Skip to content
Reflux Diary Get Reflux Diary for free

Privacy Policy

What Reflux Diary stores, where it stores it, and what never leaves your iPhone.

Effective date: 24 August 2026

On this page

  1. Who we are
  2. What stays on your iPhone
  3. What we hold on our servers
  4. Why we use this information
  5. The camera and the AI scan
  6. Barcode lookups
  7. Who receives information
  8. International transfers
  9. How long we keep information
  10. Deleting your account
  11. Your rights
  12. Complaints
  13. What we do not do
  14. Children
  15. United States residents
  16. Changes to this policy
  17. Contact

Summary

Your food and symptom diary stays on your iPhone. We do not receive it and we cannot see it. What we hold is small: your account, your subscription status, and a record of your AI scans. A picture leaves your device only when you ask for an AI scan that uses an AI company, and only after you agree on the permission screen. There are no ads, no analytics, no tracking, and no selling of your information.

This policy covers the Reflux Diary iPhone app and the refluxdiary.com website. Our Terms of Use are at https://refluxdiary.com/terms.

1. Who we are

Reflux Diary is made by Emre Demirel, an individual developer based in Poland ("we", "us"). For the information described in section 3, we are the controller under the EU General Data Protection Regulation (GDPR). You can contact us at contact@refluxdiary.com.

2. What stays on your iPhone

The app keeps your diary on your device. This includes:

  • the meals and foods you record, and how each was prepared;
  • the symptoms you record, with their severity and time;
  • the scores and statuses the app computes from your entries, and their history;
  • your scan and dish history, including products you looked up;
  • your avatar image;
  • any AI-provider API key you add yourself, which is stored in the iPhone Keychain on this device only.

None of this is sent to our servers. We have no copy of it, we cannot see it, and we cannot restore it for you. The patterns and statuses the app shows are computed on your device from your own entries. They are not decisions we make about you.

Anyone who can unlock your iPhone can read your diary. Protecting your device protects your diary.

3. What we hold on our servers

WhatDetails
AccountA random user ID. If you create an account, we also hold your email address (or the email Apple shares through Sign in with Apple, which may be a private relay address) and a display name if you provide one
AI-scan permissionWhether you agreed on the permission screen to AI scanning, recorded per provider
Subscription statusThe plan you bought, its dates and status, the price and currency recorded by the store, and one-time purchase records, mirrored from our subscription provider
AI scan recordsFor each scan that uses an AI company: your user ID, the task type, its cost against your allowance, timestamps, which provider handled it, and the parsed text result of the scan. The result is kept briefly so that a failed request can be retried without charging you twice
Billing housekeepingShort-lived records that de-duplicate subscription events
Support emailWhat you write to us, and the address you write from

You can use the app without an account. The app then runs an anonymous session with a random ID, and we hold no email address for you.

We never see your payment details. Apple processes every purchase.

Information we receive from others

If you use Sign in with Apple, Apple sends us your Apple identifier, the email address Apple shares, and your name if you chose to share it. Apple also tells us that a purchase happened. Our subscription provider sends us your entitlement status and purchase events, keyed to an identifier derived from your user ID.

4. Why we use this information, and our legal basis

What we doLegal basis (GDPR)
Run an anonymous session; create and operate your account; send sign-in codes and password-reset emails; sign you in with AppleContract: providing the app you asked for (Art 6(1)(b))
Check and record your subscription or purchaseContract (Art 6(1)(b)). De-duplication and fraud prevention rest on our legitimate interest in preventing abuse (Art 6(1)(f))
Run an AI scan you request and keep its accounting, including the cached resultContract: the scan is the service you asked for (Art 6(1)(b)). Preventing double-charging rests on our legitimate interest (Art 6(1)(f))
Look up a barcode you scanContract (Art 6(1)(b))
Answer your emailContract where it concerns the service (Art 6(1)(b)); otherwise our legitimate interest in answering you (Art 6(1)(f))
Keep the service secure, enforce our Terms, and establish, exercise or defend legal claimsOur legitimate interest in running the service safely and lawfully (Art 6(1)(f))
Delete your account when you ask; meet other legal dutiesLegal obligation (Art 6(1)(c))

Where we rely on legitimate interest, the interests are the ones named in the table. We have assessed that they do not override your rights. Your diary is not in this table because we do not process it.

