Legal

Privacy policy

DRAM+VINE · EFFECTIVE 2 AUGUST 2026

Dram+Vine is an Android app that catalogs a personal wine and spirits collection and tracks when each bottle should be opened. It is made by Doug Wright, an individual developer. This policy explains what the app stores, what leaves your phone, and what control you have over it.

There is no Dram+Vine account. You do not register, there is no user database and no login system, and the developer holds nothing that identifies you. Even if you connect Google Drive, the app never learns your name or email address: it does not request permission to see them, and it never asks Google for them.

What the app stores on your phone

Everything you enter lives in a database in the app's private storage on your device:

The app does not collect your name, your location, your contacts, your phone number, or an advertising identifier. There is no advertising in it, and the developer has added no analytics and no crash reporting of any kind. One Google library bundled inside the app does report its own diagnostics to Google, which is described below.

What leaves your phone

Everything that leaves the device is listed in this section. Nothing else does.

Bottle identification. When you photograph a label, the photo is sent to Google's Gemini model to read the label and fill in the bottle's details. If you were offline when you took it, the photo is sent the next time the app opens or the phone regains a connection.

Recommendations. A summary of your collection is sent to the same model: for each bottle its category, name, style, vintage, region, status, drink-by date and your rating. Finished bottles are left out. This happens when you ask for a recommendation, and automatically whenever you open the "what to buy" view after your collection has changed. If nothing has changed, the saved answer is reused and nothing is sent.

Drink-window checks. Tapping to re-check a bottle's drink window sends that one bottle: its name, producer, vintage, style, wine colour and region. Nothing else about it is sent, and no other bottle is included.

Your prices, your notes, your tasting comments, your purchase dates and the app's internal identifiers are never sent in either request.

Your own Gemini key. Settings has a field where you can paste your own Google Gemini API key. While one is set, everything described above goes straight from your phone to Google on that key, and none of it reaches dramvine.com or appears in the request record described below. The key is stored in the app's private storage on your device, in its own file so it can be left out of Android's cloud backup and out of the Google Sheets backup. It is not sent to the developer, it is never written to your spreadsheet, and it does not transfer to a new phone. It is sent to Google once when you save it, so the app can tell you whether it works. Uninstalling the app removes it.

One consequence is worth stating plainly. Google's free and paid API tiers carry different terms: on the free tier Google may use what you send to improve its products, including review by people, and on the paid tier it does not. The developer's own service runs on the paid tier. A key you create without attaching billing is a free-tier key, so while it is in use your photographs and collection summaries fall under the free-tier terms rather than the paid ones. Enabling billing on your own Google project moves you to the paid terms. Clearing the field returns you to the developer's service.

Where no key of your own is set, both of these travel through a proxy operated by the developer at dramvine.com, hosted on Cloudflare, which forwards them to Google. The proxy exists so that the Google API key is not stored inside the app. It attaches no account, device or advertising identifier, and the same application token is used by every copy of the app, so no identifier in the request distinguishes you from any other user.

The proxy does not store what you send. Your photographs and collection details pass through it and are not kept. A technical record of each request is retained for cost control and to detect abuse, covering the time, size, duration, cost and result of the request. That record holds no photographs, no bottle information, and no address or device details. It is capped at the most recent 100,000 requests, and older entries are discarded as new ones arrive. At the volumes a personal app generates, that means entries can persist for a long time, so it is worth saying plainly rather than describing it as short-lived.

Connecting to any website or server reveals your device's IP address to whoever operates it, and that is true here. It is not written into the request record described above, but it necessarily reaches Cloudflare's network in order for the connection to happen at all, and Cloudflare handles it under its own privacy terms. Because Cloudflare terminates the secure connection, its infrastructure also handles the photograph or collection summary in transit before it is passed on to Google.

Google Drive and Google Sheets. These are optional and off until you connect a Google account. If you connect one, label photographs are uploaded to a folder called "Bottle Photos" in your own Google Drive, and your collection is written to a spreadsheet called "Bottle Collection" in your own Google account, including the Notes and Comment fields you wrote. That spreadsheet also carries a hidden tab holding a machine-readable copy of the collection and of your app settings, which is what the restore reads back: your display title, your alert lead times, your theme and your list layout. Both live in your Drive, not the developer's. The app writes your collection out to that spreadsheet, and reads it back when you restore a collection to a new phone. It cannot see anything else in your Drive.

One permission is requested, and it is deliberately the narrowest one Google offers for this: access limited to files the app itself created. The app cannot see, search, or list anything else in your Drive, including your other spreadsheets, and that limit applies to reading as much as to writing. It is enforced by Google, not by the app's good behaviour.

