Back to Settings

Privacy Policy

Effective Date: July 25, 2026

Lézé ("we," "us," or "our") provides a wine cellar management service through the Lézé mobile application (the "Service"). End-user Service features are provided in the mobile application. The website (leze.app) provides service information, this Privacy Policy, the Terms of Service, account deletion, and limited account-support features such as sign-in. The Service is governed by the laws of the Republic of Korea and is offered to residents of the Republic of Korea, the United States, the United Kingdom, Canada, Australia, and Japan (collectively, the "Designated Countries"). The supported languages are Korean and English. Users whose primary language is neither Korean nor English (including residents of Japan) may use the English interface at their own discretion. The Service is not offered to residents outside the Designated Countries. By creating an account, you represent and warrant that you reside in one of the Designated Countries. This Privacy Policy is drafted primarily in accordance with the Korean Personal Information Protection Act (PIPA), Article 30. It also addresses the core consumer rights under the data protection laws of the other Designated Countries, including the California Consumer Privacy Act (CCPA/CPRA) and other U.S. state laws, the UK GDPR, Canada's PIPEDA and Quebec Law 25, Australia's Privacy Act 1988, and Japan's Act on the Protection of Personal Information (APPI).

1. Information We Collect

1.1 Account Information

When you create an account, we collect your email address and an encrypted password. If you sign in with Apple or Google, we collect the identifier (provider ID) and email address provided by the respective platform. Authentication is handled securely through Supabase Auth, and for Apple Sign-In we additionally store an Apple refresh token so we can revoke it when you delete your account. A unique in-service handle is also generated automatically for identification; you can change both the display name and handle separately in Community profile settings. For compliance verification at signup we additionally collect: - Country of residence: your selection among the six Designated Countries (Republic of Korea, United States, United Kingdom, Canada, Australia, Japan) - Year of birth: self-attested to the year only (month and day are not collected). Used solely to enforce the U.S. COPPA (13+) and Korean PIPA (14+) minimum-age requirements - Terms and Privacy agreement records: the effective date(s) you agreed to (e.g., 2026-07-10) and the timestamp of your agreement These five fields are kept in a separate, security-restricted storage area accessible only to you; other users cannot see them. The profile data that other users can see (display name, handle, bio, profile image) is stored in a distinct general profile area; the two areas are kept apart by design. Country of residence, year of birth, and your agreement records are never disclosed to other users.

1.2 Wine Cellar Data

You may provide wine names, vintages, producers, regions, purchase details (date, store, price, currency), quantities, tasting notes, personal ratings, consumption records, storage locations, and tags. This data is stored privately by default and is accessible only to you. You can change the audience in Settings > Cellar visibility: - 'Private' (default): Only you can view - 'My followers': Visible to users who follow you - 'Public': Visible to all users, including unauthenticated visitors Independently of your cellar visibility setting, content you voluntarily post to the Community (Wine Bar) — wine name, vintage, producer, tasting structure, score, and notes — becomes visible to other users.

1.3 Photos

When you scan a wine label, that image is sent to the Google Gemini API for label recognition and may be uploaded to cloud storage during the scan. If you save the recognized result as a cellar record, the image URL is linked to that record. General photos uploaded to Memories, Community, or other features are stored for those features and are not sent to the label-recognition AI. Wine-label images may be served through public object URLs, so do not upload images containing personal or sensitive information. We may also use label images as a reference to create a shared representative illustration of that wine (see Section 3).

1.4 Community (Wine Bar) Data

When you use the Community feature, we collect: - Profile information: nickname (display name), handle, bio (up to 160 characters), profile image - Profile visibility: 'Public', 'My followers', or 'Private' (default: 'Public') - Social graph: follower/following lists, block list - Activity data: posts (type, comments, photos), comments, likes - Points and level: point accrual records based on activity, wine level - Report data: when you report content or messages, the reason (spam, inappropriate, misinformation, harassment, impersonation, other) and any details you provide - Post language information Content posted to the Community (nickname, handle, posts, comments, photos) is visible to other users according to your profile visibility setting, and is hidden from users you block. Your email address is not displayed in the Community. Post and comment text may be automatically translated via Google Cloud Translation for users of other languages; translations are cached to avoid repeated processing and are deleted together with the original content.

