Trust Pack · Public Summary

Data Integration Principlesデータ連携原則

血糖データとつながるときの安全性、プライバシー、続けやすさの考え方です。

データ連携原則を案内するGluco
このページは、開発用の正本であるPROJECT_BIBLEと安全方針をもとに、公開向けにテーマ別で整理しています。
JP

日本語

まずはNightscoutから

現在は、開発と公開プレビューで現実的な入口としてNightscout形式のデータを使っています。ただし、GlucoScopeをNightscoutだけに固定するものではありません。

User Foundation 0.4

一般利用者向けの接続は2つに分けます。自分のNightscout環境はブラウザから直接読み取り、Gluroo Global Connectは接続先と取得内容を絞った限定中継機能を利用します。

GlurooのURLと接続用の合言葉は、選んだ端末のブラウザへ保存できます。限定中継機能では、表示に必要な血糖エントリーを一時的に処理しますが、接続情報や血糖データを保存、共有キャッシュ、ログ記録、AI送信しません。

接続情報が保存されている間は、AboutやTrustを含む同じGlucoScopeサイト内でアクセス解析を読み込みません。ユーザー版のグラフ処理も、外部CDNではなくGlucoScope内に同梱したファイルを使います。

方法①はGluroo、方法②はNightscout

どちらか1つを選べばよいことを明記し、方法のカードを押すと直接次へ進めます。GlurooはLibre・Dexcom G7・Guardian(MiniMed 780G)からつなぐ方へ案内し、Nightscoutは自分の環境をすでに使っている方や、構築・保守できる上級者向けとして分けます。

Guardianは、iPhoneのGuardian MonitorからGluroo Global Connect、限定中継、GlucoScopeまでの最初の全経路確認を完了しました。Libre 2も、FreeStyle LibreLink、LibreLinkUp、Gluroo、限定中継、GlucoScopeまでの基本経路で、現在血糖、グラフ、再読み込み、iOSホーム画面からの復帰を確認しています。2026年8月12日には、一般利用者向け限定中継のDexcom G7経路をiPhoneのSafariで確認し、接続、現在血糖、グラフの今日・昨日・7日・30日切替、再読み込み、接続削除後に設定画面へ戻ることまで合格しました。これらは過去の短時間チケット方式で行った確認です。別系統の公開デモWorkerでも、G7の定期取得と安全な公開応答を確認済みです。

Guardian(MiniMed 780G)

iPhoneのGuardian MonitorからGluroo Global ConnectへNightscout同期し、Glurooに血糖値とグラフが続けて表示されることを実機確認しました。Guardian MonitorはGlurooへデータを届ける入口であり、GlucoScopeがCareLinkやGuardian Monitorへ直接接続するものではありません。

Guardian Monitorで設定できるNightscout送信先は1つです。この点は、すでに別のNightscoutを使っている人にだけ小さく補足します。

Gluroo限定中継は1〜3人の先行体験中

GlurooはGlucoScopeとは別に運営される外部サービスです。Gluroo Global Connectは現在テスト期間中のため費用なしで利用できますが、将来はサブスクリプションになり、費用が必要になる可能性があります。有料Nightscoutサービスの「無料代替」として案内しません。料金、機能、画面、接続方法、利用条件は変わる可能性があります。

Cloudflare WorkerからGlurooへ到達できること、Guardian MonitorからGlurooへ送れること、過去の短時間チケット方式の基本境界は確認済みです。現在は、最初に1回安全確認をした後、ふだんは同じ端末でつながり続ける方式を少人数の先行体験で使っています。公開サイトと限定中継は、それぞれ専用のHTTPS接続先を使い、以前の公開中継先は閉じています。180日使わない時、ブラウザの保存を消した時、安全上必要な時は、もう一度確認します。

Glurooの公式資料では、利用する人が自分のGlobal Connect情報をNightscout互換ツールへ設定する方法が案内されています。現在確認したPrivacy PolicyとEULAにも、利用する人自身が選ぶこの限定中継を明示的に禁じる記載は見つかりませんでした。

2026年8月6日、Glurooから、EULA、利用条件、その他の文書と矛盾しない範囲で、今回の使い方は動作し問題ないとの文書回答を受け取りました。これはGlurooとの提携、推奨、法的助言、無条件の許諾を意味しません。GlucoScopeと限定中継は医療相談や医療判断には使えません。個別のCGMデータ再共有が適法かどうかをGlucoScopeが判断するものではなく、利用する人自身が必要な権限や許可を確認します。GlucoScopeや限定中継への質問は、GlurooではなくGlucoScopeが受けます。

