Privacy Policy
Version 3.4 · 2026-08-28
In short
Your logs stay on your phone. Blood glucose, carbohydrates, insulin, ketones and notes are stored only on your own device. They are sent to us only if you choose to turn on sharing with a follower. If you photograph a meal to get a carbohydrate suggestion, that photo is sent for analysis, but it is never stored, neither in the app nor with us. A guardian has to approve the feature first, using their personal identity number. The number is checked on the phone and is not stored.
We show no advertising and we sell no data. The app needs no account and no e-mail address, and contains no tracking. On this website we count visits with Google Analytics, which sets cookies in your browser. That is the website only, never the app.
Who is responsible for your data
The data controller is Föreningen ”Farföräldrar med vänner mot barndiabetes” (a Swedish non-profit association), org. no. 802512-7633, c/o Jan-Erik Hansson, V Ljungbyvägen 105, 269 72 Förslöv, Sweden.
Contact: support@diabetesninja.se
What is stored on your device
The following is stored locally in the app and does not leave your phone on its own:
- Blood glucose, carbohydrates, insulin doses, ketone readings and your own notes, plus any tags you put on a log entry (School or Sick, for example)
- The sick-day plan you write yourself: your own text and the phone numbers to your diabetes team. It never leaves the phone and is not shared with followers.
- The child's first name or nickname and the chosen ninja character
- Points, belts and quest progress
- Settings, such as the selected school and whether insulin or ketones show on the start page
- Follower codes (called ninjakod in the app) held in the operating system's secure storage
- The e-mail address you may type in when mailing out your log, so that it is remembered next time. It is stored on the device only and is not sent to us.
- If you connect a sensor via Nightscout: the family's Nightscout address and the read token, held in the operating system's secure storage, plus the fetched sensor readings. None of this is sent to us.
- If you turn reminders on: the times and names you chose. The reminders are created by the phone itself, and neither the times nor the notifications are ever sent to us.
- Whether the carb photo feature is on or off, plus the guardian's approval of the feature: the date it was given and which version of the text was approved, held in the operating system's secure storage. The personal identity number the guardian types is never stored. It is checked on the phone and discarded straight away. The photos themselves are never stored. See Food photos below.
- If you write a self-care plan in Skolninja: what you fill in (the child's name, how a low blood sugar shows, what to do at a low and at a high, who the school should call and their phone numbers, and optionally the school's name). The plan is stored in the app only and is not sent anywhere on its own.
What is sent from your device
Log sharing (optional). If you turn sharing on, your log entries are sent to our service on Microsoft Azure, linked to your follower code, so that a follower (a parent, for example) can see them. That covers every log entry, ketone readings included. If you put a tag on a log entry (School or Sick, for example), the tag travels with the entry. With sharing off, nothing is sent. You can turn sharing off again at any time.
Export (optional). When you export the log (as a CSV file or an e-mail), the content is created on your device and handed to the app you choose, such as your mail app. The export contains your log entries with values, tags and notes. It is never sent to us; where it goes after that is up to you and the app you share it with.
Followers. When you invite or follow someone, the follower code and first name are sent to our service. The QR code shown on the invite screen contains only your own ninjakod and is generated on the phone; scanning someone's QR code sends nothing anywhere. It only fills the code in for you. (The app can show a second kind of QR code, the one leading to a shared self-care plan, described below.)
Self-care plan as a PDF (optional). If you share the plan from Skolninja as a PDF, the file is created on your device and handed to the app you choose, such as your mail app. In that case the plan is never sent to us. It cannot be shared until you, the guardian, have read through and approved the content. Where the file goes after that is up to you and the app you share it with.
