Skip to content

Privacy Policy

Last Updated: August 1, 2026

This Privacy Policy describes how Retarget OÜ, a private limited company registered in Estonia (VAT number EE102572290), with its registered office at Sepapaja tn 6, 15551 Tallinn, Estonia (“Retarget OÜ,” “we,” “us,” “our,” or “Sugar Sense”), collects, uses, shares, and protects your personal data in connection with the Sugar Sense applications for iOS and watchOS and for Android and Wear OS, their related companion features (the Apple Watch and Wear OS apps, widgets, and Live Activity), our supporting cloud services, and our website (together, the “Services”).

Retarget OÜ is the data controller for the personal data processed through the Services within the meaning of Article 4(7) of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), which is the primary legal framework that applies to us as an Estonian-established company.

Sugar Sense is a continuous glucose monitoring (CGM) companion app. It connects to your existing glucose source, displays your glucose readings and trends, lets you log diabetes-related events, sends configurable alerts, lets you share your data with a Care Circle of people you choose, and offers optional features such as an AI food-carb estimator, AI insights, an emergency phone-call feature, and Apple Health and Health Connect integration. Because the Services process information about your health (in particular your glucose data), we treat the protection of this data with the highest priority.

Important medical and safety note. Sugar Sense is a supplemental information tool and is not a medical device, does not provide medical advice, and is not a substitute for your CGM’s own reader/receiver and its built-in alarms. Glucose data and alerts depend on third-party services, the internet, and Apple’s or Google’s push system, and may be delayed, missing, or fail. Do not rely on Sugar Sense as your only means of detecting low or high glucose. In an emergency, call your local emergency number (such as 112 or 911).

WHO WE ARE AND HOW TO CONTACT US

Controller: Retarget OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia. VAT number: EE102572290.

For privacy and data-protection questions, or to exercise your rights, contact us:

SUMMARY

  • We are an Estonian (EU) company; the GDPR is our primary legal framework.
  • Most of the data we process is health data (glucose readings, trends, logged insulin/medication/meals, alert thresholds, imported Apple Health or Health Connect metrics, and diabetes-profile answers). We process this special-category data on the basis of your explicit consent (GDPR Art. 9(2)(a)).
  • We connect to your glucose source using credentials or settings you provide: Abbott LibreLinkUp, optionally Dexcom Share or a self-hosted Nightscout site, or blood-glucose readings from Apple Health or Health Connect on your device. Your provider password and any Nightscout API secret are stored encrypted.
  • If you use the optional Care Circle feature, you can share your glucose readings, trends, LogBook, and statistics with followers you invite (for example a parent or carer). You stay in control and can revoke access at any time.
  • If you enable the optional emergency-call feature, we collect your phone number and an optional emergency-contact phone number and use Twilio (United States) to place automated voice calls on a confirmed low.
  • If you use the optional AI features, a food photo and/or aggregated, de-identified glucose statistics are sent to Anthropic (United States) for analysis. Food photos are processed transiently and are never stored. AI output is informational and dose-free.
  • We do not sell your personal data, and we never sell or share Apple Health (HealthKit) or Health Connect data with third parties for advertising or marketing.
  • You can permanently delete your account and associated data at any time from within the app.

PERSONAL DATA WE COLLECT

Account and identifiers

  • Sugar Sense account details: an optional name, email address, and password used to create and sign in to your Sugar Sense account, or the identity provided when you choose Sign in with Apple or Google Sign-In.
  • Account and device identifiers: your authentication user ID and a device identifier. On iOS this is Apple’s identifier for vendor, stored in the device keychain so it persists across app reinstalls; on Android it is an identifier the app generates itself (never derived from hardware identifiers), so a reinstall may create a new one. The device identifier is the primary key under which your data is stored and is sent with most requests. See also “Advertising identifier and App Tracking Transparency” below.
  • Push notification tokens: your iPhone and Apple Watch push notification device tokens, used to deliver alerts, silent data refreshes, and Live Activity updates through Apple Push Notification service (APNs), and, on Android, your Firebase Cloud Messaging (FCM) registration token, used to deliver alerts and silent data refreshes through Google’s push system.

