VinePilot Privacy Policy
Effective date: 12 September 2026 Last updated: 12 September 2026
VinePilot is operated by Blockover Corp, a Wyoming corporation ("Blockover", "we", "us"). This policy explains what information VinePilot collects, why, who sees it, how long we keep it, and the choices you have. It covers the VinePilot website and web app at vinepilot.org and the VinePilot browser extension (together, the "Service").
VinePilot is not affiliated with Amazon. Amazon's own privacy notice governs what Amazon does with your data.
1. Summary
- We collect your email address and display name to run your account.
- We collect the Amazon Vine pages you visit or that the extension fetches for you (your review queues, orders, account statistics, tax report, and the items shown to you), plus public product pages and other customers' public reviews, to help you write reviews and track your Vine activity.
- We store a one-way hash of your Amazon customer id, never the id itself, and never your Amazon password, phone number, or address.
- Photos you upload are stripped of location and camera metadata and deleted after Amazon confirms your review (or after 30 days if you abandon the draft).
- Product-level information is pooled across all users to build shared summaries. Your personal information is never shared with other users and never sold.
- Google is optional. Sign in with Google gives us your email, name, and picture. Connecting Google Photos lets you pick photos through Google's own picker — it gives us no access to your library, only the items you choose (section 10).
- We use AI providers to generate summaries and drafts. They receive product information and the notes you type, not your identity, and never your photos.
- You can export or delete everything at any time.
2. Information we collect
2.1 Account information (you give it to us)
| Data | Source | Why |
|---|---|---|
| Email address | Sign-up (magic link) or Google sign-in | Sign you in, send sign-in links and service notices |
| Display name, profile picture | Google sign-in (optional) or set by you | Show who is signed in |
| Time zone, theme | Set by you | Preferences |
| Google account connection (encrypted tokens) | Only if you connect Google Photos | Let you pick photos from Google Photos. Tokens are encrypted at rest; you can disconnect at any time. |
2.2 Amazon identity (derived)
When the extension first runs on an Amazon marketplace, it reads your Amazon customer id from the page you are signed in to and sends it to our server, which immediately computes a SHA-256 hash and stores only the hash, together with the display name Amazon shows for you and your Vine tier (for example "Silver" or "Gold"). We use the hash to:
- link your VinePilot account to your Vine account on each marketplace;
- make sure one Vine account is not linked to two VinePilot accounts; and
- keep per-account limits and fair-use budgets tied to the Vine account rather than to an email address.
We do not collect your Amazon password, payment methods, phone number, or postal address. Where an Amazon page contains your address (for example the orders page), the extension removes that block before anything leaves your browser.
2.3 Amazon Vine pages (collected by the extension)
The extension fetches pages inside your own signed-in Amazon session, at a paced rate set by our server and spread out over time rather than fetched all at once, and sends a trimmed copy of each page to our server, where it is parsed and then discarded. From these pages we keep the structured data, which includes:
| Page | What we keep |
|---|---|
| Vine review queues ("Awaiting review", "Reviewed") | Item titles, ASINs, images, order dates, review status, your review quality scores, ids of your own reviews |
| Your own reviews | Title, body, rating, media list, date, quality score |
| Vine account page | Tier, evaluation period, member-since date, total reviews, review-to-order percentage, insightfulness rating, reviews-with-media percentage, estimated taxable value totals by year |
| Vine orders page and tax report (spreadsheet) | Item titles, ASINs, order ids, order / ship / cancel dates, estimated taxable value (ETV) per item |
| Vine item lists ("Recommended for you", "Available for all", "Additional items") and their categories | Which items were on offer, in which category, at what position and ETV, and when |
| Review submission page | The form state needed to post or edit your review (create-vs-edit mode and a one-time token) |
We also capture pages you visit yourself on the Amazon Vine site while the extension is installed (the same page types as above). This is on by default and can be turned off in Settings ("Contribute pages I visit"). Pages outside /vine/ are never captured.
2.4 Public product information (collected by the extension)
For items in your queue, and as part of the shared catalog (section 5), the extension fetches public Amazon pages: product detail pages and other customers' public reviews. From these we keep product title, brand, images, features, description, rating, review count, and the public reviews (reviewer display name as shown publicly, rating, title, body, date, country, verified / Vine badges, helpful votes, review image URLs).
