CiCi · Privacy

Privacy

Using a gluten app says something about your health. That is why this page is written the way it is: everything below describes what the code does, and most of it can be checked from the outside.

The short version

A barcode is decoded on your phone and never leaves it as an image. A photographed label is read once and thrown away. No scan and no verdict ever enters an analytics event, and nothing here is sold or shared.

What we never do

What we hold, and why

WhatWhyWhereHow long
Your email addressSign-in. You can use a password or have CiCi email you a link. CiCi never sees or stores the password itself — it goes to the managed authentication service, which stores it hashed. It is never written to our database and never logged.Neon Auth (managed Better Auth), hosted in the USUntil you delete your account
Barcode lookupsThe barcode is decoded on your device and never leaves it as an image. The number is sent to look the product up.The lookup carries no user id at all, signed in or not. It answers questions about barcodes and never learns who asked.Not retained
Your scan historyIf you are signed in, CiCi keeps a list of what you scanned so you do not have to type it into your log later, and so it is there to look back on. Scanning signed out records nothing at all. A scan is never counted as something you ate unless you say so.Your row in our database, written by a separate endpoint from the lookupUntil you delete the entry or close your account
Your glutening logWhat you have told CiCi you ate and when you were ill, so the log can show you what those days had in common. It counts overlaps and never names a cause. This is the most sensitive thing on the site and the whole signed-in area is excluded from measurement.Your row in our database. Never in an analytics event, never sold, never used to infer anything about you.Until you delete the entry or close your account
Photographs of ingredient panelsRead once by Google Gemini to transcribe the text, then discarded. The text goes into the rules engine; the image goes nowhere.Held in memory for one request. Never written to disk or database.Not retained
Which pages get readTo know which of the thousand-odd reference pages to improve next. Page path only: never a scan, a verdict, a barcode, a ratio, or anything you typed into a search or lookup box.Google Analytics. Ad personalisation and Google Signals are off, and your signed-in account area is excluded from measurement entirely.14 months, then deleted by Google automatically
Saved products and listsSo your regular shop is one tap.Your row in our database, protected by row-level securityUntil you delete them or close your account
Community posts, reviews and restaurant reportsThey are the product. Other people rely on them.Public, under the display name you chooseUntil you delete them
Subscription and payment recordsBilling, refunds, tax. We never see or store your card.Stripe. We keep only a customer reference and the plan state.As long as tax law requires

Photographs of labels

When you photograph an ingredient panel, the image goes to Google's Gemini API, which transcribes the printed text and sends it back. The text is then assessed by the same rules engine a barcode scan uses. The image itself is held for the length of that one request and is never written to disk, never written to our database, and never attached to your account.

We use the paidtier of that API. Google's terms say that for unpaid use, submitted content is used to improve their products and human reviewers may read it. Their own documentation tells you not to send sensitive information through it. On the paid tier, prompts are not used to improve their products and are logged only to detect abuse. Paying for that is not optional here.

Your rights

Wherever you are, you can have everything CiCi holds about you sent to you, and you can have your account and its contents deleted. Write to privacy@askcici.com and we answer within two business days. Anything you have saved, scanned or logged can also be deleted by you, one entry at a time, from the page it appears on. Deletion removes the data rather than hiding it.

If you are in the EU or the UK, GDPR gives you rights of access, correction, erasure, restriction, portability and objection, and a right to complain to your supervisory authority. If you are in California, the CCPA and CPRA give you rights of access, deletion and correction, and a right to limit the use of sensitive personal information. We do not use it for anything beyond running the product, so there is nothing to limit. To exercise any of these, write to privacy@askcici.com and we will respond within two business days.

Children

Coeliac disease is frequently diagnosed in childhood, so children plainly use tools like this. CiCi accounts are for people aged 13 and over; a younger child should use a parent's account rather than their own. We do not knowingly collect data from a child under 13, and if we learn we have, we delete it.

Where our data comes from

CiCi is built on open data, and several of these licences require us to say so. All of it is about food and places rather than about people.

SourceLicenceWhat it is
USDA FoodData CentralCC0 / public domainBranded food label data. No attribution required; given anyway.
Open Food FactsOpen Database License (ODbL) 1.0Product data, and the only source anywhere with cross-contact "may contain" information. ODbL is a share-alike licence, so records derived from it stay identifiable in our database and separable from the rest.
OpenStreetMap contributorsOpen Database License (ODbL) 1.0Every restaurant, bakery and cafe on the map, via the diet:gluten_free tag. Contributor-recorded and not verified by CiCi, which every venue page states.
OpenFreeMap / OpenMapTilesODbL data, open-source tilesThe basemap itself.

Security

Everything is served over HTTPS. Sign-in is by magic link, so there is no password to steal from us. Your saved data is protected by row-level security in the database, and access to it is enforced in the server actions that read it rather than trusted to the client. If you find a vulnerability, write to security@askcici.com. We will not threaten you.

Changes

If we change something material we will say so here and email anyone with an account. We will not quietly widen what we collect.

Last updated 2026-07-28.