GLPily

Privacy Policy

Last updated September 14, 2026

Draft for launch preparation. Have this reviewed by counsel and fill in the bracketed company details before publishing.

GLPily ("GLPily", "we", "us") is operated by [COMPANY LEGAL NAME], [ADDRESS]. This policy explains what we collect when you use the GLPily apps and website (the "Service"), why, and the choices you have. GLPily is a self-tracking companion for people using GLP-1 medications. It is not a medical device and does not provide medical advice.

1. What we collect

Account data

Email address, display name and authentication identifiers from Sign in with Apple, Google Sign-In or email/password. We never see your Apple or Google password.

Health and wellness data you enter

Everything you log is stored so it can sync across your devices: weight, body measurements, injections (medication, dose, time, site, status), nutrition and water, symptoms, journal entries, goals and reminders. This is sensitive data and we treat it as such (see Section 5).

Apple Health and Health Connect

If you connect Apple Health or Health Connect, GLPily reads your weight records and, if you enable it, writes the weights you log in GLPily. We use this data only to provide the app's features. We never use Apple Health or Health Connect data for advertising, marketing, or data-mining, never sell it, and never share it with third parties except as needed to sync it to your own GLPily account. You can revoke access at any time in the Health app or Health Connect settings.

Photos

Progress photos you add are stored in private, encrypted storage tied to your account. When you create an AI Transformation, the photo(s) you select are transmitted to our AI image provider (currently OpenAI) solely to generate the image you requested. Under our agreement with the provider your photos are not used to train models. The generated image is stored privately in your account. Source photos and results can be deleted by you at any time.

Purchases

Subscriptions and credit packs are billed by Apple or Google. We receive purchase events (product, time, status, anonymized transaction identifiers) through RevenueCat to grant your credits and PRO access. We never receive your card number.

Device and usage data

App version, platform, crash diagnostics, push notification tokens (if you enable reminders), and basic usage events needed to run and improve the Service. We do not use third-party advertising SDKs.

2. How we use data

We do not sell personal data. We do not use your health data or photos for advertising.

3. Who we share data with

ProcessorPurposeData
SupabaseHosting, database, authentication, private file storageAccount, health logs, photos (encrypted at rest)
RevenueCatSubscription and credit-pack purchase processingApp user id, purchase events
Apple App Store / Google PlayBillingPurchase and payment data (held by them)
OpenAI (AI image provider)Generate AI Transformations you requestThe photo(s) you select, a text description of the requested edit (never your name or account id)
Expo (push notification service)Deliver notifications you enablePush token, notification content

We may also disclose data when required by law, to protect the rights and safety of users, or as part of a merger or acquisition (with notice to you).

4. Retention and deletion

Your data is retained while your account exists. Delete individual photos, transformations or logs in the app at any time. Delete your whole account from More → Account → Delete account, or by emailing support@glpily.com from your account email; account data, photos and AI results are permanently deleted within 30 days, except records we must keep for billing and legal compliance. Photos transmitted to the AI provider are not retained by us after generation beyond the result stored in your account; the provider's transient processing retention is governed by its API data policy.

5. Security

Data is encrypted in transit (TLS) and at rest. Photos and results are stored in private buckets with per-user access rules and are served through short-lived signed links. Sessions on your device are stored in encrypted storage protected by the operating system keychain. Credits and purchases are validated server-side and cannot be altered from a device.

6. Your rights

Depending on where you live (including under GDPR and CCPA/CPRA) you may have the right to access, correct, export, restrict or delete your data, and to object to certain processing. You can export your data as CSV in the app (More → Doctor report → Export CSV) and delete it as described above. For anything else, contact us; we respond within 30 days. You may also lodge a complaint with your local data protection authority.

7. Children

GLPily is intended for adults aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

8. International transfers

Our processors may store data in the United States or other countries. Where required, transfers are protected by standard contractual clauses or equivalent safeguards.

9. Changes

We will post updates here and, for material changes, notify you in the app. Continued use after the effective date means you accept the updated policy.

10. Contact

[COMPANY LEGAL NAME], [ADDRESS] · privacy@glpily.com