Privacy Policy

syncsulin GmbH  ·  Version 2.1  ·  Last updated: July 2026

A Quick Note Before You Begin

We built syncsulin because managing blood sugar is demanding - and because you deserve tools that make it feel less like a chore and more like having a knowledgeable companion by your side. This Privacy Policy explains how we collect, use, and protect your personal data. We have written it to be as clear and straightforward as possible. If you have any questions, please reach out directly - we are a small, dedicated team and we genuinely want to hear from you.

1. Acceptance

By downloading, registering, or using the syncsulin app or website, you agree to the collection and use of your information as described in this Policy. If you do not agree, please do not use the service.

We may update this Policy at any time. The “Last Updated” date at the top reflects when this document was last revised. We will notify you of any material changes by posting a notice in the app or by sending you an email. Your continued use of the service after a material change takes effect constitutes your acceptance of the updated Policy. For changes to how we process health data, we will ask for your fresh consent.

2. Who We Are

syncsulin GmbH (“we”, “us”, “our”) is a technology company incorporated in Düsseldorf, Germany. We are building a personal AI-powered lifestyle and data tracking app for people who want to understand and manage their blood sugar - in particular those living with diabetes. syncsulin helps you log, visualise, and make sense of your own data, bringing together glucose readings, insulin, meals, activity, and sleep in one place, for your personal awareness and day-to-day wellbeing.

The app and all of its content are provided for informational and personal tracking purposes only. syncsulin does not provide medical advice, diagnosis, or treatment, and is not a medical device. It is not regulated as such under the EU Medical Device Regulation (MDR), the US FDA framework, or equivalent regulations in other jurisdictions. Nothing in syncsulin is a substitute for the advice of a qualified healthcare professional. Please always consult your doctor or care team for medical decisions.

3. What this Policy Covers

This Privacy Policy applies to all services offered by syncsulin GmbH, including:

  • Our website at www.syncsulin.com
  • The syncsulin app, available on the Apple App Store
  • All features and services offered through the above

It applies to all users worldwide, including residents of the EU/EEA, UK, United States, and all other countries. Where applicable law grants you specific rights, we describe them in Section 12.

4. Which Data Do We Collect And How

We collect information in three ways: data you provide directly, data collected automatically when you use the service, and data we receive from third-party sources you connect to the app. We collect only what we genuinely need.

4.1 On our website

DataWhyRetention
Email address (newsletter / waitlist sign-up)To send you updates about syncsulinUntil you unsubscribe
IP addressSecurity and spam prevention12 months
Browser and device infoTo keep the site working properly12 months
Squarespace analytics (aggregated)To understand how people use the site12 months

4.1a Donations (via Stripe)

We offer an optional donation feature on our website powered by Stripe. Donating is entirely voluntary. If you choose to donate, Stripe processes your payment details, name, email, and transaction metadata. Stripe acts as an independent data controller. Please review Stripe’s Privacy Policy. We never see or store your card data. Legal basis: Art. 6(1)(b) and Art. 6(1)(c) GDPR. Transaction records are retained for 10 years per § 147 AO.

4.2 In the app. Data you provide directly

CategoryExamplesRetention
Account informationName, email address, hashed password, profile photoUntil account deletion, or 10 years from last use - whichever comes first
Diabetes profileDiabetes type, therapy type, insulin brand, preferred glucose unit (mg/dL or mmol/L)Until account deletion
Manual health entriesBlood glucose readings, insulin doses, menstrual cycle dataUntil account deletion
Food diary entriesMeal entries with nutrition data (carbohydrates, calories, macros), food photosUntil account deletion
CGM and pump credentialsYour Dexcom, LibreLinkUp (Abbott), or Glooko login credentials, stored AES-256 encrypted. Encryption keys are held exclusively in our backend environment, never in the database.Until you disconnect the integration or delete your account
Communication dataMessages sent via in-app support or email, including metadata10 years from last exchange

4.3 In the app. Data collected automatically

When you use the app, we automatically collect certain technical and usage data. While this is not typically personal data on its own, we treat it as personal data wherever it can be combined with other information to identify you.

