Introduction
At Cibarious, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our AI-powered ingredient narrative database at www.cibarious.org.
We apply EU-level data protection standards globally, ensuring consistent privacy protection for all our users worldwide. This policy should be read alongside our Cookie Policy, which provides specific details about our use of cookies and similar technologies.
Content Types: Our database includes educational content about a wide range of ingredients, including some that discuss alcoholic beverages (spirits, wines, beers) and dietary supplements in an educational, encyclopedic context. This content is provided for informational purposes only and does not promote consumption or constitute medical advice. For more information about how we handle specialized content, please see our Editorial Policy.Who We Are
Data Controller: Francesco Paolo Maria Di Salvia (Individual ownership) Location: Corso Vittorio Veneto, SNC - 84020 Valva (SA) - Italy Contact: [email protected] Website: www.cibarious.org Note: As we grow, our legal structure may evolve to include a registered company entity. This policy will be updated accordingly.Information We Collect
Information You Provide Directly
Account RegistrationWhen you create an account with us, we collect:
- Email address (required for authentication and communication)
- Name (for personalization)
- Nickname (display name within your account)
- Location (to provide region-relevant content)
- Age (to verify you meet our minimum age requirement of 18)
- Ingredient preferences: Items you save to your personal pantry collection
- Favorites and shelves: Your curated lists of preferred ingredients
- Usage patterns: How you organize and interact with your saved ingredients
- Support inquiries: When you contact us for help or feedback
- Newsletter subscription: If you separately opt-in to our mailing list (planned feature)
Information We Collect Automatically
Technical Information- Device data: Browser type, operating system, device identifiers
- Usage data: Pages visited, features used, time spent on site
- Network data: IP address, general location (country/region level)
- Website performance: Page load times, error rates, user flows
- Interaction patterns: How users navigate and use our service
- Aggregated statistics: Non-personally identifiable usage trends
How We Use Your Information
We process your personal data for the following purposes:Essential Service Provision (Legal Basis: Contract Performance)
- Account management: Creating and maintaining your user account
- Authentication: Secure login via magic links sent to your email
- Service delivery: Providing access to our ingredient database and features
- Pantry synchronization: Syncing your saved ingredients across devices
Service Improvement (Legal Basis: Legitimate Interest)
- Security monitoring: Detecting and preventing fraudulent or malicious activity
- Service stability: Ensuring reliable performance and preventing abuse
- Technical improvements: Identifying and fixing bugs or performance issues
Communication (Legal Basis: Consent or Contract Performance)
- Transactional emails: Account-related notifications and security alerts
- Marketing communications: Newsletter and updates (separate opt-in required)
- Support responses: Addressing your questions and providing assistance
Analytics and Optimization (Legal Basis: Consent)
- Usage analysis: Understanding how users interact with our service
- Feature development: Identifying popular features and areas for improvement
- Performance monitoring: Ensuring optimal website performance
Legal Bases for Processing
Under GDPR, we rely on the following legal bases:- Contract performance: Processing necessary to provide our service
- Consent: For analytics, advertising, marketing communications, and non-essential features
- Legitimate interests: For security, fraud prevention, and service stability
- Legal obligation: For compliance with applicable laws and regulations
Data Sharing and Disclosure
We do not sell, trade, or otherwise transfer your personal information to third parties, except as described below:Service Providers
We share data with trusted service providers who help us operate our service: Supabase (Database & Authentication)- Purpose: Secure data storage and user authentication
- Data shared: Account information, pantry data, authentication tokens
- Location: AWS US-East-2 data center
- Protection: Data Processing Agreement, encryption, access controls
- Purpose: Sending authentication magic links and planned newsletters
- Data shared: Email addresses, basic delivery metadata
- Location: EU data residency (Amsterdam) for European users
- Protection: Data Processing Agreement, encryption in transit
- Purpose: Website hosting and content delivery
- Data shared: Technical logs, basic usage statistics
- Location: Global content delivery network
- Protection: Privacy-focused hosting with data retention controls
- Purpose: Displaying personalized advertisements on our website (with your consent)
- Data shared: Anonymized usage data, advertising identifiers, cookies, page views
- Location: Global processing with servers primarily in the US
- Protection: Your explicit consent, Google's privacy safeguards, managed through InMobi CMP
