HomeProgressTrackingReviewsMedicationsToolsPrivacy

Privacy Policy

Last Updated: September 14th, 2026

Privacy at a glance

  • You control your data. Your medication logs, symptoms, nutrition, weight, and progress photos are stored on your device. On iOS, they can sync to your personal iCloud account via Apple CloudKit; Android does not use iCloud sync. We do not operate the sync servers and do not have access to your synced data. If you choose to analyze a meal photo, that photo is sent to our AI image‑analysis provider solely to generate a calorie estimate; progress photos are never shared with third parties.
  • No account required. We don't ask for your name, email, or address.
  • Cloud Sync. On iOS, your data can sync to your personal iCloud account via Apple CloudKit so you can access it across your Apple devices. Android data stays in local app storage unless you use a feature that transmits it, as described below. We do not operate the sync servers or have access to your synced data.
  • Limited sharing. We use reputable vendors for subscriptions, analytics, diagnostics, paywalls, AI functionality, and attribution. Purchase conversion measurement also shares subscription events and identifiers with Meta, as described in Section 8.
  • Health analytics (no photos). Some profile and health information you enter is sent to product analytics, diagnostics, and paywall tools to measure feature use and personalize the app and subscription offers. We do not send progress or meal photos to analytics tools. Meal photos are only sent to our AI functionality vendor to return a calorie estimate.
  • Health Connect (Android). With your permission, sync weight, nutrients, and water and read steps and active calories. Manage permissions and exported records in Health Connect. See Section 3.
  • Apple Health (HealthKit). We can import data with your permission. Apple Health data is never used for advertising or shared with ad platforms.
  • No selling. We do not sell your personal information or consumer health data.
  • Aggregate insights. We may combine de‑identified data from many users into aggregate statistics (for example, how commonly a side effect is reported in the first week) and show, publish, or share those statistics. They never identify you, we commit to never re‑identifying anyone, and we require the same of anyone we share them with. See "De‑identified & aggregated data" in Section 5.
  • Your rights. You can ask us to access, export, or delete data held with our service providers. Data on your device can be removed by clearing app data or uninstalling. Synced data can be managed through your iCloud account settings.

1) Who we are & how to contact us

GlucoPal is a GLP‑1 tracking app by The Manhattan App Studio LLC ("we", "our", "us"), a New York limited liability company.

  • Email (privacy & requests): hello@glucopal.com
  • Data Controller: The Manhattan App Studio LLC (New York, USA)
  • Intended users: Age 16+. GlucoPal is not intended for children.

Medical disclaimer. GlucoPal provides tracking and educational features. It is not a medical device and does not provide medical advice. Always consult your clinician about diagnosis or treatment.

2) Scope of this policy

This policy covers our iOS and Android mobile apps and any marketing website we operate. It explains what we collect, how we use and share it, your choices and rights, and how to contact us.

3) What we collect

A. Health & wellness data

If you choose to log them, GlucoPal saves the following data on your device. On iOS, it can also sync to your personal iCloud account via Apple CloudKit:

  • Medication: GLP‑1 type, dosage, frequency, injection‑related notes you add
  • Symptoms & notes: side effects, well‑being notes
  • Weight & goals: current, target, trends/graphs
  • Daily nutrition: e.g., calories, protein, water
  • Progress Photos: e.g., progress/timeline photos (never sent to analytics)

Your data is stored on your device. On iOS, it can sync to your personal iCloud account via Apple CloudKit; this sync is not available on Android. We do not operate the sync infrastructure and do not have access to your synced data. On iOS, setup includes consent to Cloud Sync.

B. Apple Health (HealthKit) (optional, opt‑in)

With your permission, GlucoPal can read/import certain data (e.g., weight or activity) from Apple Health to make tracking easier.

  • We do not use Apple Health data for advertising or sell it.
  • We do not share Apple Health data with advertising platforms.
  • You can manage permissions anytime in iOS Settings → Health → Data Access & Devices.

Health Connect on Android (optional, opt-in)

If you choose to connect, GlucoPal requests only the Health Connect permissions used by its tracking features:

  • Weight (read and write): import weigh-ins from connected apps or scales for your weight graph and nutrition goals, and export weigh-ins you log in GlucoPal.
  • Steps and active calories burned (read): show daily activity and step-goal progress and calibrate your calorie goal.
  • Nutrition and hydration (read and write): export meal nutrients and water totals you log in GlucoPal. GlucoPal reads its own records to avoid duplicate exports; it does not import other apps' meals or water logs. Meal names and photos are not written to Health Connect.
  • Past data (optional read): import up to one year of weight history when you grant access to data older than the standard permission window.

Sync runs while GlucoPal is in use. We do not request Health Connect background-read permission. Imported records are stored in GlucoPal's local database. GlucoPal does not require a GlucoPal account or provide cloud backup on Android.

