Last updated: 7 September 2026
1. Who is responsible for your data
Glucogaze is a non-commercial personal project operated by a private individual under the name Glucogaze, based in Manchester, England. For the purposes of the UK GDPR and the Data Protection Act 2018, we are the data controller for the personal data described here.
Contact for anything in this policy: legal@glucogaze.com.
2. The short version
We hold the minimum needed to show your glucose data on your own screens: an account, the people you follow, their readings, the connections to your data sources, and your devices. We do not sell it, we do not advertise, we run no analytics or tracking, and you can export or delete it yourself at any time.
3. What we collect
Your account
- Your email address and, if you sign in with a password, a protected form of it — never the password itself. Both are held by our authentication provider, not in our own tables.
- Your name — your display name and, where you signed in with Google, the first and last name Google gives us.
- Your country, if you tell us.
- Preferences: notification settings and how often your dashboard refreshes.
- Sign-in session records, which our authentication provider stamps with the IP address and browser user-agent of each session so you can review and revoke your own sessions in Settings.
The people you follow — health data
- Their name or nickname, their glucose unit, their colour, and their timezone.
- Their glucose thresholds — urgent low, low, high, urgent high — and their overnight window. These are health data, and the overnight window also reveals when a household sleeps.
- Their glucose readings: the value, the time it was taken, the trend direction, and which source it came from. This is a continuous record of a person’s health over time and is the most sensitive thing we hold.
- Notifications we generated — for example that someone went urgent low, with the reading and the time it happened.
Your data sources
- Which provider you connected (for example FreeStyle LibreLink Up or Nightscout), the name you gave it, and its connection status and error history.
- The credentials for that provider — for LibreLink Up your account email and password; for Nightscout the site address and access token. These are encrypted by us before they are stored (see section 10) and are used only to fetch your data.
Your devices
- The name you gave the screen, its type, its settings (brightness, quiet hours, face), its firmware version, when it was last seen, and the strength of its Wi-Fi signal.
- The credential your screen uses to check in — we cannot read it back once stored — and, during pairing, a short-lived pairing record.
Security and abuse prevention
- Rate-limiting counters. Where these need to tell visitors apart before sign-in, we use an anonymised identifier, never the IP address itself. The same applies to the pairing records.
- Error logs written by our code. These record what failed, not who it happened to, and are held by our hosting provider.
Beta signups
If you apply to the closed beta we collect your name, email address, whether you use injections or a pump, which glucose source you use, whether you already own a compatible screen, and whatever you write in the free-text box. Your therapy type is health data, and the free-text box may contain more if you choose to write it.
Beta applications are deliberately stored separately from the main service’s data, and they are not linked to any account you later create.
4. Where your data comes from
- From you — what you type into the site: your account details, the people you add, the thresholds you set, and your source credentials.
- From Google — if you choose to sign in with Google, we receive your email address and name. We never receive your Google password.
- From the sources you connect — our server signs in to the provider on your behalf, using the credentials you supplied, and fetches the readings for the people you follow. We only ever fetch data you have given us access to.
- From your devices — each paired screen reports its firmware version and signal strength when it checks in for new data.
5. Why we are allowed to use it (lawful bases)
Glucose readings, thresholds and therapy type are special category data under Article 9 of the UK GDPR, which needs a lawful basis under Article 6 and a separate condition under Article 9.
- Running your account and showing your data
- Article 6(1)(b) — necessary to perform the agreement we have with you. For the health data within it, Article 9(2)(a) — your explicit consent. You give it when you sign up and agree to the Terms of Service and this Privacy Policy, and you confirm it each time you connect a source or add a person, because that is the moment health data starts to flow. You can withdraw it at any time by disconnecting the source, removing the person, or deleting your account.
- Keeping the service secure and preventing abuse
- Article 6(1)(f) — our legitimate interest in protecting the service, other users, and the providers we depend on. We have balanced this against your privacy by using anonymised identifiers rather than storing IP addresses.
- Beta applications
- Article 6(1)(a) and Article 9(2)(a) — your consent, given by submitting the form. You can withdraw it by emailing us and we will delete your application.
- Meeting our legal obligations
- Article 6(1)(c) — where the law requires us to keep or disclose something.
Withdrawing consent does not affect anything done before you withdrew it. If you withdraw consent for the health data, we can no longer provide the service, because that data is the service.
6. What we never do
- We never sell, rent or trade your personal data.
- We never use it for advertising or marketing profiling.
- We run no analytics, no tracking pixels and no third-party advertising or behavioural cookies anywhere on this site.
- We never use your data to train machine-learning models. If that ever changes it will be a separate, opt-in choice, described here first, and it will never involve sending raw readings anywhere.
- We make no automated decisions that produce legal or similarly significant effects for you, and we do not profile you.
- We never share your data with your insurer, employer or anyone else.
7. Who else processes it
We use a small number of suppliers to run the service. They process data on our instructions under contract, and they do not use it for their own purposes.
