Your health information is some of the most personal data there is. {{app}} ("the app", "we", "us"), made by Xboost, is built so that this data stays with you. This policy explains — in plain, specific terms — exactly what we do and don't do with your information.
The short version: No account is required. Everything you log — your medication, doses, injection sites, side effects, weight, nutrition and notes — is stored on your device (and, only if you turn it on, in your own end-to-end-encrypted iCloud). That health data never reaches our servers. We collect a small amount of anonymous, non-health usage and diagnostic data to keep the app working. We do not sell your data, we do not use it for advertising, we do not track you across other apps, and we don't use the advertising identifier (IDFA).
Contents
1. Scope
This policy applies to the {{app}} application for iPhone and to this website (glp1.xboostapp.io). It describes how we handle information when you use the app or visit the site.
2. Your health data stays on your device
The information you log in the app — including your medication and doses, injection sites, side effects and their severity, weight and measurements, goals, nutrition entries, reminders, notes, and the personalization answers you give during setup — is stored locally on your device.
This health data is not transmitted to Xboost servers, and we have no ability to read it. Because no account is required, we do not maintain any profile of you or your health on our systems. If you enable iCloud sync (off by default), your data is backed up and synced across your own devices using Apple's iCloud, protected by Apple's encryption and tied to your Apple Account — we still cannot read it. Your use of iCloud is also governed by Apple's Privacy Policy.
The one exception is the optional "Describe it" food feature, where a description you type or speak is sent for an AI estimate — with no identity attached and without being stored. See Section 7.
3. Data we collect
To keep the app reliable, understand how it's used, and process subscriptions, we and our service providers collect a limited set of data. Following Apple's definitions, none of it is linked to your identity and none of it is used to track you. It never includes the health content of what you log — we may record that you saved a log, never what was in it.
| Data | Examples | Linked to you? | Used to track you? | Purpose | Processed by |
|---|---|---|---|---|---|
| Product interaction | That a screen was viewed or a dose/food/weight log was saved; which log method was used (e.g. "search" vs "describe"); anonymous session counts. No health content or values. | No | No | Understand usage and improve the app | PostHog |
| Diagnostics | Anonymous crash reports, performance data, app version, device model, OS version. | No | No | Fix bugs and keep the app stable | PostHog |
| Identifier | A random, app-generated installation identifier. Not your name, email, or Apple's advertising identifier (IDFA). | No | No | Tie anonymous events together and attribute installs | PostHog, AppsFlyer |
| Marketing attribution | Which campaign led to an install; trial-start and purchase events (amount & currency); Apple SKAdNetwork conversion values. | No | No | Measure whether our marketing works | AppsFlyer, Apple |
| Purchases | Your subscription status and App Store purchase receipt; paywall views and A/B variant. No card details (Apple handles payment). | No | No | Deliver and manage the subscription you bought | RevenueCat, Superwall, Apple |
| Food description (User Content) | Only if you use "Describe it": the text of your food description. Sent without any identifier and not stored. | No | No | Return an AI nutrition estimate | Supabase (our backend) → OpenAI |
Analytics and attribution are enabled only after you continue past the privacy notice shown on first launch. Session recording and automatic screen-content capture are turned off, so on-screen text is never harvested.
4. Data we do not collect
To be unambiguous, we do not collect, receive or store any of the following:
- Your health data. Medications, doses, injection sites, side effects, weight, measurements, nutrition values and notes never leave your device (except the on-device iCloud backup you control).
- Account / contact details. No name, email, phone number or password — there is no account.
- Contacts, calendar, photos library, or files. We never access these.
- Precise or coarse location. We do not collect your location.
- The advertising identifier (IDFA) or any cross-app tracking identifier.
- Browsing history on other apps or websites.
We do not sell or rent personal information, and we do not share health information with anyone for advertising.
5. Tracking & advertising
We do not track you in the sense defined by Apple's App Tracking Transparency framework. Specifically:
- We do not present the "Ask App Not to Track" prompt because we do not track — there is nothing to ask permission for.
- We do not access or use Apple's advertising identifier (IDFA).
- To measure installs from our own marketing, we use Apple's privacy-preserving SKAdNetwork and an attribution provider (AppsFlyer) using an anonymous identifier. We do not combine your data with data from other companies to build an advertising profile, and we do not share your data with third-party advertising networks.
- There are no third-party ads in the app.
6. Device permissions we may ask for
iOS asks your permission before the app can use these. Each is optional and used only for the stated purpose:
- Notifications — to deliver your dose and other reminders. Reminders are intentionally discreet and never show your medication name or health details on the lock screen.
- Camera — only to scan a product barcode when you choose to log food by barcode. We don't access your photo library.
- Microphone & Speech Recognition — only if you describe food by voice. Your speech is converted to text using Apple's speech recognition (subject to Apple's terms); the resulting text is handled as described in Section 7.
