Privacy Policy

Last updated: April 28, 2026

Diabetes Simulations ("we", "us", "our") operates FlightGlucose at diabetessimulations.com. This policy explains what data we collect, how we use it, and your rights.

1. The Free Tier Collects No Personal Data

The free game runs entirely in your browser. We do not require an account, and we do not collect or transmit any health data, glucose values, insulin doses, or game outcomes to our servers. Your gameplay stays on your device.

2. Analytics

We use Google Analytics to understand aggregated traffic patterns (page views, country, device type). Analytics cookies are disabled by default for visitors who send a Do-Not-Track signal or who opt out via browser settings. Analytics data is anonymised at the IP level and is never linked to individual identity.

3. Payment Data — Handled by Stripe

When you subscribe or tip, payment is processed by Stripe Inc. Your card details, billing address, and payment history are collected and stored by Stripe under their Privacy Policy. We never see or store your full card number.

From Stripe we receive: your email address, the product purchased, the amount, the country code, and a Stripe customer ID. We use this to send receipts, deliver subscription access, and provide customer support.

4. Email Communications

If you join a waitlist or contact support, we store your email address solely to reply. We do not send marketing emails. We do not sell or share email addresses with third parties.

5. Cookies

6. Children

FlightGlucose is suitable for children learning about diabetes, but the paid tiers are not intended for unsupervised purchase by minors. Parents and educators are responsible for any subscription transactions.

7. Your Rights

Depending on your jurisdiction (GDPR, CCPA, etc.), you may have rights to access, correct, delete, or port the personal data we hold about you. To exercise these rights, email hello@diabetessimulations.com. We will respond within 30 days.

8. Data Retention

Subscription records (via Stripe) are retained as long as required by tax and accounting law. Email correspondence is kept for up to 24 months unless you ask us to delete sooner. Analytics data is retained per Google's default retention (currently 14 months).

9. Security

The site is served over HTTPS. Payment data is encrypted in transit and processed by Stripe, which is PCI-DSS Level 1 certified. We have no access to raw card information.

10. International Transfers

Stripe and Google may process data in the United States or other regions. They participate in standard contractual clauses and data-transfer mechanisms required under GDPR.

11. Changes

If we materially change this policy, we will update the "Last updated" date and, where required, notify you by email or banner.

12. Contact

Questions about privacy? Email hello@diabetessimulations.com.