Consumer Health Data Privacy Policy
Last Updated: August 5, 2026
This policy explains how GlucoSpike AI — a product of GlucoSpike LLC, a Delaware limited liability company — handles consumer health data. It exists because Washington State’s My Health My Data Act requires a separate, dedicated policy for this category of data, and because we would rather over-explain it than bury it.
It applies to everyone who uses GlucoSpike AI, not only Washington residents. Nevada residents have similar protections under SB 370, and this policy describes our practices for them too.
This page sits alongside our main Privacy Policy, which covers everything else we collect. Where the two overlap, they say the same thing.
What this policy covers. Health data you enter in the app: the categories listed in §1 below. Browsing this website is a separate matter and is covered by §2.9 of the Privacy Policy. The short version is that analytics and advertising on glucospike.ai stay off until you accept them, they never reach anything you log in the app, and you can switch them off again from “Cookie settings” at the bottom of any page.
1. What Counts as Consumer Health Data Here
My Health My Data defines consumer health data broadly, including “bodily functions, vital signs, symptoms, or measurements.” In GlucoSpike AI, that means:
| Category | What it is | Is it optional? |
|---|---|---|
| Blood-glucose readings | Readings you type in yourself: the value, whether it was before a meal, after a meal or fasting, and the time it was taken. Optionally linked to a meal you logged. | Yes — fully optional |
| Glucose settings | Your preferred unit (mg/dL or mmol/L), and an optional resting level you can set yourself | Yes |
| Estimate-accuracy data | What the app predicted for a meal, the starting point it used, and whether a walk was recorded — kept so we can compare our estimate against your actual reading | Only exists if you log readings |
| Patterns | An optional tag on a meal recording how it made you feel — crashed, foggy, or energized. Collected only with your consent (§6) and stored for you to look back on. Never sent to the AI or shared with anyone (§5) | Yes — fully optional |
| Meal and nutrition logs | Photos of your meals, GlucoScores, and nutritional estimates | Yes |
| Anything you type into the personal context field | A free-text field you can use to tailor your AI coach. Some people put health conditions in it. That is entirely your choice. | Yes |
What is not here matters too. We do not collect diagnosed conditions, medications, HbA1c, lipid panels, blood pressure, weight, BMI, or any biometric data through structured fields. We do not read anything from Apple Health, Google Fit, a continuous glucose monitor, or any other connected device or sensor. Every blood-glucose value in the app was typed in by hand, by you.
2. Where It Comes From
There is only one source: you. Every piece of consumer health data listed in §1 was entered by you, in the app, on purpose.
We do not buy health data, receive it from data brokers, infer it from your behaviour elsewhere, or obtain it from any third party.
3. Why We Collect It, and How It Is Used
We collect consumer health data for these purposes and no others:
- To show you what keeps repeating. Your readings appear in your history and next to the meals they relate to, so you can see how a meal actually went instead of only what we predicted. If you tag a Pattern on a meal, that appears there too.
- To check our estimates against your reality. We compare what the app predicted for a meal against what you measured, so the estimates get closer for you over time.
- To generate the app’s core features. GlucoScores, meal insights, coaching answers, and your weekly summary.
We never use consumer health data for advertising. We do not use it for profiling, cross-context behavioural advertising, or to infer characteristics about you.
4. Who It Is Shared With
We do not sell consumer health data, and we have never sold it. Under My Health My Data, selling consumer health data requires a separate signed authorization from you — we do not have one, do not ask for one, and have no plans to.
We share consumer health data only with the service providers who make the app run, under contract, and only for the purposes above:
| Who | Category shared | Why |
|---|---|---|
| Google LLC (Firebase Firestore & Storage) | Blood-glucose readings, meal logs, photos, Patterns | Storing your data so it is there when you open the app |
| Google LLC (Gemini API) | Meal photos, meal names and GlucoScores, personal context. No blood-glucose readings and no Patterns | Generating GlucoScores, insights, and coaching responses |
That is the complete list for health data. RevenueCat, Buttondown, Open Food Facts, and the app’s analytics receive no consumer health data — they handle subscriptions, newsletter email, product lookups, and anonymized usage events respectively, as described in the Privacy Policy.
