Privacy Policy
Effective August 31, 2026 · TunariVPN Sp. z o.o.
Cibo (“we,” “us,” or “our”) is operated by TunariVPN Sp. z o.o., a company registered in Republic of Poland (NIP 7011263037, REGON 541903542, KRS 0001176044). This policy explains what data Cibo collects when you use our iPhone application, Apple Watch companion, Android application, and cibo.health website, why we collect it, and the rights you have under the EU General Data Protection Regulation (GDPR).
We've tried to write this in plain English. Where we use a legal term we define it in line.
1. Data controller
The data controller for personal data processed through Cibo is:
TunariVPN Sp. z o.o.
Zabraniecka 8L / 212
03-872 Warsaw, Poland
Email: [email protected]
Registered with the District Court for the capital city of Warsaw, XII Commercial Division.
2. What we collect
To make Cibo work for you, we collect the following:
Account data
- The email address associated with your Sign in with Apple identity (iOS) or Sign in with Google identity (Android). If you opt to share a name during sign-in, we store that too. We never receive your Apple or Google password.
- A randomly generated user identifier we use to attach your meals + profile to your account.
Profile data
- Optional onboarding answers - sex, date of birth, height, weight, activity level, and goal - used to compute your calorie target via the Mifflin-St Jeor equation.
Meal data
- Each meal you log: name, kilocalories, protein/carbs/fat (grams), sodium, sugar, the local time you logged it, and a free-text description if you provided one.
- For meals logged via photo, the resolved nutrition fields above and the photo itself, kept with the meal entry so you can see what you logged. Photos are stored in EU object storage (Cloudflare R2, Germany) and are reachable only through an unguessable URL. A copy is sent to OpenAI for the nutrition read and is deleted by OpenAI within 30 days. We never use your photos to train AI models.
- For meals logged via voice, the transcribed text. We do not retain the audio waveform after transcription.
Payment data
- The Apple In-App Purchase transaction identifier (iOS) or the Google Play purchase token (Android). We do not see your card details - Apple and Google handle the payment in full.
Apple Health data
- When you grant Cibo permission, we read steps, active energy burned, resting energy burned, and body mass directly from Apple Health on your device. This data is rendered in the Cibo UI (your daily ring, weight chart) and does not leave your device - we do not transmit it to our servers.
- When you log a meal, we write the corresponding nutrition fields back to Apple Health (energy consumed, protein, carbs, fat, sodium, sugar) so other apps you trust can see them. Writes happen on-device using Apple's HealthKit API.
Campaign link measurement (go.cibo.health)
- When you reach Cibo through one of our short campaign links (go.cibo.health), we log a random click identifier, your operating system family, your country (derived by Cloudflare from your connection - we never see or store your IP address), a coarse browser family (e.g. "Instagram in-app"), and any advertising click identifiers already present in the link URL (such as fbclid, gclid or ttclid). This is used solely to measure which campaigns work. No cookies are set, no device storage is accessed, and records are deleted after 180 days.
Health Connect data (Android)
- On Android, the same integration is offered through Health Connect by Google, and only when you enable it and grant the permissions in Health Connect's own consent screen. Cibo reads steps, active energy burned, total energy burned, and body weight to display them inside the app, and writes the meals and water you log (energy, protein, carbohydrates, fat, hydration volume) so other apps you trust can see them.
- All Health Connect reads and writes happen on your device. Cibo does not transmit Health Connect data to our servers, does not use it for advertising, and does not share it with third parties. You can revoke access at any time in Health Connect settings, and deleting the app data removes Cibo's access entirely.
Diagnostic data
- App version, iOS/Android version, device model, and crash reports. We use this to fix bugs that affect real users - we do not link diagnostics to your meals or profile.
Analytics and attribution data
- The Cibo apps include myTracker, an analytics and install-attribution SDK operated by VK (formerly Mail.ru Group). It collects device information (model, operating system version, language, app version), an SDK-generated device identifier, and a small set of in-app product events: sign-in, onboarding completed, a meal logged (the input method only, such as photo or voice, never the contents or the photo of the meal), trial started, purchase, and Together circle activity. These events are linked to your random user identifier so we can see how Cibo is used and which of our campaigns bring users who stay.
