Trust Pack · Public Summary

Privacy Notesプライバシーノート

GlucoScopeが使う情報、使わない情報、消す方法を、できるだけやさしく説明します。

プライバシーノートを案内するGluco
JP

日本語

まず知ってほしいこと

  • 公開デモに出ているのは、あなたの血糖データではありません。
  • 自分のデータをつなぐときも、血糖値や接続情報を利用状況の記録には入れません。
  • 利用状況の記録は、設定からいつでも止めたり、再開したり、削除したりできます。
  • GlucoScopeは医療機器ではなく、診断や治療、インスリン量の判断はしません。

公開デモ

公開デモには、Kazuma本人が公開に同意した血糖値、更新時刻、矢印だけを使います。公開ページは誰でも見ることができますが、ここに一般利用者のデータは混ざりません。

公開デモ用のデータは、表示に必要な範囲だけ一時保存します。更新が止まったデータは、最長36時間で消えます。

自分のデータをつなぐとき

接続先URLと合言葉は、保存を選んだ場合だけ、このスマートフォンやパソコンに保存します。共用の端末では保存しないか、使い終わったら削除してください。

Nightscoutは、この端末から直接読みます。Glurooのかんたん接続では、表示に必要な情報がGlucoScopeの中継を一時的に通りますが、GlucoScopeは接続情報や血糖データを保存、記録、AI送信、共有しません。通信を始める前に、画面でお知らせします。

Apple、Google、Gluroo、Dexcom、Libreなどのログインパスワードを、GlucoScopeへ入力することはありません。

次からもつながるための安全確認

Glurooは、最初につなぐ時だけ安全確認をします。その後は、この端末だけで使える保護された印をブラウザに持たせ、ふだんは安全確認をやり直さずにつなげます。この方式は、少人数の先行体験で使っています。Dexcom G7では、最初の安全確認後にiPhoneのホーム画面のアイコンから開き直しても、接続し直さず表示できることを確認しました。

180日使わなければ、その印は使えなくなります。ふだん使っている間は期限を先へ延ばしますが、ずっと使えることを約束するものではありません。ブラウザの保存を消した時、安全のための変更をした時、または運営側で止めた時は、もう一度安全確認をお願いします。

中継側に残すのは、元に戻せない形へ変えた端末の印、作った日時、最後に使った日時、使えなくなる日時、無効にしたかどうか、同じ接続先と合言葉かを確かめる元に戻せない印、その日の利用回数だけです。元の接続先URL、合言葉、血糖データ、氏名、メールアドレス、IPアドレス、端末やブラウザの名前は保存しません。利用状況の記録やPlusの本人確認とも結びつけません。

接続を削除するときは、この端末の接続先URLと合言葉を先に消し、その後で中継側の印も使えないようにします。通信できない時でも、端末内の削除は待たずに完了します。その場合、中継側に残った匿名の印は、最後に使った時から180日で使えなくなり、その後自動削除の対象になります。削除が終わる正確な時刻は約束しません。元のURLと合言葉は中継側にないため、その印だけで血糖データを読むことはできません。

iPhoneでは、まずSafariでGlucoScopeを開いて「ホーム画面に追加」し、追加したアイコンから開いて初回接続をしてください。Safariで先に接続してからアイコンを作ると、接続先URLと合言葉がアイコン側へ移らず、もう一度だけ入力が必要になることがあります。

表示名と利用状況

公開デモを見るだけなら、名前は必要ありません。自分のデータをつなぐときは、本名でなくてよい表示名を使います。

GlucoScopeをよくするため、表示名、使った日、AI分析を使った回数、通常のグルコの想い出の数を記録します。血糖値、接続情報、AIお手紙の本文は記録しません。

運営のため、この端末を見分けるランダムな番号、記録のオン・オフ、記録を始めた日と最後に使った日も保存します。IPアドレスを利用状況の記録として保存しません。通信や安全確認に必要な情報は、Cloudflareが同社の方針に沿って扱う場合があります。

利用状況の記録は、設定からいつでも停止・再開・削除できます。使った日の記録は90日分まで保存し、90日使われていない端末の記録は削除します。

公開する利用状況の合計には、名前や一人ずつの記録を出しません。少人数の行動を推測しにくくするため、前日までの30日間に活動した端末プロフィールが10件以上になった時だけ、全体の数を表示します。

