Privacy Policy

Celia — Gluten-Free, Food & Reaction Journal App

Last updated: 22 August 2026

Celia is designed so that we know as little about you as possible. This policy explains what data the Celia app and the trycelia.com website handle, why it is handled, where it is processed, and what rights you have.

1. Who we are

The data controller is looplib AB, a company based in Sweden.

Contact: hello@trycelia.com

2. Summary

  • Celia does not require your name, email address, phone number, or a traditional user account. The app creates a random, pseudonymous app identifier.
  • Your food and symptom journal stays on your device. This includes meals, meal photos, gluten status, FODMAP tags, symptoms, symptom intensity, stress and sleep ratings, daily notes, and observations generated from your journal.
  • Celia does not automatically send your journal to us or to an AI service.
  • Photos or text are sent to Google Gemini only when you actively use an AI feature. If you choose to include health-related information in an AI request, that information is included in the request.
  • Label text recognition and the basic gluten check happen on your device. Barcode lookups query Open Food Facts directly.
  • Celia has no advertising, advertising identifiers, or third-party advertising trackers, and we do not sell your data.
  • You can delete your local journal and pseudonymous server account from within the app.

3. Pseudonymous app identifier

When you first open Celia, the app creates a pseudonymous account with a randomly generated identifier. We do not ask for direct identifiers such as your name, email address, phone number, or date of birth.

The identifier allows the app to use protected server features without requiring registration. Pseudonymous data is still personal data under the GDPR, even though it does not directly identify you by name.

The data stored on our servers under this identifier is limited to:

  • usage counters, such as the number of AI requests and map searches, used to enforce free, subscription, fair-use, and security limits;
  • subscription status and related product information needed to provide Celia Pro; and
  • limited technical metadata needed to operate, secure, and troubleshoot the service, such as the feature requested, request time, response status, and security events.

Our AI proxy is not designed to store the content of your photos or messages.

4. Data that stays on your device

The following information is stored locally on your device and is not automatically uploaded to our servers:

  • food journal entries, including meal names, ingredients, portions, nutrition estimates, photos or thumbnails, gluten status, meal type, and FODMAP group tags;
  • whether gluten status or FODMAP groups were reviewed;
  • symptom entries, symptom intensity, and symptom notes;
  • daily stress and sleep ratings;
  • daily journal notes;
  • locally calculated food-and-symptom timing observations and journal-completeness information;
  • scan history, favorite meals, saved recipes, and app preferences; and
  • reminder settings.

We do not have access to this local journal. If you delete the app or use the in-app deletion function, the local data is removed. Local data may also be included in a device backup that you control, such as an iCloud or computer backup, subject to Apple's terms and settings.

You may create a PDF copy of your journal. The PDF is generated on your device and leaves the device only if you choose to save or share it. You are responsible for where you send or store an exported PDF.

5. Scanning, photos, chat, and AI processing

### Barcode scanning

When you scan a barcode, the barcode number is sent directly from your device to the Open Food Facts database at world.openfoodfacts.org to retrieve product information. Like any internet request, this may expose your IP address to Open Food Facts, but the request does not include your Celia app identifier or journal.

### On-device label processing

Optical character recognition of ingredient labels uses Apple's Vision framework on your device. Celia's basic gluten-ingredient check also runs on your device. This processing does not require the label image to be uploaded.

### AI features

When you actively use an AI feature—such as AI label analysis, meal-photo logging, the assistant, or recipe ideas from a fridge photo—the photo and/or text you submit is sent over an encrypted connection through our Supabase-hosted proxy to the Google Gemini API. The request includes a feature identifier and the pseudonymous authorization needed to enforce usage limits.

Your journal is not automatically attached to an AI request. However, text or images you deliberately submit may reveal food preferences, coeliac disease, IBS, digestive symptoms, or other health-related information. Such information is processed only to provide the AI response you requested. By deliberately submitting health-related information after being informed of this processing, you explicitly consent to that processing for the request. You can withhold or withdraw that consent by not submitting health information to AI features; this does not prevent you from using the local journal or non-AI features.

We do not store AI photos, prompt content, or response content on our servers. Our proxy records limited operational metadata but is not designed to log request content.

Under the terms applicable to Google's paid Gemini API services, Google states that prompts and responses are not used to improve its products. Google currently states that it retains prompts, contextual information, and generated responses for 55 days to detect and prevent abuse, maintain the safety and security of the service, and make required legal or regulatory disclosures. Google may change this retention period under its applicable terms and documentation. That processing may occur outside the EU/EEA. See the Google Gemini API Terms and Gemini API abuse-monitoring documentation for current details.

Nothing is sent to Gemini in the background. AI processing happens only when you choose to use an AI feature.

6. Location and the restaurant map

If you use the gluten-free restaurant map and grant location permission, Celia obtains your current device coordinates while you are using the app. Those coordinates are sent through our Supabase-hosted proxy to perform a nearby-place search using Google Places.

The proxy converts searches to a shared geographic grid for place lookup and caching. We do not keep a personal location history linked to your app identifier. Area-based search results may be cached by geographic area for up to 14 days so that nearby users can share results.

Your device may also store the most recent map area and restaurant results locally to make the map faster when reopened.

Location permission is optional. Other Celia features continue to work without it.

7. Purchases

Subscriptions are purchased through Apple's App Store. We do not receive your payment-card details.

