Privacy and Personal Data Policy
How local Application data, support requests, website data, advertising, and installation attribution are processed.
Key data facts
Diary contents, health information, photographs, and reports are stored and processed on the device in response to the User’s actions. The Controller does not receive them and has no remote access. Support emails independently sent by the User, standard hosting logs, website Yandex Metrica data after “Accept,” Yandex Mobile Ads SDK technical data, and AppMetrica installation and basic-session data may be processed separately.
- Local diary
- No diary transfer
- Advertising and AppMetrica
1. Controller and scope
1.1. The controller of personal data actually available to the developer through the website, emails the User independently sends to support@gastrodnevnik.ru, and the advertising integration is Individual Entrepreneur Chaplygin Artem Eduardovich, TIN (INN) 463252089851, Primary State Registration Number (OGRNIP) 326460000030126 (the “Controller”). The support action in the Application only opens an external email client with a prepared draft; the Controller receives nothing until the User sends the email. Local diary contents are not transmitted to the Controller automatically and are not part of the data processed by the Controller.
1.2. This Policy applies to the GastroDnevnik Android application with package identifier ru.gastrodnevnik.app, its updates, and the gastrodnevnik.ru website (together, the “Services”).
1.3. When the Application is distributed through an application store, the store, operating system, device manufacturer, and system-account provider process data relating to their own services under their own policies.
2. Separation of local data and Controller processing
2.1. The User independently decides what information to enter and controls operations with it on the User’s device for personal purposes. The Application is a local software tool.
2.2. As part of the core functions, the Controller does not collect, receive, view, use, or store diary contents, photographs, reports, or other local data on its own infrastructure. The Controller has no remote access to that data and cannot restore it at the User’s request.
2.3. Recording, storage, editing, organization, display, search, local analytics, report generation, import, and deletion occur automatically on the device in response to the User’s actions and settings. This Policy governs only the Controller processing described in Sections 4, 5, and 13. Export and file sharing are separate processes controlled by the User or a third party selected by the User.
Sensitive information. Local entries concerning symptoms, conditions, medication, and other health matters are sensitive information, but the Controller does not receive or process them as part of the Application’s core functions. The Application does not include them in advertising requests, its own logs, Yandex Metrica, or prepared support-email fields. If the User manually adds such information to an email being sent or shares a file with a selected third party, further processing begins only because of that separate User action.
3. User local data unavailable to the Controller
3.1. Depending on the selected functions, the User may store and process locally:
3.2. The Controller does not receive the contents of the listed data, does not use it to build advertising profiles, does not sell it, and does not disclose it to advertising networks. The presence of fields for such information in the Application does not by itself mean that the information is transmitted to the Controller.
- profile information and settings, such as a name or alias, date of birth, sex, language, height, weight, allergens, conditions, and user preferences;
- entries concerning food, products and dishes, bowel movements, sleep, mood, stress, medication, symptoms, body measurements, activity, and notes;
- photographs selected by the User through the camera or system photo picker;
- medication schedules, reminders, and notification settings;
- local analytics, generated reports, import files, and export files;
- local record identifiers, settings, feature state, and locally recorded report credits;
- local data needed to verify an Application PIN and the biometric-unlock setting. Biometric templates are processed by Android and are not provided to the Controller.
4. Data the Controller may receive
4.1. The support action does not send Application data or transmit anything to the Controller. It opens the email application installed on the device with a prepared draft. Until the User presses send, the message and attachments remain under the User’s control. After sending, the Controller and its email provider receive and process only the contents of the email actually sent.
4.2. The Application does not add diary contents, photographs, reports, symptoms, diagnoses, medication, food information, notes, or other local data to the email subject, body, or attachments. The User independently reviews and may edit the draft before sending. If the User manually adds sensitive information, the Controller uses it only to handle the request and deletes it when no longer needed, unless longer retention is required by law or to protect legal rights.
- Support email sent by the User through an external email application. Data: email address, name or signature, email text, Application version, device model, attachments, and other information the User independently leaves in and sends with the email; the Application does not add diary contents automatically. Purpose: responding, troubleshooting, protecting rights, and resolving disputes.