削除した後も、Cloudflareの復旧用バックアップには、無料プランでは最大7日、有料プランでは最大30日残る場合があります。通常の画面や集計には表示されません。

これはアカウントではありません。別の端末とのまとめ直しや、ブラウザの保存を消した後の復旧はできません。

Plus 30日パス(まだ販売していません)

Plusは、300円を1回だけ支払い、購入できた時から30日間使う追加機能です。自動では更新されません。Plusを購入しなくても、血糖値を見る基本機能は使えます。Plusは医療サービスではなく、診断や治療の判断、優先医療相談は行いません。

販売を始める場合は、Plusを別の端末へ戻せるように、購入前にメールアドレスを確認します。このメールは、Plusの本人確認、復旧、購入に必要な連絡だけに使います。表示名や、この端末の利用状況の記録とは別に扱います。

確認メールは、Resendというメール送信サービスを使う予定です。送信に使うのは、宛先のメールアドレス、10分で使えなくなる6桁の確認コード、コードの入力方法を伝える短い案内です。氏名、血糖値、グラフ、接続情報、AIお手紙、購入情報は入れません。メールを開いたか、リンクを押したかを調べる追跡は使いません。

Resendでは、通常の送信記録とメール本文が最長30日保存されます。配信できない場合や迷惑メールと報告された宛先は、誤った再送を防ぐため、それより長く送信停止リストに残ることがあります。確認コードは10分を過ぎると使えません。少人数で実際に届くことと、このプライバシーの説明を確認するまで、アカウントとPlus販売を始めません。

GlucoScopeの中では、確認コードに関する一時記録を、コードが使えなくなってからおおむね1日で削除します。メールを送ろうとした回数の記録も、おおむね1日で削除します。どちらにもメールアドレスそのものは保存しません。通常の画面からは消えますが、Cloudflareの復旧用バックアップには、無料プランで最大7日、有料プランで最大30日残る場合があります。

確認メールの悪用を防ぐため、同じインターネット接続から短時間に何度も試していないかをCloudflareで確認します。この確認に使うIPアドレスを、GlucoScopeのデータベースやログへ保存しません。

確認したメールアドレスそのものは、Plusのデータベースへ保存しません。同じメールかを確かめる元に戻せない情報と、本人利用か保護者管理かを確認した日、Plusの期間、支払い確認、無料体験、安全確認に必要な最小の情報だけを保存する予定です。血糖値、グラフ、AIお手紙、接続先URL、合言葉はPlusの購入情報へ入れず、Stripeへも送りません。

カード番号などはStripeの支払い画面だけで扱い、GlucoScopeは受け取りません。Stripeには、支払いを同じPlusアカウントへ結びつけるランダムな番号を送ります。子どもがPlusを使う時は、18歳以上の保護者が自分のメールで購入・復旧・問い合わせを管理します。この確認で、子どもの名前、生年月日、血糖値は集めません。1つのメールで管理できるPlusアカウントは1つです。メールやカードのパスワードを子どもへ渡すよう案内しません。

二重決済やPlusが始まらない問題をこちらで直せない時、またはGlucoScope側の大きな障害でPlusの主な機能をほとんど使えず解決できない時は、状況を確認して全額返金する方針です。部分返金は行わず、返金したPlusは終了します。税、問い合わせ先、確認済みアカウントと購入・会計記録を残す期間はまだ決まっていません。分かりやすい案内と安全な復旧方法を公開し、テストを終えるまで購入できません。

AIお手紙

AI分析を使うと、画面にまとめた血糖情報をOpenAIへ送ります。現在の値と変化、選んだ期間のTIR、平均、ばらつきなどが含まれます。氏名、接続先URL、合言葉、元の血糖データ一覧は送りません。

自分のデータをつないだユーザー版では、最初のAI分析の前に、送る内容を画面で確認できます。AI分析を使わなくても、血糖表示や「いつものグルコのお話」は変わりません。

生成したお手紙は、この端末に最大30件まで保存します。少人数の先行体験中は、公開デモもユーザー版も、ほかの人と共有する一時保存には入れません。接続を削除すると、この端末のお手紙と確認記録も削除します。

