Skip to document
Wine Back to Wine ↗

WINE · YOUR INFORMATION

Privacy Policy

Your cycle information is personal. This policy explains what Wine processes, why, who receives it and the choices available to you.

Draft prepared 29 September 2026

Draft for review — not yet in effect.

These documents still require the operator’s postal address and confirmation of provider retention, transfer safeguards, consent and age eligibility before launch.

On this page

  1. Who is responsible
  2. The information you choose to share
  3. Why information is used
  4. Storage, encryption and recovery
  5. Optional AI and voice features
  6. Health integrations and sharing
  7. Who receives information
  8. How long information remains
  9. Your choices and rights
  10. Website cookies and demonstrations
  11. Age and policy updates

01Who is responsible

Wine is operated by Nelson Ponte, established in Portugal, who is the controller of the personal data described here. This policy covers the Wine mobile app and winecycle.app.

For privacy questions, requests or support, contact [email protected]. You can write in Portuguese or English. A postal contact address has not yet been supplied and must be added before this document takes effect.

02The information you choose to share

Wine processes different information depending on the features you use:

  • Account: your email address, account identifier, authentication details and information supplied by your sign-in provider, such as your name. The sign-in provider handles its own password and login process.
  • Profile and cycle records: the name and birthday you enter, period dates, cycle preferences, contraception history, health conditions, height, weight and wellbeing preferences.
  • Daily check-ins: symptoms, flow, cramps, mood, energy, sleep, temperature, ovulation tests, activities, intimacy, medication and notes, where you choose to record them. Some of this is health or sex-life data and receives special protection under data protection law.
  • Optional features: chat messages, recordings you submit for transcription, health data you permit Wine to import, partner-sharing permissions and the summaries you choose to share.
  • Service records: consent choices, registered devices, encrypted recovery information, subscription and transaction identifiers, entitlement status, request counters and limited operational diagnostics.
  • Support and website requests: information you email us and technical information needed to deliver and protect the website, such as IP address, browser information, requested URL and request time.

Most health details are optional. Leaving a field blank may limit the associated comparison or estimate. Account information is needed for sign-in and account-based features. Wine does not obtain your full payment-card number through the app.

03Why information is used

Wine uses your records to display your calendar, calculate estimates, show patterns and provide features you request. These estimates can be wrong; they are not a diagnosis or contraception. Wine does not use them to make legal or similarly significant decisions about you.

  • Account and requested services: performance of our agreement with you, where necessary (GDPR Article 6(1)(b)).
  • Health and sex-life information: explicit consent for the relevant purposes (Articles 6(1)(a) and 9(2)(a)). Optional AI processing, health import and partner sharing require their own informed choices. Accepting general terms is not a substitute for explicit health-data consent.
  • Security and limited diagnostics: legitimate interests in keeping the service reliable and preventing abuse (Article 6(1)(f)), balanced against your rights. This does not authorise unrelated use of health records.
  • Purchases and support: fulfilling your request or contract; legal obligations where applicable to accounting or consumer requests (Article 6(1)(c)).

You may withdraw consent without affecting the lawfulness of earlier processing. Turn off the relevant optional feature, revoke device permissions or contact us. If you withdraw consent for core health processing, the affected tracking features cannot continue; you can request deletion of those records.

04Storage, encryption and recovery

The native app stores records in an encrypted local database. Profile, period and daily-log records are encrypted on your device before cloud synchronisation. Account identifiers, device registrations, timestamps, consent and subscription records are needed to operate the service and are not all protected in the same way as encrypted health-record contents.

Standard recovery uses a protected recovery envelope that the recovery service can open to restore your account key after authentication. Maximum privacy removes this server-assisted recovery option and relies on approved devices. If you lose all approved devices in that mode, your encrypted history may be unrecoverable. These modes do not justify a blanket claim that the service can never access a recovery key.

Encryption of stored records does not mean content stays encrypted while an optional AI provider is processing it. Keep your device, sign-in credentials and approved devices secure. No service can guarantee absolute security.

05Optional AI and voice features

Chat history is stored locally and is not part of the normal cloud record sync. When you use online AI, your message, selected conversation history and relevant cycle or wellbeing context are sent through the Wine backend to Google Gemini. Context may include recent periods, estimates, contraception, symptoms, energy, mood, sleep, temperature, weight, health preferences, language and timezone.

Notes, medication and intimacy fields are excluded from the automatically selected chat context. Information you type or speak yourself is still sent when you submit it, so do not include details you do not want processed.

Voice recordings you submit go through the backend to Groq for speech-to-text. Wine attempts to remove the temporary device recording when processing finishes or you discard it. The resulting text may be used in a chat or a log you review.

The backend does not write chat prompts, responses or recordings into the Wine database. It requests non-persistent Gemini interactions, but this does not eliminate provider security logging. Google and Groq may retain information under their service terms and data controls. Provider settings and contractual retention must be verified before launch; zero retention is not promised.

