Privacy Policy
Diaita (“we”, “us”, the “App”) is a meal and macro tracking app. We built it to be privacy-first: your profile, meals, goals, and history stay on your device, and we do not sell your information. You create an account (email + password) so your subscription stays tied to you across reinstalls and new devices — this policy explains exactly what that involves, what else the App handles, and your choices.
1. The short version
- Your profile, goals, and logged meals are stored on your device, and — once you're signed in — also synced to your account via Supabase, so they're restored if you reinstall the App or sign in on a new device.
- Your account (email + password) is handled by our authentication provider, Supabase, and exists to keep your subscription and your data tied to you, not to a device.
- Beyond that, the only other data that leaves your device is a meal photo or text description you choose to analyze, sent for AI processing.
- We do not sell your data, show third-party ads, or track you across other apps.
2. What we collect and how it's used
Your account
- Email and password, used only to create and sign in to your account. Your password is never visible to us — it's handled by Supabase, our authentication provider, using industry-standard secure storage. We use your account's unique ID to keep your subscription status consistent across app reinstalls and new devices.
- We do not use your email to send marketing and do not share it with advertisers.
Your profile, goals, and meals
- Profile you enter during onboarding: name, sex, age, height, weight, goal, target weight, activity level, and diet preference.
- Your logged meals and daily goals.
This information is stored locally on your device using its standard app storage. Once you're signed in, it is also synced to your account via Supabase, so it's restored if you reinstall the App or sign in on a new device — access is restricted to your account by database-level rules, and it is never sold, shared, or used for advertising. Your app appearance/theme setting is not synced; it stays on-device only. Deleting the App removes the on-device copy; deleting your account (see §7) removes the synced copy too.
Sent off your device only when you use an AI feature
- Meal photos and text descriptions. When you scan a meal, ask for meal ideas, or use AI auto-fill, the image and/or text you provide is sent to our backend and forwarded to our AI provider (Anthropic) to estimate calories and macros. We do not store these images or descriptions on our servers; they are processed to generate a response and then discarded. Anthropic processes the request under its own terms and does not use it to train its models via the API.
- Your account's subscription identifier. To verify that AI features are unlocked, the App sends your account's unique ID to our backend, which checks your subscription status with our payments provider, RevenueCat. Because you're signed in, this ID is linked to your account (unlike a fully anonymous device ID) — it is used only to verify your subscription, never sold or shared for advertising.
Handled by Apple and our payments provider
- Subscription and purchase information. Purchases are processed by Apple through the App Store. We never see your payment details. We use RevenueCat to manage subscription status and receive purchase events tied to your account's ID above.
3. Third-party services
We share data only as needed to provide the App's features:
- Supabase — account creation/sign-in, and storage of your synced profile, goals, and meal history. (supabase.com/privacy)
- Anthropic — AI analysis of meal photos/descriptions. (anthropic.com/legal/privacy)
- RevenueCat — subscription management and analytics. (revenuecat.com/privacy)
- Apple — App Store payments and subscriptions. (apple.com/legal/privacy)
- Render — hosts our backend, which processes (but does not store) AI requests. (render.com/privacy)
4. Data retention
- On-device data persists until you delete it in the App or uninstall the App.
- AI requests are processed transiently and are not retained on our servers.
- Your account (email, password) and your synced profile, goals, and meal history are retained by Supabase until you request deletion (see §7) or delete them yourself.
- Subscription records are retained by Apple/RevenueCat per their policies.
5. Security
Data sent off your device is transmitted over encrypted connections (HTTPS). Your password is never stored in plain text — Supabase handles it using industry-standard secure hashing. Your synced profile, goals, and meal history are stored in Supabase under database-level access rules that restrict them to your account only — no other user or app can read them, and they are never sold, shared, or used for advertising.
6. Children's privacy
Diaita is not directed to children under 13 (or the minimum age of digital consent in your region), and we do not knowingly collect personal information from them.
7. Your choices and rights
- Edit or remove your on-device data: update your profile in the App, or delete the App to remove all on-device data.
- Delete your account: email us (below) and we'll delete your account (email and password) and your synced profile, goals, and meal history from Supabase. This does not affect on-device data, which you remove by deleting the App.
- Manage your subscription: through your Apple ID → Subscriptions settings.
- Depending on your location (e.g. EEA/UK/California), you may have rights to access or delete personal data. Your on-device data is already under your direct control; for your account or any other request, contact us below.
8. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by an updated “Effective date” above.
9. Contact
Questions about this policy or your data: