Privacy Policy

DiMeals app · version 2.3 · updated 1 September 2026

In short: your meal plan, recipes, shopping list, prices and receipt photos stay on your phone. The app works without an account; if you make one, we hold your email address, when the account was made and last used, a count of your scans with a few technical details about each one, and, if you subscribe, the reference the store gives your purchase together with the date your subscription runs to. Photos and texts you send to be read go to the provider that reads them, and are not saved on our side; the result of the reading stays on the server for a short while, only so that we can give it to you if it was lost on the way. We show no ads, and we use no behaviour analytics, no cross-app tracking and no profiling.

Who is responsible for your data

The app is published by ARCTIC MAG S.R.L., VAT ID RO48130587, Trade Register J2023003030232, registered at Str. Popasului nr. 78, bloc A, sc. 1, et. 2, ap. 9, Voluntari, Ilfov County, Romania. You can write to us any time at contact@dimiol.com.

The account: when it appears, and what it is

You are not asked for an account to install or to use the app. The plan, the recipes, the list and the library all work without one. An account only appears for the features that need a server: reading a receipt, reading the nutrition table on a package, and importing a recipe, because the right to scan has to be held somewhere that does not reset when you change phones.

An account is made without a password: you type your email address, you get a 6 digit code, you enter it. That is all.

What we hold on the server:

What the phone holds: a sign-in token, kept in the system's key vault (Keychain on iPhone, Keystore on Android), so we do not ask you for a new code on every launch. We do not hold the token itself, only a fingerprint of it that cannot be reversed: we cannot read it either.

The account can be deleted at any time, and the deletion is real. See Deleting your account and the “Your rights” section below.

What the app keeps on the phone

Everything you enter is saved locally, on your phone:

Your content from the list above, that is the plan, the recipes, the shopping list, the prices, the receipts, the settings and the Nutrition goal figures, is not sent to any server of ours. We cannot see it, store it or recover it. When you uninstall the app, the local copy is removed from the device; whether any copy remains in the device backup depends on your operating system and your backup settings. What sign-in needs, meaning the token and the account's address, is used as described in the section about the account.

What does leave your phone

Seven cases, each of them needed for that feature to work:

Photos and texts sent to be read

The rule, in short: from what is inside the app, we send on only what you choose to have read. The request also carries the technical data any internet connection carries, including the IP address, described under Server logs and IP addresses. Today there are three such paths (a shopping receipt, the nutrition table on a package, and a recipe, as a photo or as pasted text). If we add others, the rule stays the same, and this page will be updated first.

What happens to what you send:

What a photo carries besides what you can see: a photo taken with a phone may carry things attached to it that are not in the picture, among them the place where it was taken, the exact time and the device model. What it actually carries depends on the phone and on your settings. The photos sent to be read do not carry those along: the app takes the picture apart and writes it again before it leaves, so what leaves is the dots of the image, not the file with everything that surrounded them. This holds for a photo taken on the spot, one chosen from the gallery, and one chosen from Files. If the rewriting does not succeed, the photo does not leave at all and we tell you so.

A PDF is the exception and leaves exactly as it is. We cannot rewrite a PDF without risking damage to the very document you want us to read, so what it carries inside leaves with it: that may be the author's name, the program that wrote it, or other notes that program adds. If you would rather it did not, photograph the document and send the photo instead.

One thing worth knowing before you photograph a receipt: receipts in Romania often carry the cashier's name printed on them. The photo that leaves is the whole receipt, as it is, not only the products and prices on it. If you would rather it did not, cover the line with the name when you take the photo, or type the prices by hand: the app works just the same, and what you type never leaves the phone.

What we keep for a short while so you do not lose a scan

A reading takes time. If your phone gives up, if your connection drops, or if the app closes right then, the scan has already been made and paid for, and the answer is lost on the way. So that this does not happen, a few things are kept for a short while. They are held only so that we can give you back a lost answer and so that the same reading is not made and paid for twice, not as a history and not as an archive: we do not read them, we do not gather them, and we do not use them for anything else.

On our server, tied to your account:

How long: the day of waiting is a FLOOR, not a ceiling: they are not deleted sooner than 24 hours after the scan ended, and the clean-up passes only once a day, at a fixed hour. So the deletion falls somewhere between 24 and about 48 hours, depending on how close to that pass the scan ended. They go together, the result and both keys. When you delete your account they go with the rest of your data, without waiting for this window; what “go with” means when the database refuses at that very moment is written under Deleting your account.

One case where that window starts later, so that you know the weak part too: if a scan is left without an outcome, meaning something failed on our side during the reading itself, its row never gets an ending moment, and without one the clock does not even start. The result of the reading is not at stake, because such a row has none written into it; the two keys are. The clock starts only when you come back: at your next scan, or merely by opening the scanning screen, the server closes the row left that way and only then gives it an ending moment. Your return starts the 24 to about 48 hour window, it does not end it: the keys go with the clean-up after that. If you never come back at all, they stay until the details of the scan are deleted, at twelve months.

On your phone, for as long as a scan has started and has not yet had an answer, we keep the key of that attempt, the account that started it, and the source to be sent again: the photo, the file (a PDF included) or the pasted text. Without them, an app closed during the reading would have nothing left to send again, and the paid scan would be lost. The registry row, that is the key, the account and the pointer to the source, lasts 24 hours, and usually far less: it goes at the first of these moments, when the answer arrives, when the scan is refused for good, when you give it up from the error card, when you leave the scanning screen, when you sign out, when your session expires, and when you delete your account. At each of them the working copy of the photo or the file goes as well.

