365CGM Privacy Policy
Last updated: September 6, 2026
This Privacy Policy covers the 365CGM.com website, the 365 CGM Android app (package name com.threesixtyfivecgm.penbridge), and its Wear OS watch app (together, "365CGM", "the service", or "the app"). It is operated by Prewitt Enterprises LLC, Miami Beach, Florida, USA ("we", "us"). Privacy questions and requests: support@365CGM.com.
1. Overview
365CGM is a data transfer, storage, and viewing utility for users of the Eversense CGM and the people they choose to share with. It is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. It has no understanding of, and makes no claim to the accuracy of, the data it transfers or displays, and it cannot provide medical advice, diagnosis, or treatment. Always consult a healthcare professional for medical advice, diagnosis, or treatment, and rely on your own device readings for medical decisions.
The service handles health information — glucose readings, insulin doses, and related records — and we treat all of it as sensitive. This Policy explains what we collect, how we use it, who it is shared with, how long we keep it, and how you can delete it.
2. Information we collect
Account and security information. Your email address; your password (stored only as a salted hash); authenticator-app and passkey credentials and recovery codes if you enable them; sign-in sessions; device tokens you create for the app and watch (stored hashed); read-only share-link tokens; and a security audit trail of sign-ins, sign-outs, and account changes that records the date and time, the IP address, and the browser or device type used.
Health and device data. Depending on which features you use:
- glucose readings, trend values, timestamps, and sensor/transmitter status from your Eversense CGM — retrieved from Senseonics' systems with your credentials, read directly from your transmitter over Bluetooth by the phone or watch app, or, in optional companion mode, read from the Eversense app's own on-phone notification;
- Eversense events imported with those readings: meals, exercise, health, insulin, and calibration events;
- insulin dose records from NovoPen pens (via NFC) and Medtronic InPen pens (via Bluetooth), and doses you enter by hand on the website, in the app, or on the watch;
- blood glucose readings from Ascensia CONTOUR NEXT ONE meters and blood glucose and ketone readings from Keto-Mojo GK+ meters (via Bluetooth), and readings you enter by hand;
- calibration records, medication lists and medication events, notes, target ranges, and alarm settings;
- if you use the Wear OS app and grant its Body sensors and Physical activity permissions: heart rate, step count, and activity state from the watch, including a live heart-rate stream while you have turned that on from the website.
Connected-service credentials. The Eversense (Senseonics) username and password you provide, and the address and API secret of any Nightscout server you configure. These are encrypted at rest with keys specific to your account and used only to retrieve or deliver your data. You can change or remove them at any time in Settings.
Device and app information. Serial numbers, identifiers, and Bluetooth addresses of the transmitter, meters, and pens you connect; their battery levels; the app and watch versions; your phone's make and model and an app-generated phone identifier (a one-way hash derived from the Android device ID, used to tell your phones apart); Bluetooth and network state; whether the Eversense app is installed on the phone and which version; and the watch model and battery level.
Operational and support information. Service logs, sync state, error details, and import progress needed to run the service securely and reliably; diagnostic logs you choose to send us; and support requests you send.
AI assistance. If you use the Ask AI or Help feature, the question you type and the data shown on your dashboard that is needed to answer it (see Section 4).
Cookies and browser storage. A session cookie to keep you signed in; browser storage for display preferences and a cached copy of your most recent reading so the dashboard paints quickly; and, if you enable web push, a push subscription for your browser. We do not use advertising or tracking cookies.
3. How we use information
We use information to:
- authenticate you and manage your account and sessions;
- retrieve, process, display, and synchronize glucose and related health data across the website, the app, and the watch;
- provide optional Nightscout delivery, sharing with people you authorize, and read-only share links;
- compute the figures the dashboard shows (time in range, trends, projections, calibration timing) and, if enabled, alarms and notifications;
- answer Ask AI and Help questions;
- operate, secure, monitor, debug, and improve the service, including login protections, rate limiting, and abuse prevention;
- respond to support requests; and
- comply with legal obligations and respond to lawful requests.
We do not use your information for advertising, and we do not build advertising or marketing profiles.
4. How information is shared
People you authorize. You control who sees your data. On your 365CGM.com account you can approve followers and other 365CGM users (including medical-provider accounts), and choose, feature by feature, whether each of them can see nothing, see only, or see and modify. A person you share with sees your glucose, events, and the records you have allowed on their own dashboard, and their alarm settings can run against your readings on our servers. You can narrow or cancel any grant at any time under Settings → Share → Permissions.