CategoryExamplesRetention
App and device dataDevice type, OS version, app version, IP address, screen resolution, language settings12 months
Usage dataCollected via Firebase Analytics. Pseudonymous app-instance ID, device model, OS version, app-usage events, coarse geolocation derived from IP. No health values are sent as event parameters.12 months from last use
Crash and error logsMobile: Firebase Crashlytics - crash stack traces, device state at crash time, Crashlytics UUID. Backend: Sentry - error events with stack traces, request route, and internal user ID. No IP addresses, no request bodies, no health values.12 months
Performance dataVia Firebase Performance Monitoring: app start-up times, screen rendering, network latency. Device info only - no health data.90 days
Push notification tokensDevice tokens for push-notification delivery via FCM (Google) and APNs (Apple). Required for glucose alerts.Until you disable notifications or delete your account
Remote config dataVia Firebase Remote Config: app-instance ID used to fetch server-controlled configuration values. No personal data stored.Session duration
Audit trailCompliance-relevant actions: account deletion requests, CGM connection lifecycle, consent decisions, data-export requests, glucose-alert changes. Internal user IDs only - no health values.3 years
Website log dataIP address, pages visited, time and date of visit, referring URL12 months

4.4 Data from Apple HealthKit

When you grant permission, the app reads health data from Apple Health on your iPhone. Specifically, we read:

  • Continuous glucose monitoring (CGM) readings and trends
  • Steps, heart rate, and heart rate variability (HRV)
  • Sleep data
  • Activity and workout data

Please note:

  • We primarily read from Apple Health. We also write data back in one specific case: when you manually log an insulin dose in syncsulin, that entry is written to Apple Health so your records stay consistent across apps. No other health data is written back without your explicit instruction.
  • HealthKit data is never used for advertising purposes.
  • HealthKit data is never shared with third parties for their own commercial use, in compliance with Apple’s developer policies.
  • HealthKit raw data is never sent to a third-party server. Derived metrics you choose to sync are stored in our EU database (Supabase, Ireland).
  • You can revoke HealthKit access at any time via iPhone Settings → Privacy and Security → Health → syncsulin.

4.5 Direct CGM and pump integrations

syncsulin can connect directly to your CGM or insulin pump data provider using your account credentials. This enables automatic background synchronisation of glucose readings and insulin delivery data, so your timeline stays up to date without manual imports.

ProviderWhat we accessHow credentials are stored
Dexcom (via Dexcom Share)Continuous glucose readings and trend data from your Dexcom accountYour Dexcom username and password are stored AES-256 encrypted in our database. Encryption keys are held only in our backend environment.
Abbott FreeStyle Libre (via LibreLinkUp)Continuous glucose readings from your LibreLinkUp accountYour LibreLinkUp email and password are stored AES-256 encrypted, as above.
GlookoInsulin delivery records and pump data from your Glooko accountYour Glooko credentials are stored AES-256 encrypted, as above.

Important notes:

  • Dexcom, Abbott, and Glooko are independent data controllers. The source data lives on their systems. You already have a direct relationship with these providers through your medical devices and/or clinic.
  • With your authorisation, we read your data from their systems. The copy we ingest is stored exclusively in our EU database (Supabase, Ireland).
  • We never send health data back to these vendors - only the credentials or authorisation needed to fetch your data.
  • You can disconnect any integration at any time in the app. Your credentials will be deleted from our systems immediately.
  • Legal basis: Art. 6(1)(b) GDPR and Art. 9(2)(a) GDPR.

4.6 Push notifications and glucose alerts

The app delivers glucose alerts and other time-sensitive notifications to your device. We want to be fully transparent about how this works technically.

