Privacy Policy

    Effective Date: March 14, 2026

    1. Introduction

    This Privacy Policy describes how mysukari.com ("My Sukari," "we," "us," or "our") collects, uses, discloses, and protects your personal information and sensitive personal data when you access or use our glucose tracking web application at mysukari.com (the "Service").

    We process personal data in accordance with the Kenya Data Protection Act, 2019 (the "Act") and the Data Protection (General) Regulations, 2021.

    By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, you should not use the Service.

    2. Data Controller

    The data controller responsible for your personal data is My Sukari (mysukari.com), operated from Nairobi, Kenya. For any inquiries regarding this Privacy Policy or the processing of your personal data, you may contact us at info@mysukari.com.

    3. Information We Collect

    3.1 Personal Information

    We collect the following personal information when you create an account and use the Service:

    • Email address
    • First name and last name (optional)
    • Username (optional)
    • Profile photograph (optional)
    • Account preferences (timezone, glucose unit preference, display theme, notification settings)

    3.2 Sensitive Personal Data (Health Data)

    Under Section 2 of the Act, health data constitutes sensitive personal data. We collect the following health data, which you voluntarily provide through the Service:

    • Blood glucose readings and related metadata
    • Meal and food intake data
    • Food photographs uploaded for carbohydrate estimation
    • Medication and insulin dose records
    • Diabetes management settings (glucose target ranges)

    The collection and processing of this health data is subject to your explicit consent, as described in Section 6 below.

    3.3 Technical and Usage Information

    We automatically collect certain technical information when you use the Service:

    • IP address
    • Browser type and version
    • Device information and user agent string
    • Pages visited and features used
    • Date and time of access
    • Session data

    3.4 Information from Third-Party Authentication Providers

    If you choose to sign in using a third-party authentication provider (Google, GitHub, or Microsoft), we receive the following information from the provider:

    • Your name and email address
    • Profile photograph URL
    • Provider-specific user identifier

    We do not receive or store your password from these providers.

    4. Legal Basis for Processing

    We process your personal data on the following legal grounds under the Act:

    • Explicit Consent (Section 32): For all health data (sensitive personal data), we obtain your explicit consent through a dedicated consent mechanism at registration or, for users who sign in via third-party providers, through a separate consent screen prior to accessing health features.
    • Performance of a Contract: For personal information necessary to operate your account and provide the Service (email, credentials, preferences).
    • Legitimate Interest: For technical and usage data necessary for security monitoring, fraud prevention, audit logging, and service improvement, where such interests are not overridden by your fundamental rights.

    5. How We Use Your Information

    We use the information we collect for the following purposes:

    • To provide and maintain the Service, including glucose tracking, data visualization, charts, statistics, reports, and pattern analysis
    • To process food photographs for carbohydrate estimation using third-party artificial intelligence services
    • To enable data sharing with individuals you designate, such as caregivers or healthcare providers
    • To generate and deliver reports in various formats
    • To send transactional communications, including email verification, password reset, share invitations, and service notifications
    • To monitor and improve the security, performance, and reliability of the Service
    • To maintain audit logs for security and compliance purposes
    • To collect anonymized usage analytics to improve the Service

    6. Health Data Consent

    In accordance with Sections 32 and 35 of the Act, we obtain your explicit consent before collecting or processing any health data. This consent is obtained as follows:

    • At Registration: Users who register with an email and password are required to provide explicit consent by selecting a dedicated health data consent checkbox before account creation.
    • Third-Party Sign-In: Users who create an account through Google, GitHub, Microsoft, or magic link authentication are presented with a separate consent screen before accessing any health data features.
    • Record-Keeping: We record the date and time of consent and the version of this Privacy Policy in effect at the time consent was given.

    Withdrawal of Consent

    You may withdraw your consent at any time by deleting your account through the Account Settings page. Deletion of your account permanently removes all personal information and health data associated with your account, as described in Section 12 below. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

    7. Third-Party Service Providers and Data Sharing

    We do not sell, rent, or trade your personal data. We share data with third-party service providers solely to operate and deliver the Service. Each provider processes data only for the specific purpose described below.

    ProviderPurposeData SharedLocation
    Hetzner Online GmbHDatabase and API server hostingAll user data (stored at rest)Germany
    Backblaze (B2 Cloud Storage)File storageMeal photographs, glucose import files, report filesGermany
    Vercel Inc.Frontend application hostingIP address, browser data (standard web serving)United States
    Amazon Web Services (SES)Transactional email deliveryEmail address, email content (verification, password reset, share invitations, reports)United States
    OpenAI / OpenRouterAI-assisted carbohydrate estimationFood photographs and descriptions (only when you use the carb estimation feature; images are not stored permanently after analysis)United States
    Google / GitHub / MicrosoftAuthentication (OAuth)Authentication tokens exchanged during sign-in (only if you choose to use these providers)United States

    User-Initiated Sharing

    You may choose to share your health data with specific individuals (such as caregivers or healthcare providers) through the Service's data sharing features. Such sharing is initiated and controlled entirely by you, and you may revoke access at any time. You may also enable a public profile, which makes your glucose statistics accessible by your username.

