Privacy Policy
Effective October 5, 2026
This policy explains what information Cibotti, Inc. ("Cibotti", "we", "us") collects through cibotti.app and the Cibotti record ledger (the "Service"), why we collect it, who we share it with, and the choices you have. Questions go to john@cibotti.app.
Who this applies to
The Service is used by businesses (our "customers") to keep tamper-evident records. People who sign in do so with an access code issued by their organization. For records a customer keeps in the ledger, the customer decides what is recorded and why, and we process that information on the customer's behalf. If you are a staff member of one of our customers, your organization is your first point of contact for questions about the records it keeps.
What we collect
| Information | Where it comes from | Why |
|---|---|---|
| Your name, role and organization | Your organization, when it sets up your access | To show who made each record and control what you can see |
| Your access code | Your organization | To sign you in. We store only a scrambled (keyed hash) form, never the code itself. |
| Ledger entries, project actions and attached files | You and your colleagues | To provide the record ledger |
| IP address, approximate location (city, region, country and coordinates estimated from your IP address) and browser/device type, for each entry | Automatically, from your connection | To record where an entry came from and to flag unusual activity, such as entries from distant locations within minutes |
| Sign-in sessions and failed sign-in counts | Automatically | To keep you signed in, sign you out after inactivity, and block guessing attacks |
| Name, email and message you send through a contact form or by email | You | To reply to you |
| Technical logs (request time, address, outcome, errors) | Automatically, from our hosting provider | To keep the Service secure and working |
We do not use advertising trackers, sell personal information, or share it for cross-context behavioral advertising.
Tamper-evident records are permanent
The purpose of the Service is that records cannot be quietly changed or removed. Each ledger entry is linked to the one before it by a cryptographic fingerprint, and fingerprints are periodically anchored to the Bitcoin blockchain through OpenTimestamps. Because of this:
- Ledger entries and their attached files are kept for as long as the customer's ledger exists, and are not edited or deleted, even on request. Corrections are made by adding a new entry that refers to the earlier one.
- Only fingerprints (SHA-256 hashes) leave our systems for anchoring. The content of entries and files is never published.
- Anyone holding a copy of a record or file can check its fingerprint on our public verify page. That page confirms whether a fingerprint exists and when it was recorded. It does not show the record's content.
- Each Project Record PDF carries a QR code and link. Anyone who has that link can see the project's name, the organization's name, the name of the person who generated the record and when, and the record's fingerprints and Bitcoin anchoring status. They cannot see the contents of the project or its files. Treat a Project Record PDF as you would any document you share outside your organization.
Who we share information with
We use these service providers to run the Service. They process information only to provide their services to us:
- Cloudflare, Inc. hosts the website, application, database and file storage, and provides network security.
- Formspree delivers messages sent through the website's contact form to our email.
- Google Fonts supplies fonts on some public pages, so your browser contacts Google when it loads them.
- cdnjs (run by Cloudflare) supplies the code libraries used to build PDF and ZIP exports in your browser.
- OpenTimestamps calendar servers and the Bitcoin network receive fingerprints only, never content.
We may also disclose information if the law requires it, to protect the rights, property or safety of Cibotti, our customers or others, or as part of a merger or sale of the business, in which case this policy continues to apply.
How long we keep it
- Ledger entries, files and the origin details recorded with them: for the life of the customer's ledger (see above).
- Sign-in sessions: deleted 2 days after they end. Sessions end on sign-out, after 30 minutes without activity, or 24 hours after sign-in.
- Failed sign-in counters (which include IP addresses): deleted after about a day.
- Technical logs: a few days, under our hosting provider's standard retention.
- Database backups: 90 days in our hosting provider's storage, then automatically deleted.
- Backup copies of uploaded files: kept for as long as the original files, which are part of permanent ledger entries (see above).
- Contact messages: as long as needed to respond and keep a record of the conversation.
How we protect it
Connections are encrypted (HTTPS). Access codes are stored only in scrambled form. Each request is checked against the person's organization and role. Sessions end automatically after inactivity. Uploads are restricted to safe file types, checked by their contents. Repeated failed sign-ins are blocked. No method of transmission or storage is completely secure, but we work to protect information and will notify affected customers of a breach as the law requires.
Your choices and rights
Depending on where you live, you may have the right to ask for access to, correction of, or deletion of your personal information, or to object to or restrict certain uses. Email john@cibotti.app. If the information is part of a customer's records, we will refer your request to that customer and help them respond. Deletion requests cannot remove permanent ledger entries (see above), but an organization can deactivate your access at any time. We will not discriminate against you for exercising your rights.
Children
The Service is for businesses and is not directed at children under 16. We do not knowingly collect their information.
International users
Cibotti is based in the United States, and our providers may process information in the United States and other countries.
Changes
We will post any changes here and update the date above. If a change is significant, we will tell customers before it takes effect.
Contact
Cibotti, Inc. · john@cibotti.app · 8 The Green, Suite B, Dover, DE 19901