Privacy Policy

DiaPulse Privacy Policy

We're committed to protecting your personal and health information. Here's exactly how we collect, use, store, and safeguard your data.

Effective Date: July 1, 2026Last Updated: July 1, 2026

1. Introduction

Welcome to DiaPulse ("we," "our," or "us"). DiaPulse is a diabetes management application designed to help individuals monitor their glucose levels, manage medications, and track their overall health. We are committed to protecting your personal information and your right to privacy.

This Privacy Policy explains how we collect, use, store, and protect your information when you use our mobile application and related services.

2. Information We Collect

2.1 Personal Information

  • Full name
  • Email address
  • Mobile number
  • Age, date of birth

2.2 Health Information

  • Blood glucose readings (fasting and post-meal)
  • A1C levels
  • Blood pressure
  • Weight and BMI
  • Diabetes diagnosis details and year
  • Medication names and dosages
  • Doctor and specialist names

2.3 App Usage Information

  • Reminder schedules and adherence history
  • Glucose trend data
  • Health documents and lab reports you upload
  • Streak and adherence statistics
  • Device FCM token (for push notifications)

2.4 Technical Information

  • Device type and operating system
  • App version
  • Error logs (for debugging purposes only)

3. How We Use Your Information

We use the information we collect to:

  • Provide and maintain the DiaPulse app and its features
  • Send medication and glucose check reminders via push notifications
  • Track your glucose trends, streaks, and medication adherence
  • Store and display your health documents and lab reports
  • Calculate health statistics such as estimated A1C, time in range, and weekly averages
  • Improve app performance and fix issues
  • Respond to your support requests
We do not use your health data for advertising, marketing, or any commercial profiling purposes.

4. How We Store Your Information

Your data is stored securely using the following infrastructure:

  • Database: MongoDB (cloud-hosted), protected with access controls and encryption at rest
  • File Storage: Amazon Web Services S3 (for uploaded health documents and lab reports)
  • Backend: Hosted on Vercel with HTTPS encryption in transit
  • Push Notifications: Firebase Cloud Messaging (FCM) is used solely to send health reminders

All data transmission between the app and our servers is encrypted using HTTPS/TLS.

5. Data Retention

We retain your data for as long as your account is active. If you choose to delete your account:

  • Your personal profile and health records will be permanently deleted within 30 days
  • Uploaded documents stored in cloud storage will also be permanently removed
  • Anonymized, non-identifiable usage statistics may be retained for service improvement

6. Sharing of Information

We do not sell, rent, or share your personal or health information with third parties except in the following limited cases:

  • Service Providers: We use AWS S3, MongoDB, Firebase, and Vercel solely to operate the app. These providers are bound by their own privacy and security policies.
  • Legal Requirements: We may disclose your information if required by law, court order, or government authority.
  • Emergency Situations: If there is a risk to your life or the life of others, we may share relevant information with emergency services.
We never share your health data with insurance companies, employers, advertisers, or data brokers.

7. Your Rights

You have the following rights over your data:

  • Access: Request a copy of all data we hold about you
  • Correction: Update or correct any inaccurate personal or health information
  • Deletion: Request permanent deletion of your account and all associated data
  • Portability: Request your health data exported in a readable format (JSON or CSV)
  • Notification opt-out: Disable push notifications at any time from your device settings

To exercise any of these rights, contact us using the details in Section 10.

8. Children's Privacy

DiaPulse is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately and we will delete it.

9. Security

We take the security of your health data seriously and implement the following measures:

  • Passwords are stored using bcrypt hashing (never in plain text)
  • All API communication is encrypted over HTTPS
  • Health documents are stored in private cloud storage (AWS S3)
  • Firebase tokens are stored securely and used only for sending reminders
  • Access to our database is restricted and monitored

Despite these measures, no system is 100% secure. We encourage you to use a strong password and keep your app updated.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at:

DiaPulse Support Team

Email: privacy@diapulse.app

Website: www.diapulse.app

We will respond to all privacy-related requests within 7 business days.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will:

  • Update the "Last Updated" date at the top of this page
  • Notify you via a push notification or in-app message if changes are significant

Continued use of DiaPulse after changes are posted means you accept the updated policy.

DiaPulse is committed to keeping your health data private, secure, and in your control.