5. The camera and the AI scan

The camera is the only system permission the app asks for. If you choose a picture from your photo library instead, only the picture you choose reaches the app. Pictures stay on your device unless you run an AI scan that uses an AI company.

What a scan sends

A scan sends the picture and related food details, for example the text the app reads from a menu or a label, to the AI service that analyses it.

The three scan routes

RouteWhere the picture goesPermission screen
On-deviceThe picture is analysed on your iPhone by Apple's on-device models. Nothing is sent to us or to any AI companyNone. The app shows an information screen instead
Through our serverThe scan goes through our server to one of the AI companies we work with, currently Google and OpenAI. Our server decides which company handles a given scan at the time of the requestYes. The screen always shows the current list of companies
With your own keyThe scan goes to the provider whose API key you added, under your own agreement with that provider. The request passes through our server, which stores neither your key nor your picture. The provider's own terms govern what it does with the picture, including retention and any use for model improvementYes

Before the first scan on a route that sends a picture, the app asks for your permission and names the companies involved. If you decline, nothing is sent, and you can keep recording meals by hand.

What happens to the picture

We do not store it. It passes through our server to the AI company and is not written to our storage. The AI company may keep it for a limited period under its own policy, for example to monitor abuse. The only thing we keep is the parsed text result, briefly, so that a failed request can be retried without charging you twice.

6. Barcode lookups

When you scan a product barcode, the app sends the barcode digits directly from your device to Open Food Facts, a non-profit food database in France. The lookup does not pass through our servers. Open Food Facts receives the digits, your device's IP address, and an identification string that contains the app's name, its version and our contact email. Open Food Facts requires this string from every app. Its own privacy policy governs its logs.

7. Who receives information

We share information only with the companies that make the app work.

WhoRoleWhat reaches them
Our cloud hosting and database provider (United States and Singapore)Hosts accounts, sign-in, subscription records and scan recordsEverything in section 3 except support email. In transit only and never stored: the scan picture and, on the own-key route, your key
The AI companies named in section 5Analyse scans on the server routeThe picture and the scan prompt
Our subscription-management provider (United States)Subscription and entitlement infrastructureAn identifier derived from your user ID, purchase and receipt data, and entitlement status
An email delivery providerSends sign-in codes and password-reset emailsYour email address and the message
AppleApp distribution, Sign in with Apple, purchasesApple acts on its own behalf, under Apple's privacy policy
Open Food FactsBarcode lookups, called directly from your deviceSee section 6
A provider you connect with your own keyAnalyses scans under your own agreement with itThe picture and the scan prompt, sent with your key

The providers that process information for us do so under data-processing agreements and only on our instructions. We have no affiliates, no ad networks and no data brokers, and we sell nothing. Beyond this table, we disclose personal information only where the law requires it, or where it is necessary to establish, exercise or defend legal claims.

8. International transfers

Some of these companies are outside the European Economic Area, including in the United States and Singapore. Where we transfer personal data outside the EEA, we rely on the European Commission's Standard Contractual Clauses in our agreement with the recipient, or on an adequacy decision where one exists. You can ask us for a copy of those clauses. Apple, Open Food Facts and any provider you connect yourself make their own arrangements.

9. How long we keep information

InformationHow long
Your diaryNot ours to keep. It is on your device
Account, AI-scan permission, subscription and purchase records, scan accountingWhile your account exists. Deleted when you delete your account
Anonymous session recordsUntil you ask us to delete them. We may also remove unused sessions
Cached parsed scan resultBriefly, to complete or retry a scan
Sign-in and password-reset codesUntil they expire, shortly after they are issued
Billing housekeeping recordsBriefly, for de-duplication
Your scan pictureNot stored by us
Support emailWhile your request is open, and afterwards for as long as we need it for follow-ups or legal claims

We keep a record for longer only where the law requires it.

