Dietten

Privacy Policy

Last updated:

Effective date:

About this policy

This policy was prepared with Google Play and KVKK requirements in mind. Before publication, it should be compared with current contact information and data-processing practices and reviewed by a qualified professional when necessary.

1. Data controller and scope

Dietten is an Android application that helps dietitians and clients manage nutrition plans, meal tracking, progress records, messaging, and appointments.

This policy covers the Dietten mobile application, in-app accounts and services, and web pages connected to Dietten.

Data controller: Dietten

Address: İstanbul, Türkiye

Contact: help@dietten.com

2. Categories of data we process

Depending on how you use the service and the permissions you grant, we may process the following data:

  • Account and identity information: full name, email address, phone number, user role, session, and account-security information.
  • Dietitian-client relationship information: invite code, active relationship, assignment, and connection status.
  • Nutrition and health information: blood type, allergies, dietary preferences and restrictions, chronic conditions or complaints, medication and supplement information, pregnancy or breastfeeding information, body measurements, weight, water and activity records, goals, and meal records.
  • Health documents: blood tests, laboratory results, health profiles, or similar PDFs and images uploaded by a client.
  • Communications and content: chat messages, photos, voice messages, diet plans, recipes, reviews, and support requests.
  • Appointment and progress information: appointment date, meeting type, meeting link or location description, weight, and progress records.
  • Technical information: app version, device and operating-system information, session-security information, and device tokens for notifications. Camera, microphone, and gallery access is used only when you use the relevant feature.

Dietten does not request location history, contacts, SMS, or call records. Permissions not used by the app should not be requested.

3. Health and special-category data

Health and nutrition information is sensitive personal data. We process it only for Dietten's service purposes, to the extent necessary, and on a legal basis permitted by applicable law. Explicit consent is obtained where required.

Dietten does not diagnose, provide emergency healthcare, or replace a doctor's examination. Users should contact an appropriate healthcare professional for symptoms, diagnoses, medication, pregnancy, or emergencies.

4. How do we use data?

We use data to:

  • create accounts, enable sign-in, and provide account security;
  • manage the active service relationship between a client and a dietitian;
  • provide personalized diet plans, meal tracking, and progress features;
  • share health documents and diet programs between authorized users;
  • provide messaging, appointment, and notification services;
  • respond to support requests, investigate errors, and protect service security;
  • comply with legal obligations, prevent disputes, and exercise our rights.

We do not sell personal or health data. We do not use data to build behavioral advertising profiles or target advertising based on health data.

5. Security and end-to-end encryption for health documents

Critical documents such as blood tests and laboratory results are encrypted on the device when the app's secure document-retrieval feature is enabled. In this flow:

  1. Document content is encrypted on the device using AES-GCM.
  2. The document-specific encryption key is protected with the relevant dietitian's RSA-OAEP public key.
  3. Encrypted content is uploaded only to restricted-access Storage.
  4. The server stores encrypted content and an encrypted key, not readable document content.
  5. The dietitian can view the document after unlocking the key on their device with a security PIN.

When this secure flow is used, a database or Storage administrator cannot read the document content alone. The raw PIN is not sent to the server; a PIN-derived value and a server-protected secret component are used together.

End-to-end encryption is limited to this secure document flow. This guarantee applies only to documents uploaded through the secure document flow and marked as encrypted in the app. Other structured health fields, such as weight, allergies, or health-profile fields, are not end-to-end encrypted; they are protected through authentication, Row Level Security, and relationship checks. Ordinary chat, meal, and profile media do not have the same end-to-end encryption guarantee.

6. Who can access data?

  • A client can access their own account and records.
  • A dietitian with an active relationship can access the client profile, health summary, meals, and document records needed to provide the service, subject to the app's authorization rules.
  • The client and dietitian can access their chat and shared content.
  • Hosting, database, Storage, authentication, and notification providers used to operate Dietten may process data only to provide the service and under contractual and security controls.

We do not share user data with unauthorized third parties unless legally required or necessary for security or dispute processes.

7. Service providers and international transfers

We may use the following types of service providers to operate the app:

  • Supabase: authentication, database, restricted Storage, and server functions;
  • Firebase Cloud Messaging: notification delivery and device notification-token management;
  • USDA FoodData Central: nutrition-data queries for food search;
  • Google or similar sign-in providers: authentication if you choose that sign-in method.

These providers may operate infrastructure outside Türkiye. Transfers are assessed under applicable international-transfer requirements and contractual and technical safeguards. The data controller may update the current list of subprocessors and transfer mechanisms when necessary.

8. Security measures

We apply reasonable and appropriate technical and administrative measures to protect data. These include encrypted network communication, session authentication, role- and relationship-based access, restricted Storage, Row Level Security, device-side encryption for sensitive documents, encrypted rather than plaintext key storage, and an account-deletion flow.

No internet or storage system is completely risk-free. If unauthorized access or a security incident is detected, notification and remediation processes will be applied in accordance with applicable law.

9. Retention and deletion

Data is retained for as long as necessary to provide the service or while the relevant person's account remains active. After an account-deletion request, account-linked records and Storage content are deleted or anonymized as soon as technically possible, subject to legal retention duties.

Copies remaining in backup systems may be automatically deleted during the applicable backup cycle. Some records may be retained longer because of a dispute, security incident, or legal obligation.

10. User rights

To the extent permitted by applicable law, you have the right to:

  • learn whether your data is being processed,
  • request information about processed data,
  • request correction of inaccurate or incomplete data,
  • request deletion or destruction,
  • request restriction of processing,
  • request compensation for damage caused by unlawful processing,
  • exercise other rights granted by law

You may send requests with information sufficient for identity verification to help@dietten.com. Additional verification may be requested depending on the request. Applications are answered within the periods required by applicable law.

11. Account deletion

You can delete your account from the account/profile settings in the app. Account deletion starts the deletion of app data, relationships, and Storage content linked to your account. Records that must be retained by law may be kept for the applicable period.

To request account deletion through the web, use the account deletion page.

12. Children's privacy

Dietten is not designed specifically for children. Use by minors should take place with the consent of a parent or legal representative and in accordance with applicable rules. Age or audience rules may be updated based on the app version and service model.

13. Policy changes

This policy may be updated if our services, data-processing purposes, or legal obligations change. Material changes will be announced through the app or appropriate communication channels. The current version is published on this page.

14. Contact

For privacy, data security, or rights requests:

Data controller: Dietten

Address: İstanbul, Türkiye

Contact: help@dietten.com

This policy does not replace a user agreement or medical-consulting agreement. Required warnings and explicit-consent flows for the app's health-related features are shown separately in the app.

Official frameworks referenced