Privacy Policy
Last updated: 30 June 2026
This Privacy Policy explains how Bolus Ltd ("Bolus", "we", "us" and "our") collects, uses, shares, and protects personal data when you use the Bolus app and related services in the United Kingdom.
Bolus is a healthy eating programme for people managing diabetes. It is not a medical device and does not provide medical advice. It does not diagnose any condition, recommend or calculate insulin or medication doses, or replace your own healthcare team. Where glucose data is shown, it is used to support food and planning choices, not to direct clinical treatment. Every user accepts a medical disclaimer to this effect when they start, and the AI assistant is designed to stay on the food and lifestyle side and to steer clinical questions back to the user's care team rather than answer them.
By using Bolus, you confirm that you have read this Privacy Policy and our medical disclaimer, and that you understand the limits of the service.
1. Who we are
Bolus Ltd is the data controller for the personal data described in this Privacy Policy.
If you have any questions about this Policy or about how we handle your data, you can contact us at:
Email: [email protected]
Address: Bolus Ltd, United Kingdom
If you are not satisfied with our response, you can complain to the UK data protection regulator, the Information Commissioner's Office (ICO). See section 11 below.
2. What data we collect
We collect the following categories of personal data.
2.1 Identity and account data
This includes:
- email address
- Apple sign-in identifier
- name
- mobile number
We use this to create and operate your account.
2.2 Health profile data
This includes:
- diabetes type
- sex at birth
- weight
- height
- whether you take weight-loss medication
- primary goal
- which glucose source or device you use
This is special category health data.
2.3 Glucose data
This includes:
- blood glucose readings
- records needed to ingest, process and analyse those readings
This is special category health data.
2.4 Meal plans and food preferences
This includes:
- weekly meal plans
- meals in those plans
- shopping lists
- meals you like
- cooking history
- food preferences gathered at onboarding, such as:
- diet pattern
- allergens
- never-eat items
- portion size
- effort
- household size
2.5 Push and notification data
This includes:
- device push tokens
- a record of notifications sent
2.6 Consent and disclaimer records
This includes a record that you accepted:
- our medical disclaimer
- our terms
- the version and timestamp of those documents
2.7 Ask safety logs
Our AI assistant, "Ask", generates limited safety logs to help us monitor abuse, protect users, and keep the assistant operating safely.
These may include:
- safety metadata that does not contain message text
- flagged message text where the safety system identifies a concern
- your conversation thread for in-app restoration
2.8 Support data
If you contact us through in-app support, we may collect the content of your message. This may include health-related details if you choose to include them.
2.9 Subscription and purchase data
If you subscribe to Bolus, your subscription is purchased through Apple In-App Purchase only.
We do not collect or store full payment card details. Apple processes the transaction and provides us with limited subscription and receipt information needed to:
- confirm whether you have an active subscription
- manage entitlement and access to the service
- handle cancellations, renewals, refunds, and chargebacks where relevant
- keep records required for accounting, tax, fraud prevention, or legal compliance
3. How we use your data
We use your personal data for the following purposes:
- to create and manage your account
- to provide the Bolus service
- to build weekly meal plans and shopping lists
- to personalise food guidance and meal recommendations
- to display glucose insights where you choose to connect glucose data
- to operate the Ask AI assistant
- to send push notifications
- to manage subscriptions purchased through Apple In-App Purchase
- to verify entitlement to paid features
- to respond to support requests
- to keep the service secure
- to detect and investigate errors, abuse, and misuse
- to maintain required records of consent, disclaimer acceptance, and subscription status
- to comply with legal obligations
We do not sell your personal data. We do not share it with third parties except for the service providers and processors listed in this Policy, or where required by law.
4. Our lawful bases for processing
We process your personal data under the UK GDPR on the following bases.
