Privacy Policy

Last updated July 29, 2026

Cipher is operated by Cipher Tracker LLC, a limited liability company registered in Illinois. This policy covers the Cipher mobile app and this website.

Questions go to app@cipher-app.org.

Section 1

What Cipher collects

Data you enter into trackers

Cipher tracks 12 categories: alcohol, caffeine, cannabis, nicotine, screen time, calories/food, sleep, exercise, hydration, medication, menstrual cycle, and journal entries.

All of it is encrypted on your device before being stored or synced. The key is derived from your password, which never leaves your device. We store only the encrypted output, so we have no way to read any of it — including the sensitive parts, like substance use, medication, and cycle records.

Your username and password

When you set up Cipher you choose a username and a password. Neither is stored the way you might expect:

  • Your password never reaches us. It stays in your device's secure storage (iOS Keychain or Android Keystore) and is used only on-device to derive your encryption key.
  • Your username is sent to our server, but only so it can be converted into an account identifier by a one-way hash. We store that derived identifier, never the username itself. Your account is a row of random-looking characters to us.
  • To sign you in, your device computes an authentication verifier from your password and sends that instead of the password. It cannot be turned back into your password and cannot decrypt anything.

The complete account record on our servers is this and nothing else:

FieldWhat it is
Account identifierA hash derived from your username
Authentication verifierA password-derived value used to check sign-ins
Encryption saltA random value used in key derivation — useless on its own
Created / last updatedWhen the account was made and last synced
Failed sign-in counterRate-limits brute-force attempts, then clears

If you set up a PIN for daily unlock, the PIN-derived key material stays on your device. The PIN is never sent to us.

We do not collect an email address

Cipher has no email field. Signing up asks for a username and password only, and the app never asks for an email address, phone number, or real name at any point. We also do not collect precise location, contacts, photos, browsing history, advertising identifiers, or biometric data.

Subscription information

If you subscribe, Apple or Google processes the payment — that is the only payment path, and we never see your card details, billing address, or store account identity.

We use RevenueCat to manage subscriptions. It receives the purchase identifier, transaction history, and subscription status so we can restore access on every device you sign in from. It identifies you by the same derived account identifier described above — pseudonymous, not anonymous: it is stable and tied to your account, though it does not reveal your username. RevenueCat never receives your encrypted health data, your password, or any tracker entries.

Food search and barcode lookups

Food search and the barcode scanner send your search term or barcode number to our own server, which is signed in as your account and queries FatSecret on your behalf. We route it this way so our nutrition database credentials never ship inside the app.

Android Usage Access

On Android, enabling the Screen Time tracker asks for Usage Access so Cipher can read daily screen-time totals. This is read only when you open that tracker, is encrypted like any other entry, and is never used for advertising or profiling. Revoke it any time in Android Settings → Apps → Special access → Usage access.

Camera

The camera is used only to scan food barcodes. The image is processed on-device to read the barcode and is not saved, uploaded, or shared. No photographs are taken or retained.

Notifications

Reminders are scheduled entirely on your device. Cipher does not use push notifications and never creates or transmits a push token, so we cannot message you and cannot see whether a reminder fired.

Exercise images

Exercise demonstration images load directly from a public GitHub repository (the Free Exercise DB). When one loads, GitHub receives your IP address and which image was requested. We do not control GitHub's logging.

Connection data

We collect the device platform, app version, and subscription status. Separately, when your device syncs, our cloud provider necessarily receives your IP address and a timestamp, as any internet service does. An IP address can indicate approximate region. We do not use it to track you or build profiles, and it is not part of your account record.

This website

The site runs no analytics, no advertising, and no tracking cookies — no Google Analytics, no Meta SDK, nothing equivalent. If you use the contact form, we receive the name, email address, subject, and message you type, purely so we can reply. We hold an email address only when you choose to hand us one. The same goes for surveys: responses are voluntary, reach us as a single email, and are anonymous unless you choose to include a reply address. We keep no database of them — they sit in our inbox like any other correspondence.


Section 2

How your data is stored

Encryption

  • Keys are derived from your password with PBKDF2-HMAC-SHA256 at 200,000 iterations. Entries written by older versions used 50,000 and are upgraded when re-saved.
  • AES-256-CTR, with a random 128-bit salt generated per account
  • A fresh random initialization vector for every encryption operation
  • HMAC-SHA256 integrity verification, so tampering is detectable
  • Your password never leaves your device

Encrypted entries are stored in Google Firebase Firestore. Sign-in uses Firebase Authentication with a custom token our server mints from your account identifier — there is no email-and-password sign-in and no email address involved.

What our cloud provider can see

Firebase can see that encrypted data exists, its size, when it last synced, the salt, and your IP address.

It cannot see what you tracked, when you tracked it, or any pattern in it. Neither can Google, nor we, nor anyone who obtained the database.

On your device

  • Your password, in iOS Keychain / Android Keystore
  • Your PIN-derived key material, in secure storage
  • Cached entries, encrypted with the same scheme
  • App preferences and settings

Section 3

Why we process it, and our legal basis

For users in the European Economic Area and the United Kingdom, the GDPR requires a stated legal basis for each purpose:

What we doLegal basis
Store and sync your encrypted entriesContract — Art. 6(1)(b)
Maintain your account record and verify sign-insContract — Art. 6(1)(b)
Rate-limit failed sign-ins; pin certificatesLegitimate interests — Art. 6(1)(f)
Answer food searches and barcode lookupsContract — Art. 6(1)(b)
Manage subscriptions and entitlementsContract — Art. 6(1)(b)
Receive and reply to contact form messages and survey responsesLegitimate interests — Art. 6(1)(f)
Delete accounts after prolonged inactivityData minimisation — Art. 5(1)(e)

Health data. The tracker categories above are special category data under Article 9. We hold them only in a form we cannot decrypt, so we have no access to their content. To the extent Article 9 applies, we rely on your explicit consent under Art. 9(2)(a), given when you enable a tracker and enter data into it. Withdraw it any time by deleting your data in the app; withdrawal does not affect processing already carried out.


