Dalo Labs ApS ("we", "us", "our"), registered in Denmark, operates the SugarCurve mobile application and website at sugarcurve.app (collectively, the "Service"). This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and your rights under applicable law, including the General Data Protection Regulation (GDPR).
By using SugarCurve, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Service.
1. Information We Collect
We collect information in three ways:
Information you provide directly: When you create an account you provide an email address and password, or authenticate via Apple Sign-In or Google Sign-In, which returns your name and email address to us. During onboarding you also provide your date of birth and your expected due date, and you may enter or edit your name. We use your name only to personalise the app and the content it generates for you, and your date of birth both to confirm you meet the minimum age for the Service (see Section 8) and to tailor nutritional targets to your age. Within the app you may enter blood sugar readings, meal and food log entries, your height, your pre-pregnancy weight and ongoing weight entries, whether you use insulin or other glucose-lowering medication, further pregnancy-related information, and personal preferences used to personalise meal plans and recipes. Photos you take using the Plate Scanner feature are sent to our AI provider to estimate nutritional content, as described in Section 3; these images are not stored on our servers or retained by our AI provider beyond the duration of the processing request.
Information collected automatically: We collect device identifiers, operating system version, app version, session duration, feature usage patterns, and crash reports in order to operate, maintain, and improve the Service. We do not collect precise GPS location. We may collect approximate country-level location derived from your IP address for analytics purposes.
Information from third-party integrations: If you choose to connect Apple Health (iOS) or Health Connect (Android), we read the health records you explicitly authorise — steps, body weight, and blood glucose. These integrations are entirely optional and read-only, and can be revoked at any time from your device settings or from within SugarCurve. Section 2 sets out exactly what we read, what we do with it, and how long we keep it.
SugarCurve processes sensitive health data — including blood sugar readings, your expected due date and other pregnancy-related information, your weight, and whether you use insulin or other glucose-lowering medication — which constitutes special-category personal data under GDPR Article 9. We process this data only with your explicit consent, which you provide when you create your account and first use these features.
2. Apple Health and Health Connect
SugarCurve can optionally read a small, fixed set of health records from Apple Health on iOS and Health Connect on Android. These integrations are strictly opt-in and are switched off by default — the app is fully usable without them. Permission is requested only when you actively choose to connect: during optional onboarding, by tapping “Connect” on the steps card, or from the Health Data section in Settings. You can revoke it at any time from Apple Health, from Health Connect, or from within SugarCurve. Access is read-only — SugarCurve never writes data back to Apple Health or Health Connect.
We request exactly three data types, and only these three:
- Steps (physical activity). On Android this uses the READ_STEPS and ACTIVITY_RECOGNITION permissions. Physical activity affects blood sugar, so we show your step count for today against a step goal you set yourself (7,500 by default) on the Home screen, and 7-day and 28-day step charts on the Trends screen alongside your blood sugar readings, so you can see how movement relates to your glucose levels. Step reads are limited to the last 30 days and are used for on-screen display only — step data is never stored on our servers.
- Body weight. On Android this uses the READ_WEIGHT permission. Weight tracking is a core part of gestational diabetes care, and SugarCurve lets you log your weight manually; this integration exists so that if you already record your weight elsewhere — for example with a connected smart scale — you do not have to enter it twice. When you turn on “Sync weight”, we read body weight records and import them into your own SugarCurve log as entries marked as automatically synced. We keep one reading per calendar day, de-duplicate against entries already in your log, and backfill at most the previous 30 days on first sync.
- Blood glucose. On Android this uses the READ_BLOOD_GLUCOSE permission. Tracking blood sugar is the app's primary purpose; you can log readings manually, and this integration exists so that if you use a glucose meter or CGM that already writes to Apple Health or Health Connect, you do not have to re-enter every reading by hand. When you turn on “Sync blood sugar”, we read blood glucose records and import them into your own SugarCurve log, marked as automatically synced. Imported readings appear in your blood sugar history, in your daily and weekly trends against the targets you have chosen (for example the ADA, NICE or Diabetes Canada guideline presets), and in the glucose report PDF you can generate and choose to share with your own doctor or midwife. Continuous-monitor data is averaged into 30-minute buckets, duplicates are skipped, and at most the previous 7 days are backfilled on first sync.
How this data is handled: Step counts are read live from your device for display and are never transmitted to or stored on our servers. Weight and blood glucose records that you choose to sync are stored in your own private SugarCurve account, alongside the entries you add manually, and are subject to exactly the same retention and deletion rules as the rest of your health data (see Section 7). You can delete any individual entry at any time from within the app.
Turning a sync off stops all future imports. Entries that were already imported remain in your log until you delete them, either individually or by deleting your account. Deleting your account removes every synced weight and blood glucose entry along with the rest of your data, within 30 days.
