GlucoHabit – Glucose Tracking & Analysis App

Privacy Policy

Effective Date: August 17, 2026  /  Operator: IronDesign
This Privacy Policy ("Policy") describes how IronDesign ("we," "us," or "the Operator") collects, uses, manages, and shares user information in connection with the smartphone application "GlucoHabit – Glucose Tracking & Analysis App" ("the App").

Please review this Policy before using the App.

1. Information We Collect and How We Collect It

We may collect the following information in connection with the provision of the App.

1.1 Information Provided Directly by Users

We may collect information that users enter into or register with the App, including:

The information above may include information related to a user's health. Health-related data, including blood glucose information, is handled with greater care than general usage information. We do not collect medication/insulin records or user profile information (such as name, date of birth, or contact details), as the App does not currently provide features for entering them.

1.2 Device and Usage Information

When users use the App, we may automatically collect information such as:

1.3 Information Obtained Through Third-Party Services

We may use the following third-party services in connection with the operation of the App.

Firebase Authentication (Google LLC) The App signs you in using Firebase's anonymous authentication, which creates a random anonymous identifier used only to support cloud sync of your records. This does not require or collect an email address, password, or other directly identifying account information.
Firebase Analytics (Google LLC) Collects basic app usage behavior, such as which screens are opened and which features are used, together with subscription-related events (e.g. viewing the Premium page, completing a purchase). Blood glucose values, meal/food names, and other health record content are never sent to Firebase Analytics.
Firebase Crashlytics (Google LLC) Automatically collects crash and error reports (device/OS information, error type, and stack trace) to help us find and fix bugs. Known local-database errors are converted to a generic error category before being sent, so the underlying blood glucose value, food name, or other record content is not included in crash reports.
Cloud Firestore (Google LLC) The App may transmit and store some of your blood glucose, meal, water, and exercise records in Cloud Firestore, associated with an anonymous identifier issued by Firebase Authentication. The on-device database is the App's primary data store, and the App does not currently provide a feature to restore on-device records from data stored in Cloud Firestore.
RevenueCat, Inc. Subscription status management. RevenueCat identifies your device using its own app-user identifier, which is separate from the Firebase identifier above.
Google AdMob / Google Mobile Ads SDK (Google LLC) Displays advertisements to users on the free plan (Premium subscribers do not see ads). Health information such as blood glucose values, meal/food records, and other health record content is not used for advertising targeting or personalized advertising by the App.
Apple App Store Payments, purchases, and subscription management

Through these services, we may receive information necessary to provide the App, including purchase status, subscription status, technical identifiers, and similar information.


2. How We Use Information

We use collected information for the following purposes:


3. Handling of Health-Related Information

The App may process information related to health, including blood glucose levels, meals, water intake, and exercise records.

We handle this information with greater care than general usage information and seek to use it only to the extent necessary to provide and improve the App.

The App is not intended to provide medical care, diagnosis, or treatment. Health-related information is processed for the purpose of helping users record and manage their own information.


4. Where Information Is Stored

4.1 Storage on the User's Device

Information entered into the App may be stored locally on the user's device depending on the user's environment and enabled features.

4.2 Storage on Servers

To provide functions necessary for the App, including data synchronization, subscription management, usage analytics, crash analysis, and advertising delivery, some information may be transmitted to and stored on servers operated by third-party service providers.


5. Sharing and Disclosure of Information

We do not disclose users' personal information to third parties except in the following circumstances.

5.1 With the User's Consent

When the user has provided consent to such disclosure.

5.2 Service Providers

We may engage third-party service providers to process information to the extent necessary to operate the App. In such cases, we seek to appropriately manage and oversee such service providers.

5.3 Third-Party Service Integrations

We may share information with third-party service providers for purposes including:

5.4 When Required by Law

When disclosure is lawfully required under applicable laws or by a court, government agency, or other public authority.

5.5 Business Transfers

In connection with a merger, corporate split, business transfer, reorganization, or other transfer of all or part of our business.


6. Data Security

We seek to implement reasonable and appropriate security measures to protect collected information against unauthorized access, loss, destruction, alteration, disclosure, and other risks.

However, because internet communications, cloud services, software, and information systems cannot be guaranteed to be completely secure, we cannot guarantee the absolute security of information.


7. Data Retention and Deletion

We retain collected information for as long as reasonably necessary to operate the App. When information is no longer necessary, we will take reasonable steps to delete, anonymize, or otherwise appropriately process it.

You can delete your data from within the App: open Menu → Data → Delete All My Data. This operation requires an internet connection. If your device is offline, the deletion does not start, and nothing is deleted. When it completes, it deletes your blood glucose, meal, water, and exercise records from the App's on-device database and the corresponding data stored in Cloud Firestore under your anonymous identifier, deletes the locally stored glucose target ranges, chart thresholds, and daily water and exercise goals, and deletes that anonymous identifier. A new anonymous identifier may then be issued so you can continue using the App. If the operation does not finish, you can retry it from the same menu. This action does not cancel an active subscription. If you cannot use this feature, contact us using Section 12.

This deletion does not erase information already sent to Firebase Analytics, Firebase Crashlytics, or Google AdMob, and it does not delete or reset the subscriber identifier held by RevenueCat. Those providers may keep that information for a limited period under their own policies.

Even after using this feature or deleting the App, we may retain certain information for a limited period where necessary to comply with legal obligations, maintain payment records, prevent fraud or abuse, resolve disputes, or for other legitimate purposes.


8. User Choices

Users may be able to control certain features, including notifications, advertising identifiers, tracking permissions, and subscription management, through device settings, settings within the App, or platform settings.

Please note that changing certain settings may result in some App features becoming unavailable or functioning differently.


9. Children's Information

The App may be used to record health information relating to the user or another person whose information the user is authorized to manage. If a user enters information about another person, particularly a minor, the user is responsible for ensuring that they have the lawful authority to enter and manage that information.

Except where required by applicable law, the App is not designed for the purpose of intentionally collecting personal information directly from children.


10. Use of Services Provided by Overseas Companies

We may use services provided by companies located outside Japan in connection with the operation of the App. As a result, user information may be stored or processed on servers located outside Japan.

By using the App, users acknowledge that their information may be processed by service providers located outside Japan in accordance with this Policy and applicable law.


11. Changes to This Privacy Policy

We may revise this Policy from time to time as necessary. If we make material changes, we will notify users through the App or by another method we consider appropriate.

The revised Policy will become effective when it is posted in the App or on our website, unless otherwise stated.


12. Contact Us

If you have any questions, comments, or inquiries regarding this Policy, please contact us at: