Legal
Privacy policy
Glycoz holds health records, which is the most sensitive category of personal data there is. This document is the formal account of what happens to them. The plain-language version is on the privacy page.
- Version
- 0.4
- Last updated
- September 2026
- Effective
- Not yet in force
Draft — not yet in force
This document has not been through legal review and the items marked in the text below still need to be supplied. It is excluded from search engines until then. It is published here so it can be reviewed, not so it can be relied on.
Who we are
Glycoz is operated by P6s, a registered sole proprietorship, of which Param Suthar is the proprietor, based in Ahmedabad, Gujarat, India (“we”, “us”). Correspondence address: [REGISTERED POSTAL ADDRESS for grievance correspondence].
For the purposes of the Digital Personal Data Protection Act, 2023, we are the Data Fiduciary in respect of the personal data described below, and you are the Data Principal.
Glycoz is run by one person. That is stated plainly because it cuts both ways: there is nobody to be escalated past, and there is also nobody who can quietly change what happens to your record.
What this policy covers
The Glycoz Android application, the Glycoz for Clinicians web panel, the servers that support them, and this website. It does not cover anything a clinician records in their own systems outside Glycoz, or what happens to a report after you have sent it to somebody.
Once you export a report or share it over WhatsApp, email or any other channel, it is outside Glycoz and outside this policy. We cannot recall it and we have no control over what the recipient does with it.
What we collect
Account information
- Your name, email address and phone number, and — where you provide it — your date of birth.
- A password, stored only as a cryptographic hash that cannot be reversed. We never hold your password and cannot recover it, only reset it.
- The version of the Terms of use and this policy you agreed to, and when you agreed.
- For clinician accounts: professional registration details, qualifications and clinic details, which we check by hand before granting access.
Health information you enter
Whatever you choose to record, across the modules you have switched on. That includes blood sugar readings and their meal context, insulin doses, HbA1c results, medicines and whether you took them, blood pressure, heart rate, blood oxygen, weight, meals, water, activity, emergency information, and any notes you attach to any of it. Under the SPDI Rules this is sensitive personal data and we treat it accordingly.
Switching a module off takes it off your home screen and out of your reports.
Information read from a wearable, if you allow it
If you connect a watch or band through Health Connect, Glycoz reads the figures you permit — typically sleep, steps, distance, resting heart rate and blood oxygen — and stores them alongside what you have typed, marked as having come from a device. Access is read-only: Glycoz writes nothing back to Health Connect.
This is optional, it is off until you turn it on, and withdrawing the permission stops it. Figures already read stay in your record until you disconnect the wearable in Glycoz, which hands the permissions back and deletes everything it imported.
Location, only for two things you start
Finding a doctor. If you open Find a Doctor, the app asks your phone for your location once, in order to sort nearby clinics by distance. It is used for that search and is not stored against your account, not kept as a history, and not shared with the clinics in the list. If you refuse the permission you can still search, just not by distance.
Tracking a walk or a ride. While a walk or ride you started is being tracked, the app uses your phone’s location to measure how far and how fast you went, and to draw the route on your phone. The distance, duration and speeds sync to your account. The route itself stays on your phone: our servers have nowhere to store one. The map under it is fetched from OpenStreetMap, which sees the part of the map on your screen — roughly where you are — but not the route.
Nothing else in Glycoz uses your location.
Photographs and lab reports, only the ones you add
If you use Diet AI, the photograph you take of a meal and any note you add are uploaded to your account, so they come back on a new phone, and are used to estimate what is in the meal. Our server removes location and camera details from the photograph when it arrives, before it is stored or used for an estimate. What happens when an estimate is made is set out in clause 6.
If you attach a lab report to an HbA1c result, the file is uploaded to your account in the same way, so it comes back on a new phone. Uploaded photographs and files are kept in the private storage listed in clause 7.
If you ask for Glycoz Premium
Glycoz Premium is a plan for patients covering the assistant, meal estimates, PDF reports longer than 15 days and how long a period Analytics draws at once. Without it, an account has a set number of free tries of the assistant and of meal estimates, once; when they are used, the assistant takes no new questions and a meal gets no estimate, though past answers and estimates stay readable. Analytics draws up to 15 days at a time without Premium and up to a year with it; the longer periods are shown with a padlock rather than hidden. Premium never limits recording, the records themselves, a module’s own history, the CSV export of any period, sharing, your doctors or the emergency button. You ask for it in the app, and the Glycoz team arranges it with you. If you ask for it or hold it, we keep your request and any note you add to it; the dates of each period of the plan, with the terms it was given on and a note of how it was arranged; how many of your free tries you have used; and each month’s count of assistant questions and meal estimates. Counts only — never the questions or the meals. No payment details are held, because there is no payment step in Glycoz.
