Privacy Policy

Last updated: 22 September 2026 · Operator of glucose.center

1. Controller

The controller under the GDPR is the operator of glucose.center (“we”, “us”). A named legal entity / commercial register entry may be added later; until then, use the contact below.

Email (general / privacy): info@glucose.center
Security / abuse: security@de.glucose.center
Website: https://glucose.center
Authentication: https://auth.glucose.center

No separate Data Protection Officer is currently appointed. Privacy requests: info@glucose.center.

2. Purposes — why we process data

glucose.center processes personal data, including health data, for:

  1. Overview of your data — displaying and visualising your own measurements and health data (e.g. glucose trends, statistics such as time-in-range / GMI, Withings metrics, sleep) in the web app and iOS app.
  2. Sharing with doctors you select — only after your explicit invite/grant; you control who gets access and can revoke it.
  3. Research on new algorithms — developing and improving analytics and visualisation algorithms. Where possible we use anonymised or aggregated data without identifying individuals. Where personal health data is needed for R&D, processing is based on your consent (Art. 9(2)(a) GDPR) for the purposes described here; you may withdraw consent at any time.
  4. Providing your account, authentication, and operating the platform.
  5. Optional third-party connections (Dexcom, Withings) and optional push / Live Activity notifications (Apple).

3. Categories of data

4. Legal bases

You give consent at account creation (checkbox / Keycloak terms) and again when connecting integrations. Withdraw anytime for the future via settings, disconnecting integrations, or info@glucose.center.

5. Recipients and transfers

We do not sell your health data.

6. Storage and security

Content data (readings, tokens, settings, etc.) is encrypted at rest with AES-GCM (per-user authenticated associated data). Transport uses TLS (HTTPS).

Retention: while your account exists and data is needed for the purposes above. After account deletion we remove related personal content data; technical logs may remain briefly for security, then are deleted or anonymised. Anonymised/aggregated research data without personal identifiers may continue to be used.

7. Your rights

Where applicable you have rights of access, rectification, erasure, restriction, portability, and objection, and to withdraw consent. Export and account deletion are available in the product. You may lodge a complaint with a supervisory authority (e.g. your local EU/EEA data protection authority).

8. Cookies and similar technologies

We use technically necessary cookies/storage for login and session (e.g. OAuth/PKCE state, session tokens). We do not use third-party advertising or tracking cookies. Theme preference may be stored locally in your browser.

9. Not a medical device / not medical advice

glucose.center is not a medical device and does not replace clinical advice, diagnosis, or treatment, or an approved CGM/measurement system. Health decisions belong with you and your clinician. Algorithms and visualisations support overview and research/improvement — not clinical decision-making.

10. Changes

We may update this policy when services or law change. The current version is at https://glucose.center/privacy and as PDF at /legal/privacy.pdf. Material changes will be announced on the site or by email where feasible.