Legal

Privacy Policy

Version 2.1  ·  Effective date: 1 September 2026

Short version. The app keeps your whiskey collection in a database in the EU, on an account that starts out anonymous. If you use the AI label scan, the photograph you take leaves your device: it goes to our server and on to Google, which reads the label for you. Usage analytics are switched off until you turn them on yourself in Profile. Crash reports are always on and carry no account identifier. Your bottles sit in one inventory shared with My Bar Shelf on the same account, so deleting your account deletes them in both. We do not sell any of it. You can export or delete all of it from inside the app, without asking us.

What changed in version 2.0, and why. Version 1.0 of this policy said the app contained no analytics, no third-party trackers, no subscription and no in-app purchase, and it described photographs as never leaving the device. Those statements were true when they were written and stopped being true as the app was built. They stayed on this page after they stopped being true, which is our fault and not a small one. This version replaces them. It names Google as the processor that reads label photographs, names Mixpanel and RevenueCat, describes the subscription, and states three places where data survives an account deletion. Section 17 lists the changes.

What changed in version 2.1, and why. Version 2.0 described three things as set once and applying to every Shelf app you use. That was a sentence about a family of apps rather than about this one, and it was wrong in the detail. The analytics setting covers five of the Shelf apps and not My Coffee Shelf. The free scan allowance is shared between three of them, named in section 4. A subscription unlocks what the particular subscription you bought unlocks, which is not always the whole set. Sections 3, 4, 6 and 8 now name the apps instead of saying “every”, and section 17 lists the changes.

1. Who we are

My Whiskey Shelf is a product of Nisshagen Advisory AB (Org.nr 559526-6742), a company registered in Stockholm, Sweden. We are the data controller for personal data collected through the My Whiskey Shelf app and through the mywhiskeyshelf.com website.

Contact hello@mywhiskeyshelf.com for any privacy question, including requests under the GDPR. We have not appointed a data protection officer and are not required to.

This policy covers both the app and the website. Where a section applies to only one of them, it says so.

2. Your account

The app creates an anonymous account the first time you open it. That account holds no email address and no name. It is a random identifier that lets your own shelf come back to you the next time you open the app. You are not asked to sign up, and you can use the app indefinitely without ever creating a real account.

An anonymous account is still a real record in our database. Everything you enter is stored against it, exactly as described in section 3. What an anonymous account cannot do is turn on usage analytics, so nothing in section 6 applies to you until you sign in.

If you create a real account so your collection survives a new phone, we store what you give us for that:

On your device the app stores your sign-in session, a flag recording that this device has held a real account, and your language preference. Signing out clears them.

3. What you record, and who it is shared with

Everything in the app besides the reference catalogue is content you create, stored against your account:

This is private to your account. There is no social feed, no public profile and no sharing with other people. Database access rules restrict every row to the account that created it. There is one exception, the shared barcode table, and section 5 sets it out.

Your bottles are shared with My Bar Shelf. Bottles live in a single inventory used by both My Whiskey Shelf and My Bar Shelf, so one bottle you own is one record rather than two. If you are signed in to the same real account in both, a bottle added in one appears in the other, editing it in one edits it in both, and deleting it in one deletes it in both. Deleting your account removes those bottles from both apps at once. This is between apps you control, under your own account. Nothing is shared with anyone else.

While you are anonymous you have a different account in each app, so nothing is shared until you sign in with a real account in both.

Three things reach past this app, and each reaches a different set of apps, so each is named rather than lumped together:

Version 2.0 of this policy called all three “set once and apply to every Shelf app you use”. That was one sentence covering three different scopes, and it was wrong about each of them.

4. Photographs and the AI label scan

This is the part of the app that sends the most away from your device, so it is set out in full.

The camera and the photo library are used for one thing: reading a bottle label. There is no separate feature for attaching a picture to a bottle. If you never run a label scan, no photograph of yours ever leaves your device.

When you start a scan, the app asks for camera or photo library permission, then:

This happens before anything is saved, and it happens even if you then discard the reading and add nothing. Cancelling the form does not undo the upload.

If you do save the bottle, the same photograph is also uploaded to our file storage and kept with the bottle. That storage area is not access controlled: the file sits at a long random web address, and anyone who has that address can open it without signing in. The address is only ever stored in your own record and we do not publish it, but we are not going to describe the file as private, because it is not.

Each successful scan writes one row recording your account identifier, which Shelf app ran the scan, what kind of scan it was and the time. That row exists to count your free allowance, which is five AI scans in total, for the lifetime of the account. It is not a daily or a monthly allowance and it does not reset.

