Privacy Policy
Eating Glasses LLC
Effective Date: June 24, 2026
Last Updated: June 25, 2026
1. Introduction
Eating Glasses LLC ("we," "us," "our") operates the Eating Glasses mobile application (the "App") — a general wellness app that helps people who use insulin understand their own glucose patterns. This Privacy Policy explains what personal information we collect, how we use and protect it, and the choices and rights you have. By using the App you acknowledge you have read this Policy. Read it together with our Terms of Service and our Consumer Health Data Privacy Policy (Section 16).
2. Who We Are (Data Controller)
Eating Glasses LLC, 1717 N St NW #1, Washington, DC 20036, United States · privacy@eatingglasses.com · https://eatingglasses.com. For EEA/UK users, an Article 27 representative will be identified here before the App is offered in those regions.
3. Information We Collect
3.1 Information you provide
- Account information: the email and password you provide at sign-up, or the identifier from Sign in with Apple (which may be an Apple private-relay email). Plus your date of birth (DOB used only to verify the 13+ minimum age; stored as a protected field).
- Wellness profile: diabetes type, experience level, and who the app is for (yourself or someone you care for) — all optional and used only to tailor language and which insights are relevant.
- Food & meal data (Premium): the foods you photograph, describe by voice, or type, plus the estimated nutrition (carbs/macros). The photo or voice clip is processed transiently to identify the food and is NOT retained; only the resulting estimated nutrition is saved to your meal history. Food scanning is a Premium feature — the free tier does not include it, and no food photos or audio are stored.
- Feedback: ratings/comments you choose to submit.
3.2 Glucose & health data from Apple Health
With your explicit, separate, per-type iOS permission, the App reads your blood glucose, plus any activity or sleep data you choose to authorize (for example steps, active energy, or sleep), from Apple Health — only the data types you authorize, used only for on-device context. This data is read and analyzed on your device (see Section 5). We do not require you to log anything.
3.3 Information collected automatically
- Device & diagnostic info (device type, OS version, app version) for compatibility/troubleshooting.
- Crash reports — anonymous; never include glucose values, patterns, or health data.
- Anonymous product analytics (optional): a small set of usage events tied to a random, per-install identifier (not your name, email, or advertising ID), stored in our own backend (Supabase) — we use no third-party analytics SDK (no PostHog, Amplitude, Segment, Mixpanel, or similar). These events never contain glucose values, patterns, diabetes type, or any health data.
3.4 Information we do NOT collect or do
- We do not sell your personal information.
- We do not share health data with advertising networks, data brokers, or third-party analytics for their own purposes.
- We do not use your information for cross-context behavioral advertising.
- We do not collect precise geolocation.
- Do Not Track: because there is no common industry standard for "Do Not Track" signals, the App does not respond to them; regardless, we do not track you across third-party apps or websites for advertising.
4. How We Use Your Information
- Provide the core wellness experience: analyze your glucose patterns and surface plain-language observations and general wellness ideas to consider.
- Tailor presentation: use your wellness profile to choose relevant insights and language.
- Operate your account: authenticate you, manage your session and subscription.
- Communicate: account-related service or security messages, including password reset. We do not send marketing email.
- Improve the App: diagnose crashes and fix problems. We do not use individual health data for product analytics.
Legal bases (EEA/UK): performance of a contract (Art. 6(1)(b)); explicit consent for health data, a special category (Art. 9(2)(a)) — withdrawable anytime; legitimate interests (Art. 6(1)(f)) for security and fixing crashes; legal obligation (Art. 6(1)(c)).
5. How We Analyze Your Data
Your glucose — on your device, never to an AI. Glucose is read from Apple Health and analyzed entirely on your device by a fixed, rules-based engine. It is not uploaded to our servers and is never sent to any artificial-intelligence or large-language-model service, or to any third party. The engine is deterministic. We do not operate a server-side CGM integration; glucose is read on-device only. (A runtime guard enforces that glucose can never be included in any AI request.)
