DigestoryDigestoryPL
← Back to homepage

Privacy Policy

Version 1.1 · Published: July 14, 2026 · Effective: July 14, 2026

1. Data controller

The controller of personal data processed in connection with the use of the Digestory app is:

Michał Konieczny Usługi Programistyczne
legal form: sole proprietorship (Poland)
registered/business address: ul. Jedności 3, 43-245 Studzionka, Poland
Tax ID (NIP): 6381803525
email: kontakt@digestory.pl
hereinafter referred to as the "Controller".

The Controller has not appointed a Data Protection Officer (DPO).

2. Scope of this Policy

  1. This Policy explains how the Controller processes personal data in connection with:
    1. using the Digestory mobile app;
    2. maintaining an Account;
    3. using AI-powered features;
    4. sending notifications;
    5. handling inquiries and complaints;
    6. using the digestory.pl website.
  2. The Controller processes data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
  3. Digestory is an app for keeping a self-tracked journal. It is not a medical records system operated by a healthcare provider.

3. What data we process

Depending on the features used, the Controller may process the following categories of data.

3.1. Account and authentication data

This includes, in particular:

  • email address;
  • internal Account identifier;
  • Account creation date;
  • information about email confirmation;
  • login dates;
  • session tokens and data necessary for authentication;
  • information related to password changes or account recovery;
  • Account status and settings.

Authentication and the database are handled using Supabase's services.

3.2. Health and lifestyle data

This may include, in particular, information about:

  • pain, bloating, gas, and other symptoms;
  • bowel movements and stool characteristics;
  • meals, products, and drinks;
  • sleep;
  • stress;
  • energy and wellbeing;
  • physical activity;
  • body weight;
  • hydration;
  • medication and supplements;
  • the menstrual cycle, if that feature is made available and the User uses it;
  • diagnoses or test results the User voluntarily enters;
  • the User's own notes;
  • the date, time, and frequency of individual events.

This data may constitute health data, i.e. a special category of personal data.

3.3. Data generated through AI use

This may include:

  • the content of an entry submitted to the "Add your Digestory" feature;
  • a transcription of speech;
  • data selected from earlier entries, if needed to perform an analysis feature;
  • system instructions and technical context;
  • the model's response;
  • the structured entry;
  • summaries, patterns, correlations, and suggestions generated by the system;
  • information about whether the User accepted or corrected the result.

The User's full profile should not be sent to an external AI provider unless necessary to perform the selected feature.

3.4. Voice recordings and speech recognition

  1. If the User uses the dictation feature, the App only accesses the microphone after the system permission has been granted.
  2. Depending on the operating system and the implementation used, speech recognition may take place:
    1. locally on the device;
    2. using Apple's services;
    3. using Google's services; or
    4. using another provider disclosed to the User before processing begins.
  3. The Controller does not store raw audio recordings on its servers — speech recognition happens locally on the device or through native operating-system mechanisms, and only the recognized text content is sent to the server.
  4. Once a transcription has been created, its content may be sent to an AI provider if the User has previously given separate consent to this.

3.5. Technical data and data about App usage

This may include:

  • IP address;
  • device type and model;
  • operating system and its version;
  • App version;
  • language and time zone;
  • date and time of the request;
  • session identifiers;
  • information about errors and crashes;
  • diagnostic data;
  • information about login attempts;
  • basic server logs;
  • information necessary to prevent abuse and ensure security.

The Controller does not use health data to build advertising profiles or to track Users across other companies' apps.

3.6. Notifications

If the User enables notifications, we may process:

  • the push notification token;
  • the device's operating system;
  • reminder settings;
  • the date and time of a scheduled notification;
  • technical information about notification delivery, where available.

Notifications may be delivered via the Apple Push Notification Service, Firebase Cloud Messaging, and the Expo Push Notifications service.

3.7. NFC tags

If the User uses NFC tags, we may process:

  • the identifier or code assigned to the tag;
  • the link between the tag and a specific action or entry;
  • the time the tag was used;
  • the identifier of the Account the tag is assigned to.

