Diva legal center
Diva Privacy Policy
Your data. Your choices. Clear limits. This page contains Diva's Privacy Policy, AI Transparency Notice, Health and Wellness Notice, account deletion instructions, and support information.
Privacy policy
How Diva handles personal data
Diva is a personal self-care app for beauty, nutrition, fitness, sleep, quit-habit tracking, wellness routines, and gamification. This policy explains the data Diva uses, why it is needed, where it may be processed, how long it is kept, and the choices available to you.
1. Who is responsible for your data
Diva operates the app ("Diva," "we," "us," or "our"). For privacy questions, rights requests, or complaints, contact slay@askdiva.app.
2. Scope
This policy applies to the Diva mobile app, Diva's public website and legal pages, customer support, and backend services used to provide the app. Third-party stores and services also apply their own policies when you use them.
3. Data we collect
| Category | Examples | Why Diva uses it |
|---|---|---|
| Account and identity | User ID, email address, name supplied by an identity provider, authentication provider, language, and account status. | Create and secure your account, sign you in, sync your data, provide support, and process deletion requests. |
| Profile and onboarding | Age, goals, desired feelings, preferences, height, weight, unit system, sex selection, activity level, nutrition goal, reminder preferences, and optional mascot name. | Personalize the app, calculate user-requested nutrition targets, configure your selected goal, and remember preferences. |
| Health, fitness and wellness | Meals, food items, calories, macros, water, weight, sleep, workouts, exercise, steps, active calories, distance, quit-habit check-ins and relapses, and routine completion. | Provide the trackers, daily summaries, trends, goals, and rewards you choose to use. |
| Photos and scans | Portrait photos you choose for skin scans or future-self previews, food photos, restaurant menu photos, barcode scans, generated beauty previews, scan choices, and structured scan results. | Perform requested scans, save scan history, display generated previews, estimate meal nutrition, and transcribe menus. |
| Purchases | Product identifier, entitlement status, purchase and expiration dates, renewal status, store, and RevenueCat app user ID. | Unlock Diva Pro, verify entitlement, restore purchases, and provide subscription support. Diva does not receive your full payment-card number. |
| Notifications | Expo push token, device binding, time zone, notification preferences, delivery status, and open/received events. | Deliver reminders you enable, avoid duplicate sends, troubleshoot delivery, and route you to the relevant feature. |
| Usage and game progress | Feature interactions, screen events, completed tasks, XP, levels, achievements, inventory, streak-related activity, and session ID. | Operate gamification, save progress, understand feature reliability, prevent reward abuse, and improve Diva. |
| Diagnostics and support | Crash reports, performance traces, app version, platform, user ID, account email attached to error reports, error context, and support or feedback messages. | Diagnose failures, maintain security and availability, respond to support, and improve app quality. |
| Technical request data | IP address and standard server request information that may be processed by hosting, security, or infrastructure providers. | Deliver the service, secure accounts and APIs, prevent abuse, and maintain operational logs. |
4. Where the data comes from
- Directly from you when you register, complete onboarding, log an activity, submit feedback, take a scan, or change a preference.
- From Apple or Google when you choose their sign-in service.
- From Apple Health or Android Health Connect only after you grant the relevant system permissions.
- From Apple, Google Play, and RevenueCat for subscription and entitlement status.
- Automatically from the app and backend when needed for security, diagnostics, usage analytics, notifications, and reliable feature operation.
5. Purposes and legal bases
Where the European Economic Area, United Kingdom, or similar law applies, Diva relies on the following legal bases:
- Contract: processing needed to create your account and provide the trackers, history, personalization, saved progress, subscription access, and support you request.
- Consent: third-party AI image processing, camera access, notifications, and health-platform permissions. You can refuse these optional permissions and continue using features that do not need them.
- Legitimate interests: limited usage analytics, diagnostics, security, fraud and abuse prevention, service reliability, and product improvement, balanced against your rights.
- Legal obligations: records or disclosures that must be retained or provided under tax, accounting, consumer, court, or regulatory requirements.
6. Service providers and recipients
Diva discloses data only as needed to operate the requested service, comply with law, protect users, or complete a transaction. Current providers include:
- SupabaseAuthentication, PostgreSQL database, private file storage, and Edge Functions. Supabase privacy information.
- Google CloudAI processing for skin, food, menu, and future-self preview scans. Google Privacy Policy and Google Cloud service terms.
- RevenueCatSubscription products, paywalls, purchase status, entitlement synchronization, and restore purchases. RevenueCat Privacy Policy.
- Apple and GoogleApp distribution, authentication where selected, payment processing, subscription management, and health-platform permissions. Apple or Google receives payment information directly; Diva receives purchase status rather than full card details.
