SugarSentry Privacy Policy
Last updated: October 7, 2026
SugarSentry ("the app") shows glucose, insulin pump and sensor data from your own account with a compatible CGM provider, and passes on the alerts your pump reports. This page explains what data the app and its server collect, why, who can see it, and how to have it deleted. SugarSentry is not a medical device; see the Terms of Use.
Who is responsible for your data
TARMO SARI is the controller of the personal data described here. Contact: info@sinilumi.com.
Who this is for
The app is used by a parent or caregiver to follow a family member's CGM data, most often a child's, on the caregiver's own phone. The person who sets up the app is the account holder. If the data belongs to someone else, the account holder confirms that they are that person's parent or legal guardian, or have their permission. The monitored person does not need to use the app.
What we collect, and why
- CGM provider sign-in. When you log in, the app gets an access token from your CGM provider's care-partner service on your behalf. With Background Sync on, this token is stored encrypted on our server, so it can keep checking for new readings and alerts while the app is closed. With Background Sync off, it stays only in your phone's Keychain.
- Glucose, insulin and device data. Sensor glucose readings, trend, active insulin and pump and sensor status (battery, reservoir, sensor life) are fetched from your CGM provider to show them to you and to pass on your pump's alerts.
- A display name you choose for each person, such as a child's first name, used to label alerts ("Emma - Low Glucose"), together with the colour and display settings you pick.
- A one-way hash of your CGM provider username, used to recognise the same account if you pair it again. The username itself is not stored.
- A push notification token from Apple and a secret your phone uses to identify itself to our server. Only a hash of the secret is stored.
- A "last checked in" time for your phone, which keeps its pairing and Lock Screen updates active and lets us remove a pairing that has gone quiet.
- A "last opened" time for the app on your phone, used only to stop repeating an alert once you have opened the app.
- The web link, if you create one. Only a one-way hash of it is stored, so we cannot read or recover the link itself.
- Messages you send with the support form: your email address, the subject and the message. They are passed straight on by email to our support inbox, so we can answer you, and are not stored on our server. The email is then kept like any other support email.
- Your IP address, held in memory for about a minute to limit repeated pairing attempts, or for up to an hour after you use the support form to limit spam, and not stored by us. Our hosting provider may keep standard connection logs.
We do not collect advertising identifiers, use analytics or tracking tools, or sell or share your data for marketing.
Legal basis
Glucose and insulin data are health data. We process them only with your explicit consent, which you give by signing in with your CGM provider and turning on Background Sync, and which you can withdraw at any time by logging out. Everything else is processed because it is needed to provide the service you asked for.
Who can see your data
- People you share the web link with. The web link is optional and only you can share it. It is random, cannot be guessed, and shows a read-only live view of one person's data to anyone who has it, without a login. You choose who gets it, such as a grandparent, a school nurse or a doctor. Create a new link and the old one stops working at once.
- Your CGM provider, the company whose care-partner service you sign in to, is where the data comes from. Your use of that service is covered by the provider's own privacy policy.
- Apple delivers push notifications to your phone. Delivery can involve Apple's servers outside the EU, under Apple's own safeguards.
- Fly.io hosts our server, in the EU.
We do not share your data with anyone else, and never sell it.
How long we keep it, and how to delete it
When the last phone paired to a person logs out, that person's stored CGM provider token, cached readings and alert history are deleted from our server at once. A small settings record is kept so that pairing again restores your choices: the hashed username, display name, colour and display settings, and the hash of the web link. That record is deleted on request.
Because that record keeps the web link's hash, a shared link shows no data after logout, but shows data again if the same person is paired again. To end a shared link for good, create a new link before logging out, or ask us to delete the record.
To delete everything we hold, email us from the address below.
Security
All traffic between the app, our server and your CGM provider uses HTTPS/TLS. Provider tokens are encrypted at rest, and device secrets and web links are stored only as hashes.
Your rights
You can ask to see, correct, delete or receive a copy of your data, to restrict or object to how it is used, and you can withdraw consent at any time. You can also complain to a data protection authority, in the country where you live or in Estonia.
Changes to this policy
If this policy changes, the new version will be published here with a new date and, as the App Store requires, released with the app's next version.
info@sinilumi.com