Privacy
Privacy Policy
The personal data we collect, the purposes for which we process it, where it is held, and how to obtain or erase it.
- Effective
- 16 August 2026
- Last updated
- 14 September 2026
Summary
Glux administers a short questionnaire, calculates your Indian Diabetes Risk Score, and generates a personalized 90-day habit plan. In order to do so, we store your responses, your plan and your progress in your account.
- Your health data is stored and processed in India. Your responses, score, plan and progress are stored in Mumbai, the servers that operate the Glux application run in Mumbai, and the AI that generates your plan operates in the same region. See §7.
- We do not sell your data, and we do not use your health information for advertising.
- We use Google Firebase within the App to record crashes, application performance and screen usage, so that we can identify and correct faults. No health information is transmitted to it — not your responses, your score, your risk band, a measurement, or the name of a metric you viewed. See §16.
- If you connect Apple Health or Google Health Connect, what we read from it — steps, distance, active energy, exercise and sleep — is shown on your phone and never uploaded to us. Where you permit it, those readings continue while the App is closed, so that we can show you a milestone when you reach it; that notification is written on your phone and sent to nobody. Only what you type in by hand — your weight and your waist measurement — reaches our servers. See §2.8 and §14.
- Your plan is generated by AI, using Google Cloud Vertex AI.
- Your score, your risk band, your weight and your waist measurement never appear in a web address, a share page, a link preview, or a notification preview. A notification composed on your phone may name a movement figure you reached that day — steps, distance, active energy or exercise minutes — and that figure reaches no one else. See §2.4.
- You may request a copy of your data, or delete your account and all data within it, either in the App or by email. Deletion takes effect after 30 days, and signing in again within that period cancels it.
This summary is provided for convenience only and does not form part of the operative provisions. The sections set out below govern.
1. Scope and identity of the Data Fiduciary
1.1 This policy applies to:
- (a) the Glux mobile application for iOS and Android (the “App”);
- (b) the website at goglux.in, including share pages at
goglux.in/s/*(the “Site”); and - (c) correspondence you send to us.
1.2 Glux is operated by Marimuthu, a sole proprietor, of Vedha Apartments, 8th Street, Kasturba Nagar, Adyar, Chennai 600020, India (“Glux”, “we”, “us”).
1.3 Under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (the “DPDP Rules”), we are the Data Fiduciary in respect of the personal data described in this policy, and you are the Data Principal.
1.4 Glux is a wellness and education product. It is not a medical device. See §17.
2. Personal data we collect, and the purposes of collection
Each category of data is stated together with the specific purpose for which it is collected.
2.1 Account information
| Data | Purpose |
|---|---|
| Name | To address you within the App |
| Email address | To create and identify your account, to verify it, and to contact you in relation to it |
| Gender | To generate a customized plan |
| Password | To authenticate you |
| Email verification and sign-in codes | To confirm that the email address is yours, and to authorise a password reset. Held only as a hash, and deleted on use or expiry |
| Date of birth or age | To calculate your IDRS score, and to confirm that you are 18 or over (§13) |
| Session tokens | To keep you signed in. Stored in your device’s secure keychain and revocable at any time |
Authentication is administered by Glux itself. Your password is stored only as a cryptographic hash, in our own database in India. It is never stored in readable form, and we are unable to recover or disclose it to you: a forgotten password is reset, never retrieved.
Where you sign in using Apple or Google, we receive your name and email address directly from that service, subject to the permissions you grant. We do not at any point receive your Apple or Google password. If you use Sign in with Apple and elect to hide your email address, we receive a private relay address from Apple in place of your address, which we use solely to contact you.
2.2 Risk questionnaire (IDRS) responses
Your age band, waist measurement, level of physical activity, and family history of diabetes.
Purpose: to calculate your Indian Diabetes Risk Score, to identify the factors contributing to it, and to generate your 90-day plan.
The IDRS is a published and validated screening questionnaire developed by the Madras Diabetes Research Foundation. Glux applies the published scoring table and does not itself determine the score or the bands.
2.3 Your 90-day plan and your progress
The plan generated for you, together with the entries you record by hand against it: your weight, your waist measurement, and which habits you have completed.
These are the only health values we store.
Purpose: to display your plan, to record your progress, and to enable a before-and-after comparison when you re-take the questionnaire.