Important: glucose values transit third-party infrastructure. Push notifications are delivered via Google’s Firebase Cloud Messaging (FCM) and Apple’s Push Notification service (APNs). This is architecturally unavoidable - mobile platforms only accept remote notifications through these official OS vendor gateways. Notification payloads may contain your current glucose reading and trend (for example: “Urgent Low - 54 mg/dL”). This means health data (GDPR Art. 9) momentarily transits Google’s and/or Apple’s global infrastructure at delivery time. Both process this under their own privacy policies and standard Data Processing Agreements. They do not use notification content for advertising purposes.

If you prefer not to have glucose values included in notification payloads, you can adjust notification settings in the app. You will still receive alerts, but without the glucose value displayed in the notification itself.

Legal basis: Art. 6(1)(b) GDPR and Art. 9(2)(a) GDPR.

4.7 Food diary and nutrition analysis

The app includes a food diary with AI-powered nutrition analysis. When you photograph a meal, the image is sent to Spike Nutrition AI for carbohydrate and nutrition estimation. The estimated nutrition values are returned to you and saved in your food diary in our EU database.

  • Spike receives a pseudonymous user identifier and the meal photo for analysis. Spike does not retain personal data from this process.
  • Meal photos are stored in our own Supabase file storage (Ireland) so you can view them in your diary history. You can delete individual entries at any time.
  • Legal basis: Art. 6(1)(b) GDPR.

5. Your Responsibilities as a User

  • Provide accurate information when setting up your account and connecting your devices.
  • Use the App only for its intended purpose - personal data tracking and visualisation.
  • Keep your login credentials confidential and notify us immediately if you believe your account has been compromised (privacy@syncsulin.com).
  • Not attempt to reverse-engineer, decompile, or tamper with the App or its infrastructure.
  • Not use the App in a way that could harm yourself, others, or the integrity of the service.
  • Not use the App for commercial purposes, to provide medical advice to others, or in any clinical setting without appropriate regulatory authorisation.

6. AI and Machine Learning: Always Your Choice

syncsulin’s core purpose is to use AI to help you understand your own glucose patterns and make better-informed decisions. With your separate, freely given consent, we may use pseudonymised health data to train and improve our machine learning algorithms for blood glucose trend prediction and personalised guidance.

Your data is processed under a randomly generated internal identifier - not your name or email. This is pseudonymisation, not full anonymisation: because glucose patterns can be highly individual, there is a small theoretical possibility of re-identification. We minimise this risk through strict access controls.

This processing is entirely optional:

  • It requires a separate, specific consent step during onboarding, clearly distinct from accepting this policy.
  • You can grant or withdraw this consent at any time in Settings → Privacy → AI Training.
  • Withdrawing has no impact on your access to the app.
  • Raw Apple HealthKit data is excluded from AI training.
  • Data is processed by Supabase (Ireland/AWS) and authorised development team members as data processors under Art. 28 GDPR. It is not shared with any other third party.
Why are we asking for this We are a small team building something that does not exist yet: a genuinely personalised layer for blood sugar management. We think it is only fair to be completely open about what that requires, and to make it genuinely optional.

7. How and Why We Use Your Data

PurposeLegal basis (EU/EEA/UK)Details
Run the app and display your dataArt. 6(1)(b) + Art. 9(2)(a) GDPRCore functionality
Automatic CGM/pump data synchronisationArt. 6(1)(b) + Art. 9(2)(a) GDPRBackground sync using your connected account credentials
Glucose alerts and push notificationsArt. 6(1)(b) + Art. 9(2)(a) GDPRTime-sensitive alerts via FCM/APNs
Food diary and nutrition analysisArt. 6(1)(b) GDPRMeal photo analysis via Spike Nutrition AI
App improvement and stabilityArt. 6(1)(f) GDPRAnalytics, crash monitoring, performance monitoring
Transactional emailsArt. 6(1)(b) GDPRWelcome email, account-deletion confirmation
AI/ML model trainingArt. 6(1)(a) + Art. 9(2)(a) GDPRSeparate, optional consent - see Section 6
Product updates and newsArt. 6(1)(a) GDPROnly if you opt in - unsubscribe any time
Legal complianceArt. 6(1)(c) GDPRGDPR documentation, legal disclosures
Security and fraud preventionArt. 6(1)(f) GDPRLegitimate interest in platform security

