Privacy by design

Privacy Policy

CigarMind is local first. You can use collection, inventory, humidor, and tasting-journal features without an account; each network feature requires a deliberate action or consent.

Effective: July 16, 2026Version 1.3Operator: Shanghai Souldigger Information Service Co., Ltd.

1. Scope and controller

This policy applies to the CigarMind mobile app, CigarMind account and sync services, and the official website at cigarmind.souldigger.cn. CigarMind is operated by Shanghai Souldigger Information Service Co., Ltd., which is responsible for the processing, support, and legal notices described here.

CigarMind is intended only for adults who have reached the legal age for tobacco use where they live. The product does not sell tobacco or encourage anyone to begin or increase tobacco use.

2. Data we process

CategoryExamplesDefault locationWhen it uses the network
Collection factsCigars, lots, inventory events, vintages, box codesOn-device SQLiteOnly if you choose cloud sync
Tastings and humidorsRatings, flavors, context, target ranges, readingsOn-device SQLiteIf you choose sync
Settings and consentLanguage, units, thresholds, adult confirmation, location and AI choicesSharedPreferencesNormally not uploaded
Security identifiersRandom installation ID and account sessioniOS KeychainWhen calling protected services
Optional notification device identifierAPNs device token, sandbox/production environment, app topic, locale, and app versionApple and the CigarMind MySQL serviceWhen you allow notifications and are signed in
Optional location weatherCoordinates rounded to two decimal places (about 1 km), locality label, current weatherCurrent app sessionWhen you consent and refresh weather
Optional AI inputA recognition photo you expressly selectDuring the requestWhen you request recognition
Optional catalog-research candidateBrand, line, model, vitola, origin, optional official source, sanitized-photo SHA‑256 digest, contributing-account binding, and consent/withdrawal relationshipOn-device SQLite and the CigarMind MySQL serviceOnly when you are signed in, attest adult status, and separately opt in; the photo is not uploaded
Account and syncHashed Apple subject, verified email, session hash, collection/journal/humidor sync recordsCigarMind MySQL serviceWhen you use Apple sign-in and sync
Subscription and entitlementProduct and environment, transaction and original-transaction IDs, account token, purchase/expiry/revocation dates, renewal and entitlement state, notification UUID, and signed-payload hashApple and the CigarMind MySQL serviceWhen you buy or restore, or Apple reports a subscription change

3. On-device storage

CigarMind stores seven categories of core user facts in on-device SQLite: cigars, inventory lots, inventory events, tasting entries, humidors, humidor readings, and recognition history. If you voluntarily contribute a catalog candidate, the device also keeps a separate table recording that catalog-consent workflow. After you confirm a recognition result or manual photo, the app may keep a JPEG copy that was re-encoded and stripped of EXIF/GPS in its private application-support directory and store that device-file reference in SQLite; SQLite itself does not store photo binaries.

Language, currency, temperature unit, target ranges, notification preferences, and consent choices use SharedPreferences. The random installation identifier and signed-in session use system secure storage—Keychain on iOS.

You can export versioned JSON containing eight on-device data tables plus collection and tasting CSV files. Exports never contain image binaries; recognition media paths are redacted by default and included only if you explicitly choose that option. “Remove from this device” transactionally deletes the seven core fact categories, catalog-consent records, and app-managed photos, but preserves preferences and the cloud account. To remove the secure session, sign out or delete the account before uninstalling the app.

4. Optional location and Open-Meteo weather

Location weather is off by default. After consent, CigarMind requests system location access only when you open the relevant feature or refresh it. The location is used only for the current operation: the app immediately rounds latitude and longitude to two decimal places (about a 1 km scale) before requesting current conditions from Open-Meteo. A city or region label is produced through device geocoding.

CigarMind does not write either raw or rounded location to the collection database or use it for advertising or cross-app tracking. The operating system, device geocoding service, and Open-Meteo may process permissions, network address, request coordinates, and service logs under their own policies. You can turn location access off in CigarMind or iOS settings.

5. AI image recognition and voluntary catalog research

Image recognition

After adult confirmation and AI-image consent, you can capture or select a photo. The app re-encodes the image as JPEG, limits its dimensions, removes EXIF/GPS, and sends it through api.cigarmind.souldigger.cn to the CigarMind service, which uses the HY‑Vision model through Tencent Cloud TokenHub. The service returns up to three candidates; only a candidate you confirm is saved to your collection and linked to the sanitized on-device copy.