Figures measured by your phone are not included in this and are not sent to us. Steps, distance, active energy, exercise and sleep are read from Apple Health or Health Connect on your device, displayed, and discarded. See §2.8.
2.4 Notifications
Push notifications are delivered through OneSignal, which acts as our processor for this purpose and transmits messages onward through Apple Push Notification service and Firebase Cloud Messaging.
| Data | Held by | Purpose |
|---|---|---|
| A push subscription identifier for your installation, together with device and platform details | OneSignal | To address a notification to your device |
| Your Glux account identifier, linked to that subscription once you sign in | OneSignal | So that a notification can be addressed to your account rather than to a device, and so that it stops when you sign out |
| A device record — an installation identifier, device type, model, manufacturer, operating system, application version, locale and time zone | Glux, in India | To recognize your installations and to support them |
| Your reminder preferences | Glux, in India | To send reminders at the times you selected |
| Labels describing your position in the programme — whether a plan has been created, whether it is running, which week and day of it you have reached, how many days in the last seven you recorded activity, the status of your membership, and whether notifications are permitted | OneSignal | To send a message that is relevant to where you are in the programme, rather than the same message to everyone |
These labels describe your progress through the programme, never your health. Your questionnaire responses, your score, your risk band, your plan’s contents and every measurement are excluded from them, and no label is derived from any of those.
A push subscription is created when the App first launches, before you sign in and whether or not you have enabled reminders, because a subscription must exist before permission to use it can be requested. No notification is sent to you unless you grant permission at the operating system level, which you may decline or withdraw at any time in your device settings.
We do not send OneSignal your name, your email address, your questionnaire responses, your score, your risk band, your plan or any measurement you record. The account identifier described above is an opaque identifier and carries no health information.
Purpose: to deliver the habit reminders and progress notifications you have requested. You may disable these in the App or in your device settings at any time.
A Glux notification will not display your score, your risk band, your weight or your waist measurement in its preview, and none of those is transmitted to OneSignal at any time.
Activity milestones are the one exception, and they never leave your device. If you connect Apple Health or Health Connect, the App may show you a notification naming a movement figure you have reached that day — for example, that you have walked 3 km, or taken 5,000 steps. Movement figures means steps, distance, active energy and exercise minutes, and nothing else. These notifications are composed on your phone from data that is never uploaded (§2.8): they are not sent through OneSignal, Apple Push Notification service or Firebase Cloud Messaging, and no third party — ourselves included — receives the figure or knows the notification was shown. You may switch them off by disconnecting Apple Health or Health Connect in the App, or by disabling notifications in your device settings.
2.5 Support and feedback
Any correspondence you send to us, and our replies.
Purpose: to respond to you and to address the matters you report.
2.6 Device and usage information, collected automatically
We use three Google Firebase tools within the App. Each is stated together with the data it receives.
| Tool | Data received | Purpose |
|---|---|---|
| Firebase Crashlytics | Crash and error reports: the error and its stack trace, device model, operating system version, application version, and a short record of the screens visited beforehand | To identify and correct crashes |
| Firebase Performance Monitoring | The time taken by the App to start, the time taken by screens to render, and the duration of calls to our own server, including which of our web addresses was called (for example /v1/plan) and the response code | To identify and correct performance issues |
| Firebase Analytics | A small, fixed set of application events — that you signed up or signed in and by which method, that you confirmed you are 18 or over, and that you opened the paywall and whether access resulted — together with the screen you are viewing, recorded as the screen’s template name | To identify where users encounter difficulty |
In addition, Firebase records device type, operating system version, application version, language, and an application instance identifier.
Screen names are recorded as templates and never as your data. Screens whose address contains information about you — the screen for a particular measurement, or a particular question in the risk questionnaire — are reported to Firebase as the template (/metric/[metric], /onboarding/[step]) and never as the resolved address. Firebase is not informed which measurement or which question was viewed. See §16.
Approximate location. Firebase derives an approximate location — country, and in some cases region — from the network address from which your device connects, and reports it in aggregate. We do not collect GPS location, and we do not store a location against your account. See §3.
Purpose: to maintain the operation of the App, to diagnose crashes, and to identify where the product is failing its users.
