Legal

Privacy Policy

Your health data is sensitive. This policy explains what GlucoScan collects, how it is stored, how it is shared with AI and payment providers, and how you can control or delete it.

What data GlucoScan collects

GlucoScan collects and stores the information you enter about your diabetes — glucose readings (including photos of meters used for OCR), meal logs (including photos used for AI carbohydrate estimates), insulin calculations, profile settings, and any messages you send us through the Contact form.

We also store basic account information such as your name, email, date of birth, and – if you provide it – your phone number.

If you join our waitlist, we store the email address you submit until you delete it or we open public access.

HIPAA and health-data compliance

GlucoScan is an informational consumer app, not a covered entity or business associate under the U.S. Health Insurance Portability and Accountability Act (HIPAA). We do not act as your healthcare provider, insurer, or clearinghouse. As such, GlucoScan itself is not "HIPAA-compliant" and does not operate under a Business Associate Agreement.

That said, we follow privacy-first engineering principles — your health data is isolated per account using row-level security, never sold, and never used for advertising.

How health data is stored and isolated

Your glucose readings, meal logs, and insulin calculations are tied to your account using row-level security. Other users cannot read or edit your health data. Only the account you have authenticated with and the workspace admin of this GlucoScan deployment may access your individual records. Admins see aggregated or account-level data only for application maintenance and support.

How we use your data

Your data is used to: (1) display your history, charts, insights, and reports inside the app, (2) compute suggested insulin doses based on your inputs, and (3) provide support if you contact us. We do not sell your health data. We do not share your health data with advertising providers.

AI processing of your photos and third-party processors

When you upload a photo of a glucose meter or a meal, the image and a small amount of context are sent to a third-party AI model (currently Google Gemini via the platform's InvokeLLM integration) to produce an estimate (a glucose value or a carbohydrate breakdown). The model provider may temporarily process the image to return the result.

We choose providers that, to the best of our knowledge, do not use your image content to train their models; we cannot, however, guarantee the provider's retention or training practices, so if you would prefer not to upload an image you may always enter values manually.

Your photos are stored as files attached to your own logs unless you delete them. Other third-party processors include our hosting platform (Base44) and, when billing is enabled, our payment processor — the processor sees only the transaction data needed to charge your card, not your health records.

Waitlist data

If you join our waitlist we store your email (and optional name) so we can notify you when early access opens. We do not sell or rent your email. You may request removal from the waitlist at any time by contacting us through the Contact page.

Payment and billing data

When paid plans are available, payment is processed by our payment processor (e.g. Stripe, or Apple's / Google's in-app purchase system on iOS and Android). The processor handles your card or store-account details — GlucoScan does not store full card numbers. We retain a record of your subscription plan, purchase date, renewal date, and processor-generated transaction and receipt identifiers so we can manage access and tax records.

Sharing with your care team

GlucoScan can produce PDF reports you may choose to share with your doctor or diabetes care team. You are in control of when and with whom you share these reports; GlucoScan does not transmit them to any third party on your behalf.

Data retention

Your health data is retained for as long as your account is active. You can delete individual logs at any time. Waitlist data is retained until removed or until early access has fully opened, whichever is sooner. Backup copies may persist for up to 30 days following a deletion as part of our standard disaster-recovery process.

Deletion of your account and data

You can delete individual logs at any time, and you can permanently delete your account and most associated data from the Profile page; deletion cannot be undone. The in-app "Delete account" flow removes your glucose readings, meal logs, insulin calculations, and reports, and signs you out.

If you would like your waitlist entry, your account record, or any remaining backups removed as well, contact us through the Contact page with the subject "Deletion request" and we will action it within 30 days.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data. To exercise these rights, use the data-deletion controls in the app or contact us through the Contact page.

Children and young people

GlucoScan is not intended for use by children without the supervision of a parent, guardian, or diabetes care team. If you are a parent or guardian and believe your child has provided information without your consent, please contact us so we can delete it.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the page and the "Last updated" date. Continued use after changes constitutes acceptance.

Contact

If you have any questions about your privacy or this policy, please reach out through the Contact page.

Last updated: 8/29/2026