GlucoseLens

Retrospective meal-impact reports for Nightscout users

Privacy Policy

Last updated 3 September 2026

GlucoseLens is a small private-beta service for reviewing how meals affected your glucose. It handles health information, so this policy describes what it actually does rather than what a service like it might do. Where a protection does not exist yet, this policy says so.

Who runs this service

GlucoseLens is operated by Huckleberry Lane Labs. You can reach us at servicedesk@huckleberrylanelabs.com. We are a small operator, not a hospital, clinic, insurer, or medical device manufacturer.

This is not a HIPAA-covered service

We are not a HIPAA covered entity or a business associate, and GlucoseLens is not HIPAA-compliant. We hold no certifications and make no claim to any compliance framework. If you need your data handled under HIPAA, do not put it here. We take the protections described below seriously, but they are our own measures, not an accreditation.

What we collect

Only what the features you use require:

  • Account. Your email address, and an account identifier from our authentication provider. That is the whole of your profile record.
  • Nightscout connection. The address of your Nightscout site and its access token, both encrypted before they are stored. We also keep a non-reversible fingerprint of each, so we can tell whether a value has changed without decrypting it.
  • Glucose readings. Readings imported from your Nightscout site: the value, the time, and the trend field your uploader supplied. We do not store the raw payload your site returns; the database rejects it outright.
  • Meals. Meal names, estimated carbohydrates, any notes you type, and nutrition details you choose to import. Notes are free text, so whatever you put there is what we hold.
  • Derived analysis. Computed meal-impact figures and report summaries, such as a baseline and a peak around a meal.
  • Phone numbers, if you use text alerts. This includes the number of any person you nominate to receive them, which means we hold a phone number belonging to someone who may not have a GlucoseLens account. Encrypted before storage, with a non-reversible fingerprint used to recognise the same number and to honour STOP, and a record of that person's own agreement and when they gave it.
  • Meal photos, only if you separately opt in to keeping them. See below.

What we do not collect

  • No advertising or analytics trackers. We use no third-party analytics service.
  • No advertising, analytics, or tracking cookies, and no third-party analytics service. The app does set one cookie: the authentication cookie that keeps you signed in. It is strictly necessary for the service to work, it is written by our authentication provider rather than an advertiser, and it is cleared when you sign out.
  • No insulin or dosing data. We read only carbohydrate entries from Nightscout.
  • No location, contacts, or device identifiers.

Meal photos and the photo scanner

If you use the photo carb scanner, the photo you choose is uploaded to our server and sent to OpenAI, which estimates the food and its carbohydrates. This happens whenever you press the scan button; it is the feature working as intended, and there is no way to use the scanner without the photo reaching OpenAI. We ask OpenAI not to retain the image, and we send no name, email, glucose value, or medical history with it. What OpenAI does with data sent to its API is governed by its own terms, not ours.

The photo is not stored unless you tick the box to keep it. If you do not, the image exists only for the duration of that one request and is then discarded. It is never written to our database and never written to a log.

If you do opt in to keeping photos, we strip embedded metadata such as EXIF location and camera information before storing anything, and the image is placed in a private storage area that is not publicly reachable. You can list what is stored and delete it from the account settings page, which removes the image files and clears the associated records.

Text alerts disclose your glucose data to someone you choose

This is the most significant disclosure GlucoseLens makes, so it is described in full rather than summarised.

Text alerts are not a mailing list you subscribe to. You nominate a person — someone you trust to help you keep an eye on your glucose — and we text them. Once they agree, that person receives messages stating your glucose reading and whether it is rising or falling, and, if you turn it on, a daily summary of your previous day.

That means the person you nominate will see your health information. Choose someone you are willing to share it with. We cannot un-send a message once it has reached their phone, and it will remain in their message history and in their carrier's records.

Nobody is added silently. When you nominate a number we text it once, and that message links to a page explaining who added them, what will be sent, and how often — the same terms set out on the text alerts page. Nothing else is sent to that number unless the person opens that page and agrees for themselves. You cannot give that agreement on their behalf, and if they decline, the number is discarded.

To deliver any of this we send the number and the message text to Twilio. The number is stored encrypted and is never shown in full.

Anyone receiving these messages can reply STOPat any time and we withdraw consent for that number immediately — whether they are the account holder or the person who was nominated. That is permanent for that number: to receive texts again it must be added and confirmed afresh. Reply HELP for contact information. You can also remove a nominated person at any time from your own settings.

Where your data goes

We use these providers, and no others receive your information:

  • Supabase — the database, authentication, and file storage behind the app. Everything we keep is kept there.
  • Cloudflare — hosts and serves the application.
  • OpenAI — receives a meal photo when you use the scanner, as described above.
  • Twilio — receives your phone number and message text when you opt in to alerts.
  • Your own Nightscout site — we read from it, and write to it only when you confirm a specific entry.

We do not sell your information and we do not share it for advertising. The only person outside these providers who receives your health information is someone you have nominated yourself for text alerts, and only after they have agreed — see below. Beyond that we disclose nothing except where the law requires it.

How it is protected

Your Nightscout address and token, your phone numbers, and any report email address are encrypted before they are written, using a key held by the operator and not stored in the database. Verification codes are stored only as fingerprints, so someone reading the database cannot confirm a number they do not control.

Other data — glucose values, meal names, notes, and derived figures — is stored without field-level encryption, protected by Supabase's own encryption at rest and by database rules that confine every row to the account that owns it. Our diagnostic logs record counts and outcomes only: no reading, no phone number, no message text, and no photo is written to a log.

Writing back to Nightscout

GlucoseLens can add a carbohydrate entry to your own Nightscout site. It never does so on its own: you are shown the exact entry first, and the request is rejected unless it matches what you were shown. It writes carbohydrates only, never insulin, a dose, or a treatment.

Keeping and deleting your data

We keep what you have entered until you remove it. Today you can, on your own:

  • Delete an individual meal.
  • Delete stored meal photos, and export a list of what is stored.
  • Remove a phone number, or text STOP.

There is not yet a self-service button that deletes your whole account or exports all of your data. We are stating that plainly rather than implying a capability we have not built. Email us at servicedesk@huckleberrylanelabs.com and we will delete your account and everything attached to it, or send you a copy of your data. Deleting the account removes the linked records with it.

Children

GlucoseLens is not intended for children under 13, and we do not knowingly collect their information. A parent or guardian managing a child's diabetes remains responsible for the account and for what is entered into it.

Changes

If this policy changes in a way that affects what we collect or who receives it, we will update the date at the top and, where the change is significant, tell you in the app.