Dietitian Studio
TRBack to home

Dietitian Studio

Privacy Policy

Effective date: 2026-08-07 · Last updated: 2026-08-10

Dietitian Studio (“Dietitian Studio”, “we”, “us”, or “our”) provides a practice-management web dashboard for dietitians and an invitation-only mobile app for their clients (“customers”). This Privacy Policy explains what personal data we process, why we process it, how it is shared, and the choices available to you.

By creating an account, activating an invitation, or using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.

1. Who this Policy covers

This Policy applies to:

  • Dietitians who register for the web dashboard and related account features.
  • Customers who activate a dietitian-issued invitation code and use the mobile app.
  • Visitors to our public marketing website.

2. Roles and responsibilities

Dietitian Studio is a multi-tenant platform. Each dietitian’s workspace is isolated; customer records are associated with exactly one dietitian.

For dietitian account data and platform operations (authentication, billing plan metadata, security logs, product analytics on our marketing and web apps), we act as an independent controller.

For customer nutrition, progress, messaging, and related care data that a dietitian collects through the Service, the dietitian typically acts as the controller of that client relationship, and we process that data on their behalf to provide the Service. Customers should contact their dietitian for care-related privacy questions, and may also contact us using the details below.

Dietitian Studio is not a medical device, clinic, or healthcare provider. Content in the Service is supplied or assigned by the dietitian and is not a substitute for professional medical advice, diagnosis, or treatment.

3. Personal data we collect

Depending on your role and how you use the Service, we may process the following categories of data.

  • Account and identity: name, email address, password (stored as a one-way hash), role (dietitian or customer), preferred language, account status, and authentication tokens.
  • Customer profile and care settings: contact details provided by the dietitian, goals (such as weight, water, or calorie targets), profile fields configured by the dietitian, and dietitian-private notes that are not shown to the customer.
  • Onboarding responses: answers to dietitian-configured questionnaires (for example allergies, habits, goals, or other intake information).
  • Program and adherence data: assigned diet programs, meal schedules, meal completion status, shopping-list derived items, and related usage.
  • Health-related tracking data: water intake logs, body weight, and body measurements entered by the customer or maintained for the customer’s program.
  • Communications and media: chat messages between a dietitian and a customer; attached images, voice notes, and documents (such as PDF or Word files); meal photos tied to meal slots; optional captions.
  • Device and notification data: push notification tokens and platform (for example iOS or Android) when notifications are enabled; local reminder preferences on the device.
  • Security and audit data: login and refresh-token metadata, and audit logs of tenant-visible actions (such as creates, updates, soft-deletes, and plan changes).
  • Website analytics: on our marketing site and dietitian web app we use Google Analytics 4, which may collect device/browser information, approximate location derived from IP, pages viewed, and similar usage metrics via cookies or similar technologies.
  • AI draft inputs (dietitians only): prompts and content sent when generating editable recipe or program drafts. Drafts are reviewed by the dietitian before anything is saved or assigned; AI does not publish plans automatically.

4. How we collect data

  • Directly from you when you register, activate an invitation, complete onboarding, log progress, chat, upload media, or contact us.
  • From your dietitian when they create your customer profile, configure forms, assign programs, or message you.
  • Automatically from your browser or device when you use the web apps (including analytics) or when the mobile app registers for push notifications.
  • From AI providers only when a dietitian requests a draft generation feature, limited to the content needed to produce that draft.

5. Why we use personal data

We process personal data to:

  • Provide, operate, and secure the Service (accounts, invitations, programs, messaging, media storage, and notifications).
  • Enable dietitians to manage clients and enable customers to follow assigned plans day to day.
  • Send transactional messages such as in-app or push notifications about chat, meal photos, or reminders you enable.
  • Enforce plan limits, prevent abuse, debug issues, and maintain audit trails.
  • Improve our public website and dietitian web product experience using aggregated analytics.
  • Comply with law, respond to lawful requests, and protect the rights, safety, and integrity of users and the Service.

6. Legal bases (where applicable)

Where GDPR or similar laws apply, we rely on one or more of: performance of a contract (providing the Service you requested); legitimate interests (securing and improving the platform, preventing fraud); consent (for example certain analytics or device permissions such as camera, microphone, photos, or notifications); and legal obligation.