1.5 Usage Data

We process usage counts for certain features, such as label scans, Sommelier chats, and wine-data collection, on our servers to enforce plan limits. AI Sommelier conversation history is stored to maintain conversational continuity. We have installed a Google Firebase Analytics foundation to analyze use of the mobile application. Firebase Analytics collection is disabled by default and sends no analytics events until separate consent for analytics—independent from advertising consent through AdMob UMP and iOS ATT—has been confirmed. If a user separately consents and enables it, in addition to normalized screen views (screen_view) sent by us, the Firebase SDK may automatically collect app-lifecycle, session, engagement, and purchase events such as first_open, session_start, user_engagement, app_update, and in-app purchase or subscription events, as well as AdMob ad-request, impression, and interaction events for free-plan users. The app-instance and device information (device type, operating system, and app version) and an approximate region (country/city level) derived from the IP address may also be processed, and the signed-in account's opaque internal identifier may be associated, never an email address, nickname, or handle. The IP address is discarded after deriving location and is not logged or stored by Google Analytics. Ad storage, ad user data, and ad personalization consent remain denied regardless of analytics consent, and Firebase Analytics data is not used for Google Ads personalization. We do not send raw URLs, query strings, dynamic identifiers, wine names, search terms, or notes to Firebase Analytics. Firebase Analytics does not run on the website. Only after separate analytics consent has been confirmed, we additionally run Microsoft Clarity inside the mobile application to collect usage-behavior information such as interaction recordings (session replay), heatmaps, and touch interactions. Content typed into input fields, numbers, and email addresses are masked on the device and are never transmitted, and we operate with full-content masking. This information is provided to Microsoft Corporation, which processes it as an independent controller under its own privacy statement. Session replay data is retained for 30 days and aggregated data such as heatmaps for up to 9 months, after which it is automatically destroyed including backups; no per-user deletion path is available. When you withdraw analytics consent, Clarity cookies are deleted and the current session recording ends immediately, and Clarity no longer runs from the next app launch. No account identifier is sent to Clarity, and advertising storage consent signals always remain denied. Clarity does not run on the website.

1.6 Push Notification Tokens and Device Information

If you enable push notifications, we collect your device push token and device platform information. Push notifications are divided into two categories: - Service notifications: drinking window alerts, direct message receipts, report decisions, and similar service-related messages (enabled by default). - Marketing/promotional notifications: weekly digests, seasonal suggestions, premium benefit announcements, and similar promotional content (requires separate consent). In accordance with the Korean Act on Promotion of Information and Communications Network Utilization (Article 50), marketing/promotional notifications require separate prior consent, including additional consent for delivery at night (21:00–08:00). You can disable each category at any time in Settings > Notifications.

1.7 Advertising Data

Ads are displayed inside the mobile application to free plan users. Depending on the device platform and its advertising privacy settings, an advertising identifier may be collected. On Apple devices, we request App Tracking Transparency (ATT) consent and collect the advertising identifier (IDFA) only with your consent. On other supported devices, a device advertising identifier may be processed in accordance with the device's advertising privacy settings and applicable law. These identifiers are used for ad delivery through Google AdMob. In addition, the Google AdMob SDK may collect an approximate (country/city-level) location derived from the device's IP address, together with the app's crash, performance, and diagnostic data, for ad delivery and measurement. This approximate location is separate from the GPS-based Nearby location described in Section 1.11. Premium plan users do not see ads, and advertising identifiers and AdMob-only diagnostic data are not collected for them. However, regardless of plan, a user who separately consents to Firebase Analytics may have the app-usage events, app-instance and device information, and IP-derived approximate region described in Section 1.5 processed.

1.8 Wine Memories and Dinner Plans

When using Wine Memories, we collect title, description, date, location, people present, photos, and a mood tag (one of: celebration, casual, romantic, discovery, special). When using Dinner Plans, we collect title, occasion, guest count, dietary restrictions, and budget range. Wine Memories are stored privately by default and are shown to other users only if you explicitly enable the public option. Dinner Plans are accessible only to you.

