Last updated: September 14, 2026
We are committed to the security and protection of your personal data.
Here's how we manage and protect your information.
We collect and store the following information:
We ask for your country of residence when you create an account to determine whether registration is available and prepare for a possible purchase. This is not your location while travelling. You can change it in your profile settings; the declared country and its last update date are stored with your account and included in your data export. When you make a purchase, Stripe also collects your billing address. Declaring a country does not, by itself, verify your residence.
If you ask to be notified when subscriptions open in a country, we store that country, your chosen language and the request date with your account, based on your consent. This request is only used to email you about that opening; it does not subscribe you to the newsletter. You can cancel it from your profile: the request is then deleted, as it is when your account is deleted. This information is also included in your data export.
If account registration is not available in your country yet, you can leave just your email to hear when it opens. With your consent, we store your email, country, language and request date. This does not create an account or subscribe you to the newsletter. We send you an email confirmation, then a notification if registration opens in this country. We also store the confirmation send date to avoid duplicates. You can separately choose to sign up for the newsletter using the suggested link; this is not required to receive the opening notification. This list is separate from requests linked to an account. To access or delete your request, write to support@happy-diabetes.com from the address concerned.
To perform your subscription and document your order, we retain your identity, email, Stripe references, accepted terms and their date, your request for immediate access, withdrawal requests and confirmations sent. Stripe processes payment; Resend delivers these contractual messages. You can download available subscription data through your account export and request copies of your contractual records. Deleting your account detaches these archives from it without erasing a pending withdrawal request or contractual evidence. Separate retention serves complaint handling, evidence of the contract and legal obligations; billing documents are managed in Stripe, and encrypted copies of contractual and accounting records may be retained in separate private storage, accessible only to authorised people. You can retain contracts and acknowledgments received by email.
To organise refunds, we compare previous requests from the same account or purchase email, ignoring letter case. The first request may be processed automatically; later requests are reviewed by a person. This check does not remove your withdrawal or refund rights.
This information is collected to:
No Commercial Sharing
We do not sell, exchange, or rent your personal data to third parties for commercial or marketing purposes.
Your personal information, including your quiz scores, chatbot questions, and any other data you entrust to us, is strictly used to improve your experience within our application.
Service Providers
We use NeonDB as our database service provider to store your information. NeonDB has access to your data only to the extent necessary to provide its hosting and database management services.
All our service providers are subject to strict confidentiality and data protection agreements, ensuring that your information is processed only according to our instructions and in accordance with this privacy policy.
International Data Transfers
Our application uses services provided by companies located outside the European Union, including:
The use of these services may involve the transfer of your personal data to countries outside the European Union. We ensure that these transfers are carried out in accordance with applicable data protection regulations, including GDPR.
Some services are hosted within the European Union:
Analytics Tools
We use PostHog (EU region) to understand how our application is used and improve the experience. For technical reasons, requests to PostHog are routed through an internal proxy on our own domain; this proxy does not modify the nature of the data transmitted — it only acts as a relay between your browser and PostHog EU.
Configuration applied to limit personal data collection:
You can accept or decline these analytics from the cookie banner. If you have an account, you can later update this choice from your privacy settings.
Legal Sharing
In certain circumstances, we may be required to share your information for legal reasons, including:
All user data is securely stored in our database hosted by NeonDB, a database service provider known for its robust security measures.
Some display preferences used only on your device, such as theme choice (light/dark/system), are stored locally in the browser or in the mobile app WebView. They are not transmitted to our servers. Other preferences linked to your account, such as some recipe preferences, may be saved to your account so they remain available when you switch devices.
Encryption: All data transmitted between your device and our servers is encrypted using SSL/TLS protocols to ensure confidentiality.
CSRF Protection: We use CSRF tokens to protect against Cross-Site Request Forgery attacks.
Restricted Access: Database access is strictly limited to authorized personnel necessary for application maintenance and development.
Regular Updates: We keep our systems updated with the latest security patches to prevent known vulnerabilities.
Continuous Monitoring: Our systems are continuously monitored to detect any suspicious activity or unauthorized access attempts.
Data needed to operate your account is used while the service is provided. Deleting the account ends this ordinary use; some records remain retained for the purposes and periods below. Health data, AI conversations and learning progress are not retained in contractual archives merely because you paid for a subscription.
These uses are based on performing the contract and related requests, our statutory obligations and, for supplementary evidence, our legitimate interest in establishing or defending our rights. Access to records retained after the service ends is limited to accounting, audits, complaints or the defence of rights. They are not used to reactivate your account or market to you.
A complaint, dispute or specific obligation may require retention of the relevant records beyond their usual expiry. This need is reviewed until the case is closed and the applicable periods have expired. It does not justify retaining your entire account.
