Privacy Policy
CarbTrack is a health app for people living with diabetes. We take your health data seriously. This policy explains exactly what we collect, why, and the controls you have over it.
Questions? Contact [email protected] ↗🔍 Privacy at a glance
- What we collect: account info (email, name), health data (glucose readings, meals, insulin, and Apple Health data you choose to share), community posts, and diagnostic data (device info, crash reports, IP address via Sentry error monitoring).
- Why we use it: to power the app's core features — meal logging, CGM and Apple Health sync, insights, notifications, and community — and to fix bugs.
- We do not sell your data to advertisers or data brokers. Ever.
- We do not run ads or use advertising trackers.
- Connected health sources: Dexcom, LibreView, and Apple Health data is only accessed when you explicitly connect or grant permission. You can disconnect or revoke permissions at any time.
- HealthKit limits: Apple Health data is never used for advertising, marketing, or data mining.
- Data retention: health data is kept while your account is active. Deleted items are purged within 90 days. Account deletion erases all personal data within 30 days.
- Your controls: you can disconnect CGM devices, delete individual meals and posts, and contact us to delete your account and all associated data.
- Age requirement: CarbTrack is intended for users aged 13 and older. We do not knowingly collect data from children under 13.
Section 01
Who we are
CarbTrack is operated by Kouidev. When this policy says "we", "us", or "our" it refers to Kouidev. If you have questions about this policy, please contact us at [email protected].
Section 02
Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, display name | You, via Clerk authentication |
| Health profile | Diabetes type, weight, age, insulin regimen, activity level, glucose targets, timezone | You, during onboarding & settings |
| Glucose readings | Blood glucose values, timestamps, reading source (manual, Dexcom, LibreView, Apple Health) | You (manual), CGM integration (Dexcom / LibreView), or Apple Health when you grant permission |
| Apple Health data | Steps, workouts, active energy, glucose samples, timestamps, source/device metadata, and sync status | Apple Health on your device, only after you grant HealthKit permission |
| Meal & nutrition data | Meal photos, ingredient names, carbs/fat/protein per item, serving sizes, eaten-at timestamp, AI-generated carb estimates | You; AI analysis powered by OpenAI |
| Insulin data | Insulin-to-carb ratios, logged doses, recommended dose calculations | You |
| Community content (UGC) | Post text and optional attached images, comments, reactions | You |
| Device & usage data | Device OS/version, app version, crash reports, error logs, IP address, and user/session identifiers (via Sentry error monitoring) | Automatically, from your device |
| Notification tokens | Push notification device token (Expo) | Automatically, when you grant notification permission |
Section 03
How we use your data
- Core app functionality: logging meals, recording glucose readings, computing insulin recommendations, and displaying your history and timeline.
- AI carb estimation: when you scan a meal photo, the image is sent to OpenAI's API to estimate nutritional content. The image is not stored by OpenAI for training without your consent under their API terms.
- AI voice logging: when you record a voice log, the audio is sent to OpenAI's API for transcription and structured data extraction (glucose readings, meals, insulin doses). Audio is not stored by OpenAI for training under their API terms.
- Insights & analytics: generating daily/weekly summaries, glucose trend analysis, and meal-impact reports — all computed server-side for your account only.
- CGM synchronisation: fetching your glucose data from Dexcom or LibreView at your request, so it appears in your timeline and insights.
- Apple Health synchronisation: importing Apple Health glucose, workout, step, and active-energy data you choose to share, so it can appear in your timeline, connected-device status, summaries, and insights.
- Notifications & alerts: sending push notifications for glucose alerts, meal reminders, and community activity you subscribe to.
- Community features: displaying your posts and comments to other users in the community rooms you join.
- Bug fixing & reliability: crash reports, error logs, and diagnostic data (including IP address and user session context) are sent to Sentry to help us identify and fix issues. This diagnostic data is not linked to your health records.
- Customer support: responding to support requests you initiate by email.
- Legal compliance: retaining records as required by applicable law.
We do not use your health data, including Apple Health data, for advertising, profiling for third-party marketing, data mining, or any purpose beyond what is described above.
Section 05
CGM integrations — Dexcom & LibreView
When you connect a Continuous Glucose Monitor account, CarbTrack will:
- Request an OAuth token (Dexcom) or authenticate with your LibreView credentials to fetch your glucose readings.
- Store the access token securely in our database to enable background synchronisation.
- Import glucose readings into your CarbTrack timeline and analytics.
- Never share your CGM credentials or data with any party other than the CGM provider itself.
You can disconnect any CGM integration at any time in Settings → Connected Devices. Disconnecting revokes our token and stops future syncs. Historical readings already imported remain in your account unless you request account deletion.
Section 06
Apple Health integration
Apple Health connection is optional. When you connect Apple Health and grant HealthKit permission, CarbTrack may read the Apple Health data types you approve, such as glucose samples, steps, workouts, and active energy.
- Permission-based access: CarbTrack can only read Apple Health data after you approve the HealthKit permission prompt. You can choose which data types to allow.
- How we use it: Apple Health data is used to add glucose and activity context to your timeline, summaries, connected-device status, and insights.
- What we store: imported readings and activity samples may be stored in your CarbTrack account so your history and insights stay available across app sessions.
- No advertising use: we do not use Apple Health data for advertising, marketing, third-party profiling, or data mining.
- Your controls: you can disconnect Apple Health in Settings → Connected Devices, revoke individual Health permissions in the iOS Health app or iOS Settings, or delete your CarbTrack account.
Disconnecting Apple Health stops future Apple Health syncs. Historical data already imported into CarbTrack remains in your account unless you delete individual readings where available or request account deletion.