1.9 Direct Message (DM) Data

When you use the Direct Message feature, we collect: - Message body (up to 2,000 characters) and timestamp - Conversation participants, conversation creation time, and last-message preview - Read state: last-read message ID and last-read timestamp - DM reception policy: 'Anyone', 'My followers', or 'Mutual follows only' (default: 'Mutual follows only') - Block list and report records Messages are readable only by the sender and recipient. We do not access message content except for clearly defined reasons such as handling reports or meeting legal obligations. When you delete a message it is removed from view immediately, and messages deleted by the sender are permanently removed from our systems.

1.10 Tasting Sessions and Groups

When you use Tasting Sessions or Wine Groups, we collect: - Session details: title, date, location, wine list, participants, notes, scores - Group details: group name, description, member list, join date, role (owner / admin / member) - Event details: schedule, attendance, RSVP status Information shared inside a group is visible only to members of that group.

1.11 Location Information

We collect your device's approximate location (latitude and longitude) only when you choose the "Nearby" sort in the restaurant recommendations (Lézé Table) on the wine detail screen. Location is obtained only after you grant the device's location permission, and it is transmitted to our servers solely to sort nearby restaurants by distance. Location data is not stored in our database and is discarded as soon as the request is processed; transmission records may remain briefly in system logs kept for service operations. If you decline the location permission, every other feature, including region filters, continues to work normally.

2. How We Use Your Information

We use the collected information to: - Provide and maintain the wine cellar management service - Process wine label images through AI for recognition and profiling - Generate personalized wine recommendations via the AI Sommelier - Operate the Community (Wine Bar), manage content, and handle reports - Operate Direct Messages, follows/blocks, tasting sessions, and groups - Send push notifications about drinking windows and wine recommendations - Sort nearby restaurants by distance (Lézé Table) — location processed transiently - Track usage for free/premium tier enforcement and process payments - Serve advertisements to free plan users - After separate analytics consent, measure mobile-app screen, app-lifecycle, session, engagement, and purchase usage and improve the Service - Prevent misuse, monitor security, and improve the Service

3. AI Processing

Wine label images are sent to the Google Gemini API for label recognition. Depending on the configured AI feature, text queries and the structured wine or user context needed to provide that feature are sent to the Anthropic Claude API or Google Gemini API for wine profiles, food pairings, and sommelier recommendations. Wine-related public web data is also gathered via the Perplexity API and Anthropic Claude's web-search tool to enrich wine profiles. AI responses may be cached for up to 30 days to improve performance. We do not use your personal information to train our own AI models. Each AI provider's processing and retention are governed by its API terms and the applicable project settings. In addition, our operators may provide label images to OpenAI (ChatGPT) as a reference input to create a wine's shared representative illustration. An account configured so that inputs are not used for model training is used for this, and the resulting illustration is a Service asset that does not identify any user.

4. Advertising and Tracking Technologies

Ads are served to free plan users inside the mobile application via Google AdMob. Ad networks may collect advertising identifiers, device information, and ad interaction data. Before serving personalized ads, we follow the tracking-consent process required by the device platform. On Apple devices, we request App Tracking Transparency (ATT) consent; if you consent, your advertising identifier (IDFA) is shared with ad networks. You may decline and still see ads, but they will be non-personalized. You can withdraw ATT consent at any time in Settings > Privacy & Security > Tracking. On other supported devices, a device advertising identifier may be shared with ad networks; you can reset the identifier or limit personalized ads in the device's privacy or advertising settings. Premium plan users do not see ads.

5. Sharing and Processing Delegation

We do not sell or share your personal information with third parties for their own independent purposes. We delegate processing to the service providers identified in Section 10 (International Data Transfers) and Section 11 (Processing Delegation Details), only to the extent needed to provide the Service. Their processing is governed by the applicable service terms, data-processing terms or agreements, and privacy policies. We configure and manage these providers to limit processing to the stated purposes and review material changes to the providers we use.

