Consumer Health Data
Last updated July 29, 2026
This policy is provided by Cipher Tracker LLC under Washington's My Health My Data Act (RCW 19.373) and Nevada SB 370 (NRS 603A.400 et seq.).
It covers consumer health data collected through the Cipher app, and stands separate from — and in addition to — our Privacy Policy.
What health data we collect
All of it is entered by you, and all of it is encrypted on your device before we receive it:
| Category | What you might log |
|---|---|
| Substance use | Alcohol, cannabis, nicotine, caffeine and quantities |
| Medication | Medications and doses taken |
| Reproductive and sexual health | Cycle dates, flow, symptoms, predictions |
| Sleep | Sleep and nap duration and timing |
| Exercise and fitness | Workouts, sets, weights, climbing, cardio, personal records |
| Nutrition and bodily functions | Calories, macronutrients, sugar, hydration |
| Mental and emotional wellbeing | Diary entries, mood and emotion tags |
| Digital wellbeing | Screen time totals |
| Health-related inferences | Streaks, trends, averages, cycle phase predictions |
We also process food search terms and scanned barcodes in readable form at the moment you search, to return nutrition results. See section 3.
Where it comes from
- Directly from you — everything you type, select or log.
- From your device, with permission — screen time totals read from Android's usage statistics, where you granted access.
- Derived on your device — averages, streaks, trends and cycle phase predictions, all computed locally.
We obtain no health data from data brokers, advertising networks, health care providers, insurers, or any other outside source.
Why we collect it
For one purpose: to provide the tracking service you asked for — storing your entries, syncing them across your devices, and showing them back to you in the Calendar, History and Stats screens.
Because it is encrypted before it reaches us, we cannot and do not use it for analytics, research, product development, profiling, advertising, model training, or any secondary purpose.
Who receives it
We do not sell consumer health data. We never have and will not. Selling it would require a signed, specific authorization from you under the My Health My Data Act; we do not seek one, because we do not sell.
We do not share it for advertising, marketing, or any third party's own purposes.
| Third party | What they receive | Readable? |
|---|---|---|
| Google LLC — Firebase, our hosting processor | Encrypted blobs; your account identifier; IP address and sync timestamps | No. Encrypted with a key Google does not have. |
| FatSecret — nutrition database | Food search terms and barcode numbers only, relayed by our server. No tracker data, no account identifier. | Yes, as to the search term itself. |
Two more receive no consumer health data at all, listed for completeness: RevenueCat (subscription status and a pseudonymous account identifier) and GitHub, Inc. (your IP address when an exercise image loads).
We have no affiliates. If that changes, this policy is updated before any sharing occurs.
Your rights
Washington residents have these rights under RCW 19.373.030, and Nevada residents substantially similar ones under NRS 603A. We extend all of them to every Cipher user, wherever you live.
Confirm and access
You may confirm whether we collect, share or sell your health data, and access it. In practice we can give you confirmation that an account exists, the account record described in our Privacy Policy, and the raw encrypted blob — but we cannot provide your health data in readable form, because we cannot decrypt it. The readable version is always in the app, where your device decrypts it.
A list of third parties
You may request the full list of third parties and affiliates we have shared your health data with, and their contact information. It is section 4 above, and it is complete.
Withdraw consent
Withdraw consent to collection and sharing at any time, by deleting your data in the app or emailing us. Withdrawal stops future collection; it does not undo processing already done.
Delete
You may delete your health data from our records. We remove it from active systems, archived records and backups. We keep no separate long-term backups of user data, so deletion is effectively immediate and complete. We notify any processor holding it, and we finish within 30 days as the Act requires.
No discrimination
We will not deny you the app, charge you differently, or degrade your service because you exercised any of these rights.
How to exercise them
- In the app, fastest — Settings, then delete your data. This erases your encrypted entries and account record from your device and our servers.
- On the web, no install needed — cipher-app.org/delete-account
- By email — app@cipher-app.org, with “Consumer Health Data Request” in the subject and which right you are exercising.
We respond within 30 days. Where the law allows we may extend by 45 days for complex requests, and will tell you why within the original 30.
Verification. We hold almost nothing identifying about you, so we normally verify by asking you to demonstrate control of the account — usually by signing in. We will not ask for extra personal information solely to verify a request. You may use an authorized agent with written proof.
If we say no
Appeal by replying to our decision, or emailing app@cipher-app.org with “Appeal” in the subject. We respond within 45 days with a written explanation. If the appeal is denied you may contact the Washington State Attorney General or the Nevada Attorney General.
Geofencing
We do not use geofencing. Cipher never requests or collects precise location, and we establish no virtual boundary around health care facilities or anywhere else. Washington's Act prohibits geofencing around in-person health services to identify or track consumers or send them health-related messages; we do not do this in any form.
Retention, and who can reach it
We keep your encrypted health data until the earlier of:
- you delete it in the app or by request; or
- nine consecutive months without your account syncing, at which point the account and all encrypted entries are automatically and permanently deleted from our servers.
Automatic deletion is irreversible. Data held on your own device is unaffected by it.
Access to the systems holding this data is limited to those who need it to run the service, under confidentiality obligations. Because it is encrypted with a key we do not possess, no employee, contractor or processor can read its contents, whatever their access level.
Changes
We will not collect, use or share consumer health data in a way materially different from what this policy disclosed at the time of collection without first obtaining your affirmative consent.
For material changes we update the date above, notify you in the app, and obtain consent where the law requires it.
Cipher Tracker LLC
2936 N Dawson Ave, Chicago, IL 60618, United States
© 2026 Cipher Tracker