- SentryProduction crash and performance diagnostics. Screenshots are disabled and default PII collection is disabled, but Diva currently attaches the signed-in user ID and account email to help investigate account-specific failures. Sentry Privacy Policy.
- ExpoApp infrastructure and delivery of push notifications. Expo Privacy Policy.
- Open Food FactsProduct and nutrition lookup when you scan a barcode. The barcode and technical request data may be sent to its public product service. Open Food Facts privacy information.
We may also disclose information to professional advisers, regulators, law enforcement, courts, or a successor in a merger or sale when legally required and subject to appropriate safeguards.
7. No sale, targeted advertising, or health-data marketing
Diva does not sell personal data, does not use third-party advertising SDKs, and does not use personal data for cross-app behavioral advertising. Data read from HealthKit or Health Connect, health and fitness logs, scan photos, and inferred cosmetic information are not used for advertising, marketing profiles, data brokerage, or insurance decisions.
8. Retention
| Data | Typical retention |
|---|---|
| Account, profile, tracking, health summaries, routines, rewards, and saved scan results | Stored while your account is active or until you delete the applicable data where an in-app control is available. Account deletion removes the account-linked records from Diva's active systems. |
| Skin scan source images and generated previews | Stored in private Supabase storage so scan history and previews remain available. They remain until account deletion or another deletion request Diva can fulfill. |
| Food and menu photos | Diva sends the optimized image to the AI provider to complete the request but does not intentionally retain the input photo in Diva storage after analysis. Diva retains the structured scan result and provider metadata with your account. |
| AI provider input and output | Subject to the limited processing and security retention described in the provider's applicable paid-service terms. See the AI Transparency Notice below. |
| Diagnostics, security, and technical logs | Retained only as long as reasonably necessary for troubleshooting, security, abuse prevention, and legal compliance, subject to configured provider retention periods. |
| Support and privacy requests | Retained while the request is handled and afterward where reasonably necessary to document the response, resolve disputes, or meet legal obligations. |
| Deletion audit | A minimal record, which may include a one-way hash of the account email, internal user ID, completion status, timestamp, and non-sensitive error status, may be retained to prove and secure the deletion process. |
Deleted data may remain temporarily in restricted backups until normal backup rotation completes. Backups are used for disaster recovery and are not used to recreate a deleted account except where legally required.
9. Security
Diva uses measures designed to protect data, including encrypted network transport, authenticated APIs, database row-level access controls, private scan-image storage, time-limited signed file links, server-side provider credentials, and encrypted device storage for Supabase session tokens. No storage or transmission method is completely secure, so absolute security cannot be guaranteed.
10. International processing
Service providers may process data in countries outside your own, including the United States and locations where they operate. Where required, Diva relies on provider data-processing agreements, standard contractual clauses, adequacy decisions, or other lawful safeguards for cross-border transfers.
11. Your rights and controls
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, withdraw consent, and complain to a data-protection authority. You may also have a right to appeal a denied privacy request and a right not to receive discriminatory treatment for exercising privacy rights.
- Edit available profile, tracker, goal, and notification settings in the app.
- Decline a camera, notification, health, or AI processing permission without losing unrelated features.
- Revoke health access through Apple Health or Health Connect settings and disconnect it in Diva.
- Revoke future AI processing by declining a scan prompt or contacting support. Withdrawal does not affect processing already completed with valid consent.
- Delete your Diva account from Profile > Privacy & Security.
- Email slay@askdiva.app for an access, correction, portability, objection, restriction, consent, or deletion request.
12. Children and age eligibility
Diva's onboarding requires users to be at least 14 years old. Diva is not directed to children under 14. If you are under the age of majority where you live, use Diva only with any parent or guardian permission required by local law. Do not submit a child's face photo or other personal data to Diva or an AI scan. If we learn that a child's personal data was collected, contact us so we can delete it.
13. Website data and cookies
This legal page contains no advertising, analytics scripts, or optional cookies. The website host may process standard request logs and strictly necessary security information to deliver the page. If optional website analytics, marketing tools, or cookies are added later, this notice and any required consent controls will be updated first.
14. Changes to this policy
We may update this policy when Diva's features, providers, or legal obligations change. The updated date will appear at the top. If a change materially affects consent-based processing, Diva will request new consent where required.
Face data and facial images
How Diva handles a face photo
This section explains what face data Diva collects, why it is used, where it is processed and stored, who receives it, how long it is retained, and how you can delete it.
What face data Diva collects
When you choose a skin scan or future-self beauty preview, Diva collects the portrait image you select, which may contain your face and visible facial features. Diva also processes the scan options you choose, the cosmetic analysis generated from the image, and any generated preview image connected to that request.
