Privacy Policy
Last Updated: August 5, 2026
GlucoSpike AI is a product of GlucoSpike LLC, a limited liability company registered in the State of Delaware, United States. GlucoSpike LLC ("we", "our", or "us") is the data controller for the information described here and is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights over it. It applies to our mobile application and website (the "Services").
1. Who We Are
GlucoSpike AI is a wellness app that helps users understand the blood glucose impact of their meals. Users photograph food, and the app uses AI to estimate how that meal may affect blood sugar, expressed as a GlucoScore (1–10 scale). The app also includes a barcode product scanner for evaluating packaged foods, and an optional log where you can record your own blood-glucose readings and see them alongside the meals you ate.
The app is not a medical device. It does not diagnose, treat, or monitor any medical condition. GlucoScores are wellness estimates, not clinical measurements.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address — used for authentication and communications
- Display name (optional)
- Firebase UID — an anonymous internal identifier generated by Firebase Authentication
You may sign in using Email/Password, Google Sign-In, or Apple Sign-In. When using Google or Apple, we receive the email address and name associated with that account (Apple may provide a masked email).
2.2 Meal Log Data
Each time you log a meal, we collect and store:
- AI-generated meal name, GlucoScore, nutritional estimates (calories, carbs, protein, fat, fiber), and ingredient list. For unpackaged meals, nutrition figures are AI estimates; for packaged products scanned by barcode, nutrition data is sourced from the Open Food Facts database.
- AI-generated insights, suggested post-meal walk duration, and Q&A content
- Whether you completed the suggested post-meal walk
- Timestamp of the meal log
- The meal photo (stored in Firebase Storage)
- Patterns (optional) — how the meal made you feel. You can tag a meal with whether it crashed you, left you foggy, or left you energized. This is entirely optional, you can change or remove it at any time, and the app works fine if you never use it.
Patterns stay with us. They are stored under your account so you can look back and see what keeps repeating. They are never sent to Google Gemini or any other AI service — not the individual tag, and not any total derived from it — and they are never shared with anyone.
How a meal made you feel is health data too, so Patterns are collected only with your consent, through the same single consent step described in §2.3.
2.3 Blood-Glucose Readings (Optional)
You can record your own blood-glucose readings in the app. This is health data, and it is optional. Every value is typed in by you — GlucoSpike AI reads nothing from Apple Health, Google Fit, a continuous glucose monitor, or any other connected device or phone sensor. The app works fully without it, and you can use it for years without ever logging a reading.
When you log a reading, we store:
| Field | What it is |
|---|---|
| Reading value | A number you type in, in mg/dL or mmol/L. Stored in mg/dL; your unit choice is a display preference. |
| Reading type | One of: before a meal, after a meal, or fasting. You choose which. |
| Time taken | Defaults to now. You can set it to an earlier time. |
| Meal link (optional) | A reading can be attached to a meal you already logged, so the app can show the two together. |
| Accuracy fields | What the app predicted for that meal, the starting point it used, and whether a walk was recorded. Kept so the estimate can be compared against what you actually measured. |
| Settings | Your preferred unit, and an optional resting level you can set (or that a fasting reading can fill in for you). |
Your consent
Because this is health data, we ask before we store any of it. The first time you enter health data — a reading, or a Pattern tag on a meal (§2.2), whichever comes first — the app shows you this before anything is saved:
"This is health data. We store your readings and how meals made you feel so you can see what keeps repeating. They are never sent to our AI, and no one else sees them. You can delete any entry, or all of them, anytime."
Your consent is recorded when you accept it, and readings and Patterns are collected only on that basis. Agreeing to our Terms of Use at sign-up is separate and does not stand in for this — health data gets its own ask.
You can withdraw it at any time by deleting your readings in the app's Log tab. This removes them, and we won't collect more unless you agree again. You can also delete your whole account whenever you want (see §10). This single consent step is what satisfies GDPR Article 9(2)(a), Washington's My Health My Data Act, and Australian Privacy Principle 3.3 — see §11.
No other person sees your readings. There is no sharing feature, no social feature, and no way for another user to reach them. The only place they go is Firebase, where they are stored for you (§6). They are never sent to the AI (§5.1).