Glucose-source connection

  • CGM and glucose-source credentials: the email or username and password for your Abbott LibreLinkUp account or (optionally) your Dexcom Share account, or, if you connect a self-hosted Nightscout site, the site address (URL) and the Nightscout API secret or access token. You enter these so that we can fetch your glucose data on your behalf. Your provider password, and any Nightscout API secret, are stored encrypted (AES-256-GCM) and are decrypted only to re-authenticate with your source. We also store the provider type and region (for Nightscout, the normalized site URL) and the session token or account identifier needed to keep the connection working. These are not your Sugar Sense account password.

Health data (special category)

  • Glucose readings and trends: continuous glucose values (stored in mg/dL) with timestamps and a trend-arrow indicator, fetched from your glucose source.
  • Logged events (LogBook): meals (including carbohydrates), insulin doses, activity/workouts, medication, and notes you log, with the glucose value and trend at the time of logging.
  • Alert configuration and thresholds: your personal low/high/very-low/very-high glucose limits (defaults 55/70/180/250 mg/dL), per-alert settings, snooze state, quiet-hours, and predictive-low settings. These reflect your clinical targets.
  • Glycemic statistics and insights: analytics computed from your glucose and events (such as Time in Range, GMI, variability, and detected patterns).
  • My Foods library: foods you save for quick re-logging, with carb values and usage counts.
  • Imported Apple Health or Health Connect metrics: see the “Apple Health (HealthKit)” and “Health Connect (Android)” sections below.
  • Diabetes profile (onboarding answers): answers you provide during onboarding, such as diabetes type, your care goal, concerns, how often you check, and which glucose source you use. These onboarding answers are sent only to our own backend and are not shared with our analytics provider.

Care Circle data

  • Care Circle connections: if you invite followers or follow someone, we store the connection (who follows whom and the access granted), the account email and display name of each participant, and a hashed form of each invite code (never the plain code). See “Care Circle and Family sharing” below for what is shared and with whom.

Emergency-call data (optional feature)

  • Your phone number: collected only if you enable the emergency-call feature, so that Sugar Sense can place an automated voice call to you on a confirmed low glucose.
  • Emergency-contact phone number: an optional phone number of a person you choose, called if you do not acknowledge the call to you. You must confirm that you have that person’s consent before adding their number.
  • Emergency-call records: the state of each emergency-call episode (timing, counters, whether you acknowledged, whether the contact was notified).

Optional AI feature data

  • Food photos: if you use the AI food scanner, the photo you capture or pick is sent for carb estimation. The photo is processed transiently and is never stored by us; only the analysis is returned. See “AI Features” below.
  • Barcodes: if you scan a packaged-food barcode, the barcode (no personal data) is looked up via Open Food Facts and/or USDA FoodData Central.

Subscription data

  • Purchase and subscription metadata: your subscription/entitlement status and transaction metadata, processed by Adapty together with Apple or Google. Billing is handled by Apple’s In-App Purchase system on iOS and by Google Play Billing on Android. We do not collect or store your payment card number.

Usage, diagnostic, and analytics data

  • Usage and funnel events: in-app events such as onboarding progress, feature usage, and paywall or purchase events, processed via Firebase / Google Analytics. These are engagement signals only: your onboarding answers (such as your diabetes type, care goal, concerns, and how often you check) are not sent to analytics; they stay on your device and are sent only to our own backend where a feature needs them.
  • Marketing-attribution and device identifiers: install and attribution identifiers, and your advertising identifier (on iOS only with your App Tracking Transparency permission; on Android the Google advertising ID), processed via Adjust and Google’s on-device conversion measurement, as described under “Advertising identifier and App Tracking Transparency” below.
  • Crash and diagnostic data: crash reports and diagnostics from the app (processed via Firebase Crashlytics) and server-side error diagnostics from our backend (processed via Sentry). These are designed to exclude your health data.
  • Technical data: limited technical information (such as app version, device/OS type, and the push environment) needed to operate and troubleshoot the Services.