Temporary consultation copies are deleted when no longer needed for the intervention. Recovery backups follow their rotation cycle and may temporarily contain data deleted from active systems; access is restricted and they are not used for ordinary operation of the service. Restoration must take account of deletion requests already made and records that must still be retained. Backup rotation does not replace statutory retention of accounting or contractual records.
You can request access to your records, including after account deletion, by writing to support@happy-diabetes.com. We verify your identity in a way proportionate to the request; retaining an invoice or contract does not require you to recreate an account.
Beta feedback may be marked as new, processed, or moved to an internal trash folder so we can track product improvements. Feedback linked to your account is deleted with the account. If you submit feedback without an account and provide an optional email address, you can ask us to delete it by emailing hi@happy-diabetes.com. Do not include health data or other sensitive information in your message.
You may request access, correction, erasure or restriction of your data and, where the conditions apply, portability or object to its processing. You may withdraw consent at any time without affecting earlier lawful processing. A statutory retention obligation may limit erasure of the relevant records only. To exercise these rights, contact support@happy-diabetes.com. You may also complain to the CNIL or the competent supervisory authority.
We use essential cookies for site security and to remember your display preferences. By continuing to use this site, you accept the use of these cookies.
We reserve the right to modify this privacy policy at any time.
Any changes will be published on this page with a revised update date. In case of significant changes, we will endeavor to inform you more directly:
We encourage you to regularly review this policy to stay informed about how we protect your information.
Your continued use of our services after the publication of changes constitutes your acceptance of these changes.
If you have questions, concerns, or requests regarding this privacy policy or the processing of your personal data, please don't hesitate to contact us by email: hi@happy-diabetes.com
Via our online contact form available on the Contact page.
We will endeavor to respond to all legitimate requests within one month.
Occasionally, it might take us more than a month if your request is particularly complex or if you have made multiple requests. In this case, we will notify you and keep you updated.
We are committed to handling your concerns fairly and transparently and to providing a satisfactory response to your privacy questions.
Our application only collects and processes personal information strictly necessary for its operation and the provision of our services.
By using our application, you accept the processing of this essential data in accordance with this privacy policy.
Legal Basis for Processing: The processing of your personal data is primarily based on the necessity to execute the contract we have with you (i.e., to provide you with our application's services) rather than on explicit consent.
Information and Transparency: During your first use of the application, we will inform you of our privacy policy via a toast message. This message will contain a link to our complete policy.
Acceptance of Terms: By continuing to use our application after being informed of our privacy policy, you indicate that you accept the terms of this policy and the processing of your data as described.
Control of Your Data: Although the processing of this data is necessary for using the application, you maintain control over your personal information. You can access and modify your data at any time through your account settings.
You can request a copy of your personal data that we hold.
If you wish to completely stop the use of your data, you can delete your account, which will result in the deletion of all your personal data from our systems.
Withdrawal of "Consent": Since processing is based on contractual necessity, there is no "consent" to withdraw per se. However, you can choose to stop using the application at any time and request the deletion of your account and data.
Our application uses artificial intelligence features, in particular the Alfred educational assistant. Here is how these features work and what data is involved.
AI providers used:
What data is transmitted to AI providers:
We do not transmit your name, email address, or any directly identifying information to AI providers. Conversation data is processed by these providers to generate responses and is governed by their respective privacy policies.
Model training opt-out commitment: None of the Alfred conversations, photos, documents, or health profile data sent to AI providers is used to train their models. This commitment rests on contractual guarantees specific to each provider:
Internal audit of provider commitments: May 14, 2026.
AI consent: Before your first use of the Alfred chat, we ask for your explicit consent to share your conversation data with our AI providers. You can withdraw or modify this consent at any time from the chat interface. Refusing consent disables the chat feature.
Opt-out: You can refuse or revoke your AI consent at any time from the chat screen. If you revoke consent, no new conversation data will be sent to AI providers.
Happy Diabetes is an education and wellness service, available on the web and as a mobile app. It is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Here is how we handle health-related data you choose to share.
What health data we may process:
How it is stored:
GDPR Article 9 — Special Category Data: Health data is classified as a special category under GDPR Article 9. We process this data on the basis of your explicit consent, given either at account creation (onboarding questionnaire) or via the AI consent flow for chat features. You may withdraw this consent and request deletion of your data at any time.
No medical use: We do not use your health data to provide medical diagnoses, prescriptions, or personalized clinical recommendations. Alfred is an educational tool only.
Our privacy policy and data processing practices are designed to comply with the European Union's General Data Protection Regulation (GDPR).
Here are the specific measures we have implemented:
We are committed to regularly reviewing and updating our practices to ensure ongoing compliance with GDPR and other applicable data protection regulations.