For US residents: we process your personal data based on your consent, our need to perform the services you have signed up for, our legitimate business interests, and our legal obligations. Where your state has specific privacy laws, Section 12 describes your rights in detail.

8. Who We Share Your Data With

Our commitment We do not sell or rent your personal data to any third party. We do not share your health data with advertisers, insurers, or any third party for their own commercial purposes.

8.1 Technical service providers

We work with trusted technical partners who process data strictly on our behalf under Data Processing Agreements (DPAs). They have no right to use your data for their own purposes.

ProviderRoleLocationData involved
SupabasePrimary database, authentication, file storage (avatars, food photos)EU - Ireland (AWS eu-west-1)All health and account data
RailwayApplication hosting - backend API, background worker, Redis cache. No health values are logged.EU - AmsterdamAll API traffic (transient); application logs with internal user IDs only
SentryBackend error monitoringEU - EU data storage regionError events with stack traces, request route, internal user ID. No IP, no request bodies, no health values.
ResendTransactional email deliverySends from EU (Ireland); metadata stored in USA - SCCsRecipient email address and email content. No health data.
Firebase Cloud Messaging (Google)Push notification delivery for glucose alertsGlobal Google infrastructure - SCCsDevice push tokens; notification payloads may contain glucose values (GDPR Art. 9 — see Section 4.6)
Firebase Analytics (Google)App-usage analyticsGlobal Google infrastructure - SCCsPseudonymous app-instance ID, device info, usage events. No health values.
Firebase Crashlytics (Google)Mobile crash reportingGlobal Google infrastructure - SCCsCrash stack traces, device state, Crashlytics UUID. No health data.
Firebase Performance (Google)App performance monitoringGlobal Google infrastructure - SCCsPerformance traces, device info. No health data.
Firebase Remote Config (Google)Server-controlled app configurationGlobal Google infrastructure - SCCsApp-instance ID only. No personal data stored.
Apple APNsPush notifications for Live Activities (real-time glucose on Lock Screen)Global Apple infrastructure - Apple DPADevice push tokens; Live Activity payloads contain current glucose reading (GDPR Art. 9 — see Section 4.6)
Spike Nutrition AIFood photo nutrition analysisSpike infrastructure - DPA in progressMeal photos and pseudonymous user ID. Spike does not retain personal data from this process.
GitHub (Microsoft)Source code repositoryUSA - SCCsSource code only - no user data
StripeDonation payment processing (independent controller)USA - SCCsDonation payment data - see Section 4.1a
SquarespaceWebsite hostingUSA - SCCsWebsite visitor data only

8.2 CGM and pump vendors (independent controllers)

Dexcom, Abbott (LibreLinkUp), and Glooko are independent data controllers, not our sub-processors. You already have a direct relationship with them through your medical devices and/or clinic. When you connect these accounts to syncsulin, we act as an authorised intermediary: with your explicit permission, we read your data from their systems and store the copy in our EU database. We never send health data back to these vendors - only the credentials needed to fetch it. Each vendor’s own privacy policy governs their independent processing.

8.3 Legal disclosures

We may share personal data with regulators, supervisory authorities, or law enforcement where we are legally required to do so. Where possible, we will notify you before making such a disclosure.

8.4 Business transfers

If syncsulin GmbH is ever involved in a merger, acquisition, or asset sale, your data may transfer to the successor entity. For health data specifically, we will ask for fresh consent before any transfer takes effect. We will notify you in advance and explain your rights.

