Privacy Policy for the Diabi app
Version: 1.0
Effective date: 1 July 2026
1. General information
This Privacy Policy describes how data is processed in the Diabi mobile app and on the diabi.app website.
The data controller is:
inn.so Marta Stasiak
ul. Katowicka 71/2
61-131 Poznań
Poland
Tax ID / NIP: 7752585567
Contact email: team@diabi.app
For privacy and data protection matters, contact us at: team@diabi.app.
Diabi is an educational app for people who want to better understand carbohydrate counting, carbohydrate exchanges and the impact of meals and activity on everyday decisions related to diabetes.
Diabi is not a medical device. The app is not intended to diagnose, treat or independently determine therapy. Results shown in the app are educational, estimated and supportive only. They do not replace consultation with a physician, diabetologist, dietitian or individual medical advice.
2. What data may be processed in the app
The app may process data entered by the user or generated while using the app.
This may include in particular:
-
meal-related data:
- meal description,
- meal ingredients,
- estimated amount of carbohydrates or carbohydrate exchanges,
- favorite meals,
- history of saved meals;
-
glucose and diabetes profile data:
- glucose level / blood glucose,
- target glucose level,
- insulin ratio,
- correction factor,
- device type, such as pen or pump,
- information about insulin,
- other data entered in the user profile;
-
analysis context data:
- physical activity,
- duration of activity,
- notes entered by the user, such as stress, illness, alcohol, menstruation or other remarks;
-
technical data and settings:
- selected app language,
- selected app background,
- user consents,
- trial status,
- subscription status,
- technical (pseudonymous) identifiers used for online analysis or subscriptions;
-
payment and subscription-related data:
- product identifier,
- subscription plan,
- purchase token,
- subscription status,
- entitlement expiry dates.
The app does not require creating a user account. We do not process a user’s email address for login purposes because Diabi has no account or login system.
3. Health data
Some data processed in the app may be considered health-related data. This applies in particular to blood glucose, diabetes profile data, insulin information, activity, stress, illness, alcohol, meal history and educational results related to diabetes.
Health data is a special category of personal data. For this reason, Diabi processes it carefully and only to the extent necessary for the app to function.
The basis for processing health data when using the app is the user’s explicit action of entering such data into the app and — in the case of online analysis — the user’s consent to send data for online analysis.
The user should not enter data of other people into the app unless they have an appropriate basis and consent from that person.
4. Data stored locally on the device
A large part of the data is processed locally on the user’s device.
Data that may be stored locally includes in particular:
- user profile,
- meal and analysis history,
- favorite meals,
- local analysis cache,
- language and appearance settings,
- user consents,
- trial data,
- subscription data,
- educational progress,
- technical (pseudonymous) identifiers.
Local data is stored in the app’s storage, in app files or in local system app settings.
Data stored locally on the device is protected by system-level app data isolation mechanisms, commonly referred to as sandboxing, and by Android or iOS security mechanisms, such as access control for app data and device storage protection.
Diabi currently does not apply additional encryption to its own local files beyond the mechanisms provided by the operating system. The user should protect the device with a passcode, password, biometrics or another available security method.
Local data can be deleted by uninstalling the app or by deleting app data in Android or iOS system settings. Some data may also be deleted using functions available in the app, such as deleting history or favorite meals, if a given app version provides such functionality.
5. Offline analysis
If the user does not consent to online analysis or disables online analysis in settings, the app may use offline analysis performed on the device.
Offline analysis does not require sending the meal description, glucose level, activity or notes to the online analysis server. Offline analysis may be less accurate than online analysis.
6. Online AI analysis
Online AI analysis is optional.
If the user consents to online analysis, the app may send the following data to our intermediary server:
- meal description,
- glucose level / blood glucose,
- physical activity,
- duration of activity,
- notes entered by the user,
- app language,
- technical meal key,
- technical (pseudonymous) app identifier.
The technical identifier is pseudonymous — it does not contain a name, surname or email address, but it allows technical requests to be linked for the purposes of rate limiting, caching and abuse prevention. It is not used to identify the user by name.
This data may relate to health.
In the current online analysis flow, data is first sent to the intermediary server based on Cloudflare Worker technology and then — in order to generate an educational response — to the AI technology provider: OpenAI.
For data of users from the European Economic Area and Switzerland, processing by OpenAI takes place in accordance with the applicable OpenAI terms, in particular with the involvement of OpenAI Ireland Limited.
In the current flow, the mobile app does not send data directly to OpenAI. The data is sent to the intermediary server, which forwards it to OpenAI in order to perform online analysis.
In the current online analysis flow, the user’s insulin profile is not sent in the online analysis request body. The profile may be used locally on the device to prepare the educational result.
Processing data using AI algorithms in the Diabi app does not constitute automated decision-making within the meaning of Article 22 GDPR. The app does not make medical, therapeutic, legal or financial decisions on behalf of the user. The result is for informational and educational purposes only, and the final decision on how to interpret the result and what to do next is always made by the user or the person caring for the user, based on their own knowledge and medical advice.
