Privacy Policy
Shuga Caddy ("the app") is a personal glucose and nutrition diary. This policy explains what data the app collects, why, where it is stored, and the choices you have. By using Shuga Caddy you agree to the practices described here.
1. What we collect
- Account identifier. When you sign in with Apple or Google we store a stable, opaque user ID and the email address provided by the identity provider. We do not receive your Apple or Google password.
- Photos you submit. Photos of dishes and glucose-meter readings that you choose to scan are transmitted to our backend for AI recognition. Recognized results (dish name, macronutrients, glucose value, timestamp) are stored against your account so they appear in your feed.
- Diary entries. Meals, glucose readings, and notes you add or correct by hand are stored against your account.
- Technical logs. Anonymous request logs (timestamp, request path, response status) are retained for up to 30 days for debugging and abuse prevention. Logs do not contain photo bytes or personal data fields.
2. Why we collect it
- To sign you in and keep your diary tied to a single account across devices.
- To run AI vision and OCR on the photos you submit and return the results to you.
- To show your historical feed, charts, and trends.
- To diagnose errors, prevent abuse, and improve reliability.
3. Third-party services
Photo recognition is performed by Google Gemini (Google LLC) under Google's Vertex AI / Generative Language terms. Photos are transmitted to Google solely to obtain a recognition result and are not used by us for model training. Sign-in is performed via Apple's "Sign in with Apple" and Google Identity Services. Crash and error telemetry may be sent to Sentry (Functional Software, Inc.).
4. Where data lives
Diary data and account records live in a managed PostgreSQL database hosted in Europe. Photos you submit are stored in Google Cloud Storage (region europe-north1, Hamina, Finland — physically in the European Union). They are encrypted at rest and only accessible through an authenticated API call from the app, and may be retained for up to 90 days to allow re-processing or correction; after that they are deleted. Recognition results derived from the photos are retained as long as your account exists or until you delete the entry.
5. Sharing
We do not sell or rent your data. We share data only with the processors named above (Google, Apple, Sentry) to the extent strictly required to deliver the feature you used. We may disclose data if required by a binding legal order.
6. Your choices
- Delete an entry. Any meal or reading can be deleted from your feed at any time. The underlying photo is also deleted.
- Delete your account. Email [email protected] from the address associated with your account and we will delete your account, diary entries, and stored photos within 14 days. Anonymous request logs older than 30 days are purged on rolling schedule.
- Decline permissions. Camera and photo-library access are requested only when you initiate a scan. Declining will limit scan functionality but does not affect other features.
7. Children
Shuga Caddy is not directed at children under 13 and we do not knowingly collect data from them.
8. Changes
Material changes to this policy will be reflected by updating the "Last updated" date and, where appropriate, prompting you in-app.
9. Contact
Questions or requests: [email protected]