Dyagnosys Health Analytics Logo

Privacy Policy

We prioritize your privacy and security

Privacy Policy — Dyagnosys Mobile Application

Last Updated: September 2026 Developer / Legal Entity: DYAGSOFTWARE LTDA (“Dyagnosys Health”)


1. Scope & Overview

This Privacy Policy describes how Dyagnosys Health (“Dyagnosys,” “we,” “us,” or “our”), operating under its legal entity DYAGSOFTWARE LTDA, collects, processes, safeguards, and shares personal and health data when you use the Dyagnosys Mobile Application (the “App”).

Dyagnosys Health is committed to protecting your privacy and handling your personal and health information with the highest standards of transparency, security, and care. This policy applies to all users of the App, regardless of where you are located, and is designed to comply with applicable privacy and data protection laws, including the European Union’s General Data Protection Regulation (“GDPR”) and Brazil’s Lei Geral de Proteção de Dados (“LGPD”).

By installing, accessing, or continuing to use the Dyagnosys Mobile Application, you acknowledge that you have read and understood this Privacy Policy.


2. Information We Collect

We collect the categories of information described below, strictly to provide and improve the Dyagnosys Health experience.

2.1 Biometric & Sensitive Data

Facial Expression Analysis. When you grant the App camera permission, facial landmarks and video frames are analyzed in real-time solely to infer emotional indicators (e.g., facial affect cues) that contribute to your wellness insights.

Speech & Voice Analysis. When you grant the App microphone permission, vocal audio is analyzed to detect vocal biomarkers associated with emotional states (e.g., tone, prosody, and other acoustic features).

On-Device Processing Notice (Crucial for Your Privacy). Dyagnosys Health processes sensitive biometric data with strict privacy safeguards:

  • All raw facial video frames and raw audio recordings are processed exclusively on-device in real-time using local edge inference models (ONNX Runtime).
  • Raw camera video and raw audio recordings are NEVER stored permanently on your device or anywhere else.
  • Raw camera video and raw audio recordings are NEVER transmitted over the internet.
  • Raw camera video and raw audio recordings are NEVER uploaded to any remote server, cloud service, or third party.
  • Only derived, aggregated emotion and wellness metrics (e.g., summarized affect scores, vocal biomarker summaries) are persisted and may be stored in your user account to power trends, insights, and recommendations.

2.2 Health & Wellness Metrics

  • Heart Rate Variability (HRV) measurements and related cardiac rhythm metrics.
  • Emotional state scores derived from on-device facial and vocal analysis.
  • User-entered wellness logs, including mood journals, notes, tags, and self-reported check-ins.

2.3 Device & Account Information

  • Account information: your name and email address used to create and manage your Dyagnosys account.
  • Device information: device model, operating system version, app version, and locale settings.
  • Anonymous crash diagnostics: de-identified crash reports and performance telemetry used solely to diagnose and fix stability issues.

We do not knowingly collect any personal data from children under the age of 13 (or such higher age as required by local law). If you believe a child has provided us with personal data, please contact us at [email protected] so we can promptly delete it.


3. How We Use Your Data

3.1 Purpose

We use the information we collect exclusively to:

  • Generate personalized mental health and emotional well-being insights for you.
  • Produce trend charts and longitudinal wellness reports based on your metrics over time.
  • Deliver wellness recommendations tailored to your historical emotional and physiological patterns.
  • Operate, maintain, secure, and improve the App, including diagnosing crashes and performance issues.
  • Authenticate your account and protect against unauthorized access.
  • Comply with applicable legal obligations.

3.2 Affirmative Commitments (Prohibitions)

Dyagnosys Health makes the following binding commitments regarding your data:

  • No Sale of Data. We do NOT sell, rent, lease, or trade your personal data, biometric information, or health data to third parties, data brokers, advertisers, advertising networks, or any other commercial entity.
  • No Advertising Use. We do NOT use your sensitive health, biometric, or emotional data for advertising, marketing, remarketing, or any form of user profiling.
  • No AI Training Without Consent. We do NOT use your personal data, biometric data, or health data to train public, commercial, or foundation AI/ML models without your explicit, informed consent.
  • No Government Backdoors. We do not provide any “backdoor” or unrestricted access to your data to any government or law enforcement agency except as strictly required by valid legal process under applicable law.

4. Third-Party Services & Data Sharing

Dyagnosys Health does not share your biometric data with any third party. The only third parties that may receive limited, non-biometric operational data are trusted infrastructure service providers operating under strict data processing agreements (DPAs) that prohibit secondary use of your data. These providers include, as applicable:

  • Encrypted cloud database hosting — for secure, encrypted storage of your account data and derived wellness metrics.
  • Authentication services — to verify your identity when you sign in to your account.
  • Error and crash reporting services — to receive de-identified crash diagnostics and performance telemetry.
  • Email delivery providers — to send you transactional emails (e.g., account verification, deletion confirmations).