2.7 Purchases
Whether you hold an active plan or subscription, your purchase and renewal history, and the application user identifier by which our billing provider knows your account. The email address and name on your account are shared with that provider as described in §15.3.
Purpose: to enable the features you have paid for, to restore your purchase on a new device, and to match a subscription to you when you contact us about billing.
We do not at any point receive your card, UPI or bank details. Payment is processed entirely by Apple or Google. See §15.
2.8 Health platform data — read on your device, never sent to us
Where you enable it, the App reads from Apple Health (iOS) or Google Health Connect (Android). Access is read-only: Glux writes nothing back to either platform.
| Read | iOS | Android |
|---|---|---|
| Steps | ✓ | ✓ |
| Distance | ✓ | ✓ |
| Active energy | ✓ | ✓ |
| Exercise sessions | ✓ | ✓ |
| Sleep | ✓ | ✓ |
This data is read on your device, displayed to you, and discarded. It is never transmitted to our servers and never disclosed to any third party. Section 14 governs this in full.
Where you have permitted it, these readings also take place while the App is closed, so that the App can show you an activity milestone at the time you reach it rather than the next time you happen to open it. On iOS this uses Apple Health’s background delivery; on Android it requires the separate “read data in the background” permission, which Health Connect asks you for and which you may refuse without affecting anything else. A background reading is treated exactly as one made while you are using the App: it is read, used to compose a notification on your phone, and discarded. Nothing is uploaded, and no third party is contacted.
The only thing retained from a background reading is a note that a given milestone has already been shown to you today — for example, that the 5,000-step message has been sent — so that it is not repeated. That note records the milestone, never the figure you actually reached, is stored only on your device, and is discarded when the day ends or when you disconnect the platform.
Purpose: to show your activity and sleep alongside your plan without requiring you to enter it by hand, and to acknowledge the movement milestones you reach.
2.9 The goglux.in website
The questionnaire is administered within the App. The Site does not collect your responses, your score or your email address; there is no form on goglux.in and no third-party form behind any of its links. Collection through the Site is limited to the analytics described in §16, which you may disable.
3. Data we do not collect
For the avoidance of doubt, and because these are categories commonly assumed to be collected by health applications:
- Precise location. We do not collect GPS location and we do not request location permission. We do not store a location against your account. Our diagnostics provider derives an approximate country-level location from your network address for aggregate reporting only. See §2.6.
- Contacts, photographs, camera, microphone or files.
- Advertising identifiers. The App contains no advertising SDK and no advertising pixel. Firebase Analytics is capable of collecting the Android Advertising ID and the iOS vendor identifier, and we have disabled that collection, together with ad personalization, ad storage and ad-network registration. We conduct no advertising of any kind.
- Health information within any analytics or diagnostics tool. Your questionnaire responses, your score, your risk band, your plan and your recorded measurements are not transmitted to Firebase or to any analytics provider. This restriction is enforced in the App’s source code and not merely as a matter of policy. See §16.
- Health platform data, on our servers or anywhere off your device. What Glux reads from Apple Health or Health Connect is displayed on your phone and discarded. It is not written to storage on the device, not uploaded, and not shared. This restriction is structural: device readings sit behind a module that has no route to the network, and the local database has no column that could hold one. See §2.8 and §14.
4. Purposes of processing
4.1 We process the data described in §2 in order to:
- (a) calculate your IDRS score, band and per-factor breakdown;
- (b) generate and deliver your personalized 90-day plan;
- (c) record and display your progress, and produce your before-and-after comparison;
- (d) send you service communications, including verification codes, receipts and account notices;
- (e) send habit reminders and progress notifications, where you have enabled them;
- (f) maintain the security and operation of the App, and investigate abuse;
- (g) improve our content, the quality of our plans and our copy, using aggregated and de-identified information that does not identify you; and
- (h) comply with applicable law and respond to lawful requests.
4.2 We do not use your health information to develop or tune any risk model. The IDRS score is produced by a fixed and published scoring table. We do not train, adjust or personalize the scoring itself.
4.3 We do not use your information for advertising purposes, and we do not sell your personal data to any person.
5. AI processing
5.1 Content that is AI-generated: your 90-day plan. It is model-generated wellness content. It is not written or reviewed by a clinician and does not constitute medical advice.