10. Deleting your account

You can delete your account inside the app, in Settings. Deletion removes your sign-in identity and every server record listed in section 3: your account, your AI-scan permission, your subscription and purchase records, your scan accounting including cached results, and billing housekeeping.

Deletion does not reach three things:

  • Your diary. It exists only on your device, and deleting the app removes it.
  • The purchase history held by our subscription provider. It holds an identifier derived from your user ID and the dates and status of your purchases. It holds no name, no email address and no diary. We keep it as proof of purchase. You can ask us to have that record erased as well.
  • Apple's own purchase records, which Apple keeps as the merchant under its own policy.

If you use the app without an account, there is no in-app delete control, because there is no account to sign into. Deleting the app removes your diary and the session from your device. To have the server-side session record removed, email us.

Deleting your account, or deleting the app, does not cancel a subscription. Cancel it in your Apple Account settings first.

11. Your rights

Wherever you live, you can ask us to:

  • tell you what information we hold about you, and give you a copy in a usable format;
  • correct it;
  • delete it, in the app or by email;
  • restrict how we use it, or object to what we do under legitimate interest;
  • clear your AI-scan permission, so that the app asks you again before any future scan.

We make no decision about you by automated means that has legal or similarly significant effects.

To exercise a right, write to contact@refluxdiary.com from the email address of your account. We may ask for proof of identity where there is reasonable doubt about who is asking. If you used the app without an account, we may need you to make the request from inside the app, where the session identifies itself. We respond within the time the applicable law allows.

12. Complaints

You can complain about how we handle your information to your data-protection authority. We ask you to write to us first, because most issues can be fixed in one email, but that is a request and not a condition.

13. What we do not do

  • We use no analytics, attribution or crash-reporting SDK in the app.
  • We show no advertising, use no ad identifier and do no tracking. The app never shows the App Tracking Transparency prompt, because there is nothing to track for.
  • We do not sell or share your personal information, for money or for anything else of value. We use no data brokers and no marketing lists.
  • We do not collect your location. The app never asks for it.
  • We do not access your contacts, your microphone or HealthKit.
  • We do not use your pictures or your information for advertising or marketing.

14. Children

Reflux Diary is for people aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has an account, tell us at contact@refluxdiary.com and we will delete it.

15. United States residents

The rights in section 11 apply to you, and exercising them never changes the service you receive. If we refuse a request, you may appeal by writing to contact@refluxdiary.com with the subject line "Privacy appeal". We do not sell personal information, we do not share it for targeted advertising, and we do not profile you in ways that produce legal or similarly significant effects.

Washington and Nevada: consumer health data

To the extent that any information listed in section 3 is "consumer health data" under Washington's My Health My Data Act or Nevada's consumer health data law, this section is our consumer health data privacy policy. The categories we collect are those listed in section 3. We collect them from you, from Apple and from our subscription provider, and only for the purposes in section 4, which is to provide the services you ask for. We share them only with the service providers listed in section 7, who process them on our behalf. We share consumer health data with no other third party and with no affiliate. We do not sell consumer health data and we have never sold it. We do not use geofencing, and the app never collects your location. You may access, correct or delete your information, or withdraw your AI-scan permission, as described in sections 10 and 11. You may appeal a refusal as described above.

16. Changes to this policy

When we change this policy, we will post the new version at https://refluxdiary.com/privacy and update the effective date. If a change is material, for example new information collected, a new recipient or a new purpose, we will tell you in the app before it takes effect.

17. Contact

Emre Demirel
contact@refluxdiary.com

For questions, rights requests or complaints, write to contact@refluxdiary.com. Please do not send details of your symptoms or your health by email. We do not need them to help you.

Reflux Diary

iPhone. Requires iOS 26.

Legal

Privacy Policy Terms of Use

Contact

contact@refluxdiary.com

Reflux Diary is a personal food and symptom diary. It is not a medical device and does not provide medical advice. Talk to a qualified professional about your health.

Food catalogue built on FoodOn, used under CC BY 4.0.

© 2026 Reflux Diary