Technical information
- Information needed to synchronise: which records changed, and when, so a device can be brought up to date.
- The phone model and app version your account was last used on, and when the app last started.
- Server logs generated when the app or the panel contacts us, including an IP address and a timestamp, kept for security and diagnosis.
- A device token, if you allow notifications, so a message can wake the app.
- For clinician sessions: an encrypted session cookie. The browser holds no API token.
What we do not collect
- Your contacts, your microphone or your call log. The camera is used only when you take a photograph for a meal, at the moment you take it.
- Where you have been. Location is used only for the two things described above, a route never leaves your phone, and location is not read at any other time.
- Advertising identifiers. There is no advertising in Glycoz and no advertising network receives anything.
- Behavioural profiles built for marketing, or any inference about you sold or shared with a third party.
Why we process it, and on what basis
We process your personal data on the basis of the consent you give when you create an account, by ticking that you have read and agree to the Terms of use and this policy — we record the version you agreed to and when — and, where applicable, for the legitimate uses permitted under the Digital Personal Data Protection Act, 2023. An account created before that tick existed is asked in the app, and every account is asked again when the version changes; choosing Not now leaves your records as they are, and the app asks again the next time it reaches our server. The purposes are limited to the following.
- To create and maintain your account, and to sign you in.
- To synchronise your records between your devices and to hold a backup, so your history survives a lost or replaced phone.
- To make records available to a clinician you have connected, limited to the categories you have not withheld.
- To generate the reports and exports you ask for.
- To carry an appointment request to a clinic, and its answer back to you.
- To deliver a prescription a clinician has written for you, and to notify you that something has arrived.
- To send an emergency alert, with what you typed, to the clinician whose card you raised it from — because that is what you pressed the button for.
- To keep the reminders you have set with your account, so they come back on a new phone — they are scheduled and sounded on your device.
- To handle a request for Glycoz Premium, to count how much of the plan, or of your free tries, has been used, and to stop new assistant questions, meal estimates and longer PDF reports that neither covers.
- To keep an audit log of clinician access, which exists to protect you.
- To keep the service secure, diagnose faults, and comply with the law.
We do not use your health information for advertising, for profiling, for training any general-purpose model, or for any purpose you have not been told about here.
The AI features
Three features send data to an outside provider: an assistant that answers your questions about your own record; meal estimates, which work out what is in a photograph of a meal; and an assistant in the clinician panel that answers a connected clinician’s questions about their patients. Yours are optional, ask for your agreement before anything of yours is sent, and run only when you use them. Everything else in Glycoz works without them.
- The provider is Google, through the Gemini API. Every request goes through our server; the app never contacts the provider directly.
- What is sent is what is needed to answer: health figures, medicine names, diabetes type and your age — and for a meal estimate, the photograph and your note, with location and camera details removed. Neither of your features sends your name, email address, phone number or date of birth.
- If a clinician you are connected to asks their assistant about you, the figures it works from — drawn from what you share with them — and any notes of their own about you that it draws on are sent to the provider through our server. Those conversations are kept for 90 days.
- Anything you ask the assistant is not visible to a connected clinician. It is not part of the record they read.
- Your two features ask you first. Before your first question to the assistant, and before your first meal estimate, Glycoz shows you what is sent and to whom and asks you to agree; nothing of yours is sent until you do. You can withdraw that agreement at any time in Settings › Your data, with no reason asked, and the two features stop. Withdrawing does not delete the answers and estimates you already have — they are part of your record — and it cannot recall what was already sent.
- The clinician assistant is not covered by that agreement. It runs when a clinician you are connected to uses it, on their access to what you have shared with them, and is governed by your sharing settings rather than by a separate agreement from you. Disconnecting them, or switching off an area, stops it in the same way it stops everything else.
- Switching a module off stops the processing for that feature and leaves the rest of the app unaffected.
- The assistant and meal estimates are part of Glycoz Premium. Without it, each account has a set number of free tries, once; after that, no question or meal photograph is sent for an answer or an estimate. Holding Premium, or using the free tries, changes nothing about what is sent.
We are currently on Google’s free API tier, and its terms permit prompts sent on that tier to be used to improve Google’s models. That is a real difference from the paid tier, which does not, and moving to the paid tier is the intention. It is stated here rather than left for you to find in somebody else’s terms.
No AI feature in Glycoz gives medical advice, diagnoses anything, or recommends any treatment. The limits are set out in full in the medical disclaimer.
Third parties and processors
We use a small number of service providers to run Glycoz. Each acts on our instructions, and each receives only what it needs to perform its function. This is the complete list.
- Google — Gemini API — Answering a patient's assistant question, estimating a meal from its photograph, and answering a connected clinician's assistant question. The health figures needed to answer, medicine names, diabetes type, age, and a meal's photograph and note; for a clinician's question, notes that clinician wrote. A patient's own features never send your name, email, phone number or date of birth. Only if the feature is used.
