1. What Cellarune processes and why
| Data / provider | Purpose and basis | Choice | Retention |
|---|---|---|---|
| Cellar Data on device and Apple iCloud/CloudKit | Store and sync the cellar; provide your requested feature | Local storage is required; iCloud sync is optional | Until you delete records or local data; iCloud copies and backups follow Apple settings and retention |
| Sign in with Apple and Firebase Authentication identifiers, Apple-supplied email, security/device data, and IP address | Cellarune Account, managed AI, deletion, security, and abuse prevention | Optional for cellar management and Store Subscription features; required for managed AI and account deletion | Until account deletion; provider backups or legally required records may take longer |
| Apple purchase history and RevenueCat subscription, installation, technical, and linked Firebase user ID data | Process purchases, validate Premium, restore access, and meet billing obligations | Optional unless you purchase Premium | Under Apple/RevenueCat terms and legal duties; Cellarune requests RevenueCat deletion with account deletion |
| Label Photos and bottle format via authenticated Firebase Functions to Google Gemini | Smart Scan and Initial Drinking Window Estimate; your Third-Party AI Permission and requested feature | Optional; refusal cancels before the network request and uses no AI allowance | Not intentionally stored in Firestore or Cellarune logs; Google's paid-service security, abuse, and legal controls apply |
| Wine Name, Producer, vintage, origin, varietals, wine type, and format via Firebase to Gemini | Drinking Window Update; your Third-Party AI Permission and requested feature | Optional; refusal cancels before the network request | Not intentionally stored in Firestore or Cellarune logs; Google's paid-service controls apply |
| Firestore quotas, Premium state, bans, expiry metadata, and deletion cooldown marker | Allowances, security, and fraud prevention | Required for managed AI | Account records until deletion; daily counters about 30 days, monthly about 93 days, cooldown 30 days |
| Google Cloud operational metadata: request ID, operation, status, latency, usage, token/image counts, and error category | Reliability, support, security, and cost control; legitimate interests | Required for managed AI | Production Cloud Logging default bucket: 30 days |
| Firebase Analytics app-instance, app/device, coarse product-use, lifecycle, and approximate-location data | Product measurement; consent | Optional and off by default | Two months; disabling resets Cellarune analytics state and stops future collection |
| Website IP, browser/device, page request, and security data processed by Microsoft Azure | Deliver and secure this website; legitimate interests | Required to load the site; email is an alternative | Azure operational/security settings and Microsoft terms; no Cellarune advertising profile |
“Cellar Data” includes your cellars, shelves, slots, bottles, Label Photos, tasting notes, wishlist, and bottle events. Cellarune's Firebase backend does not own or store your cellar as a collection. Cellarune does not sell personal data, show third-party advertising, or track you across other companies' apps.