6. Data Security

We implement industry-standard security measures including encrypted data transmission (TLS), secure authentication, database access controls (row-level security), and server request-rate limiting. However, no method of electronic transmission or storage is 100% secure.

7. Data Retention

Your account data, wine cellar records, community activity, direct messages, tasting sessions and groups, and signup compliance records (country of residence, year of birth, Terms/Privacy agreement effective dates and timestamps) are retained while your account is active. AI response caches may be retained for up to 30 days. Sommelier conversation history is retained while your account is active. Direct messages are retained until the sender deletes them and are removed when the sender deletes the message or when either party deletes their account. User- and event-level Firebase Analytics data collected after separate consent is enabled is subject to the Google Analytics property retention setting, which can be configured for up to 14 months for a standard property. Aggregated reports and provider operational data may be subject to Google's separate retention policies. Firebase Analytics collection is currently disabled, so no server-side Analytics data is created. Deleting an account in the native app resets device-local Analytics data and the app-instance identifier; Analytics collection will not be enabled until server-side Analytics deletion integration is complete. You can request account deletion through the app (Settings > Delete Account), on the web (leze.app/delete-account), or via bzr.studio.ko@gmail.com. Account deletion removes the authentication account and database records linked to it. Before deleting the account, the Service attempts to delete referenced label, memory, community, and profile images from storage and, for Apple Sign-In users, to revoke the stored Apple refresh token. Because storage deletion, token revocation, provider caches, backups, and operational logs are handled by separate systems, deletion may not be immediate in every system; those copies are removed or de-identified according to applicable law and each provider's retention policy. Contact bzr.studio.ko@gmail.com if deletion does not complete as expected. Shared representative wine illustrations that we create using label images as a reference contain no personal information and are Service assets; they are not part of the uploaded images destroyed upon account deletion.

8. Your Rights

You have the right to: - Access and export your personal data - Correct inaccurate data in your cellar records - Request deletion of your account and associated data (in-app or via email) - Opt out of push notifications - Withdraw ad-tracking consent or limit personalized advertising in your device's privacy or advertising settings - Withdraw consent for data processing

9. Children's and Minors' Privacy

The Service is an informational wine-cellar application; we do not sell, ship, deliver, or facilitate the sale of any alcoholic beverage. The Service is offered only to residents of the Designated Countries who meet the legal drinking age applicable to their country of residence: - Republic of Korea: 19 years or older (Youth Protection Act) - United States (all 50 states + DC): 21 years or older (National Minimum Drinking Age Act, 23 U.S.C. §158) - United Kingdom: 18 years or older - Australia: 18 years or older - Canada: 18 years or older (Quebec, Alberta, Manitoba) or 19 years or older (other provinces) - Japan: 20 years or older (Civil Code Art. 731 and the voluntary alcohol industry guidelines) At account creation we collect the user's self-attested year of birth and automatically block accounts under 13 years of age (under 14 for Korean residents), consistent with the U.S. Children's Online Privacy Protection Act (COPPA) and the Korean Personal Information Protection Act (PIPA). Verification against the country-specific legal drinking age relies on a self-attestation checkbox in the signup form; we do not perform an automated comparison. If we learn that a user under the applicable legal drinking age has created an account, we will delete the account and related data promptly. Parents or guardians who become aware that their child has created an account may request deletion at bzr.studio.ko@gmail.com. We will delete any personal information collected from a person under 13 without verifiable parental consent.

10. International Data Transfers

Under Article 28-8(2)(3) of the Korean Personal Information Protection Act (PIPA), and as part of providing the Service, the personal data of all Designated Country residents (Republic of Korea, United States, United Kingdom, Canada, Australia, Japan) is transferred to and processed in the United States. By creating an account, residents outside the United States explicitly acknowledge and consent to the transfer of their personal data to the United States. You may object to such transfer by deleting your account or emailing bzr.studio.ko@gmail.com; objection may limit core Service features (sign-in, AI recognition, push notifications, payments).