- Website — hosting logs. Data: IP address, request date and time, requested URL, browser or device information, referrer, and technical security logs. Purpose: delivering the website, security, diagnostics, and abuse prevention.
- Website — Yandex Metrica after “Accept.” Data: browser identifiers in cookies or localStorage, IP address, page URL and referrer, date and time, browser, operating-system, device and screen information, language, time zone, approximate region, and general page actions depending on tag settings. Purpose: traffic statistics, analysis of page use, website improvement, and identification of technical issues.
- Mobile Application — AppMetrica. Data: installation identifier and AppMetrica Device ID, IP address, date and time, device, Android, network, language and Application-version information, first launch, start and end of basic sessions, INSTALL_REFERRER, click identifier, installation source, and advertising-campaign parameters where available. Purpose: installation attribution, conversion measurement, and advertising-campaign effectiveness.
- Application store. Data: reviews, installation information, crash reports, and other information only to the extent made available to the developer by that store. Purpose: publication support and user support; the exact scope depends on store settings.
5. Yandex Mobile Ads SDK and AppMetrica
5.1. The Application is provided free of charge and is funded by advertising. It may use Yandex Mobile Ads SDK for banner, native, and rewarded advertising. The Controller selects and configures the SDK and thereby arranges the direct transmission of technical advertising data to Yandex. Yandex and participating advertising partners process the data they receive under their own policies and retention periods.
The Controller separately activates AppMetrica with its own key for installation attribution and basic-session measurement. On the first launch, the SDK reports Application activation and may obtain INSTALL_REFERRER from a supported store, including Google Play and RuStore, to associate that launch with an advertising click. After successful attribution, AppMetrica may send VK Ads an installation notification and campaign-related technical identifiers.
5.2. To load, display, measure, and protect advertising, the SDK may collect on the device and transmit directly to Yandex the IP address, device model and settings, Android and Application versions, language, network information, ad placement, loading, impression, click, reward confirmation, and information needed for frequency control, invalid-traffic prevention, security, and legal compliance. Where personalization is allowed, the Android advertising identifier and other permitted advertising signals may also be used where available.
5.3. The Application or package identifier and advertising placement can associate a technical event with use of this particular Application. Such information should therefore not be treated as fully anonymous merely because it does not include the User’s name.
5.4. The Application does not add diary content, symptoms, diagnoses, medication, food or bowel information, sleep, mood, stress, photographs, notes, reminder text, report or export contents, the Application PIN, local record identifiers, or recipients selected by the User to advertising requests.
5.5. The Application does not request location permission for advertising and does not enable coordinate transmission through the SDK locationConsent parameter. An IP address may nevertheless allow the advertising provider to infer an approximate region under its own policy.
5.6. Before the first advertising request, the User receives a prominent separate disclosure and a personalization choice where required by law, store rules, or the advertising-service configuration. The User may allow personalization or choose advertising without personalization. The choice is stored locally, passed to the SDK in the manner required by its current version, and can be changed later in the Application settings.
5.7. Choosing advertising without personalization is not an opt-out from advertising. Banner and native advertisements continue to be displayed subject to SDK capabilities, advertising inventory, and applicable law. The Application passes the selected setting to the advertising SDK and does not add diary information or its own targeting parameters. Technical information needed for delivery, measurement, frequency control, security, and fraud prevention may still be processed for advertising without personalization.
5.8. The Application does not provide a user-selectable mode that disables all advertising. Rewarded advertising starts only after a separate express User action. Ads may be temporarily unavailable because of inventory, network conditions, technical failure, or regional legal restrictions. In a region where any SDK processing requires broader consent, a separate regional flow is used or Application distribution is restricted. SDK data is transmitted over an encrypted connection according to Yandex documentation, and the advertising identifier can also be managed through Android settings.
6. Android permissions and system functions
6.1. The Application does not request access to location, contacts, microphone, calendar, Health Connect, or health data held by other applications.
6.2. Reminder text may appear on the Android lock screen depending on the User’s notification settings. The User should use neutral wording where the device may be visible to other people.
- Camera / system photo picker. Purpose: adding a selected image to a local entry; the file is not sent to the Controller. If refused, photo features are unavailable; other functions continue to work.
