Privacy Policy
Last updated: 9 September 2026
1. Controller
The controller is ProWebSolutions GmbH, Aurelienstr. 48, 04177 Leipzig, Germany. Email: info@myvinolog.com, phone: +49 176 10347813.
2. Account and service data
When you register and use the service, we process your name, email address, a non-reversible password hash, verification and reset data, and the storage locations, wines, stock levels, ratings and notes you create. This is necessary to provide your MyVinoLog account (Art. 6(1)(b) GDPR).
3. Server logs, session and app login
For secure delivery, the server and hosting provider process data such as IP address, time, requested URL, referrer, browser, operating system and technical error data. This supports operation, troubleshooting and abuse prevention under Art. 6(1)(f) GDPR. A single technical deletion period is not currently fixed for all server and error logs; records are retained only while the relevant operational or security purpose continues. A necessary session cookie maintains login and language. In the Android app, secure login tokens that rotate when used can keep the user signed in for up to 90 days. The server stores the token hash and a pseudonymised user-agent hash for abuse detection.
4. Email delivery
Confirmation and password emails are sent through our SMTP mail server. Recipient address, display name, message content and technical delivery data are processed under Art. 6(1)(b) GDPR.
5. AI-assisted wine-label recognition
When you deliberately start an AI scan, the selected label images and analysis prompt are sent through the OpenAI API to OpenAI Ireland Ltd. MyVinoLog sets store:false on the Responses API so that no Response Application State is stored for the feature. OpenAI states that API inputs and outputs are not used for model training by default unless the API account holder opts into data sharing. Content and technical metadata may nevertheless be retained in abuse and security logs for up to 30 days by default; legally required longer retention and specific image-safety reviews remain possible. OpenAI documents adequacy decisions or Standard Contractual Clauses for necessary international transfers in its current Data Processing Addendum. Do not photograph people, addresses or private content. The legal basis is the requested feature under Art. 6(1)(b) GDPR.
6. AI results
Recognised data may be incomplete or inaccurate. It is placed only in the form and becomes part of your account only after you review and explicitly save it. Scan calls are counted per user to prevent misuse; individual count records are deleted after the technical review period.
7. Google AdMob and consent management
Google AdSense is currently disabled on the website and no AdSense script is loaded. In the Android app we use Google Mobile Ads (AdMob) for voluntarily started rewarded ads. The reward is one AI label scan; manual wine entry remains available without advertising. Before the Mobile Ads SDK is initialised, Google User Messaging Platform (UMP) updates consent information, displays a required consent form and checks whether ads may be requested. AdMob and UMP may process the Advertising ID and other device identifiers, IP address and an approximate location derived from it, app interactions, and technical and diagnostic data for ad delivery, measurement and fraud prevention. In the EEA, UK and Switzerland, consent-requiring processing is managed through UMP. Users can reopen their choice through the privacy options displayed in the app. Where required, the legal basis is Art. 6(1)(a) GDPR together with applicable device-storage law.
8. Recipients and service providers
Where required for a feature, recipients are our hosting provider, our SMTP server and the recipient’s email provider, OpenAI Ireland Ltd. for AI scans, Google for optional Google sign-in, and Google AdMob and UMP in the Android app. Roles and contractual terms depend on the service; processors are engaged under Art. 28 GDPR where that role applies. No internal MyVinoLog user ID is transferred to Google for rewarded ads.
9. Retention and account deletion
Account and cellar data is retained until account deletion or as long as legal duties require. Deletion removes the account, storage locations, personal wines, stock, ratings, notes, movements, scan counters, login tokens and reset tokens; shared wine master data without an account link may remain. Password accounts can delete directly after password confirmation. Accounts using Google sign-in are directed from account settings to the external deletion process, where ownership is checked using the registered email address. Reset links are valid for 24 hours and once. Independent server, security, mail or provider logs may remain until their operational, security or legal purpose ends.
10. Your rights
Subject to statutory requirements, you have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent for the future. You may also lodge a complaint with a data protection authority.
11. Security and changes
We use appropriate technical and organisational safeguards and update this policy when features, providers or legal requirements change.
12. Google sign-in
You may optionally sign in through Google Identity Services on the web or Android Credential Manager in the app. The Google account ID (sub), verified email address and name are processed. MyVinoLog stores the Google account ID for secure matching, but no Google access or refresh tokens. No permissions for Gmail, Drive, contacts, calendar or location are requested.
13. Apple sign-in and Private Relay
In the iOS app you may sign in with Apple. We verify Apple’s signed identity token, including issuer, audience, expiry, nonce and the unique Apple account ID (sub). We store the Apple account ID and the email address verified by Apple; access and refresh tokens are not retained. If you choose Hide My Email, we receive an Apple Private Email Relay address. Existing accounts must first sign in with their current method before Apple can be linked. When an Apple account is deleted, we revoke the Apple authorization before removing account data.
14. iOS advertising, ATT and explicit AI consent
The iOS app may also use Google AdMob for rewarded ads. UMP is consulted before the Mobile Ads SDK. Where required, iOS additionally asks through AppTrackingTransparency (ATT) whether a device identifier may be used across apps for ad personalisation and measurement; refusing does not prevent use of the app or contextual advertising. Before label images are first sent to OpenAI, the iOS app presents a separate explicit consent explaining the recipient and purpose. You can reset that decision in Account for future scans; without consent, no image is sent to OpenAI. If an ad cannot be loaded for technical reasons, the scan remains available.
15. Usage statistics and operator overview
In addition to short-term abuse prevention, we store the account ID, UTC timestamp, outcome status, model and, when reported by OpenAI, token counts for each started AI call. These records support usage and cost monitoring of the service and are retained until account deletion. Only the authorised operator sees account identification, linked sign-in methods and aggregated usage. Statistics contain no images, prompts, AI response content or label text; the operator overview shows no private wines, storage locations, prices, ratings or notes.