DiaRoute

DiaRoute Privacy Policy

Last updated: 1 August 2026

Draft — pending legal review. Wording may change before public release.

1. Who We Are

DiaRoute ("we," "us," "our") is a food and glucose diary application for people managing diabetes.

The data controller for the personal data described in this policy is:

Mykola Naidenko
Email: info@diaroute.com

Use of the app is also governed by our Terms of Use, available in the app under Settings → About → Terms of Use.

2. Not a Medical Device

DiaRoute is a food and glucose diary intended for informational and record-keeping purposes only. It is not a medical device and does not provide medical advice, diagnosis, or automated treatment decisions.

3. Data We Collect

We process the following categories of personal data. Items marked (health) are special category data under Article 9 GDPR:

  • Food & nutrition logs — meals, carbohydrate/XE values, portions, templates, favorites, recipes, personal food cache (health)
  • Glucose data — entered manually, synced from Dexcom Share, or read from Apple Health / Health Connect (health)
  • Insulin log (health)
  • Treatment parameters — carbohydrate ratios, target glucose ranges (health)
  • Activity & body data from Apple Health / Health Connect, read-only and opt-in — steps, active energy, walking distance, exercise minutes, workouts, sleep incl. sleep stages (a sleep score is computed on your device from them), heart rate, resting heart rate (health)
  • Workout log you type into the app (health)
  • Type 2 data — medications, adherence, weight log (health)
  • Diary notes (health, if health-related)
  • Food photos submitted for AI recognition
  • DiaBot chat transcript and assistant memory (health, if health-related)
  • Profile — optional name, country/region, age confirmation
  • Dexcom credentials — used solely to authenticate with Dexcom
  • Settings & technical — language, theme, font size, units, diabetes type, widget layouts, reminders, glucose source selection, Health connection flag, local caches

We do NOT collect analytics data, advertising identifiers, or any third-party tracking data. DiaRoute contains no ad, analytics, or crash-reporting SDKs and does not track you across apps or websites.

4. Legal Basis

General app functionality (e.g., storing your logs locally): Article 6(1)(b) GDPR — necessary to provide the service you requested.

Health data: Article 9(2)(a) GDPR — your explicit, opt-in consent. Two separate opt-ins exist:

  • Apple Health / Health Connect access — requested via the system permission dialog only after you tap a connect button; revocable anytime in system settings.
  • AI processing — asked before any health-related content is sent to our AI processor (Google Gemini). You may withdraw it anytime in Settings; AI features then become unavailable, the rest of the app keeps working.

5. How We Use Your Data

  • To calculate carbohydrate/XE values and display them to you
  • To let you log meals, glucose, insulin, workouts, and notes
  • To compute on-device statistics (time in range, insights, steps/sleep/stress vs glucose, sleep score) — these run on your device
  • To provide AI food photo recognition and the DiaBot assistant
  • To sync CGM data from Dexcom Share or Apple Health / Health Connect, where connected
  • To generate a doctor report (PDF) on your device; it is shared only when you use the system share sheet
  • To respond to support requests

We do NOT use your data for advertising or profiling.

6. Where Your Data Is Stored

There is no user account and no cloud sync. Your logs are stored locally on your device. We do not hold a copy on our servers.

Dexcom credentials are stored in your device’s encrypted secure storage (iOS Keychain / Android Keystore). Data read from Apple Health / Health Connect is cached locally on the device only.

On Android, the system’s automatic cloud backup is deliberately switched OFF for this app (allowBackup="false" plus data extraction rules covering cloud backup and device-to-device transfer). Otherwise an unencrypted copy of your glucose readings, meals and insulin log would be uploaded to Google Drive and would survive "Delete My Data" — meaning the delete button would not keep its promise. The trade-off is that a device backup will not restore your data: use the manual export described in section 7a instead.

7. Third Parties

We do not sell your data. We share data only as follows:

GOOGLE GEMINI (AI). When you use AI features, the following is sent to Google’s Gemini API through our backend proxy (a Cloudflare Worker holding the API key server-side): the food photo you submit; your DiaBot message plus context from your glucose readings and diary, and — if Health is connected — compact activity and sleep summaries (daily step totals, sleep duration, average glucose change after workouts; raw Health samples are never sent); aggregated data for the weekly review. Sent only after your explicit consent. Google may process this data outside the EEA, including in the US.

DEXCOM. If you connect Dexcom Share, glucose is retrieved directly from Dexcom using your credentials, device-to-Dexcom over HTTPS. We never receive or store your credentials or readings on our servers. This is an unofficial Share integration; Dexcom processes your data under its own policy.

APPLE HEALTH / HEALTH CONNECT. Read-only access after the system permission dialog. Processed and cached on your device; the app never writes there and never transmits raw Health data off the device — only the compact AI summary above, with your separate AI consent. Revoke access anytime in system settings.