- Notifications / exact reminders. Purpose: displaying reminders created by the User locally through Android. If refused, reminders may not appear or may be delivered imprecisely.
- Android biometric authentication. Purpose: unlocking the interface locally through Android system services. If refused, another supported access method may be used; biometric templates remain within Android.
- Internet access. Purpose: loading advertising and opening online links. If refused, advertising and network-dependent elements are unavailable.
- Android advertising identifier. Purpose: advertising personalization and measurement where the identifier is available and its use is permitted. If refused, personalization may be limited; ordinary advertising may continue. The identifier can be reset or deleted in Android.
7. Purposes and legal bases
7.1. The Controller processes data available to it only to respond to emails actually sent and troubleshoot technical issues; deliver, secure, and analyze visits to the website using Yandex Metrica; arrange advertising display, measure advertising events, and confirm rewards; attribute installations and evaluate advertising campaigns through AppMetrica; comply with legal obligations; and protect legal rights. Diary functions, local analytics, reminders, imports, and reports run on the User’s device and are not purposes for which the Controller processes diary contents.
7.2. Depending on the circumstances and applicable law, the Controller relies on the User’s request expressed by independently sending an email; performance of the Terms insofar as external services are concerned; separate consent to advertising personalization or broader advertising processing where required; consent to load website Yandex Metrica and analytics cookies expressed by selecting “Accept”; the legitimate interest in measuring installation sources and advertising effectiveness while minimizing transmitted data; the need to deliver and secure the website, prevent abuse, and protect legitimate interests without overriding User rights; and compliance with legal obligations.
7.3. The advertising-personalization choice, and consent to broader advertising processing where legally required, are not bundled with acceptance of the Terms. Turning personalization off does not turn advertising off and does not remove access to core diary functions. Where local law requires consent to any SDK processing, a separate regional procedure applies.
7.4. The Application does not make medical decisions, diagnose conditions, or carry out automated decision-making on behalf of the Controller that produces legal or similarly significant effects. Local analytics only organizes information on the device at the User’s direction.
8. Recipients and transfers
8.1. For data actually processed by the Controller or transmitted through external components integrated by the Controller, recipients may include:
8.2. The Controller does not sell personal data. Technical advertising data is transmitted directly to Yandex through embedded SDKs, installation and basic-session data is transmitted through AppMetrica, and website-visit data is transmitted through the Yandex Metrica tag. After successful attribution and where postback is configured, AppMetrica may send VK Ads an installation postback. These processes must match the actual Service configuration and application-store declarations.
8.3. Some recipients may be located, or may process data, outside the User’s country. Such processing is governed by the recipient’s policy and applicable law. Where a transfer qualifies as a cross-border transfer carried out by the Controller, the Controller follows the procedures required by applicable law before the transfer begins.
- Yandex and participating advertising partners for technical advertising data;
- Yandex for AppMetrica installation and basic-session data; VK Ads, where postback is configured, for the attributed-install notification and related campaign parameters;
- Yandex for website-visit data transmitted through the Yandex Metrica tag, including technical information and browser identifiers stored in cookies or localStorage;
- the Controller’s email provider for information voluntarily sent to support;
- the website hosting provider for standard network request logs;
- Android, the device manufacturer, the system-account provider, and an application store for data relating to their services;
- an application, cloud service, or person independently selected by the User when exporting or sharing a file; the transfer is initiated by the User and does not mean that the Controller receives the file;
- public authorities or other parties only where disclosure is legally required or needed to protect rights through an established procedure.
9. Retention, deletion, and backups
9.1. Local data is controlled by the User and remains until deleted through the Application, Application storage is cleared, the Application is uninstalled, or the device is reset. The Controller does not retain it and cannot remotely view, restore, or erase it.
9.2. Deletion within the Application does not remove previously exported files, reports already shared, or copies held in other applications. Those copies must be removed from the relevant recipients separately.
9.3. The Android build rules disable system backup and standard Android device-to-device transfer of Application data. To move data, the User may create a local export and import it on another device.
9.4. Emails actually sent to support and website technical logs are retained only as long as reasonably necessary to respond, maintain security, resolve disputes, and meet legal obligations, after which they are deleted or anonymized. Sensitive data received accidentally is deleted without undue delay. Yandex determines retention of advertising data, AppMetrica data, and website Yandex Metrica data under its service settings, policies, and applicable rules.
