Cifru Privacy Policy

Effective date: September 3, 2026

Cifru is provided by Ionut-Madalin Dumitru. Contact: support@cifru.eu.

Purpose

Cifru is a read-only workspace builder for data sources configured by the user. Cifru does not operate a Cifru-owned backend for customer data, does not sell personal data, and does not track users for advertising in this version.

Local Data

Connection settings, workspace configuration, field mappings, Home buttons, row buttons, widgets, data links, app-mode branding, and cached rows are stored on the user's device. Passwords, API keys, access tokens, and similar secrets are stored using the platform's protected credential storage (Apple Keychain on iOS/iPadOS and Android Keystore-backed encrypted storage on Android). Cached rows may contain business or personal data depending on the sources the user chooses to connect.

Device Authentication

Users can optionally enable device authentication, such as Face ID, Touch ID, Android biometrics, or the device passcode, to unlock the local Cifru workspace. Cifru receives only the operating system's success/failure result and does not receive or store biometric data.

EAN / QR Scanner

Users can optionally open the EAN/QR scanner from a list's Search field. Cifru requests camera access only when that scanner is opened and processes supported barcodes on the device to place the recognized text into Search. The scanner does not save photos or video, does not add camera frames to the workspace or cache, and does not upload camera content to Cifru Community, the developer, or the user's configured data source. The camera session is released when the scanner closes.

External Widgets And Companion Devices

If the user chooses to show dashboard widgets outside the main app, Cifru stores a small local snapshot containing selected widget titles, values, subtitles, and refresh timing. On Apple platforms, a selected snapshot may be transferred to a paired Apple Watch using WatchConnectivity. On Android, selected snapshots may be shown by Android Home Screen widgets and supported Wear OS surfaces. External widgets and companion surfaces do not store source credentials and do not connect directly to configured data sources.

User-Configured Sources

1.1 development only: Google Drive, OneDrive/SharePoint and generic OAuth2 connections keep a separate local account session for each configured source. Access/refresh tokens stay in platform-protected credential storage, not in Community packages or AI requests. Connecting an account authorizes access; it does not upload the workspace to Cifru. File reads go directly to the selected provider. Disconnecting a source removes its local authorization, while separately saved cached data can be cleared in Cache and synchronization. Other source accounts are retained. Local-folder access grants and SMB account secrets are likewise device-local. These notes do not announce availability in the stable 1.0 apps.

When a user configures a database, API, feed, FTP location, ecommerce connector, file, object-storage item, or other source, Cifru sends only the connection request, authentication information, and read-only query/path information needed to retrieve the requested data from that source. Cifru does not send cached rows, exports, imported local files, or locally viewed business data back to configured sources. Those sources are chosen and controlled by the user or their organization, not by Cifru. Their own privacy policies, contracts, access rules, and security practices apply.

Database TLS certificates are validated by default. A user can explicitly enable Trust server certificate for a private server they control; this keeps encryption but relaxes certificate-chain verification and is shown as a security warning. Authenticated HTTP redirects and REST pagination are restricted so credentials are not forwarded to a different scheme, host, or port. Classic FTP is not encrypted and is identified as such in the app.

On Android, when the user opens a configured coordinate as a map, Cifru retrieves the public map style and tiles from OpenFreeMap over HTTPS. Like any web service, that provider may receive ordinary request metadata such as the device IP address and user agent. Cifru does not send source credentials or business rows to the map service and does not request the phone's GPS location; the displayed coordinates come only from the source selected by the user.

Optional AI Configurator

1.1 development only: Consult online manuals starts enabled for new external-provider settings, but no research runs when merely opening a screen. The privacy approval and explicit Send confirmation still apply; users can disable research before sending. The separate Pro option for custom read-only SQL starts disabled. Its optional real-data preview runs locally through the configured source; preview rows are not added to the AI request. Search-result links are distinguished from model-written assumptions and do not prove that a proposed report is correct.

Cifru includes an optional AI Configurator that can help users create dashboard drafts. Initial generation sends safe schema metadata, such as internal source/list IDs, display names, field names, field types, allowed widgets, allowed filters, allowed actions, and user-approved public vendor documentation, public documentation text, public documentation URL, or application/system name for documentation research. It does not send source-row values during initial generation.

