Privacy Policy
Effective Date: August 25, 2026
1. Introduction
GlycoLens (“we,” “our,” or “us”) is committed to protecting your privacy and handling your data with transparency. This Privacy Policy details our data practices across our website and mobile application, explaining what information we collect, how it is processed, and the controls you have over your data under applicable data privacy frameworks, including the General Data Protection Regulation (GDPR) and the Protection of Personal Information Act (POPIA).
2. Data We Process
To provide nutritional insights and manage your account, we process the following categories of data:
A. Account & Authentication Data
Name, email address, authentication credentials, and session tokens managed via our authentication provider.
B. Nutritional Scans & Food Logs
Food packaging photos, barcode numbers, detected nutrition facts (carbohydrates, sugars, fiber, calories), and user-logged meal records stored in your private database account.
C. Educational Health Context Markers
Optional, self-selected metabolic interest markers (such as general metabolic group or baseline reference ranges) stored in your profile and used strictly on-device/in-database to calibrate educational food impact formulas.
D. Minimized Operational Telemetry
When analytics consent is granted, the app transmits coarse, non-clinical operational metrics (e.g., scan method: barcode vs. image, subscription tier, multi-shot flag). We strictly do not send food names, blood glucose readings, glycemic risk scores or levels, NOVA processing tiers, or specific additive/sugar health flags to third-party analytics.
3. Sensitive Data Safeguards & Commercial Restrictions
We treat your nutritional history and contextual profile settings as confidential:
- Encryption: All data is encrypted in transit using TLS 1.3/1.2 and encrypted at rest in our production database.
- No Data Selling or Brokerage: We do not sell, rent, or trade your personal or nutritional data to advertising networks, data brokers, insurance providers, or health industry aggregators.
- Local Cache Minimization: On-device scan caches store only basic layout metadata (food name, image URL, timestamps) for fast visual rendering. Clinical risk calculations and metabolic forecasts are never stored unencrypted at rest.
4. Third-Party Service Providers (Processors)
We engage third-party infrastructure providers to support app operations. Each provider processes data under strict contractual data-protection terms:
- Clerk: Provides user authentication, multi-factor security, and session management.
- Supabase (PostgreSQL on AWS): Hosts our secure database and cloud storage for user account records, household memberships, and scan history.
- Google Cloud / Gemini API: Processes label images for camera-based optical character recognition (OCR) and food identification. Images are used strictly for real-time analysis and are not retained to train public AI models.
- PostHog: Provides product usage analytics, feature flag delivery, and optional session replay (visual interaction recordings). In production builds, raw console output is stripped from session capture. Telemetry is bound to a pseudonymous internal user identifier (not your email or health diagnosis).
- RevenueCat: Manages subscription entitlement verification and in-app purchase receipts, keyed to your pseudonymous account ID.
- Diagnostics & Crash Reporting: Captures crash logs, stack traces, and system error diagnostics to help identify and resolve technical bugs.
- Outbound Nutrition Databases (Open Food Facts & USDA FoodData Central): Receives product barcode and ingredient queries to look up public nutritional facts.
5. Age Requirements & Household Dependent Profiles
GlycoLens establishes clear rules regarding account registration and household data management:
- Account Holders (18+): You must be at least 18 years old to create an account, sign in, or subscribe to GlycoLens. Direct account registration and authentication are strictly restricted to adults.
- Dependent & Family Records: An adult account holder may create managed eater profiles to log meals and track nutritional metrics for family members, including dependents and minors. These individuals do not hold accounts, have no login access, and do not interact directly with the application.
- Authority & Control: By adding a dependent profile, the adult account holder represents that they are the parent, legal guardian, or authorized caregiver with legal authority to enter and manage nutritional information on their behalf. The adult account holder maintains complete control over these records and can modify or delete them at any time.
- Bidirectional Household Sharing: Joining a household with another adult account holder shares meal logs, food scans, and scouted grocery lists across confirmed members of that household group.
6. User Rights, Data Autonomy & Export
Depending on your location (such as under GDPR, CCPA, or POPIA), you hold specific rights regarding your personal data:
- Account Deletion: You can delete your account and all associated data at any time directly in the app via Settings → Account → Delete Account.
- Analytics Opt-Out: You can grant or revoke analytics consent at any time in the app settings; your preference is recorded on your profile.
- Access & Export: You may request a machine-readable export of your personal scan history and profile data across all processors by emailing our privacy team at privacy@glycolensapp.com.
7. Data Retention Policy
We retain personal data for as long as your account remains active. When you initiate an account deletion:
- Your account, profile information, meal logs, scans, and household associations are immediately purged from our live database and authentication systems.
- Residual copies in automated database backups expire and are purged according to our database hosting retention cycle (up to 7 days).
- In-app purchase receipts and billing transactions are maintained by the platform stores (Apple App Store / Google Play) under their statutory commercial and tax obligations.
For complete details on account deletion, visit our Account Deletion page.
8. Contact Information
For privacy inquiries, data subject access requests, or regulatory questions, contact:
privacy@glycolensapp.com