T1 Arc.

YOUR DATA, YOUR CHOICE

Privacy policy

Last updated: 10 September 2026

This policy covers the official T1 Arc Android app, Wear OS companion, T1 Arc watch faces and our support service. T1 Arc is developed by Gregor Scott in the United Kingdom. In this policy, “we” means Gregor and the T1 Arc maintainers. Contact support@t1arc.com about privacy or your information.

What stays on your devices

Glucose, insulin, meals, activity, sleep, other imported health records, notes and Tarv1s conversations are stored locally. The phone's health database uses SQLCipher encryption. Connection credentials and your OpenAI API key use Android secure storage. Android system backup is disabled.

Health Connect access is optional and controlled by Android permissions. T1 Arc reads the categories you allow, including activity, sleep, body measurements, vital signs, nutrition and cycle records. Broader history and background access need their own permissions. You can revoke access in Android settings. Strava records are brought in through Health Connect, rather than a direct Strava account connection.

Optional notification capture uses Android notification access and your configured source rules. Widgets, notifications, Android Auto and the Wear OS companion can display glucose information outside the main app. The companion receives a glucose snapshot from the paired phone for its display, tiles and complications. People who can see these surfaces may be able to read the information shown.

The optional always-on display uses an Accessibility service to observe system display events and position the glucose overlay. It does not read other apps' window content or send Accessibility events off your device. We explain this and ask for agreement before directing you to Android's enablement settings. You can disable it and keep using the rest of T1 Arc.

Connections you choose

When you connect LibreLinkUp, Dexcom Share, Medtrum, Glooko, Nightscout, xDrip or Hevy, the app communicates with the configured service to retrieve your records. Requests and credentials go to that service, not through a T1 Arc health-data server. The service receives the connection information and ordinary network metadata, such as your IP address. Provider policies continue to apply to their own copies of your records.

Tarv1s can answer some exact record questions on your phone. Optional AI requires your own OpenAI API key. It sends your question and the relevant, bounded evidence directly to OpenAI, together with a random safety identifier stored on your phone. OpenAI also receives ordinary network metadata. We do not receive these requests. You can leave AI disconnected and still use the app's other features. OpenAI's privacy policy and API data controls describe its handling and retention.

Online food search can send your search text or barcode and selected country/language to Open Food Facts. A US barcode lookup can also use USDA's food service. These requests do not upload your meal history. Bundled food reference searches and saved foods work locally. Photographing a nutrition label uses an on-device recognition model: the label photo and recognised text are not uploaded to a cloud recognition service. Temporary photo copies are removed after use where possible, with Android cache cleanup as a fallback.

Google's ML Kit SDK can send usage and performance diagnostics to Google, including app/device information, per-installation identifiers, timings, image dimensions and event/error information. This is separate from label images and recognised text. See Google's SDK disclosure and Google's privacy policy.

The manual “Check for updates” action contacts GitHub for public release information. It does not send health records, credentials or a device identifier. GitHub receives normal network metadata. Opening external guides, downloads or donation links connects you to those services under their own policies.

Reports and messages to support

In Settings → Help and support → Report a problem, you can describe an app problem and optionally include technical diagnostics: app version/build, Android version, device model and predefined event codes with minute-resolution UTC timestamps. You can inspect the exact preview before agreeing to send or export it. These diagnostic fields contain no readings, conversations, credentials, URLs, raw error messages or stack traces. Free text contains whatever you choose to write, including an email address if you want a reply.

Selected app lifecycle, foreground refresh and recoverable interface-error events are kept in the encrypted local database. This is not a complete native crash log. The log holds at most 60 events from the preceding 24 hours, pruning older entries when read or updated. Help and support lets you clear it; erasing the app's device data also clears it. Technical events are excluded from encrypted backups and are not uploaded automatically.

Save report creates an unencrypted text file at the location you select with Android's file picker. Share report passes the preview to an app you choose, whose privacy practices then apply. Temporary export files are removed after saving or cancelling; interrupted exports use the app's private temporary-file cleanup. Clearing the local log does not delete files or emails you have already exported. The delivery and retention rules below apply to general problem reports as well as Tarv1s response reports.

Opening “Report response” sends nothing. You write a message, may add the answer you are reporting, can edit it, and must agree before sending. The report contains only that text, the selected reason, app version, a random report reference and your consent flag. We do not automatically attach your question, conversation, records, contact address or API key.

Your report travels over HTTPS through Cloudflare to our private Gmail support inbox behind support@t1arc.com. Cloudflare processes IP and connection metadata; short-lived keys derived from the IP help limit abuse. The reporting service has no report database and its application logs do not contain report text or IP addresses. The support email does contain your report. If you email us directly, we also receive your email address and anything you attach.

We use these messages to investigate problems, respond where contact details are provided and improve the app. Reports are not published as GitHub issues. Please remove health details you do not want to share and never include passwords or API keys. Support is not an emergency or medical advice service.

Sending a report is optional. We rely on your consent to process the report, including any health information you choose to include. We use necessary connection metadata to protect the service from abuse. Cloudflare and Google provide the delivery and email services; their processing can take place outside the UK. Their Cloudflare and Google privacy information explains their international handling.

Keeping and deleting information

Your local records remain until you remove them using the app's device data controls or remove the app's data in Android. Disconnect sources as well if you do not want records imported again. Deleting a local copy does not delete records held by Health Connect or another provider.

You can create a passphrase-encrypted backup that you control. It excludes provider credentials, session tokens and your API key. Keep its passphrase safe. Exported conversations or other files are not necessarily encrypted: check the export you choose, and delete or protect copies you save or share. Removing the app does not erase files you exported to Downloads or another location.

We keep support reports while investigating them and remove them when they are no longer needed for that purpose. You can request deletion or withdraw consent by emailing support with the report reference. Closing a report after sending cannot recall the email. Requests do not remove copies held independently by your connected providers; contact those services for their own deletion options.

Depending on the law that applies to you, you may request access, correction, deletion, restriction or a copy of personal information we hold, or object to its use. Withdrawing consent does not change the lawfulness of earlier processing. Contact support@t1arc.com; you can also complain to the UK's Information Commissioner's Office or your local privacy regulator.

Security and changes

We do not sell your health data or use it for advertising. T1 Arc's OpenAI and report requests use HTTPS. Local xDrip connections may use HTTP on the same phone. No app or network can guarantee complete security: protect your device, backups and connected accounts.

We update this page when the app's handling changes and show the revision date above. The technical privacy model and open source code provide more detail. Independently modified builds may behave differently and need their own policy.