sommelai
How it worksStoryWhy nowFor the tradeGet the app
Legal

Privacy

LAST UPDATED · July 8, 2026

1. Overview

SommelAI, LLC (“sommelai,” “we,” “us,” “our”) provides an AI-powered wine discovery and recommendation application. This Privacy Policy explains how we collect, use, store, and share information when you use the sommelai mobile application (the “App”) and our website at thesommelai.com (the “Website,” and together with the App, the “Services”).

By using the Services, you acknowledge and agree to the practices described in this Privacy Policy.

2. Account Types

The App supports two account types:

  • Email accounts are created when you sign up with an email address and password. Email accounts require you to provide your email, display name, date of birth, and gender.

  • Apple Sign-In accounts are created using Apple’s Sign in with Apple service. Apple provides us with your email address (or a private relay address if you choose to hide your email). You also provide your display name, date of birth, and gender during sign-up.

3. Information We Collect

a. Account Information

When you create an account, we collect:

  • Email address (for email and Apple Sign-In accounts)
  • Password (for email accounts only; stored securely using industry-standard hashing)
  • Display name
  • Date of birth (used to verify you are at least 21 years old)
  • Gender (optional: Woman, Man, Non-binary, or Prefer not to say)
  • Marketing opt-in preference (whether you want to receive wine tips and recommendations)

b. Taste Profile Information

During onboarding or at any time in the App, you may provide:

  • Wine experience level (beginner, casual, enthusiast)
  • Budget preferences
  • Preferred wine varietals
  • Flavor preferences (liked and disliked flavor notes for each varietal)
  • Free-text wine preferences

c. User Content

You may submit content through the App, including:

  • Images of wine menus
  • Images of wine bottle labels
  • Wine reviews (such as ratings, flavor notes, comments, and dining location)
  • Cellar inventory entries (such as wine details, quantity, price paid, and purchase location)
  • Restaurant or venue names
  • Free-text prompts for wine recommendations

d. Images

Images you upload are processed to read and identify the wines they contain. Images are stored both on your device and in our cloud storage. We may retain images to improve our services unless you request deletion.

e. Usage and Analytics Data

We automatically collect:

  • Feature usage events (such as scans, recommendations, reviews, and navigation)
  • App interactions and session data
  • Error and crash diagnostics
  • Performance metrics (e.g., scan duration, recommendation response time)
  • Device type, operating system version, and app version

We use a third-party analytics provider to collect this information. Your account identifier is linked to your analytics profile for product-improvement purposes.

f. Identifiers

Each account is assigned a unique identifier (UUID) that links your activity and content within the App. Your account is also identified by your email or Apple ID. Authentication tokens are stored securely on your device.

g. Website Data

When you visit our Website, we and our analytics providers automatically collect:

  • Page views, referring URLs, and campaign parameters (such as UTM parameters and ad-click identifiers)
  • Clicks and interactions with page elements
  • Performance metrics (such as page-load and responsiveness measurements)
  • Browser type, device type, and operating system
  • IP address, used to determine approximate location (such as country or region) and to detect automated or fraudulent traffic
  • Events indicating interest, such as clicking a link to the App Store or submitting a form

The Website uses first-party cookies and similar technologies for these analytics purposes. You can control or block cookies through your browser settings.

We design our Website analytics to be privacy-protective:

  • We honor Global Privacy Control (GPC) and similar universal opt-out signals. If your browser sends a GPC signal when you visit, no analytics are initialized at all — we set no analytics cookies and collect no analytics events for that visit.
  • We do not record your session. We do not use session replay and do not capture your keystrokes or the values you type into forms.
  • We do not identify anonymous visitors. Analytics events do not include your name, email address, or other information that directly identifies you, and we do not create identified visitor profiles for anonymous Website visitors.

We do not use Website analytics data for cross-context behavioral advertising.

h. Business and Contact Information

If you submit an inquiry through a form on our Website (such as a business or trade inquiry), we collect the information you provide, which may include your name, company, role, email address, and message. We use this information to respond to and manage your inquiry, and we retain it for as long as needed for that purpose and to manage any resulting business relationship. Form submissions are processed and stored using third-party service providers on our behalf.

4. Information We Do Not Collect

We do not collect:

  • Precise geolocation or GPS coordinates
  • Contacts or address book data
  • Phone numbers
  • Payment or credit card information
  • Health or fitness data
  • Your browsing activity on websites and apps that are not ours

5. How We Use Information

We use the information we collect to:

  • Operate and improve the App
  • Verify your age (21+)
  • Create and manage your account
  • Generate personalized wine recommendations based on your taste profile
  • Process the menu and bottle label images you submit
  • Store and display your wine cellar inventory
  • Send you reminders and notifications related to your activity
  • Send transactional emails (password reset, email confirmation, email change notifications)
  • Send marketing emails if you opt in
  • Analyze usage patterns and improve features
  • Diagnose errors and performance issues
  • Improve and develop our services and models
  • Generate aggregated and anonymized insights

6. Automated Processing and Service Improvement

We use automated processing to operate core features of the App, such as interpreting the images and text you submit and generating personalized recommendations and content. Some of this processing is performed by third-party service providers on our behalf.