    Nightscout Integration

    If you enable the Nightscout-compatible integration, your glucose data may be transmitted to and from external Nightscout servers that you configure. This integration is entirely user-initiated, and we are not responsible for the privacy practices of third-party Nightscout instances.

    Disclosure Required by Law

    We may disclose your personal data if required to do so by law, court order, or lawful request by a government authority, including to comply with the requirements of the Act or directions from the ODPC.

    8. International Data Transfers

    Your data is stored and processed in the following jurisdictions:

    • Germany: Primary data storage, including the database and file storage. This is the primary jurisdiction for all user data and health data.
    • United States: Frontend hosting, email delivery, AI processing, and usage analytics, as described in Section 7.

    These transfers are carried out in accordance with Section 48 of the Act. Germany is a member of the European Union and provides an adequate level of data protection under the EU General Data Protection Regulation. For transfers to the United States, we ensure that service providers are contractually bound to protect your data and we limit the data transferred to what is necessary for each specific purpose.

    9. Data Retention

    We retain your data as follows:

    • Account and Health Data: Retained for as long as your account is active. Historical health data is retained indefinitely during active use, as long-term glucose records are valuable for diabetes management.
    • Food Photographs (AI Analysis): Photographs sent to the AI service for carbohydrate estimation are processed in real-time and are not permanently stored by the AI provider after analysis. Uploaded meal photographs are stored in our file storage for your reference.
    • Audit Logs: Security and compliance audit logs are retained for the lifetime of the account.
    • Inactive Accounts: We reserve the right to delete accounts that have been inactive for more than two (2) years, after providing reasonable notice to the email address on file.

    Upon account deletion, all personal information and health data is permanently deleted, as described in Section 12.

    10. Cookies and Similar Technologies

    We use cookies solely to provide essential functionality of the Service. All cookies used are strictly necessary first-party cookies for authentication and security purposes, including session management, multi-factor authentication, trusted device recognition, and protection against cross-site request forgery during sign-in. We do not use advertising cookies, tracking cookies, or third-party cookies.

    All cookies are set with HttpOnly, Secure, and SameSite attributes. You may delete cookies at any time through your browser settings; doing so will require you to sign in again.

    11. Your Rights Under the Kenya Data Protection Act

    Under the Act, you have the following rights regarding your personal data:

    • Right of Access (Section 26(a)): You may request confirmation of whether we process your personal data and obtain a copy of such data.
    • Right to Rectification (Section 26(c)): You may update or correct your personal information at any time through your profile settings.
    • Right to Deletion (Section 26(d)): You may delete your account and all associated data through the Account Settings page.
    • Right to Data Portability (Section 26(g)): You may request a copy of your personal data in a structured, machine-readable format. Glucose reports can be exported directly from the Service. For a complete data export, please contact us at info@mysukari.com.
    • Right to Withdraw Consent: You may withdraw your consent to health data processing at any time by deleting your account, as described in Section 6.
    • Right to Lodge a Complaint: You have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya.

    To exercise any of these rights, please contact us at info@mysukari.com. We will respond to your request within thirty (30) days.

    12. Account Deletion and Data Erasure

    You may permanently delete your account at any time through the Account Settings page. Account deletion results in the irreversible removal of:

    • Your personal information and profile data
    • All glucose readings and health data
    • All meals, food photographs, and medication records
    • All reports and pattern analyses
    • All shared access links and caregiver permissions
    • All sessions, authentication credentials, and audit logs

    Account deletion constitutes withdrawal of your consent for health data processing. This action cannot be undone.

    13. Children's Data

    The Service is not directed at children under the age of thirteen (13). We do not knowingly collect personal data from children under 13. If you are under 13, you may not use the Service.

    Users between the ages of 13 and 18 may use the Service with the consent of a parent or legal guardian, in accordance with Section 33 of the Act. By allowing a minor to use the Service, the parent or guardian accepts responsibility for the minor's use and agrees to this Privacy Policy on the minor's behalf.

    If we become aware that we have collected personal data from a child under 13, we will take steps to delete such data promptly. If you believe a child under 13 has provided us with personal data, please contact us at info@mysukari.com.

    14. Data Security

    We implement appropriate technical and organizational measures to protect your personal data in accordance with the Act. These measures include encryption of data in transit and at rest, secure password storage, multi-factor authentication options, access controls, audit logging, and regular security reviews.

    While we strive to protect your personal data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.

    15. Data Breach Notification

    In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ODPC in accordance with Section 43 of the Act. Where the breach is likely to result in a high risk to your rights, we will also notify you directly via the email address associated with your account.

    16. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will:

    • Update the "Effective Date" at the top of this page
    • Notify you via email or a prominent notice within the Service

    If changes materially affect how we process your health data, we may request renewed consent. Your continued use of the Service after the effective date of a revised Privacy Policy constitutes acceptance of the updated terms.

    17. Contact Information

    For questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us at info@mysukari.com.