Chargement
Skip to main content
logo

Happy Diabetes

Beta
Chat
GuidesRecipesBlogSubscriptions
Beta version. Some features may still change. Happy Diabetes is in beta. Some features may still change.
logo

Happy Diabetes

Get the next useful updates

A twice-monthly newsletter with useful Happy Diabetes updates and content.

ChatQuizzFlashcardsMobile app
Legal noticePrivacy PolicyMedical DisclaimerTerms & ConditionsData deletionHelpContact

Happy Diabetes is an education and wellness service, not a medical device. It does not provide medical advice or diagnose, treat, cure, or prevent any medical condition. For health decisions, consult your healthcare team.

© 2026 Happy Diabetes

Privacy Policy

Last updated: September 14, 2026

Introduction

We are committed to the security and protection of your personal data.
Here's how we manage and protect your information.

Information and Data Collected

We collect and store the following information:

  • User profile information (e.g., name, email address)
  • Performance and usage data (including quiz scores, answered questions, usage frequency)
  • User-generated content (such as questions asked to the chatbot, uploaded images or documents)
  • Beta feedback (category, message, page, and language), with an optional email address if you are not signed in
  • All other information you choose to provide or generate while using the application, including any health information, such as blood glucose levels.

We ask for your country of residence when you create an account to determine whether registration is available and prepare for a possible purchase. This is not your location while travelling. You can change it in your profile settings; the declared country and its last update date are stored with your account and included in your data export. When you make a purchase, Stripe also collects your billing address. Declaring a country does not, by itself, verify your residence.

If you ask to be notified when subscriptions open in a country, we store that country, your chosen language and the request date with your account, based on your consent. This request is only used to email you about that opening; it does not subscribe you to the newsletter. You can cancel it from your profile: the request is then deleted, as it is when your account is deleted. This information is also included in your data export.

If account registration is not available in your country yet, you can leave just your email to hear when it opens. With your consent, we store your email, country, language and request date. This does not create an account or subscribe you to the newsletter. We send you an email confirmation, then a notification if registration opens in this country. We also store the confirmation send date to avoid duplicates. You can separately choose to sign up for the newsletter using the suggested link; this is not required to receive the opening notification. This list is separate from requests linked to an account. To access or delete your request, write to support@happy-diabetes.com from the address concerned.

Web contracts and withdrawals

To perform your subscription and document your order, we retain your identity, email, Stripe references, accepted terms and their date, your request for immediate access, withdrawal requests and confirmations sent. Stripe processes payment; Resend delivers these contractual messages. You can download available subscription data through your account export and request copies of your contractual records. Deleting your account detaches these archives from it without erasing a pending withdrawal request or contractual evidence. Separate retention serves complaint handling, evidence of the contract and legal obligations; billing documents are managed in Stripe, and encrypted copies of contractual and accounting records may be retained in separate private storage, accessible only to authorised people. You can retain contracts and acknowledgments received by email.

To organise refunds, we compare previous requests from the same account or purchase email, ignoring letter case. The first request may be processed automatically; later requests are reviewed by a person. This check does not remove your withdrawal or refund rights.

Use of Information

This information is collected to:

  • provide application features
  • improve user experience
  • personalize content
  • analyze usage trends
  • enhance application features

Information Sharing

No Commercial Sharing
We do not sell, exchange, or rent your personal data to third parties for commercial or marketing purposes.
Your personal information, including your quiz scores, chatbot questions, and any other data you entrust to us, is strictly used to improve your experience within our application.

Service Providers
We use NeonDB as our database service provider to store your information. NeonDB has access to your data only to the extent necessary to provide its hosting and database management services.
All our service providers are subject to strict confidentiality and data protection agreements, ensuring that your information is processed only according to our instructions and in accordance with this privacy policy.

International Data Transfers
Our application uses services provided by companies located outside the European Union, including:

  • Vercel for hosting
  • NeonDB for data storage
  • OpenAI, Anthropic, and Google (Gemini) for our application's AI features

The use of these services may involve the transfer of your personal data to countries outside the European Union. We ensure that these transfers are carried out in accordance with applicable data protection regulations, including GDPR.

Some services are hosted within the European Union:

  • PostHog (EU region, Frankfurt) for product analytics and session recording
  • Sentry for technical error tracking

Analytics Tools
We use PostHog (EU region) to understand how our application is used and improve the experience. For technical reasons, requests to PostHog are routed through an internal proxy on our own domain; this proxy does not modify the nature of the data transmitted — it only acts as a relay between your browser and PostHog EU.

Configuration applied to limit personal data collection:

  • automatic masking of input text (password fields, emails, text areas)
  • masking of potentially sensitive HTML attributes
  • analytics profile creation only after identification
  • cookieless mode when you decline the consent banner

You can accept or decline these analytics from the cookie banner. If you have an account, you can later update this choice from your privacy settings.

