Last updated: September 2026

This Privacy Policy describes how Gludiary (“the App”) handles your information. We are committed to protecting your privacy, and we take particular care with health data. The controller is Muhammet Emre Yılmaz, Hannover, Germany — see Section 8 for the identification required by Art. 13 GDPR and our Impressum for full provider details.

1. Information We Collect

The App does not require you to create an account or provide your name or email address. The following categories of data are processed:

  • Blood glucose readings – The glucose value, measurement timestamp, meal context (e.g. fasting, before/after meal, bedtime), notes, tags, and optional carbohydrate and insulin details that you enter manually. Stored on your device.
  • Health profile – Diabetes type, age group, and preferred measurement unit (mg/dL or mmol/L) entered during onboarding. Stored on your device via UserDefaults.
  • Target range – Your personal low and high glucose thresholds. Stored on your device.
  • Medication records – Medication name, dose, and frequency that you enter in the Medication Tracker. Creating and editing medications is a Premium feature; viewing and deleting your existing records is always free. Stored on your device.
  • Reminders – Scheduled notification times you configure. Stored on your device; notification delivery is handled entirely on-device by iOS.
  • App settings – Language preference, colour scheme, accessibility options. Stored on your device via UserDefaults.

We do not collect your name, email address, precise location, or any other personally identifiable information directly.

2. Health Data Storage

All glucose readings, medication records, and health profile data are stored entirely on your device using Apple’s SwiftData framework. There is no automatic cloud synchronisation of your health data. Your data never leaves your device except via Apple Health (if you grant permission, see Section 3) or a manual backup export you initiate yourself from within the App.

This local-only approach means your sensitive health information is under your direct control at all times — we cannot access it, and it is not transmitted to our servers or to any third-party cloud storage service.

If you wish to transfer your data to another device, you can use the manual JSON backup and restore feature available in the App settings.

3. Apple Health (HealthKit)

With your permission, the App can read and write blood glucose data to and from the Apple Health app.

  • Writing: When you save a reading in Gludiary, it can be written to Apple Health as a blood glucose sample so that other health apps and your Apple Watch can access it.
  • Reading: The free plan includes a one-time import of blood glucose samples previously recorded in Apple Health, covering approximately the last 90 days. Gludiary Premium can keep importing new readings on an ongoing basis rather than only once.

Gludiary never transmits HealthKit samples to our servers, and never to advertising, analytics or crash reporting. Note that writing a reading into Apple Health is what makes it available to other apps you have authorised and to your Apple Watch, as described above; that sharing happens inside Apple Health under your control and is governed by Apple’s terms and by those apps’ own policies, not by this policy. You can grant or revoke Gludiary’s permission at any time in iOS Settings › Health › Data Access & Devices.

4. Advertising & App Tracking Transparency

The App displays interstitial advertisements powered by Google AdMob for users who have not subscribed to Gludiary Premium. Non-personalised ads are shown by default. The App will ask for your permission using Apple’s App Tracking Transparency (ATT) framework before showing personalised ads.

  • Default (no ATT permission): Only non-personalised ads are shown. Your device’s advertising identifier is not used for targeting or measurement.
  • If you grant ATT permission: Google AdMob may use your device’s advertising identifier (IDFA) to show you personalised ads and measure ad performance.

No health data (glucose values, diabetes type, or any other health information) is ever used for ad targeting, regardless of your ATT choice.

In the European Economic Area, the App also asks for your consent under EU privacy law (via Google’s User Messaging Platform) before requesting any advertising identifier.

You can change your ATT choice at any time in iOS Settings › Privacy & Security › Tracking.

Google AdMob Privacy Policy: policies.google.com/privacy

Subscribing to Gludiary Premium permanently disables all advertising and ATT data collection within the App.

5. Third-Party Services

The App uses the following third-party services:

  • RevenueCat – Processes and verifies your Gludiary Premium subscription. RevenueCat receives a pseudonymous user identifier and your Apple purchase receipt. No health data is shared. Privacy Policy
  • Mixpanel – Collects product-usage analytics to help us understand how the App is used and improve it. Events are linked to a device identifier rather than to your name. That identifier is persistent, so the data is pseudonymous, not anonymous: it remains personal data under the GDPR because it can be linked back to your installation. Events may include attributes such as diabetes type category, diagnosed-status, age group, and per-reading status classification (e.g. in-range, high, low). As explained in Section 8, those are health data under Art. 9 GDPR. They are used only to improve the product, never for advertising or marketing. Raw glucose values and note text are never included in any analytics event. For users in the European Economic Area (EEA), these health attributes are not collected at all (region-gated). Apple Health/HealthKit samples are never transmitted to Mixpanel or our servers. Privacy Policy
  • Sentry – Collects crash reports and error logs to help us improve stability. Reports include the device model, iOS version, and app version, tied to a pseudonymous identifier rather than to your name. No health data (glucose values, medication records, etc.) is included in crash reports. Privacy Policy

6. Medical Disclaimer

The blood glucose values, A1C estimates, and statistical summaries calculated by the App are for informational and self-monitoring purposes only. They are not a substitute for professional medical advice, diagnosis, or treatment. Always consult your doctor or qualified healthcare professional regarding the management of your diabetes or any other medical condition.

