Skip to main content
VinoMemo
VinoMemo

Privacy Policy

The French version is the legally binding reference. This English text is provided for your convenience; the French reference prevails in case of conflict.

Scope

Without a VinoMemo account, tasting notes and their photos remain in the device's Local Library. Online backup begins only when you turn on Backup & Sync.

Even without an account, VinoMemo and its providers may process the technical data required for purchases, diagnostics, updates, website delivery, and measurement of its audience and performance.

Controller and contact

Sébastien Kempf, sole proprietor, 2 Square Arago, 78330 Fontenay-le-Fleury, France, is the controller for the processing described on this page.

Contact: contact@vinomemo.app. No data protection officer has been appointed.

Purposes, data, and legal bases

PurposeData and sourceRecipientsLegal basisRequirement and consequence
Create the account and authenticate the userEmail address and identity provided by the user or returned by Apple or GoogleSupabase; Apple or Google as separate controllers if their sign-in service is chosenPerformance of the contractRequired for Backup & Sync. The application remains usable with a Local Library without an account.
Back up and synchronizeNotes, wine information, and photos provided by the userSupabasePerformance of the contractRequired for the requested service. Without this data, the relevant items are not synchronized.
Deliver and restore purchasesTransaction, store, and entitlement identifiers from Apple or GoogleRevenueCat; Apple or Google as separate controllersPerformance of the contract when a purchase is linked to a VinoMemo account; legitimate interest in delivering and restoring the purchase in other casesRequired to deliver or restore entitlements. The basic application remains usable without a purchase.
Detect technical incidentsAutomatically collected crash events and non-fatal diagnostics, with personal fields scrubbed by default and the IP address removedSentryLegitimate interest in maintaining the application's reliabilityAutomatic collection with no opt-out. VinoMemo configures Sentry not to send note content.
Deliver updatesOperating system, platform, project identifier, runtime version, and a random token specific to the installationExpo / EAS UpdateLegitimate interest in maintaining and securing the applicationAutomatic processing required to check for and deliver an update.
Deliver and secure the websiteIP address, requested URL, date, time, and other request or technical log dataVercelLegitimate interest in delivering and securing the siteAutomatic technical processing when visiting the site.
Measure website audience and performancePublic page viewed, UTM parameters in the URL, technical browser and device information, loading measurements, and a temporary session identifier derived by VercelVercel Web Analytics and Speed InsightsLegitimate interest in understanding usage and correcting performance issuesAutomatic collection during a visit. The current configuration creates no cookie or persistent identifier in the browser.
Respond to rights requests and support requestsName, email address, technical headers, subject, content, attachments, and information the sender chooses to provide; for a rights request, the right exercised, dates, outcome, and proportionate proof of identity if there is reasonable doubtVinoMemo; Cloudflare for inbound routing; Google/Gmail for the inbox; Brevo for SMTP repliesLegal obligation for rights requests; legitimate interest in responding to support requestsSupport email is optional, but a reply address and relevant information are required to respond. A rights request requires enough information to identify the account and the request.

Recipients and providers

  • Supabase manages accounts, authentication, synchronized notes, and photos.
  • RevenueCat manages purchase identifiers and entitlements.
  • Sentry receives crash events and non-fatal diagnostics.
  • Expo delivers application updates through EAS Update.
  • Vercel hosts the website, processes its technical logs, and provides Web Analytics and Speed Insights to measure audience and performance.
  • Cloudflare routes incoming email and processes routing metadata. Cloudflare states that Email Routing does not store message content.
  • Google/Gmail hosts the inbox that receives requests sent to contact@vinomemo.app.
  • Brevo relays replies from this inbox by SMTP. Brevo also receives aggregate DMARC reports sent to the domain; these reports concern email authentication, not the content of received requests.

Apple and Google also process data as separate controllers for their authentication and store services under their own policies.

International transfers

  • Supabase hosts the VinoMemo project in the US us-east-2 region. Its DPA forms part of its terms and includes the European Union's Standard Contractual Clauses.
  • RevenueCat stores data in the United States. Its DPA forms part of the contract and includes the Standard Contractual Clauses.
  • Sentry processes events in its US region.
  • Expo may process EAS Update data in the United States and other countries.
  • Vercel runs VinoMemo's Functions in Paris. Its CDN, builds, logs, account, support, and subprocessors may operate in other countries.
  • Cloudflare, Inc. may process routing metadata outside the European Economic Area. Cloudflare states that it uses the EU-U.S. Data Privacy Framework and, depending on the transfer, Standard Contractual Clauses and supplementary measures.
  • Google/Gmail may process email in several countries.
  • Brevo states that it hosts its main services in France and Belgium and uses subprocessors in the European Union, the United States, and other countries. Brevo states that it uses Standard Contractual Clauses, supplementary measures, and, where applicable, the EU-U.S. Data Privacy Framework.

Retention periods

  • Synchronized account, notes, and photos: until you delete them or delete the account. The Supabase Free project uses neither scheduled backups nor point-in-time recovery.
  • Sentry: thirty days. An event not linked to an account may remain until this period expires after account deletion.
  • RevenueCat: VinoMemo requests deletion of the customer record when applicable. RevenueCat does not publish a fixed execution or backup purge period for this operation.
  • Expo / EAS Update: for the time reasonably necessary to provide the service, under Expo's published criterion.
  • Vercel Web Analytics: the Hobby dashboard retains one month of measurements. Vercel deletes the temporary identifier used to distinguish a visitor session after twenty-four hours.
  • Vercel Speed Insights: seven days of measurements on the Hobby plan.
  • Vercel technical logs: for the period applicable to hosting logs on the Hobby account.
  • Support: two years after the request is closed, unless an unresolved dispute or legal obligation requires longer retention.
  • Rights requests: three years after closure for the request log and proof of the response. Any additional proof of identity is deleted after verification and within thirty days at the latest.
  • Provider email and logs: Gmail automatically deletes items placed in the trash after thirty days. Cloudflare, Google, and Brevo may retain their technical logs for their own service periods; no published period could be verified for Cloudflare routing logs, Brevo SMTP transit, or Brevo DMARC reports.

Account deletion

Deleting the account irreversibly erases the account data, notes, and photos held by VinoMemo in Supabase.

You separately choose whether to keep the Local Library on your device or erase it. Keeping it locally does not recreate the account or maintain Backup & Sync.

VinoMemo separately starts revocation of Apple authorization and a RevenueCat customer-record deletion request when they apply. A temporary failure may delay these operations without blocking deletion of the Supabase account. VinoMemo does not promise to revoke Google authorization.

Sentry events that cannot be linked to the account may remain until their thirty-day retention period expires.

Apple and Google may retain transaction data that they process as sellers or separate controllers under their own obligations.

Your rights

Subject to the GDPR, you may request access to, rectification or erasure of, or restriction of processing of your data. The right to data portability applies to processing based on the contract. The right to object applies to processing based on legitimate interest.

Send your request to contact@vinomemo.app. VinoMemo responds within one month of receiving it. This period may be extended by two months when justified by the complexity or number of requests; VinoMemo will inform you within the first month.

You may also lodge a complaint with the CNIL: https://www.cnil.fr.

Cookies and browser storage

In the current configuration, Vercel Web Analytics and Speed Insights create no cookie or persistent identifier in localStorage, sessionStorage, or IndexedDB. Vercel may still process requests, a temporary session identifier, audience and performance measurements, and the technical logs needed for these services. VinoMemo does not use this data for advertising or to track a person across multiple sites.

Automated decisions and profiling

VinoMemo makes no decision based exclusively on automated processing and carries out no profiling.

Changes

VinoMemo updates this page when processing changes and provides the information required by the GDPR when the change requires it.

Last updated: August 27, 2026.