Last updated: 25 August 2026
glyso (“we”), operated from London, United Kingdom, runs glyso.health and the glyso app. We have not yet incorporated a company; this page will name the company when we do. We are the data controller for everything below. Contact: [email protected].
We collect what you give us when you join the waitlist or pilot on glyso.health — your name, email, sensor, whether you live with type 1 or type 2, your answer to “what would you want glyso to tell you”, and your marketing choice — plus, in the app: your account email; your name, if you sign in with Apple and choose to share it (Apple’s “Hide My Email” gives us a masked address instead, and glyso works exactly as well with one); your CGM login (stored encrypted, used solely to fetch your readings with your permission); your glucose readings; the meals, photos, notes, movement and insulin you choose to log; your step counts, the sustained walks your phone detects in them, and workout sessions from Apple Health, if you connect it — see below; your sleep, workouts and recovery figures from WHOOP, if you connect that — also see below; your answers to the questions glyso asks you about them — what was different about a particular day, or whether you skipped something you usually have; how you say you feel — one plain word you choose from a short fixed list (for example flat, OK, rested, wired, stressed), the minute you chose it, and whether you volunteered it or answered a question glyso put to you; your time zone — including when it changes, so the app can cut your days at your own midnights and show you on the chart where your clock moved — plus your target range and units; and first-party usage analytics that never contain glucose values or meal text. We also keep the notifications glyso sends you — their wording and the screen each one opens — so that a notification you missed on your lock screen is still there to read in the app. We use it to run glyso — showing you your own data, explaining what moved your glucose, writing your coaching — and to improve it, based on contract, our legitimate interests, and your explicit consent for everything about your health.
We share it only with service providers who help us run glyso:
Where data leaves the UK or EEA — several of these are US companies — we rely on UK adequacy decisions, the EU–US Data Privacy Framework, or Standard Contractual Clauses. We keep your data only as long as needed, as set out below.
glyso never posts anything anywhere. The only thing that leaves your phone this way is what you send, by tapping a share button and choosing an app yourself.
The week card carries numbers only. A time-in-range percentage, how many days of the week that figure was measured from, the seven daily percentages behind it, how many of your nights stayed inside your range and how many were measured, your average glucose overnight, a count of what glyso has worked out, and the week’s dates. It carries no meal names, no times of day, no notes and nothing you typed — and that is enforced by the way the card is built rather than only promised here: there is no field on it that a name or a time could travel in.
Where your phone’s share sheet can take a picture, the image is written to the app’s own storage on your device and handed to that sheet. Where it cannot — or where the picture could not be produced — the same numbers go as a single line of text instead: the same numbers, nothing added. The app tells you which of the two happened.
Where it goes next is whichever app you pick in your phone’s own share sheet, under that app’s terms; we are never told which one you picked there, and we never see the post.
We count that a share happened, and two things about it: which of the three buttons in glyso you tapped — Reddit, WhatsApp or Instagram, which chooses the card’s shape and nothing else — and whether the picture or the text went. Nothing about the card’s contents rides on that count.
glyso lets you record a mood the same way you record a meal: one tap, one plain word, timestamped onto your own curve. You can log one whenever you like, and glyso may ask — once in a morning at most — how you woke up.
It is never a number. There is no 1–10 scale and no rating, in the app or in our database, and you never type anything: the words are buttons, from a short fixed list. So we hold no free text about your mental state and no score derived from one.
Nothing about it is scored or rewarded. Logging a mood earns no points, no streak and no badge, and answering the question earns nothing either. A reward for answering would be a reason to invent an answer.
We use it for one thing: understanding your own glucose. It appears on your own chart, and once you have enough of your own days, glyso compares the days you logged one word against the days you logged a different one — over the same hours of the day, and only ever across days you actually told us something about. Days you logged nothing are used for neither side of that comparison. Those comparisons describe what happened together; they do not claim that a mood caused a glucose reading or the other way round.
Like everything else in this section, it is special-category health data — about your mental state — processed only with your explicit consent, and destroyed with your account.
Your glucose readings, meals, diabetes type, medications, the moods you record and everything derived from them are special-category health data under UK GDPR. We process them only with your explicit consent (Article 9(2)(a)), given when you create your account and connect your sensor, and solely to provide glyso to you. Withdraw at any time — delete your account in the app, or email us — and we stop processing and destroy what identifies you, as described below.
glyso is a coaching app, not a medical device. It explains what already happened; it does not diagnose, treat, alarm, or give insulin dosing advice. Real-time alerts remain your CGM’s job; decisions about your care belong with you and your clinical team.
If you connect Apple Health, we read two things from it and only two: your step counts and your workout sessions — for a workout, when it started and ended, what kind it was, and the energy Health recorded for it. Nothing else Health holds is read. Nothing is ever written back to it.
Step counts are read at two levels of detail: the day’s total, and the minute-level pattern of steps across the day. The minute-level record is read so your phone can notice a sustained walk — ten minutes of steady steps after lunch that you would never start a workout for, which is often the missing half of why your glucose did what it did. That noticing happens on your phone: the minute-by-minute record itself is never sent to us and never stored by glyso anywhere. What reaches us is the finding — that a walk happened, when it started and ended, and how many steps it held — alongside the daily total.
