Privacy Policy
Effective: 8 September 2026
Cibori is provided by Francisco Pereira, Portugal ("we", "us"). For privacy questions, contact support@repzai.app.
Data stored on your device
Your meal preferences, plans, fridge inventory, shopping-list progress, saved nutrition history and settings are stored on your device. Meal planning runs on your device. You do not need to register with an email address or password.
Photos and AI scanning
Photo scanning may not be available in every version. Where enabled, it requires premium access and your explicit permission before a selected photo is uploaded. The photo and selected language pass through our Supabase backend to Cloudflare Workers AI to identify food and estimate nutrition. We use a Gemma model hosted by Cloudflare, not the Google Gemini API. Send only food photos, without people or personal information. Estimates can be wrong and are not medical or allergy advice.
Our scan database does not store photos, recognized food or nutrition results. Saved results stay on your device. We do not use photo content for analytics or advertising, and we have not authorized its use for model training. Cloudflare describes its handling of inputs and outputs in its Workers AI data policy. Processing uses third-party infrastructure and is not guaranteed to remain within the EU. Providers may process technical service and security information under their own policies.
Scan identity and security
When an authorized scan needs it, Supabase creates a technical guest identity and stores its authentication record. Access credentials are kept in the device Keychain. We associate this guest ID with RevenueCat to verify your subscription on the server. Our database keeps request identifiers, timestamps, scan type, completion state and usage counters to enforce access and spending limits, not the photo or its results. Request records older than 24 hours are removed when a later scan request runs; this is not a guaranteed deletion exactly 24 hours later. Hosting providers also process technical logs needed to run and secure their services.
Subscriptions
Apple processes payments. RevenueCat processes purchase history and subscription status under an app identifier, which may be associated with the technical scan identity described above, to verify access and restore purchases. We do not receive or store your full payment-card details. Cancelling renewal does not normally end access before the paid period expires. Resetting app data does not cancel an Apple subscription. Apple and RevenueCat may retain transaction records for subscription administration and their applicable retention obligations.
Analytics
Product analytics are off by default. If you enable them in Profile, we send limited app-usage and purchase-funnel events to PostHog in the EU, using a randomly generated app identifier. We do not join this identifier with another app's user identity. We do not send your name, email, meal text, allergy details, photos or sensitive free-text inputs. Analytics are not used for advertising or cross-app tracking. You can turn analytics off in Profile at any time to stop new events.
Your choices
You can decline camera access or AI scanning and use manual planning instead. Before your first AI scan, we ask permission to send the photos you choose or take for scanning to Cloudflare. This choice is saved on the device so you do not need to approve every scan. Withdraw it at any time using AI photo permission in Profile; we will ask again before any later scan. Resetting app data also clears this choice. Choosing a library photo uses Apple's photo picker; it does not grant access to your entire library. Optional planning reminders are scheduled locally on your device and can be disabled in its notification settings.
Use Reset app data in Profile to remove the app's saved settings, plans and history. If a scan guest identity exists, the app first requests its deletion from Supabase and removes the user link from scan-request records, then clears local credentials and app data. An internet connection is required for that server deletion. Transaction records are separate, and this action does not cancel an Apple subscription. Deleting the app alone is not a request to delete its server identity and does not cancel a subscription. Photos in your own library are not deleted by Cibori.
We process data to provide requested features, administer subscriptions and protect the service; optional AI uploads and analytics require your permission. You can withdraw permission for future optional processing. Contact us about access, correction, deletion or other applicable data-protection rights, or to ask about retention and international processing. You can also raise a concern with your local data-protection authority.
Changes
We may update this policy when the app changes. The effective date above will be updated when we do.