Legal Sharing
In certain circumstances, we may be required to share your information for legal reasons, including:

  • To comply with a legal obligation, court order, or other legal process.
  • To protect the rights, property, or safety of the site, our users, or the public.
  • To detect, prevent, or address fraud, security, or technical issues. In these cases, we will endeavor to inform you of the sharing of your information, unless legally prohibited or if it could compromise the security of other users.

Data Storage and Security

All user data is securely stored in our database hosted by NeonDB, a database service provider known for its robust security measures.
Some display preferences used only on your device, such as theme choice (light/dark/system), are stored locally in the browser or in the mobile app WebView. They are not transmitted to our servers. Other preferences linked to your account, such as some recipe preferences, may be saved to your account so they remain available when you switch devices.

Security Measures

Encryption: All data transmitted between your device and our servers is encrypted using SSL/TLS protocols to ensure confidentiality.
CSRF Protection: We use CSRF tokens to protect against Cross-Site Request Forgery attacks.
Restricted Access: Database access is strictly limited to authorized personnel necessary for application maintenance and development.
Regular Updates: We keep our systems updated with the latest security patches to prevent known vulnerabilities.
Continuous Monitoring: Our systems are continuously monitored to detect any suspicious activity or unauthorized access attempts.

Data Retention Period

Data needed to operate your account is used while the service is provided. Deleting the account ends this ordinary use; some records remain retained for the purposes and periods below. Health data, AI conversations and learning progress are not retained in contractual archives merely because you paid for a subscription.

Contractual and accounting records

  • Invoices, credit notes and accounting evidence of payments or refunds: ten years from the end of the relevant financial year.
  • Tax records for transactions at launch: ten years from creation of the record or, for a register, its latest recorded transaction. If an accounting retention obligation also applies, we use the later expiry date.
  • Electronic contracts worth €120 or more: for our continuously supplied subscriptions, throughout the contract and then ten years after the actual end of supply. For an open-ended monthly subscription, the threshold is assessed using cumulative payments under the same contract; for an annual subscription, the twelve-month commitment applies. Annual renewals and their evidence are linked to the relevant period.
  • Other contracts confirmed to be worth less than €120: throughout the service and then five years after it actually ends, to establish and defend contractual rights, unless a statutory obligation or limitation period justifies longer retention.
  • Accepted offer and terms, consents, confirmations, withdrawal and cancellation requests: the retention period of the contract they evidence; refund records also follow accounting and tax periods. Creating another copy does not restart the period.
  • Unaccepted checkout drafts without a payment or contract: ninety days after their confirmed expiry, once the absence of payment or outstanding requests has been checked. A paid order with missing reconciliation is not treated as an abandoned draft.

These uses are based on performing the contract and related requests, our statutory obligations and, for supplementary evidence, our legitimate interest in establishing or defending our rights. Access to records retained after the service ends is limited to accounting, audits, complaints or the defence of rights. They are not used to reactivate your account or market to you.

Complaints, copies and backups

A complaint, dispute or specific obligation may require retention of the relevant records beyond their usual expiry. This need is reviewed until the case is closed and the applicable periods have expired. It does not justify retaining your entire account.

Temporary consultation copies are deleted when no longer needed for the intervention. Recovery backups follow their rotation cycle and may temporarily contain data deleted from active systems; access is restricted and they are not used for ordinary operation of the service. Restoration must take account of deletion requests already made and records that must still be retained. Backup rotation does not replace statutory retention of accounting or contractual records.

You can request access to your records, including after account deletion, by writing to support@happy-diabetes.com. We verify your identity in a way proportionate to the request; retaining an invoice or contract does not require you to recreate an account.

Beta feedback may be marked as new, processed, or moved to an internal trash folder so we can track product improvements. Feedback linked to your account is deleted with the account. If you submit feedback without an account and provide an optional email address, you can ask us to delete it by emailing hi@happy-diabetes.com. Do not include health data or other sensitive information in your message.

User Rights

You may request access, correction, erasure or restriction of your data and, where the conditions apply, portability or object to its processing. You may withdraw consent at any time without affecting earlier lawful processing. A statutory retention obligation may limit erasure of the relevant records only. To exercise these rights, contact support@happy-diabetes.com. You may also complain to the CNIL or the competent supervisory authority.

Cookie Usage

We use essential cookies for site security and to remember your display preferences. By continuing to use this site, you accept the use of these cookies.

Policy Changes

We reserve the right to modify this privacy policy at any time.
Any changes will be published on this page with a revised update date. In case of significant changes, we will endeavor to inform you more directly:

  • we will display a visible notification on our website and/or in our application during your next login.
  • for major changes affecting your rights or the use of your personal data, we may also send you an email to the address associated with your account.

We encourage you to regularly review this policy to stay informed about how we protect your information.
Your continued use of our services after the publication of changes constitutes your acceptance of these changes.

If you have questions, concerns, or requests regarding this privacy policy or the processing of your personal data, please don't hesitate to contact us by email: hi@happy-diabetes.com Via our online contact form available on the Contact page. We will endeavor to respond to all legitimate requests within one month.
Occasionally, it might take us more than a month if your request is particularly complex or if you have made multiple requests. In this case, we will notify you and keep you updated.
We are committed to handling your concerns fairly and transparently and to providing a satisfactory response to your privacy questions.

