Dietly ("Dietly", "we", "us") is an app that helps people after gastric-sleeve surgery track their diet, protein, water, medications, vitamins, workouts and body composition. Dietly is made by Abdelrahman Gabr. This policy explains what data Dietly handles, why, where it goes and the choices you have.
1. Summary
- Your health records live on your phone and in an encrypted backup tied to your account.
- We don't show ads, we don't sell or rent your data, and we don't use tracking or analytics tools.
- Photos and text you send to an AI feature are processed only to give you that result.
- You can ask us to delete your account and all of its data at any time.
2. Data we collect
Account information. When you create an account: your name, email address, gender, date of birth and preferred language, and a password. Passwords are handled by Amazon Cognito and are never visible to us. Gender is used only to address you correctly in Arabic; date of birth is part of your health profile.
Sign in with Google. If you choose "Continue with Google", we receive your name, email address and a Google account identifier (the openid, email and profile scopes). We use them only to create and sign in to your Dietly account. We do not access your Gmail, contacts, calendar, Drive or any other Google data.
Health and activity data you enter. Diet plans, meals and portions, water, medications, vitamins and supplements with their doses and schedules, weight and body-composition readings (for example InBody reports and smart-scale readings), blood-test results, workouts and coach notes, gym membership details, and photos you take in the app.
Connected services you choose to link. If you connect a gym account (Global Gym) or a smart scale (OKOK), the access token you provide is stored securely (on our server or in your phone's Keychain) and used only to read your memberships or scale readings. Dietly never changes anything in those services.
Technical data. If the app crashes, an error report (the error message and where it happened, without your health data) is stored for 30 days so the problem can be fixed.
3. How we use it
- To run the features you use: your daily plan and totals, reminders, vitamin tracking, charts, and backups.
- To answer AI requests you make (reading a diet sheet, estimating a meal, identifying a medication, the assistant, grocery lists, workout plans, translations into Arabic).
- To send account emails you need: sign-up confirmation codes, password-reset codes and a welcome email. We don't send marketing emails.
- To keep the service secure and working, including per-account usage limits.
4. AI processing
When you use an AI feature, the photo or text you submit, and for the assistant and grocery list a short summary of your plan and today's log, is sent to Anthropic's Claude models through Amazon Bedrock in our AWS account. Amazon Bedrock does not use your inputs or outputs to train models. To confirm products and nutrition, a product name or barcode may be looked up in public sources: Tavily web search, the U.S. NIH Dietary Supplement Label Database, openFDA and Open Food Facts. These lookups contain the product name or barcode, not your personal details. AI results can be wrong; always check them against labels and your medical team.
5. Where data is stored
- On your phone: your records, in the app's local database. Sign-in tokens and service tokens are kept in the iPhone Keychain.
- Amazon Web Services (United States, us-east-1): account records (Amazon Cognito), encrypted daily backups of your data (Amazon S3; each backup is kept for 60 days), a shared database of product facts that contains no personal information, and error reports (30 days).
- Resend: delivers account emails; it receives your email address, name and the email content.
Data is encrypted in transit (HTTPS/TLS) and at rest.
6. Sharing
We share data only with the service providers listed above, only as needed to run Dietly, and never for advertising. We don't sell personal data. We may disclose information if required by law.
7. Google user data
Dietly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data (your name, email address and account identifier) is used only to sign you in, is not used for advertising, is not sold, and is not used to train AI models.
8. Retention and deletion
Your data stays until you delete it. Deleting a record in the app removes it from your phone and from future backups; older backups expire after 60 days. To delete your account and everything linked to it, email bedokak@gmail.com from your account's email address; we delete the account, its backups and its connected-service tokens within 30 days. Removing the app deletes the data stored on your phone.
9. Your choices and rights
- Change your name, gender or language in Settings, and export all your data as a file from the More tab.
- Ask us for a copy of your data, a correction, or deletion by emailing us.
- Turn off notifications or camera access at any time in your phone's settings.
10. Children
Dietly is not directed to children under 16 and we don't knowingly collect their data.
11. Health information
Dietly is not a medical device and does not give medical advice. Your bariatric team decides your diet, doses and supplements.
12. Changes
If we change this policy, we'll update the date above and, for significant changes, tell you in the app.
13. Contact
Abdelrahman Gabr · bedokak@gmail.com