Version 2026-09 · In effect 6 September 2026
Data & Privacy
What is stored, why, and who can see it.
Idia Solution is the controller of the personal data you enter into Healthidia-GLP 1. Billing and invoicing are carried out by ASM Professional Services, KVK Number: 42137630, VAT ID NL005526019B33. Contact us about privacy at support@healthidiaglp.com.
We store: your account details (email, sign-in method, registered passkeys and devices); your baseline profile (age, sex, height, weight, activity, goals); health information (medical conditions, GLP-1 medicine and dose history, symptoms, allergies and intolerances, weight and measurement history); your food data (plans, meal ticks, logged food, portions, fluid intake, shopping lists); your settings (reminder times, timezone, quiet hours, language, optional mobile number); the consents you gave and when; and basic technical logs needed to keep the service secure and working.
We use this data only to run the service for you: to build and adapt your plan and targets, to show your progress and audit, to send the reminders and emails you switch on, to answer messages you send us, and to keep the service secure. We do not use it for advertising, we do not sell it, and we do not profile you for anyone else.
Our legal bases are: performing our agreement with you (running your account and plans), your explicit consent for health data, optional reminders, optional analytics cookies and AI photo analysis, and our legitimate interest in keeping the service secure. You can withdraw consent at any time; withdrawing it does not affect what happened before.
Processors that handle data on our behalf, under contract and only on our instructions: Supabase (database, authentication and hosting of your account data), Cloudflare (site delivery), Google Gemini via the Lovable AI Gateway (food photo analysis only), Resend (transactional and contact emails) and Twilio (only if you switch on SMS reminders and provide a mobile number). Data may be processed outside your country; where that happens we rely on the standard contractual clauses or an equivalent safeguard.
We keep your program data for as long as your account exists. If you delete your account we remove your program, health and consent data within 30 days, except where we must keep limited records to meet a legal obligation or to resolve a dispute. Emails you send us are kept for up to 24 months. Security logs are kept for up to 12 months.
You can access, export and permanently delete your health and consent data yourself from the Profile screen. You also have the right to correct your data, restrict or object to processing, withdraw consent, and complain to your local data protection authority. Write to support@healthidiaglp.com and we will respond within 30 days.
The app is for adults. We do not knowingly collect data from anyone under 18; tell us if you believe a child has created an account and we will delete it.
We protect your data with encryption in transit, encryption at rest, per-account access rules that stop any other account reading your records, and passkey or password authentication. No system is perfectly secure; if a breach affects your rights we will tell you and the relevant authority as required by law.