We do not collect your precise geolocation, and we do not read your clipboard. (A support screen lets you tap a button to copy your device identifier to the clipboard; that is a user-initiated action and does not involve reading clipboard contents.)

PURPOSES FOR WHICH WE USE YOUR DATA

  • To connect to your glucose source and retrieve, display, and chart your glucose data and trends.
  • To deliver glucose alerts, silent data refreshes, predictive-low alerts, and Live Activity updates to your iPhone and Apple Watch, or to your Android phone and Wear OS watch.
  • To let you log and review diabetes events and to compute statistics and insights.
  • To enable Care Circle sharing with the followers you invite, and to deliver copies of your alerts to them.
  • To provide the optional emergency-call feature (calling you and, if needed, your emergency contact).
  • To provide the optional AI food-carb estimator and AI insights.
  • To integrate, where you enable it, with Apple Health (on iOS) or Health Connect (on Android).
  • To manage your subscription and entitlements, and to measure which marketing campaign led to an app install.
  • To provide customer support and to maintain, secure, debug, and improve the Services.
  • To send you first-party, opt-in communications (such as feature announcements), which you can unsubscribe from at any time.
  • To comply with legal obligations and to establish, exercise, or defend legal claims.

LEGAL BASES FOR PROCESSING (GDPR)

As an EU-established controller, we rely on the following legal bases under the GDPR:

  • Explicit consent (Article 9(2)(a)) for all health (special-category) data, including glucose readings and trends, logged insulin/medication/meal/carb data, alert thresholds, glycemic statistics, imported Apple Health or Health Connect metrics, your diabetes profile, the sharing of your data with a Care Circle follower, and any health data processed by the optional AI features. We collect this consent through a clear, separate, affirmative opt-in (not bundled into general terms acceptance), and you can withdraw it at any time.
  • Performance of a contract (Article 6(1)(b)) for providing the core Services you ask for (such as connecting to your glucose source, displaying data, and managing your account and subscription).
  • Consent (Article 6(1)(a)) for optional features you switch on (such as Care Circle sharing, the emergency-call feature, the AI features, Apple Health or Health Connect integration, marketing-attribution tracking through the App Tracking Transparency prompt on iOS, optional analytics where applicable, and marketing communications).
  • Legitimate interests (Article 6(1)(f)) for securing, debugging, and improving the Services and preventing abuse, where not overridden by your rights and freedoms.
  • Legal obligation (Article 6(1)(c)) where we must process data to comply with the law.

You can withdraw your consent at any time (for example by turning off an optional feature, or by deleting your account). Withdrawing consent does not affect processing already carried out before withdrawal.

RECIPIENTS AND SUB-PROCESSORS

We share personal data only with the providers needed to operate the Services. We do not sell your personal data. The recipients below process data on our behalf or as independent controllers for the stated, limited purposes:

