Privacy Policy
A Quick Note Before You Begin
We built syncsulin because managing blood sugar is demanding - and because you deserve tools that make it feel less like a chore and more like having a knowledgeable companion by your side. This Privacy Policy explains how we collect, use, and protect your personal data. We have written it to be as clear and straightforward as possible. If you have any questions, please reach out directly - we are a small, dedicated team and we genuinely want to hear from you.
1. Acceptance
By downloading, registering, or using the syncsulin app or website, you agree to the collection and use of your information as described in this Policy. If you do not agree, please do not use the service.
We may update this Policy at any time. The “Last Updated” date at the top reflects when this document was last revised. We will notify you of any material changes by posting a notice in the app or by sending you an email. Your continued use of the service after a material change takes effect constitutes your acceptance of the updated Policy. For changes to how we process health data, we will ask for your fresh consent.
2. Who We Are
syncsulin GmbH (“we”, “us”, “our”) is a technology company incorporated in Düsseldorf, Germany. We are building a personal AI-powered lifestyle and data tracking app for people who want to understand and manage their blood sugar - in particular those living with diabetes. syncsulin helps you log, visualise, and make sense of your own data, bringing together glucose readings, insulin, meals, activity, and sleep in one place, for your personal awareness and day-to-day wellbeing.
The app and all of its content are provided for informational and personal tracking purposes only. syncsulin does not provide medical advice, diagnosis, or treatment, and is not a medical device. It is not regulated as such under the EU Medical Device Regulation (MDR), the US FDA framework, or equivalent regulations in other jurisdictions. Nothing in syncsulin is a substitute for the advice of a qualified healthcare professional. Please always consult your doctor or care team for medical decisions.
3. What this Policy Covers
This Privacy Policy applies to all services offered by syncsulin GmbH, including:
- Our website at www.syncsulin.com
- The syncsulin app, available on the Apple App Store
- All features and services offered through the above
It applies to all users worldwide, including residents of the EU/EEA, UK, United States, and all other countries. Where applicable law grants you specific rights, we describe them in Section 12.
4. Which Data Do We Collect And How
We collect information in three ways: data you provide directly, data collected automatically when you use the service, and data we receive from third-party sources you connect to the app. We collect only what we genuinely need.
4.1 On our website
| Data | Why | Retention |
|---|---|---|
| Email address (newsletter / waitlist sign-up) | To send you updates about syncsulin | Until you unsubscribe |
| IP address | Security and spam prevention | 12 months |
| Browser and device info | To keep the site working properly | 12 months |
| Squarespace analytics (aggregated) | To understand how people use the site | 12 months |
4.1a Donations (via Stripe)
We offer an optional donation feature on our website powered by Stripe. Donating is entirely voluntary. If you choose to donate, Stripe processes your payment details, name, email, and transaction metadata. Stripe acts as an independent data controller. Please review Stripe’s Privacy Policy. We never see or store your card data. Legal basis: Art. 6(1)(b) and Art. 6(1)(c) GDPR. Transaction records are retained for 10 years per § 147 AO.
4.2 In the app. Data you provide directly
| Category | Examples | Retention |
|---|---|---|
| Account information | Name, email address, hashed password, profile photo | Until account deletion, or 10 years from last use - whichever comes first |
| Diabetes profile | Diabetes type, therapy type, insulin brand, preferred glucose unit (mg/dL or mmol/L) | Until account deletion |
| Manual health entries | Blood glucose readings, insulin doses, menstrual cycle data | Until account deletion |
| Food diary entries | Meal entries with nutrition data (carbohydrates, calories, macros), food photos | Until account deletion |
| CGM and pump credentials | Your Dexcom, LibreLinkUp (Abbott), or Glooko login credentials, stored AES-256 encrypted. Encryption keys are held exclusively in our backend environment, never in the database. | Until you disconnect the integration or delete your account |
| Communication data | Messages sent via in-app support or email, including metadata | 10 years from last exchange |
4.3 In the app. Data collected automatically
When you use the app, we automatically collect certain technical and usage data. While this is not typically personal data on its own, we treat it as personal data wherever it can be combined with other information to identify you.
