/*Analytics script */
[Last Modified: March 14, 2026]
This Privacy Policy (“Privacy Policy”) describes how Sweetch Health Ltd. (collectively with its subsidiaries and affiliated companies “Company”, “we”, “us” or “our”) collects, uses, processes, and shares Personal Data when individuals access or use our services.
For purposes of this Privacy Policy:
This Privacy Policy forms an integral part of the Terms of Service or any other applicable agreement governing your use of the Services (collectively, the “Terms”). Any capitalized terms not defined herein shall have the meanings assigned to them in the Terms or under applicable privacy laws.
This Privacy Policy explains what information we may collect from you, how such information may be used and shared, how we safeguard it, and how you may exercise your rights in relation to your Personal Data (as defined below). Our processing of Personal Data is carried out in accordance with applicable privacy and data protection laws, including, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK GDPR and the Data Protection Act 2018, applicable United States privacy laws (“US Privacy Laws”), and the Israeli Privacy Protection Law, 1981.
California Residents: If you are a resident of California, please review our separate CCPA Notice, which supplements this Privacy Policy and provides additional information regarding our data practices and your rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”).
For the avoidance of doubt, this Privacy Policy applies only to Personal Data processed in connection with the Services. It does not apply to Personal Data relating to our employees, contractors, or other personnel in the context of their employment or engagement with the Company.
If you have any questions regarding this Privacy Policy or our data practices, you are welcome to contact us at: support@sweetch.com
You should be aware that the Services will track your daily activity and collect and analyze your Personal Data, including health-related data as set out below, in order to establish a personalized program and recommendations and to help you achieve personal health goals and manage a chronic condition.
You are not required by law to provide us with any Personal Data. However, please note that some of our services require the processing of certain Personal Data and without such data we may not be able to provide you with all or part of such services (e.g., without the completion of the Application registration process we will not be able to provide you with our Services).
We reserve the right to amend this Privacy Policy from time to time, at our sole discretion. The most recent version of the Privacy Policy will always be posted on the website, and the updated date will be reflected in the “Last Modified” heading above. Subject to applicable law, any amendments to this Privacy Policy will become effective upon publication on the website, unless we notify you otherwise. If we materially change the way in which we process your previously collected Personal Data, we will provide you with prior notice, and where required under applicable law, request your consent prior to implementing such changes. We encourage you to review this Privacy Policy periodically to remain informed about our data practices.
Sweetch Health Ltd. is the Data Controller (as such term is defined under the GDPR or equivalent privacy legislation) of your Personal Data collected from you as a user of our services.
You may contact us as follows:
We have appointed Prighter Group with its local partners as our privacy representative and your point of contact. Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website: https://prighter.com/q/14428797156.
Below you can find information regarding the purposes for which we process your Personal Data, the types of Personal Data processed, the purposes for such processing, and the lawful basis relied upon under applicable data protection laws, including the GDPR.
Non-Personal Data
During your interaction with the Services, we may collect aggregated, statistical, or technical information which does not identify an individual (“Non-Personal Data”). We are not aware of the identity of the user from which such Non-Personal Data is collected. Non-Personal Data may include, for example, technical and statistical information relating to the scope, frequency, duration, and patterns of use of the Services, pages viewed, time and date stamps, interactions with content displayed through the website or the Application, language preferences, device characteristics, browser type, operating system, network information, and other similar technical parameters.
We may also process and transform Personal Data into anonymized or aggregated datasets in a manner that no longer enables the identification of an individual. Once Personal Data has been irreversibly anonymized or aggregated in such a manner, it will be treated as Non-Personal Data. Non-Personal Data may be used by the Company for any lawful purpose, including research, analytics, statistical analysis, service improvement, and the development and enhancement of the Services.
If we combine Personal Data with Non-Personal Data, the combined dataset will be treated as Personal Data as long as it remains identifiable.
Personal Data
We may collect from you, either directly or indirectly through your interaction with the Services, information relating to an identified or identifiable individual (“Personal Data”). The categories of Personal Data we process, the purposes for such processing, and the relevant lawful bases under applicable data protection laws are detailed in the table below.
For clarity, under certain United States general privacy laws, “Personal Data” does not include information that cannot reasonably be linked to an identified or identifiable individual, such as de-identified or aggregated data, or information regulated by other sector-specific legislation.
The table below details the processing of Personal Data, the purpose, lawful basis, and processing operations:
Contact Information
If you contact us, for example through a contact us form, as a Customer for support, or for general inquiries through the website, the Application, or other communication channels, we may collect Personal Data such as your name, email address, the nature of your inquiry, the category of request, and any additional information you choose to include in your communication.
