Privacy Policy
Last updated: March 15, 2026
1. Introduction
Sugar Panic (“we”, “our”, “us”) operates the Sugar Panic mobile application. This policy explains how we collect, use, store, and protect your information when you use our app. By using Sugar Panic, you agree to this policy.
2. Information We Collect
Account Information (when you sign in)
- Name and email address (via Apple Sign-In or Google Sign-In)
- A unique user identifier from your authentication provider
Device Information
- An anonymous device identifier (UUID) generated locally on your device
- Device type, operating system version, and app version
- This identifier is NOT linked to your Apple ID or Google account
Health & Wellness Data
- Sugar intake logs and craving records
- Craving triggers you identify (such as stress, boredom, social situations, late nights, or habits)
- Quiz responses and progress
- Conversations with the AI Sugar Buddy coach
- Breathing exercise completions
- Swap choices and outcomes
Usage Data
- App feature usage and screen views
- Session duration and frequency
- Feature interaction events (anonymized)
3. How We Use Your Information
- Provide and personalize the app experience
- Generate AI-powered swap suggestions and coaching responses (via OpenAI API)
- Track your progress and maintain your streak data
- Sync your data across devices when signed in
- Process and manage your subscription
- Improve the app based on anonymized usage patterns
- Send you reminders and notifications (only if you opt in)
We do NOT use your data for advertising. We do NOT sell your data to any third party.
4. AI-Powered Features
Sugar Panic uses OpenAI’s API to power the Sugar Buddy chat coach and swap suggestion features. When you use these features, your craving descriptions and chat messages are sent to OpenAI for processing. Per OpenAI’s API data usage policy, data sent via the API is NOT used to train their models and is NOT stored beyond what is needed to process your request. We do not include your name, email, or other identifying information in requests to OpenAI.
5. Data Storage & Security
- Remote data is stored on Supabase (PostgreSQL database) with encryption at rest and in transit, hosted on servers in the United States (US-West region)
- Local data is stored on your device using AsyncStorage (app data) and SecureStore (sensitive tokens such as authentication credentials)
- All communication between the app and our servers uses HTTPS encryption
- We implement industry-standard security measures to protect your data, but no method of transmission or storage is 100% secure
6. Third-Party Services
We use the following third-party services:
- OpenAI — processes AI chat and swap suggestion requests (no data retention)
- Supabase — cloud database for data synchronization
- RevenueCat — subscription management and receipt validation
- Apple — authentication (Sign in with Apple) and payment processing
- Google — authentication (Google Sign-In)
Each service operates under its own privacy policy. We encourage you to review their policies.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request deletion of your account and all associated data
- Export your data in a portable format
- Opt out of non-essential data collection
- Withdraw consent at any time
For users in the European Economic Area (EEA), you have additional rights under GDPR including the right to data portability, the right to restrict processing, and the right to lodge a complaint with a supervisory authority.
For users in California, you have rights under the CCPA including the right to know what personal information is collected, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information.
To exercise any of these rights, contact us at support@sugarpanic.app.
8. Children’s Privacy
Sugar Panic is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child under 13, please contact us and we will promptly delete it.
9. Data Retention
- Active accounts: Your data is retained for as long as your account is active
- Deleted accounts: All personal data is permanently deleted within 30 days of an account deletion request
- Anonymous analytics data that cannot be linked back to you may be retained indefinitely
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or via email. The “Last updated” date at the top of this page reflects the most recent revision. Your continued use of Sugar Panic after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Email: support@sugarpanic.app