Privacy Policy
What Reflux Diary stores, where it stores it, and what never leaves your iPhone.
Effective date: 24 August 2026
Summary
Your food and symptom diary stays on your iPhone. We do not receive it and we cannot see it. What we hold is small: your account, your subscription status, and a record of your AI scans. A picture leaves your device only when you ask for an AI scan that uses an AI company, and only after you agree on the permission screen. There are no ads, no analytics, no tracking, and no selling of your information.
This policy covers the Reflux Diary iPhone app and the refluxdiary.com website. Our Terms of Use are at https://refluxdiary.com/terms.
1. Who we are
Reflux Diary is made by Emre Demirel, an individual developer based in Poland ("we", "us"). For the information described in section 3, we are the controller under the EU General Data Protection Regulation (GDPR). You can contact us at contact@refluxdiary.com.
2. What stays on your iPhone
The app keeps your diary on your device. This includes:
- the meals and foods you record, and how each was prepared;
- the symptoms you record, with their severity and time;
- the scores and statuses the app computes from your entries, and their history;
- your scan and dish history, including products you looked up;
- your avatar image;
- any AI-provider API key you add yourself, which is stored in the iPhone Keychain on this device only.
None of this is sent to our servers. We have no copy of it, we cannot see it, and we cannot restore it for you. The patterns and statuses the app shows are computed on your device from your own entries. They are not decisions we make about you.
Anyone who can unlock your iPhone can read your diary. Protecting your device protects your diary.
3. What we hold on our servers
| What | Details |
|---|---|
| Account | A random user ID. If you create an account, we also hold your email address (or the email Apple shares through Sign in with Apple, which may be a private relay address) and a display name if you provide one |
| AI-scan permission | Whether you agreed on the permission screen to AI scanning, recorded per provider |
| Subscription status | The plan you bought, its dates and status, the price and currency recorded by the store, and one-time purchase records, mirrored from our subscription provider |
| AI scan records | For each scan that uses an AI company: your user ID, the task type, its cost against your allowance, timestamps, which provider handled it, and the parsed text result of the scan. The result is kept briefly so that a failed request can be retried without charging you twice |
| Billing housekeeping | Short-lived records that de-duplicate subscription events |
| Support email | What you write to us, and the address you write from |
You can use the app without an account. The app then runs an anonymous session with a random ID, and we hold no email address for you.
We never see your payment details. Apple processes every purchase.
Information we receive from others
If you use Sign in with Apple, Apple sends us your Apple identifier, the email address Apple shares, and your name if you chose to share it. Apple also tells us that a purchase happened. Our subscription provider sends us your entitlement status and purchase events, keyed to an identifier derived from your user ID.
4. Why we use this information, and our legal basis
| What we do | Legal basis (GDPR) |
|---|---|
| Run an anonymous session; create and operate your account; send sign-in codes and password-reset emails; sign you in with Apple | Contract: providing the app you asked for (Art 6(1)(b)) |
| Check and record your subscription or purchase | Contract (Art 6(1)(b)). De-duplication and fraud prevention rest on our legitimate interest in preventing abuse (Art 6(1)(f)) |
| Run an AI scan you request and keep its accounting, including the cached result | Contract: the scan is the service you asked for (Art 6(1)(b)). Preventing double-charging rests on our legitimate interest (Art 6(1)(f)) |
| Look up a barcode you scan | Contract (Art 6(1)(b)) |
| Answer your email | Contract where it concerns the service (Art 6(1)(b)); otherwise our legitimate interest in answering you (Art 6(1)(f)) |
| Keep the service secure, enforce our Terms, and establish, exercise or defend legal claims | Our legitimate interest in running the service safely and lawfully (Art 6(1)(f)) |
| Delete your account when you ask; meet other legal duties | Legal obligation (Art 6(1)(c)) |
Where we rely on legitimate interest, the interests are the ones named in the table. We have assessed that they do not override your rights. Your diary is not in this table because we do not process it.
5. The camera and the AI scan
The camera is the only system permission the app asks for. If you choose a picture from your photo library instead, only the picture you choose reaches the app. Pictures stay on your device unless you run an AI scan that uses an AI company.
What a scan sends
A scan sends the picture and related food details, for example the text the app reads from a menu or a label, to the AI service that analyses it.
The three scan routes
| Route | Where the picture goes | Permission screen |
|---|---|---|
| On-device | The picture is analysed on your iPhone by Apple's on-device models. Nothing is sent to us or to any AI company | None. The app shows an information screen instead |
| Through our server | The scan goes through our server to one of the AI companies we work with, currently Google and OpenAI. Our server decides which company handles a given scan at the time of the request | Yes. The screen always shows the current list of companies |
| With your own key | The scan goes to the provider whose API key you added, under your own agreement with that provider. The request passes through our server, which stores neither your key nor your picture. The provider's own terms govern what it does with the picture, including retention and any use for model improvement | Yes |
Before the first scan on a route that sends a picture, the app asks for your permission and names the companies involved. If you decline, nothing is sent, and you can keep recording meals by hand.
What happens to the picture
We do not store it. It passes through our server to the AI company and is not written to our storage. The AI company may keep it for a limited period under its own policy, for example to monitor abuse. The only thing we keep is the parsed text result, briefly, so that a failed request can be retried without charging you twice.
6. Barcode lookups
When you scan a product barcode, the app sends the barcode digits directly from your device to Open Food Facts, a non-profit food database in France. The lookup does not pass through our servers. Open Food Facts receives the digits, your device's IP address, and an identification string that contains the app's name, its version and our contact email. Open Food Facts requires this string from every app. Its own privacy policy governs its logs.