2.4 App Preferences
- Push notification preferences (on/off)
- Theme preference (light/dark/system)
- Trial start date
These are stored on your device and in Firebase Firestore.
2.5 Coach Personalization Data
Optionally, you can personalize your AI coach by providing:
- Personal context — a free-text field where you may type anything to tailor coaching, such as dietary preferences, lifestyle notes, or health conditions you choose to share (e.g., "vegetarian, budget-conscious" or "type 2 diabetes, high blood pressure"). An in-app notice beside this field explains that anything you enter will be sent to the AI and that you should share only what you are comfortable with — this notice establishes your explicit consent for any health information you voluntarily enter.
- Goals — a multi-select list of predefined wellness goals (e.g., "Lower blood sugar", "Increase protein")
Both are optional, editable, and deletable at any time in Settings. They are sent to Google Gemini for meal analysis, swap suggestions, daily coaching, and coach Q&A. They are stored in Firebase Firestore under your UID.
2.6 AI Coach Chat
The in-app AI coach lets you ask questions about your meals and health habits. When you use the coach:
- A summary of your meals logged that day (meal names and GlucoScores) is sent to Google Gemini to generate a coaching response
- Free-text questions you type into the coach are sent to Google Gemini
Coaching responses are generated on demand and are not stored as a persistent chat transcript.
2.7 Barcode / Product Scan Data
When you scan a product barcode, we look up the product in the Open Food Facts database and save the result to your scan history, so you can look back at what you have scanned. Each saved scan includes:
- Product name and brand
- Nutrition facts, as sourced from Open Food Facts
- The GlucoScore and verdict generated for that product
- The barcode number and the time you scanned it
Your scan history is stored in Firebase Firestore under your account and is removed when you delete your account (§10). No personal data is sent to Open Food Facts — only the barcode number.
2.8 Analytics & Crash Data
We use Firebase Analytics to understand how the app is used (e.g., which features are tapped, screen views) and Firebase Crashlytics to detect and fix crashes. These tools collect anonymized usage events linked to your Firebase UID, along with device information and crash stack traces.
2.9 Website Cookies and Tracking
This section is about glucospike.ai, the website — not the app. The app does not use cookies; its analytics are described in §2.8 above.
When you first visit, a banner asks what you want. The two categories do not work the same way, and one of them depends on where you are, so here is the whole picture:
- Marketing (Meta Pixel) — off until you accept, everywhere in the world, no exceptions. The script is not placed on the page at all until you say yes. Not loaded and sitting idle — absent. Rejecting it, or ignoring the banner entirely, leaves it absent.
- Analytics (Google Analytics) — depends on where you are. In the European Economic Area, the United Kingdom, Switzerland, Washington State and Nevada, it is off until you accept: the Google script loads but runs in "consent denied" mode, setting no cookies and storing no identifier. Everywhere else, including the rest of the United States, it is on unless you turn it off, and the banner and the "Cookie settings" link at the bottom of any page both let you do that at any time.
Why analytics is treated differently by region. The EEA, UK and Switzerland require opt-in consent before non-essential cookies are set, and we follow that. Washington and Nevada have consumer health data laws broad enough to cover browsing that hints at a health condition, and since many of our pages are named for one, we put both States on the opt-in side too rather than argue about whether the definition reaches us. Outside those places the law does not require opt-in for first-party analytics, and running a health site on figures that only describe the minority of visitors who click Accept produces a badly skewed picture of what people actually read. Marketing is a different matter and stays opt-in everywhere, because that is the one that discloses your browsing to somebody else.