Section 4

Who else is involved

ServiceWhat they receiveWhere
Google Firebase — hosting, sign-in, food proxyEncrypted blobs (unreadable), account identifier, IP address, timestampsUnited States
RevenueCat — subscriptionsPseudonymous account identifier, purchase and subscription status, device metadataUnited States
FatSecret — nutrition databaseSearch terms and barcode numbers, relayed by our serverAustralia / US
Apple / Google — in-app purchasesAll payment data; we receive none of itGlobal
GitHub — public-domain exercise imagesYour IP address and the image requestedUnited States
Proton AG — contact form and survey deliveryThe name, email, subject and message you type into the contact form; survey responses, with a reply email only if you volunteered oneSwitzerland
Vercel — website hostingStandard web server request logsUnited States

We use no advertising SDKs, no analytics, and no data brokers.

International transfers

We are based in the United States and, with one exception, these providers process data there. The exception is Proton AG, which processes mail in Switzerland — a jurisdiction the EU and UK both recognise as adequate, so no further transfer mechanism is needed for it. For the US providers, where personal data leaves the EEA or UK we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. In practice the transferred tracker data is encrypted with a key we do not hold, so it is unintelligible to any recipient — including any authority that compels disclosure.


Section 5

How long we keep it

DataRetention
Encrypted entries and account recordUntil you delete it, or nine months of inactivity
Failed sign-in countersCleared on successful sign-in
Food search queriesNot retained once the lookup is answered
Contact form messages and survey responsesUp to 24 months, then deleted

We keep no backups of deleted data. When it's gone, it's gone.


Section 6

Your rights

Depending on where you live you have some or all of these rights. We honour all of them for everyone, regardless of location.

  • Access — a copy of what we hold about you
  • Rectification — correct anything inaccurate
  • Erasure — have it deleted
  • Restriction — ask us to limit processing
  • Portability — receive it in a machine-readable format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — at any time
  • Complain — to your data protection authority

Export

Deleting your data

Delete everything from Settings inside the app — this erases your encrypted entries and account record from both the device and our servers, permanently. You can also request deletion from the web without reinstalling, at cipher-app.org/delete-account.

No password recovery

There is no recovery mechanism. Your password is the only way to derive your key. If you lose it, nobody — including us — can recover your data. That is intentional.

Making a request

Email app@cipher-app.org. We respond within 30 days, extendable by 60 for complex requests where the law permits, with notice to you. We will never charge you or treat you differently for asking. Since we hold nothing identifying beyond an account identifier, we may ask you to demonstrate control of the account first.


Section 7

California, and other US states

We have never sold or shared personal information, and we do not now — not in the preceding 12 months, and not for anyone under 16.

In CCPA terms we collect: identifiers (account identifier, IP address; name and email only if you use the contact form, or an email address alone if you volunteer one in a survey), commercial information (subscription status), internet activity (food search terms), and sensitive personal information (health data, held only in encrypted form we cannot read). We use sensitive personal information solely to provide the service you asked for, and never for purposes that would trigger the right to limit under Civil Code § 1798.121.

California residents have the right to know, delete, correct, opt out of sale or sharing (not applicable — we do neither), limit use of sensitive personal information, and to non-discrimination. Exercise any of them by emailing app@cipher-app.org, in-app, or at cipher-app.org/delete-account. You may use an authorized agent; we will ask for proof.

Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana grant substantially similar rights, and we use the same process for residents of those states.


Section 8

Washington and Nevada health data

Washington's My Health My Data Act and Nevada's SB 370 set specific rules for consumer health data. Because Cipher is a health tracker, we keep a separate policy covering them: Consumer Health Data Privacy Policy.


Section 9

Cookies, children, and security

Cookies

No analytics cookies, no advertising cookies, no third-party trackers. Anything set is strictly necessary for the site to function, so there is nothing to opt out of and no cookie banner. The app uses no cookies, no advertising identifiers, and no cross-app tracking — which is why it never shows an App Tracking Transparency prompt.

Children

Cipher is for adults, 18 and over. It tracks alcohol, cannabis, and nicotine, and is not designed for minors. We do not knowingly collect data from children; if we learn an under-18 account exists we delete it. Report one to app@cipher-app.org.

Security

  • Certificate pinning on connections to our cloud provider, blocking man-in-the-middle attacks
  • PIN-protected access with rate-limited lockout after repeated failures
  • Hardware-backed credential storage via iOS Keychain and Android Keystore
  • Owner-only server rules — an authenticated account can reach only its own records
  • Redacting logger, so secrets never reach logs

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant authorities as the law requires.


Section 10

Changes, and how to reach us

If this policy changes we update the date at the top. For significant changes we notify you in the app and, where required, ask for your consent before the change takes effect.

You may also complain to your local supervisory authority — in the UK, the Information Commissioner's Office at ico.org.uk.

Cipher Tracker LLC

2936 N Dawson Ave, Chicago, IL 60618, United States

app@cipher-app.org

© 2026 Cipher Tracker