Privacy policy
Last updated: 2026-09-12
GlucoBeat processes health data. That's why this policy is clear and specific: which data, what for, on what legal basis, with whom, for how long and how to exercise your rights.
1. Data controller
Diego Manuel Béjar Santiago · Tax ID 10880184B · C/ Cardenal Benlloch, 74, esc. izq., 1-1, 46920 Mislata (Valencia), España · privacidad@glucobeat.com. Data Protection Officer: Diego Manuel Béjar Santiago · privacidad@glucobeat.com.
2. What data we process and why
| Data | Purpose | Legal basis |
|---|---|---|
| Email, name (optional), language, sessions and devices | Create your account, give you access and keep it secure | Performance of a contract (art. 6.1.b GDPR) |
| Profile photo (optional): the one you upload or, only if you choose it, a copy of your Google photo | Show it to you and to the people you share your data with | Your consent (art. 6.1.a GDPR) |
| Health data: glucose, meals, exercise, insulin, medication, sleep, notes, diabetes type, treatment and targets | Store it, show it to you and compute statistics for you | Explicit consent (art. 9.2.a GDPR) |
| Anonymised summary of your data for the chosen period | AI analysis and “Can I eat this?”, only when you ask | Specific explicit consent (art. 9.2.a) |
| Birth year, sex, height and weight (optional) | Give context to statistics and analyses, always as ranges | Specific explicit consent (art. 9.2.a) |
| LibreLinkUp credentials (encrypted) | Sync your readings automatically (beta) | Specific explicit consent (art. 9.2.a) |
| Email of the people you invite and log of their access | Share your data in read-only mode | Your consent (arts. 6.1.a and 9.2.a) |
| Technical and security logs (pseudonymised IP, account actions) | Security, abuse prevention and proof of compliance | Legitimate interest (art. 6.1.f) and legal obligation (art. 6.1.c) |
| Email for news (optional) | Send you news at most once a month | Consent (art. 6.1.a) |
We don't make automated decisions with legal effects on you. AI analyses are informational and are not medical advice.
3. Artificial intelligence
Only if you explicitly accept it and each time you ask, we send Anthropic, PBC (provider of the Claude model, acting as data processor) an anonymised summary: no name, email, identifiers or real dates (only relative days and times), with free text scrubbed of emails, phone numbers and links. Anthropic processes this data under its data processing agreement and does not use it to train models. We store the summary sent and the answer so you can review or delete them.
4. Recipients and processors
- Hosting and database: Amazon Web Services EMEA SARL (región UE), on servers located in the European Union.
- Email delivery: Twilio SendGrid (login codes, invitations and notices), without open or click tracking.
- Artificial intelligence: Anthropic, PBC (only anonymised summaries and only with your consent).
- Sign in with Google (optional): Google receives your sign-in as an independent controller under its own policy. From Google we receive your email, your name and the address of your profile photo; the photo is only copied if you choose to use it.
- LibreLinkUp (optional): we access Abbott's platform on your behalf to read your readings.
- People you invite: they see your charts and events in read-only mode for the period you choose.
We don't sell your data or share it for advertising.
5. International transfers
SendGrid and Anthropic may process data in the United States. These transfers rely on the EU-US Data Privacy Framework where the provider is certified and, in any case, on the European Commission's Standard Contractual Clauses, with additional measures (encryption in transit and, for AI, prior anonymisation).
6. Retention
- Health and account data: while you keep your account. If you delete it, it is removed immediately and permanently from the database; encrypted backups are overwritten within 7 days at most.
- Imported CSV files: not stored (only their fingerprint and a summary).
- AI analyses: until you delete them or your account.
- Followers' access log: 12 months. Security and audit logs: 24 months, without health data.
- One-time codes: expire after 10 minutes and are deleted within 24 hours.
7. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability, and withdraw any consent at any time without affecting the lawfulness of prior processing. Most of them can be exercised directly in the app: Settings → Privacy (consents) and Settings → My data (full JSON download and permanent deletion with an email code). For anything else, write to privacidad@glucobeat.com. If you are not satisfied, you can complain to your data protection authority (in Spain, the Agencia Española de Protección de Datos, www.aepd.es).
8. Security
Encrypted connections (TLS), database encrypted at rest in the EU, third-party credentials encrypted with AES-256-GCM, sessions with random tokens of which we only store a fingerprint, one-time codes with attempt limits, a log of access to your shared data, and a data protection impact assessment.
9. Minors
GlucoBeat is intended for people aged 16 and over. Between 14 and 16, and under 14, only with the authorisation of a parent or legal guardian, who will manage the account.
10. Changes
If we change this policy in a relevant way we will tell you in the app and, when it affects a consent, we will ask for it again.