Two things are stored on your device no matter what you choose, because the site cannot behave sensibly without them. Neither identifies you and neither is sent anywhere.
| Name | Set by | Category | Purpose | Expires |
|---|---|---|---|---|
gs_consent (local storage) | GlucoSpike AI | Strictly necessary | Remembers the cookie choice you made, so we don't ask again on every page | Until you clear browser storage |
theme (local storage) | GlucoSpike AI | Strictly necessary | Remembers whether you chose light or dark mode | Until you clear browser storage |
_ga, _ga_G5QQKCDZDX | Google LLC (Google Analytics 4) | Analytics — only if you accept in the EEA, UK, Switzerland, Washington and Nevada; on by default elsewhere unless you turn it off | Tells us which pages get read and where people give up, so we know what is worth writing more of | 2 years |
_fbp | Meta Platforms, Inc. (Meta Pixel) | Marketing — only if you accept | Measures whether an ad or social post is what brought you here | 90 days |
_fbc | Meta Platforms, Inc. (Meta Pixel) | Marketing — only if you accept | Records which ad click brought you here. Only set if you arrive from an ad link | 90 days |
What accepting marketing actually shares. We want to be plain about this rather than bury it, because of what this site is about. Many of our pages are named for a condition — prediabetes, insulin resistance, PCOS, type 2 diabetes. If you accept marketing cookies, the Meta Pixel reports the pages you visit on glucospike.ai to Meta, and Meta can connect that to your Facebook or Instagram account. That means it can learn which of those pages you read. It is off unless you turn it on, it is limited to pages on this website, and it never has access to anything inside the app — not your meals, not your readings, not your Patterns (§5.1). If you would rather Meta not have that, reject marketing cookies and it never runs.
Changing your mind. "Cookie settings" at the bottom of any page reopens the banner with your current choices, and you can switch either category off — including analytics in the places where it starts on. Turning marketing off stops the pixel from loading on your next page view; turning analytics off stops Google's cookies being set and deletes nothing you have already sent, which we cannot undo on your behalf. Withdrawing is meant to be exactly as easy as accepting was, which is what GDPR Article 7(3) requires.
Cookies we do not use. There are no advertising cookies beyond the Meta Pixel above, no third-party ad networks, no session recording or heatmap tools, and no data brokers.
3. Information We Do Not Collect via Structured Fields
GlucoSpike AI does not require, request via structured fields, or systematically collect:
- Diagnosed medical conditions (e.g., diabetes, PCOS, thyroid conditions)
- Medications or prescription drug use
- Clinical health metrics such as HbA1c, lipid panels, or blood pressure
- Readings pulled automatically from a CGM, Apple Health, Google Fit, or any connected device
- Biometric data (weight, BMI, body measurements)
This is a boundary we hold deliberately, not an accident of what we have built so far.
Exception — blood-glucose readings you enter yourself (§2.3): The one clinical metric the app does collect through a structured field is a blood-glucose reading you type in yourself. It is optional, it is never read from a device or sensor, and it is collected only with your consent. See §2.3 for the full detail.
Exception — Coach Personal Context field (§2.5): Because this optional free-text field accepts arbitrary input, you may voluntarily enter information that falls into the above categories, including data that could qualify as GDPR Article 9 special category data. This is entirely optional, user-controlled, and deletable at any time. It is processed only on the basis of your explicit consent, established by the in-app disclosure notice shown beside the field. The app never derives, infers, or requires such data — it only stores what you choose to type.
4. How We Use Your Data
- To provide the Services: generating GlucoScores, meal insights, and product scan results
- To personalize your experience: using the coach personalization inputs you choose to set (§2.5) to provide context-aware AI analysis
- To show you what keeps repeating: your meal history, any Patterns you tag (§2.2), and any readings you log are assembled into the views and summaries you see in the app
- To send notifications: daily reminders, weekly reports, and trial expiration alerts (if enabled)
- To manage subscriptions: syncing entitlement status across devices via RevenueCat
- To improve the app: anonymized analytics to understand feature usage and fix bugs
- To communicate with you: the optional "Beat the Spike" newsletter (only if you opt in)
4.1 How We Use Your Blood-Glucose Readings
If you log readings, we use them for exactly two things:
- To show you your own patterns. Your readings appear in your history and next to the meals they relate to, so you can see how a meal actually went rather than only what the app predicted.
- To check our estimates against your reality. We compare what the app predicted for a meal with what you actually measured, so the estimates get closer for you over time.
Your readings are never used for advertising, never sold, and never shared with anyone else. They are not used to build a profile for marketing, and they are not shared with data brokers, insurers, employers, or advertisers.
