← glucose.center · Deutsch · PDF
Privacy Policy
1. Controller
The controller under the GDPR is the operator of glucose.center (“we”, “us”). A named legal entity / commercial register entry may be added later; until then, use the contact below.
Email (general / privacy): info@glucose.center
Security / abuse: security@de.glucose.center
Website: https://glucose.center
Authentication: https://auth.glucose.center
No separate Data Protection Officer is currently appointed. Privacy requests: info@glucose.center.
2. Purposes — why we process data
glucose.center processes personal data, including health data, for:
- Overview of your data — displaying and visualising your own measurements and health data (e.g. glucose trends, statistics such as time-in-range / GMI, Withings metrics, sleep) in the web app and iOS app.
- Sharing with doctors you select — only after your explicit invite/grant; you control who gets access and can revoke it.
- Research on new algorithms — developing and improving analytics and visualisation algorithms. Where possible we use anonymised or aggregated data without identifying individuals. Where personal health data is needed for R&D, processing is based on your consent (Art. 9(2)(a) GDPR) for the purposes described here; you may withdraw consent at any time.
- Providing your account, authentication, and operating the platform.
- Optional third-party connections (Dexcom, Withings) and optional push / Live Activity notifications (Apple).
3. Categories of data
- Account data (Keycloak at auth.glucose.center): email, authentication data, optional profile fields, timestamp of terms/privacy acceptance.
- Health and measurement data: glucose values (EGVs) and related metadata via Dexcom Share and/or Dexcom OAuth; manual entries (e.g. insulin, carbs, notes); Withings measurements (weight, body composition, blood pressure, sleep, etc., as you allow); optional emergency contacts.
- Doctor sharing: invite details and status for doctors you choose.
- Device / push data: tokens and parameters for Apple Push Notification service (APNs) / Live Activities if you use the iOS app.
- Technical logs: short-lived server and audit events (including hashed IP addresses) for security and troubleshooting.
4. Legal bases
- Art. 6(1)(b) GDPR (contract): account, overview/visualisation of your data, delivering features you request.
- Art. 6(1)(a) and Art. 9(2)(a) GDPR (consent): special-category health data, Dexcom/Withings connections, doctor sharing, algorithm research involving personal health data, APNs/Live Activities as needed.
- Art. 6(1)(f) GDPR (legitimate interests): IT security, abuse prevention, anonymous/aggregated product metrics — balanced against your interests.
You give consent at account creation (checkbox / Keycloak terms) and again when connecting integrations. Withdraw anytime for the future via settings, disconnecting integrations, or info@glucose.center.
5. Recipients and transfers
- Hosting / infrastructure in the EU (servers for glucose.center and auth.glucose.center).
- Keycloak authentication at auth.glucose.center.
- Dexcom if you connect Share and/or OAuth — Dexcom’s own privacy terms also apply.
- Withings if you connect Withings — Withings’ privacy terms also apply.
- Apple (APNs) for push/Live Activities; processing may occur outside the EU as provided by Apple (appropriate safeguards / SCCs as applicable).
- Doctors you select — only within your grant.
We do not sell your health data.
6. Storage and security
Content data (readings, tokens, settings, etc.) is encrypted at rest with AES-GCM (per-user authenticated associated data). Transport uses TLS (HTTPS).
Retention: while your account exists and data is needed for the purposes above. After account deletion we remove related personal content data; technical logs may remain briefly for security, then are deleted or anonymised. Anonymised/aggregated research data without personal identifiers may continue to be used.
7. Your rights
Where applicable you have rights of access, rectification, erasure, restriction, portability, and objection, and to withdraw consent. Export and account deletion are available in the product. You may lodge a complaint with a supervisory authority (e.g. your local EU/EEA data protection authority).
8. Cookies and similar technologies
We use technically necessary cookies/storage for login and session (e.g. OAuth/PKCE state, session tokens). We do not use third-party advertising or tracking cookies. Theme preference may be stored locally in your browser.
9. Not a medical device / not medical advice
glucose.center is not a medical device and does not replace clinical advice, diagnosis, or treatment, or an approved CGM/measurement system. Health decisions belong with you and your clinician. Algorithms and visualisations support overview and research/improvement — not clinical decision-making.
10. Changes
We may update this policy when services or law change. The current version is at https://glucose.center/privacy and as PDF at /legal/privacy.pdf. Material changes will be announced on the site or by email where feasible.