This traffic goes straight from your phone to Google. It does not pass through the developer's proxy, which means the Drive and Sheets side of the app creates no copy anywhere else: the developer holds no authorisation to your account, no copy of your spreadsheet, and no record of this traffic at all.

Reading text off the label is a separate step from identification and runs entirely on your phone, using a Google library bundled inside the app. No photograph leaves the device for that part. Identification, described above, is the step that does send the photo.

Diagnostics from Google's library. The text-recognition library the app uses, Google's ML Kit, reports information about its own operation back to Google: your device manufacturer, model and Android version, the app's package name and version, how long processing took, the image format and size, which events occurred, and any error codes. It does not send the photograph or the text it read. It includes an identifier tied to your installation of the app, which Google states is not intended to identify you or your device. This happens automatically inside Google's library, the developer does not receive any of it, and there is no setting in the app to turn it off.

Android backup

If you have Android's backup turned on in your device settings, your bottle database and app settings are included in that backup and stored in your own Google account. That covers your bottles, tasting notes, preferences, and the app's saved recommendation suggestions. Label photographs are excluded from cloud backup, but are included when you transfer directly from one phone to another.

You can turn this off in your device's system settings, under Google, Backup.

Security

All network traffic uses HTTPS. On the device, your data is protected by Android's app sandbox and by your phone's built-in encryption. The app does not add a second layer of encryption on top of that, so anyone who can unlock your phone can open the app and see your collection.

How long data is kept, and how to remove it

On your phone. Data stays until you remove it. You can delete a single bottle from its detail screen, which also removes that bottle's photographs and tasting notes.

To remove everything at once, uninstall the app, or use Android's system settings: Apps, Dram+Vine, Storage, Clear storage. Either one erases the whole collection, all photographs, and every setting from the device.

In your Google account. Photographs already uploaded to Drive and the "Bottle Collection" spreadsheet stay in your Google account. Deleting a bottle does not delete its photograph from Drive, and neither disconnecting nor uninstalling removes either one. The app has no delete function for Drive files, so it cannot clean them up for you. To remove those copies, delete them yourself in Google Drive.

Disconnecting, and revoking access. Disconnect in Settings stops the app using your Google account and clears what it had saved about the connection. It does not withdraw the permission you granted, which continues to exist on Google's side until you remove it. To withdraw it, go to myaccount.google.com/permissions, find Dram+Vine, and remove its access. Uninstalling the app does not do this for you either.

At the proxy. The technical request record described above is capped at the most recent 100,000 requests, with older entries discarded as new ones arrive. It holds nothing that identifies anyone, and the developer has no identifier to search it by.

At Google. Photographs and collection summaries sent for identification are handled under Google's paid terms for the Gemini API. This matters, because Google treats the two tiers differently: on the free tier it may use what you send to improve its products, including review by people. Dram+Vine uses the paid tier, where it does not. Google retains content briefly for abuse monitoring and then deletes it, under its own published terms.

Using the app without a Google account

Every feature except Drive photo backup and the spreadsheet export works without connecting a Google account. Photographing labels, identification, drink-window alerts, ratings, notes, and recommendations all work signed out. The Continue button on the first screen is not a login and does not send anything anywhere.

Children

Dram+Vine concerns alcoholic drinks and is intended for adults of legal drinking age in their country. It is not directed at children, and the developer does not knowingly collect information from anyone under 18.

Third parties involved

Your data is not sold, rented, or shared with anyone else, and there is no advertising in the app.

Your rights, and the limits of what can be honoured

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, to object to its processing, and to complain to your national data protection authority.

For almost everything this app handles, those rights are exercised directly rather than by asking: your data is on your own phone and in your own Google account, and you can read, edit and delete all of it yourself using the app and Android's settings. If you connect Google Drive, the spreadsheet the app maintains is also a ready-made export you can download in any format Sheets offers.

The small technical record kept at the proxy is the exception. It contains nothing identifying, and requests carry no account or device identifier, so there is no way to find your entries in it. That is a consequence of the design, and it cuts both ways: nobody can look you up in that log, and neither can a request from you to retrieve or delete your own entries be honoured, because nothing connects them to you.

The legal basis for the processing that happens is the performance of the service you asked for, namely identifying a bottle and tracking its drink window, together with a legitimate interest in keeping the service running and not being abused.

The developer is based in the United States. The proxy runs on Cloudflare's network, and identification is performed by Google, both US companies. If you use the app from outside the United States, the data described in this policy is processed there.

This website itself sets no cookies and runs no tracking. As with any website, requests to it reach Cloudflare's network, which handles them under its own privacy terms.

Changes

If this policy changes in a way that affects what is collected or where it goes, the change will be posted here with a new effective date, and a material change will be noted in the app's release notes.

Contact

Questions, or a request about your data: dramvine@gmail.com