Those five are not five per app. The count is kept on your ACCOUNT, in one ledger, and the check that reads it does not filter by app. So an AI scan you ran in any Shelf app comes off the same five. We checked the ledger rather than reasoning about it: it currently holds scans recorded by My Bar Shelf, My Cigar Shelf and My Wine Shelf. Not every Shelf app meters its AI features this way, and each of their policies is the place to read how theirs works. Two earlier versions got this wrong in opposite directions: one said the five were shared across every Shelf app, which was more than we had checked, and the correction named three apps as a closed set, which was less than the ledger actually counts.

If you have a subscription you are not metered, but the row is still written.

Before running a scan our server asks RevenueCat whether your account has an active subscription, which sends your account identifier to RevenueCat. Section 8 covers that.

What we cannot tell you. We call Google’s general endpoint and have not pinned it to a European region, so you should assume the photograph is processed outside the EU. We do not control what Google does with the image after it has read it, and we are not going to state a retention period we cannot verify. Google’s own terms for that API govern it. If that is not acceptable to you, do not use the label scan. Adding a bottle by barcode, by catalogue search or by hand never sends a photograph anywhere.

Older builds of the app carry a camera permission notice saying that nothing is uploaded unless you save it. That notice is wrong and it is being corrected. This section describes what the app actually does.

5. Barcode scanning, and the shared barcode table

When you scan a barcode, the digits are first checked against our own shared table of barcode-to-product mappings. If that misses, the app asks up to five external barcode databases in order and stops at the first one that returns a usable answer:

Each of them receives the barcode digits and, because the request comes from your phone, your device’s IP address. None of them receives your account identifier, your email, a photograph or anything from your shelf.

If you confirm that a barcode belongs to a particular catalogue product, the app saves that mapping to a table shared with My Bar Shelf, so the next person who scans that bottle gets an answer immediately. The saved row holds the barcode, the product, and the account identifier of whoever contributed it.

That table is readable by anyone holding the app’s public key, which is embedded in the app and is not a secret. So the contributor identifier on a barcode mapping is not private. It is a random identifier and carries no name, no email and nothing from your shelf, but it is the one place where a row of yours is not restricted to your account, and you should know it. Your contributions are deleted when you delete your account.

6. Usage analytics, which are off until you turn them on

The app can send product analytics to Mixpanel, on its EU service. It does not do so unless you switch it on.

Before you consent

The setting is off by default and is off for every new account. While it is off, the analytics library is never started, no analytics identifier is generated, no events are queued, and no connection to Mixpanel is opened at all. It is not a filter applied to data that was collected anyway. Nothing is collected.

The setting is only offered on a real account. An anonymous account cannot turn it on, so if you never sign in, no analytics of any kind are ever sent.

Turning it on

Profile, then Data, then the Usage data switch. It is a single setting, stored as one row on your account, and it covers My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf and My Cigar Shelf, which all read and write that one row. Turning it on here turns it on in those, and the other way round.

It does not cover My Coffee Shelf, which keeps its own separate answer in its own table and asks you again there, so turning it off here leaves coffee where you set it. My Supply Shelf sends no analytics at all. Version 2.0 of this policy said the setting covered every Shelf app you use with the same account, which was wrong about coffee. The wording on the switch inside the app makes the same overstatement and is being corrected there too.

You can turn it off again at any time in the same place, and you do not have to give a reason.

What is sent once it is on

Ten events and nothing else: adding an item, adding your first item, sharing a dram card, a paywall being shown, a paywall being dismissed, a restore being attempted, a restore succeeding or failing, a subscription starting, and a purchase failing. Each carries short labels from a fixed list: which route you added the bottle by, which screen you were on, whether there was a photo, whether you rated it, which paywall you saw and which feature triggered it, and an error code when a purchase fails.

Attached to every event: whether the account has a subscription, whether it is anonymous, and which sign-in method it uses. The Mixpanel library also attaches your operating system and its version, and your device manufacturer and model.

Events are identified by your account identifier, not by your name or your email address. The switch in the app calls this anonymous usage data. Pseudonymous is the accurate word, and that wording is being corrected in the app.

Never sent: bottle names, distilleries, tasting notes, ratings, prices, purchase places, storage locations, photographs, your email address, or anything else you typed.

Approximate location. We do not suppress the IP address on these events, so Mixpanel resolves it to an approximate city, region and country and stores that against the event and the profile. The app does not ask for location permission and does not read your device’s location; this is derived from the network address of the request. If you would rather that did not happen, leave the switch off.

Turning the switch off clears the stored analytics identifier, so if you ever turn it back on, the new events are not joined to the old profile. Events already sent stay with Mixpanel. Section 12 says what we do about that.

7. Crash and error reports

The app reports crashes and errors to Sentry, on its German service. This is always on and is not covered by the analytics switch, because it is how we find out that the app is broken.

