Privacy Policy
This policy explains what data Seravi collects when you use our service, why we collect it, how we protect it, and the rights you have over it. We try to be plain-spoken because privacy shouldn't require a law degree to understand.
Contents
1. Who we are
"Seravi" is a hosting service for the open-source Nightscout software, accessible at seravi.eu. The service is operated by [LEGAL ENTITY NAME], a company registered in [LEGAL ENTITY COUNTRY] ("we," "us," "our").
For the purposes of the EU General Data Protection Regulation (GDPR), [LEGAL ENTITY NAME] is the data controller for personal data processed in connection with your Seravi account and service.
If you have any questions about this policy or your data, contact us at support@seravi.eu.
2. What data we collect
Information you provide directly
- Account data — when you sign in with Google or Apple, we receive your email address and your name (as provided by Google/Apple).
- Site configuration — the username you choose for your Nightscout subdomain and the API secret you set for your site.
- Payment data — handled directly by Stripe. We do not store your credit card number, expiry, or CVV; we receive only a customer reference and subscription status from Stripe.
Health data uploaded to your Nightscout site
- Glucose readings uploaded from your continuous glucose monitor (CGM) via an uploader application you control.
- Treatments and events you or your uploader records (insulin doses, carbs, exercise, notes).
- Device status from your CGM, pump, or phone uploader.
This data is uploaded by you (or applications you authorize) directly to your private Nightscout instance. We host this data on your behalf; see section 5 for the legal basis.
Information collected automatically
- Technical data — IP address, browser type, operating system, pages visited, and timestamps. Used for security, debugging, and abuse prevention.
- Server logs — anonymized request logs retained for up to 30 days.
- Advertising measurement data — when you arrive at seravi.eu from a Google Ads campaign, Google sets cookies in your browser that allow us to measure whether your visit resulted in a sign-up. See section 10 for details and how to opt out.
3. How we use your data
- To provide the Seravi service — create and run your Nightscout site, authenticate you, host your data.
- To process payments and manage your subscription.
- To communicate with you about your account, service changes, and support requests.
- To investigate security incidents and prevent fraud or abuse.
- To measure the effectiveness of our advertising — i.e. to know how many people who clicked on a Seravi ad on Google actually signed up. This is aggregate measurement only; we do not target individual users with personalized advertising.
- To comply with our legal obligations (e.g. tax records, responding to lawful requests).
We do not sell your personal data. We do not use your glucose data or any health data for any purpose other than serving it back to you and authorized applications. We do not profile individual users for advertising purposes.
4. Legal basis for processing
Under GDPR Article 6, we process your personal data on these legal bases:
- Performance of a contract — to provide you the service you signed up for (account, hosting, payment processing).
- Legitimate interests — to keep our service secure, prevent fraud, debug technical issues, measure the effectiveness of our marketing, and improve our service. These interests are balanced against your rights.
- Legal obligation — to retain financial records, respond to lawful requests, and comply with applicable law.
- Consent — for the processing of health data, as described below.
5. Health data (special category)
We process this data on the basis of your explicit consent (GDPR Article 9(2)(a)), given by your decision to upload such data to your Nightscout instance hosted by us. You can withdraw this consent at any time by stopping uploads, exporting your data, and deleting your account (see section 9).
Our processing of this data is strictly limited to hosting and serving it — we do not analyze it, mine it, share it, or use it for any purpose other than making it available to you and to applications you authorize through your Nightscout API. Health data is never shared with Google, advertising networks, or any third party for advertising purposes.
You retain control of this data at all times. You can delete it from your Nightscout instance directly, or by deleting your account.
6. Who we share data with
We share personal data only with the following categories of recipients (our "sub-processors"), and only to the extent necessary to provide the service:
- Hetzner Online GmbH (Germany) — server hosting infrastructure. Stores all account, configuration, and health data.
- Supabase Inc. (United States) — authentication and account database. Stores email, name, and subscription metadata.
- Stripe — payment processing. Receives your email, payment details, and subscription information. Stripe is the data controller for your payment card data; see Stripe's privacy policy.
- Google LLC — (a) when you choose to sign in with Google, you authenticate with them and they share your email and name with us; (b) we use Google Ads to advertise Seravi, and Google receives data about visits to seravi.eu from Google ad clicks for the sole purpose of measuring whether our ads resulted in sign-ups. See Google's privacy policy.