Read-only share links and the Nightscout-compatible feed. If you create a share link, anyone who has it can view the information it exposes until you disable it; if you enable the built-in Nightscout-compatible feed, anyone who has its Read URL and secret key can read your current glucose and trend until you disable it or change the key (Section 6).
Services you connect. With your credentials we retrieve your data from Senseonics' Eversense systems, and, if you configure one, we deliver your readings to the Nightscout server you specify. Those systems operate under their own terms and privacy practices: Senseonics' Privacy Notice is at https://www.eversensecgm.com/senseonics-privacy-notice and its Conditions of Use at https://www.eversensecgm.com/conditions-of-use. They may change, fail, be unavailable, rate-limit requests, or return incomplete information; we do not control them.
Service providers who process data for us. We use a small number of providers under contracts that limit them to providing their service to us:
- Cloudflare, Inc. — hosts and runs the service (compute, database storage, backup storage, outbound email, bot protection on sign-in forms, and the AI models behind Ask AI and Help);
- Google LLC — holds an encrypted copy of our daily backups in Google Drive; on Android, Google Play services carries data between the phone and the watch; Google's push service delivers web push notifications to Chrome;
- Anthropic, PBC — receives an Ask AI request only when you choose "Get a deeper answer";
- browser push services (Apple, Mozilla, Google) — deliver web push notifications to your browser; the message content is encrypted so the push service cannot read it.
When you use Ask AI or Help, your question and the dashboard data needed to answer it are sent to the AI model provider (Cloudflare Workers AI, or Anthropic for a deeper answer) solely to generate the answer; the request is not used to train their models under the terms we use them on.
Legal. We may disclose information when required by law or legal process, or to protect the rights, safety, and security of users, the public, or the service.
Never. We do not sell personal or health information, we do not share it with advertising networks, data brokers, or analytics providers, the app and website contain no advertising, and the app does not use an advertising identifier or any third-party analytics or tracking SDK.
5. The Android app and the Wear OS watch app
The app requires a 365CGM.com account and a device token to function. Its dashboard is the 365CGM.com website shown inside the app, so everything above applies to it.
What the app reads from your devices. Connecting to any device takes a step only you can perform: a Bluetooth device must be paired or selected by you, and an NFC pen must be physically tapped. With that step done, the app reads insulin dose records from NovoPen and InPen pens, blood glucose and ketone readings from CONTOUR NEXT ONE and Keto-Mojo GK+ meters, and glucose values and status from your Eversense transmitter. Only at your direction, the app or the watch can also send two things to the transmitter: a fingerstick calibration value you enter, and the transmitter's vibration (do-not-disturb) setting; it does not otherwise change the transmitter. These records may include device identifiers or serial numbers, timestamps, measurement values, insulin amounts, and battery status.
Optional companion mode (Eversense). If you turn on companion mode in the app's settings and grant Android "Notification access", the app reads the current glucose value and trend from the Eversense app's own on-phone notification and uploads it to your account like any other reading. This mode is off by default, reads only the Eversense glucose notification and nothing else, and can be turned off at any time.
What the app does with the data. It uploads these records over encrypted connections (HTTPS) to your 365CGM.com account and, only if you configure it, to a Nightscout server you specify. You can use automatic mode, in which new records upload in the background, or review mode, in which you approve each record first. It also sends periodic status reports (transmitter and device status, app version, battery, Bluetooth state) so the dashboard can show whether your devices are connected.
Data stored on your phone. The app stores your device token in Android's encrypted storage, which is the only credential it holds at rest; it is created from your account and can be revoked there at any time. It also keeps device pairings, capture preferences, a local diagnostics log, and a cache of recent readings on the phone. Android's cloud backup of the app's data is disabled. Uninstalling the app removes all of this from the phone.
Background operation. To capture readings while the app is not on screen, the app runs a foreground service that maintains the Bluetooth or NFC connection to the devices you have opted in. Android shows a notification while it runs. You can stop it at any time; if you have opted at least one device into background capture, the service restarts after a reboot or app update.
The Wear OS watch app. The watch shows your current glucose and trend on the watch face, in a tile, and in the watch app, and lets you log doses from the wrist. It receives readings from the phone over the phone–watch connection, and it can also work on its own: with its own device token it talks to 365CGM.com directly, and if you pair your transmitter to the watch it can read the transmitter over Bluetooth when the phone is out of reach. If you grant the watch's Body sensors and Physical activity permissions, it collects heart rate, step count, and activity state and sends them to your account through the phone, where they appear on your dashboard; a live heart-rate stream runs only while you have started it from the website. Denying those permissions turns this feature off entirely. The watch stores its device token in the watch's encrypted storage.
