Last updated: 9 September 2026
Blood Sugar is a diabetes log for iPhone and iPad, developed by Serhii Surzhykov ("we", "the developer"). This policy explains what the app does with your data.
The short version: your health records stay on your device and in your own iCloud account. There is no account to create, no server of ours that stores your readings, and nothing about your health is ever sold, shared with advertisers, or used to build a profile of you.
Everything you log — glucose readings, carbohydrates, insulin and other medication, meals and photos of them, weight, ketones, lab results such as HbA1c, notes, targets and reminders — is stored on your device.
If iCloud is enabled on your device, the same records are synchronised through Apple iCloud (CloudKit private database) so that your iPhone, iPad and Mac show the same log. That copy lives in your personal Apple account. The developer has no access to it and cannot read it.
We do not operate any account system, and we do not have a database of users' health records.
With your explicit permission, the app reads from and writes to Apple Health:
blood glucose
dietary carbohydrates
insulin delivery
body mass
step count
active energy
Health data is used only to show your records inside the app and to keep your log and Apple Health consistent. It is never sent to the developer or to any third party. You can withdraw access at any time in Settings › Health › Data Access & Devices, or in the app's own settings.
You can photograph a meal or a nutrition label to estimate its carbohydrates. When you use this feature:
the photo is sent over an encrypted connection to a proxy operated by the developer on Cloudflare Workers, which forwards it to Google Gemini for analysis and returns the estimated carbohydrates;
the photo is not stored — neither by the proxy nor by the developer. It is held in memory only for the duration of the request. Google processes it under the Gemini API terms, which do not use paid-API content to train models;
no health record, name, email address or device identifier is attached to the photo;
to check that the request comes from an active subscriber and to apply a daily limit, the proxy receives the App Transaction signed by Apple and stores a counter keyed to your Apple subscription identifier. This identifier is a number issued by Apple; it is not linked to your name and carries none of your health data;
your IP address is processed by Cloudflare for rate limiting and abuse protection, in accordance with Cloudflare's own privacy policy.
If you never use the meal reader, no photo ever leaves your device.
When you search for a food or scan a barcode, the search term or the barcode is sent to Open Food Facts and USDA FoodData Central to retrieve nutrition information. These requests contain only what you typed or scanned. They are not linked to your health records or to any identifier of you.
If you allow it, the app can add tests and appointments from your care plan to your calendar. This permission is write-only: the app adds events and does not read your existing calendar. It can be revoked in Settings › Privacy & Security › Calendars.
To keep the app stable, we use two services, both configured to collect as little as possible:
Sentry (crash and error reports, servers in the European Union) receives a crash or error report when something goes wrong: the type of error, the stack trace, the app version and the device model. Screenshots, view hierarchies and interaction tracking are switched off, so no screen showing your readings is ever captured. IP addresses are not collected. Reports are not collected from development or simulator builds.
TelemetryDeck (product analytics, servers in the European Union, no cookies, no cross-app tracking) receives anonymous, aggregated signals about how the app is used — for example that a screen was opened, that onboarding was completed, or that a scan finished. Signals never contain glucose values, doses, carbohydrate figures, weights, lab results, food names, medication names, your diabetes type, or any text you entered.
Neither service is used for advertising, and neither receives data that identifies you.
Subscriptions are processed by Apple through the App Store. The developer never sees your payment details. Subscription receipts are validated by RevenueCat (servers in the United States), which receives the App Store transaction and an anonymous identifier, never your name, e-mail or payment details, and tells the app whether a subscription is active. Purchases can be managed and cancelled in Settings > Apple Account > Subscriptions.
Reminders are scheduled and delivered locally by your device. They contain no health values in their text, and they are not sent through any server.
We do not sell your data.
We do not share your health data with advertisers, data brokers or insurers.
We do not track you across other apps or websites.
We do not use your data for advertising.
We do not require an account, an email address or a phone number.
Delete a record or all records — in the app, at any time. Deleting removes it from your device and, through iCloud, from your other devices.
Export — you can create a backup file or a PDF report for your doctor. These files are yours; the app does not upload them anywhere.
Revoke permissions — Health, camera, photos and calendar access can each be withdrawn in iOS Settings.
Delete everything — removing the app deletes its local data. To remove the iCloud copy as well, use Settings › Apple Account › iCloud › Manage Account Storage.
If you are in the European Economic Area, the United Kingdom, or a jurisdiction with comparable law, you have the right to access, correct, export and erase your personal data, and to object to its processing. Because your health records are held on your device and in your own iCloud account rather than by us, you exercise those rights directly in the app. For anything else, write to the address below and we will respond within 30 days.
Legal bases under the GDPR: your consent for Apple Health, camera, photo library and calendar access (withdrawable at any time); the performance of a contract for processing a purchase and running the meal reader; and our legitimate interest in a stable app for crash reports and anonymous analytics.
Blood Sugar is not directed at children. It is rated 12+ and intended for adults managing their own condition, or for a parent or carer managing it on someone's behalf. We do not knowingly collect personal data from children.
Blood Sugar is a logbook and an information tool. It does not diagnose, treat or prescribe, it does not calculate insulin doses, and the carbohydrate figures it estimates from a photograph are approximations. Reference information in the app comes from World Health Organization fact sheets and describes populations, not you. Targets, doses and treatment decisions are set with your doctor. In an emergency, contact your local emergency service.
If this policy changes, the new version will be published on this page with a new "last updated" date. Material changes will also be noted in the app's release notes.
Questions about privacy, or a request about your data: sandoya1101@gmail.com