7. Who receives information
We share information only with the companies that make the app work.
| Who | Role | What reaches them |
|---|---|---|
| Our cloud hosting and database provider (United States and Singapore) | Hosts accounts, sign-in, subscription records and scan records | Everything in section 3 except support email. In transit only and never stored: the scan picture and, on the own-key route, your key |
| The AI companies named in section 5 | Analyse scans on the server route | The picture and the scan prompt |
| Our subscription-management provider (United States) | Subscription and entitlement infrastructure | An identifier derived from your user ID, purchase and receipt data, and entitlement status |
| An email delivery provider | Sends sign-in codes and password-reset emails | Your email address and the message |
| Apple | App distribution, Sign in with Apple, purchases | Apple acts on its own behalf, under Apple's privacy policy |
| Open Food Facts | Barcode lookups, called directly from your device | See section 6 |
| A provider you connect with your own key | Analyses scans under your own agreement with it | The picture and the scan prompt, sent with your key |
The providers that process information for us do so under data-processing agreements and only on our instructions. We have no affiliates, no ad networks and no data brokers, and we sell nothing. Beyond this table, we disclose personal information only where the law requires it, or where it is necessary to establish, exercise or defend legal claims.
8. International transfers
Some of these companies are outside the European Economic Area, including in the United States and Singapore. Where we transfer personal data outside the EEA, we rely on the European Commission's Standard Contractual Clauses in our agreement with the recipient, or on an adequacy decision where one exists. You can ask us for a copy of those clauses. Apple, Open Food Facts and any provider you connect yourself make their own arrangements.
9. How long we keep information
| Information | How long |
|---|---|
| Your diary | Not ours to keep. It is on your device |
| Account, AI-scan permission, subscription and purchase records, scan accounting | While your account exists. Deleted when you delete your account |
| Anonymous session records | Until you ask us to delete them. We may also remove unused sessions |
| Cached parsed scan result | Briefly, to complete or retry a scan |
| Sign-in and password-reset codes | Until they expire, shortly after they are issued |
| Billing housekeeping records | Briefly, for de-duplication |
| Your scan picture | Not stored by us |
| Support email | While your request is open, and afterwards for as long as we need it for follow-ups or legal claims |
We keep a record for longer only where the law requires it.
10. Deleting your account
You can delete your account inside the app, in Settings. Deletion removes your sign-in identity and every server record listed in section 3: your account, your AI-scan permission, your subscription and purchase records, your scan accounting including cached results, and billing housekeeping.
Deletion does not reach three things:
- Your diary. It exists only on your device, and deleting the app removes it.
- The purchase history held by our subscription provider. It holds an identifier derived from your user ID and the dates and status of your purchases. It holds no name, no email address and no diary. We keep it as proof of purchase. You can ask us to have that record erased as well.
- Apple's own purchase records, which Apple keeps as the merchant under its own policy.
If you use the app without an account, there is no in-app delete control, because there is no account to sign into. Deleting the app removes your diary and the session from your device. To have the server-side session record removed, email us.
Deleting your account, or deleting the app, does not cancel a subscription. Cancel it in your Apple Account settings first.
11. Your rights
Wherever you live, you can ask us to:
- tell you what information we hold about you, and give you a copy in a usable format;
- correct it;
- delete it, in the app or by email;
- restrict how we use it, or object to what we do under legitimate interest;
- clear your AI-scan permission, so that the app asks you again before any future scan.
We make no decision about you by automated means that has legal or similarly significant effects.
To exercise a right, write to contact@refluxdiary.com from the email address of your account. We may ask for proof of identity where there is reasonable doubt about who is asking. If you used the app without an account, we may need you to make the request from inside the app, where the session identifies itself. We respond within the time the applicable law allows.
12. Complaints
You can complain about how we handle your information to your data-protection authority. We ask you to write to us first, because most issues can be fixed in one email, but that is a request and not a condition.
13. What we do not do
- We use no analytics, attribution or crash-reporting SDK in the app.
- We show no advertising, use no ad identifier and do no tracking. The app never shows the App Tracking Transparency prompt, because there is nothing to track for.
- We do not sell or share your personal information, for money or for anything else of value. We use no data brokers and no marketing lists.
- We do not collect your location. The app never asks for it.
- We do not access your contacts, your microphone or HealthKit.
- We do not use your pictures or your information for advertising or marketing.
14. Children
Reflux Diary is for people aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has an account, tell us at contact@refluxdiary.com and we will delete it.
15. United States residents
The rights in section 11 apply to you, and exercising them never changes the service you receive. If we refuse a request, you may appeal by writing to contact@refluxdiary.com with the subject line "Privacy appeal". We do not sell personal information, we do not share it for targeted advertising, and we do not profile you in ways that produce legal or similarly significant effects.
Washington and Nevada: consumer health data
To the extent that any information listed in section 3 is "consumer health data" under Washington's My Health My Data Act or Nevada's consumer health data law, this section is our consumer health data privacy policy. The categories we collect are those listed in section 3. We collect them from you, from Apple and from our subscription provider, and only for the purposes in section 4, which is to provide the services you ask for. We share them only with the service providers listed in section 7, who process them on our behalf. We share consumer health data with no other third party and with no affiliate. We do not sell consumer health data and we have never sold it. We do not use geofencing, and the app never collects your location. You may access, correct or delete your information, or withdraw your AI-scan permission, as described in sections 10 and 11. You may appeal a refusal as described above.
16. Changes to this policy
When we change this policy, we will post the new version at https://refluxdiary.com/privacy and update the effective date. If a change is material, for example new information collected, a new recipient or a new purpose, we will tell you in the app before it takes effect.
17. Contact
Emre Demirel
contact@refluxdiary.com
For questions, rights requests or complaints, write to contact@refluxdiary.com. Please do not send details of your symptoms or your health by email. We do not need them to help you.