Cifru Privacy Policy

Effective date: July 13, 2026

Cifru is provided by Dumitru Ionut-Madalin Dumitru. Contact: madalin@madalin.org.

Purpose

Cifru is a read-only workspace builder for data sources configured by the user. Cifru does not operate a Cifru-owned backend for customer data, does not sell personal data, and does not track users for advertising in this version.

Local Data

Connection settings, workspace configuration, field mappings, Home buttons, row buttons, widgets, data links, app-mode branding, and cached rows are stored on the user's device. Passwords, API keys, access tokens, and similar secrets are stored in the iOS Keychain where available. Cached rows may contain business or personal data depending on the sources the user chooses to connect.

Device Authentication

Users can optionally enable device authentication, such as Face ID, Touch ID, or passcode, to unlock the local Cifru workspace. Cifru does not receive or store biometric data.

External Widgets, Apple Watch, And CarPlay Widget Surfaces

If the user chooses to show dashboard widgets outside the main app, Cifru stores a small local snapshot containing selected widget titles, values, subtitles, and refresh timing. Apple Watch support may transfer that selected snapshot from the user's iPhone to the user's paired Apple Watch using Apple's WatchConnectivity framework. Supported CarPlay widget surfaces use WidgetKit small widgets where the operating system supports them. External widgets do not connect directly to configured data sources.

User-Configured Sources

When a user configures a database, API, feed, FTP location, ecommerce connector, file, object-storage item, or other source, Cifru sends only the connection request, authentication information, and read-only query/path information needed to retrieve the requested data from that source. Cifru does not send cached rows, exports, imported local files, or locally viewed business data back to configured sources. Those sources are chosen and controlled by the user or their organization, not by Cifru. Their own privacy policies, contracts, access rules, and security practices apply.

Database TLS certificates are validated by default. A user can explicitly enable Trust server certificate for a private server they control; this keeps encryption but relaxes certificate-chain verification and is shown as a security warning. Authenticated HTTP redirects and REST pagination are restricted so credentials are not forwarded to a different scheme, host, or port. Classic FTP is not encrypted and is identified as such in the app.

Optional AI Configurator

Cifru includes an optional AI Configurator that can help users create dashboard drafts. Initial generation sends safe schema metadata, such as internal source/list IDs, display names, field names, field types, allowed widgets, allowed filters, allowed actions, and user-approved public vendor documentation, public documentation text, public documentation URL, or application/system name for documentation research. It does not send source-row values during initial generation.

The optional Pro custom-query helper follows the same data boundary. With separate approval, an external provider may first search official public manuals and return documentation evidence plus bounded database-object, field, and relation requirements. Cifru then discovers those candidates directly from the selected live connection and sends only the resulting safe schema for a separate declarative SQL draft. Database rows, query results, credentials, connection strings, and private URLs are not sent. Read-only and vendor-neutral structural checks, a bounded local test, at most one repair, and explicit confirmation occur before saving.

If a requested Details relation or cross-source enrichment cannot be verified from schema alone, one automatic repair may use the optional Minimal mapping samples setting. When enabled, Cifru may derive at most one identifier-only sample per relevant object, limited to no more than 12 bounded fields whose roles resemble ID, code, SKU, EAN, or barcode. Cifru locally excludes names, customer/supplier/contact data, addresses, document numbers, credentials, tokens, connection strings, private URLs, descriptions, notes, prices, amounts, totals, stock, quantities, invoice contents, exports, and full database/feed rows. The reduced sample is used only for that repair request and is not copied into generated JSON, warnings, logs, analytics, or saved configuration. The setting can be disabled in AI Configurator settings.

When Apple On-Device AI is available, it runs on device and does not require an API key or web browsing. Mock / Local Templates do not use an external provider. OpenAI, Claude, and Gemini are optional external providers configured by the user. Their API keys are stored in Keychain and are not logged.

If at least one external provider key is configured, Help can open a separate explanatory external-AI chat. It reuses the same selected provider, model, base URL, and Keychain credential, but it cannot apply dashboard changes. The bounded conversation transcript is stored in the app container with iOS complete file protection and can be deleted with the New conversation action. Before first use, Cifru asks for consent to send recent messages, safe metadata, and relevant excerpts retrieved locally from the complete public Cifru documentation. Common API keys, bearer tokens, password/connection-string fragments, and private/internal URLs are redacted locally before provider transmission. Users should still avoid typing business records or secrets into any external-AI chat.

Web search in this Help chat is disabled by default. If the user explicitly enables it, the confirmation states that the provider may search public manuals. Each request uses a bounded recent-message window and relevance-ranked safe source structures; the UI discloses those bounds.