| Category | Examples | Retention |
|---|---|---|
| App and device data | Device type, OS version, app version, IP address, screen resolution, language settings | 12 months |
| Usage data | Collected via Firebase Analytics. Pseudonymous app-instance ID, device model, OS version, app-usage events, coarse geolocation derived from IP. No health values are sent as event parameters. | 12 months from last use |
| Crash and error logs | Mobile: Firebase Crashlytics - crash stack traces, device state at crash time, Crashlytics UUID. Backend: Sentry - error events with stack traces, request route, and internal user ID. No IP addresses, no request bodies, no health values. | 12 months |
| Performance data | Via Firebase Performance Monitoring: app start-up times, screen rendering, network latency. Device info only - no health data. | 90 days |
| Push notification tokens | Device tokens for push-notification delivery via FCM (Google) and APNs (Apple). Required for glucose alerts. | Until you disable notifications or delete your account |
| Remote config data | Via Firebase Remote Config: app-instance ID used to fetch server-controlled configuration values. No personal data stored. | Session duration |
| Audit trail | Compliance-relevant actions: account deletion requests, CGM connection lifecycle, consent decisions, data-export requests, glucose-alert changes. Internal user IDs only - no health values. | 3 years |
| Website log data | IP address, pages visited, time and date of visit, referring URL | 12 months |
4.4 Data from Apple HealthKit
When you grant permission, the app reads health data from Apple Health on your iPhone. Specifically, we read:
- Continuous glucose monitoring (CGM) readings and trends
- Steps, heart rate, and heart rate variability (HRV)
- Sleep data
- Activity and workout data
Please note:
- We primarily read from Apple Health. We also write data back in one specific case: when you manually log an insulin dose in syncsulin, that entry is written to Apple Health so your records stay consistent across apps. No other health data is written back without your explicit instruction.
- HealthKit data is never used for advertising purposes.
- HealthKit data is never shared with third parties for their own commercial use, in compliance with Apple’s developer policies.
- HealthKit raw data is never sent to a third-party server. Derived metrics you choose to sync are stored in our EU database (Supabase, Ireland).
- You can revoke HealthKit access at any time via iPhone Settings → Privacy and Security → Health → syncsulin.
4.5 Direct CGM and pump integrations
syncsulin can connect directly to your CGM or insulin pump data provider using your account credentials. This enables automatic background synchronisation of glucose readings and insulin delivery data, so your timeline stays up to date without manual imports.
| Provider | What we access | How credentials are stored |
|---|---|---|
| Dexcom (via Dexcom Share) | Continuous glucose readings and trend data from your Dexcom account | Your Dexcom username and password are stored AES-256 encrypted in our database. Encryption keys are held only in our backend environment. |
| Abbott FreeStyle Libre (via LibreLinkUp) | Continuous glucose readings from your LibreLinkUp account | Your LibreLinkUp email and password are stored AES-256 encrypted, as above. |
| Glooko | Insulin delivery records and pump data from your Glooko account | Your Glooko credentials are stored AES-256 encrypted, as above. |
Important notes:
- Dexcom, Abbott, and Glooko are independent data controllers. The source data lives on their systems. You already have a direct relationship with these providers through your medical devices and/or clinic.
- With your authorisation, we read your data from their systems. The copy we ingest is stored exclusively in our EU database (Supabase, Ireland).
- We never send health data back to these vendors - only the credentials or authorisation needed to fetch your data.
- You can disconnect any integration at any time in the app. Your credentials will be deleted from our systems immediately.
- Legal basis: Art. 6(1)(b) GDPR and Art. 9(2)(a) GDPR.
4.6 Push notifications and glucose alerts
The app delivers glucose alerts and other time-sensitive notifications to your device. We want to be fully transparent about how this works technically.
If you prefer not to have glucose values included in notification payloads, you can adjust notification settings in the app. You will still receive alerts, but without the glucose value displayed in the notification itself.
Legal basis: Art. 6(1)(b) GDPR and Art. 9(2)(a) GDPR.
4.7 Food diary and nutrition analysis
The app includes a food diary with AI-powered nutrition analysis. When you photograph a meal, the image is sent to Spike Nutrition AI for carbohydrate and nutrition estimation. The estimated nutrition values are returned to you and saved in your food diary in our EU database.
- Spike receives a pseudonymous user identifier and the meal photo for analysis. Spike does not retain personal data from this process.
- Meal photos are stored in our own Supabase file storage (Ireland) so you can view them in your diary history. You can delete individual entries at any time.
- Legal basis: Art. 6(1)(b) GDPR.
5. Your Responsibilities as a User
- Provide accurate information when setting up your account and connecting your devices.
- Use the App only for its intended purpose - personal data tracking and visualisation.
