Privacy Policy

Last updated: 27 September 2026

1. Who is responsible

The controller for the AcidLog app and this website (acidlog.djump.io) is DJUMP, MB, Šilutės pl. 35G-36, LT-94105 Klaipėda, Lithuania (registration code 307521980, Register of Legal Entities of Lithuania), represented by its director Donaldas Jautzemis. Email: start@djump.io.

2. The short version

3. The AcidLog app

3.1 Your diary (health data)

The diary consists of your meals (time, meal type, the foods you pick, an optional note) and your symptoms (time, symptom type such as heartburn or regurgitation, severity 1–5, an optional note). Because it says something about your health, the GDPR treats it as a special category of personal data (Art. 9 GDPR).

The correlation between meals and symptoms — your trigger list — is calculated on your device, not on our servers. The doctor PDF report (Pro) is also created on your device; it only goes where you choose to send it through your phone's share sheet. We do not look at individual diaries, except where you ask us to (for example in a support request) or the law requires it.

3.2 Account and sign-in

An account is optional. You can sign in with an email address and password, with Sign in with Apple, or with Google. Sign-in is handled by Supabase Auth. We store your email address, your name if you give one (or your sign-in provider shares it), the provider's user ID, and — for email sign-in — your password as a one-way hash. Supabase Auth sends the emails needed for sign-in, such as address confirmation and password reset. For Sign in with Apple we also keep a token issued by Apple, solely so we can revoke your Apple sign-in when you delete your account, as Apple requires. Legal basis: contract (Art. 6(1)(b) GDPR).

AcidLog shares its sign-in system with other apps made by DJUMP, MB, so one email address and password can work in several of them. Each app's data is kept separately.

3.3 Purchases (AcidLog Pro)

Pro is a monthly or yearly subscription bought through the App Store or Google Play. Apple or Google processes the payment; we never receive your card or bank details. We use RevenueCat to check whether a subscription is active. RevenueCat receives a purchaser ID (your account ID when you are signed in, otherwise a random ID), your purchase and subscription status from Apple or Google, and basic device and app details. Legal basis: contract (Art. 6(1)(b) GDPR).

3.4 Usage analytics (PostHog) — only if you opt in

The app asks during onboarding whether you want to share usage analytics, and you can change your answer at any time in Settings. Until you opt in, nothing is sent to PostHog. If you opt in, the app sends events about how it is used — for example which screens you open, that a meal or a symptom was logged (not which one), that a trigger was found and its confidence level, and steps of the purchase flow — together with the app version, device type and operating system, and an approximate location (country, region, city) that PostHog derives from your IP address; the IP address itself is not stored. Events carry a random analytics ID and, while you are signed in, your account's internal ID. They never contain the foods you ate, your symptoms, their severity, your notes, or your email address.

We use PostHog's EU hosting (eu.i.posthog.com, Frankfurt, Germany). Legal basis: your consent (Art. 6(1)(a) GDPR; for access to your device, the national rules implementing the ePrivacy Directive, e.g. § 25(1) TDDDG in Germany). Withdraw it any time by switching analytics off in Settings. Versions of the app released before this opt-in existed sent these events without asking first; if you used such a version, update the app, and email us if you want the analytics data already collected deleted.

3.5 Crash reports (Sentry)

When the app crashes or hits an error, it sends a crash report to Sentry (EU region, Frankfurt, Germany). A report contains the error and where in the code it happened, the app version, device model and operating system, and a short trail of recent technical events: screens opened, the names of app components tapped, and the web addresses of recent requests to our database, which include your account's internal ID and a date range. Sentry also receives a signal when an app session starts and ends, so we can see how often the app crashes. Reports contain no name or email address, and never the content of your diary. Legal basis: our legitimate interest in a working, secure app (Art. 6(1)(f) GDPR). You can object at any time by email.

3.6 Reminders and notifications

The optional daily reminder is scheduled on your device. If you allow notifications, the app also obtains a push token from Expo's push service and, when you are signed in, stores it with your profile. Legal basis: your consent, given through your phone's notification permission (Art. 6(1)(a) GDPR); you can withdraw it in your phone's settings.

