← Back to Home

Privacy Policy

Effective Date: May 31, 2026 | Version 2.1

🔒 CATA PRIVACY PLEDGEBy default, your entire wine cellar inventory, tasting notes, and physical storage maps are strictly confidential. We do not sell your personal inventory, history, or uploaded photos to third-party data brokers or advertisement merchants. Your collection is only visible to users you explicitly authorize via your Friends list.

1. Categories of Personal Information We Collect

To provide our digital cellar inventory, label scanner, and premium Sommelier recommendations, we collect the following types of information:

  • Account Credentials: Username, email, password hashes, and user role type chosen during sign-up.
  • Media Uploads: Photos of wine bottle labels, dining menus, or cellars uploaded by you.
  • Cellar Metadata: Vintage years, producer names, drink counts, cellar location details, and tasting logs.
  • Location Information: Manual regional selections or coordinates input via the VineyardPicker location utility, which is used to pinpoint wine regions and display local cellars on our 3D Globe.
  • Technical Identifiers: IP addresses, browser types, session cookies, and API telemetry logs.

2. Visual Label Scanning and AI Model Subprocessing

Cata provides instant label scanning and restaurant menu pairing through advanced artificial intelligence models.

When you upload a label or menu photo, the image is securely stored in encrypted cloud repositories (AWS S3) and is transmitted to our AI subprocessing engines, including the Google Gemini API.

AI Privacy Shield: Media processed via our API integrations is protected under strict zero-retention enterprise clauses. Google and our other AI suppliers are legally barred from retaining, storing, or training their baseline public models on your uploaded images or personal profile metadata.

3. Location Pinpointing (VineyardPicker & 3D Globe)

Our VineyardPicker tool asks for location context to map your inventory to specific wine regions.

These coordinates are solely used to place regional wine statistics onto Cata's interactive 3D Globe and match your inventory with neighboring vineyards. This geographical metadata is processed at an aggregate, approximate level. We do not track your real-time GPS location in the background, nor do we share granular coordinate history with any advertising merchants.

4. Cookies and Security Credentials

Cata utilizes secure session and authentication cookies (e.g., the userId cookie) to verify your sign-in state, encrypt user credentials, and defend against cross-site scripting attacks. Session cookies are automatically cleared from your browser upon logging out or after session expiration.

5. GDPR and CCPA Data Protection Rights

Depending on your location (including the European Union under GDPR or California under the CCPA), you are granted specific rights over your personal data:

  • Right to Access & Portability: You may request a complete export of all cellar records, tasting notes, and coordinates associated with your profile at any time.
  • Right to Rectification: You can edit any catalog entries, username details, and billing settings directly inside your profile workspace.
  • Right to Opt-Out: You may disable social sharing features or retract friend access instantly via the Friends dashboard.
  • Right to Erasure (“Danger Zone”):You retain complete ownership. You can permanently erase your account and all associated logs through the “Danger Zone” menu.

6. “Danger Zone” Deletion & Data Retention Policy

When you select permanent deletion in the Profile workspace, we immediately initiate our purge sequence:

All database records (SQLite and DynamoDB user and bottle lists) are immediately and permanently erased from our active production servers. Backup directories are maintained under secure encryption and will naturally overwrite within thirty (30) days, after which your information is unrecoverable.

7. Security Standards

We employ premium corporate protection standards. All API connections are forced over TLS 1.3 encryption, and data-at-rest is protected via AES-256 standard encryption keys. While we strive to maintain comprehensive defenses, no server storage can be guaranteed 100% secure. You are responsible for safeguarding your personal login password.