Skip to content

Security

What actually protects your record.

Written for somebody who would rather check than be told. Every promise on this site is kept by something in the software rather than by a policy — this is that something, in plain words.

The shape of it

Three parts, and your phone comes first.

The app on your phone
A database on the device is the working copy. The app reads and writes there rather than over the network, which is why it keeps working with no signal — and why nothing you record is ever waiting on us to be saved.
Your account
Holds a copy so your history comes back on a new phone, and passes the categories you have shared to the doctors you have connected. It is a backup and a bridge, not the place your record lives.
Your doctor's panel
Opens in their browser. It never holds a key to your data that it can read — the keys are sealed in an encrypted cookie that only the panel's own server can open, and every request goes through that server.

Boundaries

Four things that are true whatever anybody clicks.

None of these is a setting, and none of them depends on somebody remembering a rule. They are properties of how a request is answered.

Sharing is enforced before it is sent
A category you switched off is not filtered out in your doctor's browser. It never leaves the server, so nothing sent to them after you switch it off contains it.
A record they are not connected to does not exist
Ask the panel for one and it answers as though nobody is there. A “you do not have permission” message would confirm the person is a patient, and that is itself something to give away.
A withheld area is refused, not hidden
Turning an area off is enforced where the records are, not in the page that draws them. Their panel asks for that area and the server declines — so it shows a “not shared” card rather than an empty one, and it takes effect on their very next request.
Nothing is deleted to make a point
Records are archived rather than removed, and restoring brings back exactly what was archived. No commercial situation — a lapsed plan, a practice leaving — takes anything you recorded out of your app, and nothing a doctor or a practice does can erase it.

Signing in

What is stored, and where.

Your password
Stored in a form that cannot be turned back into the password. Nobody holds it — not a doctor, not us. Support can help you reset one and can never recover it, which is the point.
Changing it
Signs out every other phone and browser that was signed in to your account. If you changed it because you were worried somebody else had it, that is the part that matters.
Staying signed in
The token that keeps you signed in is kept in the phone's own secure storage rather than in ordinary app settings, where another program could go looking for it.
A doctor's session
Their session is encrypted rather than merely signed, and their browser never holds a key to your records that it can read.
Two-factor sign-in
A doctor turns this on themselves, in their own settings, and since 19 September 2026 their staff can turn it on for their own accounts too. The phone's authenticator app makes a six-digit code that signing in asks for as well as the password, and the code is worked out on the phone rather than sent anywhere. Available, not required — nobody can switch it on for somebody else's account, and that word is exact, because this page is only worth anything if every line on it can be checked.

Keeping it

Your record survives almost everything.

Losing signal, losing a phone, a doctor leaving, a practice not paying. None of them erases what you recorded.

  • Syncing copies a record to your account. It never moves it — your phone keeps the whole history whether or not you go online again.
  • Delete something on one phone and it stays deleted on the other, rather than reappearing at the next sync from a device that had not caught up.
  • Nothing a doctor, a practice or a lapsed plan does erases anything. A request to erase, made in the app, waits 30 days before it runs, so a tap you regret can be withdrawn.
  • A doctor leaving, or their practice leaving Glycoz, leaves your prescriptions, alerts and past appointments in your app. An appointment that had not happened yet is cancelled.

What we do not have

The safest data is the data nobody collected.

There is no advertising network, no analytics service and no tracking in the app or on this website. That is not a promise about how we use it — none of it exists to be used.

And what does leave: when you ask the assistant something, or ask for an estimate from a photograph of a meal, what is needed to answer — your question and the readings relevant to it, or the photograph and your note — goes to an outside AI provider. Your name, email and date of birth do not. Neither is something you have to use. A doctor you connect can also ask their own assistant about you, which sends the figures from the areas you share. All of it is described in full on the privacy page.

Limits

What we would rather tell you than have you find out.

A page like this is only worth reading if it also contains the parts that are inconvenient to admit.

  • Two-factor sign-in is available to a doctor and to their staff, and it is not enforced for either — each person turns it on for their own account, and nobody can turn it on for somebody else. If that matters to you, ask whether the doctor you are connecting has turned it on.
  • From the September 2026 build of the app, the readings, doses and notes you record are kept on your phone in an encrypted database, under a key that stays on that phone. It does not stop somebody who can unlock your phone, so your phone's own lock still matters.
  • Two features send what they need to an outside AI provider: the assistant, and meal estimates from a photograph. If a doctor you are connected to uses their own assistant, the figures it works from — from the areas you share with them — go too, and its answers are kept for 90 days. All of it is described on the privacy page.
  • Before your first question, or your first meal photograph, Glycoz asks you. The screen names the company that receives it, says what is sent and what never is, and the box starts empty. You can turn it off again in Settings, with one switch and no reason asked, and everything else in the app works the same either way.
  • The exception is a doctor's own assistant. If a doctor you are connected to uses theirs, the figures it works from — from the areas you have shared with them — go to the same provider on their authority, not on a separate agreement from you.
  • Glycoz is early. Clinician accounts are checked by a person rather than approved by a form, which is slower and also the reason nobody gets an account by filling in a name.

Found a problem?

Tell us. A person reads it.

We would rather hear about it from you than from somebody else. There is no bounty programme and we are not going to pretend there is one.

Write to [email protected] with what you found, how to reproduce it, and what you think the impact is. If it is a real issue you will hear back with what we are doing about it and roughly when.

Please do not: test against other people’s accounts, run automated scanning that degrades the service for patients, or open data that is not yours. A finding demonstrated against your own account is just as useful to us and puts nobody else’s record at risk.