KnowGula
Legal
Last updated: April 4, 2026
KnowGula ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our food glucose intelligence application. We comply with the General Data Protection Regulation (GDPR), the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA), and all other applicable privacy laws and regulations.
Account Information: Email address, full name, and authentication credentials when you create an account.
Food Scan Data: Photos you upload for analysis, AI-generated nutritional assessments, glucose risk scores, food component breakdowns, and alternative food suggestions.
Usage Data: Interaction patterns, feature usage, device type, browser information, and IP address collected automatically.
Health-Related Data: Dietary preferences and any health information you voluntarily provide. This data is treated as Protected Health Information (PHI) under HIPAA where applicable.
We use your information exclusively to:
• Provide AI-powered food analysis and glucose risk assessments
• Store and display your scan history for personal reference
• Improve the accuracy and performance of our AI models
• Send essential service communications (never marketing without consent)
• Comply with legal obligations and enforce our terms
We never sell, rent, or trade your personal data to third parties.
Consent: You provide explicit consent when uploading food images and creating an account.
Contract: Processing is necessary to deliver the food analysis service you requested.
Legitimate Interest: We process usage analytics to improve service quality, balanced against your privacy rights.
Legal Obligation: We process data when required by law or regulation.
Where food scan data constitutes Protected Health Information (PHI), we implement the following safeguards:
• Administrative: Staff training, access controls, and incident response procedures
• Physical: Secure data center facilities with restricted access
• Technical: Encryption at rest (AES-256) and in transit (TLS 1.3), audit logging, and automatic session timeout
We maintain Business Associate Agreements (BAAs) with all third-party service providers who may access PHI.
Your data is stored on secure, encrypted servers. Food images are processed by AI and the analysis results are stored in your account. We implement industry-standard security measures including:
• End-to-end encryption for all data transmissions
• Regular security audits and penetration testing
• Role-based access controls with principle of least privilege
• Automated threat detection and incident response
• Data backup and disaster recovery procedures
Under GDPR, CCPA, and applicable laws, you have the right to:
• Access: Request a copy of all personal data we hold about you
• Rectification: Correct inaccurate or incomplete data
• Erasure: Request deletion of your data ("right to be forgotten")
• Portability: Receive your data in a structured, machine-readable format
• Restriction: Limit how we process your data
• Objection: Object to processing based on legitimate interests
• Withdraw Consent: Withdraw previously given consent at any time
• Non-Discrimination: Exercise your rights without discriminatory treatment (CCPA)
To exercise any of these rights, use the Delete Account feature in Settings or contact our data protection officer.
We retain your personal data only as long as necessary to provide our services. Scan history is retained while your account is active. Upon account deletion:
• Personal data is permanently erased within 30 days
• Uploaded food images are deleted immediately
• Anonymized, aggregated analytics may be retained for service improvement
• Legal retention obligations are respected where applicable
We use select third-party services to operate KnowGula:
• AI Processing: Food images are analyzed using AI models. Images are processed transiently and not stored by the AI provider beyond the analysis session.
• Authentication: Secure login services that do not share your credentials with us.
• Hosting: Cloud infrastructure with SOC 2 Type II and ISO 27001 certifications.
All third-party providers are contractually bound to protect your data and comply with applicable regulations.
We use only essential cookies required for authentication and session management. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. You can manage cookies through your browser settings.
KnowGula is not intended for children under 16 years of age. We do not knowingly collect personal information from children. If we discover that a child under 16 has provided us with personal data, we will delete it promptly.
If your data is transferred outside the European Economic Area (EEA), we ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users within 72 hours as required by GDPR, and report to the relevant supervisory authority. We will also comply with HIPAA breach notification requirements where applicable.
KnowGula provides educational nutrition insights only. It does not constitute medical advice, diagnosis, or treatment. Always consult qualified healthcare professionals for medical decisions. AI-generated glucose risk scores are estimates and should not replace blood glucose monitoring or professional dietary guidance.
We may update this Privacy Policy from time to time. Significant changes will be communicated via in-app notification or email. Continued use of KnowGula after changes constitutes acceptance of the updated policy.
For privacy inquiries, data requests, or concerns:
• Use the in-app Settings to manage your data
• Email our Data Protection Officer at privacy@knowgula.app
• You have the right to lodge a complaint with your local data protection supervisory authority