The optional Pro custom-query helper follows the same data boundary. With separate approval, an external provider may first search official public manuals and return documentation evidence plus bounded database-object, field, and relation requirements. Cifru then discovers those candidates directly from the selected live connection and sends only the resulting safe schema for a separate declarative SQL draft. Database rows, query results, credentials, connection strings, and private URLs are not sent. Read-only and vendor-neutral structural checks, a bounded local test, at most one repair, and explicit confirmation occur before saving.

If a requested Details relation or cross-source enrichment cannot be verified from schema alone, one automatic repair may use the optional Minimal mapping samples setting. When enabled, Cifru may derive at most one identifier-only sample per relevant object, limited to no more than 12 bounded fields whose roles resemble ID, code, SKU, EAN, or barcode. Cifru locally excludes names, customer/supplier/contact data, addresses, document numbers, credentials, tokens, connection strings, private URLs, descriptions, notes, prices, amounts, totals, stock, quantities, invoice contents, exports, and full database/feed rows. The reduced sample is used only for that repair request and is not copied into generated JSON, warnings, logs, analytics, or saved configuration. The setting can be disabled in AI Configurator settings.

When Apple On-Device AI or a supported Android system-provided model is available, it runs through the operating-system facility and does not require a user API key. Mock / Local Templates do not use an external provider. OpenAI, Claude, and Gemini are optional external providers configured by the user. Their API keys are stored in the platform's protected credential storage and are not logged.

If at least one external provider key is configured, Help can open a separate explanatory external-AI chat. It reuses the same selected provider, model, base URL, and protected credential, but it cannot apply dashboard changes. The bounded conversation transcript is stored in the protected app container and can be deleted with the New conversation action. Before first use, Cifru asks for consent to send recent messages, safe metadata, and relevant excerpts retrieved locally from the complete public Cifru documentation. Common API keys, bearer tokens, password/connection-string fragments, and private/internal URLs are redacted locally before provider transmission. Users should still avoid typing business records or secrets into any external-AI chat.

Web search in this Help chat is disabled by default. If the user explicitly enables it, the confirmation states that the provider may search public manuals. Each request uses a bounded recent-message window and relevance-ranked safe source structures; the UI discloses those bounds.

Before every generation with an external provider, Cifru displays what will be transmitted and requires the user to tap Send. The external payload can contain the user's prompt, the optional application/system name, safe metadata, any public documentation explicitly approved by the user, and, only during a necessary automatic repair while Minimal mapping samples is enabled, the reduced identifier-only sample described above. External AI Documentation Research is optional and requires an additional confirmation that documentation text or URLs are public and approved. It starts disabled in stable 1.0; the separate 1.1 development preference is explained above.

Draft parsing, schema discovery, validation, deterministic completion of requested Details/enrichment structure, removal of unrequested components, and bounded functional tests run locally. Cifru may read a limited row sample to identify actual API/feed keys, XML elements, file headers, spreadsheet columns, and field types, and to determine whether a list, widget, Details relation, or enrichment works. Those preview values and transport-specific source-column mappings remain local except for the optional reduced repair-only identifier sample described above. A complete provider response with wrong or missing mandatory documented topology is rebuilt locally and does not create a second AI request. If a provider response is incomplete or malformed, Cifru may retry once using the original prompt and safe schema metadata; the malformed partial response is not sent back. If a complete draft later needs one functional repair after a real local read-only test, Cifru may send declarative JSON, safe diagnostics such as internal object IDs, stable field names, row counts, match/no-match status and coarse error categories, plus the reduced identifier-only sample when enabled and necessary.

When necessary, Apple On-Device receives a relevance-focused subset of a very large safe schema. Required documented main/detail objects and relationship fields are retained, and local completion and validation still use the complete schema. The Configurator UI shows the full and focused structure/field counts.

External providers process requests under the user's own provider account and published privacy/retention terms. Cifru does not authorize providers to use transmitted information for tracking or advertising. Use an external provider only if its safeguards are appropriate for the information in the prompt and safe metadata. Do not type personal, confidential, credential, or row-level business data into the prompt.

