In short
- Cellarly is software, not a service: it runs on the server of whoever installs it. The operator of an instance is responsible for the data on it. The developer receives no data from instances run by others and cannot see any data on them.
- All of an instance’s data is stored in one database file on the operator’s server. Other users cannot see your cellar in the app; the wine catalogue is shared by all accounts on the instance. The operator can technically read the whole database.
- Cellarly contains no advertising, analytics, tracking, telemetry or crash reporting.
- Outside services are involved only as described below: Google Gemini (if the operator enables it) and the operator’s mail server (for password resets, if one is set up). Your browser loads Cellarly only from the instance’s own server.
- To see, correct, export or delete your data, ask the admin or operator of your instance.
Cellarly is a self-hosted wine-cellar web app: it runs on the server of whoever installs it, not as a central service. It is still in development and has not been released yet. These notes describe what the current version of the software does with personal data. Operators can base their own privacy notice on them, and users can see what to expect.
Who is responsible
Cellarly is software, not a service. Its developer does not run Cellarly as a service for others and receives no data from instances run by others. The software contains no telemetry, analytics or crash reporting and never contacts the developer.
Whoever runs a Cellarly instance (the “operator”) decides who uses it and for what. Under data protection law (GDPR), the operator is therefore the controller for the personal data on that instance. The GDPR does not apply if an instance is used only for purely personal or household purposes, for example by a family for its own cellar (Art. 2(2)(c) GDPR). If you use an instance that someone else runs, the operator is your contact for anything concerning your data. Unless the instance serves only such purposes, they must give you their own privacy notice with their contact details.
The software is written by:
Benedikt Lesch
Merzig
Germany
The developer is only the author of the software. They cannot see, change, export or delete data on any instance run by someone else.
Where data is stored
All of an instance’s data is stored in one SQLite database file on the operator’s server (by default data/cellarly.db), together with its temporary journal files. Nothing is stored with the developer or in a cloud service, unless the operator puts the server or its backups there, or enables Google Gemini. With Gemini, Google keeps what it receives under its own terms (see “Google Gemini (optional)”).
Account data
You need an account on the instance to use Cellarly. Cellarly stores:
- your name and email address,
- your password, only as a scrypt hash (never in plain text),
- your role (viewer, editor or admin) and status (pending, active or deactivated),
- whether you must change your password at your next sign-in, a counter used to end sessions, and the date your account was created.
New registrations stay pending until an admin approves them. This data is used to sign you in and to control what you are allowed to do.
You can change your password in the app, whatever your role. You need to enter your current password, or the temporary password an admin set for you.
Neither you nor an admin can currently change your name or email address in the app. Ask the operator of your instance, who can change them directly in the database.
Your cellar
The following data belongs to your account. Other users cannot see it in the app.
- Storage units: name, type, optional description and size.
- Bottles: wine and vintage, row and position, quantity, optional purchase date and price paid, and when the bottle was added.
- Ratings: stars, an optional note and the date.
- History: a running log of every bottle added or taken out, with the wine, quantity, storage unit name and time. Entries are only ever added, never changed.
Shared wine catalogue
Wine information is shared by all accounts on an instance. The catalogue contains wine names, producers, regions, countries, grape varieties, wine types, descriptions, food pairings, vintages, alcohol content, flavour profiles, drinking windows and vintage notes.
- Every account on the instance can see the catalogue. Editors and admins can add and change entries, and every change applies to everyone.
- A wine’s Description field (“A short tasting note”) is part of the shared catalogue. Do not enter anything personal there. Your rating notes stay private.
- Wines found through a label photo or a catalogue search are added to the catalogue. Other users can then see that the wine is in the catalogue, but not who looked it up.
- Catalogue entries do not record who created or changed them. They are not linked to any account and stay on the instance when an account is deleted.
Who can see what
- Other users see only the shared catalogue. They cannot see your cellar, ratings, history, name or email address.
- Admins see a list of all accounts with name, email address, role, status and sign-up date. They can approve, deactivate and delete accounts, change roles and set a temporary password for you. The temporary password is shown to the admin once, and you must change it at your next sign-in. Until you do, the app only lets you set a new password or sign out. The app does not show admins other users’ cellars.
- The operator, and anyone else with access to the server or its backups, can technically read the whole database, including cellars, prices and notes. Cellarly cannot prevent this. Only use an instance whose operator you trust.
Google Gemini (optional)
Cellarly can use Google’s Gemini API to recognise wine labels, search for wines and fill in wine details. This only happens if the operator has entered their own Gemini API key. Without a key, these features return no results and nothing is sent to Google.
When Gemini is enabled, your browser sends the data to the Cellarly server, and the server passes it on to Google (generativelanguage.googleapis.com). Your browser does not contact Google for this, so Google sees the server’s IP address, not yours. Google receives:
- Label photos that you take under “Photograph label”, or that you select as an image file if the camera is unavailable. Before uploading, your browser scales the photo down to at most 1024 pixels and saves it again as a JPEG. This removes embedded metadata such as EXIF data and GPS location. Cellarly does not store the photo.