5.2 Content that is not AI-generated: your IDRS score and your risk band. These are derived from the published IDRS scoring table, computed on our server, and returned exactly as the instrument defines them.
5.3 Place of processing: we use Google Cloud Vertex AI in the asia-south1 (Mumbai) region. In order to generate your plan we transmit your questionnaire responses and profile details, and nothing further.
5.4 Training: Google’s Service Specific Terms for Google Cloud include a Training Restriction, under which Google will not use customer data to train or fine-tune any AI/ML model without the customer’s prior permission or instruction. We have not granted that permission. Your responses are not used to train Google’s models, and we do not use them to train any model of our own.
5.5 Constraints on the model: the model is instructed not to interpret symptoms, not to recommend or dose medication, and not to state whether you have diabetes, and instead to refer you to a qualified healthcare professional. AI output may nonetheless be incorrect and should be treated as general wellness information.
5.6 No decision producing a legal effect or a similarly significant effect is taken about you by automated means.
6. Disclosure of personal data
We do not sell your personal data. We disclose it only in the circumstances set out below.
6.1 Service providers
| Provider | Function | Location |
|---|---|---|
| Google Cloud (Firebase / Firestore) | Storage of your account, responses, score, plan and progress | India (asia-south1) |
| Google Cloud Vertex AI | Generation of your 90-day plan (§5) | India (asia-south1) |
| Google Cloud Run | Operation of the Glux application server, through which every request passes | India (asia-south1) |
| Google Cloud SQL (PostgreSQL) | Your account record, your password hash and your refresh tokens | India (asia-south1) |
| Redis, self-hosted on Google Cloud | Short-lived verification codes, held only as hashes | India (asia-south1) |
| Amazon Web Services (SES) | Delivery of verification codes and account email | India (ap-south-1) |
| Google Sign-In and Sign in with Apple | Optional social sign-in, where you choose to use it | Global |
| OneSignal | Push notifications: composing and scheduling them, and holding your push subscription and, once you sign in, your Glux account identifier (§2.4) | United States |
| Firebase Cloud Messaging / Apple Push Notification service | Onward transport of push notifications to your device | Global |
| Firebase Crashlytics | Crash and error diagnostics from the App (§2.6) | United States / global |
| Firebase Performance Monitoring | Application performance and network timings (§2.6) | United States / global |
| Firebase Analytics | A fixed set of application events and screen template names (§2.6, §16) | United States / global |
| RevenueCat | Subscription and purchase state, and the email address and name on your account (§15) | United States |
| YouTube (Google) | Playback of the short videos in the App’s awareness articles, loaded only when you press play (§16) | Global |
| Google Analytics | Website analytics only (§16) | Global |
Each provider is bound by contract to process personal data only on our instructions and to protect it.
None of these providers receives your questionnaire responses, your score, your risk band, your plan or your progress logs, other than Google Cloud, which stores and processes them in India on our instructions. That includes the three Firebase diagnostics and analytics tools listed above: they are informed that the App crashed, that a request was slow, or that a screen was opened, and never of its contents.
6.2 Legal grounds
Where required by law, regulation, legal process or a lawful governmental request, or where necessary to protect the rights, safety or property of Glux, of our users, or of the public.
6.3 Business transfer
If Glux is involved in a merger, acquisition or sale of assets, your data may be transferred as part of that transaction. We will notify you before any such transfer takes place.
6.4 With your consent
For any other purpose to which you expressly agree.
7. Location of storage and processing
7.1 Your health information is stored in India. Your questionnaire responses, your IDRS score and band, your 90-day plan and your progress logs are stored on Google Cloud in the asia-south1 (Mumbai) region, and the AI processing that generates your plan is performed in the same region.
7.2 The application server that handles your requests also operates in India. The Glux server runs on Google Cloud Run in the asia-south1 (Mumbai) region, being the same region in which your health data is stored. All activity within the App — completing the questionnaire, viewing your plan and recording progress — is handled by that server, and your health data is not routed outside India in order to serve those requests.
7.3 Your account and your credentials are also held in India. Your name, email address, password hash and refresh tokens are stored in our own database on Google Cloud SQL in the asia-south1 (Mumbai) region, and your verification codes and account email are sent through Amazon SES in the ap-south-1 (Mumbai) region. Authentication is operated by Glux itself and is not delegated to any third-party identity provider.