How Diva uses face data
Diva uses this information only to provide the requested cosmetic analysis, saved scan history, skincare routine, and future-self beauty preview. The analysis may estimate visible cosmetic characteristics such as apparent face shape, skin type, undertone, texture, redness, blemishes, and under-eye appearance. It is cosmetic and informational only, not medical advice or identity verification.
Sharing and third-party processing
Yes. When you approve a skin scan or future-self preview, Diva sends the selected image and limited scan context over encrypted HTTPS to Google Cloud AI services to process the request. Google Cloud is a service provider for this feature. Diva does not sell face data, share it with advertisers, or send the original face image to RevenueCat, Sentry, or Open Food Facts. The provider may temporarily process or retain inputs and outputs under its applicable service terms for security, abuse prevention, and legal compliance; Diva does not control provider-side retention.
Storage and access
Diva stores the original scan image, any generated preview image, the structured cosmetic result, and related provider metadata in private Supabase database and storage systems linked to your account. The storage bucket is not public. The app retrieves images through authenticated backend requests and time-limited signed links. Face data is not used to create a biometric template, perform facial recognition, identify a person, infer emotion, advertise, or train Diva's own AI systems.
Retention and deletion
Diva retains face images, generated previews, and related scan results while your account is active so you can view your scan history. You can delete them by deleting your Diva account from Profile > Privacy & Security. The deletion flow removes the account-linked scan records and private storage objects from Diva's production systems. Restricted backups, security logs, and temporary third-party processing may remain only for the applicable operational, security, or legal retention period. Deleting your Diva account does not delete records held independently by Apple, Google, or other providers under their own policies.
AI transparency notice
What the scans do and what they cannot know
Diva uses third-party AI services for limited, user-requested analysis and image generation. AI is never run silently on your photos. The app asks for feature-specific consent before an image is sent for processing.
1. Skin and face scan
When you request a skin scan, Diva sends the selected face photo and a limited analysis instruction to a third-party AI service. The service estimates cosmetic skin appearance, visible texture, redness, blemishes, hydration appearance, under-eye appearance, undertone, skin type, face shape, color direction, styling suggestions, and a skincare routine. The result is cosmetic and informational only.
- Diva stores the original skin scan photo in private Supabase storage and stores the structured result so you can reopen scan history and use the routine.
- The scan does not test tissue, detect disease, measure clinical skin health, or replace a dermatologist.
- Lighting, camera quality, makeup, filters, facial expression, skin tone representation, occlusion, and model limitations can materially affect the result.
2. Future-self beauty preview
If you request a future-self preview, Diva sends your saved scan photo and your selected haircut, hair color, makeup, nail style, outfit color, and palette to a third-party image-generation service. The service creates a fictional visual preview. Diva stores the generated image and associated choices so it can be shown with the scan result.
- The preview is synthetic and may change features, details, skin appearance, hair, hands, nails, clothing, or identity cues incorrectly.
- It is not a prediction of how you will actually look and does not promise a result from products, treatments, weight change, makeup, or styling.
- Do not use a preview to impersonate, deceive, harass, or misrepresent another person.
3. Food photo scan
When you request a food scan, Diva sends an optimized meal photo to a third-party AI service. The service identifies visible or strongly implied food components and estimates portion weight or volume, calories, protein, carbohydrates, and fat. Diva stores the structured result, not the input meal photo, and lets you add, remove, or edit items before saving a meal.
Food estimates may be substantially wrong because recipes, oils, sauces, cooking methods, hidden ingredients, density, serving size, and brands cannot reliably be determined from a photo.
4. Restaurant menu scan
When you request a menu scan, Diva sends an optimized menu photo to a third-party AI service. The service transcribes visible dish names and descriptions and estimates likely components, serving size, calories, and macros. The current scan is an estimate, does not perform a live web search, and does not guarantee official restaurant nutrition. Always prefer nutrition and allergen information published directly by the restaurant.
5. Barcode lookup
Barcode lookup is separate from generative AI. Diva may send a barcode to Open Food Facts and use returned product data. Database records can be missing, outdated, region-specific, or entered by community contributors. Check the package label before relying on it.
6. Face data use limits
A skin scan photo contains your face and is personal data. Diva does not use it for identity verification, facial recognition, biometric identification, emotion recognition, advertising, surveillance, or the creation of a biometric face template. See Face Data and Facial Images for the complete collection, sharing, storage, retention, and deletion details.
7. Third-party processing and model training
Diva uses paid Google Cloud AI processing for requested scans. Under Google's applicable paid-service terms, Google states that prompts, associated files, and responses are not used to improve its products. Google may retain or log inputs and outputs for a limited period for abuse monitoring, safety, security, and legally required disclosures. Processing details can change with Google's terms, location, service configuration, and applicable documentation; review the Google Cloud service terms and Google Cloud AI data retention documentation.