- Search text that you submit in the catalogue search (at least 3 characters), if the instance’s own catalogue has fewer than five good matches.
- Wine name, producer, region and vintage year, to fill in missing details. This happens automatically when you choose a vintage while adding or editing a bottle and details are missing. It also happens when you tap “Enhance with AI”, which additionally lets Gemini look the wine up with Google Search.
Cellarly does not send your name, email address, account ID, prices, purchase dates, rating notes or storage units. Search text and wine names are sent exactly as entered, so anything you type into those fields reaches Google.
Gemini’s answers are saved in the shared catalogue.
Requests are made with the operator’s API key, under the operator’s agreement with Google. How Google may use this data is set by Google’s Gemini API terms. With paid access, and with any access by an operator in the EEA, Switzerland or the UK, Google says it does not use the data to improve its products. It then processes the data as a processor under its data processing addendum and logs it for a limited time, only to detect misuse and to meet legal requirements. With free access outside these regions, Google may use the data to improve its products, and people may review it. Cellarly cannot tell which applies, so ask your operator. When Gemini looks a wine up with Google Search (“Enhance with AI”), Google also stores the request and the answer for 30 days, to provide the search results and to debug and test this function.
Google may process the data outside the EU, including in the USA. Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR).
Fonts
Cellarly’s fonts are part of the software, and your browser loads them from the instance’s own server. To display Cellarly, your browser does not contact Google Fonts or any other outside service.
The font files (Geist and Fraunces) come from Google Fonts. They are downloaded once when the software is built, for example with docker build, and shipped with it. This download is made by the machine doing the build and contains no data about the instance’s users.
Password reset by email (optional)
If the operator has set up a mail server (SMTP), you can request a reset link under “Forgot your password?”. Cellarly then sends an email containing:
- your email address and name,
- a link to set a new password, valid for one hour and usable only once.
The email goes through the mail server chosen by the operator and then through normal email delivery. Emails are only sent to active accounts. Cellarly stores only a hash of the secret code in the link, never the link itself. Requesting a new link cancels older ones. Because the code is part of the link, it can appear in your browser history and in the operator’s web server logs.
Without a mail server, an admin sets a temporary password for you instead.
Camera
Cellarly uses your camera only to photograph wine labels. When you open “Photograph label”, your browser asks for permission and the camera starts. The video stays in your browser. If the camera is unavailable or you deny access, you can select an image file instead. On many phones this opens the camera app. Only the single photo you take or select is uploaded to the instance’s server, and it is passed on to Google only if Gemini is enabled (see above). You can withdraw camera access at any time in your browser’s site settings. Cellarly does not use your microphone, your location or any other device feature.
Cookies and local storage
Cellarly stores the following items in your browser. They are needed to keep you signed in, to remember your settings or to reload the page correctly. Because they are strictly necessary for the service you use, no consent is needed for them (in Germany under § 25(2) No. 2 of the Telecommunications Digital Services Data Protection Act, TDDDG). None of them is used for tracking, analytics or advertising, and Cellarly sets no third-party cookies.
- nuxt-session (cookie): keeps you signed in. It is set as soon as you open any page, including the sign-in page. Until you sign in, it holds only a random session ID and a timestamp. After you sign in, it also contains your user ID, name, email address, role, whether you must change your password, and a session counter. It is encrypted and signed. Scripts cannot read it (HttpOnly), other sites cannot use it for most requests (SameSite=Lax), and it is only sent over HTTPS unless the operator has turned that off for a setup without HTTPS. It has no fixed expiry date: it is cleared when you sign out (the next page you open sets a new, empty one), and in most browsers it is deleted when you close the browser.
- i18n_locale (cookie): your language, detected from your browser or chosen by you. Kept for 365 days.
- vueuse-color-scheme (local storage): light, dark or automatic theme. Kept until you clear your browser data.
- cellarly:preferred-rack-view (local storage): whether you prefer the 2D or 3D rack view. Kept until you clear your browser data.
- nuxt:reload and nuxt:reload:state (session storage): set by the underlying framework (Nuxt) only when the page has to reload itself, for example after the instance was updated. They contain the page address and the current state of the app, which can include your name and email address. They stay in that browser tab and are deleted when you close it.
Logs and IP addresses
- Cellarly does not write access logs and does not store IP addresses in its database.
- To limit sign-in, registration and password reset attempts, the server counts requests per IP address. For this, your IP address is kept only in the server’s memory. Cellarly never writes it to disk, and it is gone at the latest when the server restarts. Cellarly takes the address from the first entry of the X-Forwarded-For header if there is one, otherwise from the connection. Clients can forge that header unless the operator’s reverse proxy overwrites it, so these per-IP limits slow down password guessing but are not a hard cap.
- The server’s console output contains the admin’s email address when the first admin account is created. If a reset email cannot be sent, it also contains the error details, which can include the recipient’s address. If an unexpected server error occurs, it also contains the requested address, which can include catalogue search text or the code from a reset link. Where this output is stored and for how long depends on the operator’s setup.