7. Data Retention & Deletion

Your glucose readings, medication records, and health profile remain on your device until you delete them. You can delete individual readings from the History screen. To remove data in bulk, go to Settings › Privacy & Data › Delete All Data, which opens a selection sheet where you can choose which categories of data to delete (glucose readings, medications, reminders, profile information, and/or settings) — you are not required to delete everything at once. Deleting the App also removes all locally stored data.

8. Your Rights Under the GDPR

Controller. The controller for the processing described in this policy, within the meaning of Art. 4(7) GDPR, is Muhammet Emre Yılmaz, Hildesheimer Str. 120, 30173 Hannover, Germany, support@gludiary.com. Full provider details are in our Impressum. We are established in Germany, within the European Union, so the GDPR applies to us directly and no Art. 27 representative is required. We are not obliged to appoint a Data Protection Officer under Art. 37 GDPR; privacy enquiries go to the address above.

Health data is a special category. Your glucose readings, diabetes type, medication records, carbohydrate entries and target range are data concerning health under Art. 4(15) GDPR and fall under Art. 9. As set out in Section 2, they stay on your device: we do not receive them and have no access to them.

Where the GDPR applies to us. Because we are established in Germany, the GDPR governs our processing under Art. 3(1) regardless of where you live. Being outside the European Economic Area does not remove that protection. The analytics attributes described in Section 5 — diabetes type, diagnosed status, and the in-range/high/low classification of a reading — are health data, not merely health-adjacent, and Art. 9 therefore applies to them wherever the user is. They are not collected from users in the EEA at all. Art. 9 permits such processing only on a narrow basis, in practice your explicit consent under Art. 9(2)(a); a legitimate-interest basis is not sufficient for it.

Legal bases. Where we do process personal data, we rely on:

  • Art. 6(1)(b) – performance of the contract you enter into when you purchase Gludiary Premium: subscription verification through RevenueCat (Section 5).
  • Art. 6(1)(f) – our legitimate interest in a stable, functioning app: crash reporting through Sentry, and product-usage analytics that carry no health attributes (Section 5). This basis does not extend to the health attributes described above, and we do not rely on it for them.
  • Art. 6(1)(a) – your consent, which you may withdraw at any time: personalised advertising and any use of your advertising identifier (Section 4). The legally relevant consent is the one collected through Google’s consent flow in the EEA. Apple’s ATT prompt is a separate platform permission for cross-app tracking and access to the advertising identifier; it is not itself GDPR consent. Independently of the GDPR, § 25 TDDDG requires consent for storing information in, or reading information from, your device unless it is strictly necessary to provide the service you asked for — and that covers SDK identifiers and consent records, not only the advertising identifier.

Your rights. You have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict processing (Art. 18), to receive it in a portable format (Art. 20), to object to processing based on our legitimate interests (Art. 21), and to withdraw any consent with effect for the future (Art. 7(3)). Over your health data these rights are immediate and do not require us: it is on your device, so you already have direct access, correction, deletion and export through the App itself, as described in Sections 2 and 7. For the limited data held by the providers in Section 5, write to support@gludiary.com. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. Exercising these rights is free of charge.

International transfers. Some of the providers in Sections 4 and 5 — RevenueCat, Google AdMob, Mixpanel and Sentry — are established outside the European Economic Area or may process data outside it. Any such transfer requires a safeguard under Chapter V of the GDPR, which in practice means the European Commission’s Standard Contractual Clauses or, for a certified US recipient, the EU–US Data Privacy Framework. The mechanism differs per provider and follows the data-processing agreement we have with that provider; write to us and we will tell you which one applies to a given recipient and let you see the relevant safeguards.

Right to lodge a complaint (Art. 77). If you believe we have handled your data unlawfully, you may complain to a supervisory authority. The authority responsible for us is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
Hannover, Germany · lfd.niedersachsen.de

You may also complain to the supervisory authority in the EU or EEA country where you live or work, or where you believe the infringement took place. We would appreciate the chance to resolve the matter first, but you are not required to contact us before complaining.

9. CCPA (California Users)

We do not sell your personal information. For advertising purposes, Google AdMob may use your IDFA only with your explicit ATT consent. You may opt out at any time as described in Section 4 above.

10. Children’s Privacy

The App is not directed at children. We do not knowingly collect personal information from children. Where an information-society service is offered directly to a child and the processing rests on consent under Art. 6(1)(a), Art. 8 GDPR requires the authorisation of the holder of parental responsibility below the age of 16 in Germany. Separately, and on its own terms, the United States’ COPPA regime applies to children under 13. If you believe a child has used the App without the required authorisation, please contact us and we will take appropriate steps.

11. Changes

We may update this Privacy Policy from time to time. We encourage you to review it periodically. Continued use of the App after changes constitutes acceptance of the updated policy.

12. Contact

Muhammet Emre Yılmaz, trading as LuvleeLab
Hildesheimer Str. 120, 30173 Hannover, Germany
support@gludiary.com

Full provider details: Impressum.