Cork is a personal wine recommendation app. We take your privacy seriously. This policy explains what data we collect, how we use it, and what we don't do with it.
CellarTracker credentials. If you connect your CellarTracker account, your username and password are stored securely on your device using iOS Secure Enclave (Expo SecureStore). They are never transmitted to Cork's servers.
Your cellar and drinking history. Wine data synced from CellarTracker, imported from a file or email, or added in the app is stored on your device. When you're signed in, a copy is also stored on Cork's backend, linked to your account, so your agents can work while the app is closed and your cellar comes back on a new device. That copy includes your bottles and their locations, your drinking history and ratings (with any context you add, such as the occasion or who you were with), and your plans: nights you've set bottles aside for, occasions, and cellar runs. If you're not signed in, your cellar is sent to Cork's backend only when needed for a recommendation and isn't kept.
Your taste profile. The preferences Cork learns from your swipes and post-drink ratings are stored locally on your device. If you create an account (see “Account & Email Identity” below), a copy of your taste profile is also stored on Cork's backend, linked to your account, so it can be restored when you sign in on a new device. You can delete it at any time in Settings → Account → Delete my data. Your wishlist and the deal alerts you set up are stored the same way.
Your calendar (optional, only if you allow it). Cork reads your calendar on your device to plan wine around your week. Event titles and details stay on your phone. Cork's backend receives only what a feature needs: for a restaurant reservation, the restaurant's name and the date (so Cork can prepare its wine list); for an occasion, its type and date; and for a contact's birthday, only that it's a birthday and the birth year, when you own a bottle from that year. If you plan a bottle for a night, or choose a wine for a reservation, Cork can add it to a separate “Cork” calendar on your phone; you can hide or delete that calendar in your phone's Calendar app. You can choose which calendars Cork reads, or turn this off, in Settings → Calendar.
Device and app information. To send notifications at the right time and keep the app working, Cork stores your device's push-notification token, a device identifier, your timezone, your notification settings, the app version you're running, and how many bottles your cellar holds.
Photos you scan. When you photograph a label, a shelf or a wine list, the image is sent to our AI provider to identify the wines. Cork doesn't store the photo on its servers.
Feedback you send. If you send feedback from the app, we keep your message, any screenshot you attach, the email address you give (if any), your device identifier, and the app and OS versions, so we can follow up and fix problems.
Usage analytics. Cork collects usage signals by default (feature use, recommendation ratings, swipe counts) through PostHog, keyed to a random device identifier, not to your name or email. No wine lists, credentials or email content are included. You can turn this off at any time in Settings → Privacy, and your choice is remembered. We do not sell this data or use it for advertising.
Gmail data (optional, only if you connect the Email Scanner). If you choose to use Cork's optional Email Scanner, you grant Cork read-only access to your Gmail account (the gmail.readonly OAuth scope). See the dedicated section below for full disclosure of what is and is not accessed.
Why we ask for your email. Cork can keep your data linked to you across devices — if you switch phones, reinstall the app, or factory-reset your device, your taste profile, cellar history, and preferences come back when you sign in again. To make that work, we need a stable identifier we can recognize on any device. We use your email address.
How it works. Enter your email, we send you a one-time login link, you tap it, you're in. There's no password — and no password to forget. This is the “magic link” pattern used by Substack, Notion, Linear, and many other apps.
What we store. Your email address, so we recognize you on return; optionally your first and last name, if you share them, to personalize the app; the devices signed in to your account, so you can revoke any of them in Settings; and login times, for security. Signing in also links the data described under “What We Collect” (your cellar, taste profile, wishlist, plans and agent settings) to your account.
What we don't do. We don't share your email or name with anyone. We don't email you marketing material — only transactional login links and security notifications (e.g. “a new device just signed in”). We don't combine your email with data from other services to track you across the web.
You can skip it. Cork works fully without an email account — your data just stays on the device that created it. The email step is optional and prompted only when Cork detects you might benefit from cross-device sync (typically a few days after install). You can also delete your account at any time in Settings → Account → Delete my data, which immediately wipes both your local data and all backend records.
Cork doesn't collect your location. We don't sell data to third parties and we don't use your data for advertising. If you create an account, see “Account & Email Identity” for what's linked to it.
CellarTracker. Cork connects to CellarTracker from your device with the credentials you enter. They're stored on your device and never sent to Cork's servers. CellarTracker's privacy policy governs that data.
Anthropic (Claude). Cork's recommendations, answers in Ask, wine identification from photos, and email extraction are generated by Claude, Anthropic's AI model. Requests can include your cellar, taste profile, the question you asked, a photo you scanned, or (if the Email Scanner is on) the text of an email Cork uses. Some agents also have Claude search the web for public information about wines, such as critic scores or vintage reports; those searches contain wine names, not information about you. Anthropic's privacy policy applies to data processed by Claude.