- Keep your login credentials confidential and notify us immediately if you believe your account has been compromised (privacy@syncsulin.com).
- Not attempt to reverse-engineer, decompile, or tamper with the App or its infrastructure.
- Not use the App in a way that could harm yourself, others, or the integrity of the service.
- Not use the App for commercial purposes, to provide medical advice to others, or in any clinical setting without appropriate regulatory authorisation.
6. AI and Machine Learning: Always Your Choice
syncsulin’s core purpose is to use AI to help you understand your own glucose patterns and make better-informed decisions. With your separate, freely given consent, we may use pseudonymised health data to train and improve our machine learning algorithms for blood glucose trend prediction and personalised guidance.
Your data is processed under a randomly generated internal identifier - not your name or email. This is pseudonymisation, not full anonymisation: because glucose patterns can be highly individual, there is a small theoretical possibility of re-identification. We minimise this risk through strict access controls.
This processing is entirely optional:
- It requires a separate, specific consent step during onboarding, clearly distinct from accepting this policy.
- You can grant or withdraw this consent at any time in Settings → Privacy → AI Training.
- Withdrawing has no impact on your access to the app.
- Raw Apple HealthKit data is excluded from AI training.
- Data is processed by Supabase (Ireland/AWS) and authorised development team members as data processors under Art. 28 GDPR. It is not shared with any other third party.
7. How and Why We Use Your Data
| Purpose | Legal basis (EU/EEA/UK) | Details |
|---|---|---|
| Run the app and display your data | Art. 6(1)(b) + Art. 9(2)(a) GDPR | Core functionality |
| Automatic CGM/pump data synchronisation | Art. 6(1)(b) + Art. 9(2)(a) GDPR | Background sync using your connected account credentials |
| Glucose alerts and push notifications | Art. 6(1)(b) + Art. 9(2)(a) GDPR | Time-sensitive alerts via FCM/APNs |
| Food diary and nutrition analysis | Art. 6(1)(b) GDPR | Meal photo analysis via Spike Nutrition AI |
| App improvement and stability | Art. 6(1)(f) GDPR | Analytics, crash monitoring, performance monitoring |
| Transactional emails | Art. 6(1)(b) GDPR | Welcome email, account-deletion confirmation |
| AI/ML model training | Art. 6(1)(a) + Art. 9(2)(a) GDPR | Separate, optional consent - see Section 6 |
| Product updates and news | Art. 6(1)(a) GDPR | Only if you opt in - unsubscribe any time |
| Legal compliance | Art. 6(1)(c) GDPR | GDPR documentation, legal disclosures |
| Security and fraud prevention | Art. 6(1)(f) GDPR | Legitimate interest in platform security |
For US residents: we process your personal data based on your consent, our need to perform the services you have signed up for, our legitimate business interests, and our legal obligations. Where your state has specific privacy laws, Section 12 describes your rights in detail.
8. Who We Share Your Data With
8.1 Technical service providers
We work with trusted technical partners who process data strictly on our behalf under Data Processing Agreements (DPAs). They have no right to use your data for their own purposes.
| Provider | Role | Location | Data involved |
|---|---|---|---|
| Supabase | Primary database, authentication, file storage (avatars, food photos) | EU - Ireland (AWS eu-west-1) | All health and account data |
| Railway | Application hosting - backend API, background worker, Redis cache. No health values are logged. | EU - Amsterdam | All API traffic (transient); application logs with internal user IDs only |
| Sentry | Backend error monitoring | EU - EU data storage region | Error events with stack traces, request route, internal user ID. No IP, no request bodies, no health values. |
| Resend | Transactional email delivery | Sends from EU (Ireland); metadata stored in USA - SCCs | Recipient email address and email content. No health data. |
| Firebase Cloud Messaging (Google) | Push notification delivery for glucose alerts | Global Google infrastructure - SCCs | Device push tokens; notification payloads may contain glucose values (GDPR Art. 9 — see Section 4.6) |
| Firebase Analytics (Google) | App-usage analytics | Global Google infrastructure - SCCs | Pseudonymous app-instance ID, device info, usage events. No health values. |
| Firebase Crashlytics (Google) | Mobile crash reporting | Global Google infrastructure - SCCs | Crash stack traces, device state, Crashlytics UUID. No health data. |
| Firebase Performance (Google) | App performance monitoring | Global Google infrastructure - SCCs | Performance traces, device info. No health data. |
| Firebase Remote Config (Google) | Server-controlled app configuration | Global Google infrastructure - SCCs | App-instance ID only. No personal data stored. |
| Apple APNs | Push notifications for Live Activities (real-time glucose on Lock Screen) | Global Apple infrastructure - Apple DPA | Device push tokens; Live Activity payloads contain current glucose reading (GDPR Art. 9 — see Section 4.6) |
| Spike Nutrition AI | Food photo nutrition analysis | Spike infrastructure - DPA in progress | Meal photos and pseudonymous user ID. Spike does not retain personal data from this process. |
| GitHub (Microsoft) | Source code repository | USA - SCCs | Source code only - no user data |
| Stripe | Donation payment processing (independent controller) | USA - SCCs | Donation payment data - see Section 4.1a |
| Squarespace | Website hosting | USA - SCCs | Website visitor data only |
8.2 CGM and pump vendors (independent controllers)
Dexcom, Abbott (LibreLinkUp), and Glooko are independent data controllers, not our sub-processors. You already have a direct relationship with them through your medical devices and/or clinic. When you connect these accounts to syncsulin, we act as an authorised intermediary: with your explicit permission, we read your data from their systems and store the copy in our EU database. We never send health data back to these vendors - only the credentials needed to fetch it. Each vendor’s own privacy policy governs their independent processing.