No other person sees your readings. There is no sharing feature, no social feature, and no way for another user to reach them. Beyond the two service providers in the table above, we do not disclose consumer health data to anyone — not to insurers, employers, advertisers, or data brokers.
5. Your Health Data Does Not Go to the AI
Blood-glucose readings and Patterns are never sent to Google’s Gemini API, or to any other AI service. Not the individual entries, and not counts, averages, ranges, or any other total derived from them.
What Gemini receives is meal data: the meal photo, the meal names and GlucoScores in your daily summary, product nutrition text from barcode scans, and any coach personalization inputs you have set.
This is why the app never tells you a reading is normal, high, or low. The AI cannot comment on your readings, because it never sees them. Whether a number is good or bad is a call for you and your doctor, and we built the app so it is never in a position to make it.
As of the date of this policy, Google’s Gemini API does not use API inputs to train its models under its enterprise API terms.
6. Your Consent
We ask before we collect. The first time you enter health data — whether that is a blood-glucose reading or a Pattern tag on a meal, whichever comes first — and before anything is saved, the app shows you this:
“This is health data. We store your readings and how meals made you feel so you can see what keeps repeating. They are never sent to our AI, and no one else sees them. You can delete any entry, or all of them, anytime.”
You consent by choosing to continue, and your consent is recorded at that point. Agreeing to our Terms of Use when you sign up is a separate thing and does not stand in for this — health data gets its own ask.
If you decline, nothing is stored: no readings, no Patterns. The rest of the app carries on working normally. Both features are optional, not a condition of using GlucoSpike AI.
Withdrawing consent is meant to be as easy as giving it. You can withdraw it at any time by deleting your readings in the app’s Log tab. This removes them, and we won’t collect more unless you agree again. You can also delete any individual Pattern from within the app, or delete your account entirely. Withdrawing consent does not undo processing that already happened, but it stops anything further.
7. Your Rights
Under My Health My Data (and comparable laws elsewhere), you have the right to:
- Confirm whether we are collecting, sharing, or selling your consumer health data — we collect and share it as described in §4, and we do not sell it
- Access the consumer health data we hold about you, including a list of third parties it has been shared with
- Withdraw your consent to its collection and sharing, by deleting your readings as described in §6
- Delete it. You can delete individual readings and Patterns in the app immediately, or delete your account to remove everything at once. On request, we will also direct our service providers to delete it.
We will not deny you the app, charge you a different price, or give you a worse experience for exercising any of these rights.
How to exercise them
Email support@glucospike.ai with what you want to do. We will verify that the request is coming from you (usually by confirming the email address on the account) and respond within 45 days. If we need longer, we will tell you why and take no more than 45 additional days.
If we deny a request, you can appeal by replying to our response. If your appeal is denied, you may file a complaint with the Washington State Attorney General.
8. How Long We Keep It
We keep your consumer health data until you delete it or delete your account. There is no fixed retention period, because it is your log and it is only useful to you as a history.
Deleting your account removes your readings, meal logs, photos, and Patterns. This is permanent.
9. Where It Is Stored
In Firebase Firestore and Firebase Storage (Google LLC), on servers in the United States, encrypted at rest. Firestore security rules restrict your readings to your account, so no other user of the app can reach them.
If you are outside the United States, your consumer health data is processed there. For EU and UK users this is covered by Standard Contractual Clauses; for Australian users, this is the overseas disclosure contemplated by Australian Privacy Principle 8.
10. A Note on HIPAA
HIPAA does not apply to GlucoSpike AI. We are not a healthcare provider, a health plan, a healthcare clearinghouse, or a business associate of one, and we will never describe ourselves as “HIPAA compliant” — for a consumer app, that claim is meaningless at best and misleading at worst.
Being outside HIPAA is not the same as being outside health-data law. My Health My Data, the CCPA, the GDPR, and the Australian Privacy Act exist precisely to cover apps like ours, and those are the rules we hold ourselves to.
11. Changes to This Policy
If our handling of consumer health data changes materially, we will update this page and notify users. The “Last Updated” date above reflects the most recent revision.
12. Contact Us
GlucoSpike LLC (Delaware, USA) Email: support@glucospike.ai
Our privacy contact is reachable at the same address. If you are writing about consumer health data specifically, saying so in the subject line helps us route it faster.
GlucoSpike AI