Privacy Policy
Effective: April 12, 2026 · Last updated: April 12, 2026
Summary
IsletIQ helps people living with Type 1 Diabetes track glucose, insulin, meals, sleep, and vitals. Your health data is yours. We don't sell it, we don't use it for advertising, we don't train models on it, and we encrypt it in transit and at rest. This page explains exactly what we collect and how we use it.
Data We Collect
IsletIQ may collect the following categories of data, only when you explicitly grant permission or use a feature that requires it:
- Health & fitness data:glucose readings, insulin doses, carbohydrate and meal entries, sleep, heart rate, HRV, VO₂ Max, blood pressure, body temperature, blood oxygen, steps, and active calories. This data is read from and written to Apple HealthKit on your device.
- Account information:email address and an opaque user ID, used to authenticate you and sync your data across your devices.
- Voice and photo input:when you use Agentic Sync, microphone audio and photos you choose to submit are processed to extract meal information and respond to your questions.
- CGM and pump credentials:when you connect a third-party device (e.g., Dexcom, LibreLink), the credentials needed to fetch your readings are stored in the device Keychain.
- Diagnostic logs:anonymous, technical information needed to keep the service running (request timing, error reports). No health data is included in diagnostics.
HealthKit Data
IsletIQ's use of Apple HealthKit complies with Apple's HealthKit framework requirements:
- HealthKit data is never used for advertising or marketing.
- HealthKit data is never sold, shared with data brokers, or used for purposes other than providing the service.
- HealthKit data is never stored in iCloud or any unauthorized third-party cloud service.
- HealthKit data is encrypted in transit (TLS 1.3) when synced to our backend, and encrypted at rest within our infrastructure.
- You control which HealthKit data types IsletIQ can read or write at any time via the iOS Settings app under Health → Data Access & Devices → IsletIQ.
How We Use Your Data
We use your data only to provide and improve the service:
- Show you live glucose, insulin, meal, and vitals data.
- Generate personalized insights, alerts, and AI-assisted guidance.
- Sync data between your iPhone, Apple Watch, and any other devices linked to your account.
- Authenticate you and secure your account.
- Diagnose technical issues and improve performance and reliability.
We do not use your data for advertising, profile sale, behavioral targeting, or model training.
Third-Party Services
IsletIQ integrates with a small number of third parties, only with your permission, only for the features you use:
- Dexcom and Abbott LibreLink:to fetch your CGM readings if you connect a CGM. Your credentials are stored locally; we never see them.
- Apple HealthKit:to read and write health records on your device.
- Amazon Web Services (AWS):secure U.S.-hosted infrastructure for syncing your account data.
- OpenAI / Anthropic / ElevenLabs:for Agentic Sync responses and voice synthesis. Voice and chat transcripts are sent only when you actively use the AI feature.
Data Retention and Deletion
You can delete your account and all associated data at any time from Settings → Account → Delete Account within the app, or by emailing us at hello@isletiq.com. Deletion is permanent and propagates to all backend storage within 30 days.
HealthKit data remains on your device under your control even after you delete your IsletIQ account. To remove HealthKit data, use the Apple Health app.
Your Rights
Depending on where you live, you may have the right to access, correct, port, restrict, or delete your personal data, and to object to processing. We honor these rights for all users regardless of jurisdiction. To exercise any of these rights, email hello@isletiq.com.
Children
IsletIQ is intended for users 13 years of age or older. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.
Security
We use industry-standard practices to protect your data: TLS 1.3 for all network traffic, AES-256 encryption at rest, hardened cloud infrastructure, principle of least privilege, and regular security review. No system is perfectly secure. If you discover a vulnerability, please report it to hello@isletiq.com.
Changes to This Policy
We may update this policy from time to time. When we do, we'll update the "Last updated" date above and, for material changes, notify you via the app or by email.
Contact
Questions about this policy? Email hello@isletiq.com.