Permissions the phone app uses, each only for the function named:
- Bluetooth (scan and connect) — to connect to your transmitter, meters, and pens. Scanning is declared with Android's
neverForLocationflag; the app does not derive or use location from it. - NFC — to read NovoPen pens by tap.
- Camera — only to scan the pairing QR code shown on the 365CGM.com Device tokens card. Images are processed on the phone and are never stored or uploaded.
- Notifications — to show the required notice while the capture service runs, and your glucose alarms if you enable them.
- Network access — to reach your 365CGM.com account and any Nightscout server you configure.
- Foreground service (connected device) — to keep a device connection alive while capturing in the background.
- Run at startup — only to restart background capture after a reboot or app update, and only when you have opted a device into it.
- Alarms and reminders (exact alarms) — so a deferred calibration fires at the time you chose.
- Display over other apps (optional) — only if you turn on the floating glucose bubble.
- Set wallpaper (optional) — only if you turn on the lock-screen glucose display, which draws your reading onto a copy of your lock-screen wallpaper and restores the original when you turn it off.
- Notification access (optional) — only if you enable companion mode, to read the Eversense app's glucose notification as described above.
Permissions the watch app uses: Body sensors (heart rate) and Physical activity (steps and activity state) — both optional and requested from you on the watch; Bluetooth (the transmitter); Notifications; Network access; Foreground service (connected device); Run at startup; and Alarms and reminders (the transmitter read schedule).
The app does not request or use location, contacts, calendar, photos or media, SMS, call logs, or the microphone, and it does not use an advertising identifier.
6. Read-only share links
A share link (Settings → Share → "Copy share link") opens a read-only, limited view of your dashboard without a login. You are responsible for deciding whether to share it and with whom: anyone with the link can view the information it exposes until it is disabled, because the page is not password-protected. You can stop the link at any time with "Disable link" on the same card; it stops working at the next page refresh. Copying a new link generates a new, unique link and retires the old one.
A share-link page shows health information — glucose and event data from your CGM. Before sharing a link, consider whether the recipient should have access to that information.
The built-in Nightscout-compatible feed (Settings → Nightscout → Local Nightscout Server) publishes your current glucose value and trend to a relay we operate at nightscout.365cgm.com, so that xDrip+, Nightscout clocks and similar readers can show it. It is off by default. While it is on, anyone who has its Read URL and secret key can read that feed; you can change the key at any time and turn the feed off.
7. Security
We use technical and organizational measures designed to protect the service and the information it stores:
- all traffic between your browser, the app, the watch, and 365CGM.com is encrypted in transit (HTTPS/TLS);
- passwords are stored only as salted hashes; device tokens and recovery codes are stored hashed; connected-service credentials are encrypted at rest with keys specific to your account;
- you can protect your account with an authenticator app, passkeys, and recovery codes, and see your sign-in history;
- backups are encrypted before they are stored;
- access to systems and data is restricted and logged, and sign-in forms are protected against automated abuse.
No system can guarantee perfect security, and you use the service with that understanding. If you believe your account has been compromised, revoke your device tokens and change your password in Settings, and contact support@365CGM.com.
8. Retention
- Your health records (readings, events, doses, blood glucose and ketone values, calibrations, notes, medications) are kept for as long as your account exists, so that your history is complete. You can delete individual records you entered, and you can delete your account (Section 9).
- Operational service logs on your account are kept for about 7 days.
- Sign-in and security audit records are kept for as long as they are needed for security and abuse prevention, which may extend beyond the deletion of your account.
- Backups are taken daily and kept for about 30 days; deleted data leaves the backups when those copies expire.
- Sessions expire on their own or when you sign out; device tokens and share links last until you revoke them.
- Connected-service credentials are kept until you remove them or delete your account.
9. Deleting your data and your account
You can delete your account from inside the app or on the website: Settings → Account → Delete account, then type DELETE to confirm. You can also ask us to delete it by emailing support@365CGM.com from the email address on the account.
Deleting your account permanently removes the account and its sessions, every reading, event, calibration, and record stored for it, your passkeys and authenticator setup, your device tokens, and your share links. Copies of your data that other users received through sharing are removed from their accounts when you cancel their access, so cancel any sharing you no longer want before deleting. Deleted data leaves our backups within about 30 days. Security audit records may be retained as described in Section 8.
