Privacy Policy
Last updated: 27 September 2026
1. Who is responsible
The controller for the AcidLog app and this website (acidlog.djump.io) is DJUMP, MB, Šilutės pl. 35G-36, LT-94105 Klaipėda, Lithuania (registration code 307521980, Register of Legal Entities of Lithuania), represented by its director Donaldas Jautzemis. Email: start@djump.io.
2. The short version
- Without an account, your food and symptom diary never leaves your phone.
- With an account, your diary is synced to our database in Ireland (EU) — from app version 1.0.4, only after you have given your explicit consent (see 3.1 for accounts created earlier).
- From app version 1.0.4, usage analytics run only if you opt in (earlier versions: see 3.4). They never contain what you ate, which symptoms you had, or your email address.
- The trigger analysis runs on your device. There are no ads, we do not sell data, and we do not track you across other apps or websites.
- You can delete your account and diary in the app at any time.
3. The AcidLog app
3.1 Your diary (health data)
The diary consists of your meals (time, meal type, the foods you pick, an optional note) and your symptoms (time, symptom type such as heartburn or regurgitation, severity 1–5, an optional note). Because it says something about your health, the GDPR treats it as a special category of personal data (Art. 9 GDPR).
- Guest mode (no account): the diary is stored only on your device. We do not receive it and cannot see it.
- With an account: the diary is stored in our database (Supabase, hosted in Ireland) so it is backed up and available on every device you sign in on. When you create an account or sign in, entries you logged as a guest on that device are moved into it. Legal basis: your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR), which the app asks for with a separate checkbox when you create the account, and the contract with you for the account itself (Art. 6(1)(b) GDPR). If you do not consent, you can keep using AcidLog in guest mode.
- Withdrawing consent: delete your account in the app (see section 7). Your synced diary is deleted from our database immediately. Withdrawal does not affect processing that happened before it. If you created your account before the consent checkbox existed and do not want your diary stored on our servers, delete your account or write to us and we will delete it.
The correlation between meals and symptoms — your trigger list — is calculated on your device, not on our servers. The doctor PDF report (Pro) is also created on your device; it only goes where you choose to send it through your phone's share sheet. We do not look at individual diaries, except where you ask us to (for example in a support request) or the law requires it.
3.2 Account and sign-in
An account is optional. You can sign in with an email address and password, with Sign in with Apple, or with Google. Sign-in is handled by Supabase Auth. We store your email address, your name if you give one (or your sign-in provider shares it), the provider's user ID, and — for email sign-in — your password as a one-way hash. Supabase Auth sends the emails needed for sign-in, such as address confirmation and password reset. For Sign in with Apple we also keep a token issued by Apple, solely so we can revoke your Apple sign-in when you delete your account, as Apple requires. Legal basis: contract (Art. 6(1)(b) GDPR).
AcidLog shares its sign-in system with other apps made by DJUMP, MB, so one email address and password can work in several of them. Each app's data is kept separately.
3.3 Purchases (AcidLog Pro)
Pro is a monthly or yearly subscription bought through the App Store or Google Play. Apple or Google processes the payment; we never receive your card or bank details. We use RevenueCat to check whether a subscription is active. RevenueCat receives a purchaser ID (your account ID when you are signed in, otherwise a random ID), your purchase and subscription status from Apple or Google, and basic device and app details. Legal basis: contract (Art. 6(1)(b) GDPR).
3.4 Usage analytics (PostHog) — only if you opt in
The app asks during onboarding whether you want to share usage analytics, and you can change your answer at any time in Settings. Until you opt in, nothing is sent to PostHog. If you opt in, the app sends events about how it is used — for example which screens you open, that a meal or a symptom was logged (not which one), that a trigger was found and its confidence level, and steps of the purchase flow — together with the app version, device type and operating system, and an approximate location (country, region, city) that PostHog derives from your IP address; the IP address itself is not stored. Events carry a random analytics ID and, while you are signed in, your account's internal ID. They never contain the foods you ate, your symptoms, their severity, your notes, or your email address.
We use PostHog's EU hosting (eu.i.posthog.com, Frankfurt, Germany). Legal basis: your consent (Art. 6(1)(a) GDPR; for access to your device, the national rules implementing the ePrivacy Directive, e.g. § 25(1) TDDDG in Germany). Withdraw it any time by switching analytics off in Settings. Versions of the app released before this opt-in existed sent these events without asking first; if you used such a version, update the app, and email us if you want the analytics data already collected deleted.
3.5 Crash reports (Sentry)
When the app crashes or hits an error, it sends a crash report to Sentry (EU region, Frankfurt, Germany). A report contains the error and where in the code it happened, the app version, device model and operating system, and a short trail of recent technical events: screens opened, the names of app components tapped, and the web addresses of recent requests to our database, which include your account's internal ID and a date range. Sentry also receives a signal when an app session starts and ends, so we can see how often the app crashes. Reports contain no name or email address, and never the content of your diary. Legal basis: our legitimate interest in a working, secure app (Art. 6(1)(f) GDPR). You can object at any time by email.
3.6 Reminders and notifications
The optional daily reminder is scheduled on your device. If you allow notifications, the app also obtains a push token from Expo's push service and, when you are signed in, stores it with your profile. Legal basis: your consent, given through your phone's notification permission (Art. 6(1)(a) GDPR); you can withdraw it in your phone's settings.
3.7 App updates
To deliver fixes without a full store update, the app checks Expo's update service when it starts. That request contains a random installation ID, the platform, the app version and your IP address. Legal basis: legitimate interest in keeping the app working and secure (Art. 6(1)(f) GDPR).
