Privacy Policy
Last Updated: 11 April 2026
GlycoTrace ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your health and personal data when you use the GlycoTrace mobile application ("the App").
GlycoTrace is operated from the United Kingdom. Our processing of personal data is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where users are located in the European Economic Area (EEA), EU GDPR also applies.
1. Data We Collect
1.1 Data You Provide
- Account Information: Email address (collected via Supabase Auth at sign-up).
- Health Data (Special Category): Blood glucose readings (manual entry or imported via LibreLink), food intake (calories, carbohydrates, protein, fat), insulin dosages (rapid-acting and long-acting, recorded separately), body weight, and exercise activity (type, duration, intensity).
- Health Goals: User-configured targets for time in range, post-meal glucose, CV%, and weight management.
- Preferences: Notification settings, fasting style, display preferences.
1.2 Data Collected Automatically
- Device Data: Operating system version, device model, and app version for debugging and performance monitoring.
- Advertising Identifiers: Google Advertising ID, collected by Google AdMob for serving personalised or non-personalised ads (see Section 5).
- Crash and Performance Data: Anonymous crash reports to improve app stability.
1.3 Device Permissions
- Camera: Used only when you choose to scan a food barcode. The camera feed is processed on-device; no images are stored or transmitted.
- Microphone: Used only when you tap the voice logging button. Audio is sent to our AI service solely to parse your spoken meal description into nutritional data; it is not stored.
- We do not collect your name, address, phone number, or date of birth.
- We do not access your device contacts or location.
2. Legal Basis for Processing
| Processing Activity | Legal Basis (UK GDPR) |
|---|---|
| Core app functionality (storing and analysing your health data) | Explicit consent (Article 9(2)(a)): provided when you create an account and begin logging health data |
| AI-powered insights (Glycoflow AI chat) | Explicit consent: you choose to use the AI feature; anonymised data only |
| LibreLink glucose import | Explicit consent: you initiate the connection in Settings |
| Advertising (AdMob) | Legitimate interest (free tier) / consent for personalised ads |
| Subscription management (RevenueCat) | Contract performance (Article 6(1)(b)) |
| Anonymised research data (see Section 7) | Explicit opt-in consent (Article 9(2)(a)) |
3. How We Use Your Data
Your data is used to provide the core functionality of the App:
- Generating metabolic insights: time in range, glycaemic variability (CV%), estimated HbA1c (GMI), post-meal glucose response, and insulin sensitivity (observed drop).
- Tracking fasting state and metabolic phase transitions.
- Producing monthly PDF health reports (generated on-device, not uploaded).
- Providing AI-powered dietary and exercise context via the Glycoflow AI chat.
- Sending local notifications for glucose checks, fasting alerts, and medication reminders.
- Displaying advertisements to free-tier users.
We do not sell your health data to third parties. Your individual health records are never shared with advertisers, data brokers, or any commercial third party.
4. Data Storage and Security
4.1 Where Your Data Is Stored
Your data is stored securely using Supabase (cloud infrastructure). Supabase utilises industry-standard encryption (AES-256 at rest, TLS 1.2+ in transit) and PostgreSQL Row Level Security (RLS) to ensure that only your authenticated account can access your records.
4.2 Security Measures
- Row Level Security (RLS): Database policies enforce that each user can only read/write their own data.
- No secrets in the app: API keys for AI and external services are stored as server-side secrets, never bundled in the app binary.
- Biometric authentication: Optional fingerprint/face unlock protects app access on-device.
- LibreLink credentials: Your LibreLink bearer token is stored server-side only and never sent to the client device.
4.3 Data Retention
- Active accounts: Your data is retained for as long as your account is active.
- Deleted accounts: When you delete your account (Settings → Delete My Account & Data), all your data is permanently and irreversibly removed from our servers within 24 hours. There is no recovery period.
- Inactive accounts: Accounts with no activity for 24 months may be flagged for deletion. We will attempt to notify you by email before any action is taken.
