Consumer Health Data

Last updated September 27, 2026

This policy is provided by Cipher Tracker LLC under Washington's My Health My Data Act (RCW 19.373) and Nevada SB 370 (NRS 603A.400 et seq.).

It covers consumer health data collected through the Cipher app, and stands separate from — and in addition to — our Privacy Policy.

If you are a resident of Washington or Nevada, or your consumer health data is collected while you are in Washington or Nevada, this policy describes your rights.

Section 1

What health data we collect

All of it is entered by you, and all of it is encrypted on your device before we receive it:

CategoryWhat you might log
Substance useAlcohol, cannabis, nicotine, caffeine and quantities
MedicationMedications and doses taken
Reproductive and sexual healthCycle dates, flow, symptoms, sexual activity and sex drive, predictions
SleepSleep and nap duration and timing
Exercise and fitnessWorkouts, sets, weights, climbing, cardio, personal records
Vital signs and body measurementsWeight, blood pressure and pulse, resting heart rate, temperature, blood glucose, oxygen saturation, waist, body fat
SymptomsSelf-rated energy, pain and headache scores
Nutrition and bodily functionsCalories, macronutrients, sugar, hydration, bowel movements
Mental and emotional wellbeingDiary entries, mood and emotion tags
Digital wellbeingScreen time totals
Health-related inferencesStreaks, trends and averages; cycle phase, ovulation and fertile-window estimates; blood-pressure categories; caffeine-in-system and sleep-impact estimates; sleep debt; and nicotine recovery milestones, all calculated on your device

We also process food search terms and scanned barcodes in readable form at the moment you search, to return nutrition results. See section 3.


Section 2

Where it comes from

  • Directly from you — everything you type, select or log.
  • From your device, with permission — screen time totals read from Android's usage statistics, where you granted access.
  • Derived on your device — averages, streaks, trends, cycle phase, ovulation and fertile-window estimates, blood-pressure categories and the other estimates listed in section 1, all computed locally.

We obtain no health data from data brokers, advertising networks, health care providers, insurers, or any other outside source.


Section 3

Why we collect it

For one purpose: to provide the tracking service you asked for — storing your entries, syncing them across your devices, and showing them back to you in the Calendar, History and Stats screens.

Because it is encrypted before it reaches us, we cannot and do not use it for analytics, research, product development, profiling, advertising, model training, or any secondary purpose.


Section 4

Who receives it

We do not sell consumer health data. We never have and will not. Selling it would require a signed, specific authorization from you under the My Health My Data Act; we do not seek one.

We do not share it for advertising, marketing, or any third party's own purposes.

Third partyWhat they receiveReadable?
Google LLC — Firebase, our hosting processorEncrypted blobs, with their month labels and sizes; the names of your encrypted settings records (such as custom medications) and when each last changed; your account identifier; IP address and sync timestampsNo. Encrypted with a key Google does not have.
FatSecret (Secret Foods Pty Ltd) — nutrition databaseFood search terms and barcode numbers only, relayed by our server. No tracker data, no account identifier.Yes, as to the search term itself.

Three more receive no consumer health data at all, listed for completeness: RevenueCat (subscription status and a pseudonymous account identifier), Twilio Inc. (the phone number of a free account being verified by text) and GitHub, Inc. (your IP address when an exercise image loads).

We have no affiliates. If that changes, this policy is updated before any sharing occurs.


Section 5

Your rights

Washington residents have these rights under RCW 19.373.030, and Nevada residents substantially similar ones under NRS 603A. We extend all of them to every Cipher user, wherever you live.

Confirm and access

You may confirm whether we collect, share or sell your health data, and access it. In practice we can give you confirmation that an account exists, the account record described in our Privacy Policy, and the raw encrypted blob — but we cannot provide your health data in readable form, because we cannot decrypt it. The readable version is always in the app, where your device decrypts it.

A list of third parties

You may request the full list of third parties and affiliates we have shared your health data with, and their contact information. It is section 4 above, and it is complete.

Withdraw consent

Withdraw consent to collection and sharing at any time, by deleting your data in the app or emailing us. Withdrawal stops future collection; it does not undo processing already done.

Delete

You may delete your health data from our records. We remove it from active systems, archived records and backups. We keep no separate long-term backups of user data, so deletion is effectively immediate and complete. We notify any processor holding it, and we finish within 30 days as the Act requires.

No discrimination

We will not deny you the app, charge you differently, or degrade your service because you exercised any of these rights.


Section 6

How to exercise them

  • In the app, fastest — Settings → Security & Account → Delete All Data. This erases your encrypted entries and account record from your device and our servers.
  • On the web, no install needed — cipher-app.org/delete-account
  • By email — app@cipher-app.org, with “Consumer Health Data Request” in the subject and which right you are exercising.

We respond within 30 days. Where the law allows we may extend by 45 days for complex requests, and will tell you why within the original 30.

Verification. We hold almost nothing identifying about you, so we normally verify by asking you to demonstrate control of the account — usually by signing in. We will not ask for extra personal information solely to verify a request. You may use an authorized agent with written proof.

If we say no

Appeal by replying to our decision, or emailing app@cipher-app.org with “Appeal” in the subject. We respond within 45 days with a written explanation. If the appeal is denied you may contact the Washington State Attorney General or the Nevada Attorney General.


Section 7

Geofencing

We do not use geofencing. Cipher never requests or collects precise location, and we establish no virtual boundary around health care facilities or anywhere else. Washington's Act prohibits geofencing around in-person health services to identify or track consumers or send them health-related messages; we do not do this in any form.


Section 8

Retention, and who can reach it

We keep your encrypted health data until the earlier of:

  • you delete it in the app or by request; or
  • nine consecutive months without your account being used (none of your devices opens the app while online, syncs or signs in), at which point the account and all encrypted entries are automatically and permanently deleted from our servers.

Automatic deletion is irreversible. After it, once the app reaches our servers and finds the account gone, it signs you out and clears the data stored on that device too.

Access to the systems holding this data is limited to those who need it to run the service, under confidentiality obligations. Because it is encrypted with a key we do not possess, no employee, contractor or processor can read its contents, whatever their access level.


Section 9

Changes

We will not collect, use or share consumer health data in a way materially different from what this policy disclosed at the time of collection without first obtaining your affirmative consent.

For material changes we update the date above, notify you in the app, and obtain consent where the law requires it.

Cipher Tracker LLC

2936 N Dawson Ave, Chicago, IL 60618, United States

app@cipher-app.org

© 2026 Cipher Tracker LLC. All rights reserved.