Consumer Health Data Privacy Policy
Eating Glasses LLC
Effective Date: June 24, 2026
Last Updated: June 24, 2026
This policy describes how we handle "consumer health data" under Washington's My Health My Data Act (MHMDA) and Nevada SB 370. It is separate from, and read together with, our Privacy Policy and Terms of Service.
1. Who we are
Eating Glasses is a direct-to-consumer wellness app operated by Eating Glasses LLC. We are not a healthcare provider, health plan, or insurer, and we do not provide medical advice, diagnosis, or treatment. As a direct-to-consumer wellness app we are not a HIPAA-covered entity or business associate; the data you provide to us is not protected by HIPAA, which is one reason we publish this policy and apply the protections described here.
2. What "consumer health data" we collect
- Glucose data read from Apple Health (HealthKit) — your continuous glucose monitor (CGM) readings, with timestamps.
- Activity & sleep data you choose to authorize from Apple Health (for example steps, active energy, or sleep) — used only for context.
- Patterns we derive from the above (e.g., "tends to run higher in the evening"). These derived patterns are themselves consumer health data and are treated as such.
- Account data you provide — the email and password you create, or a Sign in with Apple identifier (which may be a private-relay email) — to create and secure your account.
- Food & meal data (Premium): when you use food scanning, the food you photograph, describe by voice, or type, and the resulting estimated nutrition (carbs/macros). The photo, voice clip, and request are processed transiently to estimate nutrition and are never stored; only the estimated nutrition is saved to your meal history. To the extent any of this is consumer health data, we treat it as such. Glucose is never included in a food request.
- We do not collect: precise location for health inference, contacts, or advertising identifiers tied to health data.
3. Where it comes from (sources)
- Apple HealthKit, only after you grant per-type read permission, which you can revoke in iOS Settings at any time.
- Direct input from you (account info; optional answers to a single occasional in-app question used to personalize an insight).
4. How we use it
- To analyze your glucose patterns on your device and show you wellness observations and educational suggestions.
- To let you review your own trends and prepare summaries for your own care team.
- We do not use your health data for advertising, marketing, profiling for ads, or to train third-party AI models. We never send your glucose data (including derived patterns) to any third-party AI/LLM service.
- Food inputs (photo/voice/text) are processed by our AI provider (Google Gemini) solely to estimate nutrition; they are transient, not stored, not used for advertising, and not used to train third-party AI models.
5. Who we share it with
- Processors only, acting on our behalf under contract (Data Processing Agreements), solely to provide the service: Supabase (encrypted database hosting), Railway (application hosting), Google Gemini via our Railway API server (receives the transient food photo/voice/text only to estimate nutrition; never your glucose, not used to train AI models, does not retain the input), and Apple (as the source platform and for app delivery).
- Categories of third parties / affiliates: the only third parties that receive consumer health data are service providers (processors) in the categories of cloud database/storage hosting, application hosting, and AI nutrition estimation — the specific processors named above. They are a subset of the processors in our general Privacy Policy; the others (such as crash diagnostics and subscription management) do not receive consumer health data. We have no affiliates with which we share it.
- Who can access it: access is limited to the processors above and to our own personnel who need it to operate, support, or secure the service, under confidentiality obligations.
- The only categories of consumer health data shared are those listed in §2, shared only with those processors to operate the service.
- We do not sell your consumer health data, and we do not share it with any third party for that third party's own purposes. A sale would require a separate, MHMDA-compliant authorization — a distinct, more rigorous instrument than the consent in §7, with the specific content elements and one-year expiry the statute requires — which we do not seek and do not use.
- No geofencing. We do not, and will not, use a geofence around any healthcare facility, provider, or other location to identify, track, collect data from, or send messages to consumers (RCW 19.373.050).
6. Your rights (and how to use them)
You may, at any time, exercise the rights below, and we will respond within 45 days of receiving your request (extendable once by an additional 45 days where reasonably necessary, with notice to you):
- Access / confirm what consumer health data we hold about you.
- Delete your consumer health data. On your request we will delete it from all parts of our systems, including archived and backup systems, and direct our processors to delete it as well. We remove it from active systems promptly; residual copies in encrypted backups are purged on our standard rotation no later than 90 days, after which they are unrecoverable.
- Withdraw consent to our collection and processing.
To exercise these rights: use Settings → Delete Account in the app (which deletes your account and its consumer health data), revoke Apple Health access in iOS Settings (which stops the App from reading your glucose and activity), or email privacy@eatingglasses.com. If we deny your request, you may appeal by replying to our decision email; we will respond to the appeal within 45 days. If we deny the appeal, you may contact the Washington State Attorney General (Washington residents) or the Nevada Attorney General (Nevada residents).
7. Consent
We collect and process your consumer health data only after you give clear, opt-in consent that is distinct from our Terms of Service, together with the separate, per-type Apple Health permission you grant in iOS. This consent (for collection and processing) is separate from an authorization (which the law requires only for a sale — we never seek one). You can withdraw consent at any time, with the same ease you gave it, by revoking Apple Health access in iOS Settings and deleting your account or on-device data; withdrawal stops future processing and you may also request deletion.
Minors. For a user aged 13–17, a parent or legal guardian must be the account holder and provide this consent on the minor's behalf. We do not knowingly collect consumer health data from anyone under 13.
8. Security
We encrypt consumer health data in transit and at rest to recognized standards. We do not upload your glucose data to our servers or to iCloud. We maintain a breach-response procedure consistent with the FTC Health Breach Notification Rule.
9. Changes & contact
We will post changes here and, for material changes affecting consumer health data, obtain renewed consent where required. Contact: privacy@eatingglasses.com, Eating Glasses LLC, 1717 N St NW #1, Washington, DC 20036.
