Consumer Health Data Privacy Policy
Last Updated: July 29, 2026
This policy explains how GlucoSpike AI handles consumer health data. It exists because Washington State’s My Health My Data Act requires a separate, dedicated policy for this category of data, and because we would rather over-explain it than bury it.
It applies to everyone who uses GlucoSpike AI, not only Washington residents. Nevada residents have similar protections under SB 370, and this policy describes our practices for them too.
This page sits alongside our main Privacy Policy, which covers everything else we collect. Where the two overlap, they say the same thing.
1. What Counts as Consumer Health Data Here
My Health My Data defines consumer health data broadly, including “bodily functions, vital signs, symptoms, or measurements.” In GlucoSpike AI, that means:
| Category | What it is | Is it optional? |
|---|---|---|
| Blood-glucose readings | Readings you type in yourself: the value, whether it was before a meal, after a meal or fasting, and the time it was taken. Optionally linked to a meal you logged. | Yes — fully optional |
| Glucose settings | Your preferred unit (mg/dL or mmol/L), and an optional resting level you can set yourself | Yes |
| Estimate-accuracy data | What the app predicted for a meal, the starting point it used, and whether a walk was recorded — kept so we can compare our estimate against your actual reading | Only exists if you log readings |
| Patterns | An optional tag on a meal recording how it made you feel — crashed, foggy, or energized. Collected only with your consent (§6), stored for you to look back on, and never sent to the AI or shared with anyone | Yes — fully optional |
| Meal and nutrition logs | Photos of your meals, GlucoScores, and nutritional estimates | Yes |
| Anything you type into the personal context field | A free-text field you can use to tailor your AI coach. Some people put health conditions in it. That is entirely your choice. | Yes |
What is not here matters too. We do not collect diagnosed conditions, medications, HbA1c, lipid panels, blood pressure, weight, BMI, or any biometric data through structured fields. We do not read anything from Apple Health, Google Fit, a continuous glucose monitor, or any other connected device or sensor. Every blood-glucose value in the app was typed in by hand, by you.
2. Where It Comes From
There is only one source: you. Every piece of consumer health data listed above was entered by you, in the app, on purpose.
We do not buy health data, receive it from data brokers, infer it from your behaviour elsewhere, or obtain it from any third party.
3. Why We Collect It, and How It Is Used
We collect consumer health data for these purposes and no others:
- To show you what keeps repeating. Your readings appear in your history and next to the meals they relate to, so you can see how a meal actually went instead of only what we predicted. If you tag a Pattern on a meal, that appears there too.
- To check our estimates against your reality. We compare what the app predicted for a meal against what you measured, so the estimates get closer for you over time.
- To generate the app’s core features. GlucoScores, meal insights, coaching answers, and your weekly summary.
We never use consumer health data for advertising. We do not use it for profiling, cross-context behavioural advertising, or to infer characteristics about you.
4. Who It Is Shared With
We do not sell consumer health data, and we have never sold it. Under My Health My Data, selling consumer health data requires a separate signed authorization from you — we do not have one, do not ask for one, and have no plans to.
We share consumer health data only with the service providers who make the app run, under contract, and only for the purposes above:
| Who | Category shared | Why |
|---|---|---|
| Google LLC (Firebase Firestore & Storage) | Blood-glucose readings, meal logs, photos, Patterns | Storing your data so it is there when you open the app |
| Google LLC (Gemini API) | Blood-glucose readings tied to a meal or a day, meal photos, personal context. No Patterns | Generating GlucoScores, insights, and coaching responses |
That is the complete list for health data. RevenueCat, Buttondown, Open Food Facts, and our analytics tools receive no consumer health data — they handle subscriptions, newsletter email, product lookups, and anonymized usage events respectively, as described in the Privacy Policy.
No other person sees your readings. There is no sharing feature, no social feature, and no export to any third party. We do not disclose consumer health data to insurers, employers, advertisers, or data brokers.
5. Which Readings Go to the AI
Blood-glucose readings are included in requests to Google’s Gemini API in exactly three places:
- When you ask about a specific meal — that meal’s own before and after readings, and how long after eating each was taken.