- Supabase
- Database and authentication — stores everything described in section 3 and sends password-reset emails. Hosted in London, United Kingdom.
- Vercel
- Website and API hosting. Our functions run in the London region. Vercel’s own access logs record IP addresses and user agents in the ordinary way of running a website.
- Cloudflare
- The “are you human?” check on our sign-in and signup forms (Turnstile). Cloudflare receives the technical signals needed to make that assessment.
- Only if you choose to sign in with Google. Google then knows you signed in to Glucogaze. If you use a password instead, Google is not involved at all.
- GitHub
- Provides part of our operational automation. No personal data passes through it.
Separately, and at your instruction, our server contacts the glucose source you connected — Abbott’s LibreLink Up servers, or the Nightscout site you named — to sign in and retrieve your readings. Those providers are not our processors; they are independent controllers of the data you hold with them, governed by their own privacy policies.
We may also disclose data if the law requires it, or to establish, exercise or defend a legal claim.
8. Where your data is held
Your account, readings, sources and devices are stored in the United Kingdom (London), and the servers that process them run in London too.
Some data necessarily leaves the UK:
- Your glucose source. Abbott assigns your account to a regional service — ours is in the EU. If your account sits in another region, requests for your readings go there. Where you use Nightscout, the data goes wherever you host it, which is your choice and your responsibility.
- Cloudflare and Google operate global networks and may process the limited data described above outside the UK.
Where a transfer leaves the UK, it is covered by UK adequacy regulations or by the ICO’s International Data Transfer Agreement or Addendum, together with appropriate safeguards.
9. How long we keep it
- Glucose readings
- Kept until you delete them — the history is the point of the product. Deleting a source, a person or your account removes them as described below.
- Account, people, sources and devices
- Kept until you delete the account, or delete the individual record.
- Notifications
- Deleted automatically 30 days after they were created, or 30 days after you bin one.
- Pairing records
- Expire 10 minutes after they are created and are deleted within a day.
- Rate-limiting counters
- Swept automatically, typically within hours.
- Beta applications
- Kept until the closed beta ends, or until you ask us to delete yours — whichever is first.
- Hosting logs
- Kept for our providers’ standard retention periods, which are short.
10. How we protect it
We protect your data with appropriate technical and organisational measures, as UK data protection law requires — including the encryption of your source credentials and safeguards at every layer between your browser, our servers and your devices.
We deliberately do not publish how those measures work: describing our defences in public would mainly help someone trying to get past them. A fuller account is available to a regulator or auditor on request.
No system is perfectly secure, and this one is maintained by one person. Please use a unique password, and think about where you place a screen — a display in a shared room shows health information to everyone who walks past.
11. Your rights
Under UK data protection law you have the right to:
- Access your data and get a copy of it;
- Portability — receive it in a structured, machine-readable format;
- Rectification — have inaccurate data corrected;
- Erasure — have it deleted;
- Restriction — have us pause processing while a dispute is resolved;
- Object to processing based on legitimate interests; and
- Withdraw consent at any time, for anything based on consent.
Several of these you can exercise yourself, immediately, without asking us:
- Export — Settings gives you a CSV of all readings for everyone on your account.
- Correct — names, thresholds and preferences are all editable in Settings.
- Delete a source’s history — disconnecting a source offers to erase the readings that came from it.
- Delete a person — removes them and erases their readings, sources, notifications and devices.
- Delete your account — erases the account and everything attached to it: every person, reading, source (including the encrypted credentials), notification and device. This is immediate and cannot be undone.
The self-service export covers your readings, which is the bulk of what we hold. For a complete copy of everything else — your profile, source configuration, devices and notification history — email legal@glucogaze.com and we will provide it.
We respond to requests within one month. We do not charge, unless a request is manifestly unfounded or excessive. We may need to verify your identity first.
12. Cookies
We use cookies only to keep you signed in. They are strictly necessary for the service to work, so no consent banner is required. We set no analytics, advertising or tracking cookies, and we do not use local storage to track you.
Cloudflare’s human-check may set its own strictly-necessary cookie on the sign-in and signup pages to prevent abuse.
13. Children and people you look after
Account holders must be 18 or over, as set out in our Terms of Service. Glucogaze is often used by a parent to follow a child’s glucose, and we designed for that — but it means an adult is entering a child’s health data.
If you add anyone other than yourself, you confirm you have the authority to do so, either through parental responsibility or that person’s explicit consent, and that you have explained to them what Glucogaze is and what it will hold. You can remove them at any time, which erases their data.
14. Changes to this policy
We may update this policy. The version on this page is always current, and the date at the top tells you when it last changed. If a change materially affects how we use your data, we will make reasonable efforts to tell you before it takes effect — and if it needs your consent, we will ask for it.
15. Contact and complaints
For anything about your data, or to exercise a right, email legal@glucogaze.com.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the UK supervisory authority:
- Information Commissioner’s Office
- Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — 0303 123 1113 — ico.org.uk