The App does not read any other data from the tag beyond what is needed to carry out the User's instruction.

3.8. Purchases and subscriptions

If paid features are made available, we may receive the following from Apple or Google:

  • the transaction identifier;
  • the type of plan purchased;
  • the subscription start and end date;
  • payment or renewal status;
  • the country and currency of the purchase;
  • information needed to verify entitlements.

The Controller generally does not receive the User's full payment card number.

3.9. Contact and support

When you contact us, we may process:

  • your email address;
  • your name, if provided;
  • the content of your message;
  • attachments;
  • information about your device and the App;
  • the correspondence history;
  • information related to complaints or the exercise of GDPR rights.

4. Where we get your data from

We receive data:

  1. directly from the User;
  2. automatically from the device or the App;
  3. from Apple or Google in connection with downloading the App, a purchase, or notifications;
  4. from infrastructure and authentication providers;
  5. as a result of AI systems processing data submitted by the User.

The Controller does not obtain medical records directly from doctors, healthcare facilities, or public health systems, unless a separately described integration is introduced in the future and the User expressly enables it.

5. Purposes and legal basis

5.1. Creating an Account and providing core features

Purpose:

  • creating and managing the Account;
  • logging in;
  • storing entries;
  • displaying history, charts, and reports;
  • carrying out the User's instructions.

Legal basis:

  • GDPR Art. 6(1)(b) – performance of a contract or steps taken before entering into one;
  • for health data, additionally GDPR Art. 9(2)(a) – explicit consent.

5.2. Processing health data

Purpose:

  • keeping the User's private journal;
  • organizing entries;
  • creating summaries;
  • showing changes and possible relationships.

Legal basis:

  • GDPR Art. 6(1)(b);
  • GDPR Art. 9(2)(a) – the User's explicit consent.

Consent to process health data is given separately from acceptance of the Terms of Service.

5.3. AI Features

Purpose:

  • recognizing and structuring entries;
  • preparing summaries;
  • identifying possible patterns and correlations;
  • making it easier to add information.

Legal basis:

  • GDPR Art. 6(1)(a) – consent;
  • where the content includes health data: GDPR Art. 9(2)(a) – explicit consent.

Consent to AI Features is required to use the App, and journaling therefore requires this consent — see section 21 for the exact wording of this consent.

5.4. Dictation and microphone access

Purpose:

  • converting speech to text at the User's request.

Legal basis:

  • GDPR Art. 6(1)(a) – consent and the granted system permission;
  • for health-related information, additionally GDPR Art. 9(2)(a).

5.5. Notifications

Purpose:

  • sending reminders set up by the User;
  • communicating important information about the Account or security.

Legal basis:

  • for optional reminders: GDPR Art. 6(1)(a);
  • for necessary communications about the service or security: GDPR Art. 6(1)(b) or (f).

5.6. Security and abuse prevention

Purpose:

  • securing Accounts;
  • detecting unauthorized logins;
  • analyzing outages;
  • preventing attacks and abuse;
  • ensuring the availability of the service.

Legal basis:

  • GDPR Art. 6(1)(f) – the Controller's legitimate interest in protecting the App, its Users, and its infrastructure.

5.7. Handling contact and complaints

Purpose:

  • responding to inquiries;
  • handling complaints;
  • documenting correspondence;
  • establishing, pursuing, or defending against legal claims.

Legal basis:

  • GDPR Art. 6(1)(b), (c), or (f), depending on the nature of the matter.

5.8. Payments and billing

Purpose:

  • verifying purchases;
  • activating premium features;
  • accounting and tax settlement;
  • handling refunds.

Legal basis:

  • GDPR Art. 6(1)(b);
  • GDPR Art. 6(1)(c).