- Logs of the web server, reverse proxy or hosting provider are outside Cellarly. Whether they record IP addresses or visited addresses, and for how long, is up to the operator.
Retention and deletion
- Your data is kept until you change or remove it, or an admin deletes your account. There is no automatic deletion. Pending and deactivated accounts keep their data.
- When you take out the last bottle in a slot, its record, including purchase date and price paid, is deleted. Only the history entry (wine, quantity, storage unit name, time) remains, and the history is never shortened. You can delete empty storage units. A new rating for a wine replaces your previous rating and note.
- When an admin deletes an account, Cellarly permanently removes it together with its storage units, bottles, ratings, history and reset links. Shared catalogue entries remain, without any link to the account.
- Expired reset-link hashes are removed the next time a new reset link is created.
- Deleted data can physically remain in the database file until it is overwritten, and in any backups the operator keeps. Cellarly has no built-in backup. Backups are up to the operator.
- There is currently no “delete my account” button and no data export. To see, correct, export or delete your data, ask the admin or operator of your instance.
Your rights
Where the GDPR applies (see “Who is responsible”), you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to data portability. Where processing is based on your consent, you can withdraw it at any time with effect for the future. You can also complain to a data protection supervisory authority.
Where processing is based on legitimate interests, you can object to it at any time on grounds relating to your particular situation (Art. 21 GDPR).
Please address these requests to the operator of your instance. The developer has no access to data on instances run by others and therefore cannot handle such requests.
Security
Cellarly protects data as follows:
- Passwords are hashed with scrypt.
- Sessions use an encrypted, signed cookie. Changing your password ends your other sessions. A temporary password set by an admin, deactivation or deletion ends all sessions of the account.
- Viewers cannot change data. The only exception is their own password. Their catalogue searches can still add wines found by Gemini to the catalogue. Only admins can manage accounts. On every request, the server checks that you only access your own cellar data.
- Rate limits: sign-in, registration and password reset 10 attempts per 15 minutes per IP address (not a hard cap, see “Logs and IP addresses”); password change 10 per 15 minutes per account; label recognition and AI enrichment 60 per hour per account; creating or editing a catalogue wine 120 per hour per account. Catalogue search, including searches passed on to Gemini, and adding a vintage to an existing catalogue wine are currently not rate-limited.
- Reset links are stored only as a hash, are valid for one hour and work only once.
- In production, the app sends security headers, including a Content Security Policy, that prevent the app from being embedded in other sites and only allow pages to load content from the instance itself.
- The Docker container runs without root privileges.
Some protections are outside the software:
- Encryption in transit (HTTPS) must be set up by the operator, for example with a reverse proxy.
- Cellarly does not encrypt the database file. The server and its backups need to be protected.
- The registration form reveals whether an email address is already registered.
No ads, no tracking
Cellarly contains no advertising, analytics, tracking, telemetry or crash reporting. It does not sell data. Apart from your instance’s own server, the only outside services involved are the ones described above: Google Gemini (if the operator enables it) and the operator’s mail server (if configured). Cellarly makes no automated decisions about you within the meaning of Art. 22 GDPR and creates no profiles. Gemini only identifies and describes wines. Cellarly has no payment features. It is a wine app and is not aimed at children.
Notes for operators
If you run an instance, you are responsible for the personal data on it. In particular:
- Give your users your own privacy notice with your name and contact details. You can base it on these notes.
- For each purpose, state the legal basis under Art. 6 GDPR and, where you rely on legitimate interests, what those interests are (Art. 13(1)(c) and (d) GDPR). These notes cannot do this for you, because it depends on how and for whom you run your instance. For example, account and cellar data typically fall under Art. 6(1)(b) GDPR, and rate limiting and server logs under Art. 6(1)(f) GDPR, to protect the instance against misuse.
- Tell your users whether Gemini is enabled. Apart from the “Enhance with AI” button, the app does not show which features send data to Google.
- Check which Gemini terms apply to your API key. Paid access, and any access if you are in the EEA, Switzerland or the UK, comes with Google’s processor terms. Google’s terms also allow only paid access when you make an application available to users in the EEA, Switzerland or the UK. Also check whether you need a data processing agreement with your mail or hosting provider.
- Use HTTPS and keep the secure cookie setting on. Protect the server and its backups. Keep the demo login switched off on any instance with real data.
- Configure your reverse proxy to overwrite (not append to) the X-Forwarded-For header, so that the per-IP limits see the real address.
- Decide how long your reverse proxy and server logs, including the server’s console output, are kept.
- Respond to your users’ requests for access, correction, export and deletion. Correcting a name or email address and exporting data currently require direct database access.
Changes
These notes are updated when Cellarly’s behaviour changes, for example how fonts are loaded or which outside services it uses. They describe the software as of 8 October 2026.
Contact
For questions about the software and these notes, write to coderoftime@gmail.com. For questions about your data on a particular instance, contact its operator. More about the developer: Legal notice (Impressum).