Legal Last updated:

Privacy Policy

CarbTrack is a health app for people living with diabetes. We take your health data seriously. This policy explains exactly what we collect, why, and the controls you have over it.

Questions? Contact [email protected]

🔍 Privacy at a glance

Who we are

CarbTrack is operated by Kouidev. When this policy says "we", "us", or "our" it refers to Kouidev. If you have questions about this policy, please contact us at [email protected].

ℹ️ Not medical advice. CarbTrack is a logging and tracking tool — it is not a medical device and does not provide medical advice. Always consult a qualified healthcare professional for medical decisions. Terms of Use apply.

Data we collect

Category Examples Source
Account data Email address, display name You, via Clerk authentication
Health profile Diabetes type, weight, age, insulin regimen, activity level, glucose targets, timezone You, during onboarding & settings
Glucose readings Blood glucose values, timestamps, reading source (manual, Dexcom, LibreView, Apple Health) You (manual), CGM integration (Dexcom / LibreView), or Apple Health when you grant permission
Apple Health data Steps, workouts, active energy, glucose samples, timestamps, source/device metadata, and sync status Apple Health on your device, only after you grant HealthKit permission
Meal & nutrition data Meal photos, ingredient names, carbs/fat/protein per item, serving sizes, eaten-at timestamp, AI-generated carb estimates You; AI analysis powered by OpenAI
Insulin data Insulin-to-carb ratios, logged doses, recommended dose calculations You
Community content (UGC) Post text and optional attached images, comments, reactions You
Device & usage data Device OS/version, app version, crash reports, error logs, IP address, and user/session identifiers (via Sentry error monitoring) Automatically, from your device
Notification tokens Push notification device token (Expo) Automatically, when you grant notification permission
⚠️ Community reminder: Community posts are visible to other CarbTrack users. Do not include sensitive personal health details (e.g. full medication doses, personal identifiers) in public posts.

How we use your data

We do not use your health data, including Apple Health data, for advertising, profiling for third-party marketing, data mining, or any purpose beyond what is described above.

Sharing & third parties

We do not sell your personal or health data. We share data only in the following limited circumstances:

Recipient What & why Your control
Clerk Authentication provider — stores your email and manages sign-in sessions. Account deletion removes your Clerk record.
Dexcom CGM data sync — we request glucose readings via Dexcom's OAuth API only when you connect your account. Disconnect anytime in Settings → Connected Devices.
LibreView (Abbott) CGM data sync — same as Dexcom; credentials used only to fetch your readings. Disconnect anytime in Settings → Connected Devices.
Apple Health / HealthKit Optional on-device health data access — we read only the data types you grant permission for, such as glucose, steps, workouts, and active energy, to show health context in CarbTrack. Disconnect Apple Health in CarbTrack or revoke Health permissions in the iOS Health app or iOS Settings.
OpenAI AI meal analysis & voice logging — meal photos and voice recordings you submit are sent to OpenAI's API for carb estimation, transcription, and structured data extraction. You choose when to scan or record; manual entry is always available.
Cloudflare R2 Cloud object storage — meal photos, community post images, and profile avatars are stored on Cloudflare R2. Deleting a meal or post removes associated images.
Expo (Notifications) Push notification delivery — your device push token is registered with Expo's notification service. Revoke notification permission in your device Settings.
Sentry (Functional Software, Inc.) Error & performance monitoring — crash reports, error logs, IP address, and user session context are sent to Sentry to help us detect and debug issues. Sentry is a US-based service. Diagnostic data is retained per Sentry's data retention policy. Account deletion removes user-identifiable context from future events.
Cloud hosting provider Our backend servers, database (PostgreSQL), and cache (Redis) run on cloud infrastructure. Providers access data only to operate the service. Covered by our data processing agreement with the provider.

We may also disclose data when required by law, court order, or to protect the safety of users or the public.

CGM integrations — Dexcom & LibreView

When you connect a Continuous Glucose Monitor account, CarbTrack will:

You can disconnect any CGM integration at any time in Settings → Connected Devices. Disconnecting revokes our token and stops future syncs. Historical readings already imported remain in your account unless you request account deletion.

Apple Health integration

Apple Health connection is optional. When you connect Apple Health and grant HealthKit permission, CarbTrack may read the Apple Health data types you approve, such as glucose samples, steps, workouts, and active energy.