Before every generation with an external provider, Cifru displays what will be transmitted and requires the user to tap Send. The external payload can contain the user's prompt, the optional application/system name, safe metadata, any public documentation explicitly approved by the user, and, only during a necessary automatic repair while Minimal mapping samples is enabled, the reduced identifier-only sample described above. External AI Documentation Research is optional, disabled by default, and requires an additional confirmation that documentation text or URLs are public and approved.

Draft parsing, schema discovery, validation, deterministic completion of requested Details/enrichment structure, removal of unrequested components, and bounded functional tests run locally. Cifru may read a limited row sample to identify actual API/feed keys, XML elements, file headers, spreadsheet columns, and field types, and to determine whether a list, widget, Details relation, or enrichment works. Those preview values and transport-specific source-column mappings remain local except for the optional reduced repair-only identifier sample described above. A complete provider response with wrong or missing mandatory documented topology is rebuilt locally and does not create a second AI request. If a provider response is incomplete or malformed, Cifru may retry once using the original prompt and safe schema metadata; the malformed partial response is not sent back. If a complete draft later needs one functional repair after a real local read-only test, Cifru may send declarative JSON, safe diagnostics such as internal object IDs, stable field names, row counts, match/no-match status and coarse error categories, plus the reduced identifier-only sample when enabled and necessary.

When necessary, Apple On-Device receives a relevance-focused subset of a very large safe schema. Required documented main/detail objects and relationship fields are retained, and local completion and validation still use the complete schema. The Configurator UI shows the full and focused structure/field counts.

External providers process requests under the user's own provider account and published privacy/retention terms. Cifru does not authorize providers to use transmitted information for tracking or advertising. Use an external provider only if its safeguards are appropriate for the information in the prompt and safe metadata. Do not type personal, confidential, credential, or row-level business data into the prompt.

Built-in external provider integrations are intended to be used only where the provider's published terms and security commitments give the limited payload protection equivalent to the protections described in this policy. If a provider cannot provide that protection for the user's context, select Apple On-Device/Mock or disable external AI.

No Developer Collection By Default

In this version, Cifru does not send workspace data, credentials, query results, analytics, crash logs, advertising identifiers, or tracking data to servers controlled by the developer. If this changes in a future version, this policy and the Apple App Store / Google Play declarations must be updated before release.

This does not mean optional external AI makes no network request. When the user chooses OpenAI, Claude, or Gemini and taps Send, the selected provider receives the limited payload described above. Cifru's developer does not receive that payload through a Cifru-owned backend.

Background Refresh

When automatic cache refresh is enabled, Cifru may contact enabled user-configured sources while the app is active and through best-effort iOS Background App Refresh when the operating system grants execution time. iOS does not guarantee exact refresh intervals. External iPhone and Apple Watch widgets display the latest local snapshot and do not expose a manual refresh control or connect directly to customer sources.

Exports And Sharing

Users can export filtered/sorted rows as Excel-compatible XLS or PDF through the iOS share sheet. The destination is chosen by the user, such as Mail, Messages, AirDrop, Files, or another installed app. Cifru does not upload exports to a Cifru backend.

Security

Users should use read-only database accounts, TLS/HTTPS where available, VPN or private network access when appropriate, strong credentials, and source-side permission limits. Cifru cannot control the security of user-provided sources, networks, credentials, or third-party services.

Cifru includes local security checks that warn about configurations such as plain HTTP, FTP, disabled TLS, relaxed certificate validation, missing endpoints, high row limits, or incomplete data links.

Source status is deliberately two-stage. OK means Cifru verified connectivity plus a concrete readable table/schema, endpoint response, sheet, or feed preview. A successful login without readable data is shown only as Connected.

Retention, Consent, And Deleting Data

Local configuration and cached rows remain until the user clears cached rows, resets the local workspace and stored secrets, or deletes the app. Users can stop future external AI processing by canceling the send confirmation, selecting Apple On-Device or Mock, disabling AI Configurator, or clearing the provider key. Data already sent to an external provider is subject to that provider's retention and deletion controls. Server-side source data must be controlled in the user's own systems.

Because Cifru has no developer account/backend in this version, the developer cannot retrieve or remotely delete local workspace data that was never transmitted to a developer-controlled service. Contact the developer for questions or requests concerning information sent directly through support.

Privacy Choices

Cifru does not provide developer-operated analytics, tracking, advertising, account sync, or cloud storage in this version. Users control which sources they configure, whether external AI is used, and can clear local cached rows or reset the local workspace from inside the app.

App Store Privacy Note

This policy is intended to be used as the App Store Connect Privacy Policy URL. If future versions add analytics, crash reporting, sync, accounts, ads, telemetry, or any developer backend, the policy and App Store privacy answers must be updated.

Contact

For privacy or support questions, email madalin@madalin.org.