Sugar360 App

Privacy Policy

What the app collects, why, who it reaches, how long we keep it, and what you can require us to do about it.

Effective 16 Sep 2026

Sugar360 ("Sugar360", "we", "us", or "our") is a diabetes care-management service provided by Zenvia Health Private Limited, Jeewanjyotee Medicare, 408 Hill Cart Road, Sevoke More, Siliguri, Darjeeling, West Bengal 734001, India. It comprises a mobile application for patients and their caregivers, and connected web tools used by clinical care teams — doctors, dietitians, health coaches and front-desk staff — to coordinate diabetes care.

This policy explains what we collect, why, who it reaches, how long we keep it, and what you can require us to do about it. It applies to everyone who uses Sugar360, whether you registered yourself or were registered by your care centre.

By creating an account or using Sugar360, you agree to the handling of information described here. If you do not agree, do not use the service.

01

Who is responsible for your data

Zenvia Health Private Limited is the Data Fiduciary for the personal data described in this policy, under India's Digital Personal Data Protection Act, 2023.

Your care centre is separately responsible for the clinical records its staff create about you, and for retaining them as medical record-keeping law requires. Where this policy says a record stays with your centre, that is what is meant.

02

Information we collect

Identity and contact details

  • Name, date of birth, sex, phone number, email address and postal address
  • Profile photograph, if you add one
  • Your medical record number at your care centre
  • Your role — patient, caregiver, doctor, dietitian, health coach or care staff — and the centre you belong to

Health information

Sugar360 exists to manage a long-term condition, so most of what it holds is health information. This is entered by you, by your caregiver, by your care team, or synced from a device you have connected.

  • Diabetes type and diagnosis history, other conditions, allergies and family history
  • Glucose readings, entered by hand or synced from a connected glucose meter or continuous glucose monitor
  • Medications prescribed to you, and each dose you record as taken or skipped
  • Meals, including photographs of food and any description you write
  • Physical activity, sleep, and body measurements such as weight, height, BMI, waist circumference, blood pressure and pulse
  • Appointments, consultation notes, prescriptions and diet plans created by your care team
  • Lab reports, prescriptions and other documents you or your care team upload
  • Messages you send to the in-app AI assistant

Data from Health Connect and Apple Health

If you choose to connect them, Sugar360 reads a limited set of measurements from the health platform on your phone. This is optional, is off until you turn it on, and can be withdrawn at any time from your phone's settings.

Health Connect (Android)
steps, sleep and resting heart rate. We read these to show activity and rest alongside your glucose, so patterns between them are visible to you and your care team.
Apple Health (iOS)
steps, sleep, resting heart rate, and glucose readings written by other apps or devices. As above, and so readings taken outside Sugar360 are not missing from your record.

We read only these categories. We do not read any other health data held on your phone. We do not use data from Health Connect or Apple Health for advertising, we do not sell it, we do not share it with data brokers, and we do not transfer it to any third party other than as described in Section 4 of this policy. Sugar360 does not write to Health Connect. On Apple Health, Sugar360 can write back only readings you logged in Sugar360 yourself, and only if you permit it.

If you disconnect the health platform, Sugar360 stops reading new data. Measurements already synced remain part of your health record and are handled as described in Section 6.

Connected glucose devices

If you link a continuous glucose monitor or glucose meter, we receive readings and the device identifier from that manufacturer's service. Linking is optional and can be undone.

Caregiver and care-team relationships

If you link a caregiver, or your centre assigns clinical staff to you, we record that relationship so the right people — and only those people — can see your information.

Device and technical information

  • A push notification token, so reminders and alerts can reach your device. It carries no health data.
  • App version, device model, operating system version, and crash diagnostics
  • Basic usage events — which screens are opened, which features are used — to understand where the app is working and where it is not

Location

Sugar360 reads your location once, only when you tap "Use my current location" while entering your address, and only while the app is open. The coordinates are turned into a street address and discarded. We do not store your location, we do not track you, and the app never requests background location access.

Microphone

If you use voice input in the AI assistant, your speech is converted to text using your phone's own speech recognition. We store the resulting text as a message. We do not record or store audio.

03

How we use your information

  • To provide the service: recording, displaying and sharing your diabetes data with the care team you and your centre have authorised
  • To let your care team plan and deliver treatment — consultations, prescriptions, diet plans and follow-ups
  • To power AI-assisted features: estimating the nutritional content of a meal from a photograph or description, and answering questions in the in-app assistant
  • To sync readings from a connected glucose device or health platform
  • To send reminders, appointment notices and clinical alerts
  • To keep the service secure, available and working correctly, and to investigate faults

We do not use your health information for advertising. We do not sell your personal information. We do not use your data to train third-party AI models.

04

Who we share information with

We share only what is needed, only with those listed here.

Your care team at your centre
the health records your centre has assigned them to, so they can provide and coordinate your clinical care.
A caregiver you have linked
only the categories you have permitted, which you can change or withdraw at any time, so a family member or carer can help manage your condition.
Anthropic PBC (United States)
the summary of your record set out in Section 5, together with the messages you send. This runs the in-app assistant, the assistant your caregiver uses, the written insights on your dashboard, the consultation support your clinician sees, and the reading of uploaded prescriptions and diet plans into your record.
Google, Gemini API (United States)
meal photographs and meal descriptions, to estimate the dishes and nutrition in a meal. This is the only Sugar360 feature that uses Google for AI.
Continuous Glucose Monitor (CGM)
device identifiers and glucose readings, to sync your connected glucose device.
Google, Firebase Cloud Messaging
a device push token, to deliver notifications. No health data.
Google, Firebase Crashlytics and Analytics
crash diagnostics and usage events, to find and fix faults. No health data.
Supabase
the data described in this policy. Our database, authentication and file storage provider.