Food scanning (Premium) — processed by our AI. When you scan a food (photo), describe it by voice (audio), or type it, that input is sent to our secure API server and processed by Google Gemini (an AI model) solely to identify the food and estimate its nutrition. The photo, voice clip, and request are transient — not stored beyond the request — and are not used to train AI models; only the resulting estimated nutrition is saved to your meal history. Glucose is never part of a food request, and food scanning requires a connection (it is not on-device).
You share a summary (e.g., with your care team) only when you choose to.
6. Apple Health
HealthKit data is read from your device only after you grant permission, and only the data types you authorize. We use it solely to show your patterns and wellness insights within the App. We do not use HealthKit data for advertising and never sell it. You can revoke access anytime in iOS Settings. Per Apple's requirements, HealthKit data is never used for marketing or sold.
7. Data Storage and Security
- What we store in the cloud: your account + saved meal nutrition — email, DOB, wellness profile, feedback, and the estimated nutrition from foods you scan (nutrition only — no food photos or audio, and no glucose values, are stored) — in Supabase (database/auth/storage), with our API server on Railway. Both operate in the United States. Your glucose values and derived patterns are NOT stored on our servers (they stay on your device per Section 5).
- All data in transit is encrypted with TLS; data at rest in Supabase is encrypted (AES-256); sensitive fields receive additional application-layer AES-256-GCM encryption.
- Access is enforced by Row-Level Security: your records are accessible only by your authenticated account, which is identified by a pseudonymous UUID (no legal name required).
- No method of storage is 100% secure; use a strong device passcode and keep iOS updated.
8. Payment Processing
Subscription payments are processed by the Apple App Store — we never see or store card details. Subscription status is managed by RevenueCat, which receives a pseudonymous app-user identifier and Apple-provided purchase/transaction data (product, price, country, transaction and original-transaction IDs, and renewal status), used solely to manage your subscription entitlements. The full subscription terms (price, auto-renewal, any trial, and cancellation) are described in our Terms of Service, Section 4.
9. Third-Party Service Providers
We share the minimum necessary with these processors, each under a data-processing agreement and none authorized to use your data for their own marketing:
| Service | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, storage | Email, DOB, wellness profile, feedback, saved meal nutrition |
| Railway | API server hosting | Account/auth + food-scan requests (no glucose) |
| Google Gemini (via our API server) | Food identification + nutrition estimation | Food photos/text (transient; never glucose) |
| RevenueCat | Subscription entitlements | Pseudonymous app-user ID, Apple purchase/transaction data |
| Apple | App Store billing; Apple Health (on-device) | Purchase records; glucose read on-device with permission |
| Sentry | Crash & error diagnostics | Anonymous, scrubbed crash/error reports (never health data) |
| Expo / EAS | App framework + over-the-air updates | App version |
(Glucose is never sent to any AI/LLM provider — a runtime guard enforces it. Food photos/audio/text are processed by Google Gemini transiently — see §5. Any product analytics are privacy-preserving, carry no glucose or health data, and are not shared with a third-party analytics provider for that provider's own purposes.)
10. Data Sharing and Sale
We do not sell your personal information and do not "share" it for cross-context behavioral advertising (as defined under CCPA/CPRA). We disclose only: to the processors in Section 9 to operate the App; to comply with law; to protect rights/safety; or in a merger/acquisition (with notice, honoring this Policy). For consumer health data specifically, any transfer in a merger or acquisition will be handled consistent with our Consumer Health Data Privacy Policy, including obtaining your authorization where required by law.
11. Data Retention
- Glucose values & patterns: kept on your device; removed when you delete the App or the App's on-device data.
- Meal nutrition results: kept in your meal history until you delete them or your account. Food photos, voice clips, and the AI requests themselves: not retained beyond the request (never stored).
- Account & profile: retained for the life of your account; deleted when you delete your account.
- Crash diagnostics: retained briefly for troubleshooting, then deleted.
When you delete your account (Section 12), we permanently remove your data from our active systems promptly and instruct our processors to do the same. Residual copies in encrypted backups are deleted on our standard backup-rotation cycle (no later than 90 days), after which they are unrecoverable.