5. Third-Party Services
| Service | Purpose | Data Shared | Policy |
|---|---|---|---|
| Supabase | Authentication, database, Edge Functions | Email, all health data (encrypted, RLS-protected) | Link |
| Groq | AI chat analysis (Glycoflow AI) | Anonymised metabolic summaries only. No PII. | Link |
| Google AdMob | Ads for free-tier users | Device advertising ID, ad interaction data. No health data. | Link |
| RevenueCat | Subscription management | Anonymous user ID, purchase receipts. No health data. | Link |
| LibreLink Up | CGM glucose import (user-initiated) | Credentials sent to Abbott API via server-side Edge Function | Link |
| Google ML Kit | On-device text recognition | None : all processing runs locally | Link |
| OpenFoodFacts | Food database searches | Search queries only. No user identifiers. | Link |
6. Your Rights
Under the UK GDPR and EU GDPR, you have the following rights:
- Access (Article 15): You can view all your data within the App at any time. You may also request a copy by contacting us.
- Portability (Article 20): You can export your data as a PDF health report from within the App.
- Rectification (Article 16): You can edit or correct any health entry directly in the App.
- Erasure (Article 17): You can permanently delete all your data using the "Delete My Account & Data" button in Settings. This is instant and irreversible.
- Restrict Processing (Article 18): You can stop using specific features (e.g., AI chat, LibreLink sync) without deleting your account.
- Withdraw Consent (Article 7(3)): You may withdraw consent at any time by deleting your account. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Object (Article 21): You may object to processing based on legitimate interest (e.g., advertising) by contacting us.
- Complaint: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
7. Research and Academic Partnerships
This section applies only if you explicitly opt in. No data is shared for research purposes without your separate, informed consent.
GlycoTrace may partner with universities, NHS trusts, or other scientific research bodies to advance understanding of glucose management, nutrition, and metabolic health.
7.1 What May Be Shared
- Anonymised, aggregated data only. Individual-level health records are never shared with research partners unless you provide explicit, separate written consent for a specific study.
- Aggregated data means statistical summaries (e.g., "average TIR across 500 users aged 30-40") that cannot identify any individual.
- Anonymisation follows the ICO Anonymisation Code of Practice and is irreversible : re-identification is not possible.
7.2 Safeguards
- All research partnerships require approval from an accredited Research Ethics Committee (REC) or equivalent institutional review board.
- A Data Processing Agreement (DPA) will be in place with any research partner before any data is shared.
- Research partners may not attempt to re-identify individuals, combine data with other datasets for identification purposes, or use data for commercial purposes.
- Any published research will use aggregated statistics only and will not identify individual users.
7.3 Your Control
- Participation in any research programme is entirely voluntary and requires separate opt-in consent within the App.
- You may withdraw your research consent at any time without affecting your use of the App.
- If you withdraw, your data will be excluded from any future analyses. Data already included in published, anonymised, aggregated results cannot be retrospectively removed (as it is no longer identifiable).
8. Children's Privacy
GlycoTrace is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
8a. GlucoEnzyme Data Handling
For users of the **GlucoEnzyme** app, the following specific data handling practices apply:
- All health data (glucose, food, insulin, enzyme logs) is stored locally on your device only and is never uploaded to our servers or any cloud service.
- Anonymous usage analytics: Only install ID, event type, and timestamp are collected. No health values or personally identifiable information are included in these analytics.
- AdMob Integration: Google AdMob may collect device identifiers for ad personalization. This is managed by Google in accordance with their privacy policy (Link).
9. International Data Transfers
Your data may be processed in countries outside the UK/EEA where our third-party providers operate (e.g., Supabase infrastructure, Groq AI). Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent protections as required by UK GDPR.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via an in-app notification. The "Last Updated" date at the top of this page reflects the most recent revision.
11. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or need to report a data concern:
- Email: privacy@glycotrace.co.uk
- Website: glycotrace.co.uk
- Supervisory Authority: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, SK9 5AF : ico.org.uk