Guardian、Libre 2、Dexcom G7の基本経路は、過去の短時間チケット方式で確認しました。新しい端末接続は、入力が正しくデータを受け取れた時だけ切り替え、入力ミスや一時的な障害では今までの接続を壊さない設計です。2026年8月16日、Dexcom G7で最初の安全確認を行い、その後iPhoneのホーム画面のアイコンから開き直しても、接続し直さず表示できることを実機で確認しました。この確認では、接続削除や削除後の再接続は試していません。提供元から停止要請があった場合、利用条件に重要な変更があった場合、異常な通信やプライバシー上の懸念が見つかった場合は、すぐに停止します。

公開比較は一般利用者向け中継と分ける

3CGM比較ラボでは、GuardianをKazumaの公開Nightscoutから直接読み、LibreとG7は公開デモ専用Workerが定期取得した期限付きKVだけを読みます。Kazumaは自分自身のLibreとG7の血糖値・測定更新時刻の公開へ別々に明示同意しました。この公開・非匿名の選択はKazuma自身のデモデータだけに適用します。安全対応と別の継続公開判断後、現在はGuardian・Libre・G7を継続公開中です。約3時間の継続稼働を確認しました。開いたままの既存ブラウザタブでも、約5分後の自動更新を別の機会にもう1回確認し、これまでの確認は合計2回になりました。表示エラーはありませんでした。正常な5分更新中は、成功するたびにKVの最長36時間の期限が更新されるため、自然失効は起きません。自然失効は、更新が止まった場合の別の安全確認として扱い、公開継続の妨げにはしません。`dexcomRouteVerified=true`はG7表示経路の確認記録で、Workerの有効化ではありません。一般利用者向け限定中継は別Workerで、現在は1〜3人の先行体験に限って有効です。

次の3段落は、一時確認後に停止へ戻した過去のチェックポイントです。現在の継続ライブ状態は、その後の段落に記録しています。

デモ専用Workerは、一般利用者向け限定中継とは別です。一般利用者向けリレーは停止したままで、一般利用者の接続情報や血糖データを保存しません。デモ用KVへ入れるのはKazumaが公開を選んだ直近24時間以内の血糖値、測定時刻、許可した方向情報だけで、最長36時間で期限切れになります。G7だけを一時有効にしたVersion `3b796eb5-11be-466f-83ea-7710279f49c1`では、Libreを停止したまま1回のCronで`public:dexcom-g7:v1`を作成し、公開応答190件の項目、型、範囲、時系列順、更新の新しさ、非公開情報を示す項目がないことを、血糖値や測定時刻を表示せず確認しました。許可OriginのGETは`200`、preflightは`204`、不許可Originは`403`、Libreは`503`でした。直後にdeployment `8de64190-7558-43c6-83c1-1e29a2cf80de`で停止Version `9994a142-a4ca-4885-9077-952ec8e7e8d2`へ100%戻し、両経路は再び`503`です。次の停止中Cron後もG7キーの有効期限は延長されませんでした。KVの生データは直接読み出しておらず、残ったキーは停止中の経路から配信せず、既存の36時間TTLで失効します。Secret値、Gluroo URL、実血糖値、測定時刻は画面出力やGitへ入れていません。停止中のG7接続先は`dexcomRouteVerified=false`のままGitHub Pagesへ反映し、合成データへの切替を確認済みです。このG7単独確認時点では、G7ライブ表示、3機種同時ライブ比較、ページ全体のライブ経路、複数回の定期更新と一般利用者向け限定中継のG7経路は未確認でした。

同じく2026年8月7日、別の明示確認後、Libreだけを一時有効にしたVersion `2e72847d-5011-47c5-80e6-8cb931a1b141`を1回の定期更新に限って本番通信へ反映しました。19:25 JSTのCronで公開`/v1/libre`応答が合計523件になったことを確認しました。件数と構造結果だけを使い、上位スキーマ、許可した項目、型、範囲、時系列順、更新の新しさ、確認対象の非公開項目がないこと、CORS境界を確認しました。実際の血糖値、測定時刻、Gluroo URL、Secret、tokenは検査出力やGitへ入れていません。G7は`503`のままでした。確認後すぐ停止Version `9994a142-a4ca-4885-9077-952ec8e7e8d2`へ戻し、両経路が`503`であることを確認しました。次の停止中Cron後もLibreキーの有効期限は延長されませんでした。確認できたのはLibreの1回の定期取得と安全な公開Worker応答までです。

