Privacy Policy
GLP Fish records health information. We do not sell it, we do not advertise against it, and we do not give it to third parties for their own use.
GLP Fish — GLP-1 Weight, Dose & Cost Tracker
1. Introduction
GLP Fish ("we," "our," or "us") is an app for keeping a record of a GLP-1 course of treatment: weight, doses, costs, meals, and body measurements. This policy explains what the app stores, where it is stored, who can see it, and what you can do about it. It covers the GLP Fish iOS app and the GLP Fish service at gpt-fish-api.safafish.com. GLP Fish is published by Safafish; the general Safafish site policy is at safafish.com/privacy.html, and this page takes precedence for GLP Fish.
2. Using GLP Fish Without an Account
You can use GLP Fish without creating an account. In that case everything you record stays in the app's storage on your device and is not sent to our servers. No email address, phone number, or contact information is required to use the app this way. If you later create an account, the app asks you explicitly whether to import the records already on this device; if you decline, they are not uploaded.
3. Account Information
If you choose to create an account so your records follow you across devices, we store:
- A username you choose (your private sign-in identifier)
- Your password, stored only as a bcrypt hash — never in readable form
- A display name used only if you post in the community
- An optional recovery email address, if you choose to add one
- Session records: an opaque access token is issued to your device, and only a SHA-256 digest of it is kept on our side
An email address is not required to register. If you add one, it is used solely to verify the address and to let you reset your password; verification codes are stored only as a keyed hash and expire. You can unbind the recovery email from within the app at any time. We do not use your email for marketing.
4. Health Information You Record
The records you create in GLP Fish may include:
- Weight readings, with the weigh-in context you select (fasted, after meals, evening) and the time of the reading. A reading can be typed in, imported from Apple Health, read from a connected Bluetooth scale, or read from a photo of your scale's display — the source is noted on the record
- Body measurements such as waist and hip circumference, height, and body-fat entries
- Medication records: whether a dose was an injection or taken orally, the amount, the time, the cost and currency you enter, and your dosing plan
- Meal and protein entries, typed in or estimated from a photo of your meal if you choose to use the photo estimate
- Course-of-treatment events: starting, pausing, resuming, and maintenance stages, plus the health-status notes you add
- Basic profile details you enter, such as height, sex, and date of birth, used to calculate BMI and the research scenarios
This information is created by you, for your own record. We do not read it to profile you, and it is never used for advertising.
5. Where Your Data Is Stored
On your device. The app keeps a local copy of your records so it works offline. Your access token is stored in the operating system's secure keychain (iOS Secure Store). Some settings stay on the device and are never uploaded: the interface language, the medication market you have selected, the BMI standard, the current time zone, and the identifiers of local reminder notifications.
On our server. If you are signed in, the health records listed in section 4 are synchronized to the GLP Fish service at gpt-fish-api.safafish.com, so that another device signed in to the same account can restore them. Transfers use HTTPS. Records belonging to different accounts on the same device are kept separate, and signing out clears the other account's cached data from the active session.
6. Health Data Is Sensitive — How We Treat It
Weight, medication and treatment records say things about you that other app data does not. We handle them under the following rules:
- Your health records are never sold, rented, or licensed to anyone.
- They are not shared with third parties for their own use — no data brokers, no insurers, no employers, no advertising networks, no analytics vendors. The only outside parties that touch any data are the service providers in section 9, acting on our instructions.
- They are not used to build advertising profiles, and the app contains no advertising SDK and no third-party analytics SDK.
- Access on our side is limited to what is needed to operate the sync service and to investigate a fault you report to us.
- If the copy of your data in the cloud cannot be read safely — a corrupt or unrecognized snapshot — the app refuses to load it rather than overwrite the records already on your device.
- Your health records are never attached to a community post. Community content carries only your display name.
Apple Health. If you turn it on, GLP Fish can import weight readings from Apple Health — read-only, with the permission you grant in iOS, and only the weight type. Imported readings are treated exactly like readings you type in. The app writes nothing back to Apple Health, and the technical marker it keeps to avoid importing the same reading twice never leaves your device. You can revoke access at any time in the iOS Health app.