These providers act as data processors, process your data only as needed to provide their services to us, and are contractually obligated to protect it.

We may also use your interactions, content, and other data to operate, improve, and develop our own services, features, and models. Where practicable, we use anonymized or de-identified data for these purposes, and any aggregated or derived data is not reversible to individual users.

7. Sharing of Information

a. Aggregated and De-Identified Data

We may share, license, or sell aggregated, anonymized, or de-identified data to third parties, including business and commercial partners.

For purposes of this Policy:

  • “Aggregated data” means information that relates to a group or category of users, from which individual identities have been removed, and that is not linked or reasonably linkable to any individual or device.
  • “De-identified data” means information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular individual or device.

Before we share, license, or sell any such data, we take commercially reasonable measures to ensure it is aggregated and/or de-identified so that it does not identify any individual user and cannot reasonably be associated with one. Demographic information (such as age and gender) is shared only in the form of aggregate distributions across groups of users, never as individual-level records. We publicly commit to maintaining and using this data only in de-identified or aggregated form, and we will not attempt to re-identify it, except as reasonably necessary to test that our de-identification measures are effective. Where we provide such data to a third party, we contractually require that the recipient not attempt to re-identify it.

b. Service Providers

We use third-party service providers to operate the Services. These include:

  • Cloud infrastructure, database, and storage providers
  • Data processing providers
  • Product and website analytics providers
  • Transactional email providers
  • Form submission and productivity providers
  • Apple (for Sign in with Apple identity verification)

These providers process data on our behalf, only as needed to provide their services to us, and are contractually obligated to protect your information.

c. Legal Requirements

We may disclose information if required by law, regulation, subpoena, or legal process, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

8. Data Storage

a. Cloud Storage

Your account information, content, and usage data are stored in our cloud database. Images are stored in private cloud storage with access controls that ensure you can only access your own files.

b. On-Device Storage

The App stores certain data locally on your device:

  • Authentication tokens (in your device’s secure storage)
  • Bottle label photos (for offline access and sharing)
  • Notification schedules

Data stored on your device persists across app updates but is removed if you delete the App.

9. Data Retention

  • Account information and user content are retained until you delete your account or the relevant content, or otherwise request deletion.
  • Images are retained until you delete them, delete your account, or request deletion.
  • App analytics data is retained for as long as needed for product-improvement purposes.
  • Website analytics data is retained for a limited period in accordance with our analytics provider’s standard retention settings (currently up to 12 months), after which it ages out.
  • Business and contact information you submit through a Website form is retained for as long as needed to respond to your inquiry and manage any resulting business relationship.
  • Aggregated, anonymized, or model-derived data may be retained even after your account or content is deleted.

10. Data Deletion

You can delete your account and all associated data at any time directly in the App: go to the Profile tab and select “Delete account,” then confirm. Deletion is immediate and permanent, and removes:

  • Your account and authentication records
  • Your profile, preferences, and taste data
  • Your scans, reviews, tasting notes, cellar items, and bottle scans
  • Your images stored in our cloud storage
  • Your analytics identity

You may also email us at [email protected] to request deletion.

Deletion does not include:

  • Anonymized, aggregated, or model-derived data
  • Data that has already been incorporated into aggregate analytics
  • Data we are required to retain for legal or compliance purposes

11. Your Privacy Rights

California Residents (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Opt out of the “sale” of personal information

We do not sell personal information as defined by CCPA. We may share, license, or sell aggregated, anonymized, or de-identified data, which does not constitute personal information under California law. We do not attempt to re-identify such data and contractually require recipients not to do so. See Section 7(a) for details.

We do not sell or share personal information for cross-context behavioral advertising. We also honor Global Privacy Control (GPC) and similar universal opt-out signals; see Section 3(g) for how this works on our Website.

To exercise your rights, contact us at [email protected].

Other Jurisdictions

If you are located in a jurisdiction with applicable data protection laws, you may have additional rights regarding access, correction, portability, or deletion of your data. Contact us to exercise any applicable rights.

12. Children’s Privacy

The App is intended solely for users who are at least 21 years old. We do not knowingly collect personal information from anyone under 21. If we learn that we have collected information from someone under 21, we will delete it promptly. If you believe we have information from someone under 21, please contact us at [email protected].

13. Age Verification

We verify your age through self-attestation:

  • When you first open the App, you must confirm that you are at least 21 years old before accessing it.
  • When you create an account, you must provide your date of birth. The App validates that you are at least 21 before allowing account creation.

We do not use independent third-party age verification services.

14. Data Security

We use reasonable administrative and technical safeguards to protect your information, including:

  • Secure authentication
  • Password hashing using industry-standard algorithms
  • Secure token storage on your device
  • Private storage with access controls
  • HTTPS encryption for all data in transit

No system is completely secure. If you become aware of a security vulnerability, please contact us at [email protected].

15. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Services or by other reasonable means. The “Last updated” date at the top indicates when the policy was last revised.

Continued use of the Services after changes constitutes acceptance of the updated policy.

16. Contact

Questions, concerns, or requests:

[email protected]

Document Version: 2.3

sommelai
StoryWhy nowFor the tradePrivacyTermsSupport
© 2026 SOMMELAI