- When you ask the daily coach a question — that day’s readings, matched to the meals they relate to.
- In the weekly summary — an aggregate only: how many readings, their average, and their range.
Readings are not sent during meal photo analysis or barcode scans, and they are not sent anywhere else. Patterns are never sent to the AI at all — they exist only in your own history.
Every one of those requests carries explicit instructions to the AI: never label a reading normal, high, or low; only describe a change when both a before and an after reading exist; never diagnose; never discuss medication; never treat a single reading as a trend; and defer anything extreme to a doctor. Whether a number is good or bad is a call for you and your doctor. We built the app so it does not make that call for you.
As of the date of this policy, Google’s Gemini API does not use API inputs to train its models under its enterprise API terms.
6. Your Consent
We ask before we collect. The first time you enter health data — whether that is a blood-glucose reading or a Pattern tag on a meal, whichever comes first — and before anything is saved, the app shows you this:
“This is health data. We store your readings and how meals made you feel so you can see what keeps repeating — only you see them, and you can delete any entry, or all of them, anytime.”
You consent by choosing to continue, and your consent is recorded at that point. Agreeing to our Terms of Use when you sign up is a separate thing and does not stand in for this — health data gets its own ask.
If you decline, nothing is stored: no readings, no Patterns. The rest of the app carries on working normally. Both features are optional, not a condition of using GlucoSpike AI.
Withdrawing consent is meant to be as easy as giving it. You can turn off health data storage in Settings at any time, which stops any further collection. You can also delete any individual reading or Pattern from within the app, delete all of them, or delete your account entirely. Withdrawing consent does not undo processing that already happened, but it stops anything further.
7. Your Rights
Under My Health My Data (and comparable laws elsewhere), you have the right to:
- Confirm whether we are collecting, sharing, or selling your consumer health data — we collect and share it as described above, and we do not sell it
- Access the consumer health data we hold about you, including a list of third parties it has been shared with
- Withdraw your consent to its collection and sharing, using the Settings control described in §6
- Delete it. You can delete individual readings and Patterns in the app immediately, or delete your account to remove everything at once. On request, we will also direct our service providers to delete it.
We will not deny you the app, charge you a different price, or give you a worse experience for exercising any of these rights.
How to exercise them
Email support@glucospike.ai with what you want to do. We will verify that the request is coming from you (usually by confirming the email address on the account) and respond within 45 days. If we need longer, we will tell you why and take no more than 45 additional days.
If we deny a request, you can appeal by replying to our response. If your appeal is denied, you may file a complaint with the Washington State Attorney General.
8. How Long We Keep It
We keep your consumer health data until you delete it or delete your account. There is no fixed retention period, because it is your log and it is only useful to you as a history.
Deleting your account removes your readings, meal logs, photos, and Patterns. This is permanent.
9. Where It Is Stored
In Firebase Firestore and Firebase Storage (Google LLC), on servers in the United States, encrypted at rest. Firestore security rules restrict your readings to your account, so no other user of the app can reach them.
If you are outside the United States, your consumer health data is processed there. For EU and UK users this is covered by Standard Contractual Clauses; for Australian users, this is the overseas disclosure contemplated by Australian Privacy Principle 8.
10. A Note on HIPAA
HIPAA does not apply to GlucoSpike AI. We are not a healthcare provider, a health plan, a healthcare clearinghouse, or a business associate of one, and we will never describe ourselves as “HIPAA compliant” — for a consumer app, that claim is meaningless at best and misleading at worst.
Being outside HIPAA is not the same as being outside health-data law. My Health My Data, the CCPA, the GDPR, and the Australian Privacy Act exist precisely to cover apps like ours, and those are the rules we hold ourselves to.
11. Changes to This Policy
If our handling of consumer health data changes materially, we will update this page and notify users. The “Last Updated” date above reflects the most recent revision.
12. Contact Us
Email: support@glucospike.ai
Our privacy contact is reachable at the same address. If you are writing about consumer health data specifically, saying so in the subject line helps us route it faster.
GlucoSpike AI