RecipientCountryItems transferredTiming & methodPurposeRetentionContact
Supabase Inc.USAAccount, cellar, community, DM data, signup compliance records, and uploaded filesReal-time during Service useAuthentication, database, and storage hostingAccount active period, plus provider backup and operational-log retention where applicableprivacy@supabase.io
Vercel Inc.USARequest metadata, session cookies, and IP addressWhen web or app-backend requests traverse the Edge networkWeb and app-backend hostingAccording to project settings and the provider's operational-log policyprivacy@vercel.com
Anthropic PBCUSAText queries and structured wine or user context needed for the requested AI featureReal-time on API callSommelier responses and wine-profile enrichment, including configured web searchAccording to the provider's API terms and applicable project settingsprivacy@anthropic.com
Google LLCUSALabel images, text, community post/comment text when translated, push tokens, advertising identifiers, and—after separate analytics consent—app-usage events, app-instance and device information, and the opaque internal account identifierOn API call, push delivery, advertising request, or encrypted network transfer during app use after separate analytics consentGemini AI, Cloud Translation, AdMob advertising, FCM push, and app-usage analysis through Firebase AnalyticsAccording to the applicable API/product terms and project settings; Analytics user- and event-level data for up to 14 months for a standard propertySee Google Privacy Policy
Perplexity AI Inc.USAWine names and related search queriesReal-time on API callWine-related public web data collectionAccording to the provider's API terms and applicable project settingssupport@perplexity.ai
OpenAI OpCo, LLCUSAWine label images (as reference for creating shared representative illustrations)When operators create illustrationsCreating shared representative wine illustrationsAccording to the provider's service terms, with model-training opt-outprivacy@openai.com
Microsoft CorporationUSAAfter separate analytics consent: in-app interaction recordings (session replay), heatmaps, device information (input values, numbers, and emails are masked on-device and never transmitted; no account identifier is sent)Encrypted network transfer during app use after separate analytics consentApp usability analysis through Microsoft ClarityReplay data 30 days and aggregated data up to 9 months, then automatically destroyed including backupsSee Microsoft Privacy Statement
RevenueCat Inc.USASubscription identifiers and payment stateOn subscription eventsIn-app purchase and subscription managementAccount active period and any longer period required by the provider's records policyprivacy@revenuecat.com
Apple Inc.USAAPNs push tokens and App Store transaction informationOn push or payment eventsiOS push notifications and App Store in-app purchase processingAccording to the applicable Apple service terms and retention policySee Apple Privacy Policy

11. Processing Delegation Details

If a processor is added beyond those listed in Section 10, we will provide notice through a revision of this Policy as required by applicable law. We use the provider's applicable service terms, data-processing terms, or a separate agreement where required, and review provisions concerning: - Restriction on processing personal data outside the stated purpose - Deletion or return of personal data when processing ends - Security safeguards for personal data - Conditions for further sub-processing - Available audit and supervision rights

12. Changes to This Policy

We may update this Privacy Policy from time to time. Every revision is published continuously in the 'Revision history' section at the bottom of this policy, together with its effective date and a before/after comparison; we may additionally announce material changes in the app or by email. A privacy policy is a disclosure document describing how we process personal data, so a revision alone does not require existing users to agree again. Where a change adds a new category of collected data or a new purpose that requires separate consent under applicable law, we request that consent separately in the app.

13. Privacy Officer

The Privacy Officer responsible for overseeing our personal information processing is: Privacy Officer Email: bzr.studio.ko@gmail.com You may contact the Privacy Officer for inquiries, complaints, or damage relief related to personal information. You may also file complaints with the Korea Internet & Security Agency (privacy.kisa.or.kr, 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972).

14. Automated Decisions

Under Article 37-2 of the Korean PIPA, we disclose that we perform the following automated decisions: - AI label recognition (Google Gemini) and automated wine profile generation (Anthropic Claude, Google Gemini, or Perplexity) - AI Sommelier personalized wine and food pairing recommendations - Automatic hiding of community posts upon accumulated reports (threshold-based) - DM reception policy auto-filtering and block-list based content limitation - Free/Premium plan limit enforcement We consider that these automated decisions do not produce legal or similarly significant effects on you. You nonetheless have the right (i) to request an explanation of an automated decision, and (ii) to object if you believe the decision significantly affects your rights or obligations. Send requests to bzr.studio.ko@gmail.com; we respond within 30 days.