8.3 Legal disclosures
We may share personal data with regulators, supervisory authorities, or law enforcement where we are legally required to do so. Where possible, we will notify you before making such a disclosure.
8.4 Business transfers
If syncsulin GmbH is ever involved in a merger, acquisition, or asset sale, your data may transfer to the successor entity. For health data specifically, we will ask for fresh consent before any transfer takes effect. We will notify you in advance and explain your rights.
9. International Data Transfer
We store all personal health data within the European Economic Area. Specifically, on Supabase servers in Ireland and our backend infrastructure on Railway in Amsterdam.
Several of our technical service providers are based outside the EU, primarily in the United States. All such transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, plus appropriate supplementary technical safeguards. Where providers also participate in the EU–US Data Privacy Framework, we additionally rely on that framework.
If you would like a copy of the safeguards for any specific transfer, contact us at privacy@syncsulin.com.
10. How Long We Keep Your Data
| Data category | Retention period | Reason |
|---|---|---|
| Account and profile data | Until account deletion | User control |
| Health data | Until you delete your account | User control |
| CGM/pump credentials | Until you disconnect the integration or delete your account | User control |
| Food photos | Until you delete the diary entry or your account | User control |
| AI training data (if consented) | Until you withdraw consent or delete your account | User control |
| Crash and error logs | 12 months | Technical necessity |
| Usage analytics | 12 months from last use | Technical necessity |
| Database backups | 7 days, then automatically deleted | Disaster recovery |
| Audit trail | 3 years | Compliance documentation |
| Account deletion log | 3 years after deletion | See note below |
| Support and email communication | 10 years from last exchange | Legal evidentiary standard |
| Newsletter / waitlist email | Until you unsubscribe | Consent-based |
You can request deletion of your account and all associated data at any time through the in-app account settings or by contacting us at privacy@syncsulin.com. We will confirm deletion within 30 days.
11. Security And Data Breach Notification
| Measure | Detail |
|---|---|
| Encryption in transit | TLS 1.3+ on all connections; database enforces SSL/TLS with certificate verification |
| Encryption at rest | AES-256, managed by Supabase |
| Credential encryption | CGM/pump account credentials encrypted AES-256; encryption keys held only in backend environment, never in the database |
| Authentication | bcrypt password hashing via Supabase Auth |
| Per-user data isolation | Two layers: backend service layer filters every query by user ID; all tables additionally protected by Postgres Row Level Security (RLS) as defence-in-depth |
| Network restrictions | Direct database access limited to an allowlist of approved IP addresses |
| Admin access | Multi-factor authentication required for all team members |
| Local storage | Health data is never persisted on your device. Only API authentication tokens are stored, in the iOS Keychain. |
| Access controls | Principle of least privilege: team members only access what they need for their role |
All team members and contractors with access to personal data are bound by confidentiality agreements. In the event of a personal data breach we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and affected users without undue delay (GDPR Art. 34). California and Washington residents will be notified within 30 days of discovery.
12. Data Protection and Your Privacy Rights
12.1 General
syncsulin processes your personal data as data controller within the meaning of GDPR Art. 4(7). We do not sell your personal data. We do not use it for advertising. We use it only to provide, maintain, and improve the syncsulin service.