The CigarMind API is designed not to write photos to disk, cache, or request logs. Base64 image data is decoded and validated only for the current request before being sent to the vision service. Service logs may include request ID, route, status, duration, model, usage, and error code, but not the original image, Base64 payload, authorization token, or request body. The third-party model service may still process requests under its applicable terms.

AI output can be wrong. A “confidence” label is not an authenticity probability, health conclusion, or valuation. Verify brand, line, box code, vintage, and provenance yourself.

Voluntary catalog candidates

A manually photographed entry remains on your device by default. Only after you are signed in, attest that you meet the local legal age, complete the catalog fields, and opt in through a separate confirmation does the app submit brand, line, model, vitola, origin, an optional query-free HTTPS official-source URL, and the sanitized photo's SHA‑256 digest. The photo, EXIF, location, inventory, price, and notes are not submitted with this candidate.

The photo digest is a non-reversible duplicate-assessment aid and is not used to reconstruct the photo. The on-device consent record stores the CigarMind user ID that contributed it so only that same account may submit, retry, or withdraw, preventing an account switch from misbinding consent. This ID is not sent as an extra catalog-candidate field; the server identifies the account from the verified session. The service keeps a withdrawal relationship to make same-account submissions idempotent, aggregate identical candidates from different accounts, and honor withdrawal or account deletion. The internal review view contains neither user identifiers nor photo digests. Candidates enter a human research queue only; they are never auto-published as official catalog facts, public photos, AI facts, or authenticity conclusions. You can withdraw from the corresponding collection detail. To avoid losing the withdrawal credential, the app blocks local clearing or deletion of the associated collection record while a candidate remains unwithdrawn.

6. Apple sign-in, Keychain, and MySQL sync

Local core features do not require an account. If you choose Sign in with Apple, the app sends an Apple identity token, one-time authorization code, login nonce, and optional Apple-user consistency identifier to the CigarMind API. We never receive your Apple password.

After verifying Apple’s signature, the server stores a non-reversible server-HMAC representation of the Apple account subject and, if Apple provides it, the verified email or private-relay indicator. The server stores only a SHA‑256 hash of each session token and encrypts the refresh credential needed to revoke Apple authorization during account deletion. The raw session token remains in device Keychain.

If you choose cloud sync, structured collection, tasting-journal, and humidor records are stored in a CigarMind-operated MySQL database. Versions, changes, deletion tombstones, and short-lived idempotency records support multi-device conflict handling. Sync is designed not to upload recognition photo binaries.

When you allow notifications and are signed in, iOS registers with Apple Push Notification service (APNs) and returns a device token. CigarMind may associate that token with the current user, the login session that registered it, the CigarMind app topic, sandbox or production environment, locale, and app version to deliver service alerts you select—such as humidor alerts—and open the corresponding screen when tapped. The token is not used for advertising, cross-app tracking, or marketing profiles, and is not echoed in API responses or operational logs.

When you buy or restore Premium, the app supplies the signed-in account's random UUID to Apple as appAccountToken to prevent a transaction from being attached to the wrong account. The server verifies Apple's signature, queries the App Store Server API for current status, and stores product, transaction and original-transaction identifiers, purchase/expiry/grace/revocation dates, auto-renewal state, environment, entitlement state, and verification time. Apple's Server Notifications V2 also supplies a notification UUID, type, signed date, and transaction references; the server stores only a SHA‑256 hash of the signed payload, not the full notification payload.

7. Purposes and choices

  • Provide collection, inventory, tasting-journal, humidor, and personal-statistics features;
  • Retrieve weather or produce AI recognition candidates when you request it;
  • Receive a minimized catalog-research candidate when you separately opt in, aggregate duplicate leads, support human verification, and honor withdrawal;
  • Authenticate accounts, secure sessions, sync selected data, and honor deletion requests;
  • Register the current device and deliver service alerts you select when notifications are enabled;
  • Verify purchases, grant or revoke Premium, prevent a subscription from being reused across accounts, and process renewal, refund, and billing-grace events;
  • Prevent abuse, diagnose faults, and maintain service security and availability;
  • Respond to support email you send and comply with applicable legal obligations.

Location, AI images, and cloud sync are not required to maintain a local collection. You may decline consent, revoke system permission, sign out, or stop using a feature. We do not sell personal data, use collection, photo, location, or tasting data for third-party targeted advertising, or place analytics trackers or advertising cookies on this website.