6. Explicit consent for health data

  1. Health data is only processed once the User has given explicit consent.
  2. Consent:
    1. is presented separately from the Terms of Service;
    2. is not pre-ticked;
    3. indicates the purpose and scope of processing;
    4. is recorded together with the date, the version of the text, and how it was given;
    5. may be withdrawn at any time.
  3. Consent can be withdrawn in the App's settings or by contacting the Controller.
  4. Withdrawing consent to health data may require deleting such data and disabling the App's core features.
  5. Withdrawing consent regarding external AI stops new content from being sent to the AI provider, but does not necessarily require deleting the Account or manually added entries.

7. How analysis and profiling work

  1. Digestory may automatically:
    1. classify the content of an entry;
    2. assign information to the relevant categories;
    3. compare entries from specific periods;
    4. calculate how often events occur;
    5. identify statistical or time-based co-occurrence of symptoms and other events;
    6. generate summaries and suggestions for the User to independently verify.
  2. For example, the system may indicate that a particular symptom was logged more often on days when the User also logged a particular meal. This does not amount to establishing a causal relationship or a diagnosis.
  3. The results of this analysis may constitute profiling under the GDPR, but are not used to make decisions about the User that produce legal effects or similarly significantly affect them.
  4. The User may correct entries, delete input data, and choose not to use optional AI analysis.

8. Third-party providers and recipients of data

To the extent necessary for the App to operate, data may be shared with the following categories of recipients.

8.1. Supabase

Role:

  • database;
  • authentication;
  • storage of App data;
  • backend functions, where used.

Scope:

  • Account data;
  • entries;
  • settings;
  • technical data;
  • health data recorded by the User.

Project region: Frankfurt, European Union (aws-eu-central-1).

8.2. Vercel

Role:

  • website hosting;
  • API/backend hosting;
  • running server-side functions;
  • content delivery;
  • technical logs.

Scope:

  • IP address and request metadata;
  • technical identifiers;
  • request content passed through by the backend, where a given feature requires it;
  • logs and diagnostic information.

8.3. OpenAI

Role:

  • providing the AI models used for the "Add your Digestory" feature and AI-based suggestion and summary features.

Scope:

  • the content of the selected entry or transcription;
  • necessary context;
  • the response generated by the model;
  • technical request identifiers.

Connection method: direct API access, without going through Vercel AI Gateway.

Retention: OpenAI's standard retention policy applies (typically up to 30 days, for abuse-detection purposes). The Controller does not currently use Zero Data Retention.

8.4. Anthropic

Role:

  • providing the AI model (Claude) used for the "Add your Digestory" feature and AI-based suggestion and summary features.

Scope:

  • the content of the selected entry;
  • the transcription;
  • necessary context;
  • the model's response.

Provider: Anthropic PBC.

Retention: Anthropic's standard retention policy applies (typically up to 30 days, for abuse-detection purposes). The Controller does not currently use Zero Data Retention.

8.5. Apple and Google

May receive data in their role as Store operators, operating-system providers, and providers of notifications, speech recognition, or payments.

Depending on the service, Apple and Google may act as independent controllers and process data under their own privacy policies.

8.6. Expo

As part of the Expo Push Notifications service, Expo processes the notification token and the technical data needed to deliver messages.

8.7. Other providers

Data may also be shared with:

  • transactional email providers: none separate — login and password-reset emails are sent by Supabase Auth's built-in mechanism;
  • error-monitoring providers: none;
  • analytics providers: none;
  • customer-support providers: no separate tool — contact is by email only;
  • accountants, lawyers, and auditors;
  • public authorities, where disclosure is required by law.

The Controller enters into the required data processing agreements with processors and requires them to ensure an adequate level of protection.

9. Is data used to train AI

  1. The Controller does not use User data to train its own general AI models.
  2. The Controller intends to use business or API tiers of AI providers' services, configured so that transmitted data is not used to train their general models, unless the User separately and knowingly agrees to different use.
  3. The Controller will consider using Zero Data Retention if it becomes available for the plan and provider in use — it currently uses the standard API mode, without that option.
  4. The specific retention mode applicable to the current configuration is set out in the section on providers and the section on retention periods.