2.5 What you type and upload
- Notes, ticked points, tones, star rating, and edits you make while drafting a review.
- Outside links you paste (for example a manufacturer page or an article). We fetch the page content once, without your cookies, and keep the text to inform the summary.
- Photos and videos you add to a review, from your computer, Google Photos, or your phone. On upload we remove EXIF and similar metadata (including GPS location, device make and model, and capture time) and, if you crop or rotate, produce an edited copy.
- Tax flags you set (consumable, brand-name, fair-market-value override).
2.6 Technical and usage information
- Extension version, browser type, the Amazon marketplaces you have enabled, and the time your extension last checked in.
- A per-device token we issue (stored hashed on our side) and the IP address of the last check-in.
- Task and check-in logs: which fetches ran, how long they took, and whether they succeeded (for example "signed out", "network error"). These feed your contribution scorecard (pages fetched, tasks completed) and our reliability metrics.
- AI usage: model, tokens, cost, and latency for each summary or draft generated for you.
- Standard server logs (IP address, user agent, timestamps) retained briefly for security.
- We do not use third-party advertising or analytics trackers on the Service.
2.7 Cookies
vinepilot.org uses a session cookie to keep you signed in and a preference cookie for theme. No advertising cookies. The extension does not set cookies on Amazon and does not read Amazon's cookies; requests simply run in your existing session.
3. How we use information and our legal bases
| Purpose | Data | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Run your account, sign you in, send service email | Account information | Contract |
| Show your review queue, deadlines, quality scores, ETV totals | Amazon identity, Vine pages | Contract |
| Generate product summaries and review drafts | Public product information, outside links, your notes | Contract |
| Post or edit your review on Amazon when you ask us to | Draft, photos, submission page state | Contract |
| Build and improve the shared product catalog | Product-level information from pages you and others fetch | Legitimate interests (making summaries available to all members); you can opt out of contributing pages you visit |
| Enforce per-account limits and fair use of fetch budget | Amazon identity hash, usage logs | Contract, legitimate interests |
| Security, abuse prevention, debugging | Technical information, short-lived raw page samples | Legitimate interests |
| Comply with law | Any | Legal obligation |
We do not use your information to build advertising profiles, and we do not make decisions about you with legal or similarly significant effects by automated means.
4. AI processing
VinePilot uses large language models from third-party providers (currently Anthropic; we may add other providers) to produce two things:
- Product summaries: ranked positives, negatives, red flags, and a guess whether an item is a consumable or a brand-name product (for tax flagging). Inputs are product information, other customers' public reviews, and any outside links a user supplied. No account or identity data is sent.
- Review drafts: written from the summary points you ticked, your notes, your star rating, and your chosen tone. Your notes are sent as you typed them; your name, email, and Amazon identity are not.
Photos and videos are never sent to an AI provider. That includes photos you import from Google Photos. The model is told only how many images are attached, as a number, so it can refer to them in the text it drafts; the image itself never leaves our storage for a model.
Providers process this data to return a result and are bound by their API terms not to train on it. Summaries are cached and shared with other users (section 5); drafts are private to you. You are the author of what you post: drafts are suggestions, and you review and edit them before anything goes to Amazon.
5. Sharing
5.1 The shared catalog (product-level data, pooled)
Product pages, public reviews, category listings, which items appeared in Vine and when, and AI summaries are stored once per product and shown to every VinePilot user. This is how one user's fetch saves everyone else a fetch. The catalog contains no personal data about VinePilot users: not your name, email, identity hash, orders, quality scores, drafts, notes, or photos. Internally, a catalog row records which account contributed it so we can measure contributions and remove abusive data; that provenance is never displayed to other users.
Other customers' public reviews in the catalog are already public on Amazon, including the reviewer's public display name. If you are an Amazon reviewer and want your public review removed from our catalog, contact us (section 13).
5.2 Service providers (processors)
| Provider | What they process | Where |
|---|---|---|
| Vercel (hosting, file storage) | All Service data in transit and photos / short-lived raw page samples at rest | United States |
| Neon (database) | All structured data | United States (AWS us-east-1) |
| Anthropic and any other AI provider we list at vinepilot.org/privacy | Product information, public reviews, outside links, your notes | United States |
| Resend (email) | Your email address and sign-in links | United States |
| Google (optional) | Sign in with Google; Google Photos Picker if you connect it | Per Google's policy |
Each processes data only on our instructions under a data processing agreement.