Recipient Data shared Purpose Location
Abbott LibreLinkUp (LibreView) Your LibreLinkUp email and password (login); we receive your glucose readings and trends Authenticate and retrieve CGM glucose data Abbott’s LibreView servers, specific to your account region
Dexcom Share (optional) Your Dexcom account name (email) and password; we receive your glucose readings Optional alternative CGM source Dexcom’s servers, specific to your account region
Nightscout (self-hosted, optional) If you connect a Nightscout site: the site address and API secret you provide; we receive your glucose readings from it Optional self-hosted CGM source that you operate Your own self-hosted server (you choose and control its location)
Apple (APNs and HealthKit) Push device tokens and glucose/alert payloads (APNs); Apple Health data you authorize (HealthKit) Push notification delivery; Apple Health integration United States / on-device (Apple)
Twilio Your phone number and optional emergency-contact phone number; the glucose value spoken in the call Optional emergency voice calls on confirmed low glucose United States
Anthropic, PBC (Claude) Food photo (transient, never stored) and/or aggregated, de-identified glucose/health statistics (no name, no email, no raw reading stream) Optional AI carb estimation and AI insights United States
Adjust (AppLovin) Mobile-measurement and attribution data: a device and attribution identifier, install and session events, and your advertising identifier (on iOS the IDFA, only if you allow tracking in Apple’s App Tracking Transparency prompt; on Android the Google advertising ID, together with the Google Play Install Referrer). No glucose or health data is sent. Marketing-attribution measurement; this involves tracking (see “Advertising identifier and App Tracking Transparency”) Adjust GmbH, Germany (part of AppLovin, United States)
Google / Firebase Authentication tokens (Auth); usage/funnel and onboarding events, plus on-device ad-conversion measurement (Analytics); crash diagnostics (Crashlytics); remote config and content reads (Remote Config, Firestore); on Android, push device tokens and glucose/alert payloads (Firebase Cloud Messaging) Authentication; product analytics; crash reporting; configuration and content; push notification delivery on Android United States (Google Cloud)
Adapty Device and purchase/subscription transaction metadata, and the marketing-attribution identifier (no payment card number) Subscription and entitlement management United States
MongoDB Atlas (managed database) The primary database where your data is stored at rest: account identifiers, your encrypted CGM/Nightscout credentials, glucose history, logged events, alert configuration, Care Circle links, subscription status, and any feedback you send Primary, encrypted-at-rest storage of your account and health data European Union (Amazon Web Services region eu-west-1, Ireland)
Cloudflare Connection metadata for requests to our API and status pages, including your IP address. TLS is terminated at Cloudflare’s edge, so in-transit traffic to our API passes through it DNS, reverse proxy, TLS termination, content delivery, and web-application firewall (security) Cloudflare, Inc. (United States company); global edge network
DigitalOcean Runs our application server and an in-memory cache that may briefly hold glucose payloads and relayed authentication tokens. Your primary database is NOT hosted here Application compute hosting (the Node.js services, the scheduled worker, and the Redis cache) DigitalOcean, LLC (United States)
Sentry (Functional Software, Inc.) Server-side error and crash diagnostics: stack traces and a pseudonymous identifier only. A fail-closed filter removes credentials, tokens, email addresses, phone numbers, photos, and glucose values before any report is sent Backend error monitoring and reliability United States (Functional Software, Inc.)
Open Food Facts Scanned barcode only (no personal data) Packaged-food nutrition lookup EU (France)
USDA FoodData Central Scanned barcode only (no personal data) Fallback packaged-food lookup United States
Telegram (Telegram FZ-LLC) Only if you submit in-app feedback: your message text together with your display name and account email is relayed to our support channel Delivering your in-app feedback to our support team Telegram FZ-LLC (United Arab Emirates) / global

We may also disclose personal data to professional advisers, or to public authorities and law-enforcement bodies, where we are legally required to do so or where disclosure is necessary to protect our rights, your safety, or the safety of others. If we are ever involved in a merger, acquisition, or asset sale, your data may be transferred to the successor entity, and we will notify you before your data becomes subject to a different privacy policy.