15. Country-Specific Rights for Designated Country Residents

In addition to the PIPA-based rights in Section 8, residents of the Designated Countries have the additional rights listed below under their local data protection laws. To exercise any of these rights, email bzr.studio.ko@gmail.com from the email associated with your account using the subject 'Privacy Rights Request'. We verify your identity and respond within 45 days (or any shorter period required by your local law), and do not charge a fee for the first request in any 12-month period. Authorized agents may submit requests on your behalf with written authorization. ■ United States (CCPA/CPRA and other state privacy laws) Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, Rhode Island, and other states with comprehensive privacy laws have: the right to know, right to access and portability, right to correct, right to delete, right to opt out of sale/sharing, right to limit use of Sensitive Personal Information (SPI), right to opt out of automated profiling, and right to non-discrimination. We do not sell personal information for monetary consideration. Personalized advertising through Google AdMob may qualify as 'sharing' under some state laws; you may opt out by declining or withdrawing tracking consent or by limiting personalized advertising in your device's privacy or advertising settings. Sensitive Personal Information (SPI): we collect account credentials and any location names you voluntarily add to Wine Memories. We do NOT collect Social Security numbers, government-issued identifiers, precise GPS coordinates, biometric identifiers, racial or ethnic origin, religious beliefs, union membership, genetic data, or health, sexual orientation, or sex-life information. ■ United Kingdom (UK GDPR / Data Protection Act 2018) UK residents have the rights of access, rectification, erasure, restriction, and portability (Articles 15–20), the right to object to processing (Article 21), and the right not to be subject to a solely automated decision (Article 22). If you are dissatisfied with our response, you may lodge a complaint with the UK Information Commissioner's Office (ICO, ico.org.uk/concerns). ■ Canada (PIPEDA + Quebec Law 25) Canadian residents have the right of access, correction, and withdrawal of consent under PIPEDA. Residents of Quebec additionally have, under Law 25, the right to data portability, the right to an explanation of automated decisions, and the right to request de-identification, and may lodge complaints with the Commission d'accès à l'information du Québec (cai.gouv.qc.ca) or the Office of the Privacy Commissioner of Canada (priv.gc.ca). This Privacy Policy and the Terms of Service are provided in Korean and English only; a French translation is not separately provided. By using the Service, Quebec residents acknowledge that they accept the English text at their own discretion. ■ Australia (Privacy Act 1988 / Australian Privacy Principles) Australian residents have rights of access, correction, use, disclosure, and rights concerning cross-border transfer under APP 1–13. If you are dissatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC, oaic.gov.au). We transfer Australian residents' personal information to the United States; under APP 8, we take reasonable steps to ensure that our sub-processors comply with the APPs. ■ Japan (APPI Act on the Protection of Personal Information) Japanese residents have, under APPI, the rights to receive notice of, disclose, correct, suspend the use of, and suspend the third-party provision of, their retained personal information. We transfer Japanese residents' personal information to the United States; this transfer is disclosed in this Privacy Policy in accordance with APPI Article 28. If you are dissatisfied with our response, you may lodge a complaint with the Japanese Personal Information Protection Commission (PPC, ppc.go.jp). In the event of a data breach, we will report to the PPC as required by APPI.

16. Contact Us

For general inquiries about this Privacy Policy, please contact us at bzr.studio.ko@gmail.com.

Revision history

Each revision is published with its effective date and a before/after comparison so changes are easy to verify.

Effective July 25, 2026Updated the §12 change procedure, and reworded technical jargon across the policy into plain language

§12

Before

"We may update this Privacy Policy from time to time. We will notify you of material changes through the app or via email. Your continued use of the Service after changes constitutes acceptance of the updated policy." — There was no provision for a published revision history where changes could be reviewed.

