← Cibus Maps

Privacy Policy

Cibus Maps · Last updated August 5, 2026

This Privacy Policy explains how Skript It Oy ("we", "us") handles information in the Cibus Maps mobile application ("the App"). We built Cibus Maps to need as little personal data as possible: there are no user accounts, we do not ask for your name or email, and we do not show ads or track you across other apps or websites.

This page is about you, as a person who uses the App. It is not about the restaurants the App lists. If you operate a restaurant and want to know where its listing came from, what we hold, and how to have it corrected or removed, that is a separate document: Where our restaurant listings come from.

1. Information we process

DataWhyWhere it goes
Approximate & precise locationTo center the map on you and to find restaurants inside the area you scan.The coordinates of an area you scan are sent to our backend, which queries Google Places to return nearby places. Your continuous location is not tracked by our backend.
Anonymous device identifierA random ID generated on your device, used to count how much scanning work you have used against a daily allowance.Sent with backend requests. It is not linked to your name, email, or real-world identity.
Search queriesThe text you type into the place search box.Proxied through our backend to Google Places autocomplete to return suggestions.
Anonymous usage analyticsTo understand how the App is used — such as how many scans run, or where people drop out of onboarding — so we can improve it.We log event names (for example "scan completed" or "app opened") to Cloudflare Analytics Engine. These events carry no name, email, or precise location. They are tagged with a one-way hash of your anonymous device ID so we can measure usage funnels; that hash cannot be reversed to identify you.

2. Stored on your device

Your saved scans, saved collections, and onboarding state are stored locally on your device only. The App may also keep your latest exact location fix locally for up to 24 hours so the map can start near you. The App does not use that fix after 24 hours; while running it schedules deletion at expiry, and after termination it deletes expired data the next time it starts. It is also deleted when the App observes that location permission was denied or revoked. These local copies are not uploaded as account data unless you explicitly share a saved scan. Removing the App deletes them.

3. Data we do not collect about you

Said precisely, because the two are easy to confuse: the App does hold names, addresses, telephone numbers and websites of the restaurants it lists, which for a business run by an individual are that person's details. Those are described in the source notice, not here.

4. Service providers

We share the limited data above only with providers that help operate the App:

5. Retention

6. Legal basis (EEA/UK)

Where the GDPR applies, we process the data above for our legitimate interest in operating and securing the App (Article 6(1)(f)). Location is processed based on the permission you grant on your device, which you can withdraw at any time in your device settings.

This page previously also claimed Article 6(1)(b) — performance of a contract. That claim is withdrawn: Article 6(1)(b) requires a contract to which the data subject is a party, and there is none. The App has no accounts and nothing is sold in it. Our position on the remaining basis is self-certified by the controller; no external qualified review obtained.

7. Your rights

You can revoke location permission in your device settings at any time. You can clear all locally stored data by deleting the App. Depending on your region, you may have rights to access, correct, or delete your data. To exercise any of them — including deletion of the limited data tied to your anonymous device ID — write to [email protected]. We do not ask you to prove your identity with a document; we reply to the address you write from.

Our lead supervisory authority is the Office of the Data Protection Ombudsman — Tietosuojavaltuutetun toimisto — in Finland. You may lodge a complaint with it under Article 77 of the GDPR. You may also complain to the supervisory authority of the EU or EEA country where you live or work, or where you believe the issue arose, under Article 56(2); that authority handles it or passes it to ours.

8. Children

Cibus Maps is not directed to children under 13, and we do not knowingly collect data from them.

9. Changes

We may update this policy as the App evolves. Material changes will be reflected by the "Last updated" date above.

10. Contact

Skript It Oy (business ID 3483624-4)
Kustaantie 9a 2, 01400 Vantaa, Finland
Data-protection requests: [email protected]
Everything else: [email protected]


Cibus Maps · Skript It Oy