Privacy Policy
Effective May 15, 2026 · TunariVPN Sp. z o.o.
Cibo (“we,” “us,” or “our”) is operated by TunariVPN Sp. z o.o., a company registered in Republic of Poland (NIP 7011263037, REGON 541903542, KRS 0001176044). This policy explains what data Cibo collects when you use our iPhone application, Apple Watch companion, Android application, and cibo.health website, why we collect it, and the rights you have under the EU General Data Protection Regulation (GDPR).
We've tried to write this in plain English. Where we use a legal term we define it in line.
1. Data controller
The data controller for personal data processed through Cibo is:
TunariVPN Sp. z o.o.
Zabraniecka 8L / 212
03-872 Warsaw, Poland
Email: [email protected]
Registered with the District Court for the capital city of Warsaw, XII Commercial Division.
2. What we collect
To make Cibo work for you, we collect the following:
Account data
- The email address associated with your Sign in with Apple identity (iOS) or Sign in with Google identity (Android). If you opt to share a name during sign-in, we store that too. We never receive your Apple or Google password.
- A randomly generated user identifier we use to attach your meals + profile to your account.
Profile data
- Optional onboarding answers — sex, date of birth, height, weight, activity level, and goal — used to compute your calorie target via the Mifflin-St Jeor equation.
Meal data
- Each meal you log: name, kilocalories, protein/carbs/fat (grams), sodium, sugar, the local time you logged it, and a free-text description if you provided one.
- For meals logged via photo, the resolved nutrition fields above and the photo itself, kept with the meal entry so you can see what you logged. Photos are stored in EU object storage (Cloudflare R2, Germany) and are reachable only through an unguessable URL. A copy is sent to OpenAI for the nutrition read and is deleted by OpenAI within 30 days. We never use your photos to train AI models.
- For meals logged via voice, the transcribed text. We do not retain the audio waveform after transcription.
Payment data
- The Apple In-App Purchase transaction identifier (iOS) or the Google Play purchase token (Android). We do not see your card details — Apple and Google handle the payment in full.
Apple Health data
- When you grant Cibo permission, we read steps, active energy burned, resting energy burned, and body mass directly from Apple Health on your device. This data is rendered in the Cibo UI (your daily ring, weight chart) and does not leave your device — we do not transmit it to our servers.
- When you log a meal, we write the corresponding nutrition fields back to Apple Health (energy consumed, protein, carbs, fat, sodium, sugar) so other apps you trust can see them. Writes happen on-device using Apple's HealthKit API.
Health Connect data (Android)
- On Android, the same integration is offered through Health Connect by Google, and only when you enable it and grant the permissions in Health Connect's own consent screen. Cibo reads steps, active energy burned, total energy burned, and body weight to display them inside the app, and writes the meals and water you log (energy, protein, carbohydrates, fat, hydration volume) so other apps you trust can see them.
- All Health Connect reads and writes happen on your device. Cibo does not transmit Health Connect data to our servers, does not use it for advertising, and does not share it with third parties. You can revoke access at any time in Health Connect settings, and deleting the app data removes Cibo's access entirely.
Diagnostic data
- App version, iOS/Android version, device model, and crash reports. We use this to fix bugs that affect real users — we do not link diagnostics to your meals or profile.
What we don't collect
- We do not sell, rent, or share your data with advertisers.
- We do not collect contacts, photos library access beyond the single image you point at a meal, location, calendar events, or microphone audio outside the active voice-log session.
- We do not retain voice clips: audio is transcribed and discarded, and only the text is stored. We do not use meal photos to train AI models and never share them with advertisers or data brokers.
3. How we use it
We process the data above for the following purposes:
- Service delivery — keeping your meals, profile, and subscription state synchronized across your iPhone, Apple Watch, and (if enabled) Apple Health.
- Nutrition resolution — sending photo crops or voice transcripts to our AI vision and speech-to-text models so they can return calorie + macro estimates.
- Subscription management — verifying your Apple In-App Purchase receipts so we know whether to unlock paid features.
- Service improvement — anonymized, aggregated usage telemetry (which input methods are popular, where errors happen) to make the product better.
- Customer support — when you email us, we use your account email to find your records and reply.
- Legal compliance — keeping the records Polish tax law requires us to keep (typically for five years after a payment).
