Legal
Privacy
Last updated: 29 September 2026
SPR Labs Ltd (“we”) makes Dia AI. This policy describes the iOS app, the diaai.app website, and the API at api.diaai.app. It matches how the product works today.
The short version
- We do not sell your data.
- Meal logs, glucose history, and insulin notes you type stay on your iPhone. A PDF or CSV export is a file you choose to send. A family-share link does not include those logs.
- A meal photo is sent to estimate carbohydrates and is not saved on our servers. The copy you keep stays on your iPhone until you delete the meal.
- Dia does not recommend insulin doses. Carb estimates and the calculator are information for you to check.
- You can delete the account data we hold from inside the app (Profile).
What stays on your iPhone
- Meals, favourites, recipes, and the carb edits you make. Stored on this iPhone, encrypted, with the key in the Keychain. The files are left out of iCloud and device backups. A restore onto a new iPhone does not bring that log with it.
- Glucose readings you log, and Apple Health data you allow. Readings you log are in the same encrypted store. Dia AI reads blood glucose, heart rate, workouts, and sleep to show meal context. When you save a meal, the carbohydrate total can be written to Apple Health. Deleting that meal, signing out, or deleting your account removes that sample. That health data is not uploaded to us.
- Insulin notes you choose to write. These stay in the encrypted profile on this iPhone. Dia does not send doses to a pump.
- Meal photos you save with a log. Encrypted on this iPhone with the same Keychain key as your meal log, and left out of iCloud and device backups, until you delete that meal or delete your data in the app. A photo from an older install is encrypted the next time it is opened.
- Home Screen widget and Apple Watch. The latest glucose reading, the carbohydrate total of a meal from the last four hours, insulin on board, carbs on board, a bolus you confirmed, and the low threshold you saved are copied into a shared app group so the widget and the Watch can show them. That snapshot is separate from the encrypted meal log. Signing out or deleting your account clears the widget. The Watch copy is replaced the next time the Watch is in range.
- Siri and Shortcuts. “Log a meal” stores the meal name and carbohydrate grams in that same shared app group until Dia AI is next opened. “Check my glucose” reads the snapshot already on this iPhone and speaks it. Neither request is sent to us. Signing out or deleting your account discards a meal that is still waiting, so it is not added to a new log.
- Lock Screen Live Activity. After you save a meal that still has carbohydrates on board, the carbohydrate total and the latest glucose reading can appear on the Lock Screen and in the Dynamic Island. It does not predict a glucose peak. A bolus appears there only after you confirm the units yourself. Signing out or deleting your account ends that activity and cancels meal reminders.
- Your name, if you share it with Sign in with Apple. Used to greet you. Your Apple identifier is stored on the device so the app can recognise you.
What leaves your iPhone
- Meal photos, for a carb estimate. The image is sent to our API and then to Anthropic to identify food and estimate carbohydrates. We do not write the photo to our database. We do not use it to train a model unless you turn on “Help Dia learn” (off by default). That opt-in sends the food labels, the gram changes, and a key that rotates about every 30 days. It does not send the photo or your Apple ID. The server keeps the calendar day, not the clock time.
- Spoken meals. Speech is recognised on the iPhone. The text of what you said is sent to estimate carbohydrates. The audio is not uploaded. A recording started on Apple Watch is sent only to your iPhone, over Apple’s Watch connection, and is not uploaded.
- Food searches and barcodes. The query or barcode is sent to our API, which asks USDA FoodData Central or Open Food Facts. That is a food lookup, not a health record.
- Sign in with Apple. When you use a feature that needs an account (family share, account deletion, and a Dexcom link after you have signed in), the app sends your Apple identity token so the API can confirm it is you. We store the stable Apple user id with those records. We do not keep a server profile of your email.
- Dexcom, if you connect it. OAuth tokens are stored on the server so the app can fetch recent glucose on your behalf. Once the link is tied to your Apple user, that glucose is only returned to a request signed with your Apple identity. You can disconnect Dexcom in Settings.
- Family share, if you create a link. We store the link and your Apple user id. The link lasts 30 days and does not include meals or glucose. The page at diaai.app/share says that nothing is shared yet. When someone signed in asks the API for the summary, we log that view against their Apple user id. That summary has no reading. Deleting your account removes links you own and anonymises your id in other people’s view logs.
- Subscriptions. Purchases go through Apple. RevenueCat tells the app whether Pro is active. That is subscription state, not health data.
- Crash and performance diagnostics, when enabled. The app can send crash and hang diagnostics to Sentry. Messages, screenshots, and user identity are stripped on the device before send. Reporting stays off until a DSN is configured in the build. We do not use advertising identifiers and we do not run product analytics in the iOS app.
- The website. diaai.app is hosted by Vercel. Vercel Web Analytics counts page views on the website. That count is not in the iOS app, and it does not receive meal photos, glucose, or an Apple ID.
- Waitlist email, on the website only. If you join the waitlist, we keep that address so we can send one welcome note and one email when Dia AI is available, through Postmark when that is configured. The form is received by Vercel and then stored on the API when the API is up. You can delete it at diaai.app/waitlist/leave. If the API cannot store it, the signup is not accepted and the address is not written to the site log. Try the form again. It is not your app account.
What we do not do
- We do not sell personal information.
- We do not use advertising identifiers or cross-app tracking.
- We do not recommend an insulin dose.
- We do not put carbohydrate estimates, the ± range, or the ability to edit a meal behind the Pro subscription.
- Carb corrections that leave the device are opt-in, default off, and stored without your Apple ID, photo, or a precise timestamp. A key that changes about every 30 days groups those rows. It is not your Apple ID.
Deletion
In the app, open Profile and delete your account. That calls the API to remove family-share links you own and Dexcom tokens tied to you, then wipes the data stored on that iPhone, including saved meal photos, carbohydrate totals Dia saved to Apple Health, and a meal still waiting from Siri, and ends a Lock Screen Live Activity. If the server purge fails, the app does not wipe the phone, so you can retry. De-identified carb corrections are not linked to your Apple ID, so they cannot be selected for deletion.
Children
Dia AI is not directed at children under 13 (16 in the EEA). We do not knowingly collect data from anyone under that age. A caregiver uses their own Apple ID.
Decision support
Dia AI is information, not medical advice and not a medical device. Carb estimates can be wrong. The calculator uses numbers you enter. Check every figure with your care team. Dia does not transmit doses to pumps.
Contact
Privacy questions: privacy@diaai.app. Security disclosures: security@diaai.app. The companies that process data for us are listed on the subprocessor page.