Privacy Policy

DRAFT — last updated 2026-04-17 — pending legal review

This page explains what data Cigar Ring collects when you use the app, why we collect it, who we share it with, and what control you have over it. We try to make this readable rather than legalistic.

Cigar Ring is a catalog and tracking app for cigar enthusiasts. We never sell tobacco products. When we link to retailers, we may earn a commission on purchases — that’s explained in our Terms.

Who we are

“Cigar Ring” refers to the application available at cigarring.app and any associated services. The operating entity is currently being formalized; for any data-protection inquiry, contact privacy@cigarring.app.

What we collect

We collect data in four categories:

  • Account data — your email address, your password (stored as a one-way hash by our auth provider), the language you chose, and the timestamps of sign-in events.
  • Content you create — cigars you add to humidors, ratings and tasting notes you write, photos you upload (band scans, smoke logs), voice notes if you record them.
  • Usage data — which screens you visit, which features you use, errors the app encountered. Used to debug issues and decide what to build next. We do not sell or share this data with third-party advertisers.
  • Technical data — your IP address, device type, browser, and approximate location (country level only, derived from IP). Used for security, fraud prevention, and to apply the right jurisdiction- specific behavior (e.g., hiding affiliate buy buttons in France per local law).

How we use it

We use your data to:

  • Provide the service (sign you in, save your collection, recognize cigar bands you scan).
  • Generate personal recommendations using AI models.
  • Detect and prevent abuse, fraud, and bot activity.
  • Comply with legal obligations (age verification, tobacco-advertising rules).
  • Improve the product (anonymous aggregate analytics, error reporting).

We do not use your personal data to train AI models. Cigar identification uses general-purpose models hosted by Anthropic and Voyage AI; your scans are sent to those providers solely to return a match for that one request, and they do not retain or train on the data per their commercial terms.

Who we share it with

We share data only with the third-party services that make the app work (“sub-processors”). They are:

  • Supabase (US, EU regions) — database hosting, authentication, file storage.
  • Vercel (US, EU edge) — application hosting and CDN.
  • Anthropic (US) — AI for cigar-band identification and recommendation drafting.
  • Voyage AI (US) — image embeddings for visual search.
  • Sentry (US, EU) — error tracking. Configured to scrub personal identifiers from error reports.
  • PostHog (US, EU) — product analytics, when you have not opted out.
  • Affiliate retailers — if you click a buy link, we send the affiliate network a tracking ID so we earn commission. We never share your email, name, or other identifying data with affiliates.

We do not sell your personal data. We do not allow advertisers to track you on our app.

Where your data lives

Your account data and content are stored in Supabase’s EU region by default. Backups are stored in the same region. Some processors (Anthropic, Voyage, Vercel) operate from US regions; data sent to them for processing transits the US. For users in the EU, this transfer is governed by Standard Contractual Clauses with each processor.

How long we keep it

We keep your account and content as long as your account is active. If you delete your account, we delete the associated personal data within 30 days. Aggregated, anonymized usage statistics may be retained indefinitely (these contain no personal identifiers).

Backups containing your data are retained for up to 90 days after deletion before being purged.

Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data (the “right to be forgotten” under GDPR).
  • Export your data in a portable format.
  • Object to certain processing or restrict it.
  • Withdraw consent where consent is the legal basis.
  • Lodge a complaint with your local data-protection authority.

To exercise any of these rights, email privacy@cigarring.app. We respond within 30 days.

Cookies

We use cookies and similar storage to keep you signed in and to remember your preferences. Details are on our dedicated cookie page.

Age requirements

Cigar Ring is for adults of legal smoking age in their jurisdiction (21+ in the United States, generally 18+ elsewhere). We verify age before showing tobacco-product content. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us and we will delete it.

Changes to this policy

When we update this policy, we change the date at the top of the page. For changes that materially affect your rights, we will notify you by email and inside the app before they take effect.

Contact

Privacy questions: privacy@cigarring.app
General contact: hello@cigarring.app