Privacy Policy
thatglp is a survey and community platform for people using or considering GLP-1 medications, operated by Innovait LLC. This page explains what we collect, why, and who it's shared with — plainly, because some of what you share with us (medications, side effects, weight, symptoms) is sensitive. For the agreement covering your use of thatglp, see our Terms of Service.
The short version: we don't sell your data. Your medication, dose, symptom, and weight entries are never sent to advertisers, and no advertising tracker runs anywhere in the iOS app. Progress photos taken in the app stay on your phone — we never receive them. You can delete everything yourself, from your profile.
What we collect
- Census/quiz answers — medication, cost, provider, side effects, and related answers you submit via the quiz.
- Account info — your email address, used for passwordless (magic link) login. We never receive or store a password.
- Tracking data you choose to log — shot dates, dosage, injection site, weight, and symptom entries, if you use the tracker.
- Check-in photos on the website — if you attach a photo to a weekly check-in on thatglp.com, it's stored in our private photo storage, visible only to you.
- Progress photos in the iOS app — stored only on your own device, in private app storage that is excluded from iCloud backup. They are never uploaded to us and we cannot see them. If you delete the app, they're gone.
- Step count from Apple Health (iOS app only) — if you choose to connect Apple Health, the app reads one thing: your step count for today. It's read on your phone, shown on your dashboard and home screen widget, and never sent to us or anyone else. We don't read any other Health data, and we never write anything to Apple Health. The only step-related thing we store is the daily step goal you set. You can disconnect anytime in the Health app → Sharing → Apps → thatglp.
- Voice input (iOS app only) — if you tap the microphone on a notes or food search field, your speech is turned into text on your phone when your phone supports it, and on older phones through Apple's speech recognition service. We never receive or keep the recording; only the text you choose to save is stored, like anything you type.
- Food barcode scans (iOS app only) — when you scan a food package, only the barcode number is sent, through our server, to Open Food Facts to look up the food. The camera image never leaves your phone.
- Basic usage data — standard web request logs (IP address, browser type) from our hosting provider, and privacy-friendly page analytics.
- Ad-campaign interaction data — on our public marketing pages on the web only (see "Advertising" below).
How we use it
To show you your own results and comparisons, to run your account and the tracker, to send the emails you'd expect (login links, your Census results, and — if you don't opt out — occasional reminders to log a check-in), and to build aggregate, de-identified community statistics (e.g. "the median reported cost is $X"). We do not sell your data, and we do not use your individual answers to identify or advertise to you personally outside of thatglp.
Research use of de-identified data
Before you submit the Census, we ask you to affirmatively agree that your de-identified responses may be used for research. If you agree, we may use aggregated and/or de-identified information from your responses for research, analysis, reports, and collaborations with research, healthcare, pharmaceutical, and other partners. "De-identified" means we strip or aggregate the information so it does not directly identify you — we do not include your name, email, or other direct identifiers in these datasets or reports. This is separate from, and does not affect, how we use your data to run your own account, show you your own results, or send you the emails described elsewhere on this page.
Who we share it with
We use a small number of vetted service providers to run thatglp. Each only receives what it needs to do its job:
- Supabase — our database, authentication, and website photo storage provider.
- PostHog — product analytics: which screens are used and where people get stuck. It never receives your medication, dose, symptoms, weight, or any other health information — only that a step happened.
- Vercel — hosts the website and app content, and provides page analytics.
- Resend — sends our transactional emails (login links, results, reminders).
- Apple — processes Founding Member subscriptions bought in the iOS app. Apple tells us whether a subscription is active; we never see your payment details.
- RevenueCat — manages subscription status between Apple and our app.
- Stripe — processes Founding Member payments made on the website. We never see or store your card details.
- Tally — powers the quiz form itself.
- Open Food Facts and USDA FoodData Central — public food databases. When you search for a food or scan a barcode, they receive only the search words or the barcode number, sent from our server — never your name, email, or any of your health entries.