将来、1日のAI利用上限を始める場合は、上限確認のため、AI分析が成功した日と回数だけを最大90日保存します。これは、設定から停止できる利用状況の記録とは別です。始める前に画面で説明し、確認を求めます。現在、この個人上限はまだ有効にしていません。

OpenAI APIへ送った内容は、通常はAIの学習には使われません。安全のための確認記録に、入力と出力が最大30日残る場合があります。詳しくはOpenAIのデータ管理の説明をご覧ください。

アクセス分析

個人データを扱わない公開ページでは、サイト全体の閲覧数や表示の速さだけを確認します。自分のデータを使っているときや、この端末に接続情報が残っているときは行いません。

血糖値、接続情報、GlucoScore、AIお手紙の本文はアクセス分析へ送りません。一人ひとりを見分けるためのGlucoScope独自の番号も使いません。

EN

English summary

At a glance

  • The glucose data in the public demo is not your data.
  • When you connect your own data, glucose values and connection details are not included in basic usage records.
  • You can stop, resume, or delete basic usage recording at any time in Settings.
  • GlucoScope is not a medical device and does not diagnose, make treatment decisions, or suggest insulin doses.

Public demo

The public demo uses only glucose values, update times, and arrows that Kazuma has agreed to publish. Anyone can view the public page, but data from other users is never mixed into it.

Only the data needed for the public demo is kept temporarily. If updates stop, the data disappears within 36 hours.

Connecting your own data

Your connection URL and passphrase are saved on this phone or computer only if you choose to save them. On a shared device, do not save them, or remove them when you finish.

Nightscout is read directly by this device. With Gluroo easy connection, the information needed for display passes briefly through the GlucoScope relay. GlucoScope does not save, log, send to AI, or share your connection details or glucose data. The screen tells you before this connection begins.

GlucoScope never asks you to enter your Apple, Google, Gluroo, Dexcom, Libre, or other service login password.

A safety check that keeps Gluroo connected

Gluroo asks for a safety check when you first connect. After that, the browser keeps a protected marker that works only on this device, so ordinary visits can reconnect without repeating the check. This design is live for the small early-access group. With Dexcom G7, the iPhone Home Screen icon reopened the display after the first safety check without requiring another connection.

The marker stops working after 180 days without use. Successful everyday use moves that date forward, but GlucoScope does not promise permanent access. Erasing browser data, a security change, or an operator revocation can require another safety check.

The relay keeps only a one-way form of the device marker, when it was created and last used, when it expires, whether it was revoked, a one-way marker used to confirm the same connection URL and passphrase, and the current day's request count. It does not keep the original URL, passphrase, glucose data, name, email address, IP address, or device or browser name. These relay records are not joined to optional usage recording or Plus identity.

When you delete the connection, GlucoScope removes the URL and passphrase from the device first, then tries to revoke the relay marker. Local deletion finishes without waiting for the network. If the device cannot reach the relay, the anonymous marker becomes unusable 180 days after its last use and is then eligible for automatic cleanup. GlucoScope does not promise an exact physical-deletion time. The relay does not have the original URL or passphrase, so the marker alone cannot read glucose data.

On iPhone, first open GlucoScope in Safari and choose Add to Home Screen. Then open the new icon and complete the first connection there. If you connect in Safari before creating the icon, the URL and passphrase may not move into the Home Screen app, so one more connection may be required.

Display name and basic usage

You do not need a name to view the public demo. When you connect your own data, you use a display name that does not need to be your real name.

To improve GlucoScope, we record your display name, days used, completed AI analyses, and the number of regular Gluco memories. We do not record glucose values, connection details, or AI letter text.

We also keep a random number for this device, whether recording is on or off, and when recording began and was last used. We do not store your IP address as part of the usage record. Cloudflare may handle information needed for communication and security under its own policies.

You can stop, resume, or delete basic usage recording at any time in Settings. Days used are kept for up to 90 days, and records for a device that has not been used for 90 days are deleted.

Public usage totals never show names or individual records. To reduce the chance of guessing what a small group did, overall totals appear only after at least 10 device profiles were active during the 30 completed days through yesterday.