Diva does not use your scans to train its own AI systems. Diva does not authorize scan content for advertising or data brokerage.
8. Consent and control
- Diva displays a disclosure before each category of AI image processing and records whether you agree.
- You can choose "Not now" and avoid sending the image. Unrelated app features remain available according to your plan.
- Food and menu estimates should be reviewed and corrected before they are saved or used.
- You can stop future AI processing by declining later prompts and can request deletion of stored scans by deleting your account or contacting support.
9. Safety and reporting an AI result
Do not submit unlawful, abusive, exploitative, sexually explicit, deceptive, or non-consensual content. Do not upload another person's face without their permission. If an AI result is harmful, offensive, unsafe, misleading, or appears to contain someone else's identity, report it through Diva's in-app Profile > Support & Feedback > Report a Bug flow and include "AI output" in the report, or email slay@askdiva.app.
Health and wellness notice
Optional health sync, limited purpose
Diva offers general wellness tracking. It is not a medical device and does not diagnose, treat, cure, or prevent any medical condition.
1. Apple Health and Health Connect data
If you explicitly connect a health provider, Diva requests read-only access to the minimum data used for your Activity summary:
- Step count
- Active calories burned
- Walking or running distance
- Exercise time or exercise sessions
- Sleep duration or sleep sessions
Diva reads the permitted records for the relevant daily time range and stores an account-linked daily summary in Supabase. It does not store your entire Apple Health or Health Connect database and does not write health records back to those platforms.
2. How health data is used
Health data is used only to display your activity and sleep summary, support the wellness trackers you select, and provide progress or rewards directly to you. It is not sent to third-party AI services for scans, sold, used for advertising, shared with data brokers, used to set insurance terms, or used for employment decisions.
3. Permissions and deletion
- You can decline health access and manually use other Diva features.
- On Android, disconnecting can revoke Diva's Health Connect permissions. You can also manage permissions in Health Connect settings.
- On iOS, Apple requires you to revoke HealthKit permissions in device settings. Disconnecting in Diva stops future app sync and updates Diva's saved connection status.
- Deleting your Diva account deletes the daily summaries stored by Diva. It does not delete source records held by Apple Health, Health Connect, or the apps that originally wrote them.
4. Nutrition, skin, sleep and quit tools
Calorie targets, macro estimates, meal scans, skin routines, sleep tracking, and quit-habit milestones are general estimates and organizational tools. They are not individualized clinical advice. Do not delay care or change medication, treatment, or a medically prescribed diet based on Diva.
Account and data deletion
Delete your Diva account
You can delete your account inside Diva or request deletion from this website if you no longer have the app. Account deletion is permanent and cannot be undone.
Option 1: Delete in the app
- Open Diva and sign in.
- Open Profile.
- Select Privacy & Security.
- Select Delete Account, review the warning, and confirm.
The in-app process requests deletion of your Supabase authentication account, profile, tracker history, AI scan results, stored scan images and previews, health summaries, notification tokens, analytics, rewards, feedback, and subscription record held by Diva. Diva also attempts to remove the linked RevenueCat subscriber profile.
Option 2: Request deletion on the web
Email us from the address connected to your Diva account. Include the words "Delete my Diva account" and the sign-in method you used. Do not send your password, Apple password, Google password, payment-card number, or health records.
Request account deletionDirect email: slay@askdiva.app. We may ask you to verify account ownership before deletion. We aim to complete verified requests within 30 days, or sooner where required.
What may remain
- A minimal deletion audit record may remain for security, proof of completion, fraud prevention, and legal compliance.
- Restricted backups may contain deleted data until normal backup rotation completes.
- Apple, Google, RevenueCat, and other independent providers may retain transaction or legal records under their own policies.
- Aggregated information that no longer identifies you may be retained.
Support and legal contact
Contact Diva
Use the contact below for account access, billing entitlement, privacy rights, deletion, safety, AI output, or technical support. Include enough information to locate the issue, but do not send passwords, full payment details, or unnecessary health information.
Android: com.bannout.diva
Privacy complaints
Please contact us first so we can investigate. If European data-protection law applies, you may also complain to the supervisory authority in the country where you live, work, or believe a violation occurred.
Document order
If sections of this page conflict, the more specific section governs the subject. Mandatory consumer and privacy law always prevails. The Privacy Policy governs personal-data processing; the Subscription Terms govern Diva Pro billing; the AI and Health notices explain feature-specific limitations; and the Terms of Service govern general use.
Back to top ↑