Built-in external provider integrations are intended to be used only where the provider's published terms and security commitments give the limited payload protection equivalent to the protections described in this policy. If a provider cannot provide that protection for the user's context, select Apple On-Device/Mock or disable external AI.

Developer-Operated Services

Cifru does not send workspace data, source credentials, query results, analytics, advertising identifiers, or tracking data to servers controlled by the developer. Optional Cifru Community accounts and content are processed by the Community service only when the user chooses to sign in, publish, review, report, or manage Community content.

When Cifru opens its public Community library from Explore the online library, it may include the app entry point (entry=cifru_app), platform (platform=ios or platform=android), and effective BCP-47 interface language (lang) in the URL to present an appropriate layout and language. Automatic language is resolved to the actual system language and region and is never sent as the literal value automatic; an unavailable language falls back to en. These parameters do not identify the user. They contain no account, email, user or device identifier, subscription or plan, explicit IP value, source configuration, business data, or credential, and are not used for advertising, profiling, fingerprinting, or individual tracking. Ordinary network services may still receive standard connection metadata, such as the requesting IP address, independently of these three app-supplied parameters.

When the user explicitly taps Report AI response or Report this AI draft, Cifru sends the selected visible generated excerpt, the AI flow/provider identifier, and the user's optional report note to the Cifru moderation service. Reports are not sent automatically. They are used only for safety review, abuse prevention, responding to legal obligations, and improving moderation. Reports and moderation decisions may be retained for up to three years where reasonably necessary to handle repeat abuse, disputes, or legal obligations.

When the user chooses OpenAI, Claude, or Gemini and confirms Send, the selected provider receives the limited payload described above directly under the user's provider account. The developer does not receive that provider request through a Cifru-owned AI proxy.

Background Refresh

When automatic cache refresh is enabled, Cifru may contact enabled user-configured sources while the app is active and through operating-system scheduled background work. iOS/iPadOS and Android decide when background execution is granted and do not guarantee exact refresh intervals. External widgets display the latest local snapshot; a platform widget refresh action may request a bounded update but does not expose source credentials.

Exports And Sharing

Users can export filtered/sorted rows in supported spreadsheet or PDF formats through the operating system's share interface. The destination is chosen by the user, such as Mail, Messages, AirDrop, Files, Drive, or another installed app. Cifru does not upload exports to a Cifru backend.

Security

Users should use read-only database accounts, TLS/HTTPS where available, VPN or private network access when appropriate, strong credentials, and source-side permission limits. Cifru cannot control the security of user-provided sources, networks, credentials, or third-party services.

Cifru includes local security checks that warn about configurations such as plain HTTP, FTP, disabled TLS, relaxed certificate validation, missing endpoints, high row limits, or incomplete data links.

Source status is deliberately two-stage. OK means Cifru verified connectivity plus a concrete readable table/schema, endpoint response, sheet, or feed preview. A successful login without readable data is shown only as Connected.

Retention, Consent, And Deleting Data

Local configuration and cached rows remain until the user clears cached rows, resets the local workspace and stored secrets, or deletes the app. Users can stop future external AI processing by canceling the send confirmation, selecting Apple On-Device or Mock, disabling AI Configurator, or clearing the provider key. Data already sent to an external provider is subject to that provider's retention and deletion controls. Server-side source data must be controlled in the user's own systems.

The developer cannot retrieve or remotely delete local workspace data that was never transmitted to a developer-controlled service. Community account deletion can be initiated in the app or from the public account-deletion resource; it removes or withdraws the account-linked content as described by the Community policy, subject to legally required retention. Contact the developer for questions or requests concerning support or safety reports.

Privacy Choices

Cifru does not provide developer-operated analytics, tracking, advertising, workspace account sync, or customer-data cloud storage in this version. Users control which sources they configure, whether external AI is used, whether they submit a safety report, and can clear local cached rows or reset the local workspace from inside the app.

Store Privacy Declarations

This policy is the public privacy URL for Apple App Store and Google Play distribution. Store privacy and Data safety declarations must remain consistent with the released app, its optional Community and AI-reporting actions, and the third-party SDKs present in each platform build.

Contact

For privacy or support questions, email support@cifru.eu.