United States

Consumer Health Data Privacy Policy

Effective date: October 10, 2026

Your hives diary is personal. This page explains, in plain language, what consumer health data DuDa collects, why, who helps us handle it, and how you can see, correct, or delete it, or stop our collection of it.

1. Who we are and what this policy covers

DuDa is a diary app for people living with hives (urticaria). It is operated by NLAP, an independent developer based in South Korea (“DuDa,” “we,” “us”).

This Consumer Health Data Privacy Policy explains how we collect, use, share, and delete consumer health data from the DuDa app and duda.nlap.app. It is written for people in the United States, including under the Washington My Health My Data Act, Nevada’s consumer health data law (SB 370), and similar state laws such as Connecticut’s. It supplements our general Privacy Policy.

Because DuDa is a hives diary, we treat the health records you save, and information linked to you that could reveal that you use a hives diary, as consumer health data under this policy.

2. Consumer health data we collect

Health records you enter
The date of each record; hives and itch scores and their totals; detailed itch scores; affected body areas (including area names you type); swelling; notes; clinic visit times; medicine, injection, and other treatment records (including names you type); and food records (food names, which meal, where you ate, tags, and anything you type).
Photos
Skin or symptom photos you choose from your photo library or take with the camera, and where each photo is stored.
Consent records
When you give or withdraw consent for health records, we keep a record of it: the action, the time (in UTC), the version and language of the consent wording you saw, the app version, and the platform.
Account information
Your DuDa user ID and how you use DuDa: signed in with Kakao, Apple, or Google, or as a guest without signing in. If you sign in, we also receive your email address (which may be an Apple private relay address) and the name, nickname, or profile image your sign-in provider shares with us.
Support messages and error records
What you send us when you contact us or report a problem, and the status of your request. We also keep error records in our own database — the type and technical details of an error, and error summaries (an error code, the time, and how many times it happened) — together with your user ID.
Error reports sent to Sentry
When the app hits an error: the type and details of the error, a screenshot of the app screen at that moment (which may show records or photos that were on screen), related request and action logs, your user ID, an app install ID created by Sentry, device and operating system information, and your IP address.
App and device information
How many times and when you last opened the app (in UTC), app version, operating system and version, device model, manufacturer, and build information, and the device name and identifiers your operating system provides (such as Apple’s identifier for vendor). Some of these may not be available, depending on your operating system.

We do not request your precise location or your advertising identifier. DuDa does not diagnose or treat any condition; your records are for your own reference.

3. Where this data comes from

From you
Health records, notes, photos, consent choices, and support messages that you enter, choose, or take in the app.
From your device and the app
Error records, error reports, and app and device information, which the app sends automatically.
From your sign-in provider
If you sign in with Kakao, Apple, or Google, they share your account identifier and the profile information you allow on their consent screen. Google shares your Google account ID, email address and whether it is verified, your name, and your profile picture address. We use this only for your account and sign-in, and we do not access any other Google account data. They do not receive your health records from us. If you sign in with different methods that share the same verified email address, they may lead to the same DuDa account.
From our service providers
Network and security logs (such as IP address, user agent, and request time) created when the app or website connects to our providers.

4. How we use it

We use consumer health data only to provide the service you ask for:

Your diary
To save your records and photos and show them back to you, including charts and the “For your doctor” summary.
Backup and your devices
To keep your records with your account so they are backed up and you can see them on more than one device.
Your account
To sign you in, recover your account, and show your profile.
Support
To answer your questions and reports.
Keeping the app working
To find and fix errors, prevent them from happening again, check compatibility, and protect the service.

We do not use your consumer health data for advertising or to build advertising profiles, and we do not sell it. The DuDa app has no advertising or analytics SDKs, and DuDa does not use artificial intelligence.

6. Who we share it with

We disclose consumer health data only to the service providers (processors) below, who process it on our behalf and under our instructions to run DuDa:

Supabase, Inc. (USA)
Sign-in, database, photo storage, and account deletion. The database and photo storage are located in the AWS Seoul region (South Korea). Supabase and its approved subprocessors may access account and service data from other countries, including the United States, to operate, support, and secure the service.
Functional Software, Inc., doing business as Sentry (USA; compliance@sentry.io)
Error reports, including the screenshot taken when an error happens, which may show health records or photos that were on screen. Error reports are kept for 30 days and then deleted automatically.
Cloudflare, Inc. (USA)
Hosting for duda.nlap.app and the app’s update-check file, content delivery, and security. Cloudflare processes network information such as IP address, user agent, requested URL and time, and security events.