10. Transfers of data outside the EEA

  1. Some infrastructure or AI providers are based, or maintain infrastructure, outside the European Economic Area, in particular in the United States.
  2. Transfers of data outside the EEA may rely on:
    1. an adequacy decision issued by the European Commission;
    2. the recipient's participation in the EU–US Data Privacy Framework, where applicable;
    3. Standard Contractual Clauses approved by the European Commission;
    4. other mechanisms permitted by the GDPR.
  3. Where Standard Contractual Clauses are used, the Controller assesses transfer risk and, where necessary, applies supplementary measures such as encryption, data minimization, or pseudonymization.
  4. Information about the safeguards used, or a copy of them, can be obtained by contacting the Controller.

11. Data retention periods

Data is not retained for longer than necessary to achieve the relevant purpose.

  1. Account and entries in the production database — for as long as the Account exists, and for up to 30 days after its deletion, unless a legal obligation requires retaining part of the data for longer.
  2. Backups — for up to 90 days after data is deleted from the production database. Data that exists only in a backup is not used for current purposes and will be deleted again if the backup is ever restored.
  3. Content sent to OpenAI — in line with OpenAI's standard policy, typically up to 30 days for abuse-detection purposes; the Controller does not currently use Zero Data Retention.
  4. Content sent to Anthropic — in line with Anthropic's standard policy, typically up to 30 days for abuse-detection purposes; the Controller does not currently use Zero Data Retention.
  5. Raw audio recordings — not stored by the Controller.
  6. Server and security logs — for 90 days, unless a longer period is necessary to investigate an incident.
  7. Notification tokens — until notifications are disabled, the Account is deleted, or the token is found to be inactive.
  8. Correspondence and complaints — for the duration of handling the matter, and thereafter until any claims become time-barred.
  9. Accounting and transaction records — for the period required by tax and accounting law.
  10. Evidence of consent given or withdrawn — for the period the App is used, and thereafter for as long as needed to demonstrate lawful processing and defend against claims.
  11. If consent is withdrawn, the data covered by that consent will be deleted or anonymized, unless another legal basis for its continued retention exists.

12. Is providing data mandatory

  1. Providing an email address and the data needed for authentication is required to create an Account.
  2. Providing specific health information is voluntary. Not providing it may limit how useful the journal is, but the User decides the scope of their own entries.
  3. Using AI, the microphone, notifications, and NFC requires the relevant consent described in section 21, which is required to use the App.
  4. Declining consent to process health data prevents the Provider from offering the features whose core purpose is storing and analyzing that data.

13. Your rights

In connection with the processing of your data, you may have the following rights:

  1. the right of access to your data;
  2. the right to obtain a copy of your data;
  3. the right to rectify your data;
  4. the right to erase your data;
  5. the right to restrict processing;
  6. the right to data portability;
  7. the right to object to processing based on legitimate interest;
  8. the right to withdraw consent at any time;
  9. the right to obtain information about the safeguards used for transfers outside the EEA;
  10. the right to lodge a complaint with a supervisory authority.

In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO).

Requests can be sent to kontakt@digestory.pl. The Controller may ask for information needed to verify the identity of the person making the request, but will not ask for excessive data.

14. Deleting your Account and data

  1. You can delete your Account directly in the App's settings.
  2. A request to delete your Account can also be submitted by email at kontakt@digestory.pl.
  3. Before deleting an Account, the Controller may verify that the request comes from an authorized person.
  4. Once a request is confirmed:
    1. the Account will be disabled;
    2. data in the active database will be deleted or irreversibly anonymized within 30 days;
    3. data in backups will be overwritten in line with the backup cycle, no later than within 90 days;
    4. notification tokens will be revoked or deleted;
    5. data required by law, or needed to defend against claims, may be retained to a limited extent.
  5. Deleting your Account does not automatically cancel a subscription in the Apple App Store or Google Play.

