1. Who We Are
DiaRoute ("we," "us," "our") is a food and glucose diary application for people managing diabetes.
The data controller for the personal data described in this policy is:
Mykola Naidenko
Email: info@diaroute.com
Use of the app is also governed by our Terms of Use, available in the app under Settings → About → Terms of Use.
2. Not a Medical Device
DiaRoute is a food and glucose diary intended for informational and record-keeping purposes only. It is not a medical device and does not provide medical advice, diagnosis, or automated treatment decisions. It has not been reviewed, cleared, or approved by any medical device regulator, and it carries no CE marking as a medical device.
3. Data We Collect
We process the following categories of personal data. Items marked (health) are special category data under Article 9 GDPR:
- Food & nutrition logs — meals, carbohydrate/XE values, portions, templates, favorites, recipes, personal food cache (health)
- Glucose data — entered manually, synced from Dexcom Share or Abbott LibreLinkUp (FreeStyle Libre), or read from Apple Health / Health Connect (health)
- Insulin log (health)
- Treatment parameters — carbohydrate ratios, target glucose ranges (health)
- Activity & body data from Apple Health / Health Connect, read-only and opt-in — steps, active energy, walking distance, exercise minutes, workouts, sleep incl. sleep stages (a sleep score is computed on your device from them), heart rate, resting heart rate (health)
- Workout log you type into the app (health)
- Type 2 data — medications, adherence, weight log (health)
- Diary notes (health, if health-related)
- Food photos submitted for AI recognition
- DiaBot chat transcript and assistant memory (health, if health-related)
- Profile — optional name, country/region, age confirmation
- Dexcom credentials — used solely to authenticate with Dexcom
- LibreLinkUp (LibreView) credentials — used solely to authenticate with Abbott’s LibreLinkUp service; the session token and the patient identifier it returns are kept on your device
- Settings & technical — language, theme, font size, units, diabetes type, widget layouts, reminders, glucose source selection, Health connection flag, local caches
- App integrity attestation — an identifier generated for this app installation and an attestation issued by the operating system, sent with requests to our proxy to prove the request comes from a genuine copy of the app (not health data, not linked to your identity)
We do NOT collect analytics data, advertising identifiers, or any third-party tracking data. DiaRoute contains no ad or analytics SDKs and does not track you across apps or websites. Crash reports and problem reports are described in section 7; they carry no glucose readings, no diary content and nothing that identifies you.
4. Legal Basis
General app functionality (e.g., storing your logs locally): Article 6(1)(b) GDPR — necessary to provide the service you requested.
Health data: Article 9(2)(a) GDPR — your explicit, opt-in consent. Two separate opt-ins exist:
- Apple Health / Health Connect access — requested via the system permission dialog only after you tap a connect button; revocable anytime in system settings.
- AI processing — asked before any health-related content is sent to our AI processor (Google Gemini). You may withdraw it anytime in Settings; AI features then become unavailable, the rest of the app keeps working.
5. How We Use Your Data
- To calculate carbohydrate/XE values and display them to you
- To let you log meals, glucose, insulin, workouts, and notes
- To compute on-device statistics (time in range, insights, steps/sleep/stress vs glucose, sleep score) — these run on your device
- To provide AI food photo recognition and the DiaBot assistant
- To sync CGM data from Dexcom Share, Abbott LibreLinkUp, or Apple Health / Health Connect, where connected
- To generate a doctor report (PDF) on your device; it is shared only when you use the system share sheet
- To respond to support requests
We do NOT use your data for advertising or profiling.
6. Where Your Data Is Stored
There is no user account and no cloud sync. Your logs are stored locally on your device. We do not hold a copy on our servers.
Dexcom and LibreLinkUp credentials — and the LibreLinkUp session token and patient identifier — are stored in your device’s encrypted secure storage (iOS Keychain / Android Keystore). Data read from Apple Health / Health Connect is cached locally on the device only.
On Android, the system’s automatic cloud backup is deliberately switched OFF for this app (allowBackup="false" plus data extraction rules covering cloud backup and device-to-device transfer). Otherwise an unencrypted copy of your glucose readings, meals and insulin log would be uploaded to Google Drive and would survive "Delete My Data" — meaning the delete button would not keep its promise. The trade-off is that a device backup will not restore your data: use the manual export described in section 7a instead.