Kakao, Apple, and Google handle sign-in as independent companies under their own privacy policies. We do not give them your scores, notes, treatment or clinic records, food records, or photos.

NLAP has no affiliates, and we do not share consumer health data with any other third party unless you give separate consent or the law requires it.

Links to each company’s privacy policy are in section 12.

7. No sale and no geofencing

We do not sell consumer health data, and we do not exchange it for anything of value.

We do not use geofencing. DuDa does not request your precise location and does not set up virtual boundaries around health care facilities or any other place.

8. Where it is stored and how long we keep it

Health records and photos are stored with Supabase in the AWS Seoul region (South Korea) and are sent over encrypted connections.

We keep your data while you have a DuDa account. When you delete a single record in the app, it may be removed from your screens first (a “soft delete”) rather than erased right away; you can ask us to erase it completely (see section 9).

When you delete your account, your account and sign-in details are deleted, and your records are anonymized and no longer linked to your account. Your support messages and error records are also no longer linked to your account. None of this is restored or re-linked if you later create a new account.

Photos are stored privately: each photo file can be opened only by your own signed-in account through the app. When you delete your account, your photo files are deleted too.

Error reports are deleted automatically by Sentry after 30 days, and may remain for up to that time after you delete your account. Temporary files, caches, and settings on your device stay until they are overwritten, you delete the app, or your operating system clears them.

We may keep information separately, only as needed and for as long as needed, when the law requires us to keep it, to handle a dispute, or in security backups and logs kept by our service providers. It is deleted after that.

9. Your rights and how to use them

You have the right to:

Confirm and access
Ask whether we collect, share, or sell your consumer health data; get a copy of it; and get a list of the third parties and processors we have shared it with, with their contact details.
Correct
Ask us to correct information about you that is wrong.
Delete
Ask us to delete your consumer health data.
Withdraw consent
Withdraw your consent to our collection of your consumer health data at any time.

In the app, you can view all of your records at any time, delete a single record from that day’s record screen, withdraw consent in Settings, and delete your account from the bottom of Settings. If you no longer have the app, you can request deletion at duda.nlap.app/account-deletion.

For anything else — a copy of your data, a correction, a list of the processors we share it with, complete deletion of remaining records or photos (including after you delete your account), or asking us not to send error reports — email contact@nlap.app. Tell us how you used DuDa (Kakao, Apple, Google, or as a guest without signing in) and an email address where we can reply. Please do not send passwords, sign-in tokens, health records, or photos. We use the least information we need to confirm that the request comes from you. There is no charge.

After you delete your account, your remaining records are no longer linked to you, so we delete them to the extent we can confirm it is you and identify the data. If we can’t, we will tell you why. If you used DuDa as a guest, we may only be able to confirm a request made from the app itself; we will tell you what we can do.

For error reports, we delete the ones we can find and tell you when the rest will be deleted automatically (after 30 days). The app currently has no setting to turn off error reports, so a later error may send a new report, which is also deleted after 30 days. Asking us not to send error reports does not affect your ability to keep recording.

We respond within 45 days of receiving your request. If we need more time, we may extend this once by up to 45 more days, and we will tell you why within the first 45 days.

If we decline your request, you can appeal by replying to our decision or emailing contact@nlap.app with “Appeal” in the subject line. We will answer your appeal in writing within 45 days and explain our reasons. If your appeal is denied, you can contact your state attorney general. Washington residents can file a complaint with the Washington State Attorney General at atg.wa.gov/file-complaint.

We will not treat you differently, or deny you the service, because you used any of these rights.

10. How we protect it

We use encrypted connections, minimized logging, least-privilege access, and access policies. Access rules on our database and photo storage let only your own signed-in account read your records and photos through the app. Health records and photos are sensitive, so please take care when using a shared device or sharing screenshots and photos.

11. Changes to this policy

If this policy changes, we will let you know in the app or on this website before the change takes effect, and we will explain important changes in plain language. If a change affects what we collect or how we use or share consumer health data, we will ask for your consent again.

12. Contact us

NLAP (DuDa) — privacy contact: the DuDa operator.

Email us with any question or request about your consumer health data.