The app does not perform profiling that would produce legal effects concerning the user or similarly significantly affect the user.
Disabling online analysis causes the app to stop sending data for online analysis and to use offline analysis on the device. After online analysis is disabled, the app removes the local online analysis token and local online analysis cache, provided that the app version supports such clearing.
7. AI providers and data retention
To prepare online analysis, the app uses an external AI technology provider: OpenAI.
Data transferred to OpenAI is used to prepare an educational response. It is not used to create a user account or to identify the user by first name, last name or email address, because the app does not use user accounts.
According to the current OpenAI documentation, data sent through the API is not used by default to train or improve OpenAI models, unless the controller explicitly enables such use or provides data through a feature intended to share it with OpenAI.
Data retention rules applied by OpenAI may result from that provider’s terms of service, security rules and technical logs. In the case of the OpenAI API, the provider may retain input data, output data and metadata for a limited period in order to provide the service, ensure security and prevent abuse, unless other terms apply to a given account or service.
We cannot guarantee that technical requests, security logs or data necessary to prevent abuse will be deleted immediately after the analysis is completed, because this also depends on the policies and infrastructure of OpenAI and other technical providers.
8. Cloudflare Worker
The app uses an intermediary server based on Cloudflare Worker technology.
This server is used to handle online AI analysis, limit direct access from the app to API keys and forward requests to the AI provider.
Cloudflare Worker may receive the data described in the “Online AI analysis” section, as well as technical transmission data, such as IP address or data resulting from the internet connection. The scope and retention period of Cloudflare technical logs may depend on the Cloudflare service configuration and the provider’s own policies.
9. Supabase and subscription backend
Supabase may be used to operate the subscription backend and verify Premium access.
In connection with subscription handling, the following data may be sent to the backend in particular:
- platform, such as Android or iOS,
- product identifier,
- plan identifier,
- purchase identifier,
- purchase token,
- purchase verification data,
- technical (pseudonymous) app identifier,
- app package identifier,
- request date.
The backend may transfer data to Google Play or Apple App Store in order to verify the validity of a purchase or subscription, depending on the platform.
Technical data related to the subscription is stored for the time necessary to handle the active subscription, restore purchases, process complaints, prevent abuse and defend against claims.
Billing and transaction data may be stored for the period required by tax regulations and limitation periods for claims, generally up to 5 years from the end of the calendar year in which the relevant tax payment deadline expired, unless a longer period is required by applicable law.
10. Payments and subscriptions
Payments and subscriptions are handled by the app store, in particular Google Play or Apple App Store, depending on the platform.
Diabi does not process full payment card details. Payment data is handled by the app store operator.
The app and backend may process technical purchase data required to check whether the subscription is active, such as purchase token, product identifier, plan and subscription status.
Rules for payments, subscription cancellation and refunds may also result from the terms of Google Play or Apple App Store.
11. Microphone and speech recognition
The app may use the microphone if the user uses the meal description dictation feature.
The microphone is used only to recognize speech and insert the recognized text into the meal description field.
The Diabi app does not save audio files and does not store voice recordings. Only text recognized from speech may be stored in the app if the user uses this feature.
Speech recognition may be performed by the Android or iOS system service. Whether speech recognition is performed locally on the device or using system services of the operating system provider depends on the settings and operation of Android or iOS.
12. What the app does not do
The Diabi app:
- does not have user accounts or login,
- does not require an email address to use the app,
- does not display advertisements,
- does not use the advertising ID,
- does not use Firebase Analytics, Google Analytics, Crashlytics, Sentry, AdMob or Meta SDK,
- does not use location,
- does not use contacts,
- does not use the camera,
- does not save meal photos,
- does not save audio recordings,
- does not sell user data to advertisers.
13. The diabi.app website
The diabi.app website may be used to present information about the app, the Privacy Policy, the Terms and contact details.
The website server may process standard technical data resulting from an internet connection, such as IP address, date and time of connection, browser type, requested page address or technical data stored in server logs.
This data is used for technical purposes, security, website maintenance and error diagnosis.
14. Purposes of data processing
Data may be processed for the following purposes:
- enabling use of the app;
- storing the user profile on the device;
- estimating carbohydrates, carbohydrate exchanges and preparing educational results;
- maintaining local meal history;
- saving favorite meals;
- handling app settings;
- handling user consents;
- enabling online AI analysis if the user gives consent;
- enabling offline analysis;
- handling the trial period;
- handling subscriptions and Premium access;
- handling complaints and user contact;
- ensuring technical security of the app and services;
- fulfilling the controller’s legal obligations.
15. Legal bases for processing
Depending on the type of data and processing purpose, the legal basis may be:
- Article 6(1)(b) GDPR — performance of a contract or taking steps prior to entering into a contract, to the extent necessary for app operation, subscription handling and service provision;
- Article 6(1)(a) GDPR — user consent, in particular for optional online AI analysis;
- Article 9(2)(a) GDPR — explicit consent of the user to process health data, to the extent the user enters such data into the app and consents to its online analysis;
- Article 6(1)(c) GDPR — legal obligation of the controller, for example regarding accounting or legal obligations;
- Article 6(1)(f) GDPR — legitimate interest of the controller, for example ensuring security, preventing abuse and establishing, pursuing or defending claims.
