Privacy Policy

Privacy Policy

How GLP-1 Simple collects, uses, stores, and protects your health and personal information.

Last updated: June 2026 | Version 2.0.0

Overview

GLP-1 Simple is a consumer wellness and education product that helps users track and manage their GLP-1 medication journey. This privacy policy explains how we collect, use, store, and protect your information.

GLP-1 Simple is not a hospital, doctor, pharmacy, health insurer, or emergency service. We are a consumer wellness application, not a covered entity under HIPAA. We comply with the FTC Health Breach Notification Rule (16 CFR Part 318), the FTC Act Section 5, and applicable state privacy laws including CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), and CTDPA (Connecticut). We follow industry-standard security practices for health data, including encryption at rest and in transit, access controls, and periodic security reviews.

This service is intended for residents of the United States who are 18 years of age or older. If you are located outside the United States, please be aware that your information may be transferred to and processed in the United States, where data protection laws may differ from those in your country.

Information We Collect

Profile information: Name, email, age range, biological sex, height range, current weight, goal weight, and activity level.

Medication information: GLP-1 medication type, current dose, start date, injection day and schedule, and GLP-1 experience level.

Health tracking data: Symptom logs (type, severity, mood, notes), injection history, protein and hydration intake, body measurements (weight, waist, hips, chest, arms), workout logs, and lab results (A1C, glucose, cholesterol, triglycerides, B12, vitamin D).

Health conditions and goals: Self-reported health conditions, primary goals, motivation, current symptoms, and dietary preferences.

Billing information: When you subscribe, our payment processor (Stripe) collects your payment card details and billing address. We do not store your full card number — only a masked reference provided by Stripe.

Technical data: Browser type, device type, IP address, timestamps, page views, and service logs necessary to operate and secure the product.

How We Use Your Information

To provide personalized health tracking, summaries, progress reports, and wellness features.

To power AI Coach conversations: When you use the AI Coach, health context such as medication, symptoms, goals, and journey phase may be sent to our AI provider for personalized coaching responses. Direct identifiers are minimized, and your first name is only used as a coaching nickname if you separately consent.

To generate personalized onboarding plans, recommendations, and insights based on your tracked data when you request those features and consent is required.

To process payments and manage your subscription through Stripe.

To monitor errors and application performance through Sentry, which may receive anonymized technical context about errors (no health data is included in error reports).

To maintain, secure, debug, and improve the product.

Cookies & Local Storage

Authentication: When you create an account or sign in, Supabase sets secure, HTTP-only session cookies in your browser to maintain your authenticated session. These cookies are required for the app to function when you are signed in.

Analytics: When you grant analytics consent, PostHog stores an anonymous session identifier in your browser's localStorage (not a cookie) to track product usage patterns. No health data is included in analytics events. You can revoke this consent at any time through Settings & Privacy, which will stop all further analytics collection.

Health data storage: Your encrypted health data is stored in your browser's localStorage on your device. This is the primary storage layer for the app and is not transmitted to our servers unless you enable cloud sync.

Preferences and state: Standard browser localStorage and sessionStorage are used to remember your UI preferences, cached data, and feature state. This data stays on your device.

We do not use third-party advertising cookies or cross-site tracking cookies.

AI Processing & Third-Party Services

Our AI Coach is powered by Google Gemini. When you use AI features, we send the limited health context needed to provide the feature and minimize direct identifiers before processing. Your name and email are never sent to AI systems unless you have separately consented to name personalization.

Where provider terms and configuration support it, AI API data is processed to provide the feature and is not used to train provider foundation models.

AI processing requires your explicit consent, which you can grant or revoke at any time through Settings & Privacy.

AI-generated responses are educational and informational only. They are not medical advice, diagnosis, or treatment recommendations.

Service Providers

We use the following third-party service providers to operate the product. Each provider receives only the data necessary to provide their service:

Supabase (supabase.com) — Cloud database, authentication, and file storage for account data, synced health data, and session management.

Google Gemini (ai.google.com) — AI processing for the AI Coach feature. Receives limited, de-identified health context when you use AI features with consent.

Stripe (stripe.com) — Payment processing for subscriptions. Receives your billing information directly. We do not store full card numbers. Stripe's privacy policy applies to payment data.

PostHog (posthog.com) — Product analytics. Receives anonymized usage interaction data when analytics consent is granted. No health data is included.

Sentry (sentry.io) — Error and performance monitoring. May receive anonymized technical error context and device/browser information. Health data is not included in error reports.

All service providers are contractually required to process your information only as directed by us and in accordance with applicable privacy law.

Data Storage & Encryption

Some health data can be stored locally on your device using browser localStorage. If you create an account, sign in, enable sync, upload photos, use notifications, or use cloud-backed features, the data needed for those features may be stored with our service providers, including Supabase.