Self-care plan as a web page (optional). If you instead choose to share the plan as a web page with a QR code, its content is sent to our service on Microsoft Azure and displayed on a page on diabetesninja.se. What is sent is what you filled in: the child's name, how a low blood sugar shows, what to do at a low and at a high, who should be called and their phone numbers, the target range the app displays, and optionally the school's name. That is sensitive health data, so:
- The link is the key. Anyone holding the link or the QR code can read the plan, with no account and no sign-in. That is the point (a substitute teacher has to be able to open it straight away), but it also means you should only share it with the people looking after the child.
- You choose how long. From one week to a school year. When the time is up the page stops working on its own.
- You can switch it off immediately. Tapping Sluta dela in the app stops the link and the QR code from working at once, printed copies included, and the plan is deleted from our service the same moment.
- It is deleted anyway. A link you let lapse is deleted automatically no later than seven days after it stopped working.
- The link's key is stored with us only as a check value that cannot be turned back into the key, and it never appears in the web address sent to our servers.
- The page that shows the plan loads no visitor statistics and sets no cookies. It is the one page on the website that is not counted.
Food barcodes. When you scan an item, its barcode (GTIN) is sent to the Dabas grocery database (dabas.com) to look up nutritional values. No information about you is included.
School meals. The municipality and school you pick are sent to our service, which in turn fetches the menu from skolmaten.se.
Food photos (optional). If you use the carb photo feature, the photo is downscaled and stripped of metadata, such as location info, on the phone itself. It is then sent through our service to Azure OpenAI at Microsoft within the EU, which suggests what the meal contains and roughly how many grams of carbohydrate. No name, no follower code and no log values are included, only the image. We never store the photo: it is processed and discarded. Microsoft may keep the image for up to 30 days to counter abuse of the AI service; it is then deleted. A guardian must approve the feature in the app before the first photo is sent. The approval happens on its own screen, where the guardian types their Swedish personal identity number. It has to be a valid number for someone aged 18 or over. The number is checked on the phone and never leaves it. We do not store the number, only the date the approval was given. You can remove the approval and turn the feature off at any time under Settings.
Notifications (optional). If you turn notifications on in the app's settings, your phone's notification address (a technical identifier created by the operating system, not anything you chose) is sent to our service together with your follower code, so that we know where the notification should go. The address is held by Azure Notification Hubs, and the notification itself is delivered through Apple's (Apple Push Notification service) or Google's (Firebase Cloud Messaging) notification service depending on your phone.
The notification contains the diabetic's first name and what was logged: blood glucose, a meal, insulin or ketones. Never a value. That means no blood glucose readings appear on a lock screen or pass through Apple's and Google's services. You can turn notifications off whenever you like, and the address is then deleted.
Sensor data (optional). If you connect a sensor, the app fetches glucose readings directly from the family's own Nightscout service over HTTPS. Nightscout is the family's own service, not ours: the address and read token are stored on the phone only and are never sent to us, and the sensor readings stay on the device. A follower who enters the same address fetches the readings the same way, directly from the family's Nightscout and from their own phone.
NattNinja (optional). If the family chooses NattNinja (cgm.diabetesninja.se) as their Nightscout service, the same applies in the app: the address and read token are stored on the phone only. But NattNinja is a separate service run by Venueve AB, with its own privacy policy and terms. The sensor readings are then stored with NattNinja, not with us.
Crash reports. If the app crashes, a technical report is sent to Sentry (Functional Software, Inc.) containing device model, operating system, app version and the technical stack trace. The app also sends performance measurements. We do not intentionally send names or log values.
Anonymous statistics. At most once a day the app sends a small message to our service saying that this installation exists. It contains four things: the app version, the type of phone (iPhone or Android), the operating system version and the country code you have set on the phone yourself. Along with it goes a random number the app makes up for itself the first time it starts.
That number is not your follower code and cannot be linked to you, your child or your logs. We do not look at where you connect from, and nothing you have logged is included. We use it only to know how many people use the app and which versions are in use. Otherwise we only know that about families who have turned sharing on, and most have not. The message is sent from every installation and cannot be switched off in the app. The four items above are its entire contents.