Uninstalling the app or the watch app removes the device token and the data stored on that device, but does not delete your account.
10. Your choices and rights
You can, at any time: disconnect Eversense or Nightscout; revoke device tokens; disable share links and the Nightscout-compatible feed; change or cancel what each follower or grantee can see; turn companion mode, background capture, the watch's health permissions, and the display surfaces off; stop using the service; and delete your account.
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to complain to a supervisory authority. You can exercise most of these directly in the product; for anything else, contact support@365CGM.com and we will respond within the time the applicable law allows. We do not sell personal information and do not discriminate against you for exercising your rights.
You remain responsible for the settings and data you choose to connect and share.
11. Children
365CGM is not directed to children under 13, and we do not knowingly create accounts for them; under our Terms of Service an account holder must be at least 18. A parent or legal guardian may use their own account to manage a child's CGM data, and is responsible for that use and for any sharing they set up. If you believe a child has created an account, contact support@365CGM.com and we will delete it.
12. Medical disclaimer, HIPAA, and regulated healthcare status
365CGM is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Consult a healthcare professional for medical advice, diagnosis, or treatment, and rely on your own device readings for medical decisions. The service requires the external hardware and accounts it connects to (an Eversense CGM system and, optionally, supported meters and pens) and cannot function without them.
365CGM handles sensitive health information, but as a transfer and services utility it is not represented as a HIPAA-covered entity, business associate, or provider of Business Associate Agreements. Do not assume HIPAA rights, regulated healthcare obligations, or clinical service guarantees apply unless we expressly say so in a separate written agreement.
NovoPen, InPen, Ascensia, CONTOUR, Eversense, Senseonics, Nightscout, Keto-Mojo, Android, and Wear OS are trademarks of their respective owners. 365CGM is an independent service and is not affiliated with, endorsed by, or sponsored by those companies.
13. International use, data location, and the GDPR
Where your data is. 365CGM is operated by Prewitt Enterprises LLC from the United States and runs on Cloudflare's global network, which spans data centers in more than 300 cities worldwide (https://www.cloudflare.com/network/). Your account's records are held in Cloudflare's storage in the data center Cloudflare selected when your account was first used — for accounts created in the United States, the United States. Daily backup copies are stored in Cloudflare storage in the United States and, encrypted, in Google Drive.
Cloudflare's edge servers, metadata, and logs. For core services such as the content delivery network and security proxies, data mostly transits, and is cached temporarily on, Cloudflare's global edge servers located in data centers worldwide. Metadata and event logs about network activity are processed and stored in Cloudflare's core facilities located in the United States and Europe. Cloudflare describes this in its GDPR overview (https://www.cloudflare.com/trust-hub/gdpr/), its privacy policy (https://www.cloudflare.com/privacypolicy/), and its Data Localization Suite (https://www.cloudflare.com/data-localization/).
Transfers. If you use the service from outside the United States, your information is transferred to and processed in the United States and in the other locations described above, where privacy protections may differ from those where you live. Our service providers (Section 4) offer data-processing terms that include the European Commission's Standard Contractual Clauses; Cloudflare and Google are also certified under the EU-U.S. Data Privacy Framework, its UK extension, and the Swiss-U.S. Data Privacy Framework.
GDPR and data localization. If you are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR (or the UK GDPR or the Swiss FADP) applies to our processing of your personal data: Prewitt Enterprises LLC is the controller, and our service providers act as processors on our instructions. We process your account data to provide the service you signed up for, your health data on the basis of the explicit consent you give by connecting your CGM data and turning features on (withdrawable at any time by disconnecting, turning the feature off, or deleting your account — Section 9), and security and audit data on the basis of our legitimate interest in keeping the service safe (Section 7). Where the law requires it, your data can be localized: Cloudflare's jurisdiction controls allow an account's stored records to be confined to a specific region, such as the European Union — contact support@365CGM.com to arrange this. You have the rights described in Section 10, including the right to lodge a complaint with your supervisory authority.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The date at the top shows when it last changed. If we publish a new legal release, you may be required to review and accept the updated Policy before continuing to use the service.
15. Contact
Prewitt Enterprises LLC, Miami Beach, Florida, USA. For privacy questions, concerns, or requests, including requests to access or delete your information, email support@365CGM.com.