Privacy Policy
Last updated July 29, 2026
Cipher is operated by Cipher Tracker LLC, a limited liability company registered in Illinois. This policy covers the Cipher mobile app and this website.
Questions go to app@cipher-app.org.
What Cipher collects
Data you enter into trackers
Cipher tracks 12 categories: alcohol, caffeine, cannabis, nicotine, screen time, calories/food, sleep, exercise, hydration, medication, menstrual cycle, and journal entries.
All of it is encrypted on your device before being stored or synced. The key is derived from your password, which never leaves your device. We store only the encrypted output, so we have no way to read any of it — including the sensitive parts, like substance use, medication, and cycle records.
Your username and password
When you set up Cipher you choose a username and a password. Neither is stored the way you might expect:
- Your password never reaches us. It stays in your device's secure storage (iOS Keychain or Android Keystore) and is used only on-device to derive your encryption key.
- Your username is sent to our server, but only so it can be converted into an account identifier by a one-way hash. We store that derived identifier, never the username itself. Your account is a row of random-looking characters to us.
- To sign you in, your device computes an authentication verifier from your password and sends that instead of the password. It cannot be turned back into your password and cannot decrypt anything.
The complete account record on our servers is this and nothing else:
| Field | What it is |
|---|---|
| Account identifier | A hash derived from your username |
| Authentication verifier | A password-derived value used to check sign-ins |
| Encryption salt | A random value used in key derivation — useless on its own |
| Created / last updated | When the account was made and last synced |
| Failed sign-in counter | Rate-limits brute-force attempts, then clears |
If you set up a PIN for daily unlock, the PIN-derived key material stays on your device. The PIN is never sent to us.
We do not collect an email address
Cipher has no email field. Signing up asks for a username and password only, and the app never asks for an email address, phone number, or real name at any point. We also do not collect precise location, contacts, photos, browsing history, advertising identifiers, or biometric data.
Subscription information
If you subscribe, Apple or Google processes the payment — that is the only payment path, and we never see your card details, billing address, or store account identity.
We use RevenueCat to manage subscriptions. It receives the purchase identifier, transaction history, and subscription status so we can restore access on every device you sign in from. It identifies you by the same derived account identifier described above — pseudonymous, not anonymous: it is stable and tied to your account, though it does not reveal your username. RevenueCat never receives your encrypted health data, your password, or any tracker entries.
Food search and barcode lookups
Food search and the barcode scanner send your search term or barcode number to our own server, which is signed in as your account and queries FatSecret on your behalf. We route it this way so our nutrition database credentials never ship inside the app.
Android Usage Access
On Android, enabling the Screen Time tracker asks for Usage Access so Cipher can read daily screen-time totals. This is read only when you open that tracker, is encrypted like any other entry, and is never used for advertising or profiling. Revoke it any time in Android Settings → Apps → Special access → Usage access.
Camera
The camera is used only to scan food barcodes. The image is processed on-device to read the barcode and is not saved, uploaded, or shared. No photographs are taken or retained.
Notifications
Reminders are scheduled entirely on your device. Cipher does not use push notifications and never creates or transmits a push token, so we cannot message you and cannot see whether a reminder fired.
Exercise images
Exercise demonstration images load directly from a public GitHub repository (the Free Exercise DB). When one loads, GitHub receives your IP address and which image was requested. We do not control GitHub's logging.
Connection data
We collect the device platform, app version, and subscription status. Separately, when your device syncs, our cloud provider necessarily receives your IP address and a timestamp, as any internet service does. An IP address can indicate approximate region. We do not use it to track you or build profiles, and it is not part of your account record.
This website
The site runs no analytics, no advertising, and no tracking cookies — no Google Analytics, no Meta SDK, nothing equivalent. If you use the contact form, we receive the name, email address, subject, and message you type, purely so we can reply. We hold an email address only when you choose to hand us one. The same goes for surveys: responses are voluntary, reach us as a single email, and are anonymous unless you choose to include a reply address. We keep no database of them — they sit in our inbox like any other correspondence.
How your data is stored
Encryption
- Keys are derived from your password with PBKDF2-HMAC-SHA256 at 200,000 iterations. Entries written by older versions used 50,000 and are upgraded when re-saved.
- AES-256-CTR, with a random 128-bit salt generated per account
- A fresh random initialization vector for every encryption operation
- HMAC-SHA256 integrity verification, so tampering is detectable
- Your password never leaves your device
Encrypted entries are stored in Google Firebase Firestore. Sign-in uses Firebase Authentication with a custom token our server mints from your account identifier — there is no email-and-password sign-in and no email address involved.
What our cloud provider can see
Firebase can see that encrypted data exists, its size, when it last synced, the salt, and your IP address.
It cannot see what you tracked, when you tracked it, or any pattern in it. Neither can Google, nor we, nor anyone who obtained the database.
On your device
- Your password, in iOS Keychain / Android Keystore
- Your PIN-derived key material, in secure storage
- Cached entries, encrypted with the same scheme
- App preferences and settings
Why we process it, and our legal basis
For users in the European Economic Area and the United Kingdom, the GDPR requires a stated legal basis for each purpose:
| What we do | Legal basis |
|---|---|
| Store and sync your encrypted entries | Contract — Art. 6(1)(b) |
| Maintain your account record and verify sign-ins | Contract — Art. 6(1)(b) |
| Rate-limit failed sign-ins; pin certificates | Legitimate interests — Art. 6(1)(f) |
| Answer food searches and barcode lookups | Contract — Art. 6(1)(b) |
| Manage subscriptions and entitlements | Contract — Art. 6(1)(b) |
| Receive and reply to contact form messages and survey responses | Legitimate interests — Art. 6(1)(f) |
| Delete accounts after prolonged inactivity | Data minimisation — Art. 5(1)(e) |
Health data. The tracker categories above are special category data under Article 9. We hold them only in a form we cannot decrypt, so we have no access to their content. To the extent Article 9 applies, we rely on your explicit consent under Art. 9(2)(a), given when you enable a tracker and enter data into it. Withdraw it any time by deleting your data in the app; withdrawal does not affect processing already carried out.
