Last updated: 2026-09-16
SweetTree Connect builds the technology platform behind SweetTree's home care services: in-home sensing, care and outcome monitoring, and the applications used by care teams and families. The people our platform serves are often vulnerable, and their information is health information — we treat the responsibility that follows as a design constraint, not a policy afterthought. This page sets out how we handle data, the controls we run, and the documents we can share. If something you need is not here, ask: every request below starts a direct conversation with us.
Care records are processed on behalf of the responsible care provider; for our own product data we act as controller. A records-of-processing and DPIA programme is in progress, and our privacy policy explains both roles in plain language.
Our core platform — database, application services, and device telemetry processing — runs in Google Cloud's London region (europe-west2).
Our public website sets no cookies and runs no analytics or advertising trackers — so it needs no consent banner. Our care applications contain no third-party advertising or analytics SDKs.
Where a certification is held, we show the certificate number and expiry and link the official register so you can verify it — not just our badge. Items marked Planned are on our assurance roadmap and will gain their evidence here as they complete.
On our assurance roadmap: we are scoping our Cyber Essentials certification with our leadership team ahead of a formal submission. This page will carry the certificate number and expiry when it is awarded — verifiable on the official register.
Official register →On our assurance roadmap: the NHS annual self-assessment that supports data sharing with NHS and local-authority partners. Once published, our status will be checkable on the official register alongside our ODS code.
Official register →Providers that process data on our behalf as part of running the platform.
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Core hosting — database, application services, analytics | London, UK (europe-west2) |
| Google Firebase | Identity (sign-in) and push notification delivery | Google global infrastructure |
| Apple | Push notification delivery to iOS devices (APNs) | Global |
| EMQX | IoT message broker for in-home device telemetry | — |
Requesting a document opens a tracked conversation with our team — a person replies, and where material is commercially sensitive we may ask for a confidentiality agreement first. Anything you need that is not listed: just ask.
The platform's core database and services run in Google Cloud's London region (europe-west2). Sign-in and push notifications use Google Firebase and Apple services, which run on those providers' global infrastructure.
No. The public website and this page set no cookies and load no analytics or advertising scripts.
No. We never sell personal data, and we never share it for advertising.
Use the request link on any document above, or email support@sweettreeconnect.com naming the document. Requests open a tracked conversation with us — we respond personally, and where a document is commercially sensitive we may ask for a confidentiality agreement before sharing.
Email support@sweettreeconnect.com with "SECURITY" in the subject line. Reports go straight to the engineering team and we will acknowledge promptly. Please do not include personal or sensitive data in the initial report.
If you believe you have found a security vulnerability in any SweetTree Connect service, email support@sweettreeconnect.com with "SECURITY" in the subject line and we will acknowledge promptly. We welcome good-faith reports and will work with you on a fix and on disclosure timing. Please do not access other people's data, degrade the service, or include personal or sensitive data in your report. A machine-readable contact is published at /.well-known/security.txt. We do not currently operate a bug bounty programme.