Privacy Policy
The short version
Your data lives in its own database, on our server, for you alone. Your device passwords are encrypted and used for one thing: fetching your data.
Two kinds of thing leave our server: meal photos and coach questions go to Anthropic to be analysed and answered, and your device credentials go back to the vendor whose data we are fetching. That is the list.
No ads. No selling your data. No third-party trackers or analytics. You can download everything, or delete everything, from Settings.
1. What we hold
- Your account: your email address, a hash of your password (never the password itself), and your sign-in sessions.
- Health data from your devices: glucose readings, insulin doses, carbs, pump events, workouts, heart rate, recovery and sleep — whatever the services you connect actually give us.
- What you log yourself: meals, boluses, glucose you typed in, workouts, your targets and ratios, your training plan.
- Meal photos you take, and the estimates made from them.
- Coach conversations: what you asked and what the coach answered.
- The minimum technical exhaust: a session cookie so you stay signed in, your time zone so the numbers land on the right day, and server logs recording that requests happened. We do not run analytics, fingerprinting, advertising pixels, or any third-party script. The app loads nothing from anyone else's servers.
2. Where it lives
T1Q does not keep everyone's data in one big table with a column saying whose row is whose. Each account gets its own database file, in its own directory, on our server. Your glucose history and someone else's are not neighbours; they are separate files. That is a deliberate architectural choice — it means the usual way health apps leak across users (a forgotten filter in a query) has nothing to leak through.
Your meal photos are stored as files inside that same private directory.
[Placeholder: the server's hosting provider and physical region to be stated here before launch.]
3. Your device passwords
Some services — a CGM cloud, a pump data service, a wearable — have no proper way to give an individual access other than their own login. When you connect one, this is what happens:
- The credentials are encrypted before they touch the disk, with a key stored outside your account's directory. A copy of your account folder on its own decrypts to nothing.
- They are decrypted in memory only when a sync runs, and used only to fetch your data from that vendor.
- No API of ours ever returns them. Once saved, they cannot be read back out of T1Q by anyone, including us through the app.
- They are never written to a log.
- When you disconnect a device, the encrypted file is deleted, not blanked.
- They are excluded from our backups by construction — the backup script cannot copy them even if someone told it to.
What we cannot do is make a third-party login safer than it is. If you would rather not hand over a vendor password, do not connect that vendor.
4. What goes to Anthropic, and what that means
Two features use Anthropic's Claude API, and both send data out of our server to do it:
- Meal photos. When you photograph a meal, the image is resized and sent to Anthropic's API, which returns a carb and macro estimate. The photo is sent as part of the request. If a photo has your kitchen, your hands, or other people in it, that goes too.
- The coach. Your question is sent, along with the parts of your own history the answer needs — for example your glucose statistics for a period, your recent workouts, your recent meals, or your low-glucose episodes. The coach fetches those from your database and includes them in the request. Earlier turns of the same conversation are sent too.
Your email address and your device credentials are never included. Anthropic receives health information about an anonymous person, not an identified account.
Anthropic is a separate company and their handling of that data is governed by their own terms, not ours. As of this draft, their commercial API terms state that inputs and outputs are not used to train their models, and are retained only briefly for safety monitoring. That is their policy and it can change — read it yourself if this matters to you, at anthropic.com/legal.
If you never take a meal photo and never use the coach, nothing about your health leaves our server for this purpose.
5. Everyone else your data touches
- The device vendors you connect — Dexcom, Glooko, Whoop and the like. We send them your credentials to fetch your data; they see requests coming from us on your behalf. They already have this data; that is why you are connecting them.
- An email provider, to deliver your six-digit sign-in and password-reset codes. It sees your email address and the message. We do not send health information by email.
- Our hosting provider, in the ordinary sense that they operate the machine.
That is the complete list. There is no advertising network, no analytics vendor, no data broker, no "partner". We do not sell your data, and we do not share it for anyone else's marketing. If law enforcement ever compelled disclosure, we would tell you unless legally forbidden.
[Placeholder: named sub-processors and their locations to be listed here before launch.]
6. Models, and what we train on
T1Q's prediction models are trained on openly licensed public research datasets, not on the data of the people using the app. If a model is ever personalised to you, it is trained on your data alone, it lives in your account, and it is deleted with your account. Your data is not used to improve anyone else's experience, and it is not sold to anyone who trains on it.
7. Backups
We take a snapshot of the databases every night and keep the most recent fourteen, so a crash or a mistake costs you hours rather than years. Backups deliberately exclude the encrypted credential vault and its key — a stolen backup disk contains no vendor logins.
Because backups exist, deleted data does not vanish from every copy the instant you delete it. It ages out of the backup set as those snapshots roll over — currently within about two weeks.
8. What you can do about all of this
- Export everything. Settings → Your data → Download. You get a zip containing what we hold: your readings, doses, meals, photos, workouts, coach conversations and settings.
- Delete everything. Settings → Your data → Delete my account. You confirm by typing DELETE and entering your password. Deletion is then scheduled seven days out and you can cancel any time within that window by signing in. After it runs, your database, your photos, your credentials and your account are erased, and the copies in backups age out as described above. We cannot undo it.
- Disconnect a device at any time — its stored credentials are deleted immediately.
- Change your password, which signs out every other device.
If you are somewhere with statutory data rights (access, correction, portability, erasure, objection), exercise them by contacting us — but note that export and delete already give you most of them, immediately, without asking permission.
9. Security, honestly
What is true: credentials are encrypted at rest, passwords are stored only as hashes, each account is a physically separate database, traffic runs over HTTPS, and backups exclude secrets.
What is also true: T1Q is early software run by a very small operation. There is no security team, no independent audit, and no bug bounty yet. Nobody can promise a system will never be breached, and we are not going to pretend otherwise. If we discover a breach affecting your data, we will tell you what happened, what was exposed, and when — quickly and in plain language.
10. Children
T1Q is not for people under 18. We do not knowingly collect data from children. If a child's data has ended up here, contact us and we will delete it.
11. Changes to this policy
If we change something that matters — a new place your data goes, a new thing we collect — we will tell you in the app or by email before it takes effect, and you will have time to export and leave.
12. Contact
[Placeholder: privacy contact email address to be filled in before launch.]