その後、別の明示確認を得て、LibreとG7を同時に有効にしたVersion `4069bca4-e8cf-474a-9e9d-d7ffa42b7567`をdeployment `9738343a-fc1d-4f02-aff1-1bae3d7cbe57`として20:58:02 JSTに本番通信へ反映しました。公開応答はLibre 527件、G7 276件で、許可した項目、型、範囲、時系列順、更新の新しさ、CORS境界を満たしました。実際の血糖値、測定時刻、接続先、Secret値は検査出力やGitへ入れていません。GitHub PagesではGuardian・Libre・G7の3つのライブカードを確認し、利用者自身も3本のグラフを目視しました。目視確認を待つ間に複数の定期実行が行われ、両KVキーの期限は21:15頃まで進みました。21:16:31 JST、deployment `e45b6547-33a4-4196-9efe-1fffd412bcd4`で停止Version `9994a142-a4ca-4885-9077-952ec8e7e8d2`へ100%戻し、両経路の`503`と、新しく開いた公開ページが「準備中・合成データ」へ戻ることを確認しました。21:25 JSTの停止中Cron後も両KVキーの期限は停止後の基準から変わらず、想定した2キーだけでmetadataもありませんでした。`dexcomRouteVerified=true`はフロント側の表示ゲートで、Workerの有効化ではありません。今回確認できたのは1回の公開ページ受け入れです。継続運用、複数回のブラウザ表示更新、古いデータ表示・自然失効は未確認で、一般利用者向け限定中継も停止中です。

その後、フロント安全commit `6f13ed8c9c4b4b5cda1bdaddc7b90a02bbff1265`をPages run `31181233497`で公開し、継続公開の別判断後、22:10:05 JSTにdeployment `e96fb11c-a2e0-4097-b54c-a1d638bbffc8`で同じ確認済みライブVersionを100%へ反映しました。定期集計確認はLibre 528件・G7 290件、次にLibre 526件・G7 290件で、両経路の`200`、`stale=false`、新しさ、許可した構造・型・範囲・順序・CORS・cache・応答サイズを満たしました。値、正確な測定時刻、接続情報、Secretは表示していません。その後、開始から約3時間の継続稼働を確認しました。開いたままの既存ブラウザタブでも、約5分後の自動更新を別の機会にもう1回確認し、これまでの確認は合計2回になりました。3機種のライブ状態を保ち、表示エラーはありませんでした。各ソースは15分境界で新しさを判定し、前回ライブの保持も15分までです。正常な5分更新中は、成功するたびにKVの最長36時間の期限が更新されるため、自然失効は起きません。自然失効は、更新が止まった場合の別の安全確認として扱い、公開継続の妨げにはしません。停止Version `9994a142-a4ca-4885-9077-952ec8e7e8d2`を復旧先として維持します。

複数の連携ルート

将来はMiniMed、Dexcom、Libre、CSV、手入力など、複数の方法を検討します。機器やサービスごとの差は、アダプター方式で吸収する設計を目指します。

個人クラウドへ預からない

利用者の血糖データを、Kazuma個人のクラウドへ集約・保有する形を基本にしません。利用者自身が管理するデータソースへ、必要な範囲で接続する方針です。

分かりやすい導入

ITスキルに応じて、構築支援、手順書、接続のみなど、複数の導入ルートを用意する考えです。難しさを利用者の責任にしません。

外部サービスの限界

外部API、CGM、Gluroo、Nightscout、ネットワークには遅延、欠損、重複、仕様変更の可能性があります。GlucoScopeは異常や古いデータを、できるだけやさしく明示します。

技術支援と医療相談を分ける

接続や設定の技術支援は検討しますが、医療判断、治療判断、インスリン量や機器設定の助言は行いません。

EN

English summary

Nightscout first

Nightscout is the current practical starting point, not a permanent lock-in.

User Foundation 0.4

The general-user connection has two distinct routes. An existing Nightscout environment is read directly by the browser. Gluroo Global Connect uses the narrowly scoped Limited Data Relay.

The Gluroo URL and passphrase may be saved in the selected browser. The relay processes only the glucose entries required for display and does not store, cache, log, or send the connection information or glucose payload to AI.

While a connection is stored, analytics is not loaded on same-origin GlucoScope pages, including About and Trust. The user-data page also uses a locally vendored chart runtime instead of a third-party CDN script.

