Privacy Policy
Celia — Gluten-Free Lifestyle App
Last updated: 17 July 2026
Celia is built so that we know as little about you as possible. This policy explains what data the Celia app and the trycelia.com website handle, why, and what rights you have.
1. Who we are
The data controller is looplib AB, a company based in Sweden.
Contact: hello@trycelia.com
2. Summary
- No account, no email, no name. The app creates a random, anonymous ID on your device. We cannot identify who you are.
- Your food journal never leaves your phone. Meals, symptoms and notes are stored only on your device.
- Label reading and the basic gluten check happen on your device. Barcode lookups query the open Open Food Facts database directly, without any identity information.
- Photos and chat messages sent to AI features are processed transiently by Google's Gemini AI to give you an answer, and are not stored on our servers.
- No ads, no analytics trackers, no sale of data. Ever.
- You can delete everything at any time with one tap in the app (Profile → Delete Account).
3. No account — an anonymous ID
When you first open Celia, the app automatically creates an anonymous account with a randomly generated ID. We never ask for your name, email address, phone number or any other identity information.
The only data stored on our servers under this ID is:
- daily usage counters (how many AI requests and map searches you have made, used to enforce fair-use limits), and
- your subscription status (whether you have Celia Pro — no payment details, see section 7).
4. Data that stays on your device
The following is stored only locally on your device and is never uploaded to our servers:
- your food journal (meals, photos you have logged, symptom entries, daily notes)
- your scan history
- your app settings and reminder preferences
We have no access to this data. If you delete the app, it is deleted with it. Note that it may be included in your own device backups (iCloud or computer backups), which are governed by Apple's terms and controlled by you.
5. Scanning, photos and AI processing
Barcode scanning. When you scan a product barcode, the barcode number is sent directly from your device to the open product database Open Food Facts (world.openfoodfacts.org, run by a French non-profit) to fetch the product's ingredient information. Like any internet request it includes your IP address, but it contains no identity or account information — and we never see or store your lookups.
Label scanning. Text recognition (OCR) of ingredient lists runs on your device using Apple's Vision framework, and the basic gluten-ingredient check is also performed entirely on your device. Nothing is uploaded.
AI features. When you use an AI feature — the AI label analysis, logging a meal photo, asking the assistant a question, or getting recipe ideas from a fridge photo — the photo and/or your text is sent over an encrypted connection through our own server proxy to the Google Gemini API, which generates the response.
- We do not store your photos or messages on our servers. Our proxy only logs technical metadata (which feature was used and when), never the content.
- Under Google's paid API terms, Google does not use this data to train its AI models. Google may retain API data for a short period for abuse monitoring in accordance with its own terms.
- Processing happens only when you actively use a feature — nothing is sent in the background.
6. Location and the restaurant map
If you use the gluten-free restaurant map and grant location permission (used only while using the app), your approximate position is sent through our server to the Google Places API to find restaurants near you.
- We do not keep any history of your location linked to you. Search results are cached on our servers by geographic area only (a coarse map grid shared by all users), for up to 14 days, so repeated searches in the same area are faster and cheaper.
- Location permission is optional — every other feature works without it.
7. Purchases
Subscriptions are purchased through Apple's App Store. We never see your payment details. To know whether your anonymous ID has an active subscription, we use RevenueCat, which receives anonymized transaction information from Apple (subscription status, product, renewal dates) linked to your anonymous ID.
8. What we don't do
- No advertising, and no advertising identifiers (IDFA).
- No third-party analytics or tracking SDKs in the app.
- No selling, renting or sharing of personal data for marketing.
- No profiling and no automated decisions with legal effect.
9. Legal bases (GDPR)
- Performance of a contract (Art. 6(1)(b)): providing the app's features you actively use — AI analysis, map search, subscription management.
- Legitimate interest (Art. 6(1)(f)): fair-use limits, abuse prevention and service security (the usage counters in section 3).
- Health-related information in your journal is processed only locally on your device and is not processed by us as a controller.
10. Processors and international transfers
We use the following service providers and data sources:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Hosting, anonymous authentication, database, server functions | EU (data stored within the EU — Ireland) |
| Open Food Facts | Product database for barcode lookups (queried directly from your device; receives no account data) | France/EU |
| Google (Gemini API) | AI processing of photos and text you submit | US/global |
| Google (Places API) | Restaurant map data | US/global |
| RevenueCat | Subscription status management | US |
| Apple | Payments and app distribution | US/global |
| Vercel | Hosting of the trycelia.com website and cookieless, aggregated page-view statistics | US/global |
Where data is transferred outside the EU/EEA, it is protected by the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses.
11. Retention
- Server-side data (usage counters, subscription status): kept while your anonymous account exists, deleted immediately when you use Delete Account in the app.
- Photos and AI messages: not stored by us at all (see section 5).
- Area-based map cache: automatically deleted after 14 days and is not linked to you.
12. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, object to processing of, and port your personal data. In Celia, the two most important rights are built in:
- Erasure: Profile → Delete Account permanently deletes your anonymous account and all server-side data, and resets the app.
- Portability: Profile → Privacy → Export lets you export your journal as a PDF.
Because we cannot identify you, requests beyond this may be technically impossible to fulfil — we simply have no way of knowing which anonymous ID is yours except through the app on your device.
You also have the right to lodge a complaint with a supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (IMY, imy.se).
13. Children
Celia is not directed at children under 13. We do not knowingly process children's data — and since we collect no identity data at all, we cannot identify any user's age.
14. Our website
If you contact us through trycelia.com or by email, we store your email address and message only for as long as needed to reply and handle your request. The website is hosted by Vercel and uses Vercel's cookieless, aggregated page-view statistics, which cannot identify you. The website does not use advertising or analytics cookies, and all fonts are served from our own domain.
15. Changes
We may update this policy as the app evolves. Material changes will be announced in the app or on this page. The "Last updated" date at the top always reflects the current version.
16. Contact
Questions about privacy? Email hello@trycelia.com.
