Last updated: June 2026
Privacy Policy
1. WHO WE ARE
Ditch The Spike ("DTS", "we", "us") is a behavioral metabolic awareness app designed to help people understand their glucose patterns. We are based in British Columbia, Canada and operate in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA).
2. WHAT WE COLLECT
We collect the following personal information when you use DTS:
Account Information:
- email address, name, password (encrypted)
Health & Behavioral Data (entered voluntarily by you):
- Glucose readings and context (fasting, post-meal, etc.)
- Meal descriptions, photos, macro estimates, and tags
- Body weight entries (if provided in MDPP program)
- Fasting window times
- Mood and energy notes attached to glucose readings
App Usage Data:
- Pages visited, features used, session duration
- Device type, operating system, browser type
- IP address (for security and fraud prevention only)
Payment Information:
- Processed entirely by Stripe — we never see or store your credit card number. We store only your Stripe Customer ID and subscription status.
3. HOW WE USE YOUR DATA
We use your data exclusively to:
- Provide the DTS app features (logging, pattern analysis, Decision Mode recommendations)
- Calculate your personal glucose patterns and consistency score
- Send you reminders and summary emails (if you opt in)
- Process your subscription payments via Stripe
- Improve app performance and fix bugs
We do NOT use your health data for advertising.
We do NOT sell your personal data to any third party.
We do NOT share your health data with insurance companies, employers, or government agencies.
4. CAREGIVER ACCESS
If you invite a caregiver to view your data, they receive read-only access to your glucose readings, meals, and patterns. You control this access and can revoke it at any time from your Profile settings. Caregiver access is initiated by you — no one can link to your account without your invite code.
5. DATA STORAGE & SECURITY
Your data is stored on Lovable Cloud infrastructure (Supabase), hosted on AWS in the United States with enterprise-grade encryption at rest (AES-256) and in transit (TLS 1.3).
Row-Level Security (RLS) policies ensure your data is only accessible by your authenticated account and any caregivers you explicitly invite. No DTS employee can access your individual health data without your explicit consent.
6. DATA RETENTION
Active accounts: your data is retained for as long as your account is active.
Deleted accounts: when you delete your account, all personal data including health logs, glucose readings, and profile information is permanently deleted within 30 days. Stripe billing records are retained as required by financial regulations (7 years).
7. YOUR RIGHTS UNDER PIPEDA
As a Canadian user you have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Withdraw consent and request deletion of your data
- Export your data (use the CSV export on your Profile page)
- File a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca)
To exercise any of these rights, contact: zain.rafique@gmail.com. We will respond within 30 days.
8. USERS OUTSIDE CANADA
If you access DTS from the European Union, your data rights under GDPR apply including the right to erasure, portability, and restriction of processing. For EU inquiries: zain.rafique@gmail.com
If you access DTS from California, USA, your rights under CCPA apply including the right to know, delete, and opt out of sale (we do not sell personal data).
9. CHILDREN'S PRIVACY
DTS is not intended for users under 13 years of age. We do not knowingly collect data from children under 13. If you believe a child has created an account, contact us and we will delete it.
10. HEALTH DATA DISCLAIMER
DTS is a behavioral awareness tool — not a medical device and not a substitute for professional medical advice. All information in the app is for informational and behavioral tracking purposes only. Always consult a qualified healthcare professional for medical decisions.
11. COOKIES & TRACKING
DTS uses essential cookies only (authentication session management). We do not use advertising cookies or cross-site tracking.
12. CHANGES TO THIS POLICY
We will notify you by email and in-app banner if we make material changes to this Privacy Policy. Continued use of DTS after changes constitutes acceptance of the updated policy.
13. CONTACT
Privacy inquiries: zain.rafique@gmail.com
General: zain.rafique@gmail.com
14. APP STORE & GOOGLE PLAY DATA DISCLOSURES
This section discloses our data practices in the format required by Apple's App Store Privacy Nutrition Labels and Google Play's Data Safety form.
Data Linked to You (used only to run the app — not for tracking):
- Health & Fitness: glucose readings, fasting windows, body weight, meal logs and macros — used solely for App Functionality and Analytics within your own account.
- Contact Info: email address — used for Authentication, Account Management, and transactional email (receipts, reminders).
- Identifiers: user ID, device ID — used for Authentication and Fraud Prevention.
- Usage Data: product interaction — used for App Functionality and Analytics only.
- Diagnostics: crash data, performance data — used to fix bugs.
- Purchases: subscription status and Stripe / In-App Purchase identifiers — used for App Functionality. Payment card numbers are never collected or stored by DTS.
Data NOT Collected:
- Precise or coarse location
- Contacts, photos (other than meal photos you explicitly attach), microphone, or audio
- Browsing history outside the app
- Advertising identifiers (IDFA / AAID)
- Sensitive info beyond the health categories disclosed above
Data Sharing & Tracking:
- We do not track you across apps or websites owned by other companies.
- We do not share your data with data brokers, advertisers, or analytics networks that build cross-app profiles.
- Limited processors: Lovable Cloud / Supabase (hosting & database), Stripe (payments). Apple In-App Purchase and Google Play Billing process subscriptions on their respective platforms. No other third parties receive your health data.
Security Practices:
- All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- You can request deletion of your data at any time from the Profile screen or by emailing us — committed for both iOS and Android per platform requirements.
- Independent security review: row-level access controls enforced server-side.
Apple HealthKit & Google Health Connect:
If a future version of DTS reads from or writes to Apple HealthKit or Google Health Connect, that data is processed on-device for app features only. Data obtained from HealthKit is never used for advertising or marketing, never sold or shared with third parties, and never used for any purpose other than providing health and fitness features within DTS — in accordance with Apple's HealthKit terms.