9. International Data Transfer

We store all personal health data within the European Economic Area. Specifically, on Supabase servers in Ireland and our backend infrastructure on Railway in Amsterdam.

Several of our technical service providers are based outside the EU, primarily in the United States. All such transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, plus appropriate supplementary technical safeguards. Where providers also participate in the EU–US Data Privacy Framework, we additionally rely on that framework.

A note on Firebase/Google and Apple APNs Because push notification payloads may contain glucose values, health data (GDPR Art. 9) momentarily transits Google’s and Apple’s global infrastructure at delivery time. Both providers process this under their own Data Processing Agreements and SCCs. They do not use notification content for any purpose other than delivery.

If you would like a copy of the safeguards for any specific transfer, contact us at privacy@syncsulin.com.

10. How Long We Keep Your Data

Data categoryRetention periodReason
Account and profile dataUntil account deletionUser control
Health dataUntil you delete your accountUser control
CGM/pump credentialsUntil you disconnect the integration or delete your accountUser control
Food photosUntil you delete the diary entry or your accountUser control
AI training data (if consented)Until you withdraw consent or delete your accountUser control
Crash and error logs12 monthsTechnical necessity
Usage analytics12 months from last useTechnical necessity
Database backups7 days, then automatically deletedDisaster recovery
Audit trail3 yearsCompliance documentation
Account deletion log3 years after deletionSee note below
Support and email communication10 years from last exchangeLegal evidentiary standard
Newsletter / waitlist emailUntil you unsubscribeConsent-based
A note on the account deletion log When you delete your account, all your data is removed: every database row, all stored photos, your authentication record, and your push notification tokens. The only record that intentionally survives is a minimal entry in a dedicated deletion log containing: your internal user ID, the email address at time of deletion, an optional reason you provided, the request IP address, and the request/completion timestamps. This exists for two purposes: (a) if a database backup is ever restored, it identifies which accounts must be re-deleted; and (b) it serves as proof of deletion for compliance audits (GDPR Art. 17(3)(e)). Access is restricted to admins. Retained for 3 years.

You can request deletion of your account and all associated data at any time through the in-app account settings or by contacting us at privacy@syncsulin.com. We will confirm deletion within 30 days.

11. Security And Data Breach Notification

MeasureDetail
Encryption in transitTLS 1.3+ on all connections; database enforces SSL/TLS with certificate verification
Encryption at restAES-256, managed by Supabase
Credential encryptionCGM/pump account credentials encrypted AES-256; encryption keys held only in backend environment, never in the database
Authenticationbcrypt password hashing via Supabase Auth
Per-user data isolationTwo layers: backend service layer filters every query by user ID; all tables additionally protected by Postgres Row Level Security (RLS) as defence-in-depth
Network restrictionsDirect database access limited to an allowlist of approved IP addresses
Admin accessMulti-factor authentication required for all team members
Local storageHealth data is never persisted on your device. Only API authentication tokens are stored, in the iOS Keychain.
Access controlsPrinciple of least privilege: team members only access what they need for their role

All team members and contractors with access to personal data are bound by confidentiality agreements. In the event of a personal data breach we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and affected users without undue delay (GDPR Art. 34). California and Washington residents will be notified within 30 days of discovery.

12. Data Protection and Your Privacy Rights

12.1 General

syncsulin processes your personal data as data controller within the meaning of GDPR Art. 4(7). We do not sell your personal data. We do not use it for advertising. We use it only to provide, maintain, and improve the syncsulin service.

12.2 For Users in the European Union and EEA

Your data is processed on the basis of your explicit consent pursuant to GDPR Art. 6(1)(a) and Art. 9(2)(a). You may withdraw your consent at any time without this affecting the lawfulness of processing prior to withdrawal.

