Privacy Policy
Last updated: April 8, 2026
1. Information We Collect
We collect the following categories of information when you use Vinny:
- Conversation content: Messages you send to Vinny and the responses generated.
- Account information: Email address and name if you create an account.
- Usage data: Pages visited, features used, timestamps, and interaction patterns.
- Device information: Browser type, operating system, and screen size (from standard HTTP headers).
- Cookies: Functional session cookies and authentication cookies (see Section 6).
2. How We Use Information
- Provide personalized wine recommendations and food pairing suggestions.
- Improve the quality and accuracy of AI-generated responses.
- Generate aggregated, anonymized analytics for restaurant partners (e.g., popular wine categories, peak usage times).
- Enforce rate limiting to ensure fair service delivery.
- Detect and prevent abuse or unauthorized access.
3. Third-Party Services
We use the following third-party services to operate Vinny. Each processes data as described:
- OpenAI: Processes your conversation messages to generate AI responses. Data sent via the OpenAI API is not used to train OpenAI models, per their API data usage policy.
- Supabase: Hosts our database and provides authentication services.
- Vercel: Hosts the application and provides web analytics and performance monitoring.
- Upstash: Provides rate limiting via Redis to ensure fair service delivery.
- Grapeminds: Provides professional wine data including tasting notes and drinking windows.
- Tavily: Provides web search capabilities for real-time wine information verification.
- Cohere: Provides search result reranking to improve recommendation quality.
4. Data Retention
- Conversations: Retained while your account is active. You may request deletion at any time.
- Account data: Retained until you request deletion.
- Analytics data: Aggregated and anonymized; retained indefinitely for service improvement.
- Rate-limiting data: Session identifiers expire after 24 hours.
5. Your Rights (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- Right to know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to delete: Request deletion of your personal information.
- Right to opt-out of sale: We do not sell your personal information to third parties.
- Right to non-discrimination: We will not discriminate against you for exercising any of these rights.
To exercise these rights, contact us through the channels listed on our website.
6. Cookies & Similar Technologies
- Session cookie (
vinny_session): A functional cookie that expires after 24 hours. Used solely for rate limiting to ensure fair service delivery. Does not track you across sites. No consent required under the ePrivacy Directive as it is strictly necessary for service operation. - Authentication cookies: Managed by Supabase for secure login sessions. Set only when you create an account and sign in.
- Local storage: Used only to remember your age verification (21+ confirmation) so you are not asked on every visit.
We do not use tracking cookies, advertising cookies, or third-party analytics cookies beyond Vercel's privacy-respecting web analytics.
7. Children's Privacy
Vinny is intended for users who are 21 years of age or older. We do not knowingly collect personal information from anyone under 21. If you believe we have collected information from someone under 21, please contact us immediately.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be noted on this page with an updated “Last updated” date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
9. Contact
For privacy-related questions or to exercise your rights, contact us through the channels listed on our website. Also see our Terms of Service.