Privacy Policy

Last updated September 27, 2026

Cipher is operated by Cipher Tracker LLC, a limited liability company registered in Illinois. This policy covers the Cipher mobile app and this website.

Questions go to app@cipher-app.org.

Washington and Nevada residents: additional rights apply to your health data. See our separate Consumer Health Data Privacy Policy.

Section 1

What Cipher collects

Data you enter into trackers

Cipher tracks 13 categories: alcohol, caffeine, cannabis, nicotine, screen time, calories/food, sleep, exercise, hydration, medication, menstrual cycle, journal entries, and vitals (readings you choose to log: weight, blood pressure and pulse, resting heart rate, temperature, blood glucose, oxygen saturation, waist, body fat, and energy, pain and headache scores).

All of it is encrypted on your device before being stored or synced. The key is derived from your password, which never leaves your device. We store only the encrypted output, so we have no way to read any of it — including the sensitive parts, like substance use, medication, sexual activity, and cycle records.

Your username and password

When you set up Cipher you choose a username and a password. Neither is stored the way you might expect:

  • Your password never reaches us. It stays in your device's secure storage (iOS Keychain or Android Keystore) and is used only on-device to derive your encryption key.
  • Your username is sent to our server, but only so it can be converted into an account identifier by a one-way hash. We store that derived identifier, never the username itself. Your account is a row of random-looking characters to us. We keep a username in readable form only when you send it to us yourself, for example in an account-deletion request (see This website below).
  • To sign you in, your device derives a separate sign-in proof from your password (PBKDF2, 50,000 rounds, with a salt computed from your username) and sends that instead of the password. We keep only a SHA-256 hash of it, the authentication verifier. It cannot decrypt anything. Like any password hash, it could be used to test password guesses offline, at 50,000 PBKDF2 rounds per guess, by anyone who obtained it, so a long, unique password is what protects you.

The complete account record on our servers is this and nothing else:

FieldWhat it is
Account identifierA hash derived from your username
Authentication verifierA SHA-256 hash of the sign-in proof, used to check sign-ins
Encryption saltA random value used in key derivation — useless on its own
Created / last updatedWhen the account was made and last synced
Failed sign-in counter and lockout timeCounts wrong passwords and, after repeated failures, when a temporary sign-in lockout ends; both clear on a successful sign-in
Verification statusWhether the account has been confirmed as a person's, how (phone, pass or subscription) and when
Phone-number hashThe keyed hash described in the Phone number section below; present only for phone-verified accounts
Purchase claim keyAn identifier of the store transaction that verified the account; present only for purchase-verified accounts
Last seenThe time of the last sign-in, set by our server; used only for the nine-month inactivity rule
Terms version acceptedThe version of the Terms and this policy you accepted, and when
Failed-PIN alertAfter a PIN lockout, the number and times of the wrong PIN entries, so your other devices can warn you; cleared once shown
Storage format versionWhich layout your encrypted entries use
Encrypted recordsYour settings, custom foods, caffeine drinks, medications and exercises, workout templates, personal records, a cached copy of your subscription status and a password check, each encrypted like your entries. The names of these records, and the times they last changed, are not encrypted

While a free sign-up is still unfinished, the record also carries a temporary phone-verification field holding the hash, a timestamp and an attempt counter. It is removed when verification completes, or when the unfinished sign-up is deleted after 24 hours.

Your entries themselves are stored under the account as one encrypted record per calendar month (see section 2).

If you set up a PIN for daily unlock, the PIN-derived key material stays on your device. The PIN is never sent to us.

We do not collect an email address

Cipher has no email field. Signing up asks for a username and password, and, for free accounts only, a phone number used once to confirm you are a person (see the next section). The app never asks for an email address or a real name. We also do not collect precise location, contacts, photos, browsing history, advertising identifiers, or biometric identifiers such as face, fingerprint or voice data.