The user may withdraw consent to online analysis at any time in the app settings. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
16. Data recipients
Data may be transferred to the following categories of recipients:
- technical infrastructure and hosting providers,
- Cloudflare — for the operation of the intermediary server and transmission security,
- AI technology providers, in particular OpenAI — for online AI analysis,
- Supabase — for the subscription backend or backend functions,
- Google Play — for payment and subscription handling on Android,
- Apple App Store — for payment and subscription handling on iOS,
- Android or iOS system speech recognition providers, if the user uses dictation,
- entities providing legal, accounting or technical services to the controller, if necessary.
We do not transfer user data to advertisers because the app does not contain advertisements.
17. Transfers outside the European Economic Area
Some technical service providers may process data outside the European Economic Area.
This applies in particular to cloud infrastructure providers, AI technology providers, app stores and Android or iOS system services.
If data is transferred outside the European Economic Area, it is done using appropriate legal mechanisms provided by the GDPR, where required, such as standard contractual clauses, adequacy decisions or other permitted mechanisms.
18. Data retention period
Local data is stored on the user’s device for as long as the app is installed, unless the user deletes app data, uninstalls the app or uses available data deletion functions.
History, profile, favorites and cache data do not have an automatic deletion period, unless a given app version introduces such a mechanism.
Online analysis data may be stored locally in the app cache to speed up operation and reduce the number of requests.
Technical data processed by external providers such as Cloudflare, OpenAI, Supabase, Google or Apple may be stored for periods resulting from their technical, security, billing, logging, abuse prevention or legal obligation rules.
Technical data related to the subscription is stored for the time necessary to handle the active subscription, restore purchases, process complaints, prevent abuse and defend against claims.
Billing and transaction data may be stored for the period required by tax regulations and limitation periods for claims, generally up to 5 years from the end of the calendar year in which the relevant tax payment deadline expired, unless a longer period is required by applicable law.
Contact data processed in correspondence with the user is stored for the period necessary to handle the matter and then for the limitation period of possible claims or the period required by law.
19. Data deletion
The user may delete local data by uninstalling the app or deleting app data in Android or iOS system settings.
If a given app version provides functions for deleting selected data, the user may also delete certain data from within the app, such as history or favorite meals.
Disabling online analysis in the app settings stops sending new data for online analysis. It may also remove the local online analysis token and local online analysis cache if the app version supports such a mechanism.
Not all technical data related to the subscription may be deleted immediately, because some of it is needed to handle Premium access, billing, security or to demonstrate proper operation of the subscription.
To request data deletion or obtain information about data processing, contact the controller at: team@diabi.app.
20. User rights
Under the GDPR, the user has rights including:
- right of access to data,
- right to rectification,
- right to erasure,
- right to restriction of processing,
- right to data portability,
- right to object to processing,
- right to withdraw consent,
- right to lodge a complaint with a supervisory authority.
In Poland, the supervisory authority is the President of the Personal Data Protection Office.
Data-related requests may be sent to: team@diabi.app.
Due to the lack of user accounts and login, in some cases identifying a specific user’s data on the controller’s side may be limited or impossible if the data is stored only locally on the user’s device or is linked only to a technical (pseudonymous) identifier.
21. Data security
We use technical and organizational measures intended to protect user data.
Communication with online services uses encrypted HTTPS connections where a given online service is used.
Locally stored data is protected by system-level app data isolation mechanisms, commonly referred to as sandboxing, and by Android or iOS security mechanisms. These mechanisms limit access by other apps to Diabi data stored in the app’s own storage area.
The app currently does not apply additional encryption to its own local files beyond the mechanisms provided by the operating system. The user should protect their device with a passcode, password, biometrics or other available security mechanisms.
Please remember that no method of data storage or transmission gives a full guarantee of security.
22. Children and minors
The Diabi app is not directed to children under the age of 13.
Minors may use the app only with the consent and under the supervision of a parent or legal guardian.
If health data of a minor is entered into the app, the parent or legal guardian should ensure that use of the app is consistent with the child’s best interests and medical advice.
Diabi does not have user accounts and does not allow the controller to knowingly create profiles of children. Data entered into the app is generally stored locally on the device, and if online analysis is enabled it may be transmitted in accordance with this Privacy Policy.
For matters concerning the data of a minor, a parent or legal guardian may contact the controller at: team@diabi.app.
23. Changes to this Privacy Policy
This Privacy Policy may be updated, in particular in the event of changes to the app, service providers, technical changes, legal changes or changes in how data is processed.
The current version of the Privacy Policy is available on diabi.app.
We may inform users about significant changes in the app or on the website.
24. Contact
For matters related to privacy, personal data or app operation, contact the controller:
inn.so Marta Stasiak
ul. Katowicka 71/2
61-131 Poznań
Poland
Tax ID / NIP: 7752585567
Email: team@diabi.app