GallDiet

GallDiet Privacy Policy

App: GallDiet
Developer: Caleb Oki
Effective Date: March 6, 2026
Last Updated: March 24, 2026


1. INTRODUCTION

GallDiet ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our mobile application and related services.

IMPORTANT: GallDiet is a health and wellness tool designed to help users track dietary choices related to gallstone and digestive health. It is not a medical device and does not provide medical advice. Always consult healthcare professionals for medical decisions.


2. INFORMATION WE COLLECT

2.1 Account Information

2.2 Health Profile Information (Onboarding)

During onboarding, you may provide:

Purpose: This data enables personalized safety scoring and trigger detection specific to your health profile.

2.3 Health Activity Information

Information generated through app usage:

Classification: This constitutes "health information" under applicable privacy regulations. We treat this data with enhanced security measures.

2.4 Photos and Media

Processing Note: Photos are transmitted to Anthropic Claude AI (primary) or Google Gemini AI (fallback) for ingredient analysis. See Section 4.2 for AI processing details.

2.5 Payment Information

2.6 Technical Information

2.7 We Do NOT Collect


3. HOW WE USE YOUR INFORMATION

Data Type Primary Use Legal Basis
Name, Email Authentication, personalization, password resets Contract performance
Health profile (onboarding) Personalized safety scoring, trigger detection Consent
Health activity logs Pattern detection, personalized insights Consent
Food photos AI ingredient analysis, safety scoring Contract performance
Payment data Subscription billing via Stripe Contract performance
Technical logs App improvement, bug fixes Legitimate interest

3.1 AI-Powered Food Analysis

When you scan a meal photo:

  1. Image is uploaded to our secure servers
  2. Image is forwarded to Anthropic Claude AI API for ingredient identification (with Google Gemini AI as a fallback provider)
  3. Results are processed against our gallstone-safe food database
  4. Original photo and analysis results are stored in your account

Data Retention: Photos are retained until you delete them or your account. See Section 6 for deletion procedures.

3.2 Pattern Detection

We analyze your logged meals and attack reports to identify potential trigger foods. This analysis:


4. THIRD-PARTY SERVICES

4.1 Stripe (Payment Processing)

4.2 Anthropic Claude AI (Primary Photo & Recipe Analysis)

4.3 Google Gemini AI (Fallback Photo Analysis)

4.4 OpenFoodFacts (Barcode Lookup)

4.5 Postmark/Resend (Email Delivery)

4.6 Sentry (Error Monitoring)


5. DATA STORAGE AND SECURITY

5.1 Storage Location

5.2 Security Measures

5.3 Access Controls


6. DATA RETENTION AND DELETION

6.1 Retention Periods

Data Type Retention Period Reason
Account data (name, email) Until deletion + 30 days Grace period for recovery
Health profile (onboarding) Until deletion + 30 days Grace period for recovery
Health activity logs Until deletion + 30 days Grace period for recovery
Photos Until deletion + 30 days Grace period for recovery
Payment records 7 years Tax and legal compliance
Server logs 30 days Security and debugging
Crash reports 90 days Bug resolution

6.2 Account Deletion

You may request complete account deletion at any time:

Process:

  1. Navigate to Settings → Privacy → Delete Account
  2. Confirm deletion request
  3. Account enters 30-day grace period
  4. After 30 days, all personal data is permanently deleted
  5. Payment records retained for legal compliance (anonymized)

During Grace Period:

Immediate Deletion: If you require immediate deletion (bypassing 30-day grace period), contact [email protected] with subject "URGENT: Immediate Account Deletion."

6.3 Data Export (GDPR Right to Portability)

You may request a complete export of your data:

Process:

  1. Navigate to Settings → Privacy → Export My Data
  2. We generate a PDF report containing:
    • Account information (name, email, profile details)
    • Health profile (age, sex, gallbladder status, preferences, triggers, allergies, emergency contacts)
    • All logged meals and attack records
    • Food scan history
    • Pattern detection results
  3. Report is emailed to your registered address within 24 hours
  4. Export includes data in human-readable format

7. YOUR RIGHTS

7.1 GDPR Rights (EU/EEA Users)

If you are in the European Union or European Economic Area, you have the right to:

  1. Access: Request a copy of your personal data
  2. Rectification: Correct inaccurate or incomplete data
  3. Erasure ("Right to be Forgotten"): Request deletion of your data
  4. Restrict Processing: Limit how we use your data
  5. Data Portability: Receive your data in a structured, machine-readable format
  6. Object: Object to certain types of processing
  7. Withdraw Consent: Withdraw consent for optional data processing

To exercise these rights: Email [email protected] with subject "GDPR Request"

Response Time: We respond to all requests within 30 days.

7.2 California Privacy Rights (CCPA/CPRA)

California residents have the right to:

  1. Know: Request disclosure of personal information collected
  2. Delete: Request deletion of personal information
  3. Opt-out: Opt-out of "sale" of personal information (we do not sell data)
  4. Non-discrimination: We do not discriminate for exercising privacy rights

To exercise these rights: Email [email protected] with subject "California Privacy Request"

7.3 Other Jurisdictions

Users in Canada, UK, and other jurisdictions have similar rights under applicable privacy laws. Contact us for jurisdiction-specific requests.


8. CHILDREN'S PRIVACY

GallDiet is not intended for children under 13 years of age (or 16 in the EU). We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, contact us immediately for deletion.


9. INTERNATIONAL DATA TRANSFERS

Your data may be processed in countries outside your jurisdiction:

We ensure appropriate safeguards are in place for international transfers, including:


10. COOKIES AND TRACKING

10.1 Mobile App

Our mobile app does not use traditional cookies. We use:

10.2 Website (if applicable)

If you visit galldiet.com:


11. CHANGES TO THIS POLICY

We may update this Privacy Policy periodically. Changes will be:

Material changes include:


12. CONTACT INFORMATION

Data Controller:
Caleb Oki
Toronto, Ontario, Canada
Email: [email protected]

Data Protection Officer (DPO):
We are not required to appoint a DPO under GDPR Article 37, but you may contact [email protected] for privacy concerns

Response Time: We aim to respond to all inquiries within 48 hours.


13. DISCLAIMERS

13.1 Not Medical Advice

GallDiet provides general wellness information and dietary tracking tools. Our AI-powered food safety assessments are based on general nutritional guidelines and crowd-sourced data, not personalized medical advice.

Always consult:

13.2 AI Limitations

Our ingredient analysis uses artificial intelligence which:


14. COMPLIANCE CERTIFICATIONS


Document Version: 1.0
Next Review Date: September 6, 2026


APPENDIX A: DATA PROCESSING AGREEMENT (DPA)

For business customers or partners requiring a DPA under GDPR Article 28, contact [email protected] to request our standard Data Processing Agreement.

APPENDIX B: SUBPROCESSOR LIST

Current subprocessors as of March 6, 2026:

Provider Service Location Purpose
Hetzner Cloud Cloud infrastructure Nuremberg, Germany Database and API hosting
Stripe Payment processing US Subscription billing
Anthropic (Claude) AI/ML processing US Primary photo analysis and recipe modification
Google (Gemini) AI/ML processing Global Fallback photo analysis
Resend Email delivery US Transactional emails
Sentry Error monitoring US Bug tracking
OpenFoodFacts Product database EU/France Barcode lookups

We notify users of new subprocessors 30 days before they are engaged (where required by law).


This Privacy Policy was drafted specifically for GallDiet and covers the unique aspects of AI-powered food analysis, health tracking for gallstone management, and subscription-based mobile application services.