Nevada Consumer Health Data Privacy Notice
Contents
- What this document answers
- 1 Who we are and what this notice covers
- 2 What we mean by consumer health data
- 3 We do not sell it, and we do not geofence
- 4 Your rights, and how long we have
- 5 How to exercise these rights
- 6 What deletion actually reaches
- 7 If we say no
- 8 How your consumer health data is processed
- 9 Reviewing your data, and asking us to change it
- 10 Material changes
- 11 Whether a third party may collect your health data across other websites and services
- 12 Language
- 13 Contact us
What this document answers
This notice is for you if you are in Nevada. It sits alongside our Consumer Health Data Privacy Policy, which is the document Washington’s law requires and which carries the shared detail: what we collect, where it comes from, who else handles it, and what a deletion reaches.
- What rights do I have, and how long do you have to answer? Section 4.
- How do I ask? Section 5.
- What does deleting reach? Section 6.
- What if you say no? Section 7.
- How is my data actually processed? Section 8.
- Can anyone track me across other sites? Section 11.
1. Who we are and what this notice covers
Paweł Milewski Software Development (the Operator, “we”, “us”, “our”) provides glumea (the App) and glumea.com (the Website). This notice is about the App.
It applies to you if you are a resident of Nevada, or if your consumer health data was collected while you were in Nevada. Nevada’s law is NRS 603A.400 et seq., enacted by SB 370 of 2023.
Why there are two documents. Washington’s My Health My Data Act requires a consumer health data policy that is a separate, standalone document and that carries only what that Act asks for. Nevada asks for four disclosures Washington does not. Keeping both in one file made the Washington document carry material it should not, so Nevada’s part lives here. Nothing has been taken away from you by the split.
Where the shared detail is. The categories of consumer health data we collect, the purposes, the sources it comes from, the companies that receive it, and the table of what a deletion reaches at each destination are set out in our Consumer Health Data Privacy Policy, sections 2 to 5 and 9. They are the same wherever you live, so they are stated once rather than twice, two copies would drift apart, and you would have no way to tell which was current. Everything in this notice is in addition to them.
Three further documents apply alongside this one: the Privacy Policy, the Terms of Service and the Medical Disclaimer. Our postal address and email are in section 13.
2. What we mean by consumer health data
Nevada defines consumer health data as personally identifiable information that is linked or reasonably linkable to you and that a regulated entity uses to identify your past, present or future health status.
Most of what glumea records falls inside that. A blood glucose reading, an insulin dose and a medication name are clear examples.
Because glumea is a diabetes app, the fact that you have an account is itself health-revealing. We therefore treat your account identifier and the email address on your account as consumer health data, even though they are not health measurements, and we treat the pseudonymous device identifier that pre-sign-in analytics events are tied to the same way. Section 2 of the Consumer Health Data Privacy Policy says the same and explains what falls outside.
3. We do not sell it, and we do not geofence
We do not sell consumer health data and we have never sold it. Nevada requires a separate signed authorization from you before any sale; we hold none and have not asked you for one.
We do not operate a geofence around any health-care facility, and we could not: glumea asks for no location permission on either platform, so the App cannot read your device’s location at all.
4. Your rights, and how long we have
Under NRS 603A.400 et seq. you have the right to:
- Confirm whether we are collecting, sharing or selling your consumer health data, and receive the list of third parties with whom it has been shared or to whom it has been sold. We sell none of it. The current recipient list is published in section 5 of the Consumer Health Data Privacy Policy.
- Stop our collection and our sharing of your consumer health data.
- Delete the consumer health data we have collected about you.
Deadlines. Nevada law requires a response within 45 days after authenticating a request. A deletion request has a shorter deadline and a wider scope: within 30 days after authentication, the regulated entity must delete covered consumer health data from its records and network and notify relevant recipients. Those recipients then have 30 days to delete their copies. The statute does not permit a charge.
Nevada is not simply a lighter version of Washington. Its deletion deadline is shorter, and the duty to notify relevant recipients runs on the same 30-day period. Washington additionally requires an active contact address for each relevant third party and an access right to the data itself.
5. How to exercise these rights
- In the App. Delete account (Settings → Account details) hard-deletes your account and everything synced with it from our servers, and wipes the local database from your device. The delete your data link, inside the Sync sheet, deletes the server copy of your entries, your medication catalogs and your medication schedules while keeping your account and the copy on your device. It needs a live sign-in and Cloud sync switched off first.
- Current limitation. [email protected] is the general privacy contact, but no email one-time-code, off-app deletion, manual authentication or custom access workflow is currently implemented. The in-app controls do not provide the full request process required by Nevada law.
Deleting your glumea account describes the supported in-app route in more detail.