- Third-party access: Google may share data with advertising partners for ad personalization
- Opt-out: You can manage your advertising preferences through our cookie consent dialog or Google Ad Settings
- Purpose: Managing cookie consent preferences and generating IAB TCF consent strings
- Data shared: Consent preferences and consent strings
- Location: Global processing
- Protection: InMobi's privacy safeguards and GDPR compliance
- Purpose: Website performance optimization, DDoS protection, and security services
- Data shared: IP addresses, request metadata, security logs, performance metrics
- Location: Global content delivery network with data centers worldwide
- Protection: Cloudflare's privacy policy, data processing agreements, and security measures
- Purpose: Website analytics and usage statistics (with your consent)
- Data shared: Anonymized page views, session data, device information (no personal identifiers)
- Location: Self-hosted or cloud-hosted analytics service
- Protection: Privacy-first analytics with no cookies, GDPR compliant, anonymized data collection
- Purpose: Detecting and preventing fraudulent activity, bot detection, and security monitoring
- Data shared: IP addresses, request metadata, device fingerprints (anonymized)
- Location: US-based processing with global coverage
- Protection: Data Processing Agreement, encryption, and security safeguards
Legal Requirements
We may disclose your information if required by law or to:- Comply with legal processes or government requests
- Enforce our terms of service
- Protect the rights, property, or safety of Cibarious, our users, or others
International Data Transfers
Some of our service providers are located outside the EU/EEA. When we transfer your data internationally, we ensure adequate protection through:- Standard Contractual Clauses approved by the European Commission
- Data Processing Agreements with all international service providers
- Your explicit consent for services requiring it (analytics, advertising)
- Technical safeguards including encryption and access controls
- EU users' data processed by SMTP2GO remains in EU data centers (Amsterdam)
- Supabase data is transferred to AWS US-East-2 under appropriate safeguards
- Google AdSense (when implemented) operates globally with your consent
- InMobi CMP processes consent data globally with appropriate safeguards
- Cloudflare processes traffic data globally with appropriate safeguards
- Umami Analytics processes analytics data with privacy-first measures (with your consent)
- IpQualityScore processes security data in the US with appropriate safeguards
Data Security
We take data security seriously and implement appropriate technical and organizational measures:Technical Safeguards
- Encryption: Data encrypted in transit (TLS) and at rest
- Authentication: Secure multi-factor authentication systems
- Access controls: Role-based access to personal data
- Regular updates: Security patches and system updates
Supabase Security Features
Our primary data processor, Supabase, implements:- SOC 2 Type II compliance
- Database-level encryption with AES-256
- Network isolation and VPC security
- Regular security audits and penetration testing
- Backup and disaster recovery procedures
Organizational Measures
- Data minimization: We collect only necessary information
- Access limitation: Personal data access on need-to-know basis
- Staff training: Regular privacy and security awareness
- Incident response: Procedures for handling potential breaches
Data Retention
We retain your personal data only as long as necessary:Account Data
- Active accounts: Data retained while your account remains active
- Deleted accounts: All personal data deleted immediately upon account deletion
- Inactive accounts: We may contact inactive users before any deletion
Technical Data
- Authentication tokens: 1 hour (access tokens) to 1 week (refresh tokens)
- Usage logs: Maximum 26 months (Google Analytics standard, when implemented)
- Security logs: Maximum 12 months for fraud prevention
Communication Data
- Support inquiries: Retained for 2 years to improve service quality
- Marketing communications: Until you unsubscribe or delete your account
Third-Party Advertising
We may display advertisements on our website through third-party advertising services. These services help us generate revenue to maintain and improve Cibarious while keeping our core features free.How Third-Party Advertising Works
Google AdSense (when implemented) When you visit our website and consent to advertising cookies through our InMobi consent dialog, Google AdSense may:- Display personalized advertisements based on your interests and browsing behavior
- Use cookies and similar tracking technologies to collect information about your visit
- Share data with Google's advertising partners to serve relevant ads across the web
- Track ad performance, impressions, and user interactions
Data Collected by Advertising Services
Third-party advertisers may collect:- Cookie identifiers: Unique identifiers stored in your browser
- Device information: Browser type, operating system, screen resolution
- Usage data: Pages visited, time spent on site, referring URLs
