Prediabetes.life — Privacy Policy
Version 2026-08-08 · Effective 2026-08-08
1. Scope
This Privacy Policy describes how Sierre Technologies LLC("we," "us," "our"), the operator of Prediabetes.life (the "Service"), collects, uses, and shares information through the Service. It applies to all users of the Service. The Service and this Policy are intended for residents of the United States only.
2. Who we are
Sierre Technologies LLC
4 Crossroads Ct, Dayton, NJ 08810, United States
Privacy contact: privacy@prediabetes.life
Support contact: support@prediabetes.life
3. Eligibility
Prediabetes.life is intended only for users who are 18 years of age or older. Users under 18 may not create or use an account. An affirmative 18+ confirmation is required before any account can be created, and is verified server-side. See Section 15.
4. Information we collect
- Account information: email address, authentication credentials (managed by our authentication provider), sign-in activity.
- Health and wellness information you provide: your stated goals, tracking preferences, weight, height, waist measurement, age, family history, and — where you choose to enter them — A1c and fasting glucose lab values.
- Clinical-screening responses: whether a healthcare professional has told you that you currently have diabetes, and whether you are currently pregnant. We ask these two questions to keep the Service's guidance appropriate and safe for you; your answers, together with any diabetes-range lab values you report, determine whether you are routed into the self-guided prevention program or advised to speak with a healthcare professional first.
- Program activity: check-ins, meal logs, self-directed experiments, and your interactions with the Service's guidance features.
- Coach feature output: the Service includes a "Coach" feature that suggests next-best actions. This feature uses deterministic, rule-based logic operating on your own data — it does not send your information to a third-party artificial-intelligence service. If this changes in the future, we will update this Policy before the change takes effect.
- Wearable/device data: metrics you connect or manually import from a supported device or service. As of this Policy's effective date, live third-party device connections (for example, Fitbit or Garmin) are not active in the Service; only manual entry and a local test-provider path exist. We will update this section with the specific provider, data exchanged, and that provider's own privacy terms before any such integration is enabled.
- AI-assisted features: the Service includes an experimental photo-based meal-analysis capability. As of this Policy's effective date, this feature does not transmit your photo or any data to a third-party AI provider — it returns a placeholder response while the capability is under development. We will update this section before this feature processes real data.
- Technical information: first-party product-usage events (for example, that you viewed a page or completed a check-in). Our systems are built to strip anything that looks like a health measurement (glucose, sleep, calorie, weight, and similar values) from this category before it is stored, and these events are readable only by you.
- Reports you generate: if you choose to generate a summary to share with your own healthcare provider, we store that report so you can access it again.
- Controlled-beta screening responses: if you apply to our controlled beta program at
/beta, and separately agree to a dedicated screening-consent step, we ask a short set of questions about your prediabetes risk context, timing, mindset toward lifestyle change, technology comfort, prior programs or apps you have tried, your ability to commit to beta-testing activities, and your primary device. We use these answers only to select and manage a varied group of beta testers — never to diagnose you or provide medical care, and never combined with your ordinary contact/waitlist information in the same record. If you decline the screening-consent step, we do not collect these answers and you remain an ordinary waitlist entry.
Outside of the limited, consent-gated beta usability analytics described in Section 9, we do not use any third-party analytics, advertising, or tracking service.
5. Sources of information
Directly from you, through account creation, onboarding, and ongoing use. Where you choose to connect a supported device, from that device or service, once that capability is active.
6. How we use information
- To provide and personalize the Service.
- To route you safely — your clinical-screening answers and reported lab values determine whether we direct you toward a healthcare professional instead of enrolling you in the self-guided program.
- To maintain the security and integrity of the Service, including audit logging of account and security events.
- To respond to your requests, including support, access, export, and deletion requests.
- To improve the Service using only the limited, health-value-scrubbed, first-party usage data described in Section 4.
We do not sell your information. We do not share your information for cross-context targeted advertising.
7. Service providers
We use the following providers to operate the Service, each of which processes data only to provide their service to us:
- Supabase — database hosting and user authentication.
- Hostinger — application hosting.
- USDA FoodData Central — public food-database lookups for food search (only the search text you enter is sent; this is a U.S. government public database).
- PostHog — privacy-limited product analytics used only during our controlled beta program, and only for participants who separately opt in (Section 9). We use a random, non-identifying subject id, never your email, name, or handle, and our systems are built to reject health values, screening answers, feedback text, and similar sensitive fields before anything is sent.
If our Gemini-based photo-analysis feature or a Fitbit/Garmin wearable integration becomes active, we will add that provider here, along with the data categories exchanged, before the feature processes real user data.
8. Sharing and disclosure
We do not sell your personal information. We do not share it for cross-context behavioral advertising. We may disclose information: to the service providers listed above; as required by law; to protect the rights and safety of you or others; or in connection with a corporate transaction, with notice to you as required by law.