6. What deletion actually reaches
The per-destination table is section 9 of the Consumer Health Data Privacy Policy, and it applies to you unchanged. Two Nevada-specific points on top of it:
- Backups. Nevada allows deletion from a backup or archived system to be delayed for up to two years after we authenticate your request. In practice our backups are kept on a single retention setting for everyone, and it is shorter than that: 7 days, and in no case longer than six months.
- The companies that received your data. Nevada requires the deletion request to be passed to relevant recipients within 30 days. Deleting the account in the App clears our production account tables, but it does not reach a PostHog profile or RevenueCat subscriber record, and the current flow sends no provider-deletion request. Sentry reports have no supported identifier for locating an individual user’s reports. The implemented flow does not perform Nevada’s required provider-notification step.
7. If we say no
Nevada law requires a written reason and appeal instructions when a request is refused, a written appeal decision within 45 days, and information about contacting the Nevada Attorney General if an appeal is denied.
No separate appeal workflow is currently implemented at [email protected], so the current process does not provide Nevada’s required appeal route. Nothing here limits a complaint to the Nevada Office of the Attorney General’s Bureau of Consumer Protection or any other right under Nevada law.
Nevada’s law is enforced by the Attorney General.
8. How your consumer health data is processed
What you log is written into the App’s local database on your device, which is encrypted with a key held in the platform keystore. The values the App derives, estimated active insulin and the hypo-risk wording beside it, average glucose and its spread, Time in Range, estimated A1C (GMI), the suggested time for your next reading, and the status label on your latest reading, are calculated on the device.
Your account, your diabetes and treatment profile and your therapy settings are held on our servers from the moment you enter them, whether or not you use cloud sync; deleting your account is what removes them. What Cloud sync controls is whether your diary is copied to our servers as well, your entries, your medication catalogs and your medication schedules. That switch is a glumea+ feature, and your answer to it is held on your account rather than on the phone. With it on, those are copied to our backend and database at Google Cloud in europe-west1, and held there so they can be returned to your devices; that server copy is what a new phone restores from. Your check-reminder times, Quiet hours, sick-day mode, lock-screen setting and health-connection settings stay on the device and are not sent to us at all.
The companies listed in the Consumer Health Data Privacy Policy operate the services described there. A provider SDK inside the App can also collect device and network information that we neither configure nor receive; RevenueCat’s SDK does so. Current builds store the Usage analytics and Error reporting preferences as enabled by default, so the present implementation is not an affirmative opt-in design. Events and reports are filtered before they are sent.
We do not process consumer health data for advertising, ad targeting, profiling, credit or insurance decisions, or research, and we do not use it to make automated decisions about you.
9. Reviewing your data, and asking us to change it
What you logged is visible in the App on any device that holds it. The App can create a CSV glucose report or an encrypted .glumea archive at no charge; a formatted PDF report is a glumea+ feature. Statutory rights are not conditioned on a subscription. No additional off-app copy workflow is currently implemented through [email protected].
Entries you logged can be deleted in the App; readings imported from Apple Health or Health Connect cannot be deleted one at a time.
Entries, profile fields and therapy settings exposed for editing can be corrected in the App. No manual server-copy or correction workflow is currently implemented at [email protected]. Section 7 describes the current appeal limitation without limiting any statutory right.
10. Material changes
The current version and effective date are published at the top. Nevada law can require advance notice, an updated notice or consent before a material change. Publishing an updated notice does not replace consent where consent is required.
11. Whether a third party may collect your health data across other websites and services
Nevada asks us to say whether a third party may collect consumer health data about you over time and across different websites or online services while you are using glumea.
No. glumea contains no advertising, attribution or measurement SDK and does not use an advertising identifier. PostHog, Sentry and RevenueCat receive the data described in the Consumer Health Data Privacy Policy; none is integrated as an advertising or cross-service tracking network. Their SDKs can collect device and network information for their own service operation. The Website sets no cookies, runs no analytics and makes no third-party-origin requests.
The reverse direction, for completeness: we do not collect consumer health data about you from other websites or applications either. The one place data reaches us from another application is Apple Health or Health Connect, and only if you connect it and grant the operating-system permission. That is a one-way import you start, of records your device’s health platform already holds, and nothing goes back the other way.
12. Language
This notice is published in English. The English version is the legally binding one. Where we publish a translation, it is offered so that you can read the notice in your own language, and it is published when it is ready, so it can lag behind the English text after an update; where a translation and the English text differ, the English text is the one that governs.
The exception is the law itself. Where the country you live in gives the language you were addressed in a status of its own, that rule applies instead of this one, and nothing here takes away a right you have under it.
13. Contact us
- Email: [email protected]
- Post: Paweł Milewski Software Development, ul. Franciszka Bohomolca 3 lok. 7, 31-416 Kraków, Poland
Related documents: Consumer Health Data Privacy Policy, Privacy Policy, Terms of Service, and Medical Disclaimer.