Data obtained from Apple Health or Health Connect is used only to provide SugarCurve's features to you. It is never sold, never used for advertising, and never used to train artificial intelligence models — ours or anyone else's. It is not disclosed to any third party except our sub-processors acting on our behalf: it is stored in your private account on our Firebase infrastructure, and, if you have separately consented to the AI features (see Section 3), the relevant readings may be sent to Google Gemini Enterprise to generate the specific result you asked for, under zero-retention terms.
3. AI Features and Third-Party AI Processing
Several SugarCurve features are powered by artificial intelligence: the Plate Scanner, AI Chef recipes, the Meal Plan Generator, food pattern analysis, and One-Tap Doctor Reports. To produce these results, SugarCurve transmits the data described below to Google Gemini Enterprise, operated by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), running on infrastructure located in the European Union. Google is our sub-processor for this purpose, and no other AI provider receives your data.
We ask before we send anything. The first time you use an AI feature, SugarCurve shows you what will be sent and who it is sent to, and asks you to agree. If you decline, no data is transmitted to Gemini Enterprise and the AI features are simply unavailable; every other part of the app — logging, trends, targets, the Food Library and the glucose report — continues to work normally. You can withdraw your consent at any time in Settings › Privacy, which stops all further transmission.
What is sent, by feature:
- Plate Scanner: the photo you take of your meal, and any short description you add. The image is transmitted to Gemini Enterprise, analysed in real time to estimate portion size and nutritional content, and the result is returned to you. It is not stored on our servers or by Google once the request completes.
- AI Chef and Meal Plan Generator: your age in years, how many weeks pregnant you are, your height, your pre-pregnancy and current weight, whether you use insulin or other glucose-lowering medication, your dietary preferences, restrictions and allergies, and your recent meal and food log entries.
- Food pattern analysis: your blood sugar readings and the meal and food log entries recorded around them, so the app can identify which foods correspond to which glucose responses.
- One-Tap Doctor Reports: your age in years and how many weeks pregnant you are, together with the blood sugar readings, weight entries and meal logs falling within the reporting period you select, and whether you use insulin or other glucose-lowering medication, so that a summary can be drafted for you to review before you choose to share it with your doctor or midwife.
What is never sent: your name, your date of birth, your expected due date, your email address, your password or authentication credentials, your payment and subscription details, your device identifiers, and your IP-derived location are never transmitted to Gemini Enterprise. Where a feature needs your age or your stage of pregnancy, only the derived values are sent — your age in years and the number of weeks you are pregnant — never the underlying dates.
Google Ireland Limited processes this data solely as our data processor, under the Google Cloud Data Processing Addendum and the EU Standard Contractual Clauses. Gemini Enterprise is configured for zero data retention: your inputs are held only for the duration of the request, are not logged or stored by Google afterwards, and are never used to train Google's models or any other party's models. These contractual and technical safeguards provide protection equivalent to that described in this Privacy Policy.
Where the data sent to Gemini Enterprise includes blood sugar or weight records that you imported from Apple Health or Health Connect, that transmission happens only after you have given the separate AI consent described above, and only to produce the feature you requested.
4. How We Use Your Information
We use the information we collect to:
- Provide, personalise, and improve the Service, including the Food Library ratings, Barcode Scanner results, AI Chef recipes, Meal Plan Generator, food pattern analysis, and One-Tap Doctor Reports.
- Generate AI-driven estimates and suggestions — Plate Scanner nutrient estimates, AI Chef and Meal Plan Generator recipes, food pattern analysis and Doctor Report summaries — by sending the data itemised in Section 3 to Google Gemini Enterprise, with your separate consent and under zero-retention terms. Your health data is never used to train external AI models.
- Read steps, body weight, and blood glucose from Apple Health or Health Connect where you have authorised that integration, in order to show your activity alongside your glucose data and to save you re-entering readings by hand (see Section 2).
- Manage your subscription and entitlements through our subscription management provider, RevenueCat.
- Send you transactional communications (account confirmations, subscription updates, important service notices). We do not send marketing emails without your separate opt-in.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
Legal basis (GDPR): We process your data on the following bases — performance of a contract (to provide the Service you signed up for); your explicit consent (for special-category health data and optional integrations); our legitimate interests (analytics, fraud prevention, service improvement, where those interests are not overridden by your rights); and compliance with legal obligations.
5. How We Share Your Information
We do not sell your personal information to third parties. We share data only with the following categories of service providers ("sub-processors"), each of which is contractually bound to protect your data:
- Firebase / Google Cloud (EU region): We use Firebase for authentication, database storage, and cloud functions. Your data is stored in Google Cloud infrastructure within the European Union and is subject to Google's data processing terms and GDPR safeguards.
- Google Gemini Enterprise (EU region), operated by Google Ireland Limited: AI features (Plate Scanner, AI Chef, Meal Plan Generator, food pattern analysis, Doctor Reports) send the data itemised in Section 3 to Gemini Enterprise running on EU-based infrastructure. Google acts solely as our data processor under the Google Cloud Data Processing Addendum and the EU Standard Contractual Clauses, which afford your data protection equivalent to that set out in this policy. Inputs are processed in real time under zero data retention: they are not stored by Google after the request and are never used to train models. Transmission occurs only after you consent in-app.
