GLPily
Privacy Policy
Last updated September 14, 2026
GLPily ("GLPily", "we", "us") is operated by [COMPANY LEGAL NAME], [ADDRESS]. This policy explains what we collect when you use the GLPily apps and website (the "Service"), why, and the choices you have. GLPily is a self-tracking companion for people using GLP-1 medications. It is not a medical device and does not provide medical advice.
1. What we collect
Account data
Email address, display name and authentication identifiers from Sign in with Apple, Google Sign-In or email/password. We never see your Apple or Google password.
Health and wellness data you enter
Everything you log is stored so it can sync across your devices: weight, body measurements, injections (medication, dose, time, site, status), nutrition and water, symptoms, journal entries, goals and reminders. This is sensitive data and we treat it as such (see Section 5).
Apple Health and Health Connect
If you connect Apple Health or Health Connect, GLPily reads your weight records and, if you enable it, writes the weights you log in GLPily. We use this data only to provide the app's features. We never use Apple Health or Health Connect data for advertising, marketing, or data-mining, never sell it, and never share it with third parties except as needed to sync it to your own GLPily account. You can revoke access at any time in the Health app or Health Connect settings.
Photos
Progress photos you add are stored in private, encrypted storage tied to your account. When you create an AI Transformation, the photo(s) you select are transmitted to our AI image provider (currently OpenAI) solely to generate the image you requested. Under our agreement with the provider your photos are not used to train models. The generated image is stored privately in your account. Source photos and results can be deleted by you at any time.
Purchases
Subscriptions and credit packs are billed by Apple or Google. We receive purchase events (product, time, status, anonymized transaction identifiers) through RevenueCat to grant your credits and PRO access. We never receive your card number.
Device and usage data
App version, platform, crash diagnostics, push notification tokens (if you enable reminders), and basic usage events needed to run and improve the Service. We do not use third-party advertising SDKs.
2. How we use data
- To provide, sync and secure the Service across your iOS, Android and web sessions.
- To generate AI Transformations you explicitly request, and to keep an accurate record of credits used.
- To send injection reminders and service notifications you enable.
- To create doctor reports and exports you ask for (generated on your device).
- To operate billing, prevent fraud and abuse, and comply with law.
- To understand aggregate usage (for example, how many transformations fail) so we can improve reliability. Internal AI cost data is never shown to or associated with individual users beyond what is necessary for billing integrity.
We do not sell personal data. We do not use your health data or photos for advertising.
3. Who we share data with
| Processor | Purpose | Data |
|---|---|---|
| Supabase | Hosting, database, authentication, private file storage | Account, health logs, photos (encrypted at rest) |
| RevenueCat | Subscription and credit-pack purchase processing | App user id, purchase events |
| Apple App Store / Google Play | Billing | Purchase and payment data (held by them) |
| OpenAI (AI image provider) | Generate AI Transformations you request | The photo(s) you select, a text description of the requested edit (never your name or account id) |
| Expo (push notification service) | Deliver notifications you enable | Push token, notification content |
We may also disclose data when required by law, to protect the rights and safety of users, or as part of a merger or acquisition (with notice to you).
4. Retention and deletion
Your data is retained while your account exists. Delete individual photos, transformations or logs in the app at any time. Delete your whole account from More → Account → Delete account, or by emailing support@glpily.com from your account email; account data, photos and AI results are permanently deleted within 30 days, except records we must keep for billing and legal compliance. Photos transmitted to the AI provider are not retained by us after generation beyond the result stored in your account; the provider's transient processing retention is governed by its API data policy.
5. Security
Data is encrypted in transit (TLS) and at rest. Photos and results are stored in private buckets with per-user access rules and are served through short-lived signed links. Sessions on your device are stored in encrypted storage protected by the operating system keychain. Credits and purchases are validated server-side and cannot be altered from a device.
6. Your rights
Depending on where you live (including under GDPR and CCPA/CPRA) you may have the right to access, correct, export, restrict or delete your data, and to object to certain processing. You can export your data as CSV in the app (More → Doctor report → Export CSV) and delete it as described above. For anything else, contact us; we respond within 30 days. You may also lodge a complaint with your local data protection authority.
7. Children
GLPily is intended for adults aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
8. International transfers
Our processors may store data in the United States or other countries. Where required, transfers are protected by standard contractual clauses or equivalent safeguards.
9. Changes
We will post updates here and, for material changes, notify you in the app. Continued use after the effective date means you accept the updated policy.
10. Contact
[COMPANY LEGAL NAME], [ADDRESS] · privacy@glpily.com
