Privacy Policy

Last updated: February 2026

1Introduction

Welcome to Ando (“we”, “our”, or “us”). Ando Care is based in France.

Ando is a personal health companion that helps people understand how daily activities affect their glucose levels. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and web services at https://ando.care and https://app.ando.care (collectively, the “Service”).

By using the Service, you agree to the collection and use of information in accordance with this policy.

2Information We Collect

2.1 Information You Provide Directly

  • Account Information: Email address and display name when you create an account
  • Food Logs: Meal names, timestamps, and photos you choose to log
  • Manual Activity Logs: Activities you manually record in the app

2.2 Information from Third-Party Services

When you connect third-party services to Ando, we receive data from those services:

ServiceData We Receive
StravaActivities (name, type, start time, duration, distance), athlete profile
DexcomGlucose readings (value, timestamp)
LibreLinkUp (Abbott)Glucose readings (value, timestamp)
NightscoutGlucose readings (value, timestamp)
Garmin (coming soon)Activities (name, type, start time, duration, heart rate)

We only access data you explicitly authorize through each service's OAuth consent flow. You can revoke access at any time.

2.3 Information Collected Automatically

  • Usage Data: App interactions, features used, and timestamps
  • Device Information: Device type, operating system version
  • Log Data: Error logs and performance data to improve the Service

2.4 What We Do NOT Collect

Precise location data
Contacts or phone data
Advertising identifiers
Cookies for tracking

3How We Use Your Information

We use your information solely to provide and improve the Service:

PurposeLegal Basis (GDPR)
Display your glucose data alongside activitiesPerformance of contract
Calculate glucose statistics (average, time in range)Performance of contract
Update your Strava activity descriptions with glucose statsYour explicit consent
Store and display your food logsPerformance of contract
Send service-related notificationsLegitimate interest
Improve the Service and fix bugsLegitimate interest

We do NOT:

Sell your personal data
Use data for advertising
Share health data without consent

5How We Share Your Information

5.1 With Third-Party Services (At Your Request)

When you connect Strava, we may update your activity descriptions with glucose statistics. This is done only with your explicit consent and can be disabled in Settings.

5.2 Service Providers

We use the following service providers to operate Ando:

ProviderPurposeLocation
SupabaseDatabase & authenticationEU
RailwayApplication hostingUS
ExpoMobile app distributionUS

All providers are bound by data processing agreements and appropriate safeguards (Standard Contractual Clauses).

5.3 Legal Requirements

We may disclose your information if required by law or in response to valid legal requests by public authorities.

6Third-Party Services

Ando connects to external services like Strava, Dexcom, LibreLinkUp, and Nightscout. When you use these integrations, their privacy policies also apply to the data they process.

We recommend reviewing their privacy policies:

We are not responsible for the data practices of these third-party services.

7Research & Clinical Studies (Optional)

7.1 Participation in Research

With your explicit consent, your anonymized data may be used to support research conducted by accredited academic institutions or healthcare organizations.

7.2 What This Means

Your data would be fully anonymized (no name, email, or identifiable information)
Only aggregated glucose patterns and activity correlations would be shared
You can opt in or out at any time in Settings → Privacy
We will never sell your raw data

7.3 How to Participate

To participate, enable “Contribute to Research” in Settings → Privacy.

To withdraw, disable “Contribute to Research” at any time. Previously shared anonymized data cannot be recalled, but no new data will be shared.

7.4 Research Partners

We only partner with:

  • Accredited academic institutions
  • Healthcare organizations with ethics board approval (IRB/CPP)
  • Research projects that have passed ethical review

8Data Retention

Data TypeRetention Period
Account informationUntil you delete your account
Glucose readings90 days (rolling)
Activity dataUntil you delete your account
Food logsUntil you delete your account
Research consent records5 years (legal requirement)

You can delete your account and all associated data at any time from Settings.

9Data Security

We implement appropriate technical and organizational measures to protect your data:

  • 🔒Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • 🔐Authentication: Secure authentication via Supabase Auth
  • 🔑Token Security: Third-party tokens (Strava, CGM) are encrypted using AES-256-GCM before storage
  • 🛡️Access Control: Row-level security ensures you can only access your own data
  • 👤Anonymization: Research data is irreversibly anonymized before any sharing

While we strive to protect your information, no method of transmission over the Internet is 100% secure.

10Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights:

RightHow to Exercise
AccessRequest a copy of your data via Settings > Export Data
RectificationUpdate your information in the app
ErasureDelete your account via Settings > Delete Account
PortabilityExport your data in JSON format
RestrictionContact us to restrict processing
ObjectionContact us to object to processing
Withdraw ConsentDisconnect services in Settings or disable research

To exercise any of these rights, contact us at privacy@ando.care.

11International Data Transfers

Your data may be transferred to and processed in countries outside the EEA (notably the United States for some service providers). We ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses approved by the European Commission
  • Service providers with appropriate data protection certifications

12Do Not Track

Most web browsers and some mobile operating systems include a “Do Not Track” (DNT) feature. As there is no uniform standard for DNT signals, we do not currently respond to DNT browser signals. If a standard is adopted in the future, we will update this policy accordingly.

13Age Restriction

Ando is intended for users aged 16 years and older. We do not knowingly collect personal information from users under 16. By creating an account or using our services, you confirm that you meet this age requirement.

If we learn that we have collected data from a user under 16, we will take steps to delete that information promptly.

14Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy on this page
  • Updating the “Last updated” date
  • Sending you an email notification for material changes

We encourage you to review this Privacy Policy periodically.

15Contact Us

If you have any questions about this Privacy Policy, please contact us:

Ando Care

Email: privacy@ando.care

Website: https://ando.care

Quick Summary

What We Do

  • Collect data you explicitly connect
  • Process data to show you insights
  • Store data securely with encryption
  • Let you delete everything anytime
  • Only share anonymized data for research (if you opt in)

What We Don't

  • Sell your data
  • Use data for advertising
  • Share health data without consent
  • Track your location
  • Share identifiable data with researchers

This Privacy Policy is effective as of February 2026.