SugarCurve
Back to Home

Privacy Policy

Last Updated: July 4, 2026

Dalo Labs ApS ("we", "us", "our"), registered in Denmark, operates the SugarCurve mobile application and website at sugarcurve.app (collectively, the "Service"). This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and your rights under applicable law, including the General Data Protection Regulation (GDPR).

By using SugarCurve, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Service.

1. Information We Collect

We collect information in three ways:

Information you provide directly: When you create an account you provide an email address and password (or authenticate via Apple Sign-In or Google Sign-In). Within the app you may enter blood sugar readings, meal and food log entries, pregnancy-related information, and personal preferences used to personalise meal plans and recipes. Photos you take using the Plate Scanner feature are processed to estimate nutritional content; these images are not stored on our servers beyond the duration of the processing request.

Information collected automatically: We collect device identifiers, operating system version, app version, session duration, feature usage patterns, and crash reports in order to operate, maintain, and improve the Service. We do not collect precise GPS location. We may collect approximate country-level location derived from your IP address for analytics purposes.

Information from third-party integrations: If you choose to connect Apple Health (iOS) or Google Fit (Android), we receive the health metrics you explicitly authorise within those platforms (such as blood glucose readings you have already logged there). This sync is entirely optional and can be revoked at any time from your device settings.

SugarCurve processes sensitive health data — including blood sugar readings and pregnancy-related information — which constitutes special-category personal data under GDPR Article 9. We process this data only with your explicit consent, which you provide when you create your account and first use these features.

2. How We Use Your Information

We use the information we collect to:

  • Provide, personalise, and improve the Service, including the Food Library ratings, Barcode Scanner results, AI Chef recipes, Meal Plan Generator, food pattern analysis, and One-Tap Doctor Reports.
  • Generate AI-driven estimates and suggestions (Plate Scanner nutrient estimates, recipe personalisation, Doctor Report summaries) using secure, non-training interactions with third-party AI providers. Your health data is never used to train external AI models.
  • Sync data with Apple Health or Google Fit where you have authorised this integration.
  • Manage your subscription and entitlements through our subscription management provider, RevenueCat.
  • Send you transactional communications (account confirmations, subscription updates, important service notices). We do not send marketing emails without your separate opt-in.
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations.

Legal basis (GDPR): We process your data on the following bases — performance of a contract (to provide the Service you signed up for); your explicit consent (for special-category health data and optional integrations); our legitimate interests (analytics, fraud prevention, service improvement, where those interests are not overridden by your rights); and compliance with legal obligations.

3. How We Share Your Information

We do not sell your personal information to third parties. We share data only with the following categories of service providers ("sub-processors"), each of which is contractually bound to protect your data:

  • Firebase / Google Cloud (EU region): We use Firebase for authentication, database storage, and cloud functions. Your data is stored in Google Cloud infrastructure within the European Union and is subject to Google's data processing terms and GDPR safeguards.
  • Google Cloud Vertex AI (EU region): AI features (Plate Scanner, AI Chef, Meal Plan Generator, Doctor Reports) use Vertex AI running on EU-based infrastructure. Inputs are processed in real time and are not retained by the AI provider or used to train models.
  • PostHog (EU region): We use PostHog, hosted in the EU, for product analytics — understanding feature usage and app performance so we can improve the Service. PostHog processes pseudonymised usage data on our behalf as our data processor.
  • RevenueCat (EU region): We use RevenueCat to manage app store subscriptions and entitlements. RevenueCat receives transaction and subscription-status data from Apple/Google on our behalf; it does not receive your payment card details.
  • Apple App Store / Google Play Store: Subscription billing is handled entirely by Apple or Google. We receive only transaction and entitlement confirmations via RevenueCat; we do not receive or store your payment card details.
  • Apple Health / Google Fit: Data sync with these platforms occurs only if you explicitly authorise it and only in the direction you choose.
  • Legal authorities: We may disclose your information if required to do so by law, court order, or in response to a lawful request from public authorities.
  • Business transfers: In the event of a merger, acquisition, or sale of substantially all of our assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a materially different privacy policy.

4. Data Security

We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, Firebase App Check and Firestore security rules to prevent unauthorised access, and authentication-based access controls that restrict your data to your account only.

While we take reasonable precautions, no method of transmission or storage is 100% secure. We cannot guarantee absolute security and encourage you to use a strong, unique password and enable two-factor authentication where available.

In the event of a data breach that is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority in accordance with GDPR requirements.

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it longer by law (for example, for tax or accounting purposes, typically up to 5 years).

Health data (blood sugar readings, meal logs) that you have logged in the app is retained for the duration of your account. You can delete individual entries at any time from within the app, or delete all data by deleting your account.

Anonymised, aggregated analytics data (with no personally identifiable information) may be retained indefinitely for service improvement purposes.

6. Children's Privacy

SugarCurve is intended for adults aged 18 and over. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child under 16 has provided us with personal data without your consent, please contact us immediately at support@dalofamilyapps.com and we will delete that information promptly.

Where applicable under local law (for example, for users in the US under COPPA), we apply the higher age threshold.

7. International Data Transfers

Our core infrastructure — including Firebase, Vertex AI, and PostHog — is hosted within the European Union. In the rare event that data is transferred outside the EU/EEA (for example, to support operations or comply with a legal request), we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, in accordance with GDPR Chapter V.

8. Your Rights

If you are in the EU/EEA or the UK, you have the following rights under GDPR (or UK GDPR) regarding your personal data:

  • Right of access: You can request a copy of the personal data we hold about you.
  • Right to rectification: You can correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): You can request deletion of your data, subject to legal retention obligations.
  • Right to restriction: You can ask us to restrict processing of your data in certain circumstances.
  • Right to data portability: You can receive your data in a structured, machine-readable format.
  • Right to object: You can object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent: Where processing is based on consent (including for special-category health data), you can withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at support@dalofamilyapps.com or dev@dalofamilyapps.com (Data Protection Officer). We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority. Our lead supervisory authority is the Danish Data Protection Agency (Datatilsynet — www.datatilsynet.dk); if you reside in another EU/EEA country, you may also complain to your local supervisory authority.

California residents: SugarCurve does not sell personal information, and we do not share data for cross-context behavioural advertising. For other CCPA/CPRA inquiries, contact us at the addresses above.

9. Cookies and Tracking

The SugarCurve mobile app does not use browser cookies. Our website (sugarcurve.app) may use essential cookies required for the site to function (such as locale preferences) and analytics collected via PostHog (EU-hosted) to understand aggregate site usage. This analytics data is pseudonymised and is used only in aggregate to understand product usage — it is not sold or shared for advertising purposes.

You can manage cookie preferences through your browser settings. Disabling non-essential cookies does not affect your ability to use the SugarCurve mobile app.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and notify you via in-app alert or email at least 30 days before the changes take effect.

Your continued use of the Service after the effective date of the updated policy constitutes your acceptance of the changes. If you do not agree with the updated policy, please stop using the Service and delete your account.

11. Contact Us

For questions, requests, or complaints about this Privacy Policy or our data practices, please contact us:

  • General support: support@dalofamilyapps.com
  • Data Protection Officer: dev@dalofamilyapps.com
  • Company: Dalo Labs ApS, CVR: DK46555058
  • Registered address: Ben Websters Vej 70, 4. th, 2450 København SV, Denmark
  • Danish supervisory authority: Datatilsynet — www.datatilsynet.dk