Health-sensitive local data is encrypted at rest using AES-256-GCM encryption where the encrypted storage adapter is used.

Data in transit is protected by HTTPS/TLS 1.2+ encryption, enforced by our hosting provider.

Avoid entering sensitive information on shared or public devices. If you use account or cloud sync features, data may be available across signed-in sessions according to the feature behavior.

Data Sharing

We do not sell your personal information or health data.

We do not share your health data with advertisers or data brokers.

We share limited information with the service providers listed in the "Service Providers" section above, solely to operate the product.

We may disclose information if required by law, regulation, court order, or valid legal process, or to protect the safety, rights, or property of our users or the public.

If GLP-1 Simple is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice via email or in-app notification before your information becomes subject to a materially different privacy policy.

Your Rights

Access: You can view all data stored by the app at any time through the dashboard.

Export: You can download a complete copy of your data as a JSON file through Settings & Privacy.

Deletion: You can permanently delete all your data through Settings & Privacy. This action cannot be undone.

Consent management: You can grant or revoke consent for AI processing and analytics at any time through Settings & Privacy.

Correction: If you believe any stored data is incorrect, you can edit or delete individual entries through the relevant tracking pages.

California residents (CCPA/CPRA): You have the right to know what personal information we collect and how it is used, the right to delete your personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information (we do not sell or share your data for advertising), and the right not to be discriminated against for exercising these rights. To submit a CCPA request, contact us at privacy@glp1simple.com.

Virginia residents (VCDPA): You have the right to access, correct, delete, and obtain a copy of your personal data, and to opt out of the processing of personal data for targeted advertising or profiling. To submit a request, contact us at privacy@glp1simple.com.

Colorado residents (CPA) and Connecticut residents (CTDPA): You have similar rights to access, correct, delete, and port your personal data, and to opt out of certain processing activities. To submit a request, contact us at privacy@glp1simple.com.

We will respond to verifiable rights requests within 45 days. We may extend this period by an additional 45 days when reasonably necessary, with notice.

Do Not Sell or Share My Personal Information

GLP-1 Simple does not sell your personal information or health data, and does not share it for cross-context behavioral advertising.

If you are a California resident and wish to exercise your right to opt out of any future sale or sharing of your personal information, you may do so through Settings & Privacy or by contacting us at privacy@glp1simple.com.

Data Retention

Local data is retained on your device for as long as you use the app or until you delete it through the available controls.

Cloud-backed account, sync, notification, billing, and support data may be retained by GLP-1 Simple and its service providers for as long as needed to provide the service, comply with legal obligations, resolve disputes, and maintain security.

AI conversations and related request data are handled according to the applicable AI provider terms. We minimize directly identifying information sent for AI processing.

Technical logs (without health data) may be retained for up to 90 days for debugging and security purposes.

When you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes such as fraud prevention or dispute resolution.

Breach Notification

In the event of a data breach involving your health information, we will notify affected users within 60 calendar days of discovery, as required by the FTC Health Breach Notification Rule.

Notifications will include: what happened, what data was involved, what steps we are taking, and what you can do to protect yourself.

For breaches affecting 500 or more individuals, we will also notify the Federal Trade Commission.

Security Measures

AES-256-GCM encryption for health-sensitive and medical data stored locally.

HTTPS/TLS encryption for all data transmitted between your device and our servers.

Rate limiting on API endpoints to prevent abuse.

Data minimization: only necessary health context is processed by AI features, with personally identifying information removed or minimized.

Input validation and sanitization on all user inputs.

Periodic internal security reviews of our data handling practices and infrastructure.

No security system is impenetrable. While we work to protect your data, we cannot guarantee absolute security.

Children's Privacy

GLP-1 Simple is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will delete that information promptly.

If you believe we may have collected information from a child under 18, please contact us at privacy@glp1simple.com.

Governing Law

This Privacy Policy and any disputes arising from it are governed by the laws of the Commonwealth of Kentucky, without regard to its conflict of law provisions.

Any legal action not subject to arbitration (as described in our Terms of Service) shall be brought in the state or federal courts located in the Commonwealth of Kentucky.

Changes to This Policy

We may update this privacy policy from time to time. If we make material changes to how we handle your health information, we will provide at least 14 days advance notice via in-app notification or email to the address associated with your account.

For material changes involving new uses of your health data, we will request renewed consent where required by applicable law.

The consent banner will reappear when the privacy policy version changes, ensuring you are always informed of current practices.

Contact

For privacy questions, data rights requests, or concerns, contact us at privacy@glp1simple.com.

We will respond to all privacy inquiries within 10 business days.