User Account Registration
When opening an account to the Application and our Services, you will be required to provide certain basic Personal Data such as your name, email address, date of birth, phone number (where applicable), login credentials, and other account-related information. If you choose to register using a third-party authentication provider (for example Apple, Google, or another supported sign-in provider), we may receive limited Personal Data from that provider, such as your name and email address, subject to the provider’s privacy policy and your authorization.
Application Usage and Lifestyle Data
As part of your interaction with the Application, we collect and process various types of information relating to your daily activities, lifestyle routines, and engagement with the Services. Such information may include, for example, activity habits, physical activity patterns (e.g., walking or exercise activity), dietary routines, hydration habits, sleep-related inputs, daily routines, task completion, user responses to coaching prompts, interaction with behavioral tasks or goals presented through the Application, participation in digital programs, engagement indicators, adherence metrics, and other behavioral or lifestyle-related signals submitted or generated during your use of the Application.
Health and Behavioral Health Information
During registration or while using the Application, you may voluntarily provide certain health-related or wellness-related information that may qualify as health data under applicable data protection laws. This may include, for example, self-reported health conditions, health goals, biometric indicators, weight or body measurements, health assessments, behavioral health indicators, responses to health questionnaires, medication adherence information, health-related lifestyle indicators, and other health or wellness information you choose to provide through the Application.
Device Sensor Data
The Application may collect certain technical signals generated by sensors available on your device, subject to your device settings and permissions. Such information may include motion-related data, accelerometer signals, gyroscope signals, device orientation information, step-count signals, or other motion and activity indicators generated by device sensors that may assist in measuring activity levels or behavioral patterns.
Data Received from Connected Devices and External Integrations
If you choose to connect the Application with external devices, wearable technologies, or third-party health platforms (for example fitness trackers, smart watches, or other connected health devices), we may collect and process certain data transmitted from such devices or platforms. Such information may include CGM data, activity measurements, physiological indicators, fitness metrics, wellness signals, or other health or activity data generated by the connected device and shared with the Application through authorized integrations.
Location Data
The Application may collect general location information derived from your device, such as approximate geographic location based on IP address or device settings. In certain cases, and subject to your device permissions, the Application may access more precise location information.
Apple Health (HealthKit) Data and Google Health ConnectIf you choose to enable integration with Apple Health (HealthKit) or Google Health Connect, we may collect and process certain health data via Apple’s or Google’s authorized APIs, such as body measurements and other related health data, as permitted by you.
Payment Data
When you make payment to receive our services (e.g., application subscription) you will be asked to submit payment information data such as your full name, address, credit card number, etc.
General Usage Data
When you use our services, information and data gets automatically generated. Also, our systems keep records of your activity and interaction with the services, your support inquiries, requests and services actually provided, and any other data related to the actual use of the services following the registration.
To the extent usage data contains Personal Information, it will be treated as Personal Information.
Online Identifiers and Advertising and Targeting data
When you interact with the website and services, we may collect online identifiers such as your Internet Protocol address (IP), Cookie-ID, etc., and other information that relates to your activity through the website, such as pages viewed, click stream data, login time and date stamp, etc. This data might be collected directly by us or through our use of third parties' cookies and advertisement platforms.
Similarly, we may collect Ad calls, which is a code shared with advertisers, include zip code, advertiser ID, the webpage that you came from, the IP address, and approximate location which assists the advertiser to determine which ads to place. The ad-call will also include your preference regarding interest-based advertising as further explained herein.
Direct Marketing
As a user, we will send you materials and marketing content, through the email information you provided during your registration.
Please note that the actual processing operation for each purpose of use and lawful basis detailed in the table above may differ. Such processing operation usually includes a set of operations made by automated means, such as collection, storage, use, disclosure by transmission, erasure, or destruction. The transfer of Personal Data to third-party countries, as further detailed in the Data Transfer Section below, is based on the same lawful basis as stipulated in the table above.
In addition, we may use certain Personal Data to prevent potentially prohibited or illegal activities, fraud, misappropriation, infringements, identity thefts, and any other misuse of the services and to enforce the Terms, as well as to protect the security or integrity of our databases, services, and the website, and to take precautions against legal liability. Such processing is based on our legitimate interests.
As part of the functionality of the Services, the Company may analyze certain Personal Data collected through your use of the Application in order to generate personalized insights, recommendations, and behavioral guidance tailored to your individual profile.
In particular, the Services may combine various data points provided by you or generated through your interaction with the Application, including lifestyle information, behavioral indicators, activity patterns, health-related inputs, engagement signals, and other usage-related data, in order to create and maintain a personalized user profile. This profile enables the Services to adapt content, recommendations, coaching prompts, and other features to your individual needs, goals, and behavioral patterns.