4. Legal basis (GDPR)
Our lawful bases for processing under Article 6 GDPR are:
- Contract performance (Art. 6(1)(b)) — for everything you need to actually use Cibo: your account, your meals, billing.
- Consent (Art. 6(1)(a)) — for Apple Health integration, analytics opt-in, and any future marketing emails. You can withdraw consent at any time without affecting service-delivery features.
- Legitimate interest (Art. 6(1)(f)) — for fraud prevention, security, and aggregated product analytics. We balance our interests against your rights and you can object.
- Legal obligation (Art. 6(1)(c)) — for tax records and responding to lawful authority requests.
5. Third-party processors
We use the following processors, each bound by a Data Processing Agreement and (where relevant) Standard Contractual Clauses:
- Apple Inc. (USA) — App Store distribution, In-App Purchases, Sign in with Apple, HealthKit. Apple sees your purchase events and your Apple ID; we never see your card details.
- Google LLC (USA) — Google Play distribution, Play Billing subscriptions, Sign in with Google, and Health Connect (on-device only) for the Android app. Google sees your purchase events and your Google account identity; we never see your card details.
- OpenAI, L.L.C. (USA) — vision model for photo nutrition resolution and Whisper for voice transcription. Photo crops and voice clips are sent to OpenAI for inference and processed under OpenAI's enterprise data policy: not used for model training, retained for ≤30 days for abuse monitoring, then deleted.
- Stripe, Inc. (USA) — used only for any future web-based checkout. Currently all v1.0 billing flows through Apple IAP.
- Hetzner Online GmbH (Germany) — hosting our backend servers in Helsinki, Finland (within the EU).
- Cloudflare, Inc. (USA) — DNS resolution and DDoS protection for cibo.health and api.cibo.health.
6. Data retention
- Account + meal data — retained for as long as your account exists. Deleted within 30 days of you requesting account deletion (via Settings → Delete account in the app, or by emailing [email protected]).
- Photo crops + voice clips sent for AI resolution — processed in memory; deleted from our servers immediately after the resolution returns. OpenAI retains them for ≤30 days for abuse monitoring before deletion.
- Payment records — retained for 5 years as required by Polish tax law (Art. 70 of the Polish Tax Ordinance).
- Diagnostic data — retained for 90 days, then aggregated and the original records discarded.
7. Your rights
Under GDPR, you have the following rights:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct anything that's wrong.
- Erasure (“right to be forgotten”) — delete your account and all data tied to it. The Settings → Delete account flow in the app does this in one tap; you can also email us.
- Portability — receive your meal history and profile in a machine-readable JSON export.
- Restriction + objection — limit how we process your data or object to specific processing (e.g. analytics).
- Withdraw consent — for anything you've consented to, at any time, with no penalty to features that don't depend on that consent.
To exercise any of these, email [email protected]. We respond within 30 days as required by Article 12 GDPR.
You also have the right to file a complaint with your supervisory authority. For users in the EU, this is the Polish data protection authority UODO (since we're registered in Poland), but you may also file with the authority in your home country.
8. International transfers
Your data is stored on servers in the European Union (Hetzner Helsinki). When we transfer data to processors in the United States (Apple, OpenAI, Stripe, Cloudflare), the transfer is governed by the EU-US Data Privacy Framework where the processor is certified, or by Standard Contractual Clauses approved by the European Commission.
9. Security
We protect your data in transit and at rest:
- All API calls use TLS 1.3. Apple App Transport Security (ATS) is enforced on the iOS app; certificate pinning is enabled.
- The database is encrypted at rest (AES-256) and access is restricted to a short list of named engineers behind SSH key + 2FA.
- Authentication tokens are stored in the iOS Keychain; we never store plaintext passwords (Sign in with Apple does not provide one to begin with).
- We follow OWASP Top 10 mitigations, run dependency vulnerability scans on every deploy, and rotate secrets quarterly.
No system is invulnerable. If you discover a security issue, please report it to [email protected] with the subject line “Security report” and we will respond within 24 hours.
10. Children
Cibo is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the product evolves. Material changes will be announced via in-app notification + email at least 30 days before they take effect. The effective date at the top of this page reflects the most recent update.
12. Contact
For any privacy question, request, or complaint:
Email: [email protected]
Postal: TunariVPN Sp. z o.o., Zabraniecka 8L / 212, 03-872 Warsaw, Poland
© 2026 TunariVPN Sp. z o.o.. All rights reserved.
