Effective Date: August 16, 2026
This Privacy Policy describes how GlucoHarmony ("the App") handles your personal health information. Please read it carefully.
Who can see your data
- The app developer can see only your email address (and name, if you provide one). The developer cannot open or read your health data — glucose readings, logs, insulin doses, notes, or any other entries you record.
- No user can see anything about another user. Every account is isolated by per-user row-level security. Your health records are visible only to you, and only on your own account.
- The only exception is access you explicitly grant to a care-team member through the Sharing feature, which you control and can revoke at any time (see section 6).
1. What the App Collects
- Account information: your name and email address (used for login only). The developer can see your email address but cannot access your health data.
- Health data you enter: glucose readings, insulin doses, food logs, exercise entries, sleep, wellness check-ins, weight, and related health metrics.
- CGM data: if you connect a FreeStyle Libre or compatible device, glucose readings are imported via LibreLinkUp.
- Usage data: basic app interactions to help improve the experience (no personally identifiable usage data is shared with third parties).
2. How the App Uses Your Data
- To display your health data back to you within the app.
- To generate AI-powered insights, patterns, and suggestions personalized to your logged data.
- To calculate statistics such as Time in Range, estimated A1C, and other glycemic metrics.
- The App does NOT sell, share, or monetize your health data with any third party.
- The App does NOT use your data for advertising purposes.
3. Data Storage, Encryption & User Isolation
- Your data is stored securely using Base44's encrypted cloud infrastructure.
- All data is transmitted over HTTPS/TLS encryption.
- Your LibreView password (if you connect a CGM) is encrypted before it is stored and is never held in plaintext. The encrypted credential is used only to run syncs on your behalf.
- User isolation: every health record is scoped to your account through per-user row-level security. No other user can read, edit, or delete your data, and you cannot see any other user's data. The app developer likewise cannot read your health records — only your email address is visible to the developer.
4. Audit Trail & Tamper-Evident Records
- Sensitive actions on your account are recorded in a tamper-evident Activity & Security Log. This includes reports generated, data exported, sharing changes (granted, updated, paused, resumed, or revoked), bulk glucose deletions, LibreView credential changes, and account-deletion requests.
- Audit entries are created automatically and cannot be edited or removed by you. Only an administrator can modify audit records, and only for legitimate platform maintenance — never to hide a user action.
- You can view your own Activity & Security Log at any time from Settings → Account → "Activity & Security Log".
- Every report the App generates (provider reports, care-team emails) is stamped with a SHA-256 integrity hash — a unique fingerprint of that report's exact content at the moment it was created. The hash is stored on your behalf so that you, or a recipient you shared it with, can later confirm the report has not been altered.
5. Data Retention & Deletion
- Retention: the App retains your health data only for as long as your account is active. No data is kept after you delete it.
- Automatic deletion: you can permanently delete ALL of your health data at any time from Settings → Account → "Delete Account & All Data". This removes every glucose reading, daily summary, food log, insulin dose, wellness entry, journal entry, medication, hypo event, experiment, challenge, badge, sharing permission, and all other tracked data. The deletion is immediate and irreversible.
- Account identity deletion: the in-app "Delete Account & All Data" button also submits a formal request to delete your account identity (name and email). This request is fulfilled by the developer within 30 days — no email required. Your health data is erased immediately and your account identity follows within 30 days.
- Export: you can export your data at any time from the Insights section before deleting. Each export is itself recorded in your Activity & Security Log.
6. Sharing With Your Care Team
- The Sharing feature lets you grant a caregiver or healthcare provider limited, specific access to your data. You choose exactly what they can see (for example glucose, meals, or insulin) and whether they can receive alerts.
- Sharing is always your choice. No one is granted access unless you explicitly add them, and you can pause, edit, or fully revoke any access at any time — instantly.
- Every sharing change (grant, update, pause, resume, revoke) is recorded in your Activity & Security Log.
- Care-team reports sent by email are stamped with an integrity hash so the recipient can confirm the report is genuine and unaltered.
7. AI-Generated Content
- The App uses AI (large language models) to analyze your logged data and generate insights.
- AI analysis is processed in a privacy-preserving way — only the data relevant to your specific query is sent.
- AI suggestions are for informational purposes only and do not constitute medical advice.
8. Third-Party Services
- LibreLinkUp / LibreView (Abbott): if you choose to connect your CGM, your login credentials are used only to fetch your glucose data. Your password is encrypted before storage and is never held in plaintext.
- Google Fit: optional integration to import step and activity data. Uses OAuth — the App never sees your Google password.
- Base44: the underlying app platform. Subject to Base44's own privacy policy.
9. Children's Privacy
- This App is not intended for use by children under 13. The App does not knowingly collect data from minors.
10. Not a Medical Device & No Guarantee of Alerts
- GlucoHarmony is a personal logging and tracking tool. It is NOT a certified medical device and does not provide medical advice, diagnosis, or treatment.
- All insulin dose calculations, glucose predictions, and AI suggestions are mathematical estimates based on your logged data and models — not medical advice. Always consult your healthcare team before making insulin or treatment decisions.
- Glucose threshold alerts and critical-glucose emails are informational only. GlucoHarmony is NOT a medical alerting or safety system. Alerts may be delayed or not delivered if the app is closed, your phone is off, a sync fails, or the email is missed. Never rely on GlucoHarmony as your only safety system for hypoglycemia or hyperglycemia emergencies.
- In an emergency, follow your own care plan and contact emergency services directly.
11. Your Rights
- Access: you can view all your data within the App at any time.
- Deletion: permanently delete all your health data AND request account-identity deletion instantly via Settings → Account → "Delete Account & All Data". The account identity is removed within 30 days of the request.
- Correction: you can edit or delete any logged entry directly in the App.
- Export: data export features are available in the Insights section.
- Audit access: view a tamper-evident record of every sensitive action on your account from Settings → Account → "Activity & Security Log".
12. Beta Notice
- This is a beta version of the App. Features and data handling practices may change.
- As a beta tester, you acknowledge that the App is under active development.
- You will be notified of any material changes to this Privacy Policy.
13. Contact
- For privacy questions, data deletion requests, or concerns, contact: glucoharmonyapp@gmail.com
GlucoHarmony — Personal Diabetes Management Tool
Not a certified medical device. For personal tracking purposes only.
← Back to App