Privacy Policy
Last updated: August 2026 · Effective date: August 2026
This Privacy Policy explains how Demi ("we", "us", "our") collects, uses, stores, and protects your personal information when you use the Demi app and related services. We take your privacy seriously — especially given the sensitive nature of health data.
By using Demi, you agree to the practices described in this Privacy Policy.
1. Who We Are
Demi is an independently developed and operated app based in Melbourne, Victoria, Australia. For privacy enquiries, contact us at hello@demiwellness.com.
2. What Data We Collect
2.1 Data you provide directly
Account information: your name and email address, provided when you create an account
Health and nutrition data: food diary entries, calorie and macronutrient information, water intake, weight entries, and free-text journal entries
Cycle data: period dates and flow, cycle mode selection, symptoms, and daily check-in responses (sleep, mood, stress, gut health, energy, and basal body temperature if you choose to record it)
Health conditions: conditions you optionally select, such as PCOS or endometriosis
Exercise data: activity type, duration, how it felt, and rest days
Recipes and custom foods: meals, recipes, and food items you create and save in the app
Profile settings: height, date of birth, weight, nutritional targets, water goal, tracking mode, and unit preferences
Feedback and enquiries: messages you send through the in-app feedback form, and the name, email address and message you submit through the contact form on our website
2.2 Data collected automatically
App usage data: crash reports and basic diagnostics needed to keep the app working
Device information: device type, operating system version, and app version
Subscription status: whether your trial or subscription is active, managed through Apple or Google
2.3 Data we do NOT collect
We do not collect your precise location
We do not access your contacts or microphone. The camera is used only when you explicitly open the barcode scanner, and images are processed on your device — they are never uploaded
We do not collect data from Apple Health or Google Fit (these integrations do not currently exist)
We do not show advertising and we do not use third-party advertising or analytics trackers
3. Local-First by Design
Demi stores your data on your device first. Your food diary, check-ins, cycle data, and settings live in the app’s local storage on your phone and work fully offline.
Cloud sync is optional. If you enable it, your data is securely synced to our cloud database so you can restore it if you change or reset your device. If you keep cloud sync off, your health data stays on your device, and deleting the app deletes that data.
When you search for foods, your search terms are sent to the food databases described in section 4 so results can be returned. Search terms are not linked to your identity by those services.
4. Third Parties We Use
We share data only with the service providers needed to run Demi, and never for advertising:
Supabase — our cloud database and authentication provider. Stores your account and, if cloud sync is enabled, your synced health data. Data is encrypted in transit and at rest.
Apple App Store / Google Play — process all payments and manage subscriptions. We never see your payment card details.
Open Food Facts — an open, non-profit food database. Your food search terms and scanned barcodes are sent to it to return nutrition results.
USDA FoodData Central — a public food database operated by the U.S. Department of Agriculture, used for additional nutrition results. Your search terms are sent to it.
Expo / EAS — build and update infrastructure, which may process crash diagnostics.
Squarespace: hosts our website and processes contact form submissions. Messages sent through the form are stored by Squarespace and forwarded to us by email.
Google Workspace: provides our email and file storage. Messages you send us, and our replies, are stored in our email system.
We do not sell your data. We do not share your data with advertisers, data brokers, or insurers. Ever.
5. How We Use Your Data
To provide the app’s features: your diary, trends, patterns, and cycle predictions are computed from the data you enter
To back up and restore your data when cloud sync is enabled
To manage your account, trial, and subscription
To respond to feedback and support requests
To fix bugs and keep the app reliable
Insights shown in Demi — including cycle-phase information — are general information computed on your device from your own entries. They are not medical advice, and your health data is never used to profile you for any other purpose.
6. Your Rights
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:
Access the personal information we hold about you
Correct information that is inaccurate or out of date (you can edit almost everything directly in the app)
Delete your account and data — available directly in the app under Profile → Privacy → Delete account
Complain to us, and if unresolved, to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au
If you are located outside Australia, you may have additional rights under your local law (such as the GDPR in Europe). Contact us and we will honour applicable requests.
7. Data Retention and Deletion
We keep your synced data for as long as your account exists. When you delete your account in the app, all of your data — your profile, diary entries, check-ins, cycle data, water, movement, weight, recipes, and custom foods — is permanently deleted from our servers, and your account record is removed. Data stored locally on your device is also cleared. This cannot be undone.
Deleting your account does not cancel an active subscription — subscriptions are managed by Apple or Google and must be cancelled in your App Store or Google Play settings.
8. International Transfers
Our cloud infrastructure may store data on servers located outside Australia. Where that occurs, we take reasonable steps to ensure your data receives protection consistent with the Australian Privacy Principles.
9. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted. No system is perfectly secure, but we design conservatively: local-first storage, minimal collection, no third-party trackers, and no advertising SDKs.
10. Children
Demi is not directed at children under 16, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.
11. Changes to This Policy
If we make material changes, we will notify you in the app before they take effect. The "Last updated" date at the top reflects the current version.
12. Contact
For any privacy questions or requests: hello@demiwellness.com
Demi is operated from Melbourne, Victoria, Australia.