1. Governance & Accountability
Company: GlucoRevert Canada Inc.
Privacy Officer: Chief Technology Officer is responsible for our privacy compliance.
Contact: privacy@glucorevert.ca
Commitment: We maintain an internal Privacy Management Program (PMP) that includes staff training, regular impact assessments, and breach response protocols.
2. The Data We Collect
- Identity Data: Name, email address (for account management).
- Health & Biometric Data: Blood glucose readings, weight, dietary logs, and photos of meals. (Classified as “Sensitive Information” under C-27).
- Technical Data: IP address, device type, browser info (for security and app optimization).
- Push Notification Data: If you enable push notifications, we store a browser-issued push subscription token (endpoint URL and encryption keys) on our servers. This token is specific to your browser and device and does not contain personal identifiers. It is deleted immediately when you disable notifications or unsubscribe.
3. How We Use Your Data
- Service Delivery: To provide the dashboard, analytics, and food scoring.
- AI Analysis: To analyze meal photos and suggest “diabetic-friendly” alternatives.
- Improvement: De-identified (anonymized) data may be used to improve our algorithm’s accuracy.
- Push Notifications: If you opt in, we use your meal reminder times, glucose alert preferences, and inactivity threshold to send timely health reminders to your device. We record a dispatch log (notification type, timestamp, delivery status) for frequency capping and audit purposes. This log does not include notification content.
4. Third-Party Sharing & Data Transfers
We do not sell data. We transfer data only to these “Service Providers” necessary to run the app:
- Hosting & Database: Amazon Web Services Canada (Montreal, ca-central-1 region).
- AI Processing: Google Cloud Platform Canada (Montreal, northamerica-northeast1 region) for food image analysis using Gemini AI.
- Label OCR: AWS Textract (ca-central-1 region) for reading nutrition facts labels. Only the label image is processed; no personal identifiers are included.
- Food Product Data: Open Food Facts (openfoodfacts.org) for barcode lookups. Only the product barcode number is transmitted — no personal information or health data. Data is licensed under the Open Database License (ODbL).
- Push Notification Delivery: When you enable push notifications, your browser's push service (operated by your browser vendor — Google for Chrome, Mozilla for Firefox, Apple for Safari) receives and delivers notification payloads to your device. We transmit only the notification content (title, body, deep link) to this service. No health data is included in notification payloads. We have no control over the browser vendor's data practices; please refer to their respective privacy policies.
- Location of Data: All personal health information remains encrypted within Canadian borders. Your data is stored in AWS ca-central-1 and processed in GCP northamerica-northeast1.
Google Cloud Platform (GCP) Processing Disclosure
What data is sent to GCP: When you use the AI-powered food logging feature, we send food photos to Google Cloud Platform for analysis. These photos are classified as Non-PHI (Non-Personal Health Information) because:
- Food photos do not contain medical diagnoses, treatment information, or prescription details
- Photos are anonymized before transmission - all identifying metadata is removed
- No user identifiers (name, email, account ID) are sent with the images
Canadian Data Residency: All AI processing occurs exclusively in Google Cloud Platform's Canadian region (northamerica-northeast1, located in Montreal). We have hardcoded this endpoint in our system to ensure your data never leaves Canada during AI analysis.
Anonymization Process: Before sending any food photo to GCP, our system:
- Strips all EXIF metadata (location, device information, timestamps)
- Generates a temporary session ID that cannot be linked back to your account
- Removes all user identifiers from the request
- Validates that the image contains only food (rejects images with faces or prescription bottles)
- Deletes the temporary session ID after 24 hours
Data Retention at GCP: Google processes the anonymized food images in real-time and does not retain them. Our audit logs (stored in Canada on AWS) record only the anonymized session ID and analysis results, not the actual images.
5. Push Notifications & Consent
Push notifications are entirely optional and require your explicit consent. When you enable them:
- What you consent to: Receiving meal reminders, glucose alerts, and inactivity nudges on the device and browser where you subscribed.
- What we store: Your push subscription token, notification preferences (reminder times, alert types, inactivity threshold), and a dispatch log for frequency capping.
- Withdrawing consent: You can disable notifications at any time from Settings → Push Notifications. This immediately revokes your consent record, deletes your subscription token from our servers, and stops all future notifications. You may also revoke permission directly in your browser settings.
- Retention: Subscription tokens are deleted upon opt-out. Dispatch logs are retained for 90 days for audit purposes, then permanently deleted.
6. Automated Decision Systems (AI Transparency)
What is it? GlucoRevert uses Artificial Intelligence to analyze your food photos and estimate carb counts.
How it works: The system compares your photo against a database of foods to predict nutritional content.
Limitations: These are estimates. You should not use these calculations for insulin dosing without verifying them yourself.
Human Review: You have the right to request a human review if you believe the AI has significantly errored in a way that impacts your service.
6. Your Rights Under Bill C-27
- Right to Disposal (The "Delete Button"): You can request the permanent deletion of your account and data at any time via the "Settings" page. We will complete this within 30 days.
- Right to Mobility: You can download a structured file (CSV/JSON) of your glucose and food logs to move to another platform.
- Right to Withdrawal: You can withdraw consent for AI processing at any time (though this may disable certain app features).
7. Data Security & Retention
Security: We use encryption in transit (HTTPS) and at rest (AES-256) to protect your sensitive health data.
Retention: We retain your personal data only as long as you have an active account. If you are inactive for 2 years, we will notify you before deleting your data.
8. User Feedback
GlucoRevert includes an optional in-app feedback feature. When you submit feedback:
- What we collect: A star rating (1–5), a category (e.g., food logging, glucose tracking), and an optional free-text comment of up to 1,000 characters.
- What we do not collect: No health data, no personal identifiers beyond your account ID, and no PII is stored in feedback records.
- How it is used: Feedback is used solely to improve the GlucoRevert product. It is never sold or shared with third parties.
- Frequency limit: You may submit feedback once every 7 days to prevent abuse.
- Retention: Feedback records are retained for 2 years, then permanently deleted.
- Voluntary: Submitting feedback is entirely optional and has no effect on your account or service access.
9. Children's Privacy
GlucoRevert is not intended for users under 18. We do not knowingly collect data from minors.