Privacy Policy
Effective date: May 19, 2026 · Last updated: May 19, 2026
Summary
Diabetes Action Layer ("DAL") is operated by GENAK ("GENAK", "we", "us"). DAL helps people with diabetes track glucose, meals, vitals, and activity, and provides AI-generated coaching grounded in published clinical guidelines. This policy explains what we collect, why we collect it, how we protect it, and the rights you have over your data. We do not sell your data. We do not use your identifiable health data to train AI models. We do not share your data with advertisers.
Who we are
DAL is operated by GENAK and available at diabeteslayer.com. For privacy questions or to exercise your rights, contact [email protected].
What we collect
Account information
- Email address and a hashed password (we never store your password in readable form).
- Display name, date of birth, and diabetes type if you choose to provide them.
Health data you enter
- Blood glucose readings, meals (including optional photos), medications, blood pressure, weight, activity, and notes.
- Onboarding responses used to personalize coaching (e.g. comfort with technology, goals).
Device and integration data
- Dexcom CGM. If you connect your Dexcom account, we receive your estimated glucose values (EGVs), timestamps, trend arrows, and Dexcom-provided metadata for the period you authorize. We use OAuth 2.0 and store encrypted access and refresh tokens; we never see or store your Dexcom password.
- FreeStyle Libre (LibreLinkUp). If you connect a LibreLinkUp follower account, we sign in on your behalf, retrieve the glucose measurements the patient has shared with that follower account, and store your follower credentials encrypted at rest (AES-256-GCM) so we can refresh your session.
- Bluetooth meters. If you pair a Bluetooth glucometer via your browser, we read measurements directly from the device using the Bluetooth Glucose profile.
Usage data
- Application logs (timestamps, endpoints accessed, success/error status) for security and debugging.
- HIPAA-style audit entries recording every access to your own protected health information.
- Approximate IP address and user-agent, used for rate limiting and fraud prevention.
How we use your data
- To show you your own data in charts, summaries, and estimates.
- To generate personalized action steps, pattern insights, and predictions. These are produced by rule-based algorithms and a large language model (LLM) running under our API key; your prompts include your recent data but are not used by the model provider to train public models.
- To let you share a time-limited summary with a clinician via a read-only link that you explicitly create.
- To send you transactional email required to operate your account (e.g. password reset). We do not send marketing email without separate opt-in.
- To secure the service: detect abuse, enforce rate limits, and satisfy our legal obligations.
Legal bases (GDPR)
If you are in the EEA or UK, we process your data under the following bases: (a) performance of our contract with you to deliver the service; (b) your explicit consent for processing of health data and for each third-party integration you connect; (c) our legitimate interest in keeping the service secure; and (d) compliance with our legal obligations.
How we protect your data
- TLS 1.2+ for all traffic to and from the service.
- AES-256-GCM encryption at rest for sensitive fields, including OAuth tokens and integration credentials.
- Passwords stored as salted bcrypt hashes; no plaintext password is ever logged or stored.
- HIPAA-aligned audit logging of every access to protected health information.
- Role-based access controls and strict separation of user data in the database.
- Security headers (HSTS, CSP, X-Frame-Options, referrer-policy) and CSRF protection on every mutating request.
- Regular dependency scanning and vulnerability patching.
No system is perfectly secure. If we discover a breach that affects you, we will notify you without undue delay.
Who we share data with
We share the minimum data necessary, and only with the following categories of recipients:
- Infrastructure providers that host the application (cloud hosting, managed database, managed Redis, email delivery). These providers act as data processors under contract and cannot use your data for their own purposes.
- AI model providers (e.g. Anthropic, OpenAI, Google) when generating a coaching response; prompts are processed under each provider's zero-retention or enterprise terms where available. These providers do not use your content to train public models under the terms we operate under.
- Device vendors you connect (Dexcom, Abbott via LibreLinkUp). When you authorize an integration we exchange tokens with the vendor on your behalf, and we pull only the data that integration returns.
- People you explicitly share with. When you create a provider-share link, anyone with that link can view the summary for the period and scope you selected. The link is time-limited and revocable.
- Law enforcement or regulators when required by a valid legal process.
We do not sell personal information, ever. We do not share personal information with advertisers.
Dexcom integration — what we receive
When you click "Connect Dexcom," you are redirected to Dexcom's servers to sign in and grant consent. Dexcom then returns an access token to our server. With that token we retrieve your estimated glucose values, systemTime/displayTime, trend, and trend rate for the periods you authorize. We do not receive your Dexcom account password, your contact information from Dexcom, or any data from other Dexcom users. You can disconnect at any time from the Devices page; disconnecting deletes the encrypted tokens from our database and stops future syncs. You can also revoke our access directly in your Dexcom account at any time.
Retention
- We keep your data for as long as your account is active.
- When you delete your account, we remove your personal data within 30 days, except for audit logs that we are required to retain for up to 6 years under HIPAA-aligned retention practices. Those audit logs do not contain health data; they record who accessed what and when.
- Aggregated, de-identified analytics (counts, trends across all users) may be retained indefinitely.
Your rights
- Access. You can view your own data in the app at any time and can request a machine-readable export.
- Correction. You can edit or delete individual entries directly in the app.
- Deletion. You can delete your account from Settings. This removes your personal data from our active systems within 30 days.
- Portability. You can request a copy of your data in JSON or CSV format by emailing [email protected].
- Withdraw consent. You can disconnect any third-party integration from the Devices page; future syncs stop immediately.
- Complaint. If you are in the EEA or UK, you have the right to lodge a complaint with your supervisory authority.
Children
Diabetes Action Layer is not intended for children under 13 (or under 16 in the EEA), and we do not knowingly collect personal data from them. If a parent or guardian wants to use the service on behalf of a minor, they must create the account and remain responsible for oversight of its use.
International transfers
Our infrastructure is hosted in the United States. If you access the service from outside the U.S., your data will be transferred to and processed in the U.S. under the protections described in this policy.
Cookies
We use strictly necessary cookies for authentication and CSRF protection. We do not use advertising cookies or third-party tracking cookies.
Changes to this policy
We may update this policy from time to time. If changes are material, we will notify you by email or through an in-app notice before the changes take effect. The "Last updated" date above always reflects the most recent revision.
Contact
Privacy questions, data requests, and formal complaints: [email protected].
See also our Terms of Service and Medical Disclaimer.