Your data
Privacy, Cookies & Health Data
How MyGLP1App collects, uses, protects, and lets you control your information.
Effective September 23, 2026. MyGLP1App LLC, a Rhode Island limited liability company, operates MyGLP1App and is responsible for the information practices described in this policy. MyGLP1App is a personal tracking and appointment-preparation service for adults using GLP-1 medications. This policy applies to the MyGLP1App website and service.
About HIPAA: MyGLP1App is not a healthcare provider, health plan, or business associate of one, so the federal HIPAA privacy rules generally do not apply to what you record here, even though much of it is health information. We still treat it as sensitive health data, and it is protected by this policy, by state consumer health data laws, and by the FTC Health Breach Notification Rule. Residents of Washington, Nevada, and Connecticut can also read our Consumer Health Data Privacy Policy, which summarizes how we handle consumer health data under those states' laws.
Information we collect
- Account and profile information: your email address, first name, optional last name and state, confirmation that you are at least 18, and account settings, including an optional dose-reminder channel, time, and IANA timezone if you opt in. For native push reminders, we also store a random app-installation identifier and an encrypted device notification token. We do not store a device name, contact list, advertising identifier, or precise location for this feature. If you opt into two-step verification, Supabase Auth also stores the authenticator factor needed to verify one-time codes. Passwords and authenticator secrets are handled by Supabase Auth and are not available to MyGLP1App in plain text.
- Google sign-in information: if you choose Google sign-in, Google and Supabase process the authentication request. Google may provide basic identity information covered by the
openid,email, andprofilescopes, such as your Google account identifier, email address, name, and profile image. MyGLP1App uses this information only to authenticate you, create or connect your account, and prefill basic profile information. We do not request access to Gmail, Drive, Calendar, Contacts, or other Google product data. - Consumer health data you provide: medication and dose history, injection details, weight and height, side effects and notes, nutrition or hydration entries if supported and used, questions for your clinician, and the reports and trends generated from those entries.
- Progress photos (optional): if you use this Premium feature, we store the processed display image and thumbnail, the date and pose you choose, and the minimum file metadata needed to operate the private timeline. Your device resizes and re-encodes the image before upload to remove location, camera, and original-file metadata. We do not keep the original, analyze your body, include these photos in reports, or send them to AI providers or subscription services.
- AI meal estimate (optional): if you choose the AI-estimate option when logging a meal on the Nutrition page, the meal description and/or photo you submit for that purpose is sent to Anthropic to generate a macro estimate. This is separate from and in addition to the plate-method logging described above, which does not use this feature. See “Service providers and disclosures” below for how that content is handled.
- Optional Withings data: if you connect a Withings account, MyGLP1App requests only the
user.metricspermission and imports your body-weight measurements and their timestamps. We store encrypted OAuth credentials so you can sync again without reconnecting each time. We do not request activity, sleep, device, or Withings profile information. - Optional Health Connect data (Android): if you connect Health Connect in the Android app, MyGLP1App requests read access to body weight only and imports weight readings with their timestamps. It does not request permission to write to Health Connect, and it cannot change or delete anything stored there. No other Health Connect data — steps, sleep, heart rate, nutrition, or any other category — is requested or read. Connecting imports the 30 days of readings before you connect, after showing you what was found, and then new readings as they appear. Health data obtained through Health Connect is never used for advertising, marketing, profiling, or analytics, and is never sold or shared with data brokers.
- Feedback: the name, email address, message, and response preference you choose to submit through the feedback form.
- Subscription and purchase information: if you use Premium, Apple or Google processes your purchase, and RevenueCat processes the store receipt or purchase token, product and transaction details, trial and renewal status, entitlement status, and limited device or app technical information needed to validate and manage the subscription. MyGLP1App identifies you to RevenueCat with the same random account UUID used by our authentication system, not your email address, and does not send RevenueCat your tracked health entries.
- First-party commercial progress: MyGLP1App records fixed milestones such as account creation, first weight or medication entry, encountering a Premium feature, viewing the paywall, starting a trial, converting to paid, and cancelling renewal. Post-account rows contain only your account UUID, the fixed event name, optional iOS/Android platform and app version, and time. Health values, medication or dose details, notes, email, URLs, IP addresses, user-agent strings, advertising identifiers, and store transaction IDs are not stored in these rows. A native first-launch count contains only platform, app version, event name, and time and is not joined to an account or device identifier.
- Service and security information: the page path and time of a page view, anonymous aggregate website-usage dimensions, account-security events, and short-lived rate-limit counters. Vercel Web Analytics may process the page path, referrer, approximate location, browser, operating system, device type, and event time. MyGLP1App removes query strings and fragments before analytics events are sent. Hosting and security providers may also process ordinary request information such as IP address, browser type, and timestamps in infrastructure logs.