10. Security
10.1. The Controller applies reasonable and proportionate technical and organizational measures to data it actually receives and to the configuration of external components under its control. Security of the local diary also depends on the device, Android, and the User’s actions. No method of storage or transmission can guarantee absolute security.
10.2. The Application PIN restricts access through the interface but does not replace Android device locking and encryption. The User should secure the device, install Android updates, keep the PIN confidential, and carefully select recipients of exported files.
10.3. Biometric verification is performed by Android system services. The Application and Controller do not receive a fingerprint, face image, or other biometric template.
10.4. Selecting the support action opens an external email client and does not send a message automatically. The Application does not attach diary contents, reports, photographs, or health information. Before sending, the User should review the draft and avoid adding information that is not needed to describe the technical issue.
11. User rights
11.1. Subject to applicable law, the User may request information about data available to the Controller, request correction, restriction, cessation, or deletion, withdraw consent, object to processing, and complain to a competent authority or court.
11.2. Local diary contents are not held by the Controller and are managed by the User through the Application interface and Android settings. A request to the Controller cannot remotely restore, correct, or erase that data.
11.3. Requests may be sent to support@gastrodnevnik.ru. To protect information, the Controller may request details reasonably necessary to verify identity and connect the request to data held by the Controller, but will not request unnecessary documents where a less intrusive method is sufficient.
11.4. Advertising personalization can be changed in the Application privacy settings, and the advertising identifier can be managed through Android. Turning personalization off does not disable banner or native advertising and does not change installation attribution already completed. An objection to further AppMetrica processing or a request concerning data available to the Controller may be sent to support@gastrodnevnik.ru. On the website, consent to load Yandex Metrica is given by selecting “Accept” and can be changed by deleting cookies and localStorage through browser settings.
12. Age
12.1. The Application is intended only for persons aged 13 or older. Persons under 13 must not install or use the Application.
12.2. Before use, the User must confirm that they are at least 13. The Application does not create separate age-based profiles or use age information for profiling.
13. The gastrodnevnik.ru website
13.1. The website uses Yandex Metrica to understand visits, traffic sources, use of pages, and technical website operation. The analytics tag loads only after the visitor selects “Accept” in the notice. Before that action, Yandex Metrica does not run and the tag does not create analytics cookies or localStorage entries. If the visitor does not select the button, the website remains available without Yandex Metrica. The current interface does not provide a separate decline button; not selecting “Accept” means that no consent is given and the tag remains unloaded. Standard hosting logs may still be processed to deliver and secure the website and diagnose failures.
13.2. After “Accept” is selected, Yandex Metrica may use browser identifiers in cookies or localStorage and receive the IP address, page URL and referrer, date and time, browser, operating-system and device information, screen parameters, language, time zone, approximate region, and general page actions such as views, link clicks, and file downloads, depending on tag settings.
13.3. Local diary contents, the prepared support-email draft and support-email contents, health information, and exported files are not sent to Yandex Metrica. The Controller does not associate Metrica identifiers with local Application entries.
13.4. The website does not treat continued browsing, scrolling, or inactivity as consent to Yandex Metrica. The consent state is stored locally in the browser so that it does not need to be requested on every page. The User may remove that stored state through browser settings.
13.5. Following an external link takes the User to a third-party resource. The Controller does not control that resource’s privacy practices, although it aims to include only necessary and relevant links.
14. Changes, language, and contact
14.1. This Policy may be updated when the Services, SDKs, recipients, law, or store requirements change. Material changes are published on the website and, where practical, communicated in the Application before new processing begins.
14.2. Russian privacy version: https://gastrodnevnik.ru/privacy/. English privacy version: https://gastrodnevnik.ru/en/privacy/. Terms of Use: https://gastrodnevnik.ru/en/terms/. If the language versions conflict, the Russian text prevails unless mandatory law requires otherwise.
- Controller: Individual Entrepreneur Chaplygin Artem Eduardovich
- TIN (INN): 463252089851
- OGRNIP: 326460000030126
- Email: support@gastrodnevnik.ru