Who else is involved
| Service | What they receive | Where |
|---|---|---|
| Google Firebase — hosting, sign-in, food proxy | Encrypted blobs (unreadable), account identifier, IP address, timestamps | United States |
| RevenueCat — subscriptions | Pseudonymous account identifier, purchase and subscription status, device metadata | United States |
| FatSecret — nutrition database | Search terms and barcode numbers, relayed by our server | Australia / US |
| Apple / Google — in-app purchases | All payment data; we receive none of it | Global |
| GitHub — public-domain exercise images | Your IP address and the image requested | United States |
| Proton AG — contact form and survey delivery | The name, email, subject and message you type into the contact form; survey responses, with a reply email only if you volunteered one | Switzerland |
| Vercel — website hosting | Standard web server request logs | United States |
We use no advertising SDKs, no analytics, and no data brokers.
International transfers
We are based in the United States and, with one exception, these providers process data there. The exception is Proton AG, which processes mail in Switzerland — a jurisdiction the EU and UK both recognise as adequate, so no further transfer mechanism is needed for it. For the US providers, where personal data leaves the EEA or UK we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. In practice the transferred tracker data is encrypted with a key we do not hold, so it is unintelligible to any recipient — including any authority that compels disclosure.
How long we keep it
| Data | Retention |
|---|---|
| Encrypted entries and account record | Until you delete it, or nine months of inactivity |
| Failed sign-in counters | Cleared on successful sign-in |
| Food search queries | Not retained once the lookup is answered |
| Contact form messages and survey responses | Up to 24 months, then deleted |
We keep no backups of deleted data. When it's gone, it's gone.
Your rights
Depending on where you live you have some or all of these rights. We honour all of them for everyone, regardless of location.
- Access — a copy of what we hold about you
- Rectification — correct anything inaccurate
- Erasure — have it deleted
- Restriction — ask us to limit processing
- Portability — receive it in a machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — at any time
- Complain — to your data protection authority
Export
Deleting your data
Delete everything from Settings inside the app — this erases your encrypted entries and account record from both the device and our servers, permanently. You can also request deletion from the web without reinstalling, at cipher-app.org/delete-account.
No password recovery
There is no recovery mechanism. Your password is the only way to derive your key. If you lose it, nobody — including us — can recover your data. That is intentional.
Making a request
Email app@cipher-app.org. We respond within 30 days, extendable by 60 for complex requests where the law permits, with notice to you. We will never charge you or treat you differently for asking. Since we hold nothing identifying beyond an account identifier, we may ask you to demonstrate control of the account first.
California, and other US states
We have never sold or shared personal information, and we do not now — not in the preceding 12 months, and not for anyone under 16.
In CCPA terms we collect: identifiers (account identifier, IP address; name and email only if you use the contact form, or an email address alone if you volunteer one in a survey), commercial information (subscription status), internet activity (food search terms), and sensitive personal information (health data, held only in encrypted form we cannot read). We use sensitive personal information solely to provide the service you asked for, and never for purposes that would trigger the right to limit under Civil Code § 1798.121.
California residents have the right to know, delete, correct, opt out of sale or sharing (not applicable — we do neither), limit use of sensitive personal information, and to non-discrimination. Exercise any of them by emailing app@cipher-app.org, in-app, or at cipher-app.org/delete-account. You may use an authorized agent; we will ask for proof.
Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana grant substantially similar rights, and we use the same process for residents of those states.
Washington and Nevada health data
Washington's My Health My Data Act and Nevada's SB 370 set specific rules for consumer health data. Because Cipher is a health tracker, we keep a separate policy covering them: Consumer Health Data Privacy Policy.
Cookies, children, and security
Cookies
No analytics cookies, no advertising cookies, no third-party trackers. Anything set is strictly necessary for the site to function, so there is nothing to opt out of and no cookie banner. The app uses no cookies, no advertising identifiers, and no cross-app tracking — which is why it never shows an App Tracking Transparency prompt.
Children
Cipher is for adults, 18 and over. It tracks alcohol, cannabis, and nicotine, and is not designed for minors. We do not knowingly collect data from children; if we learn an under-18 account exists we delete it. Report one to app@cipher-app.org.
Security
- Certificate pinning on connections to our cloud provider, blocking man-in-the-middle attacks
- PIN-protected access with rate-limited lockout after repeated failures
- Hardware-backed credential storage via iOS Keychain and Android Keystore
- Owner-only server rules — an authenticated account can reach only its own records
- Redacting logger, so secrets never reach logs
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant authorities as the law requires.
Changes, and how to reach us
If this policy changes we update the date at the top. For significant changes we notify you in the app and, where required, ask for your consent before the change takes effect.
You may also complain to your local supervisory authority — in the UK, the Information Commissioner's Office at ico.org.uk.
Cipher Tracker LLC
2936 N Dawson Ave, Chicago, IL 60618, United States
© 2026 Cipher Tracker