7.4 Certain billing, notification and diagnostic information is processed outside India. Your subscription status is held by RevenueCat in the United States. Your push subscription and account identifier are held by OneSignal in the United States (§2.4). Crash reports, application performance timings and the application events listed in §2.6 are processed by Google’s Firebase services on infrastructure outside India. Where you choose to sign in using Google or Apple, that sign-in is performed by the provider you selected, on its own infrastructure. None of these providers receives your questionnaire responses, your score, your risk band, your plan or your recorded measurements, all of which remain in India.
7.5 Where personal data is transferred outside India, we effect that transfer in accordance with the DPDP Act and under contractual protections with the relevant provider. We do not transfer personal data to any country in respect of which the Central Government has restricted such transfers.
8. Retention
| Data | Retention period |
|---|---|
| Account, questionnaire responses, plan, progress logs | For so long as you hold an account, including while it is locked for non-payment |
| Inactive accounts | Deleted 24 months after your last sign-in. We will notify you by email before any deletion |
| An account you have asked us to delete | Flagged and signed out immediately, then permanently erased 30 days later. Signing in within that period cancels the request (§10) |
| Apple Health / Health Connect data | Not retained. Read on your device when a screen needs it, displayed, and discarded (§2.8, §14) |
| Device records and reminder preferences | While you have an account. Deleted with it (§10) |
| Push subscription held by OneSignal | Until you uninstall the App or disable notifications, after which the subscription ceases to be addressable. Deleting your account unlinks your account identifier from it (§10) |
| Crash and diagnostic logs (Firebase Crashlytics) | 90 days |
| Application performance timings (Firebase Performance Monitoring) | 90 days |
| Application events and screen names (Firebase Analytics) | 14 months, after which they are deleted automatically by Google. Aggregate reports may persist beyond that period and cannot be linked to you |
| Purchase records | For so long as tax and accounting law requires |
| Aggregated, de-identified analytics | Indefinitely; this data cannot be linked back to you |
Where you withdraw consent, or where the purpose for which data was collected is no longer being served, we erase that data, save where we are required by law to retain it.
9. Your rights
9.1 Under the DPDP Act, and under any other law applicable to you, you have the right to:
- (a) access — obtain a summary of the personal data we hold about you and of our processing of it;
- (b) correct, complete, update or erase your personal data (in respect of the erasure of your entire account, see §10);
- (c) withdraw consent at any time. Withdrawal is as straightforward as the giving of consent, and does not affect the lawfulness of processing carried out before withdrawal;
- (d) obtain portability — a copy of your data in a portable, machine-readable format;
- (e) nominate a person to exercise your rights on your behalf in the event of your death or incapacity. Please email us to register a nominee; and
- (f) complain — raise a grievance with our Grievance Officer (§19), to which we will respond within 90 days. If you are dissatisfied with our response, you may complain to the Data Protection Board of India.
9.2 To exercise any of these rights, please email contact@goglux.in. We may be required to verify your identity first. We make no charge for such requests.
10. Deletion of your account
10.1 You may delete your account in the App by opening Account → Delete my account and confirming. Step-by-step instructions, including what is deleted and what we are required to retain, are set out on our account deletion page. You may alternatively email contact@goglux.in from the address registered on your account and request deletion; we will confirm the request before acting on it.
10.2 Deletion is not immediate and remains reversible for 30 days. Upon receipt of your request:
- (a) we flag your account for deletion immediately and sign you out on every device;
- (b) the account remains flagged, and unusable, for 30 days; and
- (c) at the end of that period we permanently erase your personal data, comprising your account, your questionnaire responses, your scores and bands, your 90-day plan, your progress logs, your reminders, your device records and your credentials.
Signing you out under (a) also unlinks your account identifier from your push subscription with OneSignal, so that no notification can afterwards be addressed to your account.
10.3 To cancel a deletion request, sign in again before the 30-day period expires. The flag is then cleared, no data is erased, and your account continues unaffected. This period exists so that an accidental request, or a request made by another person with access to your unlocked device, does not result in the irreversible loss of your records. If you would prefer not to wait, please email us and we will erase your data sooner.
