DiabetesIQ Privacy Policy
Effective date: July 28, 2026
Operator: StayHealthy, Inc. ("StayHealthy", "we", "us"), United States — stayhealthy.com
This document also serves as the Consumer Health Data Privacy Policy required by Washington's My Health My Data Act and similar state laws.
DiabetesIQ is a wellness app. We are not a healthcare provider, health plan, or medical device, and DiabetesIQ is not covered by HIPAA. Instead, your data is protected by this policy, by federal consumer-protection law (including the FTC Health Breach Notification Rule), and by state consumer health data laws. We wrote this policy in plain English on purpose — if anything is unclear, ask us.
The short version
- We collect only what the app needs to work: your account, your glucose readings, your meals and photos, and your chats with Emma.
- We never sell your health data. We never use it for advertising. No exceptions, and no consent screen will ever ask you to allow it.
- DiabetesIQ is currently free. We collect no payment information of any kind.
- AI processing (Emma's coaching, meal-photo analysis) happens only if you opt in, and you can turn it off anytime.
- You can export everything or delete everything, whenever you want, from Settings.
- You must be 18 or older to use DiabetesIQ.
1. What we collect
| Category | What it is | Why |
|---|---|---|
| Account | Email, name, password (stored as a secure hash) | Sign-in, account security |
| Profile | Diabetes type (Type 1, Type 2, or gestational), preferred units, target glucose range, coaching style preferences | To personalize the app |
| Glucose readings | Values you log, with timing context (fasting, post-meal, etc.) and optional notes | Tracking, trends, time-in-range |
| Meals | What you logged, carbs/fiber/protein estimates, meal scores, and — if you choose — a photo of the meal | Meal scoring and nutrition insights |
| Emma chats | Your messages and Emma's replies | So your coaching conversation has memory |
| Technical basics | IP address and device/browser info from server logs, session cookies | Security, fraud prevention, keeping you signed in |
DiabetesIQ is free: we collect no payment or billing information. We do not collect precise location, we do not use geofencing, and we do not use advertising trackers or ad SDKs.
2. Your consent
We ask for your permission before collecting your health information, during onboarding:
- Core health data consent — required to use the app: your permission for us to collect and store the glucose, meal, and chat data you log, solely to run DiabetesIQ for you.
- AI processing consent (optional) — lets our AI service provider process your logged data so Emma can coach you.
- AI photo consent (optional, separate) — lets our AI service provider analyze your meal photos to recognize foods.
- Marketing email consent (optional, separate) — if you tick the box at signup (or turn it on later in Settings), we may send occasional product updates and diabetes-friendly tips to your account email. The lawful basis is your consent. These emails are never personalized using — and never contain — your glucose readings, meals, chats, or any other health data, and we never sell or share your email or health data with advertisers or data brokers. Every email includes an unsubscribe link.
- Research contribution consent (optional, separate, off by default) — if you turn on "Contribute to diabetes research" in Settings, your logged data may be included, only after de-identification, in datasets used for diabetes and nutrition research, which may be commercial. In plain terms:
- What's included: your glucose readings, meals and their nutrition estimates, meal scores, and basic profile facts (such as age range, sex, diabetes type, medication classes, and A1C), plus app-usage patterns.
- What's never included: your name, email, exact address or location, meal photos, and your Emma conversations.
- Who it may go to: academic researchers, medical device and CGM makers, pharmaceutical companies, health insurers, and food or nutrition companies — always under contracts that prohibit re-identifying anyone, linking the data with other datasets to identify people, or passing the data onward.
- De-identification standard: the HIPAA Expert Determination method (a statistician certifies the re-identification risk is very small before anything leaves us).
- Voluntary: contributing is never a condition of using DiabetesIQ, and saying no changes nothing about your app.
- Withdrawal: turn it off anytime in Settings. Future sharing stops immediately. One honest limit: de-identified data already included in a dataset that has been shared cannot be recalled, because we can no longer tell which records are yours.
