Privacy Policy

Effective Date: July 1, 2026

This Privacy Policy is a legally reviewed draft and may be updated before official launch as vendors (e.g., payment processors) are finalized.

GlucoUs Inc. (hereinafter the "Company") establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, and other relevant laws, to protect users' personal information and to promptly and smoothly handle related grievances.

Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. Personal information is not used for any purpose other than those stated below, and if the purpose of use changes, the Company will take necessary measures such as obtaining separate consent.

  1. Membership registration and management — maintaining membership status, preventing fraudulent use, delivering notices
  2. Service provision — meal logging, providing carbohydrate estimates, meal history lookup, and other app features
  3. Service improvement and statistical analysis — understanding usage, diagnosing app errors, developing new features
  4. Marketing and information — event and new service announcements (only where separate consent is obtained)

Article 2 (Personal Information Items Processed)

General Items Collected

  • Account: Email address, social login identifier (Google/Apple ID) — required, at registration
  • Service Usage: Food photo images, food selection history, portion adjustment inputs, meal history — required, during Service use
  • Device: Device identifier, OS type/version, app version, language settings — automatically collected
  • Service Logs: Access timestamps, feature usage records, error logs — automatically collected

Food photo images may contain information from which a user's dietary habits and health condition could be inferred. The Company does not use this information beyond the purposes stated in Article 1.

Sensitive Information (collected only with separate explicit consent)

The following items constitute sensitive information (health information) under Article 23 of the Personal Information Protection Act. The Company obtains explicit consent separate from general personal information consent before collection; declining does not restrict access to the Service's core features.

  • Diabetes type (Type 1/Type 2/gestational, etc.) — from Phase 1.5 onward, if entered directly by the user, optional
  • CGM blood glucose data — from Phase 1.5 onward, if a CGM device is connected, optional

The above sensitive information is not collected during the initial Phase 1 launch.

Optional Consent Items (Research Participation)

The Company may pseudonymize users' meal record and nutrition data and use it as follows. Each purpose can be individually opted into, and declining does not result in any disadvantage in using the Service.

Category Purpose of Use Retention Period Consent Type
Scientific research
(no consent required, Art. 28-2)
Improving AI recognition and nutrient estimation algorithms through analysis of correlations between meal images and nutrition data Until purpose is achieved No legal consent required
(Company implements safeguards)
Academic research
(IRB review required)
Joint research with academic institutions on dietary habits and metabolism Until research purpose is achieved
(scheduled for deletion)
Optional opt-in
(Service remains available if declined)

When pseudonymized data is used for academic research, the Company proceeds only after the relevant research undergoes IRB (Institutional Review Board) ethical review. To ensure the safety of pseudonymized information, the Company implements managerial (internal management plan, regular training), technical (separate storage of additional information, restricted access, retention of processing records), and physical (access control to server rooms and data storage areas) safeguards.

Article 3 (Processing and Retention Period)

Item Retention Period Basis
Account information, service usage records Destroyed immediately upon withdrawal Fulfillment of service contract purpose
E-commerce transaction records 5 years Act on Consumer Protection in E-Commerce
Consumer complaint/dispute records 3 years Act on Consumer Protection in E-Commerce

Article 4 (Provision of Personal Information to Third Parties)

The Company does not provide personal information to third parties without user consent, except in the following cases:

  1. Where the user has given prior consent
  2. Where requested by an investigative agency based on applicable law
  3. Where pseudonymized data is used for academic research with the user's research-participation consent and IRB review

Article 5 (Outsourcing of Personal Information Processing)

The Company outsources the following processing tasks for Service operation and establishes the necessary safeguards in the outsourcing contract.

Recipient Outsourced Task Retention Period
Google LLC (Firebase Auth) Member authentication processing Until withdrawal
Google LLC (Google Cloud Platform) Service infrastructure operation, data storage Until withdrawal

A payment processor will be added to this article once the payment method is finalized.

Article 6 (Cross-Border Transfer of Personal Information)

For the purpose of operating Service infrastructure, the Company transfers users' personal information overseas as described below, based on Article 28-8(1)(3) of the Personal Information Protection Act (processing entrustment/storage for contract performance) and disclosure through this Privacy Policy.

Recipient Country Items Transferred Method & Timing Purpose Retention Period
Google LLC
Contact: privacy@google.com
United States Account information, service usage data Real-time transmission over network, during Service use Member authentication, infrastructure operation Until outsourcing contract ends

Method, procedure, and effect of declining the cross-border transfer

Users have the right to decline this cross-border transfer by contacting the Chief Privacy Officer (Article 10). However, since this transfer is incidental to the operation of essential Service infrastructure (Google Cloud Platform), declining may limit registration and use of the Service.

Article 7 (Rights of Data Subjects and How to Exercise Them)

Users may exercise the following rights against the Company at any time:

  1. Request to view personal information
  2. Request correction of errors
  3. Request deletion
  4. Request suspension of processing
  5. Request data portability (Article 35-2 of the Personal Information Protection Act — the right to request transmission of personal information you provided, in a prescribed format, to another personal information controller)

Rights may be exercised via the in-app settings menu or by emailing the Chief Privacy Officer below, and the Company will act without delay.

Article 8 (Destruction of Personal Information)

The Company destroys personal information without delay once the retention period has elapsed or the processing purpose has been achieved.

  • Electronic files: permanently deleted using methods that prevent recovery
  • Paper documents: shredded or incinerated

Article 9 (Measures to Ensure Safety of Personal Information)

  1. Managerial measures — establishing an internal management plan, staff training, minimizing access rights
  2. Technical measures — access rights management, data encryption (in transit/at rest), security log management
  3. Physical measures — server access control (GCP Seoul region)

Article 10 (Chief Privacy Officer)

  • Name: Yoongyeom Kim (CEO)
  • Email: Gyeom@glucous.kr
  • Data subjects may direct all inquiries, complaints, and requests for relief related to personal information processing arising from use of the Company's services to the Chief Privacy Officer.

Article 11 (Processing of Personal Information of Children Under 14)

As a matter of principle, the Company does not collect personal information from children under 14 and verifies that users are 14 or older at registration. If a user is confirmed to be under 14, the Company immediately destroys that account's personal information.

Article 12 (Changes to This Privacy Policy)

This Policy takes effect from its effective date. Changes will be announced via in-app notice at least 7 days before taking effect; changes unfavorable to users will be announced at least 30 days in advance.

If you have any questions about this Privacy Policy, please contact Gyeom@glucous.kr.