Privacy Policy
Last updated: 26 September 2026
In short: your food journal lives in an account that belongs to you. Your health data never leaves your phone. We don't store your photos on our servers. We don't show ads and we don't sell your data. You can delete your account and all of your data from inside the app in one step.
Who we are
MyDietLens is developed by Digitagram. This policy covers the MyDietLens mobile app and the mydietlens.digitagram.com website. For the purposes of the Turkish Personal Data Protection Law (KVKK) and the EU General Data Protection Regulation (GDPR), Digitagram is the data controller. You can reach us at info@mydietlens.digitagram.com.
What we process
| Data | Why | Where |
|---|---|---|
| Account ID. The first time you open the app, an anonymous account ID is created for you. | To link your records to your account and restore them on a new device. | Firebase Authentication |
| Sign in with Apple or Google. If you choose to sign in, your email address and the account ID that service provides. With Apple you can choose to hide your email. | To protect your account and reach the same records from another device. | Firebase Authentication |
| Profile. Your goal, sex, age, height, weight, target weight and activity level. | To calculate your daily calorie and macro targets. | On your device and in Cloud Firestore |
| Food journal. Meal names, ingredients, nutrition values, meal type, portion and time; water tracking; weigh-ins you enter yourself. | To show your journal, streak and progress. | On your device and in Cloud Firestore |
| Meal photos and meal descriptions you type. | To recognise the food and estimate its nutrition values. | Sent to Google Gemini for analysis. The photo is kept only on your device and is not stored on our servers. |
| What you ask the coach, plus a summary of your day (your goal and remaining calories and macros). | To suggest meals. | Sent to Google Gemini; suggestions are stored only on your device. |
| Health data. If you allow it, step count, active energy and weight are read from Apple Health or Health Connect. | To adjust your daily calorie budget to your activity and show your weight trend. | On your device only. Never sent to a server. We never write anything to your health app. |
| Crash reports. A technical trace from the moment of the crash, device model, operating system, app version and a random installation ID. | To find and fix bugs. | Firebase Crashlytics |
| App verification. A token from Apple App Attest or Google Play Integrity showing that requests come from the genuine MyDietLens app. | To block abuse and forged requests. | Firebase App Check |
Reminders are scheduled on your device, and your notification settings are never sent to a server. Camera and photo library access is used only when you take or choose a photo.
What we don't do
- We don't show ads or share data with ad networks.
- We don't sell your data.
- We don't use Apple Health or Health Connect data for advertising, marketing or data mining, and we never send it to a server or to iCloud.
- We don't track you across other companies' apps and websites.
AI analysis
When you analyze a photo or a description, the content is sent through Firebase AI Logic to Google's Gemini models and processed by Google to produce the answer. That processing is also subject to Google's own terms of service. We use your photos for nothing other than the analysis. We recommend not sending photos that show faces, documents or other personal information.
The values the AI returns are estimates and can be wrong. See the Terms of Use for details.
Legal basis
- Providing the service: account, profile, journal and analysis data are processed so we can provide the service you asked for (KVKK art. 5/2-c; GDPR art. 6(1)(b)).
- Explicit consent: weight, height and food information may count as health-related data. Apple Health and Health Connect data is only read after you allow it. We process this data based on your explicit consent (KVKK art. 6; GDPR art. 9(2)(a)). You can withdraw consent at any time in your health app's settings or by deleting your account.
- Legitimate interest: crash reports and app verification are processed to keep the app safe and working (KVKK art. 5/2-f; GDPR art. 6(1)(f)).
Who we share it with
We share data only with providers that help us run the service, and only as far as that service requires:
- Google: Firebase Authentication, Cloud Firestore, Crashlytics, App Check, Hosting and Firebase AI Logic (Gemini). On Android, Sign in with Google and Play Integrity.
- Apple: Sign in with Apple and App Attest. Apple Health data stays on your device.
Google's servers may be located outside Türkiye, including in the European Union and the United States. These transfers rely on the safeguards in KVKK art. 9 and the GDPR, such as standard contractual clauses. We may share data with competent authorities where the law requires it.
How long we keep it
- Account, profile and journal data: until you delete your account.
- Removing the app from your phone deletes the data on the device, but the cloud copy stays in your account. To delete it from the cloud as well, use Profile › Delete account and data before removing the app.
- Crash reports: automatically deleted by Crashlytics after 90 days.
Your rights
Under KVKK art. 11 and the GDPR you have the right to know whether your data is processed, and to access, correct, delete and port it, to object to processing and to withdraw consent. You can edit your profile and meals in the app yourself, and delete your account and all data from inside the app. For anything else, write to info@mydietlens.digitagram.com; we reply within 30 days at the latest. You also have the right to complain to the Turkish Personal Data Protection Authority or, if you live in the European Union, to the data protection authority in your country.
Children
MyDietLens is not designed for people under 16, and we don't knowingly collect data from them. If you become aware of such a case, write to us and we will delete the data.
Security
All traffic between the app and the servers is encrypted. Database rules allow each user to access only their own data. App Check blocks forged requests. No system is perfect, but we take every reasonable measure to protect your data.
This website
This site uses no cookies, contains no analytics or ad trackers and serves its fonts from its own server. The hosting service (Firebase Hosting) may keep standard access logs, such as IP address and browser details, for security and operations.
Changes
We may update this policy. We announce significant changes in the app or on this page, and the date of the latest update appears at the top.
Contact
Digitagram · info@mydietlens.digitagram.com