APPLE HEALTH (HEALTHKIT)

If you enable Apple Health integration (a single, free, optional toggle in Settings), the app accesses Apple HealthKit on your device as follows:

  • Reads: blood glucose, steps, exercise minutes, active energy, workouts, resting heart rate, heart rate variability, sleep, body mass, body mass index (BMI), and blood pressure.
  • Writes: blood glucose readings back into Apple Health, marked as device-sourced.
  • Uploaded to our backend: a subset only (sleep, resting heart rate, heart rate variability, and imported workouts as activity events), which is used to compute insights and may be included, in aggregated and de-identified form, in the optional AI Insights feature.
  • Display only (never uploaded): body mass, BMI, and blood pressure are read for in-app display and are not sent to our servers.
  • Never collected: reproductive, menstrual, and pregnancy health data types are explicitly rejected and are never stored.
  • Apple Health as a glucose source (optional): if you choose Apple Health as your glucose source, the app reads your blood-glucose samples (value and timestamp, for example written by a glucometer or an over-the-counter sensor) from HealthKit on your device and uploads them to our backend so they can be charted and stored like any other glucose data. This is separate from, and additional to, the display-only Health integration described above, and these uploaded readings do not trigger server-side alerts or emergency calls.

Data obtained through Apple HealthKit is never used for advertising or marketing, and is never sold or shared with third parties for advertising, marketing, or data-mining purposes. You can revoke Health access at any time in the iOS Settings or Apple Health app.

HEALTH CONNECT (ANDROID)

On Android, Sugar Sense offers a free, optional integration with Health Connect, Android’s on-device health data store. It is off by default and is requested through Health Connect’s own permission screens, where you choose exactly which data types to allow. When you enable it, the app accesses Health Connect on your device as follows:

  • Reads: blood glucose, sleep, resting heart rate, heart rate variability, exercise (workout) sessions, steps, active calories burned, weight, and blood pressure.
  • Writes: your CGM blood glucose readings into Health Connect, at your explicit opt-in, so your other health apps and your care team can see your glucose history.
  • Uploaded to our backend: a subset only (sleep, resting heart rate, heart rate variability, and imported workouts as activity events), which is used to compute insights and may be included, in aggregated and de-identified form, in the optional AI Insights feature.
  • Display only (never uploaded): steps, active calories burned, weight, and blood pressure are read for in-app display alongside your statistics and are not sent to our servers.
  • Health Connect as a glucose source (optional): if you choose Health Connect as your glucose source, the app reads your blood-glucose records (value and timestamp, for example written by a glucometer app or an over-the-counter sensor app) from Health Connect on your device and uploads them to our backend so they can be charted and stored like any other glucose data. Records written by Sugar Sense itself are excluded from these reads. These uploaded readings do not trigger server-side alerts or emergency calls.
  • Background reads: only when Health Connect is your chosen glucose source, and only if you grant Health Connect’s separate background-read permission, the app periodically reads new blood-glucose records in the background so your glucose history stays current without opening the app. Background access is used for nothing else.

Data obtained through Health Connect is never used for advertising or marketing, is never sold, and is never shared with third parties for advertising, marketing, or data-mining purposes. Our use and transfer of Health Connect data is limited to providing and improving the user-facing features described above, consistent with Google’s Health Connect permissions policy. You can review or revoke Health Connect permissions at any time in the Health Connect settings on your device.

AI FEATURES

Sugar Sense offers optional, premium AI features that send limited data to Anthropic, PBC (United States) for analysis using the Claude model:

  • AI food scanner: the meal photo you capture or pick is transmitted for carbohydrate estimation. The photo is processed transiently and is never written to disk or stored by us; only the analysis (a carbohydrate range and related estimates) is returned.
  • AI Insights: aggregated, de-identified glucose/health statistics (such as average glucose, Time in Range, variability, your target range, and detected patterns) are transmitted. We do not send your name, email, or raw reading stream.

AI output is informational and educational only and is dose-free: it never provides insulin doses, units, carb ratios, or correction factors, and it returns carbohydrate estimates as ranges rather than precise figures. We do not use your data to train AI models, and the photo is not retained for training. Because these features process health data, we rely on your explicit consent (Art. 9(2)(a)), and the transmission to the United States is covered by the safeguards described in “International Transfers” below.