Each of these providers is contractually obligated to process your data only on our documented instructions, to maintain confidentiality, and to implement appropriate technical and organizational security measures. We do not transfer your data to any third party for their own independent purposes.

If we are involved in a merger, acquisition, or sale of assets, your personal data may be transferred as a limited business asset, subject to this Privacy Policy. We will notify you before your data becomes subject to a different privacy policy.


5. Data Retention & Deletion Rights

5.1 Retention Limits

  • Account profile data (name, email): retained for as long as your account is active.
  • Derived wellness metrics and emotion/HRV summaries: retained for as long as your account is active, and no longer than necessary to provide the App’s features.
  • Raw biometric data (video frames, audio recordings): never retained. Processed in real-time, in memory only, and discarded immediately after derived metrics are produced.
  • Anonymous crash diagnostics: retained for up to 90 days for debugging purposes, in a de-identified form.
  • Backup copies: production database backups are retained for a maximum of 30 days, after which they are overwritten.

5.2 Your Right to Delete Your Account and Data

You have the right to permanently delete your Dyagnosys account and all associated personal and health data at any time. We provide two independent channels for deletion:

In-App Deletion

You can delete your entire account and all associated data directly from the App at any time by navigating to:

App Settings → Account → Delete Account

The deletion request will be processed immediately and your account will be scheduled for permanent erasure.

Web / Email Deletion Request

You may also request immediate account and data erasure through either of the following channels:

For your protection, we may need to verify your identity before processing a deletion request submitted outside the App.

5.3 Deletion Timeline

Once a deletion request is submitted (whether in-App, via the web, or via email):

  • Your account will be deactivated within 24 hours.
  • Your personal data and derived wellness metrics will be permanently purged from all production databases within 30 days of the request.
  • Data will be permanently purged from all backups within 30 days of the request.
  • After deletion is complete, your data is irrecoverable. We will send you a confirmation email once deletion has been finalized.

6. Data Security

Dyagnosys Health implements industry-leading technical and organizational safeguards to protect your personal and health data:

  • Encryption in transit: all network traffic between your device, our APIs, and our databases is protected using HTTPS with TLS 1.3.
  • Encryption at rest: all stored personal data, health metrics, and account information is encrypted at rest using AES-256 encryption.
  • Access controls: strict role-based access controls (RBAC), least-privilege principles, and audited access logs for all administrative operations.
  • On-device inference: raw biometric data is processed locally on your device and never leaves it, eliminating a large class of transit and storage risks.
  • Continuous monitoring: production systems are continuously monitored for anomalies, intrusion attempts, and security incidents.
  • Incident response: in the event of a data incident affecting your personal data, we will notify you and applicable supervisory authorities as required by GDPR, LGPD, and other applicable laws.

No method of transmission over the internet, however, and no method of electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.


7. Your Privacy Rights

Depending on your jurisdiction, you may have some or all of the following rights with respect to your personal data:

  • Right of access — to request a copy of the personal data we hold about you.
  • Right to rectification — to correct inaccurate or incomplete personal data.
  • Right to erasure / “right to be forgotten” — to request deletion of your personal data (see Section 5).
  • Right to restrict processing — to limit how we process your personal data.
  • Right to data portability — to receive your personal data in a structured, commonly used, machine-readable format.
  • Right to object — to object to processing based on our legitimate interests or for direct marketing.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.
  • Right to lodge a complaint — with your local data protection authority (e.g., ANPD in Brazil, a supervisory authority in the EEA, or other competent authority).

To exercise any of these rights, contact us at [email protected].


8. International Data Transfers

Dyagnosys Health operates globally. Your data may be processed in the country where you reside as well as in other countries where our service providers operate. When we transfer your personal data across borders, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or other lawful transfer mechanisms recognized under GDPR and LGPD.

Because all raw biometric data is processed exclusively on-device, it is never transferred across borders in raw form. Only derived, aggregated wellness metrics and account data may be transferred to our cloud infrastructure.


9. Children’s Privacy

The Dyagnosys Mobile Application is not intended for children under the age of 13 (or such higher age as required by local law, e.g., 16 in some EEA jurisdictions). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will take steps to delete the information as soon as possible. If you believe a child has provided us with personal data, please contact us at [email protected].


10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the App, or applicable law. When we make material changes, we will:

  • Update the “Last Updated” date at the top of this policy.
  • Notify you through the App and/or by email before the changes take effect, where required by law.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.


11. Contact Information & Data Protection Officer (DPO)

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, please contact us:

We will respond to your inquiry as soon as possible and within the timeframes required by applicable law.


This Privacy Policy is governed by the laws of the Federative Republic of Brazil and applicable international data protection regulations, including the GDPR and LGPD.