Private health intelligence
GlucoPilot
Fragmented personal health data becomes one coherent analytical system.
A self-hosted, single-user platform that unifies Type 1 diabetes data, wearables, labs, symptoms, and treatment history—then makes the evidence explorable.

Public, sanitized project material.
The problem
Why it exists
CGM, pump, wearable, lab, cycle, symptom, and treatment information live on different timelines in different tools.
The valuable questions are cross-domain: what changed, what correlates, what argues against a hypothesis, and what should be discussed with a clinician?
- GlucoPilot is for personal exploration and education—not diagnosis, dosing, or device control.
- Portfolio screenshots use synthetic demo data only.
Architecture
Operating model
Capabilities
What it does
Security
Trust model
- Single-user and single-tenant by design; each person runs their own instance.
- Local-model mode keeps health records and questions on the owner’s machine.
- Role-specific exports use explicit allowlists and the clinician login is read-only.
Tradeoffs
Key decisions
Evidence, not an oracle
The Companion separates observation, calculation, correlation, and hypothesis—and keeps source evidence inspectable.
One owner per deployment
A deliberately single-tenant architecture keeps custody and threat boundaries easy to understand.
Current state
Current state
- Multi-source health timeline
- Cross-domain analytics and pattern detection
- Source-linked Companion evidence
- Synthetic demo and share-safe export modes
- More data connectors
- Deeper longitudinal comparisons
- Stronger provenance and contradiction review
Lessons
What the work clarified
- Normalization creates more value than another isolated dashboard.
- Sensitive analytics need provenance, counter-evidence, and visible uncertainty.
- Privacy improves when the architecture makes the owner the default custodian.