Privacy Policy
Last updated: 4 July 2026
SugarSnap is a personal diabetes-management app for logging glucose readings, meals, and medication, and for viewing continuous glucose monitor (CGM) data. This policy explains what data the app processes, why, and where it goes. It is written to describe how the app actually works rather than to cover every legal eventuality.
SugarSnap is invite-only. Your logged data is private to your account — other users cannot see it, and the app does not sell data or use it for advertising.
What data we process
Account and authentication
- An optional email address and display name you provide.
- Passkey (WebAuthn) credentials used to sign you in. Only the public key and device metadata (such as a device name you choose) are stored. The private key never leaves your device.
- Session records, which include your IP address and browser user-agent, used to keep you signed in and to help secure your account.
- The invite code used to register.
Health data you log
- Glucose readings (entered manually or imported from your CGM), with timestamps, trends, and optional context labels such as "fasting" or "before meal".
- Meals, including descriptions, categories, estimated nutrition (carbs, protein, fat, sugar, fibre), an optional photo, and the glucose level at the time of the meal.
- Medications and dose logs, including dosage, timing, and any notes you add.
- Your display preferences: glucose unit, target range, timezone, and theme.
Integration settings
- If you connect Nightscout, we store your Nightscout URL and API secret. The API secret is encrypted (AES-256-GCM) before it is saved.
- If you connect an external health destination (see Google Health below), we store the access and refresh tokens for that connection in encrypted form, plus the sync status of each exported reading.
- If you use the app's API or MCP access (for example, connecting Claude Desktop), we store a hashed API token or OAuth tokens. Plaintext tokens are never stored.
How we use your data
Your data is used only to run the features you use:
- To authenticate you and keep your session secure.
- To store, display, and let you edit your glucose, meal, and medication history.
- To fetch and cache CGM readings from your Nightscout instance, when configured.
- To export glucose readings to a destination you connect, when you enable it.
- To create backups so your data can be recovered.
Third-party services
SugarSnap relies on a small number of external services to operate:
- Hosting infrastructure — the app and its database run on a cloud hosting platform. Your data is stored there to provide the service.
- Cloudflare R2 — used to store encrypted database backups and, if you add them, meal photos.
- Nightscout — a CGM data service you host and configure yourself. SugarSnap reads glucose data from it only when you provide its address and API secret.
- Google Health — an optional export destination (see below).
- AI assistant clients — if you choose to connect an MCP client such as Claude Desktop, it can access your data through a token you issue, on your instruction.
We only share data with these services to the extent needed to provide the feature you have enabled. We do not sell your data or share it for advertising.
Google Health integration
If you connect Google Health, SugarSnap exports only your blood-glucose readings to your Google Health account. Meals, medications, notes, and other data are never sent to Google.
- The integration requests a single, write-only permission. SugarSnap can write glucose measurements to your Google Health account but cannot read any data from your Google account.
- You choose which readings are exported (manually entered, CGM, or both) and can start, pause, or disconnect the export at any time from Settings.
- When you disconnect, SugarSnap revokes its access tokens and stops sending data. Readings already written to Google Health are managed by you within Google Health.
SugarSnap's use of information received through Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Data retention and deletion
Your data is retained for as long as your account exists. You can delete individual glucose readings, meals, and medication entries at any time from within the app. When your account is deleted, its associated data is removed from the primary database. Encrypted backups are retained on a rolling basis and age out over time.
To request account deletion or ask a question about your data, contact us using the details below.
Security
- Authentication uses passkeys (WebAuthn) — there are no passwords to steal.
- Sensitive secrets (your Nightscout API secret and external connection tokens) are encrypted with AES-256-GCM before storage.
- API tokens and session tokens are stored only as hashes, never in plaintext.
- Traffic between your device and SugarSnap is served over HTTPS.
No system is perfectly secure, but these measures are intended to protect your data in storage and in transit.
Children
SugarSnap is intended for use by adults managing their own health, or by a parent or caregiver on behalf of someone in their care. It is not directed at children as independent users.
Changes to this policy
We may update this policy as the app evolves. When we do, we will update the "Last updated" date at the top of this page. Material changes to how data is handled will be reflected here before they take effect.
Contact
For privacy questions or data requests, contact privacy@sugarsnap.me.