Your GDPR rights, exercisable at any time by contacting info@syncsulin.com:

  • Right of access (Art. 15 GDPR): to obtain confirmation of whether and what personal data we process about you.
  • Right to rectification (Art. 16 GDPR): to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17 GDPR): to request deletion of your data.
  • Right to restriction of processing (Art. 18 GDPR): to limit how we use your data.
  • Right to data portability (Art. 20 GDPR): to receive your data in a structured, machine-readable format.
  • Right to object (Art. 21 GDPR): to object to processing based on our legitimate interests.
  • Right to lodge a complaint with your national supervisory authority.
Lead supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf. www.ldi.nrw.de

We will respond to all GDPR requests within one month of receipt. Complex requests may be extended by a further two months with notice.

12.3 For Users in the United States

California (CCPA/CPRA): Right to know, delete, correct, opt out of sale/sharing (we do not sell or share your data), limit use of sensitive personal information, and non-discrimination. Contact: info@syncsulin.com. We respond within 45 days, extendable by 45 days for complex requests. Free of charge.

Washington State (WPA): Right to access, correct, delete, and port your personal data, and to opt out of targeted advertising and automated profiling. We do not engage in either. Contact: info@syncsulin.com. We respond within 45 days.

Other US states: Similar rights apply under Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other enacted state privacy laws. Contact us at info@syncsulin.com.

We do not knowingly collect personal information from residents of the United States who are under the age of 18, consistent with COPPA and applicable state laws.

12.4 Data Security

We implement appropriate technical and organisational security measures to protect your personal data, including encryption of data in transit (TLS) and at rest (AES-256), access controls, and regular security reviews. Health data is not stored locally on your device; only API authentication tokens are stored using your device’s secure storage (iOS Keychain). In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Art. 33 and 34.

13. Children’s Privacy

syncsulin is not intended for children under 16 (EU/EEA/UK) or under 13 (United States) without verified parental or guardian consent. We do not knowingly collect personal data from children below these thresholds. If you believe a child has registered without appropriate consent, please contact us at privacy@syncsulin.com and we will delete the account promptly.

14. Cookies And Tracking On Our Website

TypePurposeDuration
EssentialRequired for the site to work (navigation, session, consent memory)Session to 1 year
Analytics (Aggregate)Understand how visitors use the site at an aggregate level - no individual trackingUp to 12 months
PreferenceRemember your settings (language, cookie consent)Up to 12 months

We do not use advertising cookies or share website visitor data with ad networks. You can manage or withdraw cookie consent at any time through your browser settings or the cookie preference panel on the site.

15. Changes To This Policy

We may update this policy as syncsulin evolves. The “Last Updated” date at the top always reflects when it was last changed. For material changes, we will notify you by posting a prominent notice in the app and, where you have opted in to communications, by email. For changes that affect how we process your health data, we will ask for fresh, explicit consent.

16. Contact Us

Questions, requests, concerns: we are always happy to hear from you.

Emailprivacy@syncsulin.com
Postsyncsulin GmbH, Speditionsstraße 15a, 40221 Düsseldorf, Germany
Websitewww.syncsulin.com

We will acknowledge your request within 5 business days and respond fully within the timeframes required by applicable law (see Section 12).

17. Appendix: Managing Your Privacy Settings

SettingWhere to find it
Apple HealthKit accessiPhone Settings → Privacy and Security → Health → syncsulin
CGM/pump integrationssyncsulin app → Settings → Connections → [Provider name]
Push notificationssyncsulin app → Settings → Notifications, or iPhone Settings → Notifications → syncsulin
AI / ML training consentsyncsulin app → Settings → Privacy → AI Training
Analytics consentsyncsulin app → Settings → Privacy → Analytics
Marketing emails / newsletterUnsubscribe link in any email, or contact privacy@syncsulin.com
Cookie preferences (website)Cookie preference panel on www.syncsulin.com or browser settings
Account deletionsyncsulin app → Settings → Account → Delete Account, or contact privacy@syncsulin.com

Thank you for being part of the syncsulin® journey.