User Consent

Our application only collects and processes personal information strictly necessary for its operation and the provision of our services.
By using our application, you accept the processing of this essential data in accordance with this privacy policy.
Legal Basis for Processing: The processing of your personal data is primarily based on the necessity to execute the contract we have with you (i.e., to provide you with our application's services) rather than on explicit consent.
Information and Transparency: During your first use of the application, we will inform you of our privacy policy via a toast message. This message will contain a link to our complete policy.
Acceptance of Terms: By continuing to use our application after being informed of our privacy policy, you indicate that you accept the terms of this policy and the processing of your data as described.
Control of Your Data: Although the processing of this data is necessary for using the application, you maintain control over your personal information. You can access and modify your data at any time through your account settings.
You can request a copy of your personal data that we hold.
If you wish to completely stop the use of your data, you can delete your account, which will result in the deletion of all your personal data from our systems.
Withdrawal of "Consent": Since processing is based on contractual necessity, there is no "consent" to withdraw per se. However, you can choose to stop using the application at any time and request the deletion of your account and data.

Artificial Intelligence

Our application uses artificial intelligence features, in particular the Alfred educational assistant. Here is how these features work and what data is involved.

AI providers used:

  • Anthropic (Claude model) — used as the primary AI assistant for Alfred on complex queries
  • Google (Gemini model) — used for general chat responses on simple queries
  • OpenAI (GPT model) — used for image analysis, internal routing, and fallback

What data is transmitted to AI providers:

  • The content of your conversation messages (text, photos, or documents you send to Alfred)
  • Your personal health profile (diabetes experience, equipment used, learning goals) — only if you have explicitly given your AI consent when first accessing the chat

We do not transmit your name, email address, or any directly identifying information to AI providers. Conversation data is processed by these providers to generate responses and is governed by their respective privacy policies.

Model training opt-out commitment: None of the Alfred conversations, photos, documents, or health profile data sent to AI providers is used to train their models. This commitment rests on contractual guarantees specific to each provider:

  • Anthropic: explicit contractual prohibition against using Customer Content for training (Commercial Terms of Service, Section B, effective June 17, 2025).
  • OpenAI: default API policy since March 1, 2023; no opt-in option has been activated for Happy Diabetes.
  • Google Gemini: Happy Diabetes operates exclusively on the paid tier linked to an active Cloud Billing account, which explicitly excludes prompts and responses from being used to improve models (Gemini API Additional Terms, effective March 23, 2026).

Internal audit of provider commitments: May 14, 2026.

AI consent: Before your first use of the Alfred chat, we ask for your explicit consent to share your conversation data with our AI providers. You can withdraw or modify this consent at any time from the chat interface. Refusing consent disables the chat feature.

Opt-out: You can refuse or revoke your AI consent at any time from the chat screen. If you revoke consent, no new conversation data will be sent to AI providers.

Health Data

Happy Diabetes is an education and wellness service, available on the web and as a mobile app. It is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Here is how we handle health-related data you choose to share.

What health data we may process:

  • Blood glucose values, A1C, and glycemic metrics you upload via reports
  • Notes and calendar events you create in the app
  • Dietary information from photos or text you share with Alfred
  • Your diabetes profile (type, experience, equipment) collected during onboarding

How it is stored:

  • All health data is stored on our servers (PostgreSQL database hosted by NeonDB)
  • We do not integrate with Apple HealthKit, Google Health Connect, or any native health platform. Your health data remains within our application only.

GDPR Article 9 — Special Category Data: Health data is classified as a special category under GDPR Article 9. We process this data on the basis of your explicit consent, given either at account creation (onboarding questionnaire) or via the AI consent flow for chat features. You may withdraw this consent and request deletion of your data at any time.

No medical use: We do not use your health data to provide medical diagnoses, prescriptions, or personalized clinical recommendations. Alfred is an educational tool only.

GDPR Compliance

Our privacy policy and data processing practices are designed to comply with the European Union's General Data Protection Regulation (GDPR).
Here are the specific measures we have implemented:

  • Legal Basis: We process your personal data based on contractual necessity for essential application features, and on explicit consent for health data.
  • Transparency: This privacy policy clearly and accessibly details the types of data we collect, why we collect it, and how we use it.
  • User Rights: We fully respect your rights under GDPR, including:
  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing
  • Consent: When consent is required, we ensure it is freely given, specific, informed, and unambiguous.
  • Data Protection by Design: Our systems are designed with data protection as a priority from the start.
  • Breach Notification: In case of a data breach likely to result in a risk to your rights and freedoms, we commit to informing you within 72 hours.
  • International Transfers: If your data is transferred outside the EU, we ensure appropriate safeguards are in place. We specifically use Standard Contractual Clauses (SCCs) approved by the European Commission to frame these transfers and guarantee an adequate level of protection for your personal data.

We are committed to regularly reviewing and updating our practices to ensure ongoing compliance with GDPR and other applicable data protection regulations.