- Not a sale of identifiable data: we never sell identifiable health data, with or without this consent, and this consent does not permit it. Every consent decision is recorded with a timestamp and the version of this policy in effect, and this record is retained.
You can withdraw any consent anytime in Settings → Privacy. Withdrawing AI consent turns those features off but keeps the rest of the app working.
3. How AI is used (and disclosed)
Emma is an artificial-intelligence coach, not a human and not a medical professional. If you opt in, your relevant logged data (and, with separate consent, meal photos) is sent to our AI service provider — a company we contract with to run large-language-model processing — solely to generate your coaching responses and food recognition. Under our contract, your data may not be sold, used for advertising, or used to train their models. The numbers you see in the app (meal scores, confidence percentages, time-in-range, estimated A1C) are computed by DiabetesIQ's own tested software, not by the AI.
Emma will never give insulin dosing, medication, or diagnosis advice — those topics are blocked by design. For medical decisions, always talk to your care team.
4. Who we share data with (and who we don't)
We share personal data only with service providers under contract who need it to run the app for you:
- Hosting and database providers — run the app and store its data, encrypted in transit and at rest.
- AI provider — only with your opt-in consent (Section 3).
- Email provider — account emails (verification, security notices).
We do not sell personal data (health or otherwise). We do not share health data with advertisers, data brokers, or analytics networks. With your separate opt-in research consent (Section 2.5), de-identified data may additionally be shared with research partners under the strict conditions described there.
If we are ever acquired or merged: your data may only transfer to an organization that
agrees in writing to be bound by this policy's promises, we will notify you before the transfer, and you will have a window to delete your account first if you prefer.
Legal requests: we only disclose data in response to valid legal process, we disclose the minimum required, and we will notify you unless the law forbids it.
5. Your rights
Everyone gets these rights, regardless of which state you live in:
- Access / export — download a complete, machine-readable copy of your data from Settings → Privacy → Export my data.
- Deletion — delete your account and all your data from Settings → Privacy → Delete my account. Deletion completes within 30 days, including at our service providers; backup copies are purged on our next backup rotation (35 days or less).
- Correction — edit or delete any individual reading, meal, or chat in the app.
- Withdraw consent — Settings → Privacy, anytime.
- Ask questions or complain — contact us through stayhealthy.com. We respond within 45 days. You may also use an authorized agent to submit requests on your behalf. If we refuse a request, we'll explain why and you may appeal by replying to our decision; you can also contact your state Attorney General.
We will never discriminate against you (deny features, charge more) for exercising these rights.
6. How long we keep things
| Data | Kept |
|---|---|
| Account, glucose, meals, chats | While your account is active, or until you delete them |
| Meal photos | 18 months, then automatically deleted (the meal's nutrition results stay) |
| Access audit records | 2 years (security) |
| Backups | Rotated within 35 days |
7. Security
Health data deserves real security: encryption in transit (TLS) and at rest, per-user data isolation enforced in our data layer, access audit logging, server-side-only AI keys, and no health data in our application logs or analytics. No system is perfect — if a breach ever affects your unsecured health data, we will notify you promptly (within 60 days at most) and notify the FTC as the Health Breach Notification Rule requires.
8. Age requirement
DiabetesIQ is for adults 18 and older. We do not knowingly collect data from anyone under 18, and we block account creation for minors. If you believe a minor has an account, contact us through stayhealthy.com and we will delete it.
9. A note for users with gestational diabetes
Pregnancy-related health information is among the most sensitive data there is, and several state laws give it extra protection. We treat it accordingly: we never use it for marketing, never infer pregnancy outcomes, and prioritize deletion requests. Everything in Sections 4–6 applies with full force.
10. Where this applies, and changes
DiabetesIQ is offered in the United States. This policy is designed to satisfy the consumer health data laws of Washington, Nevada, Connecticut, Maryland, and other states — we apply the strictest protections to all users rather than varying by state. If we change this policy in a way that affects your health data, we will ask for fresh consent before the change applies to you — we won't just quietly update a date.
Contact: StayHealthy, Inc. · stayhealthy.com