12. Your Privacy Rights
All users: access (your data is visible in the App), correction (edit in the App), deletion (Settings → Delete Account, which completes within the App on its own — your data is removed from our active systems promptly and from encrypted backups within 90 days per Section 11; deletion cannot be undone; you may additionally email privacy@eatingglasses.com), and withdraw consent (disable Apple Health in iOS Settings and delete on-device data).
California (CCPA/CPRA): rights to know, delete, correct, opt out of sale/sharing, and limit the use of sensitive personal information. We collect health information, which is sensitive personal information under the CPRA. Because we use sensitive personal information only for purposes permitted under CCPA Regulations §7027(m) (providing the wellness service you requested, plus security and debugging) and do not use or disclose it to infer characteristics about you, the "Limit the Use of My Sensitive Personal Information" right does not apply; we nonetheless describe those uses here so they are visible to you. We do not sell or "share" personal information, so there is nothing to opt out of, and we do not engage in automated decision-making that produces legal or similarly significant effects. We honor non-discrimination and respond to verifiable requests within 45 days (extendable once as permitted). Categories collected in the past 12 months: identifiers (email, pseudonymous ID), age (DOB), and health information you authorize (glucose read on-device; wellness profile). Retention by category: identifiers and age are kept for the life of your account and deleted on account deletion (backups within 90 days, per Section 11); the health information you authorize is analyzed on-device and is not retained on our servers; saved meal nutrition is kept until you delete it or your account; crash/diagnostic data is kept only briefly.
EEA/UK (GDPR): access, rectification, erasure, restriction, portability, objection; withdraw consent anytime. US data transfers rely on Standard Contractual Clauses; you may complain to your supervisory authority.
Contact privacy@eatingglasses.com to exercise any right.
13. Children's Privacy
The App is not intended for children under 13. We verify age via DOB before account creation and block under-13 accounts. We do not knowingly collect data from children under 13. A parent or legal guardian who uses the App for a minor (13–17) in their care is the account holder and provides consent on the minor's behalf — including, where the minor's glucose is consumer health data, the consent described in our Consumer Health Data Privacy Policy. If you believe a child under 13 has provided us personal information, contact privacy@eatingglasses.com and we will delete it.
14. International Data Transfers
The App is operated from the United States; your account information is stored and processed there. EEA/UK features are not offered at launch; if and when they are, cross-border transfers will rely on Standard Contractual Clauses (see Section 12).
15. FTC Health Breach Notification Rule
In the event of a breach of unsecured personally identifiable health information, we will notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery, and notify the Federal Trade Commission (and, where the breach involves 500 or more individuals, contemporaneously) as required by the FTC Health Breach Notification Rule (16 C.F.R. Part 318), as amended, and other applicable laws. Where a breach affects 500 or more residents of a state, we will also notify prominent media in the affected area. Our notice will include the categories of health data involved, the name of any third party that acquired the information (where known), and the steps individuals can take.
16. Consumer Health Data (Washington MHMDA, Nevada SB 370)
Glucose and related wellness data are "consumer health data" under Washington's My Health My Data Act and Nevada SB 370. Our separate, homepage-linked Consumer Health Data Privacy Policy describes the categories collected, the purposes, your rights to access/delete/withdraw, and our consent practices. We collect and process consumer health data only with your affirmative, opt-in consent, separate from these terms, and never sell it.
17. Medical Disclaimer
Eating Glasses is a general wellness app, not a medical device. It does not diagnose, treat, cure, prevent, or predict any medical condition, and does not provide medical advice. It shares observations about your own data and general lifestyle ideas to consider; it never tells you anything about insulin or doses — those are for you and your care team. Always consult your healthcare provider before changing your diabetes management.
18. Changes to This Policy
We may update this Policy; we will notify you of material changes via an in-app notice. Continued use after the effective date constitutes acceptance — except that for changes which materially affect how we collect or process consumer health data, we will obtain your renewed opt-in consent before the change takes effect (see our Consumer Health Data Privacy Policy).
19. Contact
Eating Glasses LLC, 1717 N St NW #1, Washington, DC 20036, United States · privacy@eatingglasses.com · https://eatingglasses.com
