Ligero
Ligero

Privacy policy

Effective August 18, 2026 · replaces all earlier versions

Rewritten again, and again in the same direction: wider. The previous version said you could use the app without an account and that the journal never left your device. Both were true when they were written; neither is true now. Signing in with Apple is required to open the app at all, and your journal is kept as a private copy on our server so that it reaches your second phone. Patching the old text would have hidden exactly the part worth knowing, so this is a new one.

1. The journal — private, and now synced

An account is required. Sign in with Apple is the only way in, the app asks for it before anything else, and there is no way to skip it.

Your journal — the tastings you write, your humidors, your lots and their resting times — is written first to your own device, and it opens and works there with no connection at all. A copy of those same three things is kept on our server against your account so that a second iPhone shows the same journal.

That copy is private. It is returned only to a device holding your own session token: there is no request in this app that hands somebody else your journal, no screen that displays one, and nothing from it reaches the feed, your public profile or this website. It is a second copy for you, not a source for anyone else.

2. Your account

There is one account, and one way to get it: Sign in with Apple. There is no password anywhere in the system, because we never create one.

What Apple gives us: a stable identifier for you that is unique to this app, and an email address — which is a private relay address if you chose “Hide My Email”, and we are fine with that. Apple passes your name exactly once, at your first sign-in, and only if you allow it.

What you enter yourself: first name, last name, a profile photo, and your region — the country and, if you like, the city. Never coordinates, never precise location, never anything read from your device’s GPS. Optionally: a short bio and how long you have been smoking.

Name, photo and region are required to have an account. Faceless accounts are exactly how a public place rots, and anyone can look you up by name. Your region is there because cigar culture is regional and “who is nearby” is a real reason to follow someone.

3. What gets published, and when

Nothing is published automatically. Not once, not ever. A tasting becomes public only after you open it, tap share and confirm that you want it published.

When you do, it becomes public: visible in the app to anyone with an account, whether or not they follow you. The following goes to the server:

  • the cigar — brand, line, vitola, origin, wrapper;
  • your score, both as a normalised 0–1 value and as the label you see (“9 / 10”);
  • your verdict in your own words, and whether you would buy it again;
  • the date of the entry;
  • the comments you write under anyone’s review, and the like or dislike you leave on one.

The picture on a published review is the brand emblem from the shared catalogue (section 6), not a photograph of yours: your own shot of the band is not published, not stored on our server, and since version 2.0 not even written to your phone’s disk.

Your profile is public: your name, photo, region, bio, the tastings you published, your follower and following counts, and your shelf — which cigars you keep and how long they have been resting. Anyone with an account can open it and can follow you without asking. Following is not approved and cannot be refused; if you would rather not be read by someone in particular, block them.

What remains entirely yours is the decision to publish. An entry is yours alone until you send it, and you can send none at all: reading the feed and publishing nothing is a normal way to use the app.

This changed in version 1.2, and it changed in one direction — wider. Until then clubs were closed circles, a tasting reached only the members of the clubs you chose, and this section said there was no global feed and no public profile page. Both now exist. Everything published before the change was published into a club; it is public now.

Nothing on this website is generated from anyone’s tastings — the feed lives in the app only.

4. What never becomes public

Regardless of any setting, at any time:

  • your unpublished entries — synced for you, readable by nobody else, and never shown to another account;
  • what you paid — there is no price field in the app any more and no column for one on the server, so the value of a collection is not something that can leak from here at all;
  • where you are — the region on your profile is the country and, optionally, the city you typed in yourself; the app never reads your device’s location;
  • your photographs — see section 3.

None of this is a default that can be flipped: there is no request that carries it and no field waiting for it on the server.

5. What the server stores

  • Account: the Apple identifier, your email address, first and last name, profile photo, region, bio, years smoking, and the date you signed up.
  • Sessions: a login token for your device, so that you stay signed in.
  • Follows: who you follow and who follows you, and when each connection started.
  • Published tastings: exactly the fields listed in section 3, including your comments and reactions.
  • Shelf: the cigars and resting times from your humidor — this is the public part, shown on your profile.
  • Your synced journal: your tastings, your lots and your humidors, with their notes, scores, dates and resting times. This is the private copy from section 1: it exists so your own second device can read it, and it is returned to nobody else.
  • Devices and notifications: the push token of each device you have signed in on, and which of the three kinds of notification you want — comments, reactions, new followers.
  • Moderation: the people you have blocked, and any report you have filed or that names you.

