1Introduction
Welcome to Ando (“we”, “our”, or “us”). Ando Care is based in France.
Ando is a personal health companion that helps people understand how daily activities affect their glucose levels. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and web services at https://ando.care and https://app.ando.care (collectively, the “Service”).
By using the Service, you agree to the collection and use of information in accordance with this policy.
2Information We Collect
2.1 Information You Provide Directly
- Account Information: Email address and display name when you create an account
- Food Logs: Meal names, timestamps, and photos you choose to log
- Manual Activity Logs: Activities you manually record in the app
2.2 Information from Third-Party Services
When you connect third-party services to Ando, we receive data from those services:
| Service | Data We Receive |
|---|---|
| Strava | Activities (name, type, start time, duration, distance), athlete profile |
| Dexcom | Glucose readings (value, timestamp) |
| LibreLinkUp (Abbott) | Glucose readings (value, timestamp) |
| Nightscout | Glucose readings (value, timestamp) |
| Garmin (coming soon) | Activities (name, type, start time, duration, heart rate) |
We only access data you explicitly authorize through each service's OAuth consent flow. You can revoke access at any time.
2.3 Information Collected Automatically
- Usage Data: App interactions, features used, and timestamps
- Device Information: Device type, operating system version
- Log Data: Error logs and performance data to improve the Service
2.4 What We Do NOT Collect
3How We Use Your Information
We use your information solely to provide and improve the Service:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Display your glucose data alongside activities | Performance of contract |
| Calculate glucose statistics (average, time in range) | Performance of contract |
| Update your Strava activity descriptions with glucose stats | Your explicit consent |
| Store and display your food logs | Performance of contract |
| Send service-related notifications | Legitimate interest |
| Improve the Service and fix bugs | Legitimate interest |
We do NOT:
4Legal Bases for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process your data based on:
- 1Contract: To provide the services you signed up for
- 2Consent: For optional features like Strava description updates and research participation
- 3Legitimate Interest: To improve our services, fix bugs, and ensure security
You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
6Third-Party Services
Ando connects to external services like Strava, Dexcom, LibreLinkUp, and Nightscout. When you use these integrations, their privacy policies also apply to the data they process.
We recommend reviewing their privacy policies:
- Strava Privacy Policy →
- Dexcom Privacy Policy →
- Abbott/LibreLinkUp Privacy Policy →
- Nightscout (open-source, self-hosted) →
We are not responsible for the data practices of these third-party services.
7Research & Clinical Studies (Optional)
7.1 Participation in Research
With your explicit consent, your anonymized data may be used to support research conducted by accredited academic institutions or healthcare organizations.
7.2 What This Means
7.3 How to Participate
To participate, enable “Contribute to Research” in Settings → Privacy.
To withdraw, disable “Contribute to Research” at any time. Previously shared anonymized data cannot be recalled, but no new data will be shared.
7.4 Research Partners
We only partner with:
- Accredited academic institutions
- Healthcare organizations with ethics board approval (IRB/CPP)
- Research projects that have passed ethical review
8Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Until you delete your account |
| Glucose readings | 90 days (rolling) |
| Activity data | Until you delete your account |
| Food logs | Until you delete your account |
| Research consent records | 5 years (legal requirement) |
You can delete your account and all associated data at any time from Settings.
9Data Security
We implement appropriate technical and organizational measures to protect your data:
- 🔒Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- 🔐Authentication: Secure authentication via Supabase Auth
- 🔑Token Security: Third-party tokens (Strava, CGM) are encrypted using AES-256-GCM before storage
- 🛡️Access Control: Row-level security ensures you can only access your own data
- 👤Anonymization: Research data is irreversibly anonymized before any sharing
While we strive to protect your information, no method of transmission over the Internet is 100% secure.
10Your Rights (GDPR)
If you are located in the European Economic Area (EEA), you have the following rights:
| Right | How to Exercise |
|---|---|
| Access | Request a copy of your data via Settings > Export Data |
| Rectification | Update your information in the app |
| Erasure | Delete your account via Settings > Delete Account |
| Portability | Export your data in JSON format |
| Restriction | Contact us to restrict processing |
| Objection | Contact us to object to processing |
| Withdraw Consent | Disconnect services in Settings or disable research |
To exercise any of these rights, contact us at privacy@ando.care.
11International Data Transfers
Your data may be transferred to and processed in countries outside the EEA (notably the United States for some service providers). We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Service providers with appropriate data protection certifications
12Do Not Track
Most web browsers and some mobile operating systems include a “Do Not Track” (DNT) feature. As there is no uniform standard for DNT signals, we do not currently respond to DNT browser signals. If a standard is adopted in the future, we will update this policy accordingly.
13Age Restriction
Ando is intended for users aged 16 years and older. We do not knowingly collect personal information from users under 16. By creating an account or using our services, you confirm that you meet this age requirement.
If we learn that we have collected data from a user under 16, we will take steps to delete that information promptly.
14Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy on this page
- Updating the “Last updated” date
- Sending you an email notification for material changes
We encourage you to review this Privacy Policy periodically.
15Contact Us
If you have any questions about this Privacy Policy, please contact us:
Quick Summary
✓ What We Do
- Collect data you explicitly connect
- Process data to show you insights
- Store data securely with encryption
- Let you delete everything anytime
- Only share anonymized data for research (if you opt in)
✗ What We Don't
- Sell your data
- Use data for advertising
- Share health data without consent
- Track your location
- Share identifiable data with researchers
This Privacy Policy is effective as of February 2026.