PRIVACY
Privacy Policy
Effective date: 12 September 2026. This policy must be updated whenever a provider, feature, purpose, or retention period changes.
1. Who is responsible
The data controller is the Cigara publisher identified in the Legal Notice. Use that page for the controller’s full identity, address, registration details, and contact email. No data protection officer has been appointed.
2. Data we process
Depending on the features you choose, Cigara may process account and profile data; smoking and pacing records, pack information, dates, times, quantities, moods, triggers, reasons, notes, and personal insights; precise location and derived places when enabled; photos, scanner input, voice input, speech transcripts, and Ask Ara messages; community posts, comments, reactions, reports, and media; push-notification tokens and preferences; purchase and entitlement status; device, app, network, log, crash, security, and diagnostic information; and support messages.
Please do not enter medical diagnoses, emergency information, passwords, or unnecessary sensitive information in free-text fields. Smoking and well-being information may be sensitive in context. We do not use it to provide medical care or make medical decisions.
3. Purposes and legal bases
We use data to operate accounts, sync records, and provide requested features on the basis of contract performance; provide optional camera, location, microphone, community, and AI features on the basis of consent for optional access and processing; process Premium access and billing support on the basis of contract performance and legal obligations; send service notifications and requested reports on the basis of contract performance or consent where required; prevent abuse, secure, troubleshoot, and maintain the service on the basis of legitimate interests balanced against your rights; and keep accounting, tax, legal, and dispute records on the basis of legal obligations or legitimate interests.
We do not use your data for targeted advertising and do not sell personal data. Where processing relies on consent, you may withdraw it in the relevant setting or by contacting us.
4. Permissions
Camera, microphone, location, notification, and media permissions are requested only for features that need them. You can refuse or later disable optional permissions; unrelated features should continue to work.
5. Providers and recipients
Depending on the feature, providers may include Supabase; Firebase and Firebase Cloud Messaging; RevenueCat and Apple or Google purchase services; Google Sign-In; Groq or another configured AI provider; Resend or another email provider; Open Food Facts, catalogue, geocoding, and map-tile providers; and Cloudflare or the active web host. The live vendor register, regions, subprocessors, agreements, and safeguards must be verified before launch. We may disclose data when required by law or necessary to protect users or the service.
6. International transfers
Some providers may process data outside the European Economic Area. Where required, we rely on an adequacy decision or another lawful safeguard such as the European Commission's standard contractual clauses. The specific destination and safeguard must be verified in the live vendor register.
7. Retention and deletion
We keep data only as long as needed, then delete or anonymise it unless law requires longer retention. Account records are kept while the account is active and then deleted subject to backup and legal-retention periods. Support and billing records are kept as needed for resolution and legal obligations. Community content is kept until deletion, account deletion, or moderation removal, subject to reports and legal claims. AI history, security logs, and backups follow documented provider schedules. Exact provider periods must be confirmed before launch; data is not kept indefinitely.
8. Your rights
Subject to legal conditions, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time. Delete your account in the app or through the account deletion page. Email requests to support@cigara.app. We may verify your identity and normally respond within one month. You may also complain to the CNIL or another competent supervisory authority.
9. Security and incidents
We use measures appropriate to the risks, including access controls, secure transport, provider security controls, and data minimisation. No internet service can guarantee absolute security. We handle personal-data incidents as required by law and notify affected people when legally required.
10. Children
Cigara is not directed to children. If we learn that we collected a child's data unlawfully, we will take reasonable steps to delete it.
11. Cookies
The website may use strictly necessary technologies for security, preferences, or requested functionality. Non-essential analytics, advertising, or tracking will be used only after consent required by French law, with an equally simple way to refuse or withdraw consent. The deployed site must be checked before claiming it uses no cookies.
12. Changes
We will publish updates with a new effective date and provide additional notice or request consent where required.