아홉빛(AHopeBit)

GluLog Privacy Policy 본문

GluLog Privacy Policy

GluLog Privacy Policy

  • Drafted: July 22, 2026
  • Applicable release: 1.1.0 (versionCode 14)
  • Effective date: July 22, 2026

GluLog (the “App”) is a lifestyle app that helps users organize and review lifestyle
management records they enter themselves, including glucose, meals, exercise, medication,
and insulin. The App is not a medical device and does not diagnose, treat, cure, or prevent
any medical condition. Consult a qualified healthcare professional for medical advice,
diagnosis, or treatment.

The App's lifestyle positioning does not change the fact that applicable law or app-store
rules may classify some records as sensitive or health-related data. We protect those records
according to their nature.

1. Information We Process

1.1 Information You Enter or Select

  • Glucose values, timestamps, record slots, notes, tags, and parsed results from imported CGM CSV files
  • Meal type, time, and notes
  • Exercise type, time, duration, distance, calories, steps, elevation, and route
  • Medication and insulin records and reminder settings
  • Meter, record-slot, target-range, nickname, diabetes-type, and other App settings
  • Family-sharing connections and the limited records you choose to share
  • Inquiry category, subject, content, nickname, and optional email address

The original CGM CSV file is parsed on the device. The original file itself is not uploaded
to our server; extracted records may be synchronized if you enable account sync.

1.2 Account and Synchronization Information

If you sign in with Google and choose synchronization, your email address, account identifier,
authentication token, and synchronized records are processed through a cloud authentication
and database provider. If you do not sign in, records are generally stored only on your device.

1.3 Device, Advertising, and Usage Information

  • App and operating-system version, device model, language, and region settings
  • Approximate location inferred from IP address, advertising or app/device identifiers
  • Ad impressions, clicks, other advertising interactions, and SDK diagnostics
  • Limited screen and feature interactions if you enable optional usage analytics

Optional analytics is configured not to send glucose values, diabetes type, medication or
insulin details, user notes, or account UUIDs. Advertising information is processed according
to consent choices and applicable law.

1.4 Location

Precise location is used only when you start exercise-route tracking and grant location
permission. It supports route and distance calculation and map display.

1.5 In-App Support

When you submit an inquiry, nickname, optional email, message content, App version, device
information, language, and region settings are sent over encrypted HTTPS to a support relay
and then stored in a fixed channel maintained by a collaboration-messaging provider. The
Android App does not contain administrator credentials for that messaging provider.

2. Purposes of Processing

  • Store, display, analyze, import, and export lifestyle records
  • Provide optional sign-in, multi-device synchronization, and restoration
  • Provide family sharing at your request
  • Record exercise routes and display maps
  • Provide medication, insulin, post-meal, and prediction reminders
  • Receive inquiries, show support replies, and submit follow-up replies
  • Improve service quality through analytics you choose to enable
  • Provide, limit, secure, and measure advertising according to consent choices
  • Detect errors, maintain security, and meet legal obligations

3. Retention and Deletion

Category Retention rule
On-device records Until you reset records on this device or clear the App's data
Account and synchronized records Until the account or relevant records are deleted; provider backups and security logs may be retained on a restricted basis as needed for operations, security, and legal obligations
Family-sharing connection Until disconnected or related account deletion is completed
Inquiries and replies For support and dispute handling or according to the messaging workspace's retention setting
Optional analytics Until disabled and for the configured analytics-provider retention period
Advertising and consent data According to applicable law, consent, and provider retention policies

Information is deleted or de-identified when no longer required. Legal retention duties,
security logs, and provider backups may require restricted retention beyond the active service
period.

The App's “Reset Records on This Device” feature deletes only glucose, exercise, meal,
medication, insulin, meter, slot, and tag records stored on the current device. It does not
delete active records synchronized to the server, the authentication account, profile settings,
family connections, support records, or service-provider retained copies. If you later run
synchronization, server records may be restored to this device.

You may request deletion of your account and all associated server data through in-App Support
or the public deletion-request page. After verifying the requester, we revoke authentication
sessions and delete the account and associated server data. If applicable law, security records,
or service-provider backup expiry prevents immediate deletion of a limited subset, we explain
the reason and expected retention period.

4. External Processing Providers and Service Types

We describe services by purpose in the body of this policy. Company names are listed below
only so users can identify processors and other external providers.