Health-related and nutrition data may be processed as necessary to provide the Service requested by the dietitian–customer relationship, and—where required—on the basis of explicit consent or another available condition under applicable law. Dietitians are responsible for obtaining any client consents needed for their practice.

7. How we share data

We do not sell personal data. We share data only as described below.

  • Within a tenant: a customer’s data is available to their assigned dietitian (and not to other dietitians). Dietitian-private notes are not sent to customer-facing surfaces.
  • Service providers (processors): infrastructure and tooling such as cloud hosting and object storage (AWS), managed database hosting (MongoDB Atlas), push delivery (Expo / platform push services), email or operational tooling if enabled, AI model providers for dietitian draft features, and Google Analytics for website/web-app analytics.
  • Legal and safety: if required by law, regulation, legal process, or to protect rights, safety, or security.
  • Business transfers: if we undergo a merger, acquisition, or asset transfer, personal data may be transferred under appropriate safeguards and notice where required.

8. International transfers and hosting

Our primary application infrastructure is operated in the European Union (AWS region eu-central-1) with MongoDB Atlas as the database service. Some subprocessors (for example analytics, push, or AI providers) may process data in other countries.

Where required, we use appropriate transfer mechanisms (such as standard contractual clauses or provider terms) for cross-border processing.

9. Retention

We retain personal data for as long as needed to provide the Service and for legitimate business, security, and legal purposes.

Customer accounts are soft-deleted (marked deleted with a timestamp) rather than immediately erased from all systems, so that access can be revoked while preserving necessary audit and integrity controls. Associated media may remain until deleted through product flows or retention processes.

Audit logs and security records may be kept longer than day-to-day profile content. Analytics data is retained according to the analytics provider’s configuration and our operational needs.

When you request deletion, we will delete or anonymize personal data unless we must retain it (for example legal obligation, dispute resolution, or security).

10. Security

We use technical and organizational measures appropriate to the risk, including encrypted transport (HTTPS), hashed passwords, short-lived access tokens with rotating refresh tokens, tenant-scoped data access checks, private object storage for media with time-limited access URLs, and audit logging of tenant-visible mutations.

No method of transmission or storage is completely secure. Please use a strong unique password and protect your devices.

11. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability or withdrawal of consent.

  • Dietitians can update much of their account and client data in the web dashboard.
  • Customers can update available profile preferences in the mobile app (such as language) and should ask their dietitian for corrections to care profile data the dietitian controls.
  • Device permissions (camera, microphone, photos, notifications) can be changed in system settings; denying them limits related features.
  • You may request account or personal-data deletion via our delete-account page at https://dietitianstudio.com/en/delete-account-request, by contacting us at the email below, or—for signed-in customers—from the mobile Profile screen. You may also ask your dietitian to delete or deactivate the customer profile in the Service.
  • Where Google Analytics is used, you may use browser controls, Google’s tools, or similar opt-outs available in your region.

12. Children

The Service is directed to dietitians and adults they invite as clients. We do not knowingly collect personal data from children under 16 (or the higher age required in your country) without appropriate authorization. If you believe a child provided data inappropriately, contact us and we will take appropriate steps.

13. Invitation-only customers

Customers cannot self-register. A dietitian creates the customer record and shares a single-use invitation code. If you received an invitation, your dietitian has already created a profile for you in their workspace. Review this Policy and your dietitian’s own privacy notice (if any) before activating.

14. Third-party links and services

The Service may link to third-party sites or rely on OS-level services (app stores, push networks). Their privacy practices are governed by their own policies.

15. Changes to this Policy

We may update this Policy from time to time. We will revise the “Last updated” date and, when changes are material, provide additional notice as appropriate (for example in-product or by email). Continued use after the effective date of an update constitutes acceptance of the revised Policy where permitted by law.

16. Contact

For privacy requests or questions about this Policy, contact:

Email: privacy@copoints.com

Please include enough detail for us to verify your request and locate your account (role, email used in the Service, and dietitian relationship if you are a customer).

© 2026 Dietitian Studio. All rights reserved.privacy@copoints.com