DiabScale.AI Privacy Policy

Effective Date: August 22, 2026

This Privacy Policy describes how we collect, use, disclose, and protect your personal data when you use the DiabScale mobile application and the server-side services it relies on (the “Platform”). It is published at https://diabscale.ai/privacy-policy/.

Processing related to your use of the website at https://diabscale.ai is covered by a separate Privacy Policy, published at https://diabscale.ai/website-privacy-policy/.

1. Data Controller & Data Protection Officer

Data Controller: VP200 sp. z o.o., ul. Domańskiego 112a, 45-289 Opole, Poland (KRS 0000973664, NIP 754-335-11-38, REGON 522251034).

Data Protection Officer: [email protected]

Contact: [email protected] | VP200 sp. z o.o., ul. Domańskiego 112a, 45-289 Opole

2. Scope of Processing

Data Category Purpose Legal Basis Retention Period
Account data (email, password, profile) Service delivery Art. 6(1)(b) GDPR Until account deletion + 3 years
Health data (weight, height, glucose) Personalization of services Art. 9(2)(a) GDPR Until withdrawal of consent
Identification data (first name, last name) Payments and communication Art. 6(1)(b),(c) GDPR 5 years
Cookies & technical logs Platform functionality, analytics, marketing Art. 6(1)(f),(a) GDPR; Art. 173 Telecommunications Law Until cookies deletion or 26 months
Newsletter email Direct marketing Art. 6(1)(a) GDPR Until withdrawal of consent
Bug report (your description, device technical information, optionally an attached copy of your application data containing health data) Diagnosing and fixing defects in the application Art. 6(1)(f) GDPR; Art. 9(2)(a) GDPR for the attached copy of your data Until the report is closed, no longer than 90 days
Cloud backup (complete archive of your application data, health data included) Restoring your data after changing or losing a device Art. 9(2)(a) GDPR The 10 most recent copies; until you withdraw consent and delete the copies

3. Recipients & Joint Controllers

Your data may be shared with:

  • IT and hosting providers (itDesk Sp. z o.o.)
  • Object storage provider for cloud backups (Hetzner Online GmbH, Germany)
  • Payment processors
  • Service providers under data-processing agreements (marketing, accounting, CRM)
  • Public authorities (e.g., tax offices, social security)

Joint Controllers:

  • Meta Platforms Ireland Ltd. (Facebook Login) — https://www.facebook.com/about/privacy
  • Google Ireland Ltd. (Google Login, Google Play) — https://policies.google.com/privacy
  • Apple Distribution International Ltd. (App Store, Apple ID) — https://www.apple.com/legal/privacy

In-app advertising is served by Google AdMob. From 3 August 2026, Google may use the device’s IP address to measure ad performance and personalize advertising for users in the European Economic Area, Switzerland and the United Kingdom. For details on how Google processes user data, see: https://policies.google.com/technologies/partner-sites

4. International Transfers

Transfers to the United States are based on the EU–US Data Privacy Framework and Standard Contractual Clauses (Art. 46 GDPR).

Cloud backups are stored solely within the European Economic Area (Germany) and are not transferred outside the EEA.

5. Your Rights

You have the right to access, rectify, delete, restrict processing, port your data, object, withdraw consent, and lodge a complaint with the President of the Personal Data Protection Office. Submit requests to [email protected].

6. Cookies

We use three categories of cookies:

Type Purpose Retention
Necessary Authentication & session maintenance Until session ends
Analytics Traffic analysis (IP anonymization) 26 months
Marketing Remarketing (Facebook Pixel, Google AdMob) 26 months

Manage cookie preferences via our cookie banner or your browser settings.

7. Profiling

Profiling occurs only with your consent for personalization and marketing. We do not make automated decisions without human intervention.

8. Data Security

We employ TLS encryption, password hashing, regular backups of our own systems, and software updates to safeguard your data. The safeguards applied to backups you create yourself are described in Section 9.

9. Cloud Backup

Cloud backup is optional. We enable it only after you give explicit consent in the app. Until you do, this feature sends no data to our servers.

A backup archive contains the complete set of data you have recorded in the app, health data included: glucose readings, insulin doses, meals, body weight, and application settings. This is special category data, and the legal basis for processing it is Art. 9(2)(a) GDPR — your explicit consent.

We record the fact that consent was given: the date, the time, and an identifier of the wording you consented to. Changing that wording invalidates earlier consents and prompts you again.

The archive is encrypted on your device, before upload. The password is generated separately for each backup and stored by us in encrypted form, under a key held outside the database. The links used to upload and download a copy expire after 15 minutes.

Copies are stored in Hetzner Object Storage in Germany. We keep the 10 most recent copies; creating a new one automatically deletes the oldest.

You may withdraw consent at any time in the app: Settings → Backup. Withdrawal stops any new copies from being created. If you choose to delete the copies already uploaded, we delete them without undue delay. If you choose to keep them, we continue to store them at your explicit request, and you may delete them at any moment (Settings → Backup → Delete all backups).

Ending or losing a Subscription does not restrict your ability to withdraw consent or delete your copies. Both remain available in the app at no charge, and there they are a single command: deleting the copies withdraws the consent along with them.

Deleting your account permanently deletes every cloud backup as well.

10. Data Breach Notification

In the event of a personal data breach, we will notify the President of UODO within 72 hours and affected individuals without undue delay.

11. Data Retention

Personal data is deleted or anonymized after the retention periods specified in Section 2.

12. Account Deletion

You may delete your account via the app (Settings → Account → Delete Account). All your data, cloud backups included, will be permanently erased within 30 days.

13. Policy Changes

Updates are published at https://diabscale.ai/privacy-policy/ at least 14 days before taking effect, and reach the application with its next update. Purely informational changes that do not restrict the rights of the User may take effect on the day they are published.

14. Reporting Bugs in the Application

The “Report Bug” feature prepares an email to [email protected] containing your description of the problem and technical information: the application name and version, platform, device model, system version, and the date of the report. You send the message from your own mail client — its content and the sending itself remain your decision.

You may voluntarily attach a copy of the data stored in the application. It is the complete set of your application data, health data included. The attachment is created only if you tick the corresponding box in the report dialog; the box is unticked by default, and we accept reports without an attachment on the same terms.

The legal basis for processing your description and the technical information is Art. 6(1)(f) GDPR — our legitimate interest in fixing defects in the application. The legal basis for processing the attached copy of your data is Art. 9(2)(a) GDPR, that is your explicit consent given by ticking the box and sending the message. You give this consent separately for each report, and you may withhold it.

We retain reports until the case is closed, no longer than 90 days after its conclusion; the attached copy of your data is deleted without undue delay once the report is closed. Only authorised persons have access to the report mailbox.

You send the report through your own mail client, a channel outside our technical control. The encryption described in Section 9 does not apply to it. If you would rather not transmit health data this way, leave the attachment box unticked.

15. Contact & Complaints

For privacy inquiries or complaints, email [email protected]. We will respond within 30 days. You also have the right to file a complaint with the President of UODO.