- On Android, the app may also access the Google advertising ID (where available on your device) and receives the Google Play install referrer, a string Google Play passes to the app that tells us which ad or link led to the install. We join it to the ad click so we know which campaign the install came from.
- On iOS, when the app was installed after tapping one of our ads on the App Store, we receive an attribution record from Apple's AdServices framework. It contains only anonymised campaign identifiers (campaign, ad group, ad and country) — no device advertising identifier and nothing about you personally — and we link it to your account so we know which of our Apple Search Ads campaigns brought users who stay. Legal basis: our legitimate interest in measuring our own advertising (Art. 6(1)(f) GDPR). We never pass this record to any third party, and it is deleted together with your account.
- To measure advertising, our servers report install and subscription purchase events to the ad platforms we buy ads from (currently the Meta Conversions API). These server-side reports contain technical data (IP address, browser or device user agent, ad click identifiers) and may include your email address in SHA-256 hashed form so the platform can match the event to the ad that led you to Cibo. They never contain your meals, photos, health data, or any nutrition information.
What we don't collect
- We do not sell or rent your personal data. Advertising platforms receive only the campaign measurement events described above, never your meals, photos, health data, or nutrition information.
- We do not collect contacts, photos library access beyond the single image you point at a meal, location, calendar events, or microphone audio outside the active voice-log session.
- We do not retain voice clips: audio is transcribed and discarded, and only the text is stored. We do not use meal photos to train AI models and never share them with advertisers or data brokers.
3. How we use it
We process the data above for the following purposes:
- Service delivery - keeping your meals, profile, and subscription state synchronized across your iPhone, Apple Watch, and (if enabled) Apple Health.
- Nutrition resolution - sending photo crops or voice transcripts to our AI vision and speech-to-text models so they can return calorie + macro estimates.
- Subscription management - verifying your Apple In-App Purchase receipts so we know whether to unlock paid features.
- Service improvement: usage analytics (which input methods are popular, where errors happen, which features get used) to make the product better. These events are linked to your user identifier as described in section 2.
- Advertising measurement: counting the installs and purchases that came from a specific campaign so we know which ads work and stop the ones that do not. This uses the analytics and attribution data described in section 2.
- Customer support - when you email us, we use your account email to find your records and reply.
- Legal compliance - keeping the records Polish tax law requires us to keep (typically for five years after a payment).
4. Legal basis (GDPR)
Our lawful bases for processing under Article 6 GDPR are:
- Contract performance (Art. 6(1)(b)) - for everything you need to actually use Cibo: your account, your meals, billing.
- Consent (Art. 6(1)(a)) - for Apple Health and Health Connect integration and any future marketing emails. You can withdraw consent at any time without affecting service-delivery features.
- Legitimate interest (Art. 6(1)(f)) - for fraud prevention, security, product analytics, and measuring the performance of our advertising campaigns. We balance our interests against your rights and you can object.
- Legal obligation (Art. 6(1)(c)) - for tax records and responding to lawful authority requests.
5. Third-party processors
We use the following processors, each bound by a Data Processing Agreement and (where relevant) Standard Contractual Clauses:
- Apple Inc. (USA) - App Store distribution, In-App Purchases, Sign in with Apple, HealthKit. Apple sees your purchase events and your Apple ID; we never see your card details.
- Google LLC (USA) - Google Play distribution, Play Billing subscriptions, Sign in with Google, and Health Connect (on-device only) for the Android app. Google sees your purchase events and your Google account identity; we never see your card details.
- OpenAI, L.L.C. (USA) - vision model for photo nutrition resolution and Whisper for voice transcription. Photo crops and voice clips are sent to OpenAI for inference and processed under OpenAI's enterprise data policy: not used for model training, retained for ≤30 days for abuse monitoring, then deleted.
- Stripe, Inc. (USA) - used only for any future web-based checkout. Currently all v1.0 billing flows through Apple IAP.