7. Third Parties
We do not sell your data. We share data only as follows:
GOOGLE GEMINI (AI). When you use AI features, the following is sent to Google’s Gemini API through our backend proxy (a Cloudflare Worker holding the API key server-side): the food photo you submit; your DiaBot message plus context from your glucose readings and diary, and — if Health is connected — compact activity and sleep summaries (daily step totals, sleep duration, average glucose change after workouts; raw Health samples are never sent); aggregated data for the weekly review. Sent only after your explicit consent. Google may process this data outside the EEA, including in the US.
DEXCOM. If you connect Dexcom Share, you sign in with your own Dexcom account and glucose is retrieved directly from Dexcom, device-to-Dexcom over HTTPS. Your credentials stay in your device’s secure storage; we never receive or store your credentials or readings on our servers. DiaRoute is an independent app and is not affiliated with Dexcom, Inc.; Dexcom processes your data under its own policy.
ABBOTT (LIBRELINKUP / LIBREVIEW). If you connect FreeStyle Libre, you sign in with your own LibreLinkUp account: your email and password are sent directly from your device to Abbott’s LibreView servers over HTTPS to obtain a session token, and your glucose readings are then retrieved from there. Your credentials stay in your device’s secure storage; we never receive or store your credentials or readings on our servers. DiaRoute is an independent app and is not affiliated with Abbott; Abbott processes your data under its own policy. The regional server that serves your account (for example EU) is determined by Abbott at sign-in.
APPLE HEALTH / HEALTH CONNECT. Read-only access after the system permission dialog. Processed and cached on your device; the app never writes there and never transmits raw Health data off the device — only the compact AI summary above, with your separate AI consent. Revoke access anytime in system settings.
NUTRITION DATABASES. USDA FoodData Central — your search text is sent via our backend proxy (USDA does not receive your device’s IP). Open Food Facts — the food name or barcode is sent directly from your device to this EU-based open database, which therefore receives your device’s IP. Only the food name or barcode is sent — never glucose, insulin, or diary content.
SYSTEM SPEECH RECOGNITION. If you use the optional microphone button (food search, DiaBot chat), your speech is converted to text by the operating system’s speech recognition service (Apple on iOS, Google on Android). Depending on OS version and language, this may happen on-device or on Apple/Google servers under their own policies. The app receives only the resulting text in the input field — audio never reaches our backend or Google Gemini. Permission is requested on first use and can be revoked in system settings.
GOOGLE — APP INTEGRITY (FIREBASE APP CHECK). Every request the app makes to our backend proxy carries a short-lived attestation token proving it comes from a genuine, unmodified installation of DiaRoute on a real device. The attestation is produced by the operating system — Apple App Attest on iOS, Google Play Integrity on Android — and verified through Google’s Firebase App Check service. What is sent: an identifier generated for this installation, the attestation itself, and your device’s IP address, as with any network request. No health data, diary content, food query, account identifier, or advertising identifier is attached, and the token does not identify you as a person. Its only purpose is to stop others from using our proxy — and our AI and nutrition quotas — from outside the app. Google processes this on our behalf and may do so outside the EEA; Apple and Google also handle the underlying device attestation under their own policies. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in protecting the service from abuse. No Article 9 data is involved.
SENTRY (crash reporting and problem reports). When the app crashes, hits an internal error, or you send a report using “Report a problem” in Settings, a technical report is sent to Sentry, operated by Functional Software, Inc., and stored in the European Union (Germany).
The report contains the error message, stack trace, device model, operating system version, app version and update version. So that a fault can be reproduced, it also states the settings you are running under: interface language, glucose and carbohydrate units, whether the app is in type 1 or type 2 mode, the diabetes type you selected, which glucose source is connected (Dexcom, FreeStyle Libre, Apple Health / Health Connect, or none), whether demo mode is on, and whether you have given AI consent. If you type a description, that description is sent as well. The report is anonymous by default; it carries an email address only if you switch on the option asking us to tell you when the problem is fixed and type an address yourself, and we then use it for nothing but answering that report.
