Legal

Subprocessors

Last updated: 29 September 2026

These are the third parties that process data for Dia AI. The list matches the app and the website. Vendors that receive health information need a business-associate agreement before production traffic; “Before production” means that agreement is still required, not that it is already signed. We will update this page before adding a vendor that handles health information.

VendorPurposeData processedRegionBAA / status
AnthropicMeal photo and spoken-meal text, to estimate carbohydratesImage bytes or transcript for that request. We do not store the photo.USBefore production
API host (Postgres)api.diaai.app — Dexcom tokens, family share, waitlist addresses, optional de-identified carb correctionsOAuth tokens, Apple user ids on share links, waitlist email addresses, correction rows with no Apple IDThe host region for the production databaseBefore production
AppleSign in with Apple, App Store subscriptions, HealthKit on deviceApple user id, subscription state. Health samples stay on the iPhone.USN/A
RevenueCatSubscription entitlementsApp user id and subscription events. No health data.USN/A
SentryCrash and hang diagnostics, only when a DSN is set in the buildStack traces and device metadata. Messages and identity are stripped on device.USBefore production
DexcomGlucose fetch when you connect a Dexcom accountOAuth tokens on our server; glucose readings returned to your phone.US, EU, or JP, matching the accountN/A
USDA FoodData CentralPackaged and generic food searchThe food name or id you searched.USN/A
Open Food FactsBarcode and packaged-food searchThe barcode or food name you searched.EUN/A
PostmarkWaitlist email from diaai.appThe email address you type into the waitlist form.USN/A
VercelHosts diaai.app and counts website page viewsWebsite page-view analytics. A waitlist address is sent to the API and is not written to the site log. Not meal photos, glucose, or an Apple ID.USN/A

What “BAA” means

A business-associate agreement is the contract used when a vendor processes health information for us. Yes means that contract is in place. Before production means we will not send health information to that vendor in production until it is. N/A means the vendor does not receive health records from us (food-name lookups, subscription state, or an email you typed into the waitlist).

Where data sits

Meal logs and glucose history you record stay on the iPhone. Meal photos are sent to Anthropic for the estimate and are not stored by us. Dexcom tokens and family-share records sit in the production database for api.diaai.app. A meal photo sent for analysis is processed by Anthropic in the US.

Why we publish this

Diabetes data is some of the most sensitive personal health information a person carries. You deserve to know exactly which companies touch it, what they do with it, and where it lives. Transparency is a feature.