8. Service providers

  • Apple for identity, system permissions, Keychain, APNs device registration and notification delivery, app distribution, in-app purchases, subscription status, and refunds;
  • Open-Meteo for current weather when you enable it;
  • Tencent Cloud TokenHub / HY‑Vision for cigar-image candidate processing you request;
  • CigarMind hosting and MySQL infrastructure for accounts, session hashes, sync, minimized catalog-research candidates, and API security logs.

These providers may act as independent services or processors and may process data outside your region under their own terms, privacy policies, and applicable law.

9. Retention, export, and deletion

  • On-device facts and app-managed photos: kept until you remove them in the app, delete the corresponding collection item, or uninstall. “Remove from this device” also deletes recognition and manual photos in the app-private directory. Keychain items may survive uninstall under system behavior, so sign out or delete the account first.
  • Preferences: kept until changed, app data is cleared, or the app is uninstalled. “Clear local data” does not reset these settings.
  • AI request content: the CigarMind API does not intentionally persist recognition photos; minimized operational metadata is retained only as reasonably necessary for security, troubleshooting, and service operations.
  • Catalog-research candidates: the device consent record remains until you withdraw, delete the associated cigar, or clear local facts. The server contribution relationship remains until withdrawal or account deletion. Withdrawal removes your relationship; if no contributors remain, the aggregate candidate is also deleted. The candidate endpoint stores no photo.
  • Account and sync: kept until account deletion or for as long as needed to provide the sync service you request. Expired or signed-out sessions become invalid.
  • Notification device identifiers: kept until you turn notifications off in the app, sign out of the session that registered the device, delete the account, or Apple reports that the token is invalid. Turning notifications off attempts immediate unlinking; if offline, the app retries during a later initialization. You can also block delivery at any time in iOS Settings.
  • Subscription records: transaction bindings, transaction state, and entitlement are kept as needed to deliver purchased benefits, handle refunds or disputes, prevent credential rebinding, and meet applicable tax, legal, or platform duties. Account deletion removes the active user link to transactions and entitlement. Minimal Apple-notification anti-replay metadata—notification UUID, event type, date, transaction reference, and payload hash—may remain for the necessary period without the full signed payload.
  • Support correspondence: kept until the matter is resolved and reasonable dispute, security, and compliance periods expire; you may request deletion.

Before a cloud-account deletion succeeds, the service requests revocation of CigarMind’s Apple sign-in authorization. If revocation is temporarily unavailable, deletion is not represented as complete and you can retry. On success, the active MySQL user, sessions, encrypted Apple credential, current sync values, change log, tombstones, idempotency records, catalog-candidate contribution relationships, and user-bound subscription transactions and entitlement are cascade-deleted; aggregates with no remaining contributor are also removed. The Apple subscription is not automatically cancelled. Restricted disaster-recovery backups, if any, expire through their secure rotation and are not reused to provide a deleted account.

See the Account Deletion Guide for exact steps.

10. Security and international processing

We use HTTPS, least privilege, request-size limits, rate limits, session hashing, Apple-subject HMAC, encrypted refresh credentials, short-lived APNs ES256 authorization, and database foreign-key isolation. No system is absolutely secure. Never email a session token, Apple authorization code, APNs token, or unnecessary private photo to support.

Apple, Open-Meteo, Tencent Cloud, or model services may process requests across regions. We apply reasonable minimization, contractual, and security measures as required by applicable law. If you disagree with an optional service’s data flow, do not enable it; local features remain available.

11. Your rights and adult restriction

Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing and to withdraw consent. You can directly export or clear on-device facts, manage system permissions, sign out, and delete the cloud account in the app, or contact support. We may take reasonable steps to verify the requester’s identity.

CigarMind is only for adults who have reached the legal age for tobacco use where they live. We do not knowingly collect accounts or tobacco-preference data from minors. Contact us if you believe such data exists.

12. Website, policy updates, and contact

This website has no accounts, advertising or analytics trackers, or marketing cookies. Standard server access logs may record IP address, time, path, status, and browser technical information for security and reliability.

If this policy changes materially, we will update the effective date and provide an app or website notice when appropriate. Review the current version before continuing to use optional network features.

Privacy and support contact

Shanghai Souldigger Information Service Co., Ltd.
Email: hoprabbit-support@souldigger.cn

This is the verified shared support mailbox for existing SoulDigger products. Include “CigarMind” in the subject.