5. AI Processing — How Your Data Is Used by AI
GlucoSpike AI uses Google's Gemini API for the following features:
- Meal analysis: Your meal photo (compressed image) is sent to Gemini. If you have set coach personalization inputs (§2.5), your personal context and goals are also included to tailor the analysis.
- AI Coach: Your daily meal summary (meal names and GlucoScores) and questions you type into the coach are sent to Gemini. Coach personalization inputs (§2.5), if set, are included in these requests as well.
- Product barcode scans: Product name, brand, nutrition facts per 100g, and ingredients text (all sourced from Open Food Facts) are sent to Gemini. No personal data is included.
5.1 Your Health Data Does Not Go to the AI
Blood-glucose readings (§2.3) and Patterns (§2.2) are never sent to Google Gemini, or to any other AI service. Not the individual entries, and not counts, averages, ranges, or any other total derived from them. The AI is never given your health data in any form.
What Gemini receives is meal data: the meal photo, the meal names and GlucoScores in your daily summary, product nutrition text from barcode scans, and the coach personalization inputs you have chosen to set (§2.5). Your readings and Patterns stay in your account, for you.
This means the AI cannot comment on your readings, because it never sees them. Whether a number is good or bad is a call for you and your doctor, and we built the app so it is never in a position to make it.
What is NOT sent to the AI: Your name, email address, or any directly identifying information. Your blood-glucose readings and Patterns, as above. Diagnosed conditions, medications, HbA1c, and other clinical or biometric data are not collected by the app through structured fields, and therefore never reach the AI — except for anything you voluntarily type into the optional personal context field (see §2.5).
Data retention by Google: As of the date of this policy, Google's Gemini API does not use API inputs to train its models by default under enterprise API terms. This is subject to change per Google's policies. We recommend reviewing Google's Gemini API terms for the most current information.
You are interacting with an AI system each time you receive a GlucoScore, product scan result, or coaching response. For more details, see our AI & Ethical Use Policy.
6. Third-Party Services & Data Sharing
We share data only with the following service providers, solely to operate the app:
| Service | Provider | Purpose | Data Shared |
|---|---|---|---|
| Firebase Authentication | Google LLC | User sign-in | Email, display name, Firebase UID |
| Firebase Firestore | Google LLC | Meal history, glucose readings, preferences | Meal data, Patterns, blood-glucose readings, scan history, preferences |
| Firebase Storage | Google LLC | Meal photo storage | Meal photos |
| Firebase Analytics | Google LLC | Usage analytics (anonymous) | App events, Firebase UID |
| Firebase Crashlytics | Google LLC | Crash reporting | Crash traces, device info, Firebase UID |
| Firebase Cloud Messaging | Google LLC | Push notifications | Device push token |
| Gemini API | Google LLC | AI meal & product analysis, coaching | Meal photos, meal names and GlucoScores, product nutrition text, coach personalization inputs. No blood-glucose readings and no Patterns (see §5.1). |
| RevenueCat | RevenueCat Inc. | Subscription management | Firebase UID, purchase receipts |
| Open Food Facts | Open Food Facts (nonprofit) | Barcode product lookup | Barcode number only (no user data) |
| Buttondown | Buttondown LLC | Newsletter (optional opt-in) | Email address (only if you opt in) |
| Google Sign-In | Google LLC | OAuth authentication | Google account email, name, profile photo |
| Apple Sign-In | Apple Inc. | OAuth authentication | Apple ID email (may be masked), name |
The table above covers the app. The website uses two further third parties, Google Analytics and the Meta Pixel. The Meta Pixel runs only if you accept it in the cookie banner; Google Analytics runs only if you accept it in the regions listed in §2.9, and by default elsewhere. What they receive is set out in §2.9.
We do not sell your personal data to any third party. The one disclosure that is not a service-provider relationship is the Meta Pixel on the website, which runs only with your consent and is described in §2.9 and §11.
7. Data Storage & Security
Your data is stored in Firebase Firestore and Firebase Storage (Google LLC), encrypted at rest. Meal photos are linked to your account and stored until you delete your account. App preferences are also stored locally on your device using secure local storage.