Section 07
Your controls & how to delete your data
You have full control over your data. Here is how you can review, manage, and delete each type of data we store:
- Edit your profile: update your name, health profile, and alert settings any time in Settings.
- Delete meals: any meal can be deleted from the Meals History screen. Deleting a meal permanently removes the log, its nutritional data, and its associated photo.
- Delete posts & comments: you can delete your own community posts and comments at any time from the app. Deleted content is immediately hidden from other users and permanently purged from our servers within 90 days.
- Delete glucose readings: you can delete individual blood glucose readings from your history. Deleting a reading permanently removes it from your timeline and analytics.
- Delete insulin doses: you can delete individual logged insulin doses from your history. Deleting a dose permanently removes the record.
- Disconnect CGM devices: go to Settings → Connected Devices and tap Disconnect next to Dexcom or LibreView. This immediately revokes our access token, stops future data syncs, and deletes your stored CGM credentials from our servers.
- Disconnect Apple Health: go to Settings → Connected Devices and disconnect Apple Health to stop future syncs. You can also revoke individual Health permissions in the iOS Health app or iOS Settings.
- Manage AI consent: you can review what data is sent to third-party AI providers and revoke your consent at any time in Settings → AI & Privacy within the app.
- Manage device permissions: camera and photo library access can be revoked in your device's Settings app at any time. Notification permission can also be toggled there.
- Delete your account: contact us at [email protected] with the subject "Delete my account". We will permanently delete your account and all associated health data within 30 days. Community posts may be anonymised rather than individually deleted where doing so is technically required for integrity of existing threads.
Section 08
Security
- All data is transmitted over HTTPS / TLS — never in plain text.
- Authentication tokens are signed JWTs verified server-side on every request.
- API keys, CGM credentials, and connected-health sync credentials are stored encrypted in our database, not in plain text.
- Access to production data is restricted to authorised personnel only.
- We use Cloudflare as our network edge for DDoS mitigation and request filtering.
No system is perfectly secure. If you discover a security vulnerability, please report it responsibly to [email protected].
Section 09
Data retention & deletion
We retain your personal data only for as long as necessary to provide the CarbTrack service. Below is a detailed breakdown of how long each category of data is kept, and how it is deleted when you choose to remove it.
| Data category | How long we keep it | How to delete it |
|---|---|---|
| Account & profile data Email, display name, health profile, alert settings |
For as long as your account is active. On account deletion, permanently erased within 30 days. | Contact us at [email protected] to request account deletion. |
| Meal & nutrition data Meal logs, photos, ingredients, AI carb estimates |
For as long as your account is active. When you delete a meal, it is soft-deleted (hidden immediately) and permanently purged from our servers within 90 days. | Delete individual meals from the Meals History screen in the app. All meals are permanently deleted with your account. |
| Glucose readings Blood glucose values, timestamps, reading source |
For as long as your account is active. On account deletion, permanently erased within 30 days. | Delete individual readings from the BG Readings History screen in the app. All readings are permanently deleted with your account. |
| Apple Health data Glucose samples, steps, workouts, active energy, timestamps, source/device metadata |
For as long as your account is active. Disconnecting Apple Health stops future syncs. On account deletion, imported Apple Health data is permanently erased within 30 days. | Disconnect Apple Health in Settings → Connected Devices or revoke permissions in iOS. Delete individual glucose readings where available, or request account deletion to remove all imported Apple Health data. |
| Insulin data Insulin-to-carb ratios, logged doses |
For as long as your account is active. On account deletion, permanently erased within 30 days. | Delete individual doses from your insulin history in the app. All insulin data is permanently deleted with your account. |
| Community content Posts, comments, reactions, attached images |
Visible while your account is active. When you delete a post or comment, it is hidden immediately and permanently purged within 90 days. On account deletion, posts may be anonymised rather than deleted where required for thread integrity. | Delete individual posts and comments from the app. All community content is removed or anonymised on account deletion. |
| CGM connections Dexcom/LibreView access tokens and credentials |
Stored only while your CGM account is connected. Immediately deleted when you disconnect. | Disconnect anytime in Settings → Connected Devices. This immediately revokes our access and deletes your stored CGM credentials. |
| Apple Health connection Connection status, sync anchors, and permission-related sync metadata |
Stored only while Apple Health is connected. Deleted when you disconnect Apple Health or delete your account. | Disconnect anytime in Settings → Connected Devices or revoke Health permissions in iOS. |
| Device & diagnostic data Crash reports, error logs, IP address (Sentry) |
Retained per Sentry's data retention policy. On account deletion, user-identifiable context is removed from future error events. | Diagnostic data is automatically managed by Sentry. Account deletion removes your user context from future events. |
| Push notification tokens Expo push notification device token |
Stored while notifications are enabled. Deleted when you revoke notification permission or delete your account. | Revoke notification permission in your device Settings, or delete your account. |
| Cache & analytics data Redis caches, anonymised usage statistics |
Cached data is purged immediately on account deletion. Anonymised, aggregated statistics (e.g. total user count, crash rates) may be retained indefinitely as they cannot identify individuals. | Automatically cleared on account deletion. Anonymised aggregates cannot be deleted as they are not linked to any individual. |
Section 10
Children's privacy
CarbTrack is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, please contact us at [email protected] and we will delete the account promptly.
For users between 13 and 18, we recommend parental or guardian involvement in reviewing this policy and configuring the app's health settings.
Section 11
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via an in-app notice or email before the changes take effect. The "Last updated" date at the top of this page always reflects the most recent revision. Continued use of CarbTrack after the effective date constitutes acceptance of the revised policy.
Section 12
Contact us
Kouidev — CarbTrack Privacy Team
For privacy requests, data deletion, or policy questions:
[email protected]For general support:
[email protected]We aim to respond to all privacy-related requests within 5 business days.