ADVERTISING IDENTIFIER AND APP TRACKING TRANSPARENCY

We use a mobile-measurement provider, Adjust (Adjust GmbH, Germany, part of AppLovin), and Google’s on-device conversion measurement (bundled with Firebase Analytics), to understand which marketing campaign led to an app install. Before any of this can access your device’s advertising identifier (IDFA), iOS shows you Apple’s App Tracking Transparency prompt during onboarding. If you choose “Ask App Not to Track”, your IDFA is not shared and no cross-app tracking takes place; attribution then relies only on non-IDFA device and attribution identifiers.

Adjust receives a device and attribution identifier, install and session events, and, only with your ATT permission, your IDFA. This attribution identifier is also passed to our subscription provider, Adapty, so that a subscription can be linked to its acquisition channel. We do not send glucose, health, or LogBook data to Adjust, AppLovin, or Google for advertising, and we do not sell your personal data. You can change your tracking choice at any time in iOS Settings (Privacy and Security, then Tracking).

On Android, there is no App Tracking Transparency prompt; instead, Adjust receives the Google advertising ID (GAID) together with install and session events, and install attribution additionally uses the Google Play Install Referrer. As on iOS, no glucose, health, or LogBook data is ever sent to Adjust, AppLovin, or Google for advertising, and Health Connect data is never used for advertising. You can delete or reset your advertising ID at any time in Android Settings (Privacy, then Ads).

EMERGENCY-CALL FEATURE

The emergency-call feature is optional and off by default. When you enable it, the app collects your phone number, and (if you choose) an emergency-contact phone number, and uses Twilio (United States) to place an automated voice call on a confirmed low glucose. If you do not acknowledge the call to you, the call may escalate to your emergency contact. You must confirm that you have your emergency contact’s consent before adding their number. We rely on your consent for this feature (including, for the emergency-contact escalation, the consent you confirm on the contact’s behalf).

This feature is not an emergency-dispatch or guaranteed life-safety service; it does not contact emergency services. It depends on third-party services, the internet, and the telephone network, and may be delayed or fail. In an emergency, call your local emergency number (such as 112 or 911).

CARE CIRCLE AND FAMILY SHARING

Sugar Sense includes an optional Care Circle feature that lets you share your diabetes data with people you choose (for example a parent, partner, or carer), and lets you follow someone who has invited you. This is genuine person-to-person sharing of health data, and it happens only when you invite a follower or accept an invitation. You stay in control: you can revoke access at any time, and access stops within about one minute.

What a follower you approve can see. When you grant access, the follower can view, in their own app and on a read-only basis:

  • your glucose readings and trend arrows, both live and historical;
  • your LogBook entries (meals and carbohydrates, insulin doses, activity, medication, and notes);
  • your glycemic statistics (such as Time in Range, GMI, variability, patterns, and streaks);
  • a summary of certain imported health metrics where available (sleep duration, resting heart rate, and heart-rate variability, from Apple Health or Health Connect);
  • copies of selected urgent alerts (very-low, very-high, predictive “heading low”, and readings-stopped), delivered as push notifications to the follower’s device and containing your glucose value and display name; and
  • if the follower enables it on a supported plan, a continuous “follower mirror” Live Activity showing your current glucose on their Lock Screen.

How invitations work. To add a follower you generate a single-use invite (a shareable code and link, for example via the sugarsense://care/join deep link) that expires after a limited time. We store only a hashed form of the code, never the plain code. When a follower accepts, we record that follower’s own account email and name to manage the connection and for support; this is not shown back to you. Your display name and chosen avatar are visible to your followers.

Plan and seats. Following someone, and being followed, is available without charge; some follower features (such as the follower-mirror Live Activity) and the Family plan, which provides a limited number of seats, require a paid subscription managed through Adapty and Apple.

Control and audit. You can revoke any follower at any time, which stops both their access and any live mirror within about one minute. For security and to maintain a consent trail, we keep a record of cross-account reads of your data (who accessed what, and when) for up to 90 days, and a revoked follow link is retained in a revoked state rather than deleted. We rely on your explicit consent (GDPR Article 9(2)(a)) for this sharing of health data. You are responsible for choosing whom you invite: a follower you approve can see the data listed above, so only invite people you trust.