3.8 What stays on your device
The app stores on your phone what it needs to work: your diary (as a guest, or as an offline copy with an account), entries waiting to sync, a random guest ID, your settings and, when signed in, your session. This storage is strictly necessary for the service you asked for. Signing out removes the account's diary copy from the device.
4. This website
- Hosting: the site is hosted by Vercel. Serving a page necessarily involves your IP address, the requested address, time and browser details, which Vercel logs briefly for delivery and security. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Website analytics: we count page views with Vercel Web Analytics. It sets no cookies and stores nothing on your device; it records the page, referrer, browser, operating system, device type and country, and tells visitors apart by a hash of the request that is discarded after 24 hours. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). The website does not load PostHog, advertising or social-media trackers, and its fonts are served from this site, not from Google.
- Contact form: your name, email address and message are passed through our server function on Vercel and emailed to our inbox by Resend. We use them only to answer you. Legal basis: legitimate interest in answering your request, or steps before a contract (Art. 6(1)(f) and (b) GDPR). Please do not include health details unless they are needed for your question.
- No cookies are set by this website.
5. Who receives data
We use the following service providers. Except for Apple and Google, they process data on our behalf under data processing agreements. Apple and Google act as independent controllers for sign-in and payments under their own privacy policies.
| Recipient | Purpose | Data | Location and transfer safeguard |
|---|---|---|---|
| Supabase Pte. Ltd. | Database, sign-in, server functions | Account data, diary entries of account users, profile settings, push token, Apple revocation token | Ireland, EU (AWS eu-west-1). Any support access from outside the EEA: Standard Contractual Clauses |
| PostHog Inc. | Usage analytics — only after opt-in | Usage events, device and app details, approximate location, analytics ID, account ID | Frankfurt, Germany, EU (PostHog EU Cloud). US company: Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Crash and error reports | Error details, device and app details, recent technical events, account ID | Frankfurt, Germany, EU (Sentry EU region). US company: Standard Contractual Clauses / EU–US Data Privacy Framework |
| RevenueCat, Inc. | Subscription status | Purchaser ID, purchases and subscription status, device and app details | USA: Standard Contractual Clauses / EU–US Data Privacy Framework |
| 650 Industries, Inc. (Expo) | App updates, push token | Installation ID, platform, app version, IP address, push token | USA: Standard Contractual Clauses / EU–US Data Privacy Framework |
| Vercel Inc. | Website hosting, contact-form function, website analytics | Server logs, page views, contact-form content in transit | USA and global edge network: Standard Contractual Clauses / EU–US Data Privacy Framework |
| Plus Five Five, Inc. (Resend) | Delivering contact-form messages to us | Name, email address, message | USA: Standard Contractual Clauses / EU–US Data Privacy Framework |
| Apple | Sign in with Apple, App Store purchases | Sign-in data, purchases | Independent controller (Apple privacy policy) |
| Sign in with Google, Google Play purchases | Sign-in data, purchases | Independent controller (Google privacy policy) |
Where a provider relies on the EU–US Data Privacy Framework, this applies only while it is certified; otherwise the Standard Contractual Clauses (Art. 46(2)(c) GDPR) apply. We do not sell personal data, share it with advertisers, or use it to train AI models.
6. How long we keep data
- Guest diary: on your device until you delete the entries or the app.
- Account diary and account data: for as long as the account exists. Deleting an entry or the account removes it from our database immediately; routine encrypted backups roll off automatically within 30 days.
- Your sign-in (email address, name, sign-in provider link): deleted together with your AcidLog account, unless you still use another DJUMP app with the same sign-in — then it stays for that app.
- Crash reports: deleted by Sentry automatically after at most 90 days.
- Usage analytics: kept until we delete them. Deleting your account does not delete them automatically — email us and we will.
- Subscription records: RevenueCat keeps them while they are needed to manage your subscription; we delete them on request. Apple and Google keep their own transaction records as the law requires them to.
- Contact messages: as long as needed to handle your request and any follow-up.
- Website: hosting logs are kept by Vercel only briefly; the analytics visitor hash is discarded after 24 hours.
7. Deleting your account
In the app: Profile → Settings → Delete Account. This immediately deletes every meal and symptom entry of your account from our database. If you signed in with Apple, your Apple sign-in token is revoked with Apple. Your sign-in itself is deleted too, unless you still use another DJUMP app with it. On the device, the app returns to an empty guest diary. If you no longer have the app, see acidlog.djump.io/delete-account. A subscription is not cancelled by deleting the account — cancel it in your App Store or Google Play settings.
8. Your rights
Under the GDPR you have the right to access your data, to have it corrected or deleted, to restrict its processing, to receive it in a portable format, and to object to processing based on legitimate interest (Art. 15–18, 20 and 21 GDPR). Where processing is based on your consent, you can withdraw it at any time with effect for the future (Art. 7(3) GDPR). Write to start@djump.io.
You also have the right to lodge a complaint with a supervisory authority — ours is the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt) — or with the authority where you live or work.
9. Security
All connections between the app, this website and our servers are encrypted (TLS). In the database, row-level security ties every diary entry to its owner's account, so one account cannot read another's entries.
10. Children
AcidLog is meant for adults and is not directed at children under 16. We do not knowingly process children's data; if you believe a child has given us data, contact us and we will delete it.
11. Automated decisions
We make no decisions about you based solely on automated processing (Art. 22 GDPR). The trigger list is a statistical calculation on your device that you are free to ignore.
12. Changes and other languages
If what the app or website does with personal data changes, we update this page and its date, and announce material changes in the app. This policy is also available in German.