We do not sell Health Connect data, use it for advertising, or share it with advertising platforms. Its permitted use is to provide and improve the tracking and goal features described here, subject to Google's Health Connect requirements. Our use of Health Connect data follows the Health Connect permissions policy, including its Limited Use requirements.

You can decline individual permissions or disconnect in Android Settings → Health Connect → App permissions → GlucoPal. Revoking permission stops future access but does not automatically erase records already imported or exported. Delete imported records in GlucoPal; manage or delete exported records separately in Health Connect. Settings → Delete My Data in GlucoPal leaves Health Connect records in place.

C. Non‑health technical & usage data

To operate and improve GlucoPal, we may collect non‑health technical information and usage telemetry, such as:

  • App version, device model, OS version, language, time zone
  • App stability data (e.g., Crashlytics) and performance metrics
  • Pseudonymous analytics/attribution identifiers (e.g., IDFV, Android advertising ID when available, or SDK-scoped IDs), IP address, and approximate location derived from IP
  • Paywall interactions, purchase events, and subscription status; paywall profile attributes are described below

D. Profile and health analytics

GlucoPal sends selected profile attributes and manually entered health information to product analytics, diagnostics, and paywall tools. These can include birth year, sex, height, weight and weight goals, medication and dose, and activity level. We use these attributes to understand feature use, improve reliability, and personalize the app and subscription offers. Superwall receives profile attributes for paywall personalization and experiments.

  • Never photos. We never transmit your photos to analytics.
  • Never for ads. We do not use health data for advertising or share it with ad platforms.
  • Minimization. We send only what's necessary for measuring feature adoption, usability, and quality.
  • Masking. We configure session/experience tools to mask/redact fields likely to contain free‑text health content whenever possible.

Important for Apple Health data: HealthKit‑sourced data is not used for advertising and is not shared with ad platforms. Where Apple policies require, we do not include HealthKit‑sourced data in analytics beyond what App Store rules permit.

E. Purchase data

We process in‑app purchases and entitlements via:

  • RevenueCat (purchase validation, subscription status)
  • SuperWall (purchase validation, subscription status)
  • Apple App Store (iOS) and Google Play (Android) (platform billing)

We do not receive your full payment card details.

F. Marketing website (if/when you visit)

We may use basic analytics to understand aggregate traffic (pages visited, referrers). We do not collect your app health entries on our website.

G. Data we do not collect

  • No names, emails, postal addresses, phone numbers
  • No precise GPS location, contacts, or calendars
  • No progress photos are shared with third parties

4) How we collect data

  • You enter it (manual logging in the app)
  • Apple Health on iOS or Health Connect on Android (if you opt in and grant permission)
  • Automatic telemetry (crash logs, performance, pseudonymous analytics IDs)
  • Purchases (entitlement state via RevenueCat/SuperWall/App Store/Google Play)
  • Attribution (install/conversion signals from AppsFlyer; see §7)
  • Cloud Sync (iOS only: your data can sync to your personal iCloud account via Apple CloudKit)

5) How we use data (purposes)

  • Provide core features (logging, reminders, charts, cross‑device sync, estimated medication levels)
  • Product improvement (feature adoption, usability, stability, diagnostics)
  • Security & integrity (fraud prevention, abuse detection, troubleshooting)
  • Purchases & subscriptions (entitlements, receipts, refunds)
  • Compliance (legal obligations, audits, responding to lawful requests)

We do not use your health data for cross‑context behavioral advertising and do not sell personal or health data.

De‑identified & aggregated data

We may create de‑identified and aggregated data from the information described in this policy, including consumer health data. De‑identified data has been processed so that it cannot reasonably be used to identify you, describe you, or be linked to you or your device. Aggregated data combines information across many users into statistics (for example, the share of users who report nausea in their first week of treatment).

Because this data does not identify anyone, we may use and disclose it for any lawful purpose, including:

  • Aggregate insights in the app (for example, how commonly other users report a side effect at a given point in treatment)
  • Published statistics on our website or in other content, such as reports or articles
  • Research and collaborations with partners, and the improvement of our products and services

Whenever we create, use, or share de‑identified or aggregated data, we: (a) take reasonable technical and organizational measures to ensure the data cannot be associated with any individual, including aggregating across minimum group sizes; (b) publicly commit to maintain and use the data only in de‑identified form and to never attempt to re‑identify it; and (c) contractually require anyone who receives it to honor these same commitments. Progress photos and meal photos are never included in de‑identified or aggregated data.

To the extent permitted by applicable law, de‑identified and aggregated data is not personal information or consumer health data, and this policy's restrictions on those categories do not apply to it.

