PLEN
← Back to homepage

Privacy Policy for the Diabi app

Version: 1.1
Effective date: 25 August 2026

1. General information

This Policy describes data processing in the Diabi mobile app and on diabi.app.

The data controller is:
inn.so Marta Stasiak
ul. Katowicka 71/2
61-131 Poznań, Poland
Tax ID (NIP): 7752585567
e-mail: team@diabi.app.

Diabi is an educational app. It is not a medical device and does not diagnose, treat or calculate insulin doses.

2. Data that may be processed

Depending on the features used, the App may process:

  • meal descriptions, ingredients, carbohydrate estimates, meal history and favorites;
  • physical activity information and activity duration;
  • an optional meal photo used for online analysis;
  • app settings, language, consents, educational progress and trial status;
  • pseudonymous technical identifiers used for online analysis, abuse prevention and subscriptions;
  • technical purchase data such as product ID, plan, purchase token, subscription status and entitlement expiry.

The App does not require a Diabi account or an e-mail address for sign-in.

3. Health-related data

Meal descriptions, activity and diabetes-related content may in some circumstances constitute health data. For Online Analysis, data is transmitted only after the User gives separate consent.

Users should not enter another person’s data without an appropriate legal basis.

4. Data stored locally

Meal analysis history, favorites, settings and preferences, educational progress, consents, trial data and local cache may be stored primarily on the device.

Local data is protected by Android or iOS app-data isolation mechanisms. Diabi does not claim additional encryption of its own local files beyond operating-system protections.

Local data can be removed through available App functions, by clearing app data or by uninstalling the App, subject to data independently retained by the app store or subscription backend.

5. Offline analysis

If Online Analysis is disabled or unavailable, the App may use a local model running on the device. This does not require sending the meal description or photo to the online analysis server and may be less accurate or less detailed.

6. Online AI analysis

Online Analysis is optional and requires separate consent in the App.

In the current flow, the following may be sent to the intermediary server:

  • meal description;
  • physical activity information;
  • activity duration, if provided;
  • an optional meal photo;
  • language/locale information required to prepare the response;
  • a pseudonymous technical request or installation identifier.

The current online analysis flow does not send blood glucose or an insulin profile to the AI model.

Data is first sent to an intermediary server based on Cloudflare Worker technology and then, as needed to generate an educational response, to the AI technology provider OpenAI.

AI output is an estimate and may contain errors. It is not a medical decision and does not constitute automated decision-making producing legal effects for the User.

7. AI provider

Online Analysis uses the OpenAI API. Data is transmitted only to the extent needed to generate a response and provide technical security.

Processing and retention by the provider are governed by the applicable service terms, account configuration and OpenAI security rules. The Controller does not promise a shorter provider-side deletion period than those rules provide.

8. Cloudflare Worker and analysis cache

Cloudflare Worker acts as an intermediary server, protects provider API keys, applies security controls and rate limits, and may use a technical response cache.

Cloudflare infrastructure may receive the Online Analysis data described above and technical transmission data such as IP address and connection metadata. Log scope and retention depend on service configuration and provider rules.

9. Supabase and subscription backend

Supabase is used for server-side subscription entitlement verification.

The backend may process the platform, app package ID, product ID, base plan, purchase token, subscription state, entitlement expiry, purchase acknowledgement state and a pseudonymous technical User identifier.

This data is used to determine whether paid access is active, restore entitlements and prevent abuse.

10. Payments and Google Play

Subscription payments are processed by the app store, currently Google Play on Android. Diabi does not receive full payment-card details.

The store may process payment, transaction and Google account data under its own terms. Diabi’s backend receives technical data required to verify the purchase.

11. What the App does not do

  • it does not create Diabi accounts requiring sign-in;
  • it does not send blood glucose or an insulin profile to the current Online AI Analysis;
  • it does not calculate or recommend insulin doses;
  • it does not save meal photos in the App history;
  • the supplied website version does not use advertising or analytics scripts such as Google Analytics or Meta Pixel.

12. The diabi.app website

diabi.app is an informational website providing App information, legal documents and contact details. The supplied website version does not contain its own account forms or advertising/analytics scripts.

The hosting server may process standard connection data such as IP address, date, time and requested resource according to the hosting configuration.

13. Purposes and legal bases

Data may be processed to provide App and Subscription features, perform Online Analysis requested by the User, ensure security, handle complaints, process billing and comply with legal obligations.

Depending on the situation, the legal basis may be performance of a contract (Article 6(1)(b) GDPR), consent (Article 6(1)(a)), explicit consent for health data voluntarily sent to Online Analysis (Article 9(2)(a)), a legal obligation (Article 6(1)(c)) or the Controller’s legitimate interests such as security and legal claims (Article 6(1)(f)).

14. Recipients and international transfers

Data may be disclosed to providers technically necessary for the service, including Cloudflare, OpenAI, Supabase and Google for payments and purchase verification, and to hosting or legal-service providers where needed.

Some providers may process data outside the European Economic Area. Where applicable, transfer mechanisms required by the GDPR and the relevant provider terms are used.

15. Retention

Local data is stored until the User deletes it, clears App data or uninstalls the App, unless a feature removes it earlier.

Subscription-backend data is kept for as long as needed to verify entitlement, handle transactions, security, complaints and legal obligations. Technical data held by external providers is retained under their configuration and rules.

16. Data deletion

Information about deleting data is available on the Data deletion page. For backend data requests, contact team@diabi.app.

17. User rights

Where provided by the GDPR, Users may request access, rectification, erasure, restriction, portability, object to processing and withdraw consent at any time without affecting the lawfulness of prior processing.

Users may also lodge a complaint with the competent data-protection authority.

18. Security

We use measures intended to limit access to technical keys and data, including an intermediary backend, pseudonymous identifiers and server-side purchase verification. No system can completely eliminate risk.

19. Minors

Minors should use the App in accordance with applicable law and, where required, with the consent or supervision of a parent or legal guardian.

20. Changes and contact

This Policy may be updated when features, providers or laws change. The current version is published at diabi.app.

Privacy contact: team@diabi.app.