Privacy Policy — Glucose Widget

Introduction

Glucose Widget (“the App”) is a desktop widget application developed by Melbourne Online that displays continuous glucose monitoring (CGM) data from the Dexcom Share API. This Privacy Policy explains how we collect, use, and protect your information.

Information We Collect

Account Credentials

  • Dexcom Account Email: Used to authenticate with the Dexcom Share service
  • Dexcom Account Password: Used to authenticate with the Dexcom Share service

Technical Data

  • Window position and size: Saved locally to restore your preferred layout
  • Display preferences: Units, thresholds, opacity, alert settings

Health Data

  • Glucose readings: Retrieved from the Dexcom Share API and displayed on screen
  • This data is only displayed temporarily and is not stored by the App

Licence Validation

  • Licence key: Your licence key is transmitted to melbourneonline.com.au for activation and periodic validation
  • Device ID: A SHA-256 hash of your machine name and Windows SID is sent during activation to bind the licence to your device. No personally identifiable hardware serial numbers are transmitted

How We Use Your Information

  • Authentication: Your Dexcom credentials are used solely to connect to the Dexcom Share API
  • Display: Glucose data is retrieved and displayed on your desktop widget
  • Settings: Your preferences are saved locally to personalise your experience
  • Licensing: Your licence key and device ID are used to verify your purchase

Data Storage

Local Storage Only

All personal data is stored locally on your computer:

  • Settings: %AppData%GlucoseWidgetsettings.json
  • Log files (if debug logging is enabled): %AppData%GlucoseWidgetLogs

Password Encryption

Your Dexcom password is encrypted using Windows Data Protection API (DPAPI), which provides user-level encryption tied to your Windows account. The password cannot be read by other users on the same computer.

No Cloud Storage of Health Data

  • We do not store your glucose readings on any server
  • We do not transmit your health data to any third party
  • Glucose readings exist only in your computer’s memory while the widget is running

Third-Party Services

The App connects to the following external services:

  • Dexcom Share API (share1.dexcom.com or shareous1.dexcom.com) — to retrieve your glucose readings. Governed by Dexcom’s Privacy Policy
  • Melbourne Online licensing server (melbourneonline.com.au) — to activate and validate your licence key

Data Sharing

We do not share, sell, or distribute your personal information to any third parties.

Data Security

  • Dexcom passwords are encrypted using Windows DPAPI
  • All network communications use HTTPS (TLS) encryption
  • No health data is transmitted to our servers
  • Licence validation uses HTTPS only

Your Rights

You can:

  • Delete all your data: Uninstall the App and delete the %AppData%GlucoseWidget folder
  • View your stored settings: Open settings.json in any text editor (the password field is encrypted)
  • Disable logging: Turn off debug logging in the Settings dialog
  • Request licence data deletion: Email us and we will remove your licence record from our server

Children’s Privacy

This App is not intended for use by children under 13 years of age without parental supervision. Glucose monitoring for children should be managed by a parent or guardian.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected by updating the “Last Updated” date at the top of this page.

Contact Us

If you have questions about this Privacy Policy:

Disclaimer

Glucose Widget is not affiliated with, endorsed by, or sponsored by Dexcom, Inc. or any CGM manufacturer. The App is provided for informational purposes only and should not be used to make medical treatment decisions. Always consult your healthcare provider.

By using Glucose Widget, you agree to this Privacy Policy.