Phone number (free accounts only)

When you create a free account we ask for a mobile phone number and text you a one-time code. This exists for one reason: to stop scripts from creating accounts in bulk. You can skip it entirely by buying the one-time Verification Pass or starting any Cipher Pro plan; paying users are never asked for a phone number.

Here is exactly what happens to the number:

  • It is sent to Twilio, the company that delivers the text message, so that the code can reach you. Twilio processes it under its own privacy policy and its contract with us.
  • Our servers keep only a keyed hash of the number: the number is combined with a secret key we hold and run through a one-way function. The result lets us tell whether the same number has already verified an account. It is not the number, it cannot be turned back into the number without our key, and we do not use it for anything else. Because we hold the key, this hash is pseudonymous personal data, not anonymous data, and we treat it as such.
  • The number itself is stored only on your device, encrypted like the rest of your data, so the Settings screen can show you which number you used.
  • We never use the number for marketing, we never share it with anyone other than Twilio for delivery, and we never sell it.
  • The hash is deleted when your account is deleted. Unfinished sign-ups are deleted within 24 hours.

Subscription information

If you subscribe, Apple or Google processes the payment — that is the only payment path, and we never see your card details, billing address, or store account identity.

We use RevenueCat to manage subscriptions. It receives the purchase identifier, transaction history, and subscription status so we can restore access on every device you sign in from. It identifies you by the same derived account identifier described above — pseudonymous, not anonymous: it is stable and tied to your account, though it does not reveal your username. RevenueCat never receives your encrypted health data, your password, or any tracker entries.

The one-time Verification Pass is a non-subscription purchase handled the same way; RevenueCat records that the purchase exists so it can verify exactly one account.

Food search and barcode lookups

Food search and the barcode scanner send your search term or barcode number to our own server, which is signed in as your account and queries FatSecret on your behalf. We route it this way so our nutrition database credentials never ship inside the app.

Android Usage Access

On Android, enabling the Screen Time tracker asks for Usage Access so Cipher can read daily screen-time totals. This is read only when you open that tracker, is encrypted like any other entry, and is never used for advertising or profiling. Revoke it any time in Android Settings → Apps → Special access → Usage access.

Camera

The camera is used only to scan food barcodes. The image is processed on-device to read the barcode and is not saved, uploaded, or shared. No photographs are taken or retained.

Notifications

Reminders are scheduled entirely on your device. Cipher does not use push notifications and never creates or transmits a push token, so we cannot message you and cannot see whether a reminder fired.

Exercise images

Exercise demonstration images load directly from a public GitHub repository (the Free Exercise DB). When one loads, GitHub receives your IP address and which image was requested. We do not control GitHub's logging.

Connection data

We collect the device platform, app version, and subscription status. Separately, when your device syncs, our cloud provider necessarily receives your IP address and a timestamp, as any internet service does. An IP address can indicate approximate region. We do not use it to track you or build profiles, and it is not part of your account record.

This website

The site runs no analytics, no advertising, and no tracking cookies — no Google Analytics, no Meta SDK, nothing equivalent. If you use the contact form, we receive the name, email address, subject, and message you type, purely so we can reply. We hold an email address only when you choose to hand us one. The same goes for surveys: responses are voluntary, reach us as a single email, and are anonymous unless you choose to include a reply address. We keep no database of them — they sit in our inbox like any other correspondence.

If you use the account-deletion form, we receive the Cipher username you give, a reply email address, the request type and any notes, and we send an acknowledgement to that address. It is the one place we ask for a username alongside an email address. It reaches us as an email and is kept like other correspondence (see section 5).


Section 2

How your data is stored

Encryption

  • Keys are derived from your password with PBKDF2-HMAC-SHA256 at 200,000 iterations. Entries written by older versions used 50,000 and are upgraded when re-saved.
  • AES-256-CTR, with a random 128-bit salt generated per account
  • A fresh random initialization vector for every encryption operation
  • HMAC-SHA256 integrity verification, so tampering is detectable
  • Your password never leaves your device

Encrypted entries are stored in Google Firebase Firestore. Sign-in uses Firebase Authentication with a custom token our server mints from your account identifier — there is no email-and-password sign-in and no email address involved.