After

Stated (1) that each revision is published continuously with its effective date and a before/after comparison in the "Revision history" section below, (2) that a privacy policy is a disclosure document, so a revision alone does not require existing users to agree again, and (3) that any change requiring separate statutory consent — such as a new category of collected data or a new purpose — is requested separately in the app. In-app/email notice was reworded from a firm promise to an option we may use in addition for material changes.

intro · §1.1 · §1.4 · §1.5 · §6 · §9 · §10 · §14

Before

Some passages still used internal system storage names and developer terminology (technical abbreviations and jargon), and the descriptions of the website's role and of where analytics run mentioned internal operator-only administration screens that are not offered to users.

After

Reworded into plain language ("a separate, security-restricted storage area", "database access controls", "server request-rate limiting", and similar). References to internal operator-only screens were removed — as before, analytics run only in the mobile application and never on the website. There is no substantive change to what we collect, why we process it, the security measures applied, or your rights.

Effective July 24, 20261.0 launch edition — consolidates the disclosures added during the tester period (after the initial 2026-05-26 version)

§1.3

Before

Label image use was described only as label recognition and linking to cellar records.

After

Added "We may reference label images to produce a shared representative illustration for that wine (see §3)."

§1.4

Before

The community section did not mention translation.

After

Added that post and comment text may be auto-translated via Google Cloud Translation for readers in other languages, that translations are cached to avoid repeat translation, and that they are deleted together with the source text.

§1.5

Before

"We automatically collect information about how you use the Service, including feature usage counts (label scans, sommelier conversations, wine data collection), session data, device information (device type, OS, app version) and search history."

After

Narrowed the scope to "usage counts processed to enforce plan limits" and disclosed two analytics providers that run only where a separate analytics consent — distinct from advertising consent (AdMob UMP / iOS ATT) — is confirmed. (1) Google Firebase Analytics: app lifecycle, session, engagement, purchase and ad-interaction events, app instance identifier, device information and a coarse region derived from IP (the IP itself is not stored); not used for ad personalisation; raw URLs, query strings, wine names, search terms and notes are never sent. (2) Microsoft Clarity: session replays, heatmaps and touch interactions, with typed values, numbers and email addresses masked on-device and never transmitted (full content masking) and no account identifier sent; session replays deleted after 30 days and aggregate data after at most 9 months including backups; withdrawing consent deletes the cookie immediately and stops Clarity from the next launch. Both run in the native app only, never on the public website or the web admin console.

§1.7

Before

The advertising identifier was described per platform ("IDFA on iOS after ATT consent / GAID on Android"), there was no disclosure of coarse location or diagnostic data collected by the AdMob SDK, and the premium carve-out was a single sentence: "Premium subscribers see no ads."

After

Reworded the identifier disclosure platform-neutrally (IDFA on Apple devices after ATT consent; on other supported devices per the device's advertising settings) and **added that the AdMob SDK may collect a coarse location derived from the device IP (country/city level) and app crash, performance and diagnostic data** for ad delivery and measurement, noting that this coarse location is separate from the GPS location in §1.11. The premium carve-out was made specific ("no advertising identifier or AdMob-specific diagnostic data is collected"), and it now adds that, independent of plan, a user who separately consents to analytics may have the §1.5 items processed.

§14

Before

The automated-decision list named only two providers: "AI label recognition and automatic wine profile generation (Anthropic Claude, Google Gemini)."

After

Corrected to "AI label recognition (Google Gemini) and automated wine profile generation (Anthropic Claude, Google Gemini, or **Perplexity**)," so the disclosure names every provider actually in use.

§5 · §11

Before

The processor sections stated that we "conclude a processing agreement under the personal data protection statutes with every processor" and "execute a standard processing agreement or an equivalent DPA."

After

Reworded to match actual practice: each provider's processing is governed by its applicable terms of service, data processing terms or, where needed, a separate agreement, and we review and manage purpose limitation, deletion on termination, sub-processing conditions and available audit rights. The no-third-party clause was also clarified to "we do not provide or sell personal data for a third party's **independent purposes**."

§1.1

Before

Account information listed only email, password, social-login identifiers and the auto-generated handle.