6) Legal bases (GDPR/UK GDPR/EEA)

  • Consent: collection/processing of consumer health data and any HealthKit or Health Connect data; Cloud Sync to your iCloud account; analytics involving health data; optional notifications.
  • Legitimate interests/Contract: app operation, security, crash reporting, purchases, non‑health analytics strictly necessary for functionality.
  • Compliance with law: responding to lawful requests, audits, accounting.

You may withdraw consent at any time (see §13). Where required (e.g., Washington/Nevada), we seek affirmative consent before collecting or sharing consumer health data beyond your device.

7) Sharing (who we work with)

We use service providers to operate GlucoPal and advertising measurement partners to measure purchase conversions. The data and purposes are described here and in Section 8.

Key vendors & what they receive

VendorPurposeHealth data?Photos?
RevenueCatSubscription validation, entitlementsNoNo
GroqCalorie estimation from meal photosNoYes (meal only)
Google (Play)Android billing & distributionNoNo
Apple (App Store)Billing & distributionNoNo
FirebaseStability, performance, analyticsYes (limited)No
MixpanelProduct analyticsYes (limited)No
PostHogProduct analyticsYes (limited)No
UXCamExperience analyticsYes (limited)No
SuperwallPaywall UI, personalization & experimentsYes (profile attributes)No
MetaPurchase conversion measurement via RevenueCatSubscription metadata; no health entriesNo
AppsFlyerAttribution & measurementNoNo
Apple (CloudKit)Cross‑device data syncYes (encrypted, user's own iCloud account)No

Progress photos are never shared with third parties. Only photos used for nutritional analysis of meals are shared with our AI image‑analysis provider.

The purchase-measurement integration described below does not include medication entries, weight measurements, meal content, photos, or Health Connect records. We may disclose information if required by law, to protect rights/safety, or during a corporate transaction (with notice and appropriate safeguards).

8) Advertising & attribution

We advertise on platforms such as Apple Search Ads, TikTok, and Facebook. We may receive aggregated campaign‑level reports and use AppsFlyer for install attribution.

Our RevenueCat integration sends purchase and subscription conversion events to Meta. These can include subscription product, purchase amount and currency, transaction information, pseudonymous user and device identifiers, and IP address and device context when available. Meta uses these events to attribute and measure advertising performance. Purchase metadata indicates use of GlucoPal; it does not include the health entries or photos you log.

  • We do not send your in‑app health entries or photos to ad platforms.
  • We do not use consumer health data for targeted ads.

9) Data location, storage & backups

  • Your logs, photos and health entries: stored on your device, with personal iCloud sync via Apple CloudKit on iOS only. Apple encrypts CloudKit data in transit and at rest. We do not operate these servers or have access to your synced data.
  • Vendor systems: telemetry, analytics (including limited health analytics), paywall, and attribution data are stored by our processors in their secure cloud environments (commonly US/EU). All data in transit uses TLS/HTTPS; vendors encrypt data at rest per their standards.

10) Retention

  • On‑device data: kept until you delete it or uninstall the app.
  • Cloud Sync data (iOS only): stored in your iCloud account for as long as the app is installed. You can delete synced data by uninstalling the app or managing your iCloud storage through Apple.
  • Vendor analytics/telemetry: retained per vendor defaults and our settings (commonly 90 days to 26 months).
  • Purchases/entitlements: retained as necessary for accounting, fraud prevention, and legal compliance.

When we no longer need data, we instruct vendors to delete or de‑identify it.

11) Security

We apply technical and organizational measures to protect data:

  • Encryption in transit (HTTPS/TLS)
  • Vendor encryption at rest
  • Cloud Sync uses Apple CloudKit with encryption in transit and at rest, managed by Apple's infrastructure
  • Access controls and data minimization (e.g., progress photos are never shared with third parties; meal photos are transmitted to our AI image‑analysis provider; masking/redaction where supported)

No method is 100% secure. If a security incident impacts your information, we'll follow applicable notification laws.

12) Children

GlucoPal is intended for individuals 16 years and older. We do not knowingly collect data from children under 16. If you believe a child has used GlucoPal, contact hello@glucopal.com so we can assist.

13) Your privacy rights & choices

Depending on your location (e.g., GDPR/UK GDPR, California CPRA, and other U.S. state laws), you may have the right to:

  • Access the data we hold about you with our vendors
  • Export/Port data in a machine‑readable format
  • Correct inaccurate data (where applicable)
  • Delete data (including instructing our vendors to delete)
  • Withdraw consent (for health analytics and any optional processing)
  • Object/Restrict certain processing

Exercising your rights

  • Local app data (on device): remove entries, clear app data (if available), or uninstall the app.
  • Cloud Sync data (iOS only): manage or delete synced data through your iCloud account settings or by uninstalling the app.
  • Vendor data (analytics/telemetry/purchases): email hello@glucopal.com.