15. Security

The Controller applies technical and organizational measures appropriate to the nature and risk of processing, including — subject to their actual implementation:

  • encrypting transmissions using HTTPS/TLS;
  • access control and authentication;
  • restricting permissions on a least-privilege basis;
  • mechanisms isolating individual Users' data;
  • encrypting or otherwise securing data stored by infrastructure providers;
  • managing secrets and API keys;
  • logging security events;
  • backups and restoration procedures;
  • security updates;
  • periodic reviews of permissions and providers;
  • an incident-response procedure;
  • testing and evaluating the effectiveness of safeguards;
  • minimizing the scope of data sent to AI.

No method of transmitting or storing data can guarantee the complete elimination of risk. In the event of a personal data breach, the Controller will take the steps required by the GDPR.

16. Selling data, advertising, and marketing

  1. The Controller does not sell Users' personal data.
  2. Health data is not used for:
    1. behavioral advertising;
    2. marketing targeting;
    3. determining creditworthiness;
    4. insurance-related profiling;
    5. trading in databases.
  3. The App currently does not display advertising. Any future decision to enable advertising will be preceded by an update to this Policy and, where required, the User's appropriate consent.
  4. Introducing marketing communications would require separately informing the User and, where required, separate consent.

17. Children

  1. Digestory is not intended for children under 16.
  2. The Controller does not knowingly collect data from such persons without appropriate consent or a guardian's authorization.
  3. If a parent or guardian believes a child under 16 has created an Account, they should contact the Controller.
  4. Given the sensitive nature of the data, the Controller may apply proportionate age-verification mechanisms.

18. The digestory.pl website

  1. The digestory.pl website is informational in nature.
  2. The website does not use marketing cookies or client-side analytics tools.
  3. Regardless of the above, the hosting provider may automatically process IP addresses, request headers, the date and time of connections, and basic technical logs in order to serve the website, protect against attacks, and diagnose errors.
  4. If analytics, marketing tools, or non-essential cookies are introduced in the future, this Policy will be updated and the User will be given an appropriate consent mechanism.

19. Changes to this Policy

  1. This Policy may be updated, in particular in connection with changes to the law, providers, functionality, processing methods, or security measures.
  2. The User will be notified of material changes in the App, by email, or on the website before the changes take effect.
  3. If a change requires new consent, the related processing will not begin until that consent has been given.
  4. Archived versions of this Policy should be kept by the Controller together with the dates they were in effect.

20. Contact

For matters relating to privacy, data protection, withdrawing consent, or exercising your rights, you can contact the Controller:

email: kontakt@digestory.pl
address: ul. Jedności 3, 43-245 Studzionka, Poland

21. Consents given during registration

The following sections describe in detail the two separate consents the App asks for when creating an Account.

21.1. Explicit consent for health data

Digestory records information that may relate to your health, including symptoms, meals, bowel movements, sleep, stress, wellbeing, medication, and your own notes. This data is used to keep your private journal and to create summaries and charts.

Consent text: "I give my explicit consent for Michał Konieczny Usługi Programistyczne to process my health data in order to manage my account and provide Digestory's journaling features."

This consent is required to use the App — without it, an Account cannot be created. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, but it will prevent further use of the journal and will result in the Account being deleted.

21.2. Separate consent to share data with third-party AI providers

When you use the "Add your Digestory" feature or AI analysis features, the content of the selected entry, its transcription, and any necessary context may be sent to OpenAI and Anthropic. This data is used to recognize and organize the entry, or to prepare a summary, and may be processed outside the European Economic Area. See sections 8 and 11 for details, including retention periods.

Consent text: "I give my explicit consent for the content of the entries I select, which may include health data, to be shared with the listed AI providers in order to perform the "Add your Digestory" feature and AI analysis features."

This consent is required to use the App — without it, an Account cannot be created. AI outputs may be inaccurate and do not constitute a diagnosis or medical advice.

Digestory. Your digestive story.

Terms of ServicePrivacy PolicyContact

© 2026 Digestory. All rights reserved.