Beginner-first setup

The screen says that only one route is needed. Method 1 uses Gluroo for Libre, Dexcom G7, and Guardian (MiniMed 780G). Method 2 is for people who already use or maintain their own Nightscout environment.

Guardian has completed its first iPhone end-to-end acceptance from Guardian Monitor through Gluroo Global Connect, the limited relay, and GlucoScope. FreeStyle Libre 2 has separately completed its first basic path from FreeStyle LibreLink through LibreLinkUp, Gluroo, the relay, and GlucoScope. On 2026-08-12, the general-user Dexcom G7 path also passed connection, graph-period, reload, and deletion checks. These checks used the historical short-lived-ticket design. Separately, the public-demo Worker has passed G7 scheduled-retrieval and sanitized-response checks.

Gluroo limited relay is in 1–3 person early access

Gluroo is an external service operated separately from GlucoScope. Gluroo Global Connect currently has no cost during its testing phase, but Gluroo is considering a subscription model and GGC may not remain free. GlucoScope does not market it as a free alternative to subscription Nightscout services. Pricing, features, screens, connection methods, and terms may change.

Worker-to-Gluroo reachability, Guardian Monitor upload to Gluroo, and the historical short-lived-ticket boundaries are verified. The small early-access group now uses a replacement that performs one safety check and then normally keeps the same device connected. The public site and relay each use a dedicated HTTPS endpoint, and the former public relay target is closed. It asks again after 180 days without use, after browser data is removed, or when a security change requires it.

Gluroo's official materials explain how a person can use their own Global Connect details with Nightscout-compatible tools. The Privacy Policy and EULA reviewed for this phase do not state an express prohibition on this user-directed limited relay.

On 2026-08-06, Gluroo replied in writing that the proposed use should work and was acceptable to them only to the extent that it remains consistent with the EULA, terms, and other Gluroo documents. This does not create affiliation, endorsement, partnership, legal assurance, or an unconditional license. GlucoScope and the relay are not for medical advice or medical decision-making. GlucoScope does not determine whether a particular person's CGM data re-sharing is lawful; each person remains responsible for the necessary authority and permissions. Questions about GlucoScope or its relay are handled by GlucoScope, not Gluroo.

Guardian, Libre 2, and Dexcom G7 completed their basic route checks under the historical short-lived-ticket design. The new device-session design changes a connection only after the proposed details return glucose data, so a typo or temporary provider failure does not discard the existing working connection. On 2026-08-16, Dexcom G7 completed the first safety check and then reopened from the iPhone Home Screen icon without reconnecting. Connection deletion and reconnection after deletion were not tested in that run. The relay will be paused immediately if Gluroo objects, applicable terms materially change, abnormal traffic is detected, or a privacy concern appears.

Public comparison stays separate from the general-user relay

The 3CGM Comparison Lab reads Guardian directly from Kazuma's public Nightscout and reads Libre and G7 only from expiring KV snapshots refreshed by a dedicated demo Worker. Kazuma separately consented to publishing his own Libre and G7 glucose values and measurement/update timing. This public, non-anonymous choice applies only to Kazuma's demo data. After the frontend safety release and a separate continuing-publication decision, Guardian, Libre, and G7 are now published continuously. About three hours of continuous operation passed. At a later checkpoint, an existing browser tab completed one further five-minute auto-refresh, bringing the total confirmed browser refreshes to two, without display errors. During healthy five-minute refreshes, each successful write renews the KV's maximum 36-hour lifetime, so natural expiry does not occur. Natural expiry is a separate, non-blocking stopped/failure-path check. `dexcomRouteVerified=true` records G7 display-path verification and does not enable the Worker. The separate general-user Limited Data Relay is currently enabled only for 1–3 person early access.

The next three paragraphs are historical checkpoints that were returned to the stopped state after temporary checks. The later paragraph records the current continuous-live state.