Because we don't have accounts or emails, we may ask for device details (e.g., app version, device model) and allow you to share SDK identifiers (e.g., an in‑app "Analytics ID" if/when exposed) so we can locate records with processors. We'll verify requests and respond within the timelines required by law (generally 30–45 days, with possible extension where permitted).

Withdrawing consent for health analytics will stop future health analytics events and we'll instruct processors to delete existing records to the extent feasible.

14) U.S. state privacy notices (summary)

California (CPRA)

  • We do not sell or share personal information for cross‑context behavioral advertising.
  • We process Sensitive Personal Information (health data) only for the purposes described above (providing the service, product improvement with consent, security/compliance).
  • You can exercise rights listed in §13.

Colorado / Connecticut / Virginia / Utah (and similar)

We honor applicable state privacy rights as described in §13.

15) Consumer Health Data Addendum (Washington & Nevada)

This Addendum supplements the policy to comply with Washington's My Health My Data Act (MHMDA) and Nevada's Consumer Health Data Privacy Law.

What is "consumer health data"?

Any personal data linked or reasonably linkable to you that identifies your health status—e.g., your medication logs, dosage values, symptoms, weight, and nutrition entries.

Collection & purposes

We collect consumer health data to:

  • Provide you with GlucoPal's core functionality, including syncing your data across your Apple devices via Cloud Sync
  • Maintain and secure the app (e.g., crash reporting)
  • Improve product features and reliability via limited health analytics (never progress photos; never for ads)
  • Comply with legal obligations

Consent

We request your affirmative consent during setup before collecting or sharing consumer health data outside your device (e.g., syncing your data to your iCloud account via Cloud Sync, sending limited health analytics to service providers). You may withdraw consent at any time (see §13).

Sharing

We do not sell consumer health data. We share consumer health data only with processors that support the purposes above (see §7) and only under contracts requiring confidentiality and security.

De‑identified data

We may create de‑identified and aggregated data as described in Section 5. We take reasonable measures to ensure this data cannot reasonably be associated with you, we publicly commit not to attempt to re‑identify it, and we contractually require the same of any recipient. Data meeting these standards is not "consumer health data" under MHMDA or Nevada's law.

Geofencing

We do not use geofencing to target locations providing health services.

Access, deletion, and appeals

You may request access to or deletion of your consumer health data (§13). If we deny your request, you may appeal by replying to our decision. We will respond with our reasoning and further options, including how to contact your state Attorney General.

16) International transfers

Some processors may store or process data outside your state/country. Where required (e.g., EEA/UK), we rely on Standard Contractual Clauses or comparable safeguards.

17) Changes to this policy

We reserve the right to change and reissue this Privacy Policy at any time by posting an updated version on our website. If we make material changes in the way we collect, use, or disclose your data, we will provide you reasonable advanced notice of the changes before they take effect for you. If we have an existing relationship with you we may provide you notice through our mobile app or directly using the contact information you have provided to us.

If we do not have an existing relationship with you (for instance, if you only visit our website), any notice we provide will be posted to our website. If you continue using the services after those changes are in effect, our processing of your data will be subject to the new Privacy Policy.

We encourage you to regularly review this Privacy Policy to ensure that you remain aware of what data we collect, how we use and otherwise process it, under what circumstances we will disclose it to third parties, and your privacy rights and choices.

18) Contact us

Questions, requests, or appeals: hello@glucopal.com

19) Glossary (helpful definitions)

  • Consumer health data: Health‑related personal data covered by laws like WA MHMDA and Nevada's CHD law.
  • Health data analytics: Limited health data (never progress photos) used in product analytics/diagnostics to improve features and reliability—not for ads.
  • Progress photos: Body/timeline photos you store in the app. These are never shared with third parties.
  • Meal photos: Food/food label images you choose to upload for AI calorie estimation. These are sent to our AI image‑analysis vendor solely to return a result; the photos are not sent to analytics or ad platforms.
  • Processor/Service provider: A vendor that handles data on our behalf under contractual limits (e.g., RevenueCat, Firebase).
  • Sell/Sale: Exchange of personal data for monetary or other valuable consideration (we do not sell).
  • Share (CPRA): Disclosure for cross‑context behavioral advertising (we do not share for ads).
  • Pseudonymous ID: An identifier that doesn't directly reveal your identity (we don't collect names/emails).
  • De‑identified & aggregated data: Information processed so it cannot reasonably identify or be linked to you, and statistics combined across many users. We commit to never re‑identifying this data and require the same of anyone who receives it.
  • Cloud Sync: On iOS, GlucoPal can sync your data to your personal iCloud account via Apple CloudKit, allowing access across your Apple devices. We do not operate the sync infrastructure or have access to your synced data.