It does NOT contain glucose values, insulin doses, food names, diary entries, DiaBot messages, or search queries: these are removed on your device before the report is sent, including from any text you type yourself. No account, name or advertising identifier is attached — nor any email address unless you asked for a reply as described above — and no screenshot or screen recording is ever taken. Reports are retained for 90 days and are used solely to find and fix defects.
Legal basis: Article 6(1)(f) GDPR — our legitimate interest in a safe, working application. The report carries no readings, no diary content and nothing that identifies you, but it does state your diabetes type and whether you use a glucose sensor.
WEBSITE FEEDBACK FORM (diaroute.com/feedback). This one concerns our website, not the app. If you send feedback through that form, what you submit is stored by us and emailed to us: the rating and description you write, the screen and app version you name, whichever known issue you tag, and — only if you choose to fill them in — your name and email address. A screenshot is included only if you attach one yourself.
Storage is Cloudflare KV (Cloudflare, Inc.) and delivery is Resend (Resend, Inc.); both act as processors on our behalf and may process data outside the EEA. Entries are deleted automatically 180 days after they are sent, or sooner if you ask us at info@diaroute.com. Name and email are optional: without them the report is anonymous, but we cannot reply to you.
Please do not put glucose values, insulin doses or other health details into this form, and check a screenshot before attaching it. Unlike the in-app “Report a problem”, the website form does not strip such content for you — it stores what you send. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in fixing the defects people report.
No other third parties: no analytics, ads, or tracking services.
7.7 Exporting and Moving Your Data
Settings → Data → Export data writes every record listed in section 3 into a single JSON file and hands it to the system share sheet. Nothing is uploaded by us: where the file goes — mail, a messenger, a cloud drive — is entirely your choice, and once it leaves the app it is outside our control and outside this policy. This is how you exercise your right to data portability (Article 20 GDPR), and it replaces the Android system backup disabled in section 6.
Import replaces your existing data entirely rather than merging it, and asks for explicit confirmation showing the record counts found in the file. Merging two diaries without stable record identifiers risks duplicating insulin entries, and a duplicated dose in a doctor report is not a cosmetic problem.
Dexcom and LibreLinkUp credentials are never written to the export file — they stay in the device keychain. Reconnect your CGM manually after an import.
7.8 Demo Data
Settings contains an optional "Demo data" switch, off by default. Turning it on generates a sample fortnight of glucose readings, meals, insulin entries and workouts on your device so that the screens, statistics and doctor report can be evaluated without a connected sensor and without weeks of history.
This data is synthetic. It is produced entirely on your device, describes no real person, is never transmitted anywhere, and can only be added while the app is empty, so it never mixes with your own records. Every generated record is tagged, so switching the option off removes exactly those records and nothing else. While it is on, a permanent "DEMO DATA" marker is shown on every screen and cannot be dismissed.
No personal data is processed by this feature.
7.9 The Website and the Beta Programme
Everything above describes the app, where your diary lives on your device and we hold no copy. This section is about something different: the two forms on diaroute.com. They are the only places where you hand data to us directly, and what they collect is simply what you typed into them — nothing is gathered in the background, and neither form can see anything inside the app.
PROBLEM REPORT (diaroute.com/feedback). Described in section 7 under "Website feedback form": your rating and description, the screen and app version you name, the known issue you tag, a screenshot only if you attach one, and your name and email only if you fill them in.
BETA GROUP SIGN-UP (the form on the same page). If you ask for a place in the beta group, we store the answers you give: your name, email address, whether you use an iPhone or an Android phone, your phone model and OS version, which sensor you use, your diabetes type, your glucose and carbohydrate units, your country, what you tell us annoys you about logging food today, and where you heard about DiaRoute. On Android the email address is your Google account, because that is the only account a Play test invitation can be attached to.
We use these answers for two things and nothing else: to choose who joins the beta group, and to write to you about the beta — the invitation, the short things to try, and the weekly note. We do not use them for advertising, we do not profile you, and we do not pass them to anyone beyond the processors named below.