What our cloud provider can see

Firebase can see that encrypted data exists and how large it is; that your entries are stored as one record per calendar month, labelled with the year and month, and how large each month's record is; the names of the encrypted settings records your account has (such as custom medications, custom foods or workout templates) and when each last changed; the plaintext account fields listed in section 1, including the salt; when you last synced; and your IP address.

It cannot read any encrypted record: not what you logged, on which days, or any value. Neither can Google, nor we, nor anyone who obtained the database.

On your device

  • Your password, in iOS Keychain / Android Keystore
  • Your PIN-derived key material, in secure storage
  • Cached entries, encrypted with the same scheme
  • App preferences and settings

Section 3

Why we process it, and our legal basis

For users in the European Economic Area and the United Kingdom, the GDPR requires a stated legal basis for each purpose:

What we doLegal basis
Store and sync your encrypted entriesContract — Art. 6(1)(b)
Maintain your account record and verify sign-insContract — Art. 6(1)(b)
Rate-limit sign-ins, sign-ups, verification codes and purchase checks; pin certificates on AndroidLegitimate interests — Art. 6(1)(f)
Confirm a free sign-up comes from a person (phone code, or a store purchase)Legitimate interest in preventing automated abuse (Art. 6(1)(f))
Answer food searches and barcode lookupsContract — Art. 6(1)(b)
Manage subscriptions and entitlementsContract — Art. 6(1)(b)
Receive and reply to contact form messages and survey responsesLegitimate interests — Art. 6(1)(f)
Delete accounts after prolonged inactivityData minimisation — Art. 5(1)(e)

Health data. The tracker categories above are special category data under Article 9. We hold them only in a form we cannot decrypt, so we have no access to their content. To the extent Article 9 applies, we rely on your explicit consent under Art. 9(2)(a), given when you enable a tracker and enter data into it. Withdraw it any time by deleting your data in the app; withdrawal does not affect processing already carried out.


Section 4

Who else is involved

ServiceWhat they receiveWhere
Google Firebase — hosting, sign-in, food proxyEncrypted blobs (unreadable), account identifier, IP address, timestampsUnited States
RevenueCat — subscriptionsPseudonymous account identifier, purchase and subscription status, device metadataUnited States
Twilio — one-time verification texts (free accounts)Phone number, delivery statusUnited States
FatSecret — nutrition databaseSearch terms and barcode numbers, relayed by our serverAustralia / US
Apple / Google — in-app purchasesAll payment data. We receive none of it, only a reference to the store transaction when a purchase verifies an accountGlobal
GitHub — public-domain exercise imagesYour IP address and the image requestedUnited States
Proton AG — contact form, deletion request and survey deliveryThe name, email, subject and message you type into the contact form; deletion requests (username, reply email, request type and notes); survey responses, with a reply email only if you volunteered oneSwitzerland
Vercel — website hostingStandard web server request logsUnited States

We use no advertising SDKs, no analytics, and no data brokers.

International transfers

We are based in the United States and, with one exception, these providers process data there. The exception is Proton AG, which processes mail in Switzerland — a jurisdiction the EU and UK both recognise as adequate, so no further transfer mechanism is needed for it. For the US providers, where personal data leaves the EEA or UK we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. In practice the transferred tracker data is encrypted with a key we do not hold, so it is unintelligible to any recipient — including any authority that compels disclosure.


Section 5

How long we keep it

DataRetention
Encrypted entries and account recordUntil you delete it, or nine months of inactivity
Phone-number hash and purchase claimUntil you delete your account
Unfinished sign-ups24 hours
Failed sign-in countersCleared on successful sign-in
Food search queriesNot retained once the lookup is answered
Contact form messages, survey responses and deletion requestsUp to 24 months, then deleted. A minimal record that a deletion happened may be kept where the law requires it

We keep no backups of deleted data. When it's gone, it's gone.