Separately, an optional “Family messages” ping lets you send a simple acknowledgement notification that carries only a notification type and a display name (for example, to show “X pinged you”). That ping does not, by itself, share your glucose history, logs, or other health data.

INTERNATIONAL TRANSFERS

We are established in the European Union (Estonia), and your account and health data is stored at rest in the European Union (our managed database runs in Amazon Web Services’ Ireland region via MongoDB Atlas). However, some processing takes place outside the European Economic Area (EEA). Our application server is operated on DigitalOcean, traffic to our API passes through Cloudflare’s global edge, and a number of sub-processors are located in the United States or elsewhere, in particular Twilio (phone numbers and the spoken glucose value), Anthropic (food photos and aggregated health statistics), Google / Firebase (authentication, push delivery on Android, analytics, and crash data), Adapty (subscription metadata), Apple (push tokens and glucose payloads), Adjust and AppLovin (attribution data, Germany and the United States), Sentry (error diagnostics, United States), and, where you submit feedback, Telegram (United Arab Emirates).

Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V of the GDPR, such as the European Commission’s Standard Contractual Clauses, an adequacy decision, and/or the EU-U.S. Data Privacy Framework where applicable. You may request information about these safeguards using the contact details above.

HOW WE STORE AND SECURE YOUR DATA

We take appropriate technical and organisational measures to protect your personal data, including encryption in transit (HTTPS/TLS), encryption at rest, encryption of your CGM provider credentials and any Nightscout API secret with AES-256-GCM, and access controls. Your account and health data is stored in our managed database (MongoDB Atlas) hosted in the European Union (Amazon Web Services, Ireland), with point-in-time backups enabled. Our application server and cache are operated on DigitalOcean in the United States, where transient glucose payloads may sit briefly in memory or cache while the Services run; traffic to our API passes through Cloudflare’s global edge network. Our operational logs are minimised and time-limited. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

RETENTION OF DATA

We retain your account data, glucose readings, logged events, and imported health metrics for as long as your account remains active, in order to provide trends, statistics, and the Services. In addition, raw glucose readings are automatically pruned after about 365 days even while your account stays active. When you delete your account (see below), your data is irreversibly deleted from our active systems immediately, and in any event without undue delay. Copies in our routine database backups are then overwritten as those backups expire under our backup retention schedule. Food photos used by the AI scanner are never stored. We may retain limited records for longer where necessary to comply with legal obligations or to establish, exercise, or defend legal claims, including a security and consent-trail record of cross-account (Care Circle) access, which is kept for up to 90 days.

ACCOUNT DELETION

You can permanently delete your account and associated data at any time, directly in the app: go to Settings → Terms & account → Delete Account. This action is irreversible and takes effect immediately. It removes your profile and account row, your CGM and glucose-source credentials, your glucose history, your logged events, your alert configuration, your emergency-call records, your imported health metrics (from Apple Health or Health Connect), your My Foods library, your saved insight feedback, your subscription and entitlement record, your push notification tokens, your in-app feedback, your free-scan counter, and your authentication record.

Two points to note. First, for security and to preserve a consent trail, Care Circle follow links are set to a revoked state rather than erased, and the record of cross-account reads of your data is kept for up to 90 days before it self-deletes (pending Care Circle invitations are deleted). Second, copies of your data in our routine database backups persist until those backups roll off (see “Retention of data” above).

You can also sign out on a per-device basis (“Log out”), which clears the connection and push tokens on that device while keeping your account.

Deletion covers the data we hold. Where data has already been transmitted to a processor (for example, an aggregated statistic sent to Anthropic, or analytics events sent to Google), we will, where applicable, instruct the relevant processor accordingly; copies held by those processors are subject to their own retention and deletion practices.