7. Camera, Photos, and Bluetooth
Three optional features use device permissions. Each runs only when you start it, and the app works fully without them.
- Scale photos. You can photograph your scale's display, or pick such a photo from your library, and the app reads the number for you. The reading happens on your device; the photo is never uploaded. If the photo carries a capture time, it is used to prefill the time of the reading. Only the weight you confirm is saved.
- Meal photos. You can photograph a meal, or pick a photo from your library, to get a calorie and protein estimate. The photo is sent over HTTPS to our server, which passes it to the AI provider named in section 9 solely to produce that estimate. The photo is not stored on our server after the estimate is returned, and it is not used to train anyone's models. Only the entry you confirm is saved to your records. We keep a count of how many estimates your account has used.
- Bluetooth scales. With your permission the app can connect to a compatible Bluetooth scale and take the reading directly. Scanning runs only while the connection screen is open. Readings are stored like any other weight entry. Bluetooth is not used for location or tracking of any kind.
8. Community Posts
The community section is optional. If you post or comment, the text you write and the display name shown at the time of posting are visible to other people. Your username, email address, and health records are never included. Do not put anything in a post that you want to keep private, and do not use a display name you wish to keep private. You can delete your own posts, and you can report someone else's.
9. Service Providers
We keep outside parties to a minimum:
- Apple distributes the app through the App Store. Apple's own handling of downloads and any App Store transaction is governed by Apple's privacy policy; we do not receive payment card details.
- Resend delivers verification and password-reset email, and only if you have chosen to add a recovery email address. It receives that address and the message, and no health data.
- An AI provider (currently Anthropic) produces the estimate when you use the meal-photo feature. It receives the photo and the request itself — not your name, username, or health records. Under the provider's API terms the photo is not used to train its models, and we do not keep the photo after the estimate is returned.
No other third party receives data from GLP Fish. We may disclose information if we are legally required to do so, and we will resist requests that reach further than the law requires.
10. Medication Information Links
GLP Fish shows official medication information matched to your market — for example the FDA, PMDA, EMA, MFDS, or TFDA — and opens those documents inside the app. Those are public regulator pages. Opening one is an ordinary web request to that regulator's site; we do not send them your records.
11. Your Rights
You can, at any time:
- See every record you have made — the app shows them on one timeline
- Correct or edit any weight reading, dose, cost, meal, measurement, or stage
- Delete individual records, or delete the app to remove the local copy from your device
- Unbind your recovery email address
- Delete your account, which deletes the health records held for that account on our server
- Ask us for a copy of the data held for your account
You can delete your account directly in the app: Account screen → Delete Account. Deletion takes effect immediately and removes the account and every record it owns from our server. If you cannot access the app, write to us from the address below and tell us your username; we complete the deletion within 30 days and confirm when it is done. Deleting your account removes the profile, weight, measurement, medication, meal, cost, and course-of-treatment records held for it; community posts you have already published are removed with it.
12. Data Retention
Account and health records are kept for as long as the account exists, because the point of the app is a record that stays readable years later. Sessions expire 30 days after sign-in. Email verification codes expire within 10 to 15 minutes. Local data on your device is removed when you delete the app.
13. Children's Privacy
GLP Fish is intended for adults following a medication plan agreed with their doctor. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
14. Medical Disclaimer
GLP Fish is not a medical device. It does not provide medical advice, diagnose conditions, treat side effects, or recommend dose changes. Always follow your doctor's instructions on taking your medication, adjusting your dose, or stopping treatment. Research scenarios show study-group averages and do not represent your individual results.
15. Changes to This Policy
We may update this policy from time to time. Changes are posted on this page with an updated effective date. This version is effective August 15, 2026.
16. Contact Us
Questions about this policy, a data request, or an account deletion? Contact us at: — or through the Safafish support page.