Skip to content
Dietly!Dietly!
English
Application legal documents

Privacy Policy

Last updated: September 11, 2026

Dietly! ("Software") is committed to protecting your and your patients' data. This policy explains how data is handled within our "Zero-Knowledge" and "Offline-First" architecture.

1. What data do we collect?

The developers of Dietly! do not collect any personal, health, or biometric data, and no data is transmitted automatically. The Software does not have a centralized cloud database. All data you enter into the Software (including patient names, contact info, weight, lab results, and dietary diaries) is stored exclusively on your physical device (computer).

There are exactly two cases in which data can leave your machine — both only on your explicit action, and each is described in its own section below: voluntary bug reporting (section 5) and Microsoft Store licence validation (section 6).

2. Data Storage and Security

The database stored on your device is protected by industry-standard AES-256 (SQLCipher) encryption. The encryption key is stored securely in your operating system's keychain (Windows Credential Manager). The developers do not have access to your password; therefore, if it is lost, the developers cannot recover your data.

An important distinction between outgoing files: a backup created with the built-in feature (.ddb) stays encrypted. By contrast, GDPR data exports, PDFs and CSVs are unencrypted files — storing, transferring and, where required, destroying them is your responsibility.

3. GDPR and Data Controller Role

Because the Software is strictly a local tool, under the European General Data Protection Regulation (GDPR), you act as the Data Controller, and the developers are not data processors. It is your responsibility to:

  • Have a valid legal basis (e.g., consent) to record patient data.
  • Obtain, have signed, and upload the patients' GDPR consent declarations into the Software. The developers and owners cannot be held liable for the failure to fulfill this obligation.
  • Ensure the physical and digital security of your device (passwords, screen locks, antivirus).
  • Create secure backups of the encrypted database using the application's built-in feature.
  • Securely handle and transfer to the patient any unencrypted files consciously extracted by you from the Software (e.g., GDPR Data Export).
  • Inform the patient that, for legal and safety reasons, the Software automatically logs to their local record if you override a configured allergen or preference warning.

3.1. What deletion means in the Software

The Software protects the retrospective integrity of finished meal plans. If you delete an ingredient or a recipe from the catalogue, its name and nutritional values are preserved as a "ghost" inside previously created meal plans, so that historical calculations are not distorted after the fact. This behaviour applies to the catalogue, not to patient data.

Deleting a patient, by contrast, removes that patient's entire record from the local database. If a patient exercises their GDPR right to erasure, deleting the patient record is the operation that applies.

4. Third Parties

The Software contains no analytics, tracking, or advertising modules. Your data is not sold, and in normal operation it is not transmitted to third parties, as it does not leave your device.

5. Voluntary Bug Reporting (Diagnostics)

The Software includes a bug reporting feature. It produces a data package only when you start it yourself.

  • The package contains the application's operational logs and technical environment; the system redacts patients' personal identifiers from it.
  • The file is produced with AES-256 encryption (.dlog), and the Software never sends it anywhere automatically — the file is created on your machine, and you decide whether to forward it to the developers.
  • During the beta period you may additionally, and optionally, share the ingredients and recipes you created yourself; that package contains no patient data.

If you do send such a package, the developers use it solely to investigate the reported issue.

6. Microsoft Store Licence Validation

The edition installed from the Microsoft Store validates your subscription through Microsoft's systems. This communication concerns licence and subscription status only and contains no patient data, meal plans, or health information. Microsoft's own privacy policy also applies to this process. The edition installed with the traditional installer (.exe) performs no such validation.

7. Changes to This Policy

The developers may update this policy in future releases. The version currently in force is always available inside the Software under About → Privacy Policy, carrying the "Last updated" date shown above.