After deletion, recovery backups may still keep the data for up to 7 days on the Free plan or up to 30 days on a Paid plan. It does not appear in the normal screen or usage totals.

This is not an account. Records cannot be combined across devices or recovered after browser storage is erased.

Plus 30-day pass (not yet for sale)

Plus is a proposed JPY 300 one-time purchase for 30 days starting when payment is confirmed. It never renews automatically. Core glucose viewing remains available without Plus. Plus is not medical care and does not provide diagnosis, treatment decisions, or priority medical advice.

Before sales begin, an email address will be verified so the same Plus access can be restored on another device. The email will be used only for Plus identity, recovery, and necessary purchase messages. It will remain separate from your display name and optional device usage record.

Verification email is planned through an email delivery service called Resend. The service receives the destination email address. The message contains a six-digit code that stops working after 10 minutes and short instructions for entering it. It will not contain a name, glucose value, graph, connection detail, AI letter, or purchase information. GlucoScope will not track whether you open the email or click a link.

Resend may keep ordinary sending records and the message body for up to 30 days. If delivery permanently fails or someone reports the message as spam, the destination may remain longer on a send-block list to prevent mistaken repeat delivery. The code still stops working after 10 minutes. Accounts and Plus sales will remain off until a small closed test confirms delivery and this privacy explanation is accepted.

Inside GlucoScope, temporary verification-code records are deleted about one day after the code stops working. Records counting email send attempts are also deleted after about one day. Neither record keeps the email address itself. They disappear from normal screens, but Cloudflare recovery backups may retain them for up to 7 days on the Free plan or up to 30 days on a Paid plan.

To prevent misuse of verification email, Cloudflare checks whether the same internet connection is trying too many times in a short period. GlucoScope does not save the IP address used for this check in its database or logs.

The Plus database will not keep the verified email address itself. It is planned to keep only a one-way value used to recognise the same email and the minimum information needed for the self-or-guardian confirmation date, Plus period, payment confirmation, free trial, and safety checks. Glucose values, graphs, AI letters, connection URLs, and passphrases will not enter the Plus purchase record or be sent to Stripe.

Card details stay on Stripe's hosted payment page and are not received by GlucoScope. A random identifier connects the payment to the same Plus account. When a child uses Plus, a guardian aged 18 or older manages the purchase, recovery, and support using the guardian's email. This confirmation does not collect the child's name, birth date, or glucose values. One email can manage one Plus account. GlucoScope will not tell a child to use an adult's email or card password.

If GlucoScope cannot correct a duplicate charge or a paid pass that did not start, or if a major GlucoScope-side outage made the main Plus features mostly unusable and could not be resolved, the policy is to confirm what happened and provide a full refund. Partial refunds are not offered, and the refunded Plus pass ends. Tax, the public support contact, and the retention periods for verified-account, purchase, and accounting records are not yet decided. Plus will remain unavailable until clear notices, safe recovery, and test-mode acceptance are complete.

AI letters

When you use AI analysis, the glucose summary shown on the screen is sent to OpenAI. It can include the current value and change, TIR, average, and variability for the selected range. Your name, connection URL, passphrase, and original list of glucose readings are not sent.

In the personal user experience, you can review what is sent before the first AI analysis. Glucose display and Gluco's everyday story work even if you do not use AI analysis.

Up to 30 generated letters are kept on this device. During the small early-access period, neither public-demo nor personal-user letters are placed in a shared temporary cache. Deleting the connection also removes these letters and the consent record from this device.

If a daily personal AI limit is introduced later, only the day and count of successful analyses will be kept for up to 90 days to enforce that limit. This is separate from the optional basic usage record. The screen will explain it and ask for confirmation before it begins. The personal limit is not enabled today.

OpenAI API data is not used to train models by default. Inputs and outputs may remain in abuse-monitoring logs for up to 30 days. See OpenAI's data controls for details.

Site analytics

On public pages that do not handle personal data, we review only overall visits and display speed. Analytics is not used while you are using your own data or while connection details remain on this device.

Glucose values, connection details, GlucoScore, and AI letter text are not sent to site analytics. GlucoScope also does not add its own number to identify individual visitors.