YOUR DIABETES TYPE IS HEALTH DATA. The sign-up form asks for it, and under Article 9 GDPR that makes it a special category of personal data, which may not be processed on the ordinary "legitimate interest" basis used elsewhere in this policy. That is why the form carries an explicit, unticked consent box and will not submit until you tick it: your consent under Article 9(2)(a) GDPR is the legal basis, you give it deliberately or not at all, and you may withdraw it at any time by writing to info@diaroute.com — withdrawal does not affect what was lawful before it. The processing of the remaining answers rests on Article 6(1)(b) GDPR, the steps taken at your request before entering the beta.
Both forms are stored in Cloudflare KV (Cloudflare, Inc.) and delivered by email through Resend (Resend, Inc.); both act as processors on our behalf and may process data outside the EEA. Entries are deleted automatically 180 days after they are sent, and sooner if you ask us at info@diaroute.com. Asking us to delete your sign-up also takes you out of the beta group, since we would no longer have the address to write to.
Please do not put glucose values, insulin doses or diary content into either form. Unlike the in-app "Report a problem", the website forms do not strip such content for you — they store what you send. The website sets no analytics, advertising or tracking cookies, and loads no third-party scripts other than the Cloudflare Turnstile anti-spam check on the forms themselves.
8. International Transfers
Some data leaves the EU/EEA: Google Gemini (AI processing, may include health data), Google Firebase App Check (app integrity tokens, no health data) and USDA FoodData Central (food name queries via proxy). Open Food Facts is EU-based. For non-EEA transfers we rely on the applicable safeguards (e.g., Standard Contractual Clauses). You may request details at info@diaroute.com.
9. Retention & Deletion
All of your data lives on your device; we hold no copy.
Settings → Delete My Data erases, in one action and irreversibly, everything the app has stored about you: glucose readings; food, insulin, and workout diary; ratios and targets; templates, favorites, recipes, personal food cache; Type 2 medications, adherence, weight log; DiaBot memory and transcript; AI consent; name, country, age confirmation; Dexcom and LibreLinkUp credentials, including the LibreLinkUp session token and patient identifier (from Keychain/Keystore); glucose-source selection and Health connection flag with cached summaries; reminders, layouts, search history, caches. Only language, theme, and font size are kept.
Sign Out is a full reset including interface preferences.
Data inside Apple Health / Health Connect is not ours to delete — the app only ever held read permission. Content previously sent to Google, Dexcom, or Abbott is subject to their retention policies; we never held a copy, so deletion requests must go to them — we will help you identify the right channel.
10. Your Rights
Under GDPR you have the right to access, rectify, erase (in-app via Delete My Data), restrict, port, object, and to withdraw consent at any time (AI — in Settings; Health — in system settings). You may lodge a complaint with your supervisory authority, incl. Slovenia’s Information Commissioner.
Because your data lives only on your device, access and portability are exercised through the app itself: Settings → Data → Export data produces a complete machine-readable JSON copy (Article 20), and the PDF doctor report produces a human-readable one. We cannot retrieve your data for you — we never hold it.
To exercise any right, contact info@diaroute.com.
11. Children
DiaRoute is intended for users aged 18 and older; the app requires an explicit 18+ confirmation during onboarding. We do not knowingly collect data from minors.
12. Security
- Third-party API keys (Gemini, USDA) live server-side in our Cloudflare Worker proxy and are never shipped in the app
- Dexcom and LibreLinkUp credentials are stored in iOS Keychain / Android Keystore, never in ordinary app storage, and are never written to crash reports
- Requests to our proxy carry a Firebase App Check attestation (App Attest / Play Integrity), so traffic that does not come from a genuine app installation can be rejected
- All network communication uses HTTPS
- Health and CGM access is read-only — the app writes nothing to external health stores
No system is 100% secure; we take technical measures appropriate to the sensitivity of health data.
13. Changes & Contact
We may update this policy; material changes affecting health-data processing will require renewed consent where legally required.
Data controller: Mykola Naidenko. Email: info@diaroute.com. Supervisory authority: Information Commissioner of the Republic of Slovenia.
For questions about the app itself — bugs, ideas, how something works — use the support address in Settings → Support instead; it reaches us faster than the legal contact above.