development — commands cannot reach a real pump CarbSnap
Last updated 21 August 2026

Privacy

CarbSnap sends carbohydrate, insulin and override commands to a Nightscout site you run, which forwards them to a Loop app you built. It is a thin, deliberately small piece of plumbing between an AI assistant and software you already operate. This page describes exactly what it keeps.

What CarbSnap stores

DataWhy
Your email address and name, from GoogleTo know who you are and who took an action
The first name you give the person you are managingSo the interface can say "Liam" rather than an id
Your Nightscout addressTo know where to send commands
Your Nightscout API secret and Loop one-time password keyRequired to send a command at all. Encrypted with AES-256-GCM before storage.
Your safety limitsTo refuse a command that exceeds them
A log of every command attempted, including refusalsSo you can see what happened. One-time passwords are redacted from it.
Food descriptions and carbohydrate amounts you logYour own record, and to eventually learn per-food absorption patterns

What CarbSnap does not store

Who else sees your data

Only the services required to make it work, and only what each needs:

ServiceWhat it receives
CloudflareHosting, database and network. All stored data lives here.
WorkOSSign-in. Your email address and name.
GoogleConfirms who you are when you sign in. Google is told you signed in to CarbSnap; it is not told anything about the person you manage.
Your own NightscoutThe commands you send, which is the entire point.
ResendOnly when email is enabled: your address, to deliver a confirmation link.
USDA FoodData Central and Open Food FactsThe food name you typed, e.g. "pepperoni pizza". No identity, no glucose, no dose.

Your data is never sold, and never shared with anyone else.

Who can see your care circle

Only you, and anyone you explicitly invite. An invited caregiver can log carbs, request a bolus and start an override, and must accept the medical disclaimer themselves — consent is never inherited from whoever set things up. Only the owner can change credentials, limits, or membership. Every action is recorded against the person who took it.

Security, and its honest limits

Deleting your data

Turning off remote commands in settings stops every assistant immediately without deleting anything. To have your account and all associated records removed, email jay.winters@clearjet.com. Deletion removes your stored credentials, care circle, audit log and food log.

Changes

If this page changes in a way that affects what is collected or who receives it, you will be asked to review it before continuing to use CarbSnap.

Back to CarbSnap · Terms