12.2 For Users in the European Union and EEA
Your data is processed on the basis of your explicit consent pursuant to GDPR Art. 6(1)(a) and Art. 9(2)(a). You may withdraw your consent at any time without this affecting the lawfulness of processing prior to withdrawal.
Your GDPR rights, exercisable at any time by contacting info@syncsulin.com:
- Right of access (Art. 15 GDPR): to obtain confirmation of whether and what personal data we process about you.
- Right to rectification (Art. 16 GDPR): to correct inaccurate or incomplete data.
- Right to erasure (Art. 17 GDPR): to request deletion of your data.
- Right to restriction of processing (Art. 18 GDPR): to limit how we use your data.
- Right to data portability (Art. 20 GDPR): to receive your data in a structured, machine-readable format.
- Right to object (Art. 21 GDPR): to object to processing based on our legitimate interests.
- Right to lodge a complaint with your national supervisory authority.
We will respond to all GDPR requests within one month of receipt. Complex requests may be extended by a further two months with notice.
12.3 For Users in the United States
California (CCPA/CPRA): Right to know, delete, correct, opt out of sale/sharing (we do not sell or share your data), limit use of sensitive personal information, and non-discrimination. Contact: info@syncsulin.com. We respond within 45 days, extendable by 45 days for complex requests. Free of charge.
Washington State (WPA): Right to access, correct, delete, and port your personal data, and to opt out of targeted advertising and automated profiling. We do not engage in either. Contact: info@syncsulin.com. We respond within 45 days.
Other US states: Similar rights apply under Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other enacted state privacy laws. Contact us at info@syncsulin.com.
We do not knowingly collect personal information from residents of the United States who are under the age of 18, consistent with COPPA and applicable state laws.
12.4 Data Security
We implement appropriate technical and organisational security measures to protect your personal data, including encryption of data in transit (TLS) and at rest (AES-256), access controls, and regular security reviews. Health data is not stored locally on your device; only API authentication tokens are stored using your device’s secure storage (iOS Keychain). In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Art. 33 and 34.
13. Children’s Privacy
syncsulin is not intended for children under 16 (EU/EEA/UK) or under 13 (United States) without verified parental or guardian consent. We do not knowingly collect personal data from children below these thresholds. If you believe a child has registered without appropriate consent, please contact us at privacy@syncsulin.com and we will delete the account promptly.
14. Cookies And Tracking On Our Website
| Type | Purpose | Duration |
|---|---|---|
| Essential | Required for the site to work (navigation, session, consent memory) | Session to 1 year |
| Analytics (Aggregate) | Understand how visitors use the site at an aggregate level - no individual tracking | Up to 12 months |
| Preference | Remember your settings (language, cookie consent) | Up to 12 months |
We do not use advertising cookies or share website visitor data with ad networks. You can manage or withdraw cookie consent at any time through your browser settings or the cookie preference panel on the site.
15. Changes To This Policy
We may update this policy as syncsulin evolves. The “Last Updated” date at the top always reflects when it was last changed. For material changes, we will notify you by posting a prominent notice in the app and, where you have opted in to communications, by email. For changes that affect how we process your health data, we will ask for fresh, explicit consent.
16. Contact Us
Questions, requests, concerns: we are always happy to hear from you.
| privacy@syncsulin.com | |
| Post | syncsulin GmbH, Speditionsstraße 15a, 40221 Düsseldorf, Germany |
| Website | www.syncsulin.com |
We will acknowledge your request within 5 business days and respond fully within the timeframes required by applicable law (see Section 12).
17. Appendix: Managing Your Privacy Settings
| Setting | Where to find it |
|---|---|
| Apple HealthKit access | iPhone Settings → Privacy and Security → Health → syncsulin |
| CGM/pump integrations | syncsulin app → Settings → Connections → [Provider name] |
| Push notifications | syncsulin app → Settings → Notifications, or iPhone Settings → Notifications → syncsulin |
| AI / ML training consent | syncsulin app → Settings → Privacy → AI Training |
| Analytics consent | syncsulin app → Settings → Privacy → Analytics |
| Marketing emails / newsletter | Unsubscribe link in any email, or contact privacy@syncsulin.com |
| Cookie preferences (website) | Cookie preference panel on www.syncsulin.com or browser settings |
| Account deletion | syncsulin app → Settings → Account → Delete Account, or contact privacy@syncsulin.com |
Thank you for being part of the syncsulin® journey.