I'm bet they probably do collect e.g. your phone's operating system and use that to figure out which market segment you belong to. But as far as I know Dexcom doesn't have any agreements with anyone to sell their user's data; If they have ads in the dex app I've never seen one. I would be extremely surprised if that were the case.
>You can ask us not to use or share certain protected health information for treatment, payment, or our operations. We are not required to agree to your request
What they're talking about here isn't necessarily what you expect. It's that, if you e.g. encounter a bug in the product that they need to disclose to the FDA, you cannot withhold information from them that would prevent them from doing that. Or, if they need to know what kind of diabetes you have so that they can charge your insurance for the correct prescription, you can't say "you're not allowed to share that." (doesn't really apply here, but that's kind of what's meant in that clause). You can see: treatment, payment, or operations. The scope of each of those is kept as small as possible, and they do have audits from time to time ensuring that it is.
I assure you that CGM readings, trends, averages, reports, etc. ALL of that stuff is absolutely, positively considered PHI and considered extremely privileged. The only time anyone, even in the company, can see that data is if they are a customer support agent helping a specific customer, or if they are on the data science team looking at broad trends to help e.g. calibrate the product.
>Once a year you can also request that they send you a report on who they shared your data with and why without paying them for it, but it will not include anything involving "treatment, payment, and health care operations, and certain other disclosures (such as any you asked us to make)."
It's because they have extra requirements around storage, retention, etc of that PHI data. It's very likely that they can't send you a report because all parties have much stricter access controls on that data so it can't be aggregated and put in a report without filing a mountain of paperwork.
I assure you, these companies do not fuck around with patient data. They don't even do things that give off the appearance of fucking around with patient data, because they know that if the HHS thinks that they are that's millions of dollars in audit costs.