CeliacTrack

Privacy Policy

Last updated: 2026-05-12 · Effective date: at app launch

CeliacTrack ("we," "our," or "the app") is a mobile application that helps Canadians with celiac disease track gluten-free food purchases and generate Medical Expense Tax Credit (METC) summaries for the Canada Revenue Agency (CRA). This policy explains what data we collect, why, where it lives, and what control you have over it.

This policy is written to comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws (including British Columbia's Personal Information Protection Act).

Contents

  1. Who we are
  2. What we collect — and why
  3. How we use it
  4. Where data is stored
  5. Third-party services
  6. How long we keep it
  7. Your rights
  8. Children
  9. Security
  10. Changes
  11. Contact

1. Who we are

CeliacTrack is operated by Thomas Mazalek of Coldstream, British Columbia, Canada. Contact us at hello@celiactrack.ca with any privacy questions.

2. What we collect — and why

We collect only what the app needs to do its job. Specifically:

Account data

Tax-credit calculation data

You enter or capture the following so the app can compute your credit estimate:

Usage data

Payment data

We do not see or store credit-card information. All payments are processed by Apple (App Store) or Google (Play Store) and handed to RevenueCat for subscription state management. RevenueCat receives an anonymous identifier and your purchase status only.

3. How we use it

We use your information only to:

We do not sell your data. We do not use it to train AI models. We do not show advertising.

4. Where data is stored

DataStored byRegion
Account, profile, receipts, comparables, calculation resultsSupabase Inc.United States (West)
Receipt + comparable photosSupabase StorageUnited States (West)
Subscription stateRevenueCatUnited States
Email delivery (password reset)Supabase Auth → SendGridUnited States

Storage in the US is a routine cross-border transfer for cloud infrastructure. The processors above are bound by data-processing agreements consistent with PIPEDA's accountability requirements.

5. Third-party services

When you tap "Look up product" or "Suggest a comparable", the product description text and store name (e.g., "Glutino Pretzels, Costco") are sent to Anthropic, Inc. ("Claude AI") which performs a web search and returns structured product information. No personally identifying information is sent — Anthropic receives only the non-personal text snippet. Anthropic does not use this data to train its models. Results are cached so the same product isn't re-queried for every user.

Other third parties:

6. How long we keep it

Your data is kept as long as your account is active. When you delete your account from inside the app (Profile → Delete account), we:

Inactive accounts (no sign-in for 24 months) may be flagged for deletion after a notice email.

7. Your rights

Under PIPEDA you have the right to:

8. Children

CeliacTrack is intended for adults filing Canadian tax returns. We do not knowingly collect data from anyone under 18. If we learn we have collected data from a minor we will delete it.

9. Security

We cannot guarantee absolute security but we follow industry-standard practices. If we discover a breach affecting your data, we will notify you and the Privacy Commissioner of Canada per PIPEDA's breach notification requirements.

10. Changes to this policy

If we make material changes to this policy we will update the "Last updated" date and notify you inside the app at next sign-in. Continued use after that notice constitutes acceptance.

11. Contact

Thomas Mazalek
494 Middleton Close, Coldstream, BC V1B 4E7, Canada
Email: hello@celiactrack.ca

For privacy concerns specifically, write to privacy@celiactrack.ca.