Skip to content
PrivacyTerms
←Back to home

Privacy Policy

Last updated: 19 September 2026

1. Who We Are

Cella (the "App") is made by Ahmed Youssef, an individual developer based in Australia, who is the data controller for the limited personal data described in this policy. You can reach us at info@cella-ai.com.

2. Data Collection and On-Device Processing

We do not collect your personal information. Cella has no accounts and no sign-in, so we never ask for your name, your email address, or a password, and we never receive them. We do not track you, we show no advertising, we run no analytics, and we do not sell or share your personal data with anyone.

Your documents are stored on your device and synchronized through your Apple iCloud account so they are available on your devices. Personal documents, including Private Vault content, remain in your private CloudKit database. If you choose to share a Default-vault space, Apple exposes that space and its documents from the owner's private database to people with the sharing link and to participants you invite through their shared CloudKit databases. Apple processes synchronized and shared data under its iCloud terms and privacy policy. We do not operate the iCloud databases and cannot access their contents. By default, classification and Ask AI still run on-device using Apple Intelligence. Your documents never reach us: there is no setting that sends them our way, and no version of using the App that puts them in our hands.

One category of data does reach us, and we would rather state it here than have you discover it later. When the App crashes or encounters an error, it sends us a technical report about that failure. The report contains no document content, no file names, and nothing that identifies you. Clause 6 sets out its exact contents and how to switch it off.

3. Third-Party AI Providers

If you choose to enable a cloud AI provider for a vault, the content of documents in that vault is sent to the provider you selected in order to classify documents and answer your questions. This happens only for vaults you explicitly configure to use a cloud provider. Those requests go from your device directly to the provider, using your own account and key. They do not pass through us, and we never see their contents. Because both the provider and the account are yours, that provider's own terms and privacy practices govern what happens to your content once it arrives, as clause 7 explains. Cloud processing stays off until you turn it on, and switching a vault back to on-device processing stops it.

4. API Keys and Credentials

Any API keys you enter are stored securely in the iOS Keychain on your device. We do not collect, transmit, or have access to your API keys.

5. Backups

Backups you create are password-encrypted files. You control where those files are stored. We do not have access to your backups or their passwords.

6. Crash Diagnostics

Crash and error diagnostics are the only data the App ever sends us. A report contains only the following: the crash itself, your device model and iOS version, the App version, and a short code describing what failed. Nothing further is included. It never includes your documents, their names, their file paths, their contents, or anything a document produced. It does not include your name, email address, or IP address, and there is no account or advertising identifier attached. Each installation is given a random identifier so that repeated reports from the same install can be grouped; it is not linked to you. Because that identifier could in principle single out one installation, data protection law treats these reports as personal data even though they say nothing about who you are, so we give them every protection the rest of this policy describes.

Diagnostics are on when you install the App, and you can turn them off at any time in Settings under Diagnostics. We rely on our legitimate interest in keeping the App working correctly as our lawful basis for this, having judged that a crash report carrying no document data and no contact details is minimally intrusive. If you would rather we did not, the switch in Settings is the fastest way to object, and you can also write to us.

7. Disclosure to Third Parties

We use Sentry (Functional Software, Inc.) to receive and store the diagnostics described above, under a data processing agreement that permits them to use it only to provide that service to us and requires them to protect it to the standard this policy sets out. Apple distributes the App, handles subscription payments, and provides the private and shared CloudKit databases used for synchronization, acting on its own behalf and under its own privacy policy. We use no advertising networks and no analytics beyond the diagnostics above.

A cloud AI provider you configure yourself is the one recipient for which we cannot give that assurance. It receives the document content you send it under the terms of your own account, authenticated with your own key, over a request that never passes through us. We do not choose it, we hold no agreement with it, and we are therefore not in a position to extend this policy's protections to it or to vouch for how it behaves. That is why cloud processing stays off until you enable it for a specific vault, and why the provider's own terms are worth reading before you do.

8. Retention of Diagnostic Data

Diagnostic events are deleted automatically 30 days after we receive them. We keep nothing else about you, because there is nothing else to keep.

9. Storage Location and International Transfers

Diagnostics are stored on servers in the European Union. Because we are based in Australia, we access them from there, which means the data leaves the EU when we read it. That transfer relies on the European Commission's Standard Contractual Clauses, which form part of our agreement with Sentry.

10. Your Rights

Your documents never reach us, so most of these rights you exercise directly in the App or through your Apple account: you can delete documents, remove cloud providers, export your data, manage participants, leave a shared space, and manage Cella's iCloud access at any time. Deleting a document in Cella synchronizes that deletion to devices that can access it. Stopping a share, removing a participant, or leaving removes access on the affected device's next sync; revocation is best effort and cannot retract copies exported earlier. Deleting the App removes its local data from that device, but synchronized personal documents remain in your private iCloud account and can return if you reinstall Cella. Delete content in Cella before uninstalling if you also want its synchronized copy removed. Keep an encrypted backup from Settings under Backup & Restore for independent recovery; received shared content is excluded from vault backups.

The crash diagnostics described in clause 6 are the only data we hold about you. You may ask us for a copy of them, ask us to correct or delete them, ask us to restrict how we use them, or object to our using them at all. These rights are not conditional on where you live. Write to info@cella-ai.com and we will respond within one month. Because diagnostics carry no contact details, we may need the random installation identifier from Settings to find your reports.

11. Changes to This Policy

We may update this policy from time to time. When we do, we will change the date at the top, and the current version will always be available in the App and on our website.

12. Contact and Complaints

For privacy questions or requests, contact us at info@cella-ai.com. If our response does not resolve the matter, you can complain to the data protection authority for your country.

© 2026 Cella

Built on-device
PrivacyTermsContact