- Hetzner Online GmbH (Germany) - hosting our backend servers in Helsinki, Finland (within the EU).
- Cloudflare, Inc. (USA) - DNS resolution and DDoS protection for cibo.health, api.cibo.health and go.cibo.health; for campaign links Cloudflare also derives the country of a click from the connection (the IP address itself is never stored by us).
- VK / myTracker (myTracker is an analytics service operated by VK, formerly Mail.ru Group): app analytics and install attribution for the iOS and Android apps, as described in section 2. It receives device data and product events on its own infrastructure; it never receives meal contents, photos, health data, or nutrition information.
- Meta Platforms, Inc. (USA): advertising measurement. Receives the server-side install and purchase events described in section 2, including technical data, ad click identifiers, and, where used, your email address in SHA-256 hashed form; it never receives meal contents, photos, health data, or nutrition information.
6. Data retention
- Account + meal data - retained for as long as your account exists. Deleted within 30 days of you requesting account deletion (via Settings → Delete account in the app, or by emailing [email protected]).
- Photo crops + voice clips sent for AI resolution - processed in memory; deleted from our servers immediately after the resolution returns. OpenAI retains them for ≤30 days for abuse monitoring before deletion.
- Payment records - retained for 5 years as required by Polish tax law (Art. 70 of the Polish Tax Ordinance).
- Diagnostic data - retained for 90 days, then aggregated and the original records discarded.
- Analytics and attribution events: held by the analytics and advertising partners listed in section 5 under their own retention schedules. When you delete your account we stop linking new events to your user identifier, and you can ask us to pass a deletion request to those partners by emailing [email protected]. Campaign link click records (go.cibo.health) are deleted after 180 days.
7. Your rights
Under GDPR, you have the following rights:
- Access - get a copy of the personal data we hold about you.
- Rectification - correct anything that's wrong.
- Erasure (“right to be forgotten”) - delete your account and all data tied to it. The Settings → Delete account flow in the app does this in one tap; you can also email us.
- Portability - receive your meal history and profile in a machine-readable JSON export.
- Restriction + objection - limit how we process your data or object to specific processing (e.g. analytics).
- Withdraw consent - for anything you've consented to, at any time, with no penalty to features that don't depend on that consent.
To exercise any of these, email [email protected]. We respond within 30 days as required by Article 12 GDPR.
You also have the right to file a complaint with your supervisory authority. For users in the EU, this is the Polish data protection authority UODO (since we're registered in Poland), but you may also file with the authority in your home country.
8. International transfers
Your data is stored on servers in the European Union (Hetzner Helsinki). When we transfer data to processors in the United States (Apple, Google, OpenAI, Stripe, Cloudflare, Meta), the transfer is governed by the EU-US Data Privacy Framework where the processor is certified, or by Standard Contractual Clauses approved by the European Commission. Analytics and attribution data sent to myTracker is processed on VK's own infrastructure; the scope of that data is limited to what section 2 describes and is covered by myTracker's own privacy documentation.
9. Security
We protect your data in transit and at rest:
- All API calls use TLS 1.3. Apple App Transport Security (ATS) is enforced on the iOS app; certificate pinning is enabled.
- The database is encrypted at rest (AES-256) and access is restricted to a short list of named engineers behind SSH key + 2FA.
- Authentication tokens are stored in the iOS Keychain; we never store plaintext passwords (Sign in with Apple does not provide one to begin with).
- We follow OWASP Top 10 mitigations, run dependency vulnerability scans on every deploy, and rotate secrets quarterly.
No system is invulnerable. If you discover a security issue, please report it to [email protected] with the subject line “Security report” and we will respond within 24 hours.
10. Children
Cibo is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the product evolves. Material changes will be announced via in-app notification + email at least 30 days before they take effect. The effective date at the top of this page reflects the most recent update.
12. Contact
For any privacy question, request, or complaint:
Email: [email protected]
Postal: TunariVPN Sp. z o.o., Zabraniecka 8L / 212, 03-872 Warsaw, Poland
© 2026 TunariVPN Sp. z o.o.. All rights reserved.