Notifications are sent only when somebody reacts to you: a comment on your review, a like on it, or a new follower. The app asks for permission on the feed rather than at launch, and iOS Settings → Notifications turns them off at any time.

Photos — your profile picture and any photo attached to a published tasting — are stored as files on the server, not in the database. Profile pictures are resized to at most 800×800. They are served only to people entitled to see them under the rules above.

Servers are rented from Hetzner and located in Germany. Data is not transferred outside the EU except where a service listed in section 8 operates internationally.

6. AI sommelier

The sommelier is not a bonus feature you can ignore: photographing a band is how an entry starts, and typing a cigar name by hand no longer exists in the app. The free plan carries five requests a week, shared across all three features below. When you use one, only what that feature needs is sent to OpenRouter, which routes the request to an AI model provider:

  • Band scan: the photo you take of the cigar band — first to read it, then, if the catalogue has no picture for that cigar yet, to draw a clean one.
  • What to smoke tonight: your answers to the short prompt (new or familiar, how much time, a drink, strength), the cigars currently in your humidor, and how you rated the ones you have already smoked.
  • Similar cigars: the cigar you ask about and the cigars in your humidor.

These requests carry no name, no email and no account identifier — not even when you are signed in. Prices are never included. Photos are sent for that single request and are not stored by us. See OpenRouter’s privacy policy.

Only the band itself is sent, not the whole photo: the camera crops to the frame you aim with, and a picture chosen from your library goes through the same crop step before anything leaves the device. The cropped band is sent for that single request and is not stored by us.

Each cigar in the catalogue gets one clean picture of its band. It is drawn from your photo by an image model, not the photo itself: a picture of how that brand’s band looks, without the tear, stain or glare your particular one had. Your photograph is never stored on our server or shown to anyone — only the drawn picture is, and it carries no name.

7. Analytics

To see which features are used and which are dead weight, the app reports anonymous usage events through Amplitude — for example, which screen was opened or whether a purchase completed. These events carry a random identifier and are not linked to your name, your email or your account. They never contain the content of a tasting, a cigar, a price, or anything you published. No advertising identifiers, no tracking across other companies’ apps or websites, and no sale or sharing of data for advertising. See Amplitude’s privacy policy.

8. Purchases

Purchases and subscriptions are processed entirely by Apple through the App Store; we never see your payment details. For receipt validation the app uses RevenueCat, which receives an anonymous receipt token and nothing else. See RevenueCat’s privacy policy.

9. Everyone who touches your data

  • Apple — sign-in and payments. Policy.
  • Hetzner (Germany) — the server this site and the app’s feed run on.
  • OpenRouter — only for the AI features described in section 6.
  • Amplitude — anonymous usage events.
  • RevenueCat — anonymous receipt validation.

That is the entire list. We do not sell data, we do not share it for advertising, and we do not run advertising in this app.

10. Deleting your account

You can delete your account from inside the app. Deletion is immediate and physical, not a hidden flag: your profile, your photo, every tasting and comment you published, your follows in both directions, your shelf entries, your block list, your device tokens and the synced copy of your journal are removed from the database and the files are removed from disk. Nothing of yours stays in the feed, and nothing of your journal stays on our server, after your account is gone.

What deletion does not touch is the journal on the phone in your hand: that copy is yours and it stays exactly where it is. Delete the app to remove that too.

If you cannot reach the app, write to efsh49@gmail.com from the address linked to your account and we will delete it for you.

11. Your rights

If you are in the EU or the UK, the GDPR gives you the right to access the data we hold about you, to correct it, to have it erased, to receive a copy in a portable form, and to object to processing. Everywhere else we apply the same rules anyway, because maintaining two standards is not worth the trouble. Write to efsh49@gmail.com and you will get an answer within 30 days, usually much sooner.

Our legal basis for processing your account data is the contract between us — without it there is no feed and no profile to speak of. For analytics it is our legitimate interest in knowing which parts of the app are worth keeping.

12. Children

Ligero is rated 17+ and is not directed at children. We do not knowingly create accounts for anyone under that age; if we learn of one, we delete it and everything on it.

13. Changes to this policy

If this policy changes, the new version is published at this address with a new effective date. Material changes — anything that widens what we collect or who sees it — will also be shown in the app before they take effect.

14. Contact

Ligero is developed and published by Yevhenii Rubanov, who is also the data controller. Questions, requests or complaints: efsh49@gmail.com.