When you first connect, we read the last 90 days of those two things, so that movement joins your whole history rather than only the days after you connected — your glyso energy score compares a day against your own recent normal, and a score that counted movement from Tuesday but not from Monday would not be comparable with itself. After that, the app sends recent days each time you open it, because Apple Health revises its own history when a second device syncs or you edit an entry.
Nothing that comes out of Apple Health is stored on your phone by glyso. It is read, and either sent to us over an encrypted connection (totals, workouts, detected walks) or used on the spot and dropped (the minute-level step record, which never leaves the device). What the app keeps on the device is whether you have been through the permission screen and when it last synced — times and switches, no measurements.
We use it for one thing: understanding your own glucose. Movement is part of your glyso energy score, and it is very often the missing half of an explanation — a morning walk can be doing work that breakfast gets the blame or the credit for. When a piece of coaching is about a day you moved, that figure goes to our AI provider with the rest of that request, on the same terms as everything else here: to write your coaching, never to train a model, never for advertising.
Apple’s rules for health data are stricter than the law’s, and we follow them. Data from Apple Health is never used for advertising or marketing, never sold, never shared with anyone else, and never stored in iCloud. It is also kept out of the de-identified research set described below — the aggregated learning in the next section excludes anything that came from Apple Health. If we ever want to include it, we will ask you for that specifically and you will be free to say no.
Alongside the two kinds of data, we keep a short record of the connection itself: when your phone first sent us Health data, when it last did, and whether you have switched Apple Health off inside glyso. It contains no health data — only times. We keep it because your glyso energy score has to say honestly whether movement is one of the things it counted, and because iOS does not tell us when you withdraw access.
You can withdraw access at any time in iOS Settings → Privacy & Security → Health. Apple does not notify us when you do, so what we notice is that your phone stops sending Health data while you carry on using glyso; after about a week of that we treat the connection as ended, stop counting movement in your score, and say so. Reconnecting starts it again. What we already hold is destroyed with your account like everything else here.
WHOOP is optional and entirely separate from Apple Health. You can connect either, both, or neither, and turning one off does nothing to the other.
If you connect WHOOP, you are sent to WHOOP’s own website to sign in. We never see your WHOOP password — WHOOP hands us back a key that lets us read your data, and nothing else. That key is stored encrypted, exactly as your sensor login is, and it is never shown on any screen or included in any export.
We read three things:
We read this for one purpose: to explain your glucose. Sleep and recovery are among the strongest reasons a day behaves differently from your usual, and they are things a glucose sensor cannot see. We do not use any of it for advertising or marketing, and we do not sell it.
Unlike Apple Health, which your phone sends to us, WHOOP data is fetched by our own servers — so it arrives even when the app is closed. WHOOP tells us when something new is ready, and we then ask WHOOP for it. When you first connect, we ask for the last 90 days so the app has enough of your history to say what is normal for you.
You can disconnect at any time inside glyso, or revoke glyso’s access in your WHOOP account. Disconnecting inside glyso destroys the key immediately, and we stop fetching anything from that moment. What we have already stored stays until you delete it or your account — the same as everything else here — and reconnecting simply starts the fetching again.
glyso learns from patterns — that is the product, and we want to be plain about what that means. We keep and use aggregated and de-identified data to improve glyso and to build research insight into how food, movement and routine shape glucose — and the mood words you choose are part of it, because how a day felt belongs in that picture; they carry no free text and no rating, only a word from our own short list. De-identified means: your name, email, account identifiers and free text are stripped; timestamps are coarsened to day-relative form, so a record reads “07:40 on a weekday”, never a date a person could be matched to; and the result sits under strict access control — nobody outside glyso can reach it. Data that came from Apple Health is not part of it, for the reason given above.
When you delete your account, everything that identifies you is destroyed immediately and permanently: your account row, name and email; your encrypted sensor login; your push tokens and history; your analytics rows; your settings; your cached coaching text and day stories; the words you typed into the logger; the moods you recorded. There is no soft delete, and the list of tables deletion covers is checked by an automated test against the application’s own schema, so a table added in future cannot silently escape it. What survives is only the de-identified science: a curve and what a meal did to it, belonging to no one.
If a breach ever puts your data at risk, we notify the ICO and, where the risk to you is high, you — within the timescales UK GDPR sets.
Website sign-ups: until you ask to be removed — one email does it — or an app account supersedes them. App data: as long as you keep your account. On deletion: everything identifiable destroyed at once; de-identified data may be retained and used as described above. Backups roll off on their own short cycle.
Under UK GDPR you can access, correct, delete, export, restrict, or object, and withdraw any consent. Email [email protected] — we answer within a month. You can complain to the ICO at ico.org.uk, or to your own country’s authority. glyso is intended for adults and is not directed at children under 13; if you believe a child has an account, email us and we will delete it.
When the product changes in a way that matters — new data collected, a new provider, a new use — this page changes with it, and for material changes we tell you by email before they take effect. The date at the top is always current.
This policy is governed by the law of England and Wales, and the courts of London have jurisdiction over any dispute about it. Nothing here removes rights your local consumer or data protection law gives you.
[email protected] · glyso, London, United Kingdom
glyso — know the ‘why’ behind your glucose.