Legal
Subprocessors
Last updated: 29 September 2026
These are the third parties that process data for Dia AI. The list matches the app and the website. Vendors that receive health information need a business-associate agreement before production traffic; “Before production” means that agreement is still required, not that it is already signed. We will update this page before adding a vendor that handles health information.
| Vendor | Purpose | Data processed | Region | BAA / status |
|---|---|---|---|---|
| Anthropic | Meal photo and spoken-meal text, to estimate carbohydrates | Image bytes or transcript for that request. We do not store the photo. | US | Before production |
| API host (Postgres) | api.diaai.app — Dexcom tokens, family share, waitlist addresses, optional de-identified carb corrections | OAuth tokens, Apple user ids on share links, waitlist email addresses, correction rows with no Apple ID | The host region for the production database | Before production |
| Apple | Sign in with Apple, App Store subscriptions, HealthKit on device | Apple user id, subscription state. Health samples stay on the iPhone. | US | N/A |
| RevenueCat | Subscription entitlements | App user id and subscription events. No health data. | US | N/A |
| Sentry | Crash and hang diagnostics, only when a DSN is set in the build | Stack traces and device metadata. Messages and identity are stripped on device. | US | Before production |
| Dexcom | Glucose fetch when you connect a Dexcom account | OAuth tokens on our server; glucose readings returned to your phone. | US, EU, or JP, matching the account | N/A |
| USDA FoodData Central | Packaged and generic food search | The food name or id you searched. | US | N/A |
| Open Food Facts | Barcode and packaged-food search | The barcode or food name you searched. | EU | N/A |
| Postmark | Waitlist email from diaai.app | The email address you type into the waitlist form. | US | N/A |
| Vercel | Hosts diaai.app and counts website page views | Website page-view analytics. A waitlist address is sent to the API and is not written to the site log. Not meal photos, glucose, or an Apple ID. | US | N/A |
What “BAA” means
A business-associate agreement is the contract used when a vendor processes health information for us. Yes means that contract is in place. Before production means we will not send health information to that vendor in production until it is. N/A means the vendor does not receive health records from us (food-name lookups, subscription state, or an email you typed into the waitlist).
Where data sits
Meal logs and glucose history you record stay on the iPhone. Meal photos are sent to Anthropic for the estimate and are not stored by us. Dexcom tokens and family-share records sit in the production database for api.diaai.app. A meal photo sent for analysis is processed by Anthropic in the US.
Why we publish this
Diabetes data is some of the most sensitive personal health information a person carries. You deserve to know exactly which companies touch it, what they do with it, and where it lives. Transparency is a feature.