Privacy Policy

Effective date: March 10, 2026  ·  Last updated: March 10, 2026

1. Overview

GlucoSensei ("we", "our", "us") is a personal health tool that helps you understand how food affects your blood glucose. This Privacy Policy explains what information we collect, how we use it, and your rights with respect to that information.

By creating an account or using GlucoSensei, you agree to the practices described in this policy. If you do not agree, please do not use the service.

2. Information We Collect

2a. Account Information

When you create an account, we collect your name and email address. Your password is hashed and never stored in plain text. We do not collect payment information directly. Any billing is handled by our third-party payment processor.

2b. Health & Wellness Data

To provide the core functionality of the app, we collect health-related data that you voluntarily enter, including:

  • Diabetes type and diagnosis year
  • Glucose target range preferences
  • Blood glucose readings (value, timestamp, source)
  • Food and meal logs (description, macronutrients, meal type, timestamp)
  • Meal photos (only when you choose to use the photo analysis feature)
  • CGM device preference (for simulation purposes; no real device data is accessed in v1.0)

2c. Usage & Technical Data

We may collect standard server logs (IP address, browser type, pages visited, timestamps) for security, debugging, and performance purposes. This data is not linked to your health data and is retained for up to 90 days.

3. How We Use Your Information

  • To provide, operate, and improve the GlucoSensei service
  • To generate AI-powered insights and glucose predictions personalized to your data
  • To send meal reminder notifications (only if you enable them)
  • To authenticate your account and maintain session security
  • To respond to your support requests or inquiries
  • To detect and prevent fraud, abuse, and security incidents

We do not sell your personal data. We do not use your health data for advertising.

4. AI Analysis & Third-Party Services

GlucoSensei uses the Anthropic Claude APIto analyze meal photos and generate insights. When you use these features, the following data is transmitted to Anthropic's servers:

  • Photo analysis: the base64-encoded meal image you capture or upload. No name, email, or account identifiers are included.
  • Insight generation: aggregated meal and glucose summary statistics (no raw photos, no name, no email).
  • Glucose prediction: food name and macro values you enter, along with anonymized historical meal patterns.

Anthropic processes this data under their own Privacy Policy. We do not permit Anthropic to use your data to train their models under our enterprise API agreement.

We use Supabaseas our database provider. Your data is stored in a PostgreSQL database hosted on Supabase's infrastructure (AWS us-east-2). Supabase applies encryption at rest and in transit.

5. Data Storage & Security

Your data is stored in a secure PostgreSQL database. We use the following protections:

  • All connections use TLS/SSL encryption in transit
  • Passwords are hashed using a strong one-way algorithm (bcrypt)
  • Session tokens are signed and short-lived
  • API routes are rate-limited to prevent abuse
  • All data access is scoped to the authenticated user (no cross-account access)

No security system is perfect. In the event of a data breach that affects your personal data, we will notify you as required by applicable law.

6. Data Retention

We retain your account and health data for as long as your account is active. You may delete all your logged data (glucose readings and food logs) at any time from Settings → Your Data → Clear All Data. This action is irreversible and removes all health data immediately.

To delete your account entirely (including your email and name), please contact us at privacy@glucosensei.com. We will process your request within 30 days.

7. Coach Data Sharing (Optional)

GlucoSensei offers an optional feature that allows you to share your glucose readings and food logs with a designated health coach. This feature is off by default and requires your explicit opt-in from Settings.

When enabled, your coach can view your logged data in read-only mode. You can revoke this access at any time by disabling the toggle in Settings. No data is shared without your active consent.

8. Children's Privacy

GlucoSensei is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child under 18 has provided us with personal information, we will delete it promptly.

9. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Data portability (receive a copy of your data in a structured format)

To exercise any of these rights, contact us at privacy@glucosensei.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and notify you via email or an in-app notice. Your continued use of GlucoSensei after changes are posted constitutes your acceptance of the updated policy.

11. Contact Us

If you have questions or concerns about this Privacy Policy or how your data is handled, please contact us at:

GlucoSensei
Email: privacy@glucosensei.com