DiabScale.AI Privacy Policy
Effective Date: August 22, 2026
This Privacy Policy describes how we collect, use, disclose, and protect your personal data when you use the DiabScale mobile application and the server-side services it relies on (the “Platform”). It is published at https://diabscale.ai/privacy-policy/.
Processing related to your use of the website at https://diabscale.ai is covered by a separate Privacy Policy, published at https://diabscale.ai/website-privacy-policy/.
1. Data Controller & Data Protection Officer
Data Controller: VP200 sp. z o.o., ul. Domańskiego 112a, 45-289 Opole, Poland (KRS 0000973664, NIP 754-335-11-38, REGON 522251034).
Data Protection Officer: [email protected]
Contact: [email protected] | VP200 sp. z o.o., ul. Domańskiego 112a, 45-289 Opole
2. Scope of Processing
| Data Category | Purpose | Legal Basis | Retention Period |
|---|---|---|---|
| Account data (email, password, profile) | Service delivery | Art. 6(1)(b) GDPR | Until account deletion + 3 years |
| Health data (weight, height, glucose) | Personalization of services | Art. 9(2)(a) GDPR | Until withdrawal of consent |
| Identification data (first name, last name) | Payments and communication | Art. 6(1)(b),(c) GDPR | 5 years |
| Cookies & technical logs | Platform functionality, analytics, marketing | Art. 6(1)(f),(a) GDPR; Art. 173 Telecommunications Law | Until cookies deletion or 26 months |
| Newsletter email | Direct marketing | Art. 6(1)(a) GDPR | Until withdrawal of consent |
| Bug report (your description, device technical information, optionally an attached copy of your application data containing health data) | Diagnosing and fixing defects in the application | Art. 6(1)(f) GDPR; Art. 9(2)(a) GDPR for the attached copy of your data | Until the report is closed, no longer than 90 days |
| Cloud backup (complete archive of your application data, health data included) | Restoring your data after changing or losing a device | Art. 9(2)(a) GDPR | The 10 most recent copies; until you withdraw consent and delete the copies |
3. Recipients & Joint Controllers
Your data may be shared with:
- IT and hosting providers (itDesk Sp. z o.o.)
- Object storage provider for cloud backups (Hetzner Online GmbH, Germany)
- Payment processors
- Service providers under data-processing agreements (marketing, accounting, CRM)
- Public authorities (e.g., tax offices, social security)
Joint Controllers:
- Meta Platforms Ireland Ltd. (Facebook Login) — https://www.facebook.com/about/privacy
- Google Ireland Ltd. (Google Login, Google Play) — https://policies.google.com/privacy
- Apple Distribution International Ltd. (App Store, Apple ID) — https://www.apple.com/legal/privacy
In-app advertising is served by Google AdMob. From 3 August 2026, Google may use the device’s IP address to measure ad performance and personalize advertising for users in the European Economic Area, Switzerland and the United Kingdom. For details on how Google processes user data, see: https://policies.google.com/technologies/partner-sites
4. International Transfers
Transfers to the United States are based on the EU–US Data Privacy Framework and Standard Contractual Clauses (Art. 46 GDPR).
Cloud backups are stored solely within the European Economic Area (Germany) and are not transferred outside the EEA.
5. Your Rights
You have the right to access, rectify, delete, restrict processing, port your data, object, withdraw consent, and lodge a complaint with the President of the Personal Data Protection Office. Submit requests to [email protected].
6. Cookies
We use three categories of cookies:
| Type | Purpose | Retention |
|---|---|---|
| Necessary | Authentication & session maintenance | Until session ends |
| Analytics | Traffic analysis (IP anonymization) | 26 months |
| Marketing | Remarketing (Facebook Pixel, Google AdMob) | 26 months |
Manage cookie preferences via our cookie banner or your browser settings.
7. Profiling
Profiling occurs only with your consent for personalization and marketing. We do not make automated decisions without human intervention.
8. Data Security
We employ TLS encryption, password hashing, regular backups of our own systems, and software updates to safeguard your data. The safeguards applied to backups you create yourself are described in Section 9.
9. Cloud Backup
Cloud backup is optional. We enable it only after you give explicit consent in the app. Until you do, this feature sends no data to our servers.
A backup archive contains the complete set of data you have recorded in the app, health data included: glucose readings, insulin doses, meals, body weight, and application settings. This is special category data, and the legal basis for processing it is Art. 9(2)(a) GDPR — your explicit consent.
We record the fact that consent was given: the date, the time, and an identifier of the wording you consented to. Changing that wording invalidates earlier consents and prompts you again.
The archive is encrypted on your device, before upload. The password is generated separately for each backup and stored by us in encrypted form, under a key held outside the database. The links used to upload and download a copy expire after 15 minutes.
Copies are stored in Hetzner Object Storage in Germany. We keep the 10 most recent copies; creating a new one automatically deletes the oldest.
You may withdraw consent at any time in the app: Settings → Backup. Withdrawal stops any new copies from being created. If you choose to delete the copies already uploaded, we delete them without undue delay. If you choose to keep them, we continue to store them at your explicit request, and you may delete them at any moment (Settings → Backup → Delete all backups).
Ending or losing a Subscription does not restrict your ability to withdraw consent or delete your copies. Both remain available in the app at no charge, and there they are a single command: deleting the copies withdraws the consent along with them.
Deleting your account permanently deletes every cloud backup as well.
10. Data Breach Notification
In the event of a personal data breach, we will notify the President of UODO within 72 hours and affected individuals without undue delay.
11. Data Retention
Personal data is deleted or anonymized after the retention periods specified in Section 2.
12. Account Deletion
You may delete your account via the app (Settings → Account → Delete Account). All your data, cloud backups included, will be permanently erased within 30 days.
13. Policy Changes
Updates are published at https://diabscale.ai/privacy-policy/ at least 14 days before taking effect, and reach the application with its next update. Purely informational changes that do not restrict the rights of the User may take effect on the day they are published.
14. Reporting Bugs in the Application
The “Report Bug” feature prepares an email to [email protected] containing your description of the problem and technical information: the application name and version, platform, device model, system version, and the date of the report. You send the message from your own mail client — its content and the sending itself remain your decision.
You may voluntarily attach a copy of the data stored in the application. It is the complete set of your application data, health data included. The attachment is created only if you tick the corresponding box in the report dialog; the box is unticked by default, and we accept reports without an attachment on the same terms.
The legal basis for processing your description and the technical information is Art. 6(1)(f) GDPR — our legitimate interest in fixing defects in the application. The legal basis for processing the attached copy of your data is Art. 9(2)(a) GDPR, that is your explicit consent given by ticking the box and sending the message. You give this consent separately for each report, and you may withhold it.
We retain reports until the case is closed, no longer than 90 days after its conclusion; the attached copy of your data is deleted without undue delay once the report is closed. Only authorised persons have access to the report mailbox.
You send the report through your own mail client, a channel outside our technical control. The encryption described in Section 9 does not apply to it. If you would rather not transmit health data this way, leave the attachment box unticked.
15. Contact & Complaints
For privacy inquiries or complaints, email [email protected]. We will respond within 30 days. You also have the right to file a complaint with the President of UODO.