Sending personal data is switched off in our configuration, and we never attach an account to a report, so reports do not carry your account identifier by design, your email, a username, your IP address or cookies.

A report contains the error and its message, where in the code it happened, the device model, the operating system and version, the app version, the device locale and timezone, memory, storage, battery and orientation, and the list of loaded modules. Screenshots, view hierarchies, session replay and performance profiling are all switched off.

The honest limit. The Sentry library records a breadcrumb trail of network requests, storing the method, the web address and the status of each. Some of our database requests carry your account identifier in the address, and a catalogue search carries the text you typed. So a crash report can contain those two things. Request bodies are not recorded, so a bottle you saved does not travel to Sentry that way. We cannot promise more than that: when a database write fails, the error we attach is the database's own message, and a database message can quote the value that caused the failure. We are not going to claim that a crash report contains nothing about you.

8. Subscriptions and purchases

Some parts of the app are reserved for subscribers, and the free AI scan allowance in section 4 is one of the limits a subscription lifts.

We do not take your money and we never see your payment details. Subscriptions are sold and billed by Apple on the App Store or by Google on Google Play. Your card, bank details and billing address are held by them, not by us, and are never sent to us.

We use RevenueCat to keep track of whether a subscription is active. RevenueCat receives your account identifier as soon as you sign in, whether or not you ever buy anything, because the app asks it on every launch whether that account holds a subscription. It also receives your platform and the IP address of the request, from which it derives an approximate country. If you do buy or restore a subscription, it additionally receives the purchase and receipt information the store issues and the country of your store account. Our server also asks RevenueCat about your account when you run a label scan, to decide whether to count the scan against your free allowance.

RevenueCat processes this in the United States. Section 15 covers that transfer.

What a subscription unlocks depends on which one you bought. RevenueCat holds your entitlements against your account identifier, so an entitlement bought in one Shelf app is visible to another that asks about the same account. There are two kinds. A bundle subscription is honoured by the Shelf apps that check for it, so it unlocks more than the app you bought it in. A single-app subscription, which is what most current subscribers hold, unlocks the app it was bought for and is not honoured by the others. Version 2.0 of this policy said one subscription covers every Shelf app on the same account. That is true of the bundle and not of the rest, and it should not have been written as a flat rule.

Either way it needs a real account: while you are anonymous your identifier differs per app, so nothing carries across.

Cancel in your App Store account settings or your Google Play subscriptions. We cannot cancel or refund it for you. Deleting your My Whiskey Shelf account does not cancel a subscription, so cancel it in the store first or billing continues. The Terms of Service set out the renewal and cancellation terms in full.

9. The website

Reading pages on mywhiskeyshelf.com does not require an account and we do not ask you for anything.

The site uses Vercel Web Analytics for aggregate traffic measurement: page views, referrer, country, device, operating system and browser, with a visitor identifier that is hashed and rotates daily. It is cookieless, it does not follow you across sites, and it does not build a profile of you. There are no other pixels and no non-essential cookies, so there is no cookie banner.

You can sign in on the website with the same account as the app, using an email address and password, a one-time link, Google or Apple, and you can delete your account there. Signing in stores a session in your browser. That is functional storage, not tracking, and it is cleared when you sign out.

Catalogue pages load data straight from our database, so your browser’s IP address reaches our database provider in the EU. Some product photographs are served from the Swedish retail catalogue’s own image server rather than from us, so your IP address reaches that server too.

Fonts on this website are served by Google Fonts, which means your browser requests the font files from Google’s servers and Google receives your IP address as part of that request. No font cookies are set. The app does not load fonts over the network; they ship inside it.

10. Who processes your data

Every third party the app or the site sends anything to
Who What they receive Why Where
Supabase Your email address and sign-in, everything on your shelf, your saved photographs, and the IP address of each request The database, the sign-in system, file storage and our own server functions EU, Frankfurt
Google, Gemini API The label photograph and a fixed instruction. No account identifier, no email, nothing from your shelf Reading the label so the form fills itself Not pinned to a region. Assume outside the EU
Mixpanel Only if you consented: the ten events in section 6, your account identifier, device and operating system, and an approximate location derived from your IP address Understanding which parts of the app get used EU
Sentry Crash and error reports. No account identifier attached, with the limit stated in section 7 Finding and fixing faults EU, Germany
RevenueCat Your account identifier, store purchase and receipt data, store country, platform, request IP address Knowing whether a subscription is active, across the Shelf apps United States
Apple and Google, as stores Your payment details, which go to them and not to us. Your sign-in identifier if you use Sign in with Apple or Google Selling and billing the subscription, distributing the app, signing you in Global, per their own terms
Open Food Facts and Open Products Facts A scanned barcode and your device’s IP address Looking up a bottle we do not hold France
Vinmonopolet A scanned barcode and your device’s IP address Looking up a bottle we do not hold Norway, EEA
UPCitemdb and Brocade A scanned barcode and your device’s IP address Looking up a bottle we do not hold United States
Vercel Website requests, and the aggregate analytics in section 9 Hosting this website United States company
Google Fonts Your IP address when this website loads its fonts Serving the typefaces on the site Global
The Swedish retail catalogue’s image server Your IP address when a product photograph loads Showing the packshot next to a catalogue entry Sweden

We do not sell your data, we do not rent it, and we do not share it with data brokers. None of the providers above is an advertising network, and we do not use any of them for advertising. We are describing our own configuration and our contracts with them, not making a promise on their behalf about their other business.

