Privacy Policy
Last updated: September 2026
GLP-1 Companion ("we," "our," or "us") is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your personal information when you use our application.
We collect information you provide directly to us, including:
Except for the automatic website visit analytics, subscription-flow analytics, and limited service diagnostics described below, we do not collect personal information without your explicit input or action in the App. We do not use your health data for advertising, marketing, or any purpose other than providing the app's core tracking and insights features.
In production app releases where Sentry is configured and enabled, Sentry automatically reports app crashes, samples limited performance information, and tracks app sessions to help us diagnose errors and improve reliability. This integration is disabled in development and Expo Go, and is inactive when the required Sentry configuration is not present.
These diagnostics may include technical context such as your device, operating system, platform, and app version or build information. When you are signed in, we may attach only an opaque Clerk account identifier so we can correlate an issue with an account; the integration is configured not to send default personally identifying information such as your name or email address.
When you visit our website, we automatically record page visits to understand website traffic and campaign or referring-site performance. A page-visit record may include the page pathname, referring website host, UTM source, medium, or campaign values when present, and whether the request was authenticated. Query strings and hash fragments are removed from the stored pathname, and referring URLs are reduced to their host name.
The website generates a random visitor ID and stores it in your browser's localStorage. When a campaign URL includes UTM source, medium, or campaign values, the first-touch values are stored there as well. The visitor ID and those attribution values are sent with page visits to help us count returning browsers and analyze traffic. They persist in that browser until local storage is cleared or unavailable. Because the visitor ID can link visits from the same browser, this traffic is not anonymous in the strict sense.
Website visit analytics are separate from your account data. We do not state a retention period or promise automatic deletion for these records in this policy.
For signed-in accounts, we record subscription-flow steps such as viewing a paywall, selecting a plan, opening or canceling checkout, and encountering a purchase error. We also record trial and payment outcomes confirmed by our payment providers. These records help us identify subscription problems and understand where people stop in the signup and payment process.
These records are linked to your account and include the event time, platform, plan, and a limited technical error code when relevant. They do not contain health entries, payment-card details, passwords, or free-text error messages. Access is restricted to authorized administrators.
Subscription-flow event records are scheduled for removal after 180 days from recording and are removed when your account is permanently deleted. This applies to our subscription-flow analytics, not to financial records retained by payment providers or the separate website visit and diagnostic datasets described above.
On iOS, GLP-1 Companion can optionally connect to Apple Health (HealthKit) to mirror data into and out of the app. HealthKit access is opt-in: nothing is read or written until you explicitly grant permission through the iOS system prompt, and you can revoke access at any time in the Settings app under Privacy & Security → Health.
When you grant permission, the app may:
Apple Health data is processed only on your device. We do not transmit, store, or share any HealthKit-sourced data with our servers or any third party. We never use HealthKit data for advertising, marketing, data mining, or for sharing with third parties for those purposes, in accordance with Apple's HealthKit guidelines.
GLP-1 Companion includes an optional Progress Photos feature that lets you capture and compare photos to track visible changes during your journey. Camera and photo library access is opt-in and requested only when you tap the corresponding option.
Your information is used solely to:
Your data is stored on secure servers using industry-standard encryption. Authentication is handled by a trusted third-party identity provider (Clerk) — we do not store passwords. All data transmission uses HTTPS encryption.
We do not sell, rent, or share your personal health data with third parties for advertising or marketing purposes.
We use the following third-party services to operate the app:
These services only receive the minimum information necessary to provide their respective functions (e.g., email address for authentication, payment details for billing). None of these services receive your health tracking data.
GLP-1 Companion offers premium subscription plans billed on a monthly or annual basis. All subscriptions include a 7-day free trial.
We retain account data in accordance with the account lifecycle and deletion process. Website visit analytics and service diagnostics are separate datasets; their retention periods and deletion handling are not specified here.
You may request deletion of your account data at any time by contacting us. An account deletion request does not promise automatic deletion of website visit analytics or service diagnostics; requests concerning those datasets are outside the account-deletion operation and require separate review.
GLP-1 Companion is intended for adults aged 18 and older. We do not knowingly collect information from children under 13.
You have the right to:
If you have questions about this privacy policy or your data, please contact us at:
We may update this privacy policy from time to time. We will notify you of significant changes through the app. Continued use of the app after changes constitutes acceptance of the updated policy.