Blood-glucose readings are stored in Firebase Firestore under your account only. Firestore security rules restrict access to that data to the account owner, so no other user of the app can reach your readings.
8. Notifications
We send the following types of notifications:
- Local (on-device): Daily meal reminder at 8:00 PM (skipped if you've already logged today), weekly report reminder every Sunday at 10:00 AM, and trial expiration alerts on days 3 and 6 of your trial
- Remote push (via Firebase Cloud Messaging): May be used for server-initiated messages
Notification permission is requested at app launch and can be disabled at any time in your device's Settings.
9. Subscriptions & Payments
Payments are processed by Apple (App Store) or Google (Play Store). GlucoSpike AI never receives or stores payment card data. Subscription entitlement is synced across your devices via RevenueCat using your Firebase UID.
10. Data Deletion & Your Rights
10.1 Account Deletion
You can delete your account at any time via Settings → Account → Delete Account within the app. Deleting your account removes your Firebase Authentication record, all Firestore documents associated with your UID (including every blood-glucose reading you have logged and your scan history), all meal photos in Firebase Storage, and clears local device storage. This action is permanent and cannot be undone.
10.2 Deleting Individual Readings and Patterns
You can delete any single blood-glucose reading from the app's Log tab, or any Pattern you tagged on a meal, without deleting anything else. Deleting your account removes all of it at once, as described in §10.1.
10.3 Your Rights
Depending on your jurisdiction, you may have the following rights:
- Right to access: Request a copy of the personal data we hold about you
- Right to correction: Request correction of inaccurate data
- Right to erasure: Request deletion of your data (account deletion within the app fulfills this for most data)
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Where we rely on your consent — as we do for blood-glucose readings and Patterns (§2.3) — you can withdraw it at any time by deleting your readings in the app's Log tab. This removes them, and we won't collect more unless you agree again. Withdrawing does not affect processing that already happened.
- Right to limit use of sensitive personal information: California residents may direct us to limit the use of sensitive personal information. We already restrict blood-glucose readings to the two purposes in §4.1, and we never use them for advertising or sell them.
- Right to data portability (GDPR Art. 20): Not currently available as a self-serve feature — contact us at support@glucospike.ai
To exercise any of these rights, contact us at support@glucospike.ai.
11. Regulatory Compliance
Health Data and Consent — The Short Version
Blood-glucose readings are health data, and health data is treated as a protected category almost everywhere our users live. Different laws use different names for it — sensitive personal information in California, consumer health data in Washington, special category data in the EU and UK, sensitive information in Australia — but they converge on the same requirement: ask first.
So we ask once, clearly, before the first reading is ever stored (§2.3), and that single consent step is what we rely on across all of these regimes. The paragraphs below explain how it maps to each one.
GDPR (EU and UK Users)
Legal basis for most data: Processing is necessary for performance of the contract (providing app functionality) and our legitimate interests (analytics, crash reporting). This covers meals and preferences.
Legal basis for website cookies: Different, and deliberately so. Analytics and marketing cookies on the website (§2.9) run on consent, not legitimate interests — the ePrivacy Directive requires consent before anything non-essential is stored on or read from your device, and legitimate interests cannot substitute for it. That is why they stay off until you accept, and why the footer lets you withdraw.
Legal basis for health data: Blood-glucose readings are data concerning health under Article 4(15), which Article 9(1) prohibits processing unless a condition in Article 9(2) applies. Legitimate interests cannot carry Article 9 data, so contract performance alone is not enough here. The same is true of Patterns, which record symptoms. We therefore process both on the basis of your explicit consent — Article 6(1)(a) together with Article 9(2)(a) — given through the in-app consent step described in §2.3. The same basis covers any health information you voluntarily type into the optional personal context field (§2.5).
Withdrawing consent: Under Article 7(3) you can withdraw your consent at any time, and it must be as easy to withdraw as it was to give. You withdraw by deleting your readings in the app's Log tab: this removes them, and we won't collect more unless you agree again. You can also delete any individual Pattern, or delete your account entirely, from within the app.
