United States
Consumer Health Data Privacy Policy
Effective date: October 10, 2026
Your hives diary is personal. This page explains, in plain language, what consumer health data DuDa collects, why, who helps us handle it, and how you can see, correct, or delete it, or stop our collection of it.
1. Who we are and what this policy covers
DuDa is a diary app for people living with hives (urticaria). It is operated by NLAP, an independent developer based in South Korea (“DuDa,” “we,” “us”).
This Consumer Health Data Privacy Policy explains how we collect, use, share, and delete consumer health data from the DuDa app and duda.nlap.app. It is written for people in the United States, including under the Washington My Health My Data Act, Nevada’s consumer health data law (SB 370), and similar state laws such as Connecticut’s. It supplements our general Privacy Policy.
Because DuDa is a hives diary, we treat the health records you save, and information linked to you that could reveal that you use a hives diary, as consumer health data under this policy.
2. Consumer health data we collect
- Health records you enter
- The date of each record; hives and itch scores and their totals; detailed itch scores; affected body areas (including area names you type); swelling; notes; clinic visit times; medicine, injection, and other treatment records (including names you type); and food records (food names, which meal, where you ate, tags, and anything you type).
- Photos
- Skin or symptom photos you choose from your photo library or take with the camera, and where each photo is stored.
- Consent records
- When you give or withdraw consent for health records, we keep a record of it: the action, the time (in UTC), the version and language of the consent wording you saw, the app version, and the platform.
- Account information
- Your DuDa user ID and how you use DuDa: signed in with Kakao, Apple, or Google, or as a guest without signing in. If you sign in, we also receive your email address (which may be an Apple private relay address) and the name, nickname, or profile image your sign-in provider shares with us.
- Support messages and error records
- What you send us when you contact us or report a problem, and the status of your request. We also keep error records in our own database — the type and technical details of an error, and error summaries (an error code, the time, and how many times it happened) — together with your user ID.
- Error reports sent to Sentry
- When the app hits an error: the type and details of the error, a screenshot of the app screen at that moment (which may show records or photos that were on screen), related request and action logs, your user ID, an app install ID created by Sentry, device and operating system information, and your IP address.
- App and device information
- How many times and when you last opened the app (in UTC), app version, operating system and version, device model, manufacturer, and build information, and the device name and identifiers your operating system provides (such as Apple’s identifier for vendor). Some of these may not be available, depending on your operating system.
We do not request your precise location or your advertising identifier. DuDa does not diagnose or treat any condition; your records are for your own reference.
3. Where this data comes from
- From you
- Health records, notes, photos, consent choices, and support messages that you enter, choose, or take in the app.
- From your device and the app
- Error records, error reports, and app and device information, which the app sends automatically.
- From your sign-in provider
- If you sign in with Kakao, Apple, or Google, they share your account identifier and the profile information you allow on their consent screen. Google shares your Google account ID, email address and whether it is verified, your name, and your profile picture address. We use this only for your account and sign-in, and we do not access any other Google account data. They do not receive your health records from us. If you sign in with different methods that share the same verified email address, they may lead to the same DuDa account.
- From our service providers
- Network and security logs (such as IP address, user agent, and request time) created when the app or website connects to our providers.
4. How we use it
We use consumer health data only to provide the service you ask for:
- Your diary
- To save your records and photos and show them back to you, including charts and the “For your doctor” summary.
- Backup and your devices
- To keep your records with your account so they are backed up and you can see them on more than one device.
- Your account
- To sign you in, recover your account, and show your profile.
- Support
- To answer your questions and reports.
- Keeping the app working
- To find and fix errors, prevent them from happening again, check compatibility, and protect the service.
We do not use your consumer health data for advertising or to build advertising profiles, and we do not sell it. The DuDa app has no advertising or analytics SDKs, and DuDa does not use artificial intelligence.
5. Your consent
Before you save your first health record, the app asks for your separate consent to collect and store the health information described above. Existing users are asked once after the app update that introduces this screen. The consent screen explains what we collect, how we use it, where it is stored, and how long we keep it.
You can say no. Without consent you can’t save new records, but you can still view and delete the records you already have, or delete your account.