In order to perform such personalization and profiling, the Services may utilize automated analytical tools, including algorithmic models and artificial intelligence-based systems operated by the Company or by service providers acting on the Company’s behalf. These systems may process the Personal Data described above, including lifestyle information, behavioral indicators, engagement patterns, activity signals, and health-related inputs, in order to identify behavioral patterns, generate insights, and adapt recommendations and digital coaching features within the Application. Where such processing is carried out by third-party technology providers, such providers act solely as service providers processing Personal Data on our behalf and in accordance with our instructions and applicable data protection laws and are not permitted to use such data for their own independent purposes.
Such analysis may constitute profiling, as defined under applicable data protection laws, meaning automated processing of Personal Data used to evaluate certain personal aspects relating to you, such as your lifestyle habits, behavioral tendencies, activity levels, and progress toward personal wellness goals.
For the avoidance of doubt, the profiling activities carried out as part of the Services are intended solely to support the functionality of the digital health platform and to enhance personalization of the Services. The Services do not involve automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of applicable data protection laws. For the avoidance of doubt, the Services are not intended to provide medical advice, diagnosis, or treatment. Any insights, recommendations, or guidance generated through the Services are provided solely for lifestyle and wellness purposes and should not be relied upon as a substitute for professional medical advice. Users should always consult with a qualified healthcare professional regarding any medical condition or health-related decision.
Processing related to profiling is based on the lawful bases applicable to the underlying categories of Personal Data used for such analysis, as described in Section 4 above. Where profiling relies on health-related information, such processing is carried out based on your explicit consent, provided through the Application.
Depending on the nature of your interaction with us, we may collect the above detailed information from you, as follows:
When you access or use our services, we may use “cookies” or similar tracking technologies, which store certain information on your device (i.e., locally stored). The use of cookies is standard industry-wide practice. A “cookie” is a small piece of information that a website assigns and stores on your computer while you are viewing a website. Cookies are used by us for various purposes, including allowing you to navigate between pages efficiently, as well as for statistical purposes, analytic purposes and advertising. You can find more information about our use of cookies here: www.allaboutcookies.org.
There are several types of cookies, including without limitation:
You may find more information about the cookies we use as well as opt-out from cookies or change your preferences at any time by using the cookies setting tool available on the footer of our website.
Where we use third-party advertising cookies, such third-party may independently collect, through the use of such tracking technologies, some or all types of Personal Data detailed above, as well as additional data sets, including to combine such information with other information they have independently collected relating to your online activities across their network of websites, for the purpose of enhanced targeting functionality and delivering personalized ads, as well as providing aggregated analytics related to the performance of our advertising campaign you interacted with. These third parties collect and use this information under their own privacy policies, and we are not responsible for their privacy practices.
Although we do not sell your personal information for profit, we do engage in targeted advertising on the website, this type of advertising activity may be considered a “sale” of Personal Data under certain US Privacy Laws and may also be referred to as “targeted advertising”. Please note that even if you opt-out you may still see personalized ads based on information other companies and ad networks have collected about you, if you have not opted out of sharing with them.
For IBA opt out options on desktop and mobile websites, please visit:
We also honor browser-based opt-out signals, such as the Global Privacy Control (GPC) and Universal Opt-Out Mechanisms (UOOM), by automatically disabling non-essential cookies when such signals are detected.
As part of the Application, we utilize certain third party’s Software Development Kits (SDKs), that communicate certain information, which may include Personal Information, to such third-parties. However, our use of SDKs is always subject to contractual terms forbidding the third-party from utilizing such information for any other purpose than the Application’s operation. The following Third-Party SDKs are being utilized in the Application:
Apple (for Apple Users)
We share your data with third parties, including our partners or service providers that help us operate and make the most of the website. You can find here information about the categories of such third-party recipients.
Our Affiliated Companies
Our Service Providers
Legal and Law Enforcement
Corporate Transactions
Apple Health (HealthKit) or Google Health Connect
When we share information with service providers, we ensure they only have access to such information that it is strictly necessary for us to operate the services. These parties are required to secure the data they receive and to use the data for pre-agreed purposes only while ensuring compliance with all applicable data protection regulations (however, sometimes certain service providers, such as social networks, may use certain data for their own benefit, subject to the separate terms between them and you, as direct user of their services).
In general, we retain the Personal Data we collect for as long as it remains necessary for the purposes set forth above, all under the applicable regulation, or until you express your preference to optout, where applicable.