NUTRITION DATABASES. USDA FoodData Central — your search text is sent via our backend proxy (USDA does not receive your device’s IP). Open Food Facts — the food name or barcode is sent directly from your device to this EU-based open database, which therefore receives your device’s IP. Only the food name or barcode is sent — never glucose, insulin, or diary content.

SYSTEM SPEECH RECOGNITION. If you use the optional microphone button (food search, DiaBot chat), your speech is converted to text by the operating system’s speech recognition service (Apple on iOS, Google on Android). Depending on OS version and language, this may happen on-device or on Apple/Google servers under their own policies. The app receives only the resulting text in the input field — audio never reaches our backend or Google Gemini. Permission is requested on first use and can be revoked in system settings.

No other third parties: no analytics, ads, tracking, or crash-reporting services.

7.7 Exporting and Moving Your Data

Settings → Data → Export data writes every record listed in section 3 into a single JSON file and hands it to the system share sheet. Nothing is uploaded by us: where the file goes — mail, a messenger, a cloud drive — is entirely your choice, and once it leaves the app it is outside our control and outside this policy. This is how you exercise your right to data portability (Article 20 GDPR), and it replaces the Android system backup disabled in section 6.

Import replaces your existing data entirely rather than merging it, and asks for explicit confirmation showing the record counts found in the file. Merging two diaries without stable record identifiers risks duplicating insulin entries, and a duplicated dose in a doctor report is not a cosmetic problem.

Dexcom credentials are never written to the export file — they stay in the device keychain. Reconnect Dexcom manually after an import.

7.8 Demo Data

Settings contains an optional "Demo data" switch, off by default. Turning it on generates a sample fortnight of glucose readings, meals, insulin entries and workouts on your device so that the screens, statistics and doctor report can be evaluated without a connected sensor and without weeks of history.

This data is synthetic. It is produced entirely on your device, describes no real person, is never transmitted anywhere, and can only be added while the app is empty, so it never mixes with your own records. Every generated record is tagged, so switching the option off removes exactly those records and nothing else. While it is on, a permanent "DEMO DATA" marker is shown on every screen and cannot be dismissed.

No personal data is processed by this feature.

8. International Transfers

Some data leaves the EU/EEA: Google Gemini (AI processing, may include health data) and USDA FoodData Central (food name queries via proxy). Open Food Facts is EU-based. For non-EEA transfers we rely on the applicable safeguards (e.g., Standard Contractual Clauses). You may request details at info@diaroute.com.

9. Retention & Deletion

All of your data lives on your device; we hold no copy.

Settings → Delete My Data erases, in one action and irreversibly, everything the app has stored about you: glucose readings; food, insulin, and workout diary; ratios and targets; templates, favorites, recipes, personal food cache; Type 2 medications, adherence, weight log; DiaBot memory and transcript; AI consent; name, country, age confirmation; Dexcom credentials (from Keychain/Keystore); glucose-source selection and Health connection flag with cached summaries; reminders, layouts, search history, caches. Only language, theme, and font size are kept.

Sign Out is a full reset including interface preferences.

Data inside Apple Health / Health Connect is not ours to delete — the app only ever held read permission. Content previously sent to Google or Dexcom is subject to their retention policies; we never held a copy, so deletion requests must go to them — we will help you identify the right channel.

10. Your Rights

Under GDPR you have the right to access, rectify, erase (in-app via Delete My Data), restrict, port, object, and to withdraw consent at any time (AI — in Settings; Health — in system settings). You may lodge a complaint with your supervisory authority, incl. Slovenia’s Information Commissioner.

Because your data lives only on your device, access and portability are exercised through the app itself: Settings → Data → Export data produces a complete machine-readable JSON copy (Article 20), and the PDF doctor report produces a human-readable one. We cannot retrieve your data for you — we never hold it.

To exercise any right, contact info@diaroute.com.

11. Children

DiaRoute is intended for users aged 18 and older; the app requires an explicit 18+ confirmation during onboarding. We do not knowingly collect data from minors.

12. Security

  • Third-party API keys (Gemini, USDA) live server-side in our Cloudflare Worker proxy and are never shipped in the app
  • Dexcom credentials are stored in iOS Keychain / Android Keystore
  • All network communication uses HTTPS
  • Health and CGM access is read-only — the app writes nothing to external health stores

No system is 100% secure; we take technical measures appropriate to the sensitivity of health data.

13. Changes & Contact

We may update this policy; material changes affecting health-data processing will require renewed consent where legally required.

Data controller: Mykola Naidenko. Email: info@diaroute.com. Supervisory authority: Information Commissioner of the Republic of Slovenia.

For questions about the app itself — bugs, ideas, how something works — use the support address in Settings → Support instead; it reaches us faster than the legal contact above.