Disconnecting Apple Health stops future Apple Health syncs. Historical data already imported into CarbTrack remains in your account unless you delete individual readings where available or request account deletion.

Your controls & how to delete your data

You have full control over your data. Here is how you can review, manage, and delete each type of data we store:

ℹ️ We do not currently offer a self-serve data export feature. If you need a copy of your data, contact us and we will provide one in a machine-readable format where technically feasible.

Security

No system is perfectly secure. If you discover a security vulnerability, please report it responsibly to [email protected].

Data retention & deletion

We retain your personal data only for as long as necessary to provide the CarbTrack service. Below is a detailed breakdown of how long each category of data is kept, and how it is deleted when you choose to remove it.

Data category How long we keep it How to delete it
Account & profile data
Email, display name, health profile, alert settings
For as long as your account is active. On account deletion, permanently erased within 30 days. Contact us at [email protected] to request account deletion.
Meal & nutrition data
Meal logs, photos, ingredients, AI carb estimates
For as long as your account is active. When you delete a meal, it is soft-deleted (hidden immediately) and permanently purged from our servers within 90 days. Delete individual meals from the Meals History screen in the app. All meals are permanently deleted with your account.
Glucose readings
Blood glucose values, timestamps, reading source
For as long as your account is active. On account deletion, permanently erased within 30 days. Delete individual readings from the BG Readings History screen in the app. All readings are permanently deleted with your account.
Apple Health data
Glucose samples, steps, workouts, active energy, timestamps, source/device metadata
For as long as your account is active. Disconnecting Apple Health stops future syncs. On account deletion, imported Apple Health data is permanently erased within 30 days. Disconnect Apple Health in Settings → Connected Devices or revoke permissions in iOS. Delete individual glucose readings where available, or request account deletion to remove all imported Apple Health data.
Insulin data
Insulin-to-carb ratios, logged doses
For as long as your account is active. On account deletion, permanently erased within 30 days. Delete individual doses from your insulin history in the app. All insulin data is permanently deleted with your account.
Community content
Posts, comments, reactions, attached images
Visible while your account is active. When you delete a post or comment, it is hidden immediately and permanently purged within 90 days. On account deletion, posts may be anonymised rather than deleted where required for thread integrity. Delete individual posts and comments from the app. All community content is removed or anonymised on account deletion.
CGM connections
Dexcom/LibreView access tokens and credentials
Stored only while your CGM account is connected. Immediately deleted when you disconnect. Disconnect anytime in Settings → Connected Devices. This immediately revokes our access and deletes your stored CGM credentials.
Apple Health connection
Connection status, sync anchors, and permission-related sync metadata
Stored only while Apple Health is connected. Deleted when you disconnect Apple Health or delete your account. Disconnect anytime in Settings → Connected Devices or revoke Health permissions in iOS.
Device & diagnostic data
Crash reports, error logs, IP address (Sentry)
Retained per Sentry's data retention policy. On account deletion, user-identifiable context is removed from future error events. Diagnostic data is automatically managed by Sentry. Account deletion removes your user context from future events.
Push notification tokens
Expo push notification device token
Stored while notifications are enabled. Deleted when you revoke notification permission or delete your account. Revoke notification permission in your device Settings, or delete your account.
Cache & analytics data
Redis caches, anonymised usage statistics
Cached data is purged immediately on account deletion. Anonymised, aggregated statistics (e.g. total user count, crash rates) may be retained indefinitely as they cannot identify individuals. Automatically cleared on account deletion. Anonymised aggregates cannot be deleted as they are not linked to any individual.
ℹ️ Legal holds. In limited circumstances, we may retain certain records beyond the periods stated above when required by applicable law, court order, or to protect the safety of users or the public. If a legal hold applies to your data, we will notify you to the extent permitted by law.

Children's privacy

CarbTrack is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, please contact us at [email protected] and we will delete the account promptly.

For users between 13 and 18, we recommend parental or guardian involvement in reviewing this policy and configuring the app's health settings.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via an in-app notice or email before the changes take effect. The "Last updated" date at the top of this page always reflects the most recent revision. Continued use of CarbTrack after the effective date constitutes acceptance of the revised policy.

Contact us

Kouidev — CarbTrack Privacy Team

For privacy requests, data deletion, or policy questions:

[email protected]

For general support:

[email protected]

We aim to respond to all privacy-related requests within 5 business days.