Service type Provider Processing
Cloud authentication and database Supabase, Inc. Optional sign-in, account identifier, synchronization, family sharing
Sign-in, maps, analytics, and advertising Google LLC and applicable contracting affiliates Sign-in, maps, optional analytics, advertising, consent, diagnostics
Support relay network Cloudflare, Inc. and affiliates Inquiry delivery, network security, rate limiting, minimal error logs
Collaboration messaging Slack Technologies Limited or Slack Technologies, LLC Inquiry and reply thread storage and support handling

Advertising providers may process certain information under their own policies and your
consent choices. Advertising controls are available through device settings and the App's
privacy-options entry point.

5. International Transfers

Optional sign-in, synchronization, maps, analytics, advertising, and support may transfer or
store information outside your country over encrypted network connections.

Recipient Country Data and purpose Timing and method Retention
Supabase, Inc. The country hosting the production project and other service-support processing locations Account, sync, family sharing On sign-in or sync over HTTPS Section 3 and contracted backup settings
Google LLC and affiliates United States and other countries where Google operates processing infrastructure Sign-in, maps, optional analytics, advertising When the relevant feature or SDK is used over HTTPS Provider settings, policies, and consent
Cloudflare, Inc. and affiliates United States and global network processing locations Support relay and security On inquiry or reply over HTTPS The relay does not persist inquiry bodies; minimal error logs follow operational settings
Slack Technologies Limited or Slack Technologies, LLC Ireland or the United States and other service-processing locations Inquiry and reply storage On inquiry or reply over HTTPS Workspace retention setting and support needs

You may avoid or withdraw optional sign-in, sync, analytics, exercise maps, or support features.
Some processing by essential SDKs in an ad-supported free App may still be required to provide
the service.

6. Family Sharing

Family sharing operates only after you explicitly create or enter a sharing code. Shared fields
are limited to nickname and diabetes type, glucose value/time/slot, meal time, and exercise
time/duration needed for the dashboard. You can disconnect sharing in the App.

7. Your Choices and Rights

  • Grant or revoke location, notification, and other operating-system permissions.
  • Enable or disable optional usage analytics in Settings.
  • Reopen advertising consent choices through the App's privacy options.
  • Reset lifestyle records stored on the current device in the App.
  • Request deletion of the account and all associated server data through in-App Support or the
    public account-and-data-deletion page linked below.
  • Request access, correction, restriction, or withdrawal of consent for account-related data.

Account and related data requests: Settings > Support or ahopebit.labs@gmail.com

Public account and data deletion information:
GluLog Account & Data Deletion

We may request the minimum information needed to verify identity. The public deletion-request
page provides an email link or request form, and that public URL is registered in the Play
Console account-deletion field.

8. Security Measures

  • HTTPS/TLS in transit
  • A server relay that keeps support administrator credentials out of the Android App
  • Database access policies scoped to authenticated users
  • Per-inquiry encrypted tickets and install/IP rate limits
  • Optional analytics disabled by default and restricted by an event allowlist
  • Transactional Room deletion when resetting records on this device
  • Authentication-session revocation followed by account and associated server-data deletion for
    full-deletion requests
  • Data minimization, including restricted family-sharing fields

9. Children

The App is not designed for children. Users who require parental consent under applicable law
should not use account sync or support features without that consent.

10. Changes and Contact

We will announce material changes in the App or on the public policy page and identify the
effective date.

  • Operator: Ahopebit Labs
  • Privacy contact: ahopebit.labs@gmail.com

11. Account & Data Deletion

GluLog distinguishes resetting records on one device from deleting an account and its
associated server data.

  • Reset records on this device: In the App, go to Settings > Data Management > Reset
    Records on This Device
    . This deletes lifestyle records on the current device only. It does
    not delete synchronized server records or the authentication account, and server records may
    be downloaded again during a later synchronization.
  • Delete the account and associated server data: Submit a request through Settings >
    Support
    , email ahopebit.labs@gmail.com, or use the
    public deletion information page.
    After verifying the requester, we delete the authentication account and associated server
    data, normally within 30 days of receiving the request. If legal retention duties, security
    records, or service-provider backup expiry prevents immediate deletion of a limited subset,
    we explain the affected scope and retention period.
  • You may separately revoke GluLog's access through
    Google Account third-party connections. Revoking
    access alone does not complete a deletion request for the GluLog account or server data.