- Country availability check: for signed-out visitors, our hosting provider derives an approximate two-letter country code from the public IP address. MyGLP1App reads that code only to limit the current launch to the United States. We do not add the country code or IP address to your MyGLP1App account or application database. Missing or invalid country information does not block access.
We collect account, profile, health, and feedback information directly from you; basic Google identity information comes from Google only when you choose Google sign-in; and limited service and security information is generated when you use the service.
How we use information
We use the information described above to:
- create, authenticate, secure, and support your account;
- optionally cover the native app behind device authentication when you enable Privacy lock;
- save and display the entries you ask us to track across your signed-in devices;
- generate your trends and pre-visit report;
- send transactional account messages such as confirmation and password-reset emails;
- send an upcoming-dose email at the local time you choose, only when you opt in;
- generate an optional AI-assisted meal macro estimate when you choose to submit a meal description or photo for that purpose;
- respond to feedback and support requests;
- validate, restore, support, and administer optional Premium subscriptions; and
- operate, protect, troubleshoot, and understand basic use and commercial progression of the service.
The optional native-app Privacy lock stores only its enabled state and timeout on that device. Face ID, Touch ID, fingerprint, passcode, and PIN checks are performed by the operating system; MyGLP1App does not receive or store biometric templates.
We do not use consumer health data or Google user data for advertising, data-broker activity, eligibility decisions, or training advertising profiles. We do not sell personal information or consumer health data.
We do not create de-identified or aggregated datasets from your health entries to sell, license, publish, or share with researchers, advertisers, insurers, employers, or other third parties. The internal counts we keep to run the service, such as the number of accounts, page views, and storage used, do not include your health values. If we ever want to use health data this way, we will update this policy first and ask for your consent where the law requires it.
Service providers and disclosures
We disclose information only as needed to operate the service, at your direction, or when legally required. Our current service-provider categories are:
- Supabase: authentication, database hosting, and private object storage, including account and consumer health data and optional progress photos.
- Vercel: website hosting, delivery, operational security, and cookie-free aggregate Web Analytics. Analytics events are not connected to your MyGLP1App account or tracked health entries.
- Resend: delivery and scheduling of transactional account and opt-in dose-reminder emails; it receives your email address, delivery time, and message content needed to send those messages. Reminder emails do not include your medication name or dose amount.
- Firebase Cloud Messaging and Apple Push Notification service: delivery of native push notifications only when you opt in. These providers receive the device token and generic notification needed for delivery. The lock-screen message does not include a medication name, dose, date, side effect, or other tracked health detail.
- Google: authentication only when you choose Google sign-in. MyGLP1App does not send your tracked health entries to Google.
- Withings: optional body-weight import only when you explicitly connect your Withings account. Withings receives the authorization and measurement requests needed to provide that feature; MyGLP1App does not send your medication, dose, side effect, or clinician-question data to Withings.
- Anthropic: only when you choose the optional AI meal-estimate option, Anthropic processes the meal description and/or photo you submit to return a macro estimate. Anthropic does not use this content to train its models. It deletes it within 30 days, unless it is flagged for a possible violation of Anthropic’s usage policy (then it may be kept for up to 2 years) or the law requires Anthropic to keep it longer. We send only the description and/or photo you submit for that estimate — no other account, medication, or health data accompanies it.
- Apple App Store and Google Play: the store for your device presents and processes optional Premium purchases, renewals, cancellations, and refunds under its own account, payment, and privacy terms. MyGLP1App receives subscription status needed to provide Premium access; tracked health entries are not sent to either store for subscription processing.
- RevenueCat: validates Apple and Google purchase records and provides entitlement, trial, renewal, cancellation, and billing status for Premium. RevenueCat receives the random MyGLP1App account UUID, purchase history and store receipt or token, and limited app/device technical information needed for subscription functionality and aggregate subscription analytics. We do not provide RevenueCat your email address, advertising identifier, or tracked health entries.
We may disclose information if reasonably necessary to comply with law, protect the security or rights of users or the service, or complete a business transaction in which the recipient assumes the obligations described in this policy. We do not disclose consumer health data to affiliates or third parties for their independent marketing purposes.
Your choices and rights
From Settings, signed-in users can correct profile information, export a copy of account and tracking data, delete all tracked entries, or permanently delete the account and its associated active data. You can independently choose email, push, both, or no dose reminder at any time; turning a channel off cancels its pending reminder when it has not already been sent, and signing out unregisters that app installation. You can also disconnect MyGLP1App from your Google Account; doing so does not itself delete your MyGLP1App account. You may also disconnect Withings at any time. Disconnecting deletes the stored Withings authorization but keeps weight readings already imported into your history unless you delete them. You may disconnect Health Connect at any time, in MyGLP1App or by revoking access in Health Connect itself; when you disconnect in MyGLP1App you choose whether to keep or delete the readings it imported. Either way, disconnecting never alters the data held in Health Connect, which remains yours to manage there.