3.7 App updates

To deliver fixes without a full store update, the app checks Expo's update service when it starts. That request contains a random installation ID, the platform, the app version and your IP address. Legal basis: legitimate interest in keeping the app working and secure (Art. 6(1)(f) GDPR).

3.8 What stays on your device

The app stores on your phone what it needs to work: your diary (as a guest, or as an offline copy with an account), entries waiting to sync, a random guest ID, your settings and, when signed in, your session. This storage is strictly necessary for the service you asked for. Signing out removes the account's diary copy from the device.

4. This website

5. Who receives data

We use the following service providers. Except for Apple and Google, they process data on our behalf under data processing agreements. Apple and Google act as independent controllers for sign-in and payments under their own privacy policies.

RecipientPurposeDataLocation and transfer safeguard
Supabase Pte. Ltd.Database, sign-in, server functionsAccount data, diary entries of account users, profile settings, push token, Apple revocation tokenIreland, EU (AWS eu-west-1). Any support access from outside the EEA: Standard Contractual Clauses
PostHog Inc.Usage analytics — only after opt-inUsage events, device and app details, approximate location, analytics ID, account IDFrankfurt, Germany, EU (PostHog EU Cloud). US company: Standard Contractual Clauses
Functional Software, Inc. (Sentry)Crash and error reportsError details, device and app details, recent technical events, account IDFrankfurt, Germany, EU (Sentry EU region). US company: Standard Contractual Clauses / EU–US Data Privacy Framework
RevenueCat, Inc.Subscription statusPurchaser ID, purchases and subscription status, device and app detailsUSA: Standard Contractual Clauses / EU–US Data Privacy Framework
650 Industries, Inc. (Expo)App updates, push tokenInstallation ID, platform, app version, IP address, push tokenUSA: Standard Contractual Clauses / EU–US Data Privacy Framework
Vercel Inc.Website hosting, contact-form function, website analyticsServer logs, page views, contact-form content in transitUSA and global edge network: Standard Contractual Clauses / EU–US Data Privacy Framework
Plus Five Five, Inc. (Resend)Delivering contact-form messages to usName, email address, messageUSA: Standard Contractual Clauses / EU–US Data Privacy Framework
AppleSign in with Apple, App Store purchasesSign-in data, purchasesIndependent controller (Apple privacy policy)
GoogleSign in with Google, Google Play purchasesSign-in data, purchasesIndependent controller (Google privacy policy)

Where a provider relies on the EU–US Data Privacy Framework, this applies only while it is certified; otherwise the Standard Contractual Clauses (Art. 46(2)(c) GDPR) apply. We do not sell personal data, share it with advertisers, or use it to train AI models.

6. How long we keep data

7. Deleting your account

In the app: Profile → Settings → Delete Account. This immediately deletes every meal and symptom entry of your account from our database. If you signed in with Apple, your Apple sign-in token is revoked with Apple. Your sign-in itself is deleted too, unless you still use another DJUMP app with it. On the device, the app returns to an empty guest diary. If you no longer have the app, see acidlog.djump.io/delete-account. A subscription is not cancelled by deleting the account — cancel it in your App Store or Google Play settings.

8. Your rights

Under the GDPR you have the right to access your data, to have it corrected or deleted, to restrict its processing, to receive it in a portable format, and to object to processing based on legitimate interest (Art. 15–18, 20 and 21 GDPR). Where processing is based on your consent, you can withdraw it at any time with effect for the future (Art. 7(3) GDPR). Write to start@djump.io.

You also have the right to lodge a complaint with a supervisory authority — ours is the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt) — or with the authority where you live or work.

9. Security

All connections between the app, this website and our servers are encrypted (TLS). In the database, row-level security ties every diary entry to its owner's account, so one account cannot read another's entries.

10. Children

AcidLog is meant for adults and is not directed at children under 16. We do not knowingly process children's data; if you believe a child has given us data, contact us and we will delete it.

11. Automated decisions

We make no decisions about you based solely on automated processing (Art. 22 GDPR). The trigger list is a statistical calculation on your device that you are free to ignore.

12. Changes and other languages

If what the app or website does with personal data changes, we update this page and its date, and announce material changes in the app. This policy is also available in German.

← Back to AcidLog