The demo-only Worker is separate from the general-user Limited Data Relay. The general-user relay does not store general-user connection details or glucose data and is currently limited to 1–3 person early access. Demo KV may contain only Kazuma's consented glucose values from the latest 24 hours, measurement times, and an allowlisted direction, and expires within 36 hours after the last successful refresh. Temporary G7-only Version `3b796eb5-11be-466f-83ea-7710279f49c1` kept Libre disabled while one Cron created `public:dexcom-g7:v1`. The 190-entry public response passed the reviewed field, type, bound, ordering, recency, and private-marker checks without printing glucose values or measurement timestamps. Approved-origin GET returned `200`, preflight `204`, an unapproved Origin `403`, and Libre remained `503`. Deployment `8de64190-7558-43c6-83c1-1e29a2cf80de` then restored stopped Version `9994a142-a4ca-4885-9077-952ec8e7e8d2` at 100%; at that historical checkpoint both routes returned `503`, and the next stopped Cron did not extend the retained G7 key expiry. The raw KV value was not directly read. At that checkpoint the key was not served, its expiration was unchanged, and the stopped G7 endpoint was published with `dexcomRouteVerified=false`; the GitHub Pages synthetic fallback check passed. At that G7-only checkpoint, G7 live rendering, simultaneous live three-source comparison, the full live page path, repeated scheduled refreshes, and the general-user Limited Data Relay G7 path were unverified.

Also on 2026-08-07, after another separate explicit approval, Libre-only Version `2e72847d-5011-47c5-80e6-8cb931a1b141` received production traffic for one scheduled refresh. The 19:25 JST Cron produced a public `/v1/libre` response with 523 entries. Aggregate-only validation passed the reviewed top-level schema, entry-field allowlist, type, range, chronological-order, recency, private-marker, and CORS checks. No actual glucose value, measurement timestamp, Gluroo URL, Secret, or token entered validation output or Git. G7 remained at `503`. Stopped Version `9994a142-a4ca-4885-9077-952ec8e7e8d2` was then restored; both routes returned `503`, and the next stopped Cron did not extend the Libre key expiration. This verifies one Libre scheduled retrieval and sanitized public Worker response only.

Later, after separate explicit approval, live Version `4069bca4-e8cf-474a-9e9d-d7ffa42b7567` enabled Libre and G7 together in deployment `9738343a-fc1d-4f02-aff1-1bae3d7cbe57` at 20:58:02 JST. The public responses contained 527 Libre entries and 276 G7 entries and passed the reviewed field allowlist, type, range, chronological-order, recency, and CORS checks. No actual glucose value, measurement timestamp, source URL, or Secret value entered validation output or Git. GitHub Pages showed live Guardian, Libre, and G7 cards, and the user visually confirmed three graph lines. Several scheduled runs occurred while visual confirmation was pending, advancing both KV expirations to about 21:15. At 21:16:31 JST, deployment `e45b6547-33a4-4196-9efe-1fffd412bcd4` restored stopped Version `9994a142-a4ca-4885-9077-952ec8e7e8d2` to 100%. Both routes returned `503`, and a newly opened page returned to the clearly labelled synthetic dataset. After the 21:25 JST stopped Cron, both KV expirations were unchanged from the post-stop baseline; only the two expected keys remained and neither had metadata. `dexcomRouteVerified=true` is a frontend display gate and does not enable the Worker. This completes one public-page acceptance; continuing operation, repeated browser-display refreshes, stale display, and natural expiry remain unverified. The general-user Limited Data Relay remains paused.

After frontend safety commit `6f13ed8c9c4b4b5cda1bdaddc7b90a02bbff1265` was published by Pages run `31181233497`, a separate continuing-publication decision assigned 100% of demo traffic to the same reviewed live Version through deployment `e96fb11c-a2e0-4097-b54c-a1d638bbffc8` at 22:10:05 JST. Scheduled aggregate checks observed Libre/G7 counts of 528/290 and then 526/290. Both routes returned `200` with `stale=false` and passed the reviewed freshness, schema, type, range, order, CORS, cache, and response-size boundaries without printing values, exact measurement times, connection details, or Secrets. About three hours of continuous operation passed. At a later checkpoint, an existing browser tab completed one further five-minute auto-refresh, bringing the total confirmed browser refreshes to two. All three live sources remained available, with no display errors. Each source uses a 15-minute freshness boundary and preserves a previous live view for at most 15 minutes. During healthy five-minute refreshes, each successful write renews the KV's maximum 36-hour lifetime, so natural expiry does not occur. Natural expiry remains a separate, non-blocking stopped/failure-path check. Stopped Version `9994a142-a4ca-4885-9077-952ec8e7e8d2` remains the rollback target.

Multiple paths

Future adapters may support MiniMed, Dexcom, Libre, CSV, and manual input.

No personal data hub

User glucose data should not be centralized in Kazuma’s personal cloud.

Clear boundaries

Technical connection support is separate from medical advice or treatment decisions.