Last updated: 04-09-2026
Coco Vino is an app for keeping track of your wine cellar. This policy explains what information the app handles, why, and what rights you have. We have tried to make it as concrete and readable as possible, rather than writing it in generic legal language.
Coco Coding is the data controller for the processing of personal data described in this policy.
Email: cocovino@coco-coding.dk
Everything you add to the app — wine names, producers, vintages, images, purchase prices, cellar locations, notes and tasting notes — is stored locally on your device. If iCloud sync is enabled, the data can sync through Apple's CloudKit to your private iCloud account. It is not stored on servers that we operate or have access to.
When you use an AI-powered feature, the information needed for that specific feature is sent to Anthropic's Claude API to generate the response:
Before the app sends information to an AI service for the first time, it asks for your permission. You can later withdraw that permission in the app's Settings. No new information will then be sent to AI services unless you grant permission again.
These requests pass through a proxy service we run on Cloudflare, which forwards the request to Anthropic. The proxy does not store the content of the requests.
To prevent misuse of the AI features, the app generates a random device identifier that is stored in the device's Keychain. The identifier — not the content of your requests — is used to count AI calls within a given period, so that we can limit usage per device and protect the service against abuse. It does not contain your name, email address or information about your wine collection.
As an infrastructure provider, Cloudflare may in addition keep short-lived technical logs (for example to prevent abuse), but these do not contain your wine collection as such.
Anthropic processes the content of each individual request in order to generate the response. This means information may be processed outside the EU/EEA, including in the United States.
We only disclose information when necessary to provide a feature you use or to operate and secure the service. The main service providers are:
Anthropic and Cloudflare may process information outside the EU/EEA. Where the GDPR requires a transfer mechanism, appropriate safeguards are used, including the European Commission's Standard Contractual Clauses (SCCs). The current data processing agreements of both providers include such mechanisms.
You can contact us at cocovino@coco-coding.dk if you would like further information about the safeguards used.
Siri shortcuts and widgets display or retrieve data from your own cellar using Apple's own on-device technologies (SiriKit/App Intents, WidgetKit). We receive no separate information from Apple about your use of these.
Subscriptions are handled entirely by Apple through the App Store. We never receive your payment details — only a confirmation of whether you have an active subscription.
If you have enabled diagnostics in your iOS settings, Apple may share anonymised crash reports with us to help fix problems. This is governed entirely by your own device settings.
If you use "Contact / send feedback" in the app's Settings, an email opens in your own mail app. The subject line automatically contains the app's version and build number, along with your device model and iOS version, to make it easier for us to help you. This email is only sent if you choose to send it, and the content is what you write yourself.
We do not use your information for targeted advertising or sell it to third parties. The taste profile analyses only your wine preferences in order to personalise features within Coco Vino.
Under the GDPR, processing of personal data must have a legal basis. For Coco Vino, we rely on the following:
The separate AI permission in the app is an additional privacy safeguard that gives you control over whether information may be sent to AI services. It does not change the fact that, when you actively use an AI feature, the processing is carried out in order to provide the feature you requested.
You are not legally required to provide us with personal data. Some information is, however, necessary for the feature you choose to use. For example, if you do not want information sent to AI services, you can continue to use the parts of the app that do not require AI.
Coco Vino does not make automated decisions that produce legal effects or similarly significantly affect you within the meaning of Article 22 GDPR. AI results in the app are advisory only.
Your wine collection is stored on your device for as long as you choose. If iCloud sync is enabled, it may also be stored in your private iCloud account. You can delete data in the app and manage any iCloud data through your Apple settings. We do not store your wine collection separately.
Anthropic states that API inputs and outputs are generally deleted from its backend within 30 days. Data may in some cases be retained for longer, for example where necessary to enforce its Usage Policy or comply with legal obligations.
The content of AI requests is not retained by our proxy beyond the time it takes to process the individual request. Anthropic may retain data briefly in accordance with their own policy, primarily for security and abuse-prevention purposes.
The random device identifier is used in our counting system for as long as needed to enforce usage limits. The relevant count typically applies to the current day or month.
Emails you send to support are retained for as long as is necessary to answer your enquiry.
Where the GDPR applies to the processing of your information, you may, depending on the circumstances, have the right to:
Because most of your wine collection is stored on your device and, if enabled, in your private iCloud account, you exercise many of these rights directly in the app or through your Apple and iCloud settings. For information processed by us or by service providers on our behalf, you can contact us at cocovino@coco-coding.dk. We will respond without undue delay and normally within one month.
We use appropriate technical and organisational security measures. Communication between the app and our services is encrypted using HTTPS, and access to external AI services is handled server-side.
We may update this policy from time to time, for example if we add new features. The date at the top of the page shows when it was last updated. Significant changes will be mentioned in the app's "What's New" text for the relevant update.
If you have questions about this policy or about how we handle your information, you can contact us at cocovino@coco-coding.dk.
This is an English translation of the Danish privacy policy. In case of discrepancy, the Danish version applies.