The button that sends your choice again does NOT delete it, and that is worth knowing, because it is the whole point of it: sending again needs the source. It rewrites the attempt, so the 24 hours start over from your last send, not from the first. For as long as you keep trying, the source stays on your phone; the limit is counted from your latest attempt. The button next to it, the one that takes you back to choose something else, is the one that gives up and deletes.

And if none of those moments ever gets to happen, because the app closed during the reading and you never come back to the scanning screen, the attempt expires anyway after 24 hours. The app clears its own expired attempts, together with their working copies: once at every start, whichever screen you land on, then on its own at the hour of expiry if it stays open, and once more every time you bring it back to the front. You do not have to open the scanning screen and you do not have to do anything.

What we cannot promise, so that you know the weak part too: while the app is closed or put to sleep by the phone, no code of ours runs, for anybody. So the deletion does not happen at the exact minute the 24 hours are up, but at the first start or return after that. This is not a choice of ours: a phone gives no app a background window that a to-the-minute promise could rest on. Until then the file sits in the app's temporary space, on your phone: it goes nowhere and it never reaches us.

When you send someone a recipe

The “Send the recipe” button makes a link to dimiol.com, and the recipe travels inside the link, after the # character. What follows the hash never reaches the server: that is how the internet is built, it is not a promise of ours. The fragment after the hash is not part of the HTTP request the browser makes, so it never reaches our server. We checked it live in the server's log: when such a link is opened, the address our server is asked for is /r/, without the recipe. So it is not that we do not keep your recipe: we never receive it.

The page that opens asks nothing of anybody else: no fonts, no measurement, no images from other servers. Neither you nor the person you send it to needs an account for this.

Camera and photo library

The app asks for camera and photo library access only when you choose to attach a photo to a receipt or a product, or to scan something. Photos you attach to a receipt or a product are copied into the app's folder on your phone and stay there; they are not uploaded anywhere. A photo you send to be read does leave, as described above, and only after you confirm on a screen that tells you what is about to happen.

Photos taken for scanning are first put through a conversion on the phone, which shrinks them. We have checked that the resulting photo does not carry the place where it was taken, the phone's make, or the date.

Server logs and IP addresses

As with any internet request, our server sees the IP address of your connection, because otherwise it would have nowhere to reply. What we do with it:

What we do not do

If you write to us

When you use “Write to us” or “Report a problem” in the app, your own email app opens with the message prepared. For a problem report we automatically add, at the end of the message, the app version, the operating system and the language, so we can fix it. Nothing from your plan or recipes is attached. The message is sent when you send it, and it arrives in contact@dimiol.com, hosted by Zoho Corporation in its European Union data centre. We keep the correspondence for as long as we need it to answer you and to track reported problems, then we delete it.

Deleting your account

You can delete your account from inside the app, at any time: “•••” → About the app → Delete my account. If you have already uninstalled the app, write to us from the account's own address at contact@dimiol.com and we will delete it, within 30 days at most.

The deletion is real, not a flag. What disappears from our database is your email address, the history of your scans with every technical detail attached to them, including the briefly kept result and the request keys, if any were still there, the details of your subscription including the store’s purchase reference, any sign-in codes still stored at that time, and every token, meaning every phone you were signed in on. No “deleted” row with your address in it is left behind.

Three things survive deletion, and they deserve to be named.

What we cannot promise, so that you know the weak part too. The mark sits on the server and reaches our own computer only when we fetch the copies, which we do from time to time, by hand. If we lost the server entirely just between your deletion and the next fetch, that mark would not reach anywhere, and a rebuild from the older copies could bring you back. It is the only situation in which your deletion would not defend itself, and if it happened, you can ask us to delete again.

What stays: everything on your phone, that is, your recipes, plan, list, product library and receipts. We do not hold them, so we cannot delete them; the local copy is removed when you uninstall the app, and whether any copy remains in the device backup depends on your operating system and your backup settings. If you asked for deletion by email, we keep your message for as long as we need it to show that we acted on it. The steps, in full, are at Deleting your account.

Your rights

The General Data Protection Regulation (GDPR) gives you the right of access, rectification, erasure, restriction, portability and objection. Here is what each one means here, concretely:

On what basis we process: we hold your email address, the history of your scans and the details of your subscription in order to perform the contract between you and us, that is, to give you the features you asked for: without an account we cannot tell that a subscription is yours, and scanning cannot work. Sending a photo to the provider that reads it is on the same basis, at your explicit request, tapped by you on a confirmation screen. On the basis of the contract as well, we keep for a short while the result of the reading and the request keys, described under What we keep for a short while so you do not lose a scan: without them we could not give you the scan you asked for, if the answer was lost on the way.

The technical processing, on which basis: three things happen that you did not ask for one by one, and all three rest on our legitimate interest (Article 6(1)(f) GDPR) rather than on the contract:

You can object to any of these, at contact@dimiol.com, and we will tell you what stays possible without them.

The deletion mark, on what ground: we keep the account's internal number and the date of deletion so that we can meet our legal obligation to erase your data for real, including after a backup is restored (the right to erasure, Article 17 GDPR). We cannot let you object to this one: without that mark, a restore would bring your account back. How long we keep it is written below, under “How long we keep things”.

Support correspondence, on which basis: we process what you write to us in order to answer you and to follow up the problems you report. For answering about the service we rely on performing the contract; for keeping a record of reported problems and looking into them we rely on our legitimate interest in keeping the app working and safe.

How long we keep it:

If you are not satisfied with our answer, you may contact the Romanian Data Protection Authority (dataprotection.ro) or the supervisory authority of the country where you live, where you work, or where the alleged breach took place.

Children

The app is not aimed at children and collects no data about them. The baby marks on recipes are cooking notes written for parents, not information about any particular child.

Changes

If the app ever starts sending new data off your phone, we will update this page before that feature reaches you, and say clearly in the app what changes. The date at the top shows the last change.