SugarSentry

SugarSentry Privacy Policy

Last updated: October 7, 2026

SugarSentry ("the app") shows glucose, insulin pump and sensor data from your own account with a compatible CGM provider, and passes on the alerts your pump reports. This page explains what data the app and its server collect, why, who can see it, and how to have it deleted. SugarSentry is not a medical device; see the Terms of Use.

Who is responsible for your data

TARMO SARI is the controller of the personal data described here. Contact: info@sinilumi.com.

Who this is for

The app is used by a parent or caregiver to follow a family member's CGM data, most often a child's, on the caregiver's own phone. The person who sets up the app is the account holder. If the data belongs to someone else, the account holder confirms that they are that person's parent or legal guardian, or have their permission. The monitored person does not need to use the app.

What we collect, and why

We do not collect advertising identifiers, use analytics or tracking tools, or sell or share your data for marketing.

Legal basis

Glucose and insulin data are health data. We process them only with your explicit consent, which you give by signing in with your CGM provider and turning on Background Sync, and which you can withdraw at any time by logging out. Everything else is processed because it is needed to provide the service you asked for.

Who can see your data

We do not share your data with anyone else, and never sell it.

How long we keep it, and how to delete it

When the last phone paired to a person logs out, that person's stored CGM provider token, cached readings and alert history are deleted from our server at once. A small settings record is kept so that pairing again restores your choices: the hashed username, display name, colour and display settings, and the hash of the web link. That record is deleted on request.

Because that record keeps the web link's hash, a shared link shows no data after logout, but shows data again if the same person is paired again. To end a shared link for good, create a new link before logging out, or ask us to delete the record.

To delete everything we hold, email us from the address below.

Security

All traffic between the app, our server and your CGM provider uses HTTPS/TLS. Provider tokens are encrypted at rest, and device secrets and web links are stored only as hashes.

Your rights

You can ask to see, correct, delete or receive a copy of your data, to restrict or object to how it is used, and you can withdraw consent at any time. You can also complain to a data protection authority, in the country where you live or in Estonia.

Changes to this policy

If this policy changes, the new version will be published here with a new date and, as the App Store requires, released with the app's next version.

Questions or data requests:
info@sinilumi.com