We are not a healthcare provider. We do not rely on Article 9(2)(h) — that condition requires a health professional or someone under an equivalent obligation of secrecy, which we are not.
International transfers: Your data is processed by Google (US-based) and RevenueCat (US-based), covered under their Standard Contractual Clauses. Data Processing Agreements (DPAs) are in place with Google, RevenueCat, and Buttondown.
CCPA / CPRA (California)
We collect sensitive personal information. The blood-glucose readings and Patterns you log are health data, which is sensitive personal information under California law. We collect it only with your consent, use it only for the two purposes in §4.1, and retain it until you delete it or delete your account.
We do not sell personal data as that term is defined under CCPA/CPRA. We have never taken money for it and we do not intend to.
"Sharing" has one exception, and it is opt-in. CPRA uses "share" narrowly, to mean disclosing personal information for cross-context behavioural advertising. If you accept marketing cookies on the website (§2.9), the Meta Pixel does exactly that: it discloses the pages you viewed on glucospike.ai to Meta so we can measure advertising. That is a "share" under CPRA and we are not going to call it anything else. It applies to website browsing only, it never happens unless you opt in, and you can withdraw it at any time through "Cookie settings" in the footer, which serves as our Do Not Sell or Share mechanism. Nothing from the app is ever shared this way.
Sensitive personal information is never involved. We do not use sensitive personal information to infer characteristics about you, and blood-glucose readings and Patterns are never used for advertising, never shared with Meta, and never leave the app for any advertising purpose.
California residents may exercise their rights — including the right to limit the use of sensitive personal information (§10.3) — by contacting us at support@glucospike.ai.
My Health My Data Act (Washington)
Blood-glucose readings and Patterns are both consumer health data under Washington's My Health My Data Act, which expressly covers measurements of bodily functions, vital signs and symptoms. We obtain your consent before collecting either, we do not sell consumer health data, and we would seek separate written authorization before ever doing so.
Website browsing. Washington's definition is broad, and reading a page named for a condition could reasonably be argued to say something about your health. We would rather treat it that way than argue the point. Washington is one of the places we deliberately keep on the opt-in side, so cookie-based analytics and marketing are both off there until you accept them (§2.9), the Meta Pixel is the only thing that would disclose such browsing to anyone else, and we do not sell it. Rejecting marketing cookies stops it entirely.
Washington residents (and anyone else who wants the detail) should read our dedicated Consumer Health Data Privacy Policy, which sets out the categories collected, the purposes, who it is shared with, and how to exercise your rights.
Privacy Act 1988 (Australia)
Blood-glucose readings and Patterns are health information, and therefore sensitive information under the Australian Privacy Principles. Under APP 3.3 we do not collect either without your consent, which we obtain as described in §2.3.
Under APP 8, we disclose that your data is stored outside Australia: Firebase (Google LLC) hosts it in the United States. Your readings and Patterns are not sent to the Gemini API (§5.1); other data, such as meal photos, is processed there. By consenting to the collection of readings you also consent to this overseas handling.
HIPAA
HIPAA does not apply to GlucoSpike AI. We are not a healthcare provider, a health plan, a healthcare clearinghouse, or a business associate of one, so we do not describe ourselves as "HIPAA compliant" — that would be misleading. The laws above are the ones that govern consumer apps like ours, and they are the ones we hold ourselves to.
COPPA
GlucoSpike AI is intended for adults 18 and older. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us immediately at support@glucospike.ai.
EU AI Act
GlucoSpike AI's use of AI for food wellness estimates is classified as minimal to limited risk under the EU AI Act. We are committed to transparency about AI interactions — users are informed when AI-generated results are provided. See our AI & Ethical Use Policy for full details.
12. Changes to This Policy
We may update this Privacy Policy as our practices change. We will notify users of material changes. Continued use of the app after changes constitutes acceptance of the updated policy. The "Last Updated" date at the top reflects the most recent revision.
13. Contact Us
For any privacy-related questions, requests, or concerns:
GlucoSpike LLC (Delaware, USA)
Email: support@glucospike.ai
GlucoSpike AI