- PostHog (EU region): We use PostHog, hosted in the EU, for product analytics — understanding feature usage and app performance so we can improve the Service. PostHog processes pseudonymised usage data on our behalf as our data processor.
- RevenueCat (EU region): We use RevenueCat to manage app store subscriptions and entitlements. RevenueCat receives transaction and subscription-status data from Apple/Google on our behalf; it does not receive your payment card details.
- Apple App Store / Google Play Store: Subscription billing is handled entirely by Apple or Google. We receive only transaction and entitlement confirmations via RevenueCat; we do not receive or store your payment card details.
- Apple Health / Health Connect: These are sources we read from, not recipients — we never send your data to them. Reading occurs only if you explicitly authorise it, is read-only, and is limited to steps, body weight, and blood glucose.
- Legal authorities: We may disclose your information if required to do so by law, court order, or in response to a lawful request from public authorities.
- Business transfers: In the event of a merger, acquisition, or sale of substantially all of our assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a materially different privacy policy.
6. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, Firebase App Check and Firestore security rules to prevent unauthorised access, and authentication-based access controls that restrict your data to your account only.
While we take reasonable precautions, no method of transmission or storage is 100% secure. We cannot guarantee absolute security and encourage you to use a strong, unique password and enable two-factor authentication where available.
In the event of a data breach that is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority in accordance with GDPR requirements.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it longer by law (for example, for tax or accounting purposes, typically up to 5 years).
Health data — blood sugar readings, meal logs, and weight entries, whether you entered them manually or imported them from Apple Health or Health Connect — is retained for the duration of your account. You can delete individual entries at any time from within the app, or delete all of your data by deleting your account.
Account deletion is carried out by an automated routine that cascades through all of your stored records, including every blood glucose and weight entry synced from Apple Health or Health Connect. Step counts are never stored on our servers, so there is nothing to delete. Deletion completes within 30 days.
Anonymised, aggregated analytics data (with no personally identifiable information) may be retained indefinitely for service improvement purposes.
8. Children's Privacy
SugarCurve is intended for adults aged 18 and over. We collect your date of birth during onboarding and use it to confirm that you meet this threshold; accounts that do not are not created. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child under 16 has provided us with personal data without your consent, please contact us immediately at support@dalofamilyapps.com and we will delete that information promptly.
Where applicable under local law (for example, for users in the US under COPPA), we apply the higher age threshold.
9. International Data Transfers
Our core infrastructure — including Firebase, Gemini Enterprise, and PostHog — is hosted within the European Union. In the rare event that data is transferred outside the EU/EEA (for example, to support operations or comply with a legal request), we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, in accordance with GDPR Chapter V.
10. Your Rights
If you are in the EU/EEA or the UK, you have the following rights under GDPR (or UK GDPR) regarding your personal data:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): You can request deletion of your data, subject to legal retention obligations.
- Right to restriction: You can ask us to restrict processing of your data in certain circumstances.
- Right to data portability: You can receive your data in a structured, machine-readable format.
- Right to object: You can object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: Where processing is based on consent (including for special-category health data), you can withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at support@dalofamilyapps.com or dev@dalofamilyapps.com (Data Protection Officer). We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority. Our lead supervisory authority is the Danish Data Protection Agency (Datatilsynet — www.datatilsynet.dk); if you reside in another EU/EEA country, you may also complain to your local supervisory authority.
California residents: SugarCurve does not sell personal information, and we do not share data for cross-context behavioural advertising. For other CCPA/CPRA inquiries, contact us at the addresses above.
11. Cookies and Tracking
The SugarCurve mobile app does not use browser cookies. Our website (sugarcurve.app) may use essential cookies required for the site to function (such as locale preferences) and analytics collected via PostHog (EU-hosted) to understand aggregate site usage. This analytics data is pseudonymised and is used only in aggregate to understand product usage — it is not sold or shared for advertising purposes.
You can manage cookie preferences through your browser settings. Disabling non-essential cookies does not affect your ability to use the SugarCurve mobile app.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and notify you via in-app alert or email at least 30 days before the changes take effect.
Your continued use of the Service after the effective date of the updated policy constitutes your acceptance of the changes. If you do not agree with the updated policy, please stop using the Service and delete your account.
13. Contact Us
For questions, requests, or complaints about this Privacy Policy or our data practices, please contact us:
- General support: support@dalofamilyapps.com
- Data Protection Officer: dev@dalofamilyapps.com
- Company: Dalo Labs ApS, CVR: DK46555058
- Registered address: Ben Websters Vej 70, 4. th, 2450 København SV, Denmark
- Danish supervisory authority: Datatilsynet — www.datatilsynet.dk