There is no advertising in the app, no advertising identifier, and nothing that Apple defines as tracking, so the app does not show the tracking permission prompt.

11. Lawful basis for each purpose

Giving us this data is not a statutory requirement. It is what the app needs in order to be a shelf: without an account there is nowhere to put a bottle.

There is no automated decision-making that produces legal or similarly significant effects, and no profiling. The label reading is a machine guess that fills a form, and you review and edit every field before anything is saved.

12. How long we keep things

13. Your rights under the GDPR

You have the right to access your data, to rectification of anything inaccurate, to erasure, to restriction of processing, to object to processing based on legitimate interests, to portability, and to withdraw consent at any time.

Three of these are buttons rather than emails, and using the button is faster than writing to us:

For anything else, write to hello@mywhiskeyshelf.com from the address on the account. We will respond within one month, and it is free of charge. If we cannot identify you from what you send us, we may have to ask for more before we can act.

You also have the right to complain to a supervisory authority. In Sweden that is Integritetsskyddsmyndigheten (IMY), imy.se. You can also complain to the authority where you live.

14. Deleting your account

You can do it yourself. In the app: Profile, then Delete account, then confirm twice. On this website: sign in and delete from your account page. No email and no asking us first. The account deletion page sets out the steps.

What is removed: your bottles, from the inventory shared with My Bar Shelf, so they disappear from there as well; your bottle details, including purchase price, place and storage location; your pours and every tasting note on them; your shopping list; your accessories; the photographs you saved; your barcode contributions; and your profile record, including your analytics consent setting. That consent row is the one shared with My Bar Shelf, My Wine Shelf, My Beer Shelf and My Cigar Shelf, so removing it here removes your recorded answer for those as well, and any of them will ask you again.

What may stay. Your sign-in record is only deleted if the account holds no data in the other Shelf apps. If you also use My Coffee Shelf, My Wine Shelf, My Cigar Shelf, My Beer Shelf or My Supply Shelf, the sign-in stays and only the data listed above is removed, so that those apps keep working. Delete your data there first if you want the sign-in gone, or write to us and we will do it.

Removing the saved photograph files is best effort: they are deleted after the records that point at them, and if that step fails it is logged and the deletion still completes. If you want confirmation that a photograph is gone, write to us.

Section 12 lists the three things that survive a deletion: export files, analytics already sent, and your RevenueCat record. Ask and we will remove them by hand.

If you have an active subscription, deleting your account does not cancel it. Cancel it in your App Store account settings or your Google Play subscriptions first, or the store will keep billing you.

Deletion is permanent. We cannot restore it afterwards.

15. International transfers

Our database, sign-in, file storage, server functions, crash reporting and analytics are hosted in the European Union: the database and storage in Frankfurt, crash reporting in Germany, analytics on Mixpanel’s EU service. Two of the barcode databases are in France and one is in Norway, inside the EEA.

These leave the EEA:

For these we rely on the European Commission’s standard contractual clauses, which form part of the data processing terms these providers publish, together with the safeguards described in those terms.

16. Age

My Whiskey Shelf concerns collections of alcoholic spirits and is intended solely for adults of legal drinking age in their country of residence. When you create an account the app asks you to confirm that you are. It is not directed at children, and we do not knowingly collect data from anyone below that age. If you believe a minor has given us data, write to us and we will delete it.

17. Changes to this policy

If we make material changes we will publish the updated version here and update the version number and effective date at the top of this page. If a change materially affects data we already hold about you, we will tell you before it takes effect.

Version 2.1, 1 September 2026, corrected four claims in version 2.0. Each of them said something was uniform across the Shelf apps when it is not, and each was written from the shape of the portfolio rather than from what we had checked:

This policy was the reference the other Shelf policies were corrected against in the passes before this one, and it was left unedited on that basis. It carried the same errors. That is recorded here rather than quietly fixed.

Version 2.0, 31 August 2026, replaced version 1.0 in full. What changed:

18. Contact

Questions or concerns about your privacy? Write to hello@mywhiskeyshelf.com.

Nisshagen Advisory AB, Stockholm, Sweden.