vintage), your chosen currency, and a city name derived from your current location at the moment of the request. The city is used for that query and not stored. We do not see the request, the city, or the response.

When you complete a typed-in wine's details or find its label image online, the wine's identity you entered (producer, name, vintage) is sent to OpenAI — to look up the details, or to locate pages showing the label. No location is involved in either case.

We are not in that loop. We do not see your requests or responses. Your data is handled by OpenAI under OpenAI's API privacy and API terms, and you are OpenAI's customer for billing purposes.

If you do not add an OpenAI key, none of these features run and nothing leaves your device.

Finding a label image online

When you use "Find label online," OpenAI's web search returns links to pages that show the wine. Your device then requests those pages, and the label image on them, directly from the third-party websites — the same kind of request a web browser makes when you visit a site. Those sites see an ordinary web request (such as your IP address and browser identifier); we don't add tracking, and we never receive the page or the image. The image is shown to you for approval and, only if you accept it, saved with your cellar. You are responsible for ensuring you have the right to use any image you add.

Permissions the app requests

Camera — when you tap Scan to photograph a wine label.

Photos — only if you choose to use an existing photo instead of the camera. On Android the app uses the system photo picker, which needs no permission and gives the app only the single image you pick; it never has access to your photo library. On iPhone and iPad the app asks for photo library access for the same purpose.

Location (while using the app) — used in two places:

  • When you log a tasting note or a pour entry on a wine, the app turns your current position into a readable place name so you can later remember where you opened a bottle. On Android this uses the approximate-location permission and records a place name at city level (for example "Neutral Bay, New South Wales, Australia"). On iPhone and iPad the place name may be more precise, down to a street address.

  • When you use a buying feature (where-to-buy, similar-wine, or buying-list sourcing), the app converts your position into a city name (for example "Sydney") that is sent to OpenAI for that query only.

Neither usage stores raw coordinates. The place name from the first path is stored as text on that entry only, and you can edit or delete it at any time. The city name from the second is used per query and not retained. The app does not track your location in the background.

You can grant or revoke any of these at any time — on iPhone and iPad in Settings → The Cellar Schematic, and on Android in Settings → Apps → Cellar Schematic → Permissions.


Cellar sharing

Cellar sharing is a feature of the iPhone and iPad app. When you share a cellar with another person via iCloud, that sharing happens through Apple's CloudKit Sharing. Apple manages the share invitation and the participant access. We do not see the share, the participants, or the cellar contents. Each shared participant uses their own OpenAI API key for AI features — keys are not shared.

The Android app does not currently offer cellar sharing.

Vivino and CellarTracker imports

If you import wines from Vivino or CellarTracker, the import reads a CSV file that you export and place on your own device. The app processes that file locally; nothing is sent to Vivino, CellarTracker, or any other service. We are not affiliated with either company.

Retailers and the buying features

The buying features show you current retailers via OpenAI's web-search results. We do not have affiliate relationships, referral arrangements, or revenue-share agreements with any retailer. We do not receive a commission, a referral fee, or any other payment when you tap a retailer link or when you purchase a wine you found through the app. The retailer's product page opens in an in-app browser using only the URL OpenAI returned — we do not add tracking parameters, referral codes, or analytics tags to the link. What the retailer sees is whatever they would see from any ordinary web visit.

The price you see in the buying-features panel is the retailer's listed price as found by OpenAI's web search. We don't mark it up, mark it down, or filter retailers based on any business relationship. Rankings are by stock availability and price only.

Children's privacy

The Cellar Schematic is intended for adults. The app does not knowingly handle data from anyone under the age legally permitted to consume alcohol in their jurisdiction. The app is rated for adults on both the App Store and Google Play, in line with this.

Changes to this policy

If we make material changes to this policy, the updated version will appear here with a new date. If you continue using the app after the new version is posted, you are agreeing to the updated terms. If you don't agree, you can stop using the app — your cellar data stays where it has always been, in your own iCloud account or on your own device, and is yours to keep regardless.

Contact

For privacy questions or anything else, write to contact@thecellarschematic.com. For help with the app, support@thecellarschematic.com. Both inboxes are read by a real person.