- Meta (Facebook) — a conversion-tracking pixel runs on our public marketing pages on the web only, so we can measure ad performance. It does not run anywhere in the iOS app, and it never runs on any page where you log a shot, symptom, weight, or photo.
- Research, healthcare, and pharmaceutical partners — only if you checked the research-consent box on the Census, and only in aggregated and/or de-identified form as described above.
We do not otherwise sell, rent, or share your individual data with data brokers, advertisers, employers, or insurers. We may disclose information if the law requires it, or to protect someone's safety — and we'll tell you unless we're legally prevented from doing so.
Advertising & the Meta Pixel
On our public marketing pages on the web, the Meta Pixel logs that a page was viewed so we can measure how well our ads perform. It does not run in the iOS app at all, and it does not run on any page where health tracking happens. Your medication, dose, symptom, weight, and photo entries are never sent to Meta or any other advertising network. Data from Apple Health is never used for advertising or marketing, and never shared with any third party. If you'd prefer not to be tracked on our marketing pages, use your browser's tracking-protection settings or an ad blocker.
Your consumer health data
Some of what you share — medication, dose, side effects, symptoms, weight — is consumer health data under laws including the Washington My Health My Data Act and the Nevada consumer health data law. We collect it only when you enter it yourself, and we use it only to run the Service for you and to produce aggregate, de-identified statistics as described above.
We do not sell consumer health data, and we do not share it for advertising. We will not share identifiable consumer health data with anyone other than the service providers listed above without your separate, specific written authorization. You can withdraw consent, ask what we hold, or have it deleted at any time using the options below.
Your choices and rights
- Delete everything yourself. Go to your profile in the app or on the website and choose to delete your account. This removes your census answers, tracker entries, symptom logs, check-in photos, and your login itself. Can't sign in? Use the account deletion page instead.
- Or ask us. Email hello@thatglp.com from the address on your account to request a copy of your data, correct it, or have it deleted. We'll confirm and complete deletion within 30 days, except where a law requires us to keep something.
- Unsubscribe. Every reminder and marketing email has an unsubscribe link. Unsubscribing does not affect required account emails like login links.
- Withdraw research consent. Email us and we'll stop including your responses in future research datasets. Aggregate statistics already published can't be unpicked, since they no longer reference you.
Depending on where you live, you may have additional rights — to know what we hold, to get a copy, to correct it, to delete it, to limit how we use sensitive information, and to be free from discrimination for exercising them. We honor these requests from everyone, wherever you are, rather than checking your address first. We will never charge you or degrade your service for making a request.
Data retention
We keep your data for as long as your account is active, or as needed to provide the Service. If you delete your account, we delete your identifying data within 30 days, except where a law requires us to keep records (for example, payment records for tax purposes). De-identified, aggregated survey statistics may be retained, since they no longer reference you.
Security
Data is encrypted in transit and at rest with our hosting and database providers. Access is limited to what's needed to operate the Service. Login is passwordless, so there's no password of yours for anyone to steal from us — but it also means your email account is the key to your thatglp account, so keep that secure. No system is perfectly secure; if a breach ever affects your information, we'll notify you and the relevant authorities as the law requires.
Where your data is handled
We operate in the United States, and our service providers store and process data there. If you use thatglp from outside the US, you're sending your information to the US, where privacy laws differ from those where you live.
Children
thatglp is not directed at, and is not intended for use by, anyone under 13. We don't knowingly collect information from anyone under 13. If a child under 13 needs an account, a parent or guardian should set it up — email us. If you believe a child under 13 has given us information directly, email us and we'll delete it.
Changes to this policy
If we make a material change to how we handle your data, we'll update this page, note the new date at the top, and tell you through the Service or by email before the change takes effect.
Contact
Questions about this policy or your data: Innovait LLC · hello@thatglp.com.
← Back to thatglp