Privacy
Last updated 26 August 2026
This describes what we actually hold and what the system actually does, in the same language as the rest of the site. Health data deserves a policy you can finish reading.
01Who is responsible
Wellovue is operated by Wellovue Limited, registered in Ireland, which is the data controller for the information described here. Reach us through the contact page.
02What we hold
Only what you give us or what the service needs to run.
- Your account: email address, an optional display name, and a hashed password. We never store the password itself.
- Health data you enter or import: glucose readings, meals and estimated nutrition, medication records, activity, sleep, symptoms, and lab results. In the UK and EU this is special category data, and it is treated as such.
- Files you upload: meal photos and device exports. The original import file is kept so an import can be replayed and checked.
- An access record: every read and write of your record, with who did it and when.
We do not ask for your name, address, phone number, date of birth, or any national health identifier, because the product does not need them.
03Why we are allowed to hold it
For health data we rely on your explicit consent, given when you create an account and add data. Consent can be withdrawn at any time, and withdrawing it means we delete the data, not that we keep it quietly.
For your account and security records we rely on performance of a contract, and on our legitimate interest in keeping the service safe.
04Where it lives
On infrastructure we run and control: a PostgreSQL database for records, and object storage for photos and imported files. Nothing is copied into a third-party analytics or marketing tool, because there is no such tool in this product.
Uploaded files are stored under opaque identifiers that reveal nothing about you, and your browser only reaches them through links that expire in minutes. Connections are encrypted in transit.
05Who can see it
You. Nobody else sees your health data unless you deliberately share it, and clinician sharing is off unless you turn it on for a specific person.
A small number of our engineers can reach production systems to keep them running. Any such access is recorded in the same access trail you can read yourself, and that trail cannot be edited or deleted by anyone, including us.
We do not sell data, and we do not share it for advertising. If we ever use it in aggregate to improve the models, it will be aggregate: nothing that identifies a person, and you will be asked first.
06How long we keep it
Your health record stays until you delete it or close your account. Sign-in sessions expire after 30 days. The access trail is kept for seven years, because an audit record you can shorten at will is not an audit record.
07Getting it back, or getting rid of it
Ask and we will export everything we hold in a portable format. Ask and we will erase it.
One honest caveat about erasure. Deleting your account removes your health data and unlinks you from the access trail, so no entry points at you any more. The trail still records that events occurred, because it is append-only by design and that is what makes it trustworthy. It cannot be used to identify you afterwards.
You also have the right to correct your data, to object to or restrict processing, and to complain to your data protection authority. In the UK that is the ICO.
08Others who process data for us
We keep this list short on purpose. At present it is our hosting and infrastructure provider, ImaniHosting, and Microsoft for the mail we send you. Each is bound by a data processing agreement. This list is updated when it changes.
09Children
Wellovue is for adults. It is not designed for anyone under 16, and we do not knowingly hold their data. If you believe a child has an account, tell us and we will remove it.
10Changes
If this policy changes in a way that affects how your health data is used, we will tell you before the change takes effect rather than quietly updating the date at the top.
How the system works technically is described on how this works. The single cookie we set is described under cookies.