Skip to content
Dulce

Legal

Privacy Policy

Last updated: 2026-07-08

This Privacy Policy explains what personal data Dulce collects, how we use it, and the rights you have over it. It applies to both this website (dulceglucosa.com) and the Dulce mobile application.

1. Data controller

The data controller is Giorgio Khimshiashvili, operating as a sole trader, based in Spain. You can contact us about anything related to your data at hola@dulceglucosa.com.

2. What data we collect

2.1 Website

  • Waitlist: your email and your session's language.
  • Beta form: name, email, CGM device, and region. Optionally, any notes you choose to share.
  • Minimal technical data: an anonymous hash (SHA-256) of your IP combined with a daily-rotating salt, used only to throttle form abuse. We never store the raw IP.
  • Anonymous analytics: we use Vercel Analytics, which sets no cookies and collects no personal identifiers. It only measures page views and performance.

2.2 In the app, on your device

  • Your LibreLinkUp credentials. You sign in with the email and password of your LibreLinkUp account (Abbott). They are stored only in your device's secure keychain and are used to fetch your glucose from Abbott's service. They are never sent to Dulce servers.
  • Glucose readings fetched from LibreLinkUp, stored in a local database on your device.
  • Your logbook: carbohydrates, insulin, manual glucose entries and notes. Stored locally.
  • Apple Health data in read-only mode, if you grant permission.
  • Preferences: units, target range, language, theme, alert settings.

2.3 The Dulce relay (real-time features)

Some features need to keep working while your phone is locked or the app is closed: the Lock Screen Live Activity, glucose alerts, Apple Watch updates and family following. To power them, a small server operated by us (the "relay", hosted on Cloudflare) fetches your readings from LibreLinkUp and pushes them to your devices. When — and only when — you turn one of these features on, the relay processes:

  • A LibreLinkUp session token (not your password), so it can fetch readings on your behalf.
  • Anonymous push tokens for your devices, issued by Apple or Google. They identify a device for notifications; they don't identify you personally.
  • Your most recent glucose readings, kept as a short rolling window needed to render the Live Activity, watch and follower views. The relay is not a long-term store of your health history — that stays on your device.
  • The minimum settings needed to format what you see (units, target range, alert thresholds, language).

If you never enable these features, nothing is sent to Dulce servers. If you turn them off, sign out, or delete your account in Settings, the associated relay data is deleted.

2.4 Family following

If you invite someone to follow you, the relay delivers your recent readings and alerts to their device from the moment they accept — earlier history is not shared. Short predefined nudge messages between you and your followers also pass through the relay. You can revoke a follower's access at any time, and you can turn off follower messages entirely.

2.5 Purchases

Subscriptions are processed by Apple. We never see your name, card or billing details. We use RevenueCat to validate subscriptions using a random identifier generated by the app — not your email or your identity.

3. Why we use your data

  • Show your glucose on your devices and, if you choose, your followers' devices.
  • Deliver the alerts you configure.
  • Validate your subscription and unlock Pro features.
  • Let you know when Dulce is available (waitlist).
  • Protect the site from abuse (IP hash, rate limit).
  • Understand which pages perform best (anonymous analytics).
  • Comply with legal obligations and respond to your rights requests.
  • Explicit consent (Art. 9(2)(a) GDPR): processing your glucose data through the relay when you enable real-time features or family following.
  • Contract (Art. 6(1)(b) GDPR): providing the app and the features you subscribe to.
  • Consent (Art. 6(1)(a) GDPR): when you join the waitlist or beta.
  • Legitimate interest (Art. 6(1)(f) GDPR): basic site security and anonymous analytics.

5. Special category data (Art. 9 GDPR)

Glucose readings and other health data are special categories of personal data. Our approach:

  • By default, they are processed and stored only on your device.
  • They reach our relay only when you explicitly enable a feature that requires it, and only as a short-lived recent window.
  • They are always encrypted in transit (TLS).
  • They are used exclusively to deliver your own data to your own devices and to the followers you choose — never for advertising, profiling or resale.

6. How long we keep your data

  • Relay data: recent readings are overwritten continuously; session and push tokens are kept while the feature is active and deleted when you disable it, sign out, or delete your account (Settings → Delete account).
  • App data on your device: until you delete it or uninstall the app.
  • Waitlist: until launch + 6 months, or until you ask to be removed.
  • Beta form: for the duration of the beta + 12 months.
  • IP hash: 30 days.

7. Who we share your data with

We share data only with the providers strictly required to run the service. They all act as processors under contract:

  • Cloudflare — hosts the Dulce relay described above.
  • Apple — push notifications (APNs), Live Activities, Apple Health (on-device), and payments.
  • Google Firebase — push notifications on Android.
  • RevenueCat — subscription validation (pseudonymous ID only).
  • Supabase (waitlist and beta storage) — hosted in the EU (eu-west-3).
  • Resend (waitlist confirmation email) and Vercel (website hosting and anonymous analytics).
  • Abbott (LibreLinkUp) — your device and our relay connect to Abbott's service with your credentials/session to fetch your readings. That connection is governed by Abbott's own privacy policy.

We never sell, rent or hand over your data to third parties for advertising or commercial purposes.

8. International transfers

Some of our processors (Cloudflare, RevenueCat, Resend, Vercel, Apple, Google) process data in the US or at global edge locations. Transfers are made under the European Commission's Standard Contractual Clauses (SCCs) or equivalent frameworks (DPF). You can request a copy of these safeguards at hola@dulceglucosa.com.

9. Your rights

As a data subject, you have the right to:

  • Access your personal data.
  • Rectify it if inaccurate.
  • Request its deletion.
  • Object to processing or request restriction.
  • Portability of data you have provided.
  • Withdraw your consent at any time.

The fastest way to delete everything Dulce holds about you is Settings → Delete account inside the app. You can also exercise any of these rights by writing to hola@dulceglucosa.com. We respond within 30 days at the latest.

If you believe our processing does not comply with the law, you have the right to file a complaint with the Spanish Data Protection Agency (AEPD).

10. Children

Dulce is not directed at children under the age of 14. A parent or legal guardian may use Dulce to follow a minor's glucose under their own responsibility. If you believe a minor in your care has provided us with data without your consent, contact us and we will delete it.

11. Cookies

We only use strictly necessary technical cookies (language preference, CSRF token on forms). We do not use tracking or advertising cookies. More in our Cookie Policy.

12. Changes to this policy

If we make material changes, we will notify affected users by email or inside the app and publish the updated version with its revision date on this page.

13. Contact

For any questions about this Privacy Policy or the processing of your data, write to hola@dulceglucosa.com.