You can disable AI sharing in Settings. This stops future authorised requests; it cannot undo a request already processed. Availability for users aged 16–17 remains unresolved because the current Gemini integration has an under-18 restriction. This draft is not approval to offer it to that age group.

06Health integrations and sharing

If you enable them, Wine can read basal body temperature and sleep from Android Health Connect, and basal body temperature, sleeping wrist temperature and sleep from Apple Health. Only the enabled categories are requested. Imported records can become part of your Wine check-ins, encrypted sync and, with separate AI permission, selected AI context.

Revoke health permissions in your device’s health settings to stop future imports. Revocation does not automatically remove information already imported; remove the relevant records in Wine or request deletion. Deleting Wine data does not delete the original records in Apple Health or Health Connect.

Partner sharing is optional. Your chosen recipient receives only the permitted summaries through encrypted sharing. Revoke permissions to stop further access, but Wine cannot retract screenshots or copies someone has already made. Information you export or share outside Wine is handled by the recipient or app you choose.

Microphone and camera permissions are used for requested voice or QR features, and notification permissions for reminders. You can change device permissions at any time.

07Who receives information

Wine does not sell health information or use it for targeted advertising. Service providers receive the information needed for their role:

  • Supabase: authentication, account infrastructure, encrypted record storage and backend processing.
  • Google Gemini and Groq: optional AI requests and transcription as described above.
  • RevenueCat, Apple and Google: purchase processing, subscription status, account or customer identifiers and transaction information where paid features are offered. App stores and payment services also handle data under their own notices.
  • Sentry: limited crash and operational diagnostics when enabled. Wine disables session replay, screenshots and interaction tracing, and filters user details, request bodies and message contents from events. Technical network information may still be processed by the service.
  • Cloudflare: website delivery and security when the production website is hosted there.
  • Google Gmail: delivery and storage of messages you send to our support address. Please avoid sending full health histories or identity documents unless specifically needed.

We may disclose information where a valid legal obligation requires it, or as necessary to establish or defend legal claims, subject to applicable safeguards. Optional sharing with a partner happens only at your direction.

These providers may process information outside Portugal or the European Economic Area, including in the United States. The applicable destinations, processor agreements and transfer safeguards must be confirmed before this draft becomes effective. We do not claim that all data stays in the EU. You can request information about the relevant safeguards through our contact address.

08How long information remains

  • Local records and chat history: remain on the device until removed through the app or local app data is cleared. Merely signing out does not necessarily erase local history.
  • Cloud account data: kept to provide your account until deletion. A successful account deletion removes the account and linked active database records. Removing an individual record may leave an encrypted deletion marker needed to synchronise devices.
  • AI requests and audio: not retained as a Wine cloud conversation archive. Provider security retention is separate from device history and depends on the provider’s applicable settings and terms.
  • Support, diagnostics, security and purchase records: kept only as needed to resolve the request, investigate a fault or abuse, meet a specific legal obligation or handle a dispute. The operational retention schedule and backup expiry periods still require confirmation before publication.

Account deletion does not automatically erase copies in provider backups, store payment records, exported files or another person’s possession. Any retention exception must have a specific purpose and period or criterion; it is not permission to keep health data indefinitely. Contact us for the applicable details.

09Your choices and rights

Depending on the legal basis and circumstances, you can request access, a copy of your personal data, correction, erasure, restriction or portability, and object to processing based on legitimate interests. You can also withdraw consent.

Email [email protected] with the request and the email associated with your account. We may ask for proportionate verification before disclosing or deleting data. Never send your password, login code or encryption key. We normally respond within one month; if a lawful extension is needed, we will explain it within that first month.

For account deletion, follow the deletion instructions. Some encrypted content can only be opened on an approved device; we will explain how that affects an access or portability request rather than asking you to surrender your key.

You may complain to Portugal’s Comissão Nacional de Proteção de Dados (CNPD) or the competent supervisory authority where you live or work. You do not have to contact us first.

10Website cookies and demonstrations

The current marketing website does not set advertising or analytics cookies and does not include third-party tracking pixels. The animated chat and cycle examples are demonstrations; they do not submit your health details to an AI service.

Ordinary delivery and security requests can still involve technical logs. Following an external link or emailing us involves the destination service. If non-essential tracking is added, this notice and the relevant consent controls must be updated before it is activated.

11Age and policy updates

Wine is intended for people aged 16 or older. We do not intend to collect information from children under 16. Contact us if you believe an ineligible child has provided personal data. Online AI eligibility is subject to the unresolved restriction described above.

We will identify the effective date of a final policy and communicate material changes appropriately. A new use of health information that requires consent will need a new informed choice; publishing a changed policy alone does not provide that consent.

© 2026 Wine · Nelson Ponte, Portugal

Privacy PolicyTerms of ServiceDelete your Wine account
[email protected]