- Apple Inc. — when you choose to sign in with Apple, you authenticate with them and they share your email and name with us. See Apple's privacy policy.
- Email delivery providers — used to send transactional emails (account confirmations, password resets, billing notices). We receive delivery metadata.
We will also share data when required by law, court order, or lawful request by a public authority, and where reasonably necessary to protect our rights, property, or safety, or that of our users or others.
7. International transfers
Some of our sub-processors are located outside the European Economic Area (EEA), notably Supabase, Stripe, and Google in the United States. Where data is transferred outside the EEA, we rely on:
- Standard Contractual Clauses approved by the European Commission, where applicable; and
- The sub-processor's own GDPR compliance program and supplementary measures.
You can request more information about these safeguards by contacting us.
8. How long we keep data
- Account data — while your account is active, plus up to 90 days after closure to allow recovery or handle disputes.
- Health data — for as long as your Nightscout instance is active. When you cancel and your site is shut down, data is retained for 30 days (in case you reactivate), then permanently deleted.
- Payment records — retained for up to 7 years to comply with tax and accounting obligations.
- Server logs — up to 30 days.
- Email logs — up to 90 days.
- Google Ads conversion data — retained by Google per their retention policies (typically 30–90 days for click and conversion measurement).
You can request earlier deletion of your personal data at any time (see section 9), subject only to data we are legally required to retain.
9. Your rights
Under GDPR, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete personal data.
- Erasure ("right to be forgotten") — request deletion of your personal data, subject to limited exceptions.
- Portability — receive your data in a structured, machine-readable format and transmit it to another controller.
- Restriction — request that we limit how we process your data in certain circumstances.
- Objection — object to processing based on legitimate interests, including advertising measurement.
- Withdraw consent — for processing based on consent (e.g. health data), you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Complain to a supervisory authority — if you believe we have mishandled your data, you have the right to lodge a complaint with the data protection authority in your country of residence.
To exercise any of these rights, email support@seravi.eu. We will respond within 30 days. There is no charge for reasonable requests.
10. Cookies and similar technologies
Seravi uses the following cookies and similar storage:
- Authentication storage (essential) — to keep you signed in. Set by Supabase. Strictly necessary for the service to work and cannot be disabled.
- Stripe checkout cookies (essential) — set by Stripe during the checkout process for fraud prevention and session continuity.
- Google Ads conversion tracking (measurement) — when you arrive at seravi.eu from a Google Ads campaign, Google sets cookies in your browser to record that visit and whether it resulted in a sign-up. This allows us to measure the effectiveness of our advertising. The data shared with Google includes your IP address, the page visited, and the timestamp. It does not include any health data, payment data, your name, or your email. You can read Google's privacy policy at policies.google.com/privacy.
We do not use cookies that build personalized advertising profiles, sell data to advertising brokers, or track you across unrelated websites.
To opt out of Google Ads measurement cookies: you can install Google's official opt-out browser extension at tools.google.com/dlpage/gaoptout, manage personalized advertising at adssettings.google.com, or clear and block cookies for seravi.eu in your browser settings. Opting out does not affect your ability to use Seravi.
11. Children's data
Many people with Type 1 diabetes are children, and their parents or guardians often manage their care. The Seravi account itself must be held by an adult (18+) or by a parent/guardian on behalf of a minor. If you are a parent or guardian managing your child's diabetes data through Seravi, you are responsible for compliance with applicable law regarding the processing of your child's data, including obtaining any required consent.
If we become aware that a Seravi account is held directly by a child under the age of digital consent applicable to their country, we will deactivate the account and contact the guardians.
12. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will additionally notify you by email to the address associated with your account at least 30 days before the change takes effect. Your continued use of Seravi after the effective date constitutes acceptance of the updated policy.
13. How to contact us
For any questions about this privacy policy, to exercise your rights, or to raise a concern:
Email: support@seravi.eu
Operating entity: [LEGAL ENTITY NAME], [LEGAL ENTITY COUNTRY]
You also have the right to complain to your local data protection authority. In the EU, you can find your authority at edpb.europa.eu/about-edpb/about-edpb/members_en.