Cookies and visitor statistics on this website
This section is about the diabetesninja.se website only. The app uses no cookies at all and contains no Google Analytics.
We use Google Analytics to count visits to the website. It runs on every page and sets cookies in your browser as soon as the page loads: one called _ga and one starting with _ga_. We do not ask first.
What is processed is your IP address, which pages you visit and when, approximate location (country or region), language, the page you came from, and technical information about your browser and device. A random number in the cookie means repeat visits from the same browser are recognised.
We use it only to see how many people visit the website and which pages are read. It is never used for advertising or profiling: advertising features, Google signals and ad personalisation are switched off. The statistics cannot be linked to your follower code, your child or anything you logged in the app.
If you share a self-care plan as a web page, that plan is displayed on diabetesninja.se (see Self-care plan as a web page above). That page is the exception: it loads no visitor statistics and sets no cookies. The link's key sits after the # in the address and is therefore never sent onwards, neither to us nor to Google.
The legal basis is our legitimate interest in knowing how the website is used, Article 6(1)(f) of the GDPR. Google LLC is the data processor for this processing, and the data may be processed in the USA. The cookies are deleted after 13 months.
If you would rather not be counted, block cookies for this site in your browser, or install Google's add-on that switches Google Analytics off everywhere. The website works exactly as well.
What we never do
- We show no advertising and do no marketing inside the app
- We do not sell, trade or disclose data for advertising or marketing purposes
- We use no cookies for advertising or profiling. The website's visitor statistics only count visits
- We do not read your location, your calendar or your contacts
- We require no account, no password and no e-mail address
Children's data
DiabetesNinja is made for children and young people with type 1 diabetes, and is intended to be used together with a parent or guardian. Blood glucose, carbohydrate, insulin and ketone information is health data, and therefore a special category of personal data under Article 9 of the GDPR.
It is the guardian who consents to the processing and who decides whether sharing is turned on. Sharing is off by default. The same applies to food photos: no photo is sent until a guardian has approved the feature in the app with their personal identity number.
Legal basis
Processing is based on consent under Article 6(1)(a) of the GDPR and, for health data, on explicit consent under Article 9(2)(a). You may withdraw your consent at any time by turning sharing off or by contacting us.
The website's visitor statistics are the exception. They rest on our legitimate interest in knowing how the website is used, Article 6(1)(f). They process no health data.
How long data is kept
Shared log entries are kept for 12 months and then deleted.
The anonymous statistics follow the same limit: if an installation has not been in touch for 12 months, its row is deleted.
A self-care plan you shared as a web page has its own limit: the one you chose when you shared it. Switching sharing off deletes the plan immediately. If you let the link lapse, it is deleted no later than seven days after it stopped working.
Data that exists only on your device is kept for as long as you have the app installed. Uninstalling the app removes it.
If you ask us to delete your data, we remove it sooner than that.
Your rights
You have the right to
- know what data we hold about you and receive a copy,
- have inaccurate data corrected,
- have your data erased,
- withdraw your consent, and
- complain to the Swedish Authority for Privacy Protection (IMY) if you believe we handle your data incorrectly.
Requesting or deleting your data
E-mail support@diabetesninja.se and we will help you. Our contact page explains how to stop sharing your log and how to request the data stored about you.
Security
All traffic between the app and our service is encrypted over HTTPS, and the service sits behind Azure API Management. Follower codes are held in the operating system's secure storage.
Knowing a follower code is not enough to fetch a shared log: whoever fetches it must also be connected as a follower of that person. The diabetic sees their followers under Min Ninja and can remove them at any time.
The database on the phone is not separately encrypted; it is protected by the operating system's isolation between apps. Anyone with unlocked access to the phone can therefore reach the data in the app.
Changes to this policy
If we change anything material about how we handle data, we will update this page and the version number at the top. Continuing to use the app after a change means the new version applies.