Google (Gmail API). If you connect the Email Scanner, Cork uses Google's OAuth and Gmail APIs as described in the Gmail section below. Google's privacy policy applies to that connection.
Email forwarding (Mailgun). If you forward receipts to your personal Cork address, our email provider Mailgun receives them and passes them to Cork, which reads them the same way as the Email Scanner and doesn't keep the message.
Notifications (Expo). Push notifications are delivered through Expo's push service using your device's push token.
Sign-in email (Resend). Login links and security emails are sent through Resend.
Analytics (PostHog). See “Usage analytics” above.
The Email Scanner is an opt-in feature that reads the wine-related email in your Gmail, such as purchase receipts, wine offers, allocations, auction catalogs and restaurant reservations. Cork uses it to keep your cellar up to date and to power the agents you turn on. It is never enabled automatically. You can disconnect at any time from Settings, which immediately deletes our copy of your Google refresh token.
What we access. Cork's Gmail searches only find wine-related email. Every search requires either a known wine sender or a wine word. Wine senders are wine retailers, wineries, wine clubs and wine apps, wine auction houses, and restaurant-booking services such as OpenTable, Resy, Tock, SevenRooms and Yelp reservations. Yelp email is matched only when its subject is about a reservation. Wine words are “wine”, “winery”, “vineyard”, “sommelier”, or a grape or region name, such as “cabernet” or “Barolo”. Mail from senders that also send non-wine email, such as general auction houses and restaurant payment systems like Toast or Square, is matched only when it mentions wine. Email with no wine signal, such as a shopping order, a bill or a flight reservation, is never searched up or read.
What we read. For each matched email, Cork first reads only the sender, subject and a short preview. It reads the full message only when one of your Cork features uses it. Other matched email is counted from its preview only.
What we extract. From each email Cork uses, we extract structured wine information only. That covers a purchase (producer, wine, vintage, quantity, price, merchant, date), an offer (wine, price, retailer, how long it lasts), a reservation (restaurant, date, party size), an allocation or release window, or an auction lot. Purchases are shown to you for review before anything is added to your cellar.
What we store. The Google refresh token is stored on Cork's backend so Cork can check for new wine email once a day, and when you open the app if it hasn't checked in a day. Extracted results are stored on your device. Results that become an agent card, such as an offer or a reservation reminder, are also stored with your account so the card can be shown to you. The raw text and HTML of your email messages is never persisted. It is processed in memory and then discarded.
What we never do. We do not read email outside the searches above. We do not use your Gmail data for advertising, model training, or any purpose other than your cellar, your wine recommendations, and the Cork agents you have turned on (purchases and order tracking, wine offers and deal alerts, allocations and releases, restaurant reservations and bills that include wine, auction catalogs and results, and futures). We do not transfer your Gmail data to any third party except the AI provider needed to extract wine information (Anthropic Claude), and only as required to deliver the user-visible feature you requested. No human at Cork reads your email content except as strictly required to debug an error you have reported, investigate suspected abuse, or comply with applicable law.
Limited Use compliance. Cork's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting. Open Settings → Cellar sources → Email → Disconnect. This wipes our refresh token immediately and stops all future scans. Past extraction results that you accepted into your cellar remain on your device under your control; you can delete them in Settings → Privacy & data → Reset all data.
All local Cork data can be deleted in Settings → Privacy & data → Reset all data. Uninstalling the app removes local data.
If you created an account, your backend records (your cellar copy, taste profile and drinking history, wishlist, plans, deal alerts, agent settings and cards, Email Scanner refresh token, and login sessions) are deleted via Settings → Account → Delete my data, within 30 days of the request. Email us at support@getcork.ai if you've lost access to the account and need help wiping it.
If you are a California resident, you have the right to know what personal information we hold about you, to receive a copy of it, to request its deletion, and not to be discriminated against for exercising these rights. Cork does not sell your personal information. You can exercise these rights in the app: Settings → Account → Export my data (a copy of everything tied to your account) and Delete my data (removes your local data and all backend records, completed within 30 days). You can also email support@getcork.ai.
Cork is intended for adults of legal drinking age. By using Cork you confirm that you are 21 or older (or the legal drinking age in your jurisdiction). We do not knowingly collect information from anyone under that age; if we learn that we have, we delete it.
Your use of Cork is also governed by our Terms of Service.
We may update this policy as Cork evolves. When we make material changes we will update the “Last updated” date above and, where appropriate, notify you in the app. Continued use of Cork after a change means you accept the updated policy.
Questions? Reach us at support@getcork.ai.
© 2026 Cork. All rights reserved.