5.3 Everyone else
We do not sell personal information and have not done so. We do not share personal information with advertisers or data brokers. We may disclose information when required by law, to protect the rights and safety of users or the public, or as part of a merger or acquisition (with notice to you). Amazon receives only what you choose to post through the Service, exactly as you would by posting yourself.
6. Retention
| Data | Kept for |
|---|---|
| Account, identity hash, queue, orders, own reviews, drafts, tax flags, account snapshots | While your account exists; deleted within 30 days of account deletion |
| Photos and videos you upload (original and edited copies) | Deleted automatically when Amazon confirms the review that used them, or 30 days after last activity if the draft is abandoned; you can delete them at any time |
| Raw copies of fetched pages | Normally discarded immediately after parsing. A copy is kept for up to 14 days only when parsing fails or as a 1 % quality sample; then deleted |
| Task, check-in, and AI usage logs | 90 days in detail; aggregated daily scorecard while your account exists |
| Server access logs | 30 days |
| Shared catalog (product-level, no personal data) | Indefinitely; refreshed as products change |
| Google sign-in profile (email, name, picture) | While your account exists, like any other account information |
| Google Photos connection tokens | Until you disconnect in Settings, revoke access at myaccount.google.com, or delete your account — whichever comes first |
| Photos imported from Google Photos | Exactly as for photos you upload: deleted when Amazon confirms the review, or 30 days after last activity |
7. Security
- All traffic uses HTTPS. The extension only communicates with Amazon (in your own session) and vinepilot.org; server CORS rules accept requests only from the published extension.
- Amazon customer ids are hashed before storage; device tokens are stored hashed; Google tokens are encrypted at rest with a key held separately from the database.
- Photos are stored in private storage and served only through short-lived signed URLs.
- Access to production data is limited to Blockover staff who need it, with two-factor authentication, and administrative actions are logged.
- No method is perfectly secure. If we learn of a breach affecting your personal data we will notify you and the relevant authorities as the law requires.
8. International transfers
Blockover Corp is in the United States and our providers store data there. If you use the Service from the EU, UK, or another region with data transfer rules, your data is transferred to the United States. We rely on Standard Contractual Clauses (and the UK Addendum) with our processors and, where a provider is certified, the EU-U.S. Data Privacy Framework.
9. Browser extension disclosures
This section restates, for the browser extension specifically, the disclosures Chrome Web Store and other stores require.
- Single purpose. The extension exists to help Amazon Vine members write their reviews and track their Vine activity. It does nothing on sites other than Amazon and vinepilot.org.
- Permissions.
storage(your VinePilot token, chosen marketplaces, settings, an hourly page counter),alarms(the periodic check-in), and access to the Amazon marketplaces you enable plus vinepilot.org. Optional marketplaces are requested only when you enable them. - What it reads. Amazon Vine pages (
/vine/*) and, when working on an item, public product and review pages, all inside your own signed-in session. It does not read other tabs, your browsing history, passwords, or cookies. - What it stores locally. Only the items under
storageabove. No Amazon page content is kept in your browser. - What it sends. Trimmed copies of the pages above and the results of tasks it ran, to vinepilot.org only.
- Remote code. None. The VinePilot web app appears inside the extension in an iframe as an ordinary web page; the extension's own code is entirely in the package.
- Data use certification. We do not sell your data, do not use it for purposes unrelated to the extension's single purpose, and do not use it to determine creditworthiness or for lending.
- Uninstalling the extension stops all collection immediately. Your account and data remain until you delete them (section 11).
10. Google user data
Two separate, optional Google features. Each asks for its own consent, and you can use VinePilot without either.
10.1 Sign in with Google
If you choose "Continue with Google" instead of an emailed sign-in link, we request the scopes openid, email, and profile. We receive your email address, your name, and your profile picture, and use them only to create and identify your account — the same information we would hold if you signed up by email. We do not receive your Google password, your contacts, or anything else in your Google account.
10.2 Google Photos
If you connect Google Photos, we request one scope: https://www.googleapis.com/auth/photospicker.mediaitems.readonly.