- Google — Firebase Cloud Messaging — Waking the app when something arrives for you. A device token and a short notice such as “Message from your doctor”; an appointment notice also carries its time and the doctor’s name. Never anything clinical — what a doctor wrote is read in the app, after you unlock your phone.
- Google — Gmail — Password resets and sign-in codes, appointment updates and visit summaries, emergency alerts to your doctor, notice that Glycoz Premium is on or renewed, a practice's invoices, and telling us you have asked to be erased. The recipient’s email address, a name, and what the message is about — in an emergency alert, the note you typed with your phone number and email address; after a visit, the titles of what your doctor wrote for you; when you ask to be erased, your name, email address and any reason you gave, sent to us.
- OpenStreetMap — Drawing the map under a walk or ride you track. Your phone’s internet address and which part of the map is on screen, which shows roughly where you are. Never the route itself, and nothing about your health. Only if the feature is used.
- Amazon Web Services — S3 — Storing files uploaded to Glycoz: lab reports and meal photographs, a doctor’s profile photo, and a clinic’s staff documents. The files themselves, filed under an account number rather than a name, in a private bucket in Amazon’s Mumbai region closed to public access. Amazon encrypts the stored files at rest. When a file is deleted, its previous version is kept for 90 days, then deleted permanently. Only if the feature is used.
- Cloudflare — Carrying traffic between your phone and our server. Encrypted traffic in transit. It is the road, not a destination: nothing is stored there.
Everything else is run on our own servers: the database holding your records, the panel your clinician signs into, and the invoices and receipts Glycoz generates. The files you upload are kept with Amazon Web Services, as listed above, and the reports you make are made on your phone. There is no managed database, no analytics service, no crash reporting service and no advertising network anywhere in Glycoz.
This website carries no third-party analytics, no advertising tags and no social media trackers.
How long it is kept
- Your health records are kept while your account exists, because their purpose is to be a history. A record you delete in the app is marked as deleted, so that your other devices remove it too, and stays on our server in that form until your account is erased.
- If you ask to be erased from inside the app, nothing changes for 30 days and you can withdraw the request; when the 30 days have passed, your account and the records set out in Delete my data are erased automatically. A request by email is carried out once we have confirmed it is yours, within 30 days, and takes effect at once. Either way, an erasure cannot be undone.
- Glycoz Premium records — your requests, the periods of any plan you hold, how many free tries you have used, and monthly counts of assistant questions and meal estimates, never the questions or the meals themselves — are kept with your account and erased with it. Our own record of each period we gave or ended — its dates, its price and how it was arranged — is kept in our administrative log after an erasure.
- Audit log entries of clinician access are kept after a connection ends and after an erasure, because their purpose is to remain checkable, including on your behalf. They record that a record was opened, when, and by whom, not what it contained. The record of an erasure — the account's email address and counts of what was removed — is kept in the same way. No period has yet been set after which these entries are deleted.
- Questions a clinician asks their own assistant about a patient are kept for 90 days from the last message, then expire.
- Server logs are kept for security and diagnosis. They can include internet addresses and account numbers, and no fixed period has yet been set for deleting them.
- Our server's database is backed up every night and before each update. Each backup is deleted after 14 days, so a deleted record, or an erased account, can remain in a backup for up to about 15 days.
- When a file you uploaded is deleted, by you or with your account, our storage provider keeps its previous version for 90 days so that a mistaken deletion can be undone, then deletes it permanently.
- An email we have sent — to you, to your doctor, or to us — stays in the mailbox it reached, and an erasure cannot reach it.
- We may retain the minimum necessary to meet a legal obligation, resolve a dispute or enforce our terms, and nothing beyond that.
Records on your own device are under your control. Uninstalling the app removes them, and when your account is erased, a current version of the app clears what the account left on that phone and returns to the sign-in screen.
A prescription a clinician wrote for you stays on your record, and stays attributed to them, even if they or their practice later leave Glycoz. It is part of your medical history, and removing it because of a commercial event between us and a clinic would take something from you that was never ours.
How it is protected
The technical measures are described in more detail on the security page. In summary: passwords are stored as unreversible hashes; sign-in tokens are held in the Android Keystore rather than in app preferences; clinician sessions use an encrypted cookie and the browser never holds an API token; clinician access to a patient record is scoped by an explicit connection and is written to an audit log before the record is read, failing closed if the log cannot be written; and category-level sharing is enforced on the server rather than in the browser.