Without limiting the generality of the above, retention periods may vary depending on the nature of the Personal Data and the purposes for which it was collected. In determining appropriate retention periods, the Company considers a number of factors, including: (i) the duration of the user’s relationship with the Services and the need to maintain an active user account; (ii) the need to retain health-related or behavioral data in order to maintain the functionality of the personalized digital program and enable users to track progress over time; (iii) legal, regulatory, accounting, or reporting obligations applicable to the Company; (iv) the need to maintain records for the purpose of resolving disputes, enforcing agreements, or establishing legal claims; and (v) technical, security, fraud-prevention, and service integrity requirements.
Retention periods of Apple Health (HealthKit) or Google Health Connect data are set by Apple or Google.
We take great care in implementing physical, technical, and administrative security measures for the website and services, that we believe comply with applicable regulation and industry standards to prevent your information from being accessed without the proper authorization, improperly used or disclosed, unlawfully destructed, or accidentally lost.
If you feel that your privacy was not dealt with properly or was dealt with in a way that was in breach of our Privacy Policy or if you become aware of a third party’s attempt to gain unauthorized access to any of your Personal Data, please contact us at our email.
Due to our global business operation, we may store or process your Personal Data in several territories, including, for example in Israel, the UK, EU, US or in other countries (whether directly or indirectly through the use of our vendors). Thus, your Personal Data may be transferred to and processed in countries other than the country from which you accessed our websites or otherwise the country of your jurisdiction. We will take appropriate measures to ensure that your Personal Data receives an adequate level of data protection upon its transfer in accordance with applicable law.
Further, when Personal Data collected within the EU is transferred outside the EU (and not to a recipient in a country that the European Commission has decided provides adequate protection) it shall be transferred under the provisions of the standard contractual clauses approved by the European Union. If you would like to understand more about these arrangements and your rights in connection therewith, please contact us at our email.
In addition, some of the third parties used for cookies management on our website may store and process data globally, including in the US (e.g., Google Analytics servers). When granting consent for such cookies, you hereby acknowledge and approve such cross-border transfer, in accordance with such third party’s privacy practices.
Data protection and privacy laws may grant you certain rights with regard to your Personal Data, all according to your jurisdiction. The rights may include one or all of the following: (i) request to amend your Personal Data we store; (ii) review and access your Personal Data that we hold; (iii) request to delete your Personal Data that we hold (as long as we do not have a legitimate reason for retaining the data); (iv) restrict or object to the processing of your Personal Data; (v) exercise your right of data portability (vi) contact to a supervisory authority in your jurisdiction and file a complaint; and (vii) withdraw your consent (to the extent applicable).
If you wish to submit a request to exercise your rights, please fill out the Data Subject Request Form (“DSR”) available here and send it to our email at: support@sweetch.com
When you contact us and request to exercise your rights regarding your Personal Data, we will require certain information from you in order to verify your identity and locate your data and that the process of locating and deleting the data may take reasonable time and effort, as required or permitted under applicable law. Data privacy and related laws in your jurisdiction may provide you with different or additional rights related to the data we collect from you, which may also apply.
In certain circumstances, and subject to applicable US Privacy Laws, you may permit an authorized agent to submit requests on your behalf. For more information, please refer to our DSR form.
Subject to applicable privacy law of your jurisdiction, you may have the right to lodge a complaint to the relevant privacy authority, including any EU Member State supervisory authority, if you are not satisfied with the way in which we handled the complaint.
Additionally, in accordance with applicable US Privacy Laws, if we decline to take action on your request, we will inform you within 45 days (Colorado residents) or 60 days (all other U.S. jurisdictions) of receipt. Our response will include a justification for the decision and an explanation about your right to lodge an appeal. If you wish to do so, please send your appeal request with a summary of the request and decision you want to appeal to: support@sweetch.com. We will respond to appeals within 45 days (one 15‑day extension possible where reasonably necessary).
If you are not satisfied with our response, you may have the right, depending on your jurisdiction, to lodge a complaint with your State Attorney General or other competent regulatory authority.
Our Privacy Policy only addresses the use and disclosure of Personal Data we collect from you. To the extent that you disclose your Personal Data to other parties via the website (e.g., by clicking on a link to any other website or location), different rules may apply to their use or disclosure of the Personal Data you disclose to them, and this Privacy Policy does not apply to any such third-party products and services. You agree that we shall have no liability whatsoever with respect to such third-party sites and your usage of them.
Our services are not directed nor intended for use by children, and we do not knowingly process, sell or share children’s information. Please contact us at: support@sweetch.com, if you have reason to believe that a child has shared any information with us.