- Face ID / device passcode — only if you choose to lock the app. This authentication is handled by iOS; we never receive your biometric data.
7. Food logging in detail
Most food logging happens entirely on your device. Food search uses a nutrition database bundled inside the app, and your saved and recent foods are stored locally — no network request is made. When you scan a product barcode, the app may look the product up in the public Open Food Facts database, sending only the barcode number — never your identity.
The optional "Describe it" feature is the only part that sends your input off the device. When you use it, the text of your description is sent over an encrypted connection to our backend (a Supabase Edge Function), which relays it to OpenAI to estimate the food and its nutrition, then returns the result to your device. In that flow:
- the request contains your description text only — no name, no account, and no device or user identifier;
- our backend does not store the request content; transient network logs (such as IP address, used only for abuse-prevention rate limiting) are deleted within 24 hours;
- the request to OpenAI is made with storage disabled, and your descriptions are not used to train AI models.
If you never use "Describe it", no food description ever leaves your device.
8. Subscriptions & purchases
{{app}} offers an optional paid subscription. All payments are handled by Apple's In-App Purchase system — we never see or store your payment card details. We use RevenueCat to know whether your subscription or free trial is active and to restore purchases, and Superwall to present offers and run pricing experiments. Paywalls are targeted only by non-health attributes (such as whether you're in a trial) — never by your medication or health data. These services process an anonymous identifier and your purchase receipt, and are not linked to your health data. Billing terms are in our Terms of Use.
9. Service providers
We share the limited, non-health data described above only with providers that process it on our behalf, under agreements restricting them to providing their service to us:
- Apple — App Store distribution, In-App Purchase, iCloud sync, SKAdNetwork. Privacy
- PostHog — anonymous product analytics and diagnostics (autocapture and session replay disabled). Privacy
- AppsFlyer — privacy-preserving install/marketing attribution (no IDFA). Privacy
- RevenueCat — subscription state and restore. Privacy
- Superwall — paywall presentation and A/B testing. Privacy
- Supabase — hosts our backend function for the "Describe it" feature (does not store request content). Privacy
- OpenAI — generates the "Describe it" food estimate (storage disabled; no training on your input). Privacy
10. International data transfers
Some of our providers are based in the United States and may process the limited non-health data described above there or in other countries. Where personal data is transferred out of your region (for example the EEA or UK), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Your health data is not part of these transfers, because it stays on your device or in your own iCloud.
11. Legal bases for processing (GDPR/UK GDPR)
Where the GDPR applies, our legal bases are:
- Consent — for analytics and attribution, which we enable only after you continue past the first-launch privacy notice; you can opt out at any time (see Your rights).
- Performance of a contract — to provide the subscription you purchase and features you request, such as "Describe it".
- Legitimate interests — to keep the app secure, prevent abuse, and fix crashes, balanced against your rights.
For your on-device health data, you remain in control; we do not act as a controller of data that never reaches us.
12. Retention & deletion
Because your health data lives on your device (and, if enabled, in your own iCloud), you control its retention. Deleting the app removes on-device data; the in-app Delete my data control erases your data on the device and in your iCloud, with no undo — and works even after a free trial or subscription ends. The limited anonymous analytics and diagnostic data are retained only as long as needed for the purposes above and are not tied to you. "Describe it" request content is not stored; abuse-prevention logs are deleted within 24 hours. Purchase records are retained as long as needed to manage your subscription and to meet legal and accounting obligations.
13. Security
Data on your device is protected by the device's own security, including your passcode and hardware encryption, and the app can additionally lock with Face ID or your device passcode. All network requests (subscription checks and "Describe it") use encrypted HTTPS connections. No method of storage or transmission is perfectly secure, but our strongest protection is structural: the sensitive data is data we never receive.
14. Your rights
Depending on where you live, you may have rights to access, correct, delete, port or restrict processing of your personal information, to object to processing, and to withdraw consent — for example under the GDPR/UK GDPR or the California Consumer Privacy Act (CCPA/CPRA). Because we don't hold your health data or an account for you, the most direct way to exercise these rights over that data is the in-app Export and Delete my data controls. You can disable analytics/attribution in the app's privacy settings at any time. For requests about the limited data we do process, email [email protected] and we will respond as required by law. We do not "sell" or "share" personal information as defined by California law, and you will not be discriminated against for exercising your rights.
15. Children
{{app}} is intended for adults managing their own GLP-1 treatment and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will address it.
16. Changes to this policy
If we make material changes to how we handle your information, we will update this page and revise the "Last updated" date above. If a change would meaningfully expand what we collect, we will make that clear before it takes effect.
17. Contact
Questions about privacy? Email [email protected]. We're a small team and we read every message.
Medical note: {{app}} is a personal tracking tool, not a medical device, and does not provide medical advice or dosing recommendations. Always consult your healthcare provider about your medication.