Privacy Policy

Last updated: 2026-07-08

Effective: 2026-07-08

InRange AI (“InRange”, “we”, “us”) is a personal coaching service for people living with Type 1 or Type 2 diabetes. This policy explains what data we collect, why we collect it, how we protect it, and the rights you have. It applies to the InRange iOS app, the InRange web experience at getinrange.ai, and the coaching conversations you have with us over Signal, Telegram, or in-app.

Wellness, not medical device. InRange is a wellness product. We do not diagnose disease, we do not recommend insulin doses, and we are not a substitute for medical care. Nothing in the service should be treated as a critical alert. Always follow the guidance of your healthcare team.

Who is the data controller? Inopia AB, Stockholm, Sweden, is the data controller. You can reach us at privacy@getinrange.ai.

1. What we collect

Account data. When you sign in with Apple, we receive an anonymous Apple ID token and, if you choose to share it, your name and an Apple-generated relay email. We use this to create your account and let you sign in again. We never see your Apple ID password.

Health data. With your explicit permission, InRange reads glucose readings, activity, sleep, heart rate, and body-mass data from Apple HealthKit. If you connect a continuous glucose monitor (Dexcom, Libre, Eversense), your device fetches those readings and forwards them to your InRange account. We may also write glucose data back to HealthKit so all your other health apps stay in sync.

Profile and coaching data. Onboarding answers (diabetes type, age, date of birth, coaching goals, preferred chat channel, player type), the messages you send your coach, the coach’s responses, and the goals and events you log with the coach.

Date of birth. Providing your date of birth is optional. If you share it, we use it to verify your age, to adapt the coaching to your age category, and for personal touches throughout the app. You can skip this during onboarding, and it is included in your data export if you request one.

Voice and image input. If you send a voice note or a photo (for example, of a meal), we transcribe or interpret it to feed the coaching conversation. Raw audio and images are processed and then deleted from our servers within 24 hours; only the transcription or extracted context is retained in your conversation history.

Subscription data. Purchases are handled by Apple’s App Store. We receive a receipt confirming your subscription status. We never see or store your payment card information.

Device and diagnostic data. Basic technical logs (app version, iOS version, device model, crash reports, request identifiers). This is used to keep the service working. We do not use third-party advertising SDKs or analytics that identify you personally.

2. What we do not collect or do

3. How we use your data (legal bases under GDPR)

4. Sharing with third parties

We share the minimum amount of data needed with the following processors:

We do not sell your data. We do not authorise these processors to use your data for their own purposes.

5. Where your data lives

Your account and health data are stored in the European Union (Fly.io region arn, Stockholm, Sweden). Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). We use short-lived database backups (retained for 30 days) for disaster recovery.

Because our AI providers operate globally, some conversation context is transferred to servers in the United States when we generate a coach response, transcribe a voice note, or render an avatar. Those transfers rely on Standard Contractual Clauses and, where available, the EU–U.S. Data Privacy Framework.

6. How long we keep it

When you delete your account, your profile, health data, and conversation history are removed from our production database immediately and from all backups within 30 days.

7. Your rights

If you are in the EU/EEA, UK, or Switzerland, you have the right to:

Users in the U.S. state of California (CCPA/CPRA) have parallel rights to know, delete, correct, and opt out of any sale or sharing of personal information. We do not sell or share personal information for cross-context behavioural advertising.

To exercise any of these rights, email privacy@getinrange.ai. We respond within 30 days.

8. Children

InRange is intended for users aged 16 and over in the EU/UK and 13 and over in the United States. We do not knowingly collect personal data from anyone below those age thresholds without verifiable parental consent. If you believe a child has provided us with data, please contact us and we will delete the account.

9. Security

Our security posture is aligned with NIS 2 baseline controls: encrypted storage, encrypted transport, multi-factor authentication for administrative access, immutable audit logging of sensitive operations, vulnerability disclosure, and an incident-response plan that includes notifying affected users within 72 hours of confirmed personal-data breaches, as required under GDPR Art. 33–34.

Report suspected security issues to security@getinrange.ai or through the process described on our Security page.

10. Automated decision-making

The coach uses machine learning to personalise its responses. It does not make legal or similarly significant automated decisions about you. All coach output is advisory and never overrides your own clinical decisions.

11. Changes to this policy

When we materially change this policy, we will update the “Last updated” date at the top and, if the change is significant, notify you through the app before it takes effect.

12. Contact

Inopia AB
Stockholm, Sweden
Email: privacy@getinrange.ai