4.1 Performance of a contract
We rely on performance of a contract to process:
- identity and account data
- meal plans and food preferences
- support data where needed to provide the service
- device and notification data where needed to deliver the service
- subscription and entitlement data needed to provide paid access
4.2 Consent and explicit consent
We rely on consent or explicit consent, as appropriate, to process:
- health profile data
- glucose data
- any special category health data you choose to provide or connect
- acceptance of the medical disclaimer and terms
You can withdraw consent at any time by deleting your account or, where relevant, by disconnecting the feature or source. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
4.3 Legitimate interests
We rely on legitimate interests to process:
- push and notification data
- Ask safety logs
- support and abuse prevention data
- security and service integrity data
- limited operational analytics and error monitoring data
- limited subscription administration and fraud-prevention data
Where we rely on legitimate interests, we consider the impact on your privacy and only use the data where our interests are not overridden by your rights and freedoms.
4.4 Legal obligations
We may retain certain records where needed to comply with legal obligations, to demonstrate compliance, or to defend legal claims.
5. Special category data
Some of the data we process is special category data under the UK GDPR, including health data and glucose data.
We only process special category data where you have given explicit consent and where the processing is necessary to provide the service you have chosen to use.
6. Data collected on the device
The Bolus iOS app collects and transmits to our backend the same categories described above, including profile and preference data, glucose readings, questions to Ask, support messages, subscription status, and push registration details.
6.1 Apple Health
If you allow it, the app reads blood glucose only from Apple Health.
We do not read:
- workouts
- activity
- steps
- weight
- any other health or fitness data
We do not write anything back to Apple Health.
6.2 Device permissions
The app requests only the following permissions:
- Apple Health access for blood glucose
- push notifications
The app does not use:
- camera
- location
- contacts
- photos
- microphone
6.3 Stored on the device
The sign-in token is held in the device keychain and is not included in device backups. If you connect a FreeStyle Libre account, the Libre credentials you provide are also stored only in the device keychain and never leave your device. A copy of recent glucose readings is held locally so the app works smoothly; this is cleared when the user logs out.
6.4 Ask
Ask is an informational assistant only. It provides guidance, suggestions, and support for food and planning questions, but it does not perform any automated actions without your explicit approval.
Ask does not make decisions for you. It does not diagnose conditions, provide medical advice, recommend treatment, or calculate or replace insulin or medication decisions. Ask is not a medical device and must not be used as a substitute for treatment, diagnosis, or advice from medical professionals. If you ask Ask a medical, diagnostic, or treatment question, it is designed to refuse to answer that question and to direct you back to a healthcare professional.
Ask is monitored by humans for safety and performance reasons. We review limited interactions and safety logs to improve the service, prevent misuse, and maintain the quality of the feature.
6.5 Subscriptions and payments
Subscriptions are purchased through Apple In-App Purchase only. We do not store full payment card details. We may receive limited subscription and receipt information from Apple for entitlement, support, accounting, and legal purposes.
7. Third parties we share data with
We use a small number of processors. We do not use any email or SMS provider or advertising network. Subscriptions are processed through Apple In-App Purchase, and we receive only limited subscription and receipt information needed to manage entitlement. We do not receive full card details.
- Database hosting. Our application database is hosted by Neon, running on AWS in Europe (Europe West). It holds the server-side data described in section 2.
- AI assistant. The Ask feature uses Anthropic's Claude models via Amazon Bedrock, running within the EU. We send the model a limited, purpose-built view of the user's plan, preferences, and food context. We do not send the user's email, real name, or account identifier. Health profile details and glucose reflections are only included when the relevant features are switched on, and the user's first name is added to the reply on our own servers rather than being sent to the model. Under the AWS Service Terms, Amazon is contractually obligated not to use data sent through Bedrock to train or improve its foundation models.
- Error monitoring. We use Sentry, on its EU instance, to detect crashes and errors. It receives only a masked user reference, with personal data, message bodies, and health values stripped out.
- Product analytics. We use TelemetryDeck for basic usage analytics in both the app and on this website. In the app it receives only a fixed list of anonymous interaction events with a masked user reference; it cannot receive health data or other personal data. On the website it records anonymous, aggregated usage only: page views, how far visitors scroll, clicks on key calls to action, and the marketing-campaign tags (UTM parameters) in the link a visitor arrived from. The website analytics set no cookies and store nothing on your device, and cannot identify you. TelemetryDeck is operated by TelemetryDeck GmbH (Germany) and hosts data in the EU (Germany) for all accounts; it offers no other region, so there is no residency setting to configure.