- Advertising data: Ad views, clicks, and interaction patterns
- Approximate location: Country or region-level geolocation based on IP address
Your Control Over Advertising
You have multiple ways to control advertising on our website: Consent Management- Use our InMobi consent dialog (displayed on first visit) to accept or reject advertising cookies
- Update your preferences at any time through the cookie settings link in our footer
- Withdraw consent without affecting your access to core website features
- Visit Google Ad Settings to manage personalized advertising
- Opt out of interest-based advertising through the NAI Consumer Opt-Out
- Use browser settings to block third-party cookies (may affect website functionality)
- We respect Do Not Track (DNT) browser signals where technically feasible
- Note that third-party advertisers may have their own DNT policies
Advertising Without Consent
If you decline advertising cookies:- You will still see advertisements, but they will not be personalized
- Ads will be contextual (based on page content) rather than behavioral (based on your browsing history)
- Your website experience and access to features will not be affected
Third-Party Privacy Policies
Our advertising partners have their own privacy policies that govern how they collect and use your data:- Google AdSense: Google Privacy Policy
- Google Advertising: How Google uses information from sites or apps that use our services
Your Rights Under GDPR
As a data subject, you have the following rights:Access and Portability
- Right of access: Request information about data we hold about you
- Data portability: Receive your data in a structured, machine-readable format (planned feature)
Correction and Deletion
- Rectification: Correct inaccurate or incomplete personal data
- Erasure: Request deletion of your personal data (immediate upon account deletion)
Processing Limitations
- Restrict processing: Limit how we process your data in certain circumstances
- Object to processing: Object to processing based on legitimate interests
- Withdraw consent: Withdraw consent for analytics, marketing, or other consent-based processing
Exercising Your Rights
To exercise these rights:- Log into your account to update basic information
- Contact us directly at [email protected] for complex requests
- Use cookie settings to manage analytics and advertising consent
Age Restrictions
Cibarious is intended for users aged 18 and older. We do not knowingly collect personal information from minors under 18. If we become aware that we have collected personal data from a minor, we will delete such information promptly. If you are a parent or guardian and believe your child has provided personal information to us, please contact us immediately.Marketing Communications
Newsletter and Updates
- Separate opt-in: Marketing communications require explicit, separate consent
- Clear identification: All marketing emails clearly identify Cibarious as sender
- Easy unsubscribe: One-click unsubscribe link in every marketing email
- Preference management: Manage communication preferences in your account
No Spam Policy
We never:- Send unsolicited marketing emails
- Share your email with third-party marketers
- Use pre-checked boxes for marketing consent
- Make service access conditional on marketing consent
Data Breach Notification
In the unlikely event of a data breach:- Authority notification: We will notify relevant supervisory authorities within 72 hours
- User notification: You will be informed without undue delay if the breach poses high risk
- Mitigation measures: We will take immediate steps to minimize impact
- Prevention improvements: We will strengthen security to prevent similar incidents
Third-Party Links
Our website may contain links to third-party services or websites. This Privacy Policy does not apply to those external sites. We encourage you to review the privacy policies of any third-party services you visit.Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technologies, or legal requirements. When we make material changes:- Effective date will be updated at the top of this policy
- Website notification may be displayed for significant changes
- Email notification for substantial changes affecting your rights (if you're subscribed)
- Continued use of our service after changes indicates acceptance
Supervisory Authority
If you have concerns about our data processing practices, you have the right to lodge a complaint with your local data protection authority: For EU residents: Your local Data Protection Authority For Italian residents: Garante per la protezione dei dati personali (https://www.gpdp.it)Contact Information
For any questions about this Privacy Policy or our data practices: Email: [email protected] Website: www.cibarious.org Response time: We aim to respond within 3 business days Data Protection Inquiries: Same contact information above Data Controller: Francesco Paolo Maria Di Salvia Location: Corso Vittorio Veneto SNC - 84020 Valva (SA) - ItalyThis Privacy Policy is designed to comply with the EU General Data Protection Regulation (GDPR), ePrivacy Directive, and other applicable data protection laws. We apply these standards globally to ensure consistent privacy protection for all users. Last reviewed: November 5, 2025