Privacy Policy — SommelAI (v1.0)

Last updated: April 20, 2026


1. Overview

SommelAI, LLC (“SommelAI,” “we,” “us,” “our”) provides an AI-powered wine discovery and recommendation application. This Privacy Policy explains how we collect, use, store, and share information when you use the SommelAI mobile application (the “App”).

By using the App, you acknowledge and agree to the practices described in this Privacy Policy.


2. Account Types

The App supports three account types:

When you convert from an anonymous account to an email or Apple Sign-In account, your existing data (scans, reviews, cellar items) is preserved and linked to your new account.


3. Information We Collect

a. Account Information

When you create an account, we collect:

b. Taste Profile Information

During onboarding or at any time in the App, you may provide:

c. User Content

You may submit content through the App, including:

d. Images

Images you upload are processed for optical character recognition (OCR) and wine identification. Images are stored both on your device and in our cloud storage. We may retain images to improve our services unless you request deletion.

e. Usage and Analytics Data

We automatically collect:

We use PostHog for analytics. PostHog anonymizes IP addresses by default. Your Supabase user ID is linked to your PostHog analytics profile for product improvement purposes.

f. Identifiers

Authentication tokens are stored securely on your device using iOS Keychain.


4. Information We Do Not Collect

We do not collect:


5. How We Use Information

We use the information we collect to:


6. AI Processing and Model Training

We use third-party AI processing services to:

These AI processing services act as data processors on our behalf and handle your data according to their own policies and agreements with us. We select providers whose terms state that API inputs are not used to train their general-purpose models by default. For details on their specific data handling practices, consult the current terms of the service providers listed in Section 7.

Your interactions, images, and content may be used to train and improve SommelAI’s own models and algorithms. Where possible, these processes use anonymized or de-identified data. Aggregated or derived data is not reversible to individual users.


7. Sharing of Information

a. Aggregated and De-Identified Data

We may share, license, or sell aggregated, anonymized, or de-identified data to third parties, including wine distributors, suppliers, and industry partners. This data does not identify individual users and cannot reasonably be used to do so.

Examples of aggregated data we may share or sell include:

b. Service Providers

We use the following third-party service providers to operate the App:

Provider Purpose Data Processed
Supabase Database, authentication, file storage Account information, user content, images
AI processing services OCR, wine identification, recommendations, taste profiles Images, prompts, wine lists, taste preferences
Resend Transactional email delivery Email addresses
PostHog Product analytics and error tracking Usage events, device metadata, user IDs
Apple Identity verification (Apple Sign-In) Apple identity tokens
Cloudflare Hosting for legal and support pages No user data (static content only)

These providers process data on our behalf and are contractually obligated to protect your information.

c. Legal Requirements

We may disclose information if required by law, regulation, subpoena, or legal process, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.


8. Data Storage

a. Cloud Storage

Your account information, content, and usage data are stored in our Supabase database. Images are stored in private Supabase Storage buckets with access controls that ensure you can only access your own files.

b. On-Device Storage

The App stores certain data locally on your device:

Data stored on your device persists across app updates but is removed if you delete the App.


9. Data Retention


10. Data Deletion

You may request deletion of your account and associated data by emailing support@thesommelai.com with the subject line “Data Deletion Request.” Include your Account ID (found in the Profile tab of the App).

Upon receiving a verified request, we will delete:

Deletion does not include:

We aim to process deletion requests within 30 days.


11. Your Privacy Rights

California Residents (CCPA)

If you are a California resident, you have the right to:

We do not sell personal information as defined by CCPA. We may share, license, or sell aggregated, anonymized, or de-identified data that does not constitute personal information under California law. See Section 7(a) for details.

To exercise your rights, contact us at support@thesommelai.com.

Other Jurisdictions

If you are located in a jurisdiction with applicable data protection laws, you may have additional rights regarding access, correction, portability, or deletion of your data. Contact us to exercise any applicable rights.


12. Children’s Privacy

The App is intended solely for users who are at least 21 years old. We do not knowingly collect personal information from anyone under 21. If we learn that we have collected information from someone under 21, we will delete it promptly. If you believe we have information from someone under 21, please contact us at support@thesommelai.com.


13. Age Verification

We verify your age through self-attestation:

We do not use independent third-party age verification services.


14. Notifications

The App uses local notifications only. Notifications are scheduled and delivered entirely on your device using iOS notification APIs. We do not use any third-party push notification services.

Notification types include:

You can disable notifications in your device’s Settings at any time.


15. Data Security

We use reasonable administrative and technical safeguards to protect your information, including:

No system is completely secure. If you become aware of a security vulnerability, please contact us at support@thesommelai.com.


16. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App or by other reasonable means. The “Last updated” date at the top indicates when the policy was last revised.

Continued use of the App after changes constitutes acceptance of the updated policy.


17. Contact

Questions, concerns, or requests:

support@thesommelai.com


Document Version: 1.0