We may also disclose information where the law requires it, or to protect the safety of a person.

Some of these providers process data outside India. Where that happens, we rely on contractual protections with the provider and transfer only what the service requires.

05

AI features, and their limits

Sugar360 uses two AI providers, for different things.

Anthropic (Claude)
runs the in-app assistant, the assistant your caregiver uses, the written insights on your dashboard, the consultation support your clinician sees, and the reading of uploaded prescriptions and diet plans into your record.
Google (Gemini)
is used for one thing only: estimating the dishes and nutrition in a meal from a photograph or a description.

Both process your information in the United States.

What is sent when you use the assistant

More than the message you type. So that an answer relates to you rather than to diabetes in general, each request carries a summary of your record:

  • Your name, age and sex
  • Your diabetes type, year of diagnosis, last HbA1c and current treatment
  • Glucose readings from the last seven days, with their values and whether each was fasting, after a meal or at bedtime
  • Meals you logged in the last three days
  • The medicines you are currently prescribed, with dose and frequency
  • Your care plan, your progress figures and your adherence score
  • The names and roles of the clinicians on your care team, and your upcoming appointments
  • Earlier messages from today's conversation

Requests raised from a clinician's own screen — consultation support and the clinician's daily summary — also carry that clinician's name, your weight and BMI, and the diagnosis and assessment recorded at your last consultation. Clinicians are therefore data subjects under this section too, not only patients.

Meal analysis estimates dishes and nutrition from a photograph or description. The estimates are approximations and are shown as such. You can correct any of them before saving.

The assistant answers general questions about diabetes management using your recent data for context. It does not give medical advice, does not diagnose, and does not prescribe. It is not a member of your care team and its answers are not reviewed by a clinician before you see them. See the Medical Disclaimer.

You can decline AI analysis when you join, and withdraw that permission at any time under Menu, Additional Settings, Permissions. Meal photographs are then not sent for analysis and you enter dishes yourself.

06

How long we keep information

Clinical records
consultation notes, prescriptions, diagnoses and readings — are retained by your care centre for as long as medical record-keeping law requires. Closing your Sugar360 account does not delete them.
Identity and contact details
are removed when you close your account, as described in Section 8.
Meal photographs and uploaded documents
are retained while your account is open, and thereafter as part of the clinical record where your care team has relied on them.
Crash and usage diagnostics
are retained for 12 months and are not linked to your health record.

07

Your rights

Under the Digital Personal Data Protection Act, 2023, you may:

Access
a summary of the personal data we hold about you and who it has been shared with
Correct
anything inaccurate, incomplete or out of date. Most of your profile and health information can be edited directly in the app; ask your care team to correct a clinical record.
Erase
personal data we no longer need for the purpose it was collected, subject to the medical retention obligations described above
Withdraw consent
you previously gave. Most of the permissions on that screen — reading from your devices, bringing in dietitians and educators, reminders, sharing with your care partner, AI assistance, and research — can be switched off by you at any time under Menu, Additional Settings, Permissions. A change there takes effect straight away.

Two cannot be switched off there, and the app shows them with a padlock: your care team can read what you record and we watch your numbers between visits. These are not extras. They are the care itself, and switching them off would end it rather than adjust it. To withdraw either one, tell your care centre, or close your account as described in Section 8. Your centre will talk through what that means for the plan you are enrolled in.

Withdrawing consent does not undo processing already carried out lawfully, and it does not remove clinical records your centre is required by law to keep.

Nominate
another person to exercise these rights on your behalf if you become unable to
Complain
to us, and afterwards to the Data Protection Board of India

To exercise any of these, contact our Grievance Officer in Section 11. We respond within 30 days.

08

Closing your account

You can close your account from within the app, under Menu, Additional Settings. You can also request closure by email, without installing the app, at support@sugar360.in, or at https://sugar360.in/app/delete-account.

When an account is closed:

  • Your name, phone number, email address and postal address are removed from your record
  • Your login is disabled permanently and cannot be restored
  • Your linked caregiver loses access immediately
  • Readings, meals, activity and doses you logged are removed from your account. Where your care team has used any of it in a consultation note or prescription, that copy stays in the clinical record your centre is required to keep.

Closure cannot be reversed, and creating a new account does not restore anything.

09

Data security

  • Data is encrypted in transit and at rest.
  • Access to your health information is restricted to the specific care team members assigned to you. It is not open to every user of the platform.
  • Uploaded documents are held in private storage and reached only through short-lived authenticated links. They are not publicly accessible.
  • Access to clinical records is logged.

No security measure is perfect. If you believe your account has been compromised, or you find a security weakness, contact us immediately at the address in Section 11.

10

Children

Sugar360 accounts are for adults, or are managed by a parent or guardian on behalf of a patient under 18, under the supervision of a care team. We do not knowingly allow a child to create or manage an account independently. If you believe a child has done so, contact us and we will act.

11

Contact and grievances

For any question about this policy, or to exercise a right under Section 7:

Grievance Officer: Rishabh Kumar
Zenvia Health Private Limited, Jeewanjyotee Medicare, 408 Hill Cart Road, Sevoke More, Siliguri, Darjeeling, West Bengal 734001, India. info@sugar360.in

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

12

Changes to this policy

We may update this policy. If a change materially affects how your information is handled, we will tell you in the app before it takes effect. The date this version took effect is shown at the top of this page.

Questions about this page?

Write to the Sugar360 app support team and we will get back to you. For anything about your treatment, contact your care centre directly.

support@sugar360.in