10.4 Deletion is available at all times. It is free of charge, it is not conditional on holding an active subscription, and it remains available if your account is locked for non-payment. See clause 12.6 of the Terms.
10.5 We retain only what we are required by law to retain — for example purchase records that must be kept under tax and accounting law — together with aggregated de-identified records that cannot be linked to you.
10.6 If you require a copy of your data, you should request it before requesting deletion. Please email contact@goglux.in (§9). Once the 30-day period has expired the data no longer exists and we are unable to produce a copy of it.
11. Security
11.1 We protect personal data by means of encryption in transit (TLS), encryption at rest, access controls restricting who may access production data, passwords stored only as hashes, and session tokens stored in your device’s secure keychain. Sessions may be revoked at any time.
11.2 No system is entirely secure and we cannot guarantee absolute security. If you believe your account has been accessed by another person, please email us immediately.
12. Personal data breach
If a personal data breach affects your data, we will notify the Data Protection Board of India and will notify you within 72 hours of becoming aware of it. Our notice will describe, in plain language, the nature of the breach, the data affected, the measures we are taking, the steps you may take to protect yourself, and how to contact us.
13. Age requirement
13.1 Glux is available only to adults aged 18 years or over. We ask your age at sign-up and do not permit accounts to be held by persons under the age of 18.
13.2 We do not knowingly collect personal data from any person under the age of 18. Under the DPDP Rules, the processing of a child’s personal data requires verifiable parental consent, and we do not process children’s personal data at all. Where we become aware that an account is held by a person under 18, we will delete that account and its data. If you believe that a minor has created an account, please email contact@goglux.in.
14. Apple Health and Google Health Connect
14.1 Synchronization is opt-in and is off until you enable it. Glux is fully functional using manual logging, and you are under no obligation to grant health permissions. Your choice is recorded per device, not on your account: enabling synchronization on one phone does not enable it on another.
14.2 Access is read-only. Glux reads the categories listed in §2.8 and writes nothing back to either platform.
14.3 Health platform data never leaves your device. It is read, displayed to you, and discarded. We do not store it, we do not transmit it to our servers, and no third party receives it. It is consequently not part of any copy of your data we can produce under §9, and there is nothing of it to erase under §10 — because we never held it.
14.4 Reading while the App is closed. Where you permit it, Glux reads the same categories in the background so that it can show you an activity milestone at the time you reach it. On iOS this uses Apple Health’s background delivery; on Android it requires Health Connect’s separate “read data in the background” permission, which you may refuse — synchronization and every screen in the App continue to work without it. Paragraph 14.3 applies to a background reading in full: it is used to compose a notification on your phone and is then discarded, and nothing about it is transmitted to us or to anyone else. You may stop these readings by turning synchronization off in the App, or by withdrawing the permission as described in 14.6.
14.5 We will not use Apple Health or Health Connect data for advertising or marketing purposes, sell it, share it with data brokers, or use it for any purpose you have not enabled.
14.6 You may withdraw access at any time. Turning synchronization off in the App stops Glux reading from the platform. It does not by itself revoke the permission you granted at the operating system level; to revoke that, use iOS Settings or the Health Connect app, and the App provides a route to both.
15. Payments and subscriptions
15.1 Glux costs ₹499 every 3 months, auto-renewing at the same price until cancelled, following a 2-week free trial for new subscribers. Your IDRS score is provided free of charge.
15.2 Purchases are processed by the Apple App Store or Google Play. We do not see or store your card, UPI or bank details. Apple’s and Google’s own privacy policies govern the payment itself.
15.3 We use RevenueCat to administer subscription state. RevenueCat receives your application user identifier, the email address and name on your account, your purchase and renewal history, and basic device information. The identifier, purchase history and device information are what is necessary to inform the App of your entitlements; your email address and name are provided so that a subscription can be matched to you when you contact us about billing, a refund or a store dispute. They are sent when you subscribe or are granted an entitlement, and not otherwise. It does not receive your questionnaire responses, your score or your plan.
15.4 You may manage or cancel your subscription in your App Store or Google Play account settings.
16. Cookies and analytics
16.1 Within the App
We use Google Firebase for three purposes: crash reporting (Crashlytics), performance measurement (Performance Monitoring), and product analytics (Analytics). Section 2.7 states precisely what each receives. We use no advertising SDK, and we have disabled Firebase’s advertising-identifier collection (§3).