- Cloudflare. Cloudflare sits in front of the backend as the DNS, CDN, and security layer, and it proxies API traffic. It terminates the HTTPS connection from the device at its nearest edge and forwards to our server, so it briefly handles traffic in transit. Cloudflare Inc is a US-headquartered company with a global network and acts as a data processor under its standard data processing addendum, which incorporates the EU Standard Contractual Clauses for any transfer outside the EU.
- Push notifications. Apple's push service delivers notifications using a device token.
- Sign in with Apple. Apple handles authentication, and we ask Apple to revoke the sign-in grant when an account is deleted.
- FreeStyle Libre (Abbott). For users who connect Libre, the app talks to Abbott's LibreLinkUp service directly from the device to fetch glucose readings. The Libre credentials you provide are stored only on your device and are not sent to our servers.
- Apple In-App Purchase. Apple processes all subscription payments and provides us with subscription and receipt information needed to manage access and related records.
We do not pass your data to anyone outside this list except where required by law.
8. Where everything is hosted
Our infrastructure runs in the EU. We use the following providers:
- AWS — server infrastructure and AI assistant
- Neon — database
- Cloudflare — DNS, CDN, and security
- Sentry — error monitoring (EU instance)
- TelemetryDeck — analytics (EU)
Cloudflare is a global provider and may process data outside the EU in accordance with its data processing terms and the EU Standard Contractual Clauses.
9. Retention
We keep personal data only for as long as necessary for the purposes described in this Policy.
9.1 Account data, health data, meal data and support data
These are kept for the life of your account and deleted when you delete your account.
9.2 Notification delivery records
Notification delivery records are kept for 90 days.
9.3 Consent and disclaimer records
We keep a live record of your consent and disclaimer acceptance for the life of your account.
When you delete your account, we retain a minimal archive record for 6 years consisting of:
- terms version
- acceptance time
- terms link
- privacy policy link
This archive is kept only for accountability purposes and to defend potential legal claims. It is not used by the app and is accessible only to authorised legal and administrative personnel.
9.4 Ask safety logs
We retain Ask safety data as follows:
- non-identifiable safety metadata may be retained after account deletion because it cannot reasonably be linked back to you
- flagged message text is normally deleted after about 30 days
- flagged message text is deleted immediately for you when you delete your account
- your conversation thread is deleted when you delete your account
9.5 Subscriptions and purchase records
We keep limited subscription and receipt information received from Apple for as long as necessary to manage entitlement, support, accounting, tax, fraud prevention, and legal obligations.
9.6 Deletion
Account deletion is initiated in-app under Settings > Delete account and is immediate and irreversible. There is no grace period.
If you use Sign in with Apple, deleting your account also revokes the Apple sign-in grant.
10. Security
We use reasonable technical and organisational measures designed to protect your data, including:
- access controls
- encryption in transit and at rest where applicable
- least-privilege access
- pseudonymisation where possible
- logging and monitoring for abuse and system integrity
- secure key handling and environment-based secret management
No system is completely secure, but we take steps designed to reduce risk and protect personal data against unauthorised access, loss, misuse, or disclosure.
11. Your rights
Depending on the circumstances, you may have the following rights under UK data protection law:
- the right to be informed
- the right of access
- the right to rectification
- the right to erasure
- the right to restrict processing
- the right to data portability
- the right to object to processing based on legitimate interests
- the right to withdraw consent at any time where we rely on consent
If you wish to exercise any of these rights, contact us using the details in section 1.
We may need to verify your identity before responding. In some cases, we may not be able to delete or restrict certain data where we must keep it for legal reasons, for the minimal consent archive, or to establish, exercise, or defend legal claims.
12. Children
Bolus is intended for adults and is not directed to children under 18. We do not knowingly collect personal data from children.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the service, our processing activities, or legal requirements. If we make material changes, we will take reasonable steps to notify you.
The version posted in the app and on our website is the current version.
14. Contact us
Bolus Ltd
Email: [email protected]
United Kingdom
15. Complaints
If you are unhappy with how we handle your personal data, please contact us first so we can try to resolve the issue.
You also have the right to lodge a complaint with the UK regulator:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113