On a phone with a version of the app built after 13 September 2026, the records you keep in the app and what your doctor sends you are held in a database encrypted under a key kept in the Android Keystore. The photographs you add and the profile details kept in the app’s settings are outside that database and are not encrypted, and none of it stops somebody who can unlock your phone. Those versions also turn off Android’s own cloud backup and phone-to-phone transfer for Glycoz, so your records reach a new phone only by signing in. Files you upload are kept in a private storage bucket closed to public access, where the storage provider encrypts them at rest. Traffic between the app and our server is encrypted in transit; the database on our server has no encryption of its own beyond what the server’s disk provides.
Two-factor sign-in is available on clinician accounts and is not currently required. That word is exact, and it is here rather than omitted because a security section is only worth reading if the gaps are in it too.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India as required under the Digital Personal Data Protection Act, 2023.
Your rights
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights. Exercising any of them is free, and we will not ask you to justify the request.
- Access — a summary of the personal data we process about you, and who it has been shared with. Much of this is available to you directly: your records are in the app, and Settings › Your data will email you a copy of everything we hold, without your needing to ask us.
- Correction — you can correct or complete your records in the app at any time, and ask us to correct account information.
- Erasure — you can have your account and your records deleted: from inside the app, where the request waits 30 days so it can be withdrawn and then runs by itself, or by email without the app. See Delete my data for both routes, and what is kept.
- Withdrawal of consent — you can disconnect a clinician, switch off a category, or turn off a module, at any time and without explanation.
- Portability — you can ask, in Settings › Your data, for a copy of everything held about you. We email you a link to it; the link works once and lasts 48 hours, and the file is deleted afterwards. Your photographs and uploaded documents are listed in it by name and date rather than enclosed, and they stay available to you in the app. A clinician’s own private notes about a consultation are their record, not yours, and are not included. You can also export your records as a CSV from within the app at any time.
- Nomination — you may nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
- Grievance — you can complain to us first, and to the Data Protection Board of India if we do not resolve it.
Children and people under 18
Type 1 diabetes is often diagnosed in childhood, so this needs to be explicit. Glycoz is intended for use by adults. A person under 18 may use it only with the consent of a parent or lawful guardian, given and verifiable in accordance with the Digital Personal Data Protection Act, 2023, and a parent or guardian may keep records on behalf of a child in their care.
We do not carry out behavioural advertising, tracking or profiling of any user, which the Act prohibits in respect of children. If you believe a child’s data has been provided to us without the necessary consent, write to us and we will delete it.
If you are a clinician
A clinician account carries data about you as well as about your patients, and the following apply to it.
- Your registration number, qualifications and clinic details are checked by a person before an account is created, and are held so that a patient connecting to you can see who they are connecting to.
- Your profile photo, and documents your practice uploads about its staff, are kept in the private storage listed in clause 7.
- If your plan includes it and you choose to publish a listing, your name, speciality, clinic and its location appear in Find a Doctor, where patients can search them. This is a public listing and you control what is in it.
- Your commercial relationship with us — your plan, your invoices, what you have paid — is yours and your practice's. It is never shown to any patient, in any form, at any time.
- You are responsible for your own registration and for anything you prescribe. Glycoz records what you write; it does not review it.
If you leave Glycoz, your patients are shown one neutral word about the connection ending. They are not told why, and they are not told anything about your practice’s commercial situation.
This website
This website sets no advertising or analytics cookies. There is no cookie banner because there is nothing to consent to. If you submit the contact form or the clinician access form, we receive what you typed and your contact details so that we can reply, and nothing else.
Please do not put health details into the contact form. It is ordinary email, not the app, and it is not the right place for your medical information.
Where it is processed
Glycoz is operated for users in India, and your records are held on servers in India: our database on hardware we run ourselves, and the files you upload in a private Amazon Web Services storage bucket in its Mumbai region. If the database moves to a datacentre it will stay in India, and this page will say where.
The service providers listed in clause 7 are operated by companies outside India. Amazon Web Services keeps the files you upload in its Mumbai region, in India; the others may process what reaches them outside India. That is limited to what each entry describes. We rely on those transfers only as permitted under the Digital Personal Data Protection Act, 2023.
Changes to this policy
When this policy changes materially — a new category of data, a new processor, a new purpose — we will say so in the app and on this page before the change takes effect, not afterwards. The version number and date at the top of this page always reflect the current text. When the version changes, the app asks you to read the new version and agree to it, and records which version you agreed to and when.
Grievance redressal
If you are unhappy with how your personal data has been handled, tell us. A complaint is acknowledged within 24 hours and resolved within 15 days, in line with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
- Grievance Officer: Param Suthar, P6s
- Email: [email protected]
- Address: [REGISTERED POSTAL ADDRESS for grievance correspondence]
- General enquiries: [email protected]
If we do not resolve your complaint to your satisfaction, you may escalate it to the Data Protection Board of India.
Other documents: Medical disclaimer · Privacy policy · Terms of use · Delete my data