This scope does not give VinePilot access to your photo library. We cannot list, search, or browse your photos. Picking happens in Google's own picker, hosted by Google, and we receive only the specific items you select there for the review you are working on. If you pick three photos, those three are all we ever see.
- How we access it. Our server exchanges your consent for an access token and a refresh token, then downloads the bytes of the items you picked.
- How we use it. Only to attach those photos to the Amazon review you are writing. Nothing else.
- How we store it. Photos go to our media storage, stripped of location and camera metadata on arrival, exactly like photos you upload from your computer. Tokens are encrypted at rest with AES-256-GCM.
- How long we keep it. Photos are deleted when Amazon confirms the review that used them, or 30 days after you last touch an abandoned draft. Tokens are kept until you disconnect, revoke, or delete your account.
- Who else sees it. Nobody. Photos are not shared with other users, not included in the shared catalog, not sold, and never sent to an AI provider (section 4).
10.3 Limited Use
VinePilot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, we do not and will not:
- use Google user data for advertising, or transfer it to anyone for advertising;
- sell Google user data;
- allow humans to read it, except with your explicit consent for a support request you raised, where it is necessary for security or to comply with law, or on data that has been aggregated and anonymised;
- use it to develop, improve, or train generalised artificial intelligence or machine learning models. Our AI features never receive your photos at all (section 4).
10.4 Disconnecting
You can disconnect Google Photos at any time from Settings → Google Photos → Disconnect. That deletes our copy of your tokens immediately; any photos already attached to a draft stay with that draft until the draft is posted or expires, and you can delete them individually from the photos step.
You can also revoke VinePilot's access from your Google account directly at myaccount.google.com/permissions. Revoking there stops any further access; we discover it the next time we try to use the connection, and treat it as disconnected.
Deleting your VinePilot account deletes the connection and its tokens along with everything else (section 11).
11. Your rights and choices
Everyone, regardless of location, can do the following from Settings or by emailing privacy@vinepilot.org:
| Right | How |
|---|---|
| Access / export | Settings -> Export: a JSON and CSV bundle of everything tied to your account, usually ready within minutes |
| Correct | Edit your profile, tax flags, and drafts in the app; ask us for anything else |
| Delete | Settings -> Delete account: removes all personal data within 30 days and revokes every device. Catalog rows you contributed stay, with your account reference removed, because they contain no personal data |
| Restrict / object | Turn off "Contribute pages I visit"; disconnect Google; uninstall the extension; or object to a legitimate-interests use by email |
| Portability | The export above is machine-readable |
| Withdraw consent | Where we rely on consent (Google Photos), disconnect at any time |
| Complain | You may complain to your local data protection authority. We would appreciate the chance to address your concern first |
We will respond within 30 days (45 days for CCPA requests, extendable once). We may need to verify your identity, typically by confirming access to your account email. We do not discriminate against you for exercising these rights.
12. Children
The Service is for adults who are members of Amazon Vine. It is not directed to anyone under 18, and we do not knowingly collect information from children under 16. If you believe a child has provided us personal information, contact us and we will delete it.
13. Contact
Blockover Corp, a Wyoming corporation privacy@vinepilot.org
Write to us at that address for anything in this policy, including the rights in section
- We answer within 30 days. If you need a postal address for a formal notice, ask and
we will provide it.
14. Additional information for California residents
Under the CCPA/CPRA, the categories of personal information we have collected in the past 12 months are: identifiers (email, display name, hashed Amazon id, device token, IP address); commercial information (Vine orders, items received, estimated taxable value); internet or network activity (Vine pages visited, extension check-ins); audio/visual information (photos and videos you upload); and inferences (none about you personally; product-level summaries only). Sources, purposes, and recipients are described in sections 2, 3, and 5.
We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information other than to provide the Service. You have the rights to know, delete, correct, and to non-discrimination described in section 11. You can appoint an authorized agent by giving them written permission; we may ask them to prove it.
15. Additional information for the EU, UK, and Switzerland
The controller is Blockover Corp (section 13). Legal bases are in section 3. Transfers are in section 8. Retention is in section 6. You may lodge a complaint with your supervisory authority; in the UK that is the Information Commissioner's Office.
16. Changes to this policy
We will post any changes here with a new "Last updated" date. For material changes we will email you or show a notice in the app at least 14 days before they take effect, and where the law requires, ask for your consent.