After

Added that sign-up compliance checks also collect **country of residence** (chosen from the six designated countries), **year of birth** (self-declared, year only — month and day are not collected, used solely for the COPPA 13+ / PIPA 14+ minimum-age check) and the **terms/privacy agreement record** (the effective date agreed to and the time of agreement). Also stated that these items are stored in a self-access-only area, kept separate from the profile information visible to other users.

§9

Before

Stated only that "we verify age at account creation by date-of-birth check or self-declaration and block sign-ups under 13," without listing the legal drinking age per country or explaining how it is verified.

After

Stated that the Service is an informational wine record app that **never sells, delivers or brokers alcohol**, published the legal drinking age for each designated country, and clarified precisely what is checked: at sign-up we **automatically enforce only the COPPA 13+ / PIPA 14+ (Korean residents) minimum age**, while the per-country drinking age **relies on a self-attestation checkbox and is not compared automatically**.

intro · §1.6 · §4 · §8 · §15

Before

Service scope and device-settings guidance named specific platforms ("iOS and Android", "APNs/FCM tokens", "iOS ATT settings / Android advertising ID settings", "iOS: Settings > Subscriptions / Android: Google Play > Subscriptions"), and the website was described as operating "for informational purposes only."

After

The same content was reworded platform-neutrally ("device push token", "your device's privacy or advertising settings", "the subscription menu of the app market you paid through"). The website's role now includes account deletion and **limited account-support features such as sign-in**, and the web admin console for authorised internal operators is explicitly not an end-user web service. Across these five sections there is no substantive change to collected items, purposes or user rights.

§1.11

Before

(no such section)

After

New. Coarse device location (latitude/longitude) is collected only when the "nearby" sort is selected in the wine detail restaurant recommendations (Lézé Table), only if device location permission is granted, and is sent to the server transiently for distance sorting alone. It is never stored in the database and is discarded immediately after the request; declining permission leaves every other feature, including region filters, fully usable.

§2

Before

The purposes list contained no location or analytics entry.

After

Added "providing distance-sorted nearby restaurants (Lézé Table) — transient processing of location" and "measuring mobile app screen, lifecycle, session, engagement and purchase usage after separate analytics consent, and improving the Service."

§3

Before

OpenAI was not listed among AI processors.

After

Added that an operator may supply label images to OpenAI (ChatGPT) as reference input to produce the shared illustration, that an account configured to exclude inputs from model training is used, and that the resulting illustration is a service asset which does not identify any individual user.

§7

Before

The retention list omitted the sign-up agreement record, and no rule covered deletion of illustration assets or retention of analytics data.

After

Stated (1) that the retention list includes the **sign-up terms/privacy agreement record (country of residence, year of birth, time and version of agreement)** and that deleting your account automatically destroys this record together with all other data linked to the account, (2) that a shared representative illustration produced by referencing label images is a service asset containing no personal data and is therefore outside the uploaded-image deletion scope when an account is deleted, (3) that analytics data collected after consent follows the Google Analytics property retention setting (up to 14 months for standard properties), with Google's own retention policy possibly applying to aggregate reports, and (4) that deleting an account resets on-device analytics data and the app instance identifier.

§10

Before

The cross-border processor list held six entries (Supabase, Anthropic, Google, Perplexity, RevenueCat, Apple); the Supabase entry did not mention the agreement record, and the Google entry covered neither translation source text nor analytics data.

After

Added three processors — Vercel Inc. (United States — request metadata, session cookies and IP for web/app backend hosting; 30-day access logs), OpenAI OpCo, LLC (United States — label images, producing the shared illustration) and Microsoft Corporation (United States — session replays, heatmaps and device information after separate analytics consent; 30 days for replays, up to 9 months for aggregates) — added the sign-up agreement record to the Supabase entry, and extended the Google LLC entry with "community post and comment text (when translated)" and "app usage events, app instance, device information and internal account identifier after separate analytics consent", the Cloud Translation and Firebase Analytics purposes, and retention (up to 14 months for standard properties).

Effective May 26, 2026Initial version

Initial version (nothing to compare)