Privacy policy
Botilo · Last updated September 21, 2026
Data you add
Botilo stores bottle details, tasting records, shelf locations, and photos you choose to add.
Storage and iCloud
Botilo keeps a local copy on your device. When iCloud is available, SwiftData synchronizes it through your private iCloud database so it can appear on your Apple devices. The developer does not receive or view that private data.
No separate account
Botilo does not require a separate sign-in or use advertising tracking. iCloud uses your Apple Account. For registration balances, Botilo verifies an Apple-signed app transaction and creates a pseudonymous customer identifier; your Apple email address is not shared with Botilo.
Photos and camera
Camera and photo-library access are used only when you choose a photo for a bottle or tasting record. Photos are copied into the app's local data store.
Bottle photo processing
Photo creation and label reading are part of adding a bottle. With your agreement, bottle photos are sent through Botilo's Cloudflare-hosted server to OpenAI for image creation and label reading. Processing runs automatically for future bottle photos. Label reading does not use web search. Printed fields that are not visible or legible are left blank, except that for a confidently identified wine Botilo may suggest a missing country, region or grape variety from general wine knowledge; such values are marked "Suggested" before saving and can be edited or cleared. Capacity, alcohol content and vintage are never inferred. Tasting notes and your cellar database are not sent. No bottle photos are sent before you agree.
Withdrawing photo consent
Open My cellar → AI photo processing and turn off Allow photo processing to stop new bottle-photo uploads. Your saved bottles remain available. Monthly limits and period end dates still apply. You can enable processing again from the same screen. Withdrawing consent does not cancel Botilo Plus or remove photos already sent; those photos follow the retention policy below. Contact support to request server-data access or deletion.
Processing and retention
Source photos are processed in memory by Botilo's server. Generated bottle photos and label results are kept until the app confirms a local copy has been saved, or for a 30-day recovery window if delivery is interrupted; expired results are removed automatically. Optional back-label reading sends the front and back photos together. Supplemental label results and photo fingerprints used to prevent duplicate processing are retained for up to 30 days after the original registration; the source photos are not stored on Botilo's server. An on-device recovery cache is excluded from device backups and pruned after 30 days or when it exceeds 100 MiB. OpenAI normally retains API content for up to 30 days for abuse monitoring, with longer retention where required by law or necessary for safety under its policy. OpenAI does not use API inputs and outputs for model training by default. Botilo retains pseudonymous purchase, balance and registration records to restore unused registrations and prevent duplicate charges. Device authentication identifiers and short-lived sessions protect access. Infrastructure providers also process technical network information under their policies.
Purchases
Apple handles payment. RevenueCat receives your pseudonymous customer identifier, purchase history, subscription state and technical app information for purchase validation, restoration and revenue reporting. Botilo receives purchase and refund events to maintain your registration balance. No payment-card details, bottle photos, tasting notes or cellar database are sent to RevenueCat. Purchase records are not used for advertising tracking.
Background sync
The app uses silent system notifications to keep your private iCloud data up to date. It does not send marketing alerts.
Home Screen widget
The Cellar widget shows the names and images of your newest bottles. It reads a small snapshot that the app saves in its shared app-group container on this device. The widget does not use the network, and nothing from it is sent to Botilo's server or any other party.
Backups
The app keeps up to five full backups on this device, including automatic snapshots and recovery copies made before restore or deletion. My cellar → Backup lets you restore a recovery copy or save a copy to Files. Shared backups contain your photos and notes; access to those copies is controlled by the destination you choose.
Deleting data
My cellar → Backup includes Delete everything. The app first creates a local recovery backup, then deletes the cellar. When iCloud sync is available, that deletion also synchronizes to your other devices. This also clears the on-device AI recovery cache. It does not cancel a subscription or erase unused paid registrations. Contact support for server-data access or deletion requests; transaction records needed for outstanding balances, fraud prevention or legal obligations may need to be retained.
Provider policies: OpenAI · RevenueCat · Cloudflare.
Contact
Operated by Sakino Tomiura, Japan. Email support@botilo.download.