In the installed iOS or Android app, Subscription settings lets you restore a prior purchase and open the purchasing store's management page. Deleting your MyGLP1App account removes its owner-linked commercial-event rows but does not cancel a subscription held by Apple or Google. Cancel through the purchasing store before deleting the account if you do not want the subscription to renew.
You may also ask us to confirm, access, correct, export, or delete information; to withdraw consent for future collection or disclosure where consent is the basis; to receive a list of the third parties we have shared your consumer health data with, with a way to contact each one; or to appeal a decision on a privacy request. Email support@myglp1app.com. We may need to verify your identity and will respond within the period required by applicable law. We will not discriminate against you for exercising a privacy right.
Someone you authorize, such as a family member or attorney, can make a request for you. We will ask for proof that you gave them permission, such as a signed authorization or power of attorney, and may still need to verify your identity with you directly.
To appeal, reply to our response or email us with “Appeal” in the subject line, and we will tell you the outcome and our reasons. If we deny your appeal, you can contact your state Attorney General. Washington residents can file a complaint with the Washington Attorney General.
Cookies and similar technology
Strictly necessary cookies: Supabase authentication uses first-party cookies to keep you signed in, refresh and verify your session, and protect private routes. They are not optional because they provide the login service you request; signing out ends the active session.
Optional two-step verification: you can connect or remove an authenticator in Settings. Once connected, new sessions must provide a current code; a password reset alone does not bypass that protection.
First-party page counts: MyGLP1App records the path and time of a page view without storing a cookie identifier, user or session identifier, IP address, or user-agent field in the page-view record.
First-party commercial milestones: the fixed, minimum-necessary events described above are stored without cookies or advertising identifiers. The native install count is anonymous; post-account events use the account UUID so they can be deleted with the account. Health values are never copied into these events.
Vercel Web Analytics: Vercel also receives anonymous page-view information for aggregate service analytics. It does not use analytics cookies; Vercel derives a daily visitor hash that is not connected to your account and resets after 24 hours. MyGLP1App sends no custom events to Vercel Analytics and removes URL query strings and fragments before transmission.
We do not use advertising cookies or cross-site tracking cookies. Because we do not track your activity across unrelated services, browser “Do Not Track” signals do not change the service's current behavior. Other parties do not collect personal information through MyGLP1App for cross-site behavioral advertising. We honor Global Privacy Control (GPC) signals as a request to opt out of the sale or sharing of personal information. We already do neither for anyone, so a GPC signal needs no further action.
Retention and deletion
Account information, settings, and tracked entries are kept while your account exists unless you delete them sooner. Deleting tracked data or your account removes it from active application systems. Encrypted, access-controlled backups are kept for up to about six months and then permanently deleted, so deleted data can remain in a backup for up to that long. Provider logs age out under the providers' own retention schedules. Copies can be kept longer only when the law requires it. Before a backup is restored for use, later deletion requests must be reapplied so deleted data is not returned to service. Feedback and operational records are kept only as long as reasonably needed for support, security, and service administration. Rate-limit counters in the application database expire after 24 hours.
First-party commercial milestones are retained for up to 24 months. Deleting all tracked data removes the health-derived first-weight and first-medication milestones; deleting the account removes every owner-linked milestone. Anonymous native-install counts cannot be linked back to an account or device and expire after 24 months. Apple, Google, and RevenueCat may retain purchase and transaction records under their own policies and legal obligations even after a MyGLP1App account is deleted.
Security
We use access controls, encrypted connections, account authentication, row-level database security, and other administrative and technical safeguards intended to protect your information. No internet service can guarantee absolute security. Protect your password and contact us if you believe your account has been compromised.
If we learn of a security breach that affects your personal information or consumer health data, we will investigate it and notify you, and regulators such as the Federal Trade Commission, without unreasonable delay and within the time required by applicable law, including the FTC Health Breach Notification Rule. We will send notice to the email address on your account and explain what happened, what information was involved, and what you can do.
Age and location
MyGLP1App is for adults age 18 and older and is currently offered for use in the United States. We do not knowingly collect information from children under 18.
Policy changes
We may update this policy as the service changes. We will post the revised policy here and update its effective date. If a change is material, such as a new use or recipient of your information, we will also email you at the address on your account before it takes effect. We will not collect, use, or disclose new categories of consumer health data for materially new purposes without the notice and consent required by applicable law.
Contact
Privacy questions or requests can be sent to support@myglp1app.com.