YOUR DATA PROTECTION RIGHTS

Under the GDPR, you have the following rights regarding your personal data:

  • Access: to obtain confirmation of, and a copy of, the personal data we hold about you.
  • Rectification: to have inaccurate or incomplete data corrected.
  • Erasure: to have your personal data deleted (you can also do this yourself via in-app Account Deletion).
  • Restriction: to ask us to restrict processing in certain circumstances.
  • Objection: to object to processing based on our legitimate interests.
  • Data portability: to receive your glucose and event data in a structured, commonly used, machine-readable format.
  • Withdraw consent: to withdraw your consent at any time where we rely on it (including for health data, the optional features, and marketing), without affecting prior processing.

To exercise any of these rights, contact us at [email protected]. We will respond within one month, as required by Article 12(3) of the GDPR (this period may be extended for complex requests, in which case we will inform you). We may need to verify your identity before responding.

RIGHT TO LODGE A COMPLAINT

If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with a supervisory authority. As an Estonian-established controller, our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI), https://www.aki.ee. You may also lodge a complaint with the supervisory authority in your own EEA Member State of residence, place of work, or place of the alleged infringement.

WHEN YOU PROVIDE ANOTHER PERSON’S DATA

If you provide the personal data of another person (for example, an emergency-contact phone number, or by inviting a follower to your Care Circle), you confirm that you have a lawful basis and that person’s consent to do so, and that you have informed them how their data will be used. Retarget OÜ remains the data controller for that data.

CHILDREN’S PRIVACY

The Services are not directed to or intended for children. Because the Services process special-category health data, any permitted use by a minor must take place with the active involvement of a parent or guardian. The minimum age for digital consent under the GDPR in Estonia is 13; below that age, a parent or guardian must be involved. If we become aware that we have collected personal data from a child without a valid legal basis, we will delete it without undue delay. If you believe a child has provided us with personal data, please contact us at [email protected].

MARKETING COMMUNICATIONS

We may send you first-party communications from Retarget OÜ about Sugar Sense, only where you have opted in. We do not sell or share your contact details with third parties for their own direct marketing. You can opt out at any time using the unsubscribe link in our emails or by contacting [email protected].

COOKIES AND SIMILAR TECHNOLOGIES (WEBSITE)

This section applies to our website at sugarsense.io. The Sugar Sense app itself does not use web cookies; on the app it relies on the device identifiers and SDKs described above.

Our website uses cookies and similar technologies in two categories:

  • Strictly necessary cookies: these keep the site working and remember your cookie choice (for example, a first-party cookie that records whether you accepted optional cookies), together with security cookies that may be set by our content-delivery and security provider, Cloudflare. These do not require your consent.
  • Optional analytics cookies: set only if you accept them in our cookie banner. We use Google Analytics (loaded through Google Tag Manager) to understand how the site is used so we can improve it. We apply Google Consent Mode: until you give consent, analytics storage is denied and no analytics cookies are set. We do not use advertising or cross-site tracking cookies on the website.

When you first visit, our cookie banner lets you accept or reject the optional cookies. You can change or withdraw your choice at any time using the “Cookie settings” link in the website footer. Our web fonts are served from our own server (first-party), so simply viewing the site does not send a request to, or set a cookie for, a third-party font provider.

LINKS TO OTHER SERVICES

The Services may contain links to websites or services not operated by us. We are not responsible for the content or privacy practices of those third parties, and we encourage you to review their privacy policies.

CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last Updated” date above. For material changes, we will provide additional notice (for example, in-app or by email) where appropriate. Please review this Privacy Policy periodically.

CONTACT US

If you have any questions about this Privacy Policy or our handling of your personal data, please contact us:

By email: [email protected] (data protection) or [email protected]
By mail:
Retarget OÜ
Sepapaja tn 6, 15551 Tallinn, Estonia
VAT number: EE102572290