You can withdraw your consent at any time in the app: open Settings and tap “Withdraw consent for health records.” After you withdraw, the app stops saving new records. Records you already saved stay until you delete them or ask us to delete them (see section 9).
We do not share consumer health data with third parties other than the processors listed in section 6. If we ever want to share it for any other purpose, we will ask for your separate consent first. If we change what we collect or how we use it, we will update the consent wording and ask you again.
7. No sale and no geofencing
We do not sell consumer health data, and we do not exchange it for anything of value.
We do not use geofencing. DuDa does not request your precise location and does not set up virtual boundaries around health care facilities or any other place.
8. Where it is stored and how long we keep it
Health records and photos are stored with Supabase in the AWS Seoul region (South Korea) and are sent over encrypted connections.
We keep your data while you have a DuDa account. When you delete a single record in the app, it may be removed from your screens first (a “soft delete”) rather than erased right away; you can ask us to erase it completely (see section 9).
When you delete your account, your account and sign-in details are deleted, and your records are anonymized and no longer linked to your account. Your support messages and error records are also no longer linked to your account. None of this is restored or re-linked if you later create a new account.
Photos are stored privately: each photo file can be opened only by your own signed-in account through the app. When you delete your account, your photo files are deleted too.
Error reports are deleted automatically by Sentry after 30 days, and may remain for up to that time after you delete your account. Temporary files, caches, and settings on your device stay until they are overwritten, you delete the app, or your operating system clears them.
We may keep information separately, only as needed and for as long as needed, when the law requires us to keep it, to handle a dispute, or in security backups and logs kept by our service providers. It is deleted after that.
9. Your rights and how to use them
You have the right to:
- Confirm and access
- Ask whether we collect, share, or sell your consumer health data; get a copy of it; and get a list of the third parties and processors we have shared it with, with their contact details.
- Correct
- Ask us to correct information about you that is wrong.
- Delete
- Ask us to delete your consumer health data.
- Withdraw consent
- Withdraw your consent to our collection of your consumer health data at any time.
In the app, you can view all of your records at any time, delete a single record from that day’s record screen, withdraw consent in Settings, and delete your account from the bottom of Settings. If you no longer have the app, you can request deletion at duda.nlap.app/account-deletion.
For anything else — a copy of your data, a correction, a list of the processors we share it with, complete deletion of remaining records or photos (including after you delete your account), or asking us not to send error reports — email [email protected]. Tell us how you used DuDa (Kakao, Apple, Google, or as a guest without signing in) and an email address where we can reply. Please do not send passwords, sign-in tokens, health records, or photos. We use the least information we need to confirm that the request comes from you. There is no charge.
After you delete your account, your remaining records are no longer linked to you, so we delete them to the extent we can confirm it is you and identify the data. If we can’t, we will tell you why. If you used DuDa as a guest, we may only be able to confirm a request made from the app itself; we will tell you what we can do.
For error reports, we delete the ones we can find and tell you when the rest will be deleted automatically (after 30 days). The app currently has no setting to turn off error reports, so a later error may send a new report, which is also deleted after 30 days. Asking us not to send error reports does not affect your ability to keep recording.
We respond within 45 days of receiving your request. If we need more time, we may extend this once by up to 45 more days, and we will tell you why within the first 45 days.
If we decline your request, you can appeal by replying to our decision or emailing [email protected] with “Appeal” in the subject line. We will answer your appeal in writing within 45 days and explain our reasons. If your appeal is denied, you can contact your state attorney general. Washington residents can file a complaint with the Washington State Attorney General at atg.wa.gov/file-complaint.
We will not treat you differently, or deny you the service, because you used any of these rights.
10. How we protect it
We use encrypted connections, minimized logging, least-privilege access, and access policies. Access rules on our database and photo storage let only your own signed-in account read your records and photos through the app. Health records and photos are sensitive, so please take care when using a shared device or sharing screenshots and photos.
11. Changes to this policy
If this policy changes, we will let you know in the app or on this website before the change takes effect, and we will explain important changes in plain language. If a change affects what we collect or how we use or share consumer health data, we will ask for your consent again.
12. Contact us
NLAP (DuDa) — privacy contact: the DuDa operator.
Email us with any question or request about your consumer health data.