We use RevenueCat to determine whether the pseudonymous app identifier has an active Celia Pro entitlement. RevenueCat receives transaction and subscription information from Apple, such as product, subscription status, renewal date, and transaction identifiers, and associates it with the app identifier.

Deleting your Celia account or deleting the app does not cancel an App Store subscription. Subscriptions must be managed through Apple.

8. What we do not do

  • We do not display advertising or access the advertising identifier (IDFA).
  • We do not use third-party advertising or behavioral-tracking SDKs in the app.
  • We do not sell or rent personal data.
  • We do not share data for targeted advertising or marketing profiles.
  • We do not use journal or health-related information for advertising.
  • We do not make automated decisions that produce legal or similarly significant effects.

9. Legal bases under the GDPR

Depending on the feature, we rely on the following legal bases:

  • Performance of a contract (Article 6(1)(b)): to provide features you request, including AI processing, map searches, account functions, and subscription management.
  • Legitimate interests (Article 6(1)(f)): to enforce fair-use limits, prevent abuse and fraud, keep the service secure, diagnose failures, and maintain service reliability. We balance these interests against your rights and keep the data limited.
  • Consent (Article 6(1)(a)): for optional device permissions where consent is the appropriate basis. You can withdraw device permission in iOS Settings.
  • Explicit consent for special-category data (Article 9(2)(a)): when you deliberately include health-related information in content submitted to an AI feature. You can withdraw consent for future processing by not submitting health-related information to AI features.

Health-related information stored solely in your local journal is processed on your device and is not received by looplib AB as controller. Locally generated pattern observations remain on the device unless you choose to export or share them.

10. Service providers, data sources, and international transfers

ProviderPurposeMain processing location
SupabaseEU hosting, pseudonymous authentication, usage counters, database, and server functionsEU, including Ireland
Open Food FactsProduct database queried directly for barcode lookupsFrance/EU
Google Gemini APIAI processing of photos and text you choose to submitUS/global
Google PlacesRestaurant and venue search dataUS/global
RevenueCatSubscription and entitlement managementUS
AppleApp distribution, payments, device permissions, and optional device backupsUS/global
VercelHosting trycelia.com and cookieless aggregated website measurementsUS/global

Where personal data is transferred outside the EU/EEA, we use or rely on an applicable transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework where applicable, or the European Commission's Standard Contractual Clauses.

Third-party providers process data under their own terms and privacy documentation in addition to their agreements with us.

11. Retention

  • Pseudonymous account data, usage counters, and subscription association: retained while the Celia account exists and deleted or disassociated when account deletion is completed, except where limited information must be retained for security, fraud prevention, legal compliance, or transaction-record obligations.
  • Local journal: retained on your device until you delete entries, delete the account through the app, erase the app's data, or delete the app. Device backups are controlled separately by you and Apple.
  • AI content: not stored by our proxy. Google currently states that it retains prompts, contextual information, and generated responses for 55 days for abuse prevention, service safety and security, and required legal or regulatory disclosures. Google may change this period under its applicable terms and documentation. Under the terms applicable to Google's paid Gemini API services, this content is not used to improve Google's products.
  • Operational and security metadata: retained only as long as reasonably necessary to enforce limits, secure the service, investigate failures, and meet legal obligations.
  • Area-based restaurant cache: retained for up to 14 days and not designed to be associated with an individual user.
  • Website and support messages: email correspondence is retained only as long as reasonably necessary to respond, administer the relationship, resolve disputes, and meet legal obligations.

12. Your rights

Under the GDPR, where applicable, you may have rights to access, rectify, erase, restrict or object to processing, withdraw consent, and receive certain personal data in a portable format.

Celia provides the following controls:

  • Delete entries: individual journal records can be deleted within the app.
  • Delete Account: Profile → Delete Account deletes the local app data and requests deletion of the pseudonymous server account and associated server-side data. This cannot remove an App Store transaction record controlled by Apple or records another provider must retain by law.
  • Journal export: Profile → Privacy → Export creates a PDF copy of selected journal information on your device. This is a readable journal export and is not represented as a complete machine-readable GDPR portability export.
  • Permissions: camera, photo-library, notification, and location permissions can be changed in iOS Settings.
  • AI health-data consent: you can withdraw consent for future AI processing by no longer submitting health-related content to AI features.

Because we do not request direct identity information, we may need information available within the app, such as the pseudonymous app identifier, to locate server-side data. We will not collect additional identity information unless reasonably necessary to verify and handle a request.

You may lodge a complaint with a supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se.

13. Children

Celia is intended only for people aged 18 or older, and we do not knowingly collect personal data from anyone under 18. Celia does not request a user's date of birth, so we cannot ordinarily determine a user's age. A parent or guardian who believes a person under 18 has submitted personal data may contact us at hello@trycelia.com.

14. Our website

The trycelia.com website is hosted by Vercel. It uses cookieless, aggregated page-view measurements and does not use advertising cookies. Standard network and security information, such as IP address and request metadata, may be processed by the hosting provider to deliver and protect the website.

If you contact us through the website or by email, we process your email address and message to respond and handle your request.

15. Changes to this policy

We may update this policy as Celia evolves. Material changes will be announced in the app or on the website as appropriate. The date at the top identifies the current version.

16. Contact

Questions or privacy requests can be sent to hello@trycelia.com.