9. Cookies and analytics
We use a cookie to keep you signed in and manage your session, using our authentication provider's standard library. We do not use advertising or third-party tracking cookies. We operate a limited first-party usage-analytics system, described in Section 4, that never stores health values and is scoped to your own account.
Controlled-beta product analytics.During our controlled beta program, and only for participants who separately agree to a beta-analytics disclosure at that time, we use PostHog to record privacy-limited usage events — for example, which pages or features you use and which buttons or actions you select — to understand usability. This is identified only by a random, non-identifying id, never your email, name, or handle. It does not intentionally include health answers, measurements, lab values, free-text notes, Coach conversations, Doctor Summary contents, or screening responses. Session replay (a recording of on-screen interactions) is disabled everywhere except a small set of specifically reviewed, non-sensitive pages. You can withdraw this analytics consent at any time from Settings; withdrawing stops new analytics collection immediately and does not affect your ability to use the Service.
10. Retention
We retain your information according to the following schedule:
- Active account and health/wellness data: retained while your account is active and needed to provide the Service. Upon a verified deletion request, we work to delete this data from active systems promptly, with an operational target of 30 days.
- Backups: deleted data is removed from backups through normal backup rotation, with a maximum target of six months after an authenticated deletion request. Data is not restored to active use from a backup except for disaster recovery, in which case we reapply any deletion request that applied to it.
- Policy and consent-acceptance records: minimal acceptance evidence (account identifier, consent/policy type, exact version accepted, and timestamp) is retained for six years after the later of account closure or replacement of the accepted version — a period aligned with New Jersey's general contract-claim period, not a claim that this is a universal legal minimum.
- Security and authentication logs: retained by default for up to 24 months, extended only for an active investigation, legal hold, fraud/security need, or documented provider requirement.
- Product/audit events: retained by default for up to 24 months where needed for security, integrity, debugging, and compliance.
- Support and privacy-request records: retained for up to three years after the request is closed, extended only for an active dispute or legal hold.
- Generated exports: returned to you directly when you request them; we do not keep a separate stored copy after delivery.
11. Security
We use technical and organizational measures designed to protect your information, including access controls that restrict your data to your own account and internal audit logging of account-security events. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not claim certification under HIPAA or any other specific security or privacy framework.
12. Your rights and choices
- Access: you can request confirmation of what information we hold about you.
- Export: you can request a full copy of your information in a portable format at any time from Settings.
- Correction: you can request correction of inaccurate information by contacting us.
- Deletion: you can permanently delete your account and associated data at any time from Settings, or by contacting privacy@prediabetes.life. Our operational target for completing a deletion request from active systems is 30 days — faster than, and within, the response window below.
- Consent withdrawal: you can withdraw your acceptance of a specific policy (for example, this Privacy Policy or our Terms of Service) at any time from Settings, or by contacting privacy@prediabetes.life. Withdrawing acceptance of a required policy will limit or end your ability to use the Service, consistent with Section 3 of our Terms of Service.
- Appeal: if we deny your request, you may appeal. See Section 16.
We will respond to a request under this section within 45 days of receipt. Where reasonably necessary given the complexity or number of requests we receive, we may take one additional 45-day extension, and we will notify you of that extension, and the reason for it, within the initial 45-day period. These are outer limits, not a target — we aim to respond sooner wherever possible.
To exercise any of these rights, contact privacy@prediabetes.life.
13. State privacy rights
Depending on where you live, you may have additional rights under state law (for example, California). Contact privacy@prediabetes.life and we will address your request under the applicable law.
14. Consumer health data — Washington and similar laws
If you are a Washington resident, or a resident of a state with a similar consumer health data law, additional rights and protections apply to your consumer health data. See our separate Consumer Health Data Privacy Policy, linked from our homepage, which describes these rights in detail, including access, withdrawal, deletion (including from backups), and appeal rights specific to consumer health data.
15. Children's privacy
Prediabetes.life is intended only for users who are 18 years of age or older. Users under 18 may not create or use an account. An affirmative 18+ confirmation is required before any account can be created, verified server-side; existing accounts that predate this requirement are required to confirm before continuing to use the Service. If we learn that we have collected information from a user under 18 despite this, we will delete that account and associated information.
16. Appeal process
- You may appeal by emailing privacy@prediabetes.life with the subject line "Privacy Appeal."
- Where operationally possible, your appeal will be reviewed by someone who was not solely responsible for the original decision.
- We will determine the outcome of your appeal within 45 days of receipt, unless a shorter period is required by applicable law.
- If you remain dissatisfied, you may contact the applicable state or federal regulator.
17. Breach notification
If we experience a security incident that affects your information, we will notify you without unreasonable delay and in accordance with applicable law.
18. Changes to this Policy
We will post any changes to this Privacy Policy here with a new effective date. Any change that expands the health data we collect or share, or reduces your rights, is a material change: we will ask you to reaccept before it applies to you.
19. Contact us
Sierre Technologies LLC
4 Crossroads Ct, Dayton, NJ 08810, United States
privacy@prediabetes.life