Section 6

Your rights

Depending on where you live you have some or all of these rights. We honour all of them for everyone, regardless of location.

  • Access — a copy of what we hold about you
  • Rectification — correct anything inaccurate
  • Erasure — have it deleted
  • Restriction — ask us to limit processing
  • Portability — receive it in a machine-readable format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — at any time
  • Complain — to your data protection authority

Export

Deleting your data

Delete everything inside the app from Settings → Security & Account → Delete All Data. This erases your encrypted entries and account record from both the device and our servers, permanently. You can also request deletion from the web without reinstalling, at cipher-app.org/delete-account.

No password recovery

There is no recovery mechanism, and that is intentional. On a new device, or once you are signed out, your password is the only way to derive your key, so if you lose it we cannot recover your data for you. A device you are still signed in to keeps working with your PIN until you sign out or are locked out.

Making a request

Email app@cipher-app.org. We respond within 30 days, extendable by 60 for complex requests where the law permits, with notice to you. We will never charge you or treat you differently for asking. Since we hold nothing identifying beyond an account identifier (and, for text-verified accounts, a keyed hash of the phone number), we may ask you to demonstrate control of the account first.


Section 7

California, and other US states

We have never sold or shared personal information, and we do not now — not in the preceding 12 months, and not for anyone under 16.

In CCPA terms we collect: identifiers (account identifier, IP address; for free accounts, a hashed phone number or a purchase claim; name and email only if you use the contact form, a username and email if you use the account-deletion form, or an email address alone if you volunteer one in a survey), commercial information (subscription status), internet activity (food search terms), and sensitive personal information (health data, held only in encrypted form we cannot read). We use sensitive personal information solely to provide the service you asked for, and never for purposes that would trigger the right to limit under Civil Code § 1798.121. The hashed phone number and purchase claim are used only to confirm that a free sign-up comes from a person; they are not sold, and not shared for cross-context behavioral advertising.

California residents have the right to know, delete, correct, opt out of sale or sharing (not applicable — we do neither), limit use of sensitive personal information, and to non-discrimination. Exercise any of them by emailing app@cipher-app.org, in-app, or at cipher-app.org/delete-account. You may use an authorized agent; we will ask for proof.

Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana grant substantially similar rights, and we use the same process for residents of those states.


Section 8

Washington and Nevada health data

Washington's My Health My Data Act and Nevada's SB 370 set specific rules for consumer health data. Because Cipher is a health tracker, we keep a separate policy covering them: Consumer Health Data Privacy Policy.


Section 9

Cookies, children, and security

Cookies

No analytics cookies, no advertising cookies, no third-party trackers. Anything set is strictly necessary for the site to function, so there is nothing to opt out of and no cookie banner. The app uses no cookies, no advertising identifiers, and no cross-app tracking — which is why it never shows an App Tracking Transparency prompt.

Children

Cipher is for adults, 18 and over. It tracks alcohol, cannabis, and nicotine, and is not designed for minors. We do not knowingly collect data from children; if we learn an under-18 account exists we delete it. Report one to app@cipher-app.org.

Security

  • Certificate pinning on Android, for connections to our database and to Firebase's sign-in service. Other connections, including calls to our server functions and every connection from iOS, use standard TLS encryption without pinning
  • PIN-protected access with rate-limited lockout after repeated failures
  • Hardware-backed credential storage via iOS Keychain and Android Keystore
  • Owner-only server rules — an authenticated account can reach only its own records
  • Redacting logger, so secrets never reach logs

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant authorities as the law requires.


Section 10

Changes, and how to reach us

If this policy changes we update the date at the top. For significant changes we notify you in the app and, where required, ask for your consent before the change takes effect.

You may also complain to your local supervisory authority — in the UK, the Information Commissioner's Office at ico.org.uk.

Cipher Tracker LLC

2936 N Dawson Ave, Chicago, IL 60618, United States

app@cipher-app.org

© 2026 Cipher Tracker LLC. All rights reserved.