No health information is transmitted to Firebase. Specifically:
- (a) your questionnaire responses, your IDRS score, your risk band, your per-factor breakdown, your 90-day plan and every measurement you record are never transmitted to Firebase in any form — neither as an event, nor as a value attached to an event, nor as a user property, nor as a label on a performance measurement;
- (b) screens are reported by template and never by resolved address. The screen for a specific measurement is reported as
/metric/[metric], and a specific question in the risk questionnaire is reported as/onboarding/[step]. Firebase is not informed which screen was viewed; - (c) the events we transmit constitute a short, fixed set, defined in the App’s source code as a closed set that cannot be added to inadvertently: that you signed up or signed in and by which method, that you confirmed you are 18 or over, and that you opened the paywall and whether access was granted; and
- (d) Firebase is informed which of our own web addresses the App called — for example
/v1/idrs— and how long the call took. That records the fact of a request, and never its contents or its response.
If it becomes necessary to transmit anything outside that set, we will amend this policy before the change is released.
Videos in awareness articles. Some of the general-education articles in the App include a video from our YouTube channel. Nothing is requested from YouTube when you open an article; the video player is loaded only when you press play. At that point YouTube, a Google service, receives the information any embedded video receives — such as your IP address, device and browser details, and which video was played — under Google’s own privacy policy. No health information is transmitted to YouTube: your questionnaire responses, score, risk band, plan and measurements are never part of that request.
16.2 Disabling in-App collection
The App does not currently provide an in-app control for crash reporting or analytics, and one is being added. Until it is released, this collection may be stopped by ceasing to use the App; deleting your account (§10) ends it entirely. To raise this matter in the interim, please email contact@goglux.in (§9).
This collection includes no health information, so disabling it does not affect the handling of your responses, score or plan, which are governed by §2.2, §2.3 and §10 and are not present in Firebase in any event.
16.3 On goglux.in
We use Google Analytics to understand how the Site is found and used, including which pages are visited, how long visitors remain, and which links referred them. Google Analytics sets cookies and shares this website usage data with Google, which may use it in accordance with its own privacy policy.
Website analytics operates on an opt-out basis and may be disabled at any time. We state this in a notice on your first visit. If you disable it, Google Analytics stops immediately, any cookies it has already set are cleared, and no part of the Site ceases to function. Your choice is recorded on your device, and you may change it at any time using Cookie preferences in the Site footer.
No health information is transmitted to Google Analytics. Your score, your band, your questionnaire responses and your plan exist only within the App and are never present on the Site, so there is no health information available to any website analytics tool. Google Analytics is a distinct tool from the Firebase Analytics used within the App; both are subject to the same commitment.
16.4 Essential storage
The App and the Site store limited data on your device in order to keep you signed in and to record your preferences. This does not constitute tracking and is necessary for the product to function.
16.5 Share pages
Where you share a Glux result, the share page carries no health data — no score, no band and no value — in the web address, on the page, in the link preview, or in the page’s metadata. The artwork on a share page is illustrative. Your own values are rendered only within the App.
17. No medical advice
Glux is a wellness application and not a medical device. It does not diagnose, treat, cure or prevent any disease or medical condition. All information provided is for educational purposes only. You should always consult a qualified healthcare professional in relation to your health and before making any change to your health routine.
The IDRS is a screening questionnaire. It is neither a blood test nor a diagnosis. A score falling within a higher-risk band is a reason to consult a doctor and obtain a confirmatory blood test; it does not mean that you have diabetes or prediabetes. Your 90-day plan is general wellness guidance generated by an AI model and is not a treatment plan.
18. Amendments to this policy
18.1 We may amend this policy from time to time. Where an amendment materially affects our handling of your data, we will notify you in the App or by email before it takes effect, and will update the “Last updated” date stated above. Continued use of Glux after an amendment takes effect constitutes acceptance of the amended policy.
18.2 Previous versions are available on request.
19. Contact
Grievance Officer: Marimuthu
Email: contact@goglux.in
Address: Vedha Apartments, 8th Street, Kasturba Nagar, Adyar, Chennai 600020, India
We respond to grievances within 90 days. If you are dissatisfied with our response, you may complain to the Data Protection Board of India.