Privacy & Data Security
Transparency is core to our operating system. Here is how Glandor Intelligence protects, processes, and respects your bio-digital data.
Effective Date: April 2026 • Last Updated: April 2026
Non-HIPAA Covered Entity
Glandor Health provides wellness insights, not medical treatment. We are not a healthcare provider or a HIPAA-covered entity. While we employ enterprise-grade security (AES-256), your data does not have the specific legal protections of physician-patient confidentiality.
1. What Data We Collect
Personal & Bio-Metric Data
- Account info: Name, email address, profile photo (via Google OAuth or email sign-up)
- Bio-Metrics: Height, weight, age, gender, and activity levels used for caloric calculation
- Health data: Steps, heart rate, calories burned, distance, and hydration (via Apple HealthKit / Google Health Connect)
- Nutritional Logs: Photos and text descriptions of meals, allergy preferences, diet type
Device & Usage Data
- Device telemetry: Device type, OS version, app version for crash reporting and performance
- Location data: GPS coordinates used only when you explicitly request nearby restaurant suggestions
- Camera & microphone: Used for meal photo analysis (camera) and voice commands (microphone). Media is processed and not persistently stored on our servers
- Cookies: We use minimal local cookies for UI state (e.g., sidebar preferences). No third-party advertising cookies
2. Why We Collect It
- Core functionality: To provide personalized nutrition tracking, meal planning, organ health insights, and hydration reminders
- AI personalization: To create your unique “Health Digital Twin” that predicts nutritional needs and generates meal suggestions
- Service improvement: De-identified, aggregated data helps refine our AI food recognition models
- Communication: To send push notifications (meal reminders, hydration alerts, organ health updates) that you have opted into
3. Third-Party Services We Use
We share data with the following third-party service providers strictly for app functionality. We do not sell your personally identifiable data to advertisers.
| Service | Purpose | Data Shared |
|---|---|---|
| Google Firebase (FCM) | Push notifications | Device tokens, notification content |
| NVIDIA AI | Food image analysis, AI chat assistant, meal planning, health analysis, voice transcription | Meal photos, chat messages, audio files, health report data |
| Convex | Cloud database & backend | All user account and health data |
| Google OAuth | Authentication | Email, name, profile picture |
| Google Places API | Nearby restaurant suggestions | GPS coordinates (when requested by user) |
| Apple HealthKit / Google Health Connect | Health data integration | Steps, heart rate, calories, distance, hydration |
| Google Play Billing | Subscription payments | Purchase tokens (no credit card data) |
4. Your Rights & Data Control
Access, Modify & Delete Your Data
- Access: You can view all data stored about you at any time within the app (Profile → Settings)
- Modify: You can edit your profile, health data, meal logs, and preferences at any time
- Delete: You can permanently delete your account and all associated data from Settings → Privacy & Security → Delete My Account. This action is irreversible
- Data Portability: Contact us at privacy@glandor.com to request a copy of your data in a machine-readable format
- Opt-Out: You can opt out of push notifications, data analytics, and location tracking through your device and app settings
5. Regional Data Protection
GDPR (EU/EEA Users)
- We process your data based on consent (which you provide during onboarding) and legitimate interest (service improvement)
- You have the right to access, rectify, erase, restrict, and port your personal data
- You may withdraw consent at any time without affecting lawfulness of prior processing
- Data breaches will be reported to the relevant supervisory authority within 72 hours
CCPA / CPRA (California)
- We do not sell your personal information to third parties
- You have the right to know what data we collect and the right to delete it
- You will not be discriminated against for exercising your privacy rights
- To exercise any right, email us at privacy@glandor.com or use the in-app deletion feature
6. Data Retention
- Active accounts: Data is retained for as long as your account is active to provide our services
- Deleted accounts: Upon account deletion, all personal data is permanently erased within 30 days. Anonymized, aggregated data may be retained for research
- Inactive accounts: Accounts inactive for 24 months may be flagged for deletion with 30 days advance notice via email
- Legal obligations: Some data may be retained longer if required by applicable law (e.g., transaction records)
7. Children's Privacy
Glandor Health is intended for users aged 18 and older. We do not knowingly collect personal information from children under 13 years of age. If we learn that we have inadvertently collected data from a child under 13, we will promptly delete that information. If you believe a child under 13 has provided us with personal data, please contact us at privacy@glandor.com.
Security Architecture
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the app or via email. Continued use of the service after changes constitutes acceptance of the updated policy. We encourage you to review this page periodically for the latest information.
Questions about your data?
privacy@glandor.comLast Updated: April 2026 • Glandor Health Technologies • Delaware, USA