Privacy policy

This policy explains what information the food diary stores, why it needs it and when that information may leave your device.

Effective from 29 September 2026.

Your diary is stored on your device. Analytics and diagnostics each require your consent. The publisher does not receive entries, photos or reports created in the app.

Who this policy applies to

This policy covers the Food diary app on iOS and Android and its use without an account or login. The app is intended for adults and is not designed for children.

The app is published by Sushi Corner Stare Miasto Sp. z o. o., ul. Św. Wincentego 45/19, 50-251 Wrocław, Poland, trading as UMAMI GRP. For privacy and support enquiries, contact hi@dietlogapp.com.

Data stored only on your device is not collected or viewed by the publisher. For messages sent to support, the publisher named above is the controller of the sender's data and the message content. Please do not include health entries or diary backups unless necessary.

Website visit statistics

The dietlogapp.com website uses Vercel Web Analytics to measure anonymous, aggregate visit statistics. The service may record visit time, the page visited, the referring page, approximate location, and device, operating system and browser type.

Website statistics do not include entries or other data stored in the app. Vercel Web Analytics does not use third-party cookies or give the publisher IP addresses or data that identifies a specific person.

Website language and preference cookie

A URL containing /pl or /en determines the page language. On URLs without a language, we use your previous choice or the languages sent by your browser. If no supported language matches, we use English. We do not use IP location for this.

Only clicking the PL/EN switch creates the session cookie dietlog_language, containing pl or en. Its only purpose is to remember your chosen language in this browser. It contains no person identifier and is not used for advertising or analytics. It is limited to the current domain, sent over HTTPS, and has no persistent expiry date. Your browser manages the session, including any session restoration.

You can change your choice with the switch or delete the cookie in your browser settings. Direct language URLs still work when cookies are blocked. We do not transfer preferences or consent from dietlog.pl to dietlogapp.com. Choosing a language does not give consent to app analytics or diagnostics.

Optional app usage analytics

With separate consent, disabled by default, we may collect limited information about which general diary screens and features are used and whether an action succeeds. This is used only to assess usage and improve features. Processing is based on voluntary consent. The app also works without it.

Analytics does not include diary content, meal names, blood glucose, symptoms, wellbeing, photos, notes, or the dates and times of recorded events. We do not use IDFA, IDFV, device or installation identifiers. After consent, the app creates a random identifier for the current session only. It stays in memory, is not saved on the device, and disappears when the app starts fresh or consent is withdrawn. It only links general events within one session and is not linked to a user.

The data processor is PostHog, Inc. through PostHog Cloud EU. Events include only an action name from a fixed list, limited action parameters, the app version and build number, and the platform. PostHog does not receive IP addresses, GeoIP is disabled, and no person profile is created. Data is not used for advertising, tracking across apps or websites, or combining with other customers' data. Events are retained for no longer than 12 months.

You can refuse or withdraw consent at any time in Settings. Withdrawal immediately stops further sending, cancels transmission in progress, and removes the local queue and current session identifier. The app deliberately does not retain earlier session identifiers, so it cannot later find a particular person's or device's history in the analytics dataset.

Optional technical diagnostics

With separate consent, disabled by default, the diary may send limited technical information about crashes, freezes and application failures to Sentry in the EU region. This helps identify errors and improve stability. Processing is based on voluntary consent, and the app remains fully usable without it.

Diagnostics may include the app version and build number, platform, limited technical environment information, a fixed operation phase or result code, and redacted code locations needed for symbolication and finding the error.

Diagnostics does not include diary content, health data, meal names, blood glucose, symptoms, wellbeing, photos, notes, or the dates and times of recorded events. We do not create a user profile or a persistent device or installation identifier. IP addresses and geolocation are not stored.

The data processor is Functional Software, Inc., the operator of Sentry in the EU region. Raw diagnostic data is retained for no longer than 30 days.

You can refuse or withdraw consent at any time in Settings. Withdrawal immediately stops further transmission and removes the local diagnostics queue. Diagnostics consent is independent of consent to improve the app, and neither limits diary features.

What data the app stores

The app's private storage may contain:

  • your first and last name, provided to label the diary and report;
  • meals, descriptions and photos, hunger levels and symptoms;
  • sleep, activity, mood, notes and optional blood glucose readings;
  • settings, custom suggestion lists and unsaved drafts;
  • PDF reports and manual backups, if you choose to create them.

This information is used only to keep your diary, retrieve earlier entries and create the report or backup you choose. The app has no advertising, profiling, remote synchronisation or tracking across apps. The optional analytics and diagnostics described above do not receive this information.

Camera and photo selection

The camera is used only when you choose to add a photo to a meal. You can also choose an existing photo with the system picker. The app does not scan your whole library or save photos it takes back to the gallery.

Large photos are optimised before permanent storage. The diary keeps an optimised master and does not retain an additional original copy. A smaller, reproducible working version may be created for reports.

Denying access to the camera or photos does not stop you saving an entry without a photo. The diary does not request location, contacts, microphone, calendar or data from Health Connect or Apple Health.

Reports, backups and sharing

PDF reports and manual data backups are created on your device. A file leaves the app's private storage only after an explicit action: you choose to save or share, then select a location or recipient in your phone's system dialog.

Storage from then on depends on the chosen app, service or recipient and is subject to their privacy rules. Manual backups are not encrypted and may contain health data and photos, so keep them somewhere you trust.

How long data stays on your device

Data stays in the app until you delete it. In Settings → Your data you can choose Delete all data; this removes your profile, settings, suggestion lists, drafts, entries and photos.

Uninstalling the app removes its active private storage. Automatic Android system backup is disabled. On iOS, app data may be included in device or iCloud system backups if enabled in Apple settings. The publisher cannot access those backups; you control their retention and deletion in your Apple account settings.

To keep your entries before changing phones or uninstalling, independently of system settings, create a manual backup first.

How data is protected

The app stores data in the private area assigned by your phone's operating system and does not expose a network service. Writes involving several items are performed transactionally, and a backup is checked in full before replacing current data.

No storage method completely removes the risk of access by someone who can use an unlocked or modified device. Protect your phone with a passcode or biometrics, and carefully choose report recipients and backup storage.

Your rights, questions and policy changes

Where the GDPR applies, you may request access, correction, deletion, restriction, portability and independently withdraw each consent. Withdrawal does not affect the lawfulness of earlier processing. Because analytics and diagnostics do not retain a persistent person, device or installation identifier, finding a specific person's earlier events may be technically impossible.

Send privacy questions or requests to hi@dietlogapp.com. If you believe data is processed unlawfully, you may complain to the President of the Polish Personal Data Protection Office (UODO).

The current policy will always be available at this address. If the app's behaviour or libraries change, the policy and store disclosures will be reviewed again.

Go to help