Glone

Privacy Policy

Effective Date: March 8, 2026

Last Updated: August 1, 2026

1. Introduction

Glone is a personal tracker for people on GLP-1 medications. Your health data stays on your iPhone and, if you use iCloud, in your own private Apple iCloud account. Our servers never receive it. We do not sell your data and we do not use it for advertising.

Glone is not a medical app and does not provide medical advice, diagnosis, or treatment. It is a personal wellness tracker. Always consult your healthcare provider before making any medical decisions.

Glone (“we,” “us,” or “our”) is a health and wellness application designed to help users track GLP-1 therapy, including injections, weight, body measurements, nutrition, water intake, and side effects.

Publisher: Glone App, Warsaw, Poland

Contact: support@glone.app

This Privacy Policy explains how we collect, use, store, and protect your information when you use the Glone mobile application (the “App”). By using the App, you agree to the practices described in this Privacy Policy.

Important: Glone is designed with a privacy-first approach. Your health and wellness data is stored on your device and, if you are signed in to iCloud, in your own private Apple iCloud account — Glone's servers never receive your health data. Data that we do collect on our servers is limited, encrypted in transit, and pseudonymized. We do not sell your data. We do not use your data for advertising.

You must be at least 18 years old to use Glone.

2. Data We Collect

Here is a simple overview of where your data lives. Your health data stays on your iPhone and in your own private iCloud. The only things on our servers are your sign-in account record, pseudonymized usage analytics, push notification tokens, and your meal schedule.

DataWhere it is storedWho can access it
Health data (weight, injections, body measurements, meals, water, symptoms)Your iPhone (SwiftData) + your private iCloud (if signed in to iCloud)Only you
Personal info (name, email, Apple ID) on deviceYour iPhone (Keychain, hardware-encrypted)Only you
Authentication account record (Apple User ID and email)Our authentication provider (Supabase Auth)Us, to sign you in and verify your device's requests
Profile and goal settingsYour iPhone + iCloud Key-Value Storage (if enabled)Only you, across your devices
Usage analytics (which features you use)Our server (Supabase), pseudonymizedUs, for product improvement only
Food photos (AI analysis)In transit only, never storedOur food-analysis service and OpenAI (processes and discards)
Subscription statusApple + RevenueCatApple, RevenueCat, us
Push notification tokensOur server (Supabase)Us, to deliver notifications
Meal schedule (times only)Our server (Supabase)Us, for Live Activity updates

2a. Account Data

When you sign in with Apple, we receive:

Your Apple User ID, email, and display name are stored securely on your device in the iOS Keychain.

To establish an authenticated session, Glone completes Sign in with Apple through Supabase Auth, our authentication provider (hosted in the United States). During this exchange, the identity token issued by Apple — which contains your Apple User ID and, on first sign-in, your email address — is sent to Supabase Auth, which creates and stores an account record for you (your Apple User ID and email). This record is used only to authenticate you and to verify that requests to our servers come from your device. It is not used for advertising, is never sold, and is not shared beyond the providers described in Section 4. See Section 6 for how this record is handled when you delete your account.

2b. Health and Wellness Data

You may enter the following data within the App:

All health and wellness data is stored on your device using SwiftData. If you are signed in to iCloud, this data is also synchronized to your own private iCloud account (Apple's CloudKit private database) so that it is backed up and available across your Apple devices. This synchronization is handled by Apple under your Apple ID; the data remains within your personal iCloud storage, and Glone's servers never receive it. You can control iCloud syncing for the App in iOS Settings > [your name] > iCloud.

Certain profile and goal settings (for example, your name, gender, birth date, height, weight, medication and schedule preferences, and your water, nutrition, and activity goals) are additionally synchronized across your Apple devices using Apple's iCloud Key-Value Storage. As with the SwiftData sync above, this data stays within your own private iCloud account and is never sent to Glone's servers.

Your health and wellness data is not sent to Glone's servers. The only exceptions are described in Section 2c and Section 9 (the optional AI food analysis feature, which transmits a food photo you choose to a processing service) and Section 2d (writing selected values back to Apple HealthKit at your request).

2c. Food Photos

When you use the AI food analysis feature, you may take or select a photo of your meal. This photo is:

The photo is transmitted together with a device identifier and, if you are signed in, your authentication token, which our service uses solely to apply usage limits and prevent abuse; these are not forwarded to OpenAI. No health data, name, or email is sent with the photo.

2d. Apple HealthKit Data

With your explicit permission, the App may:

Read the following data from HealthKit:

Write the following data to HealthKit:

HealthKit access requires your explicit authorization through the iOS permissions dialog. You can revoke access at any time in iOS Settings > Privacy & Security > Health > Glone.

3. How We Use Your Data

We use your data only to make the App work for you. We never use it for advertising, never sell it, and never build profiles about you for sale.

We use your data solely to provide and improve the App's functionality:

We do not use your data for advertising, marketing to third parties, or building user profiles for sale.

4. How We Share Your Data

We do not sell your data. Period. We only share limited, specific data with the services that make the App work.

We do not sell your personal data. We do not share your data with advertisers.

We share limited data with the following third parties, strictly for App functionality:

OpenAI (United States): compressed food photos only, for AI nutritional analysis via OpenAI's vision model.

USDA FoodData Central (United States): food item names only, for nutritional data verification.

Apple (United States): Apple ID authentication, HealthKit data, and payment processing, for sign in, health data sync, and subscriptions. Your iCloud backup and sync of App data occurs within your own Apple account.

RevenueCat (United States): your Apple User ID and subscription transaction data (product purchased, purchase date, expiration, renewal status) are shared with RevenueCat, Inc. to manage subscription entitlements and enable cross-device subscription restoration. RevenueCat does not receive your health data, name, email, or any wellness information. RevenueCat's privacy policy: https://www.revenuecat.com/privacy/

Supabase (United States): our backend provider. Supabase hosts:

No health data (injections, weight, body measurements, food logs, symptoms) is stored on Supabase.

We may also disclose data if required by law, court order, or governmental regulation, or to protect our legal rights.

5. Data Storage and Security

Your health data is protected by Apple's encryption on your iPhone and in your own private iCloud. The limited data on our servers (your account record, analytics, push tokens, and meal schedule) travels over encrypted connections, and analytics identifiers are pseudonymized with a keyed hash.

On-Device Storage

Your iCloud (under your Apple account)

Server-Side Storage (Supabase)

Encryption

6. Data Retention

Your data stays until you delete it. When you delete your account, we erase everything on your device and in your private iCloud, and we also delete your account record, push tokens, meal schedule, and device record from our servers.

On-device data is retained until you delete it within the App or delete the App itself. Data synchronized to your own iCloud is retained by Apple under your Apple account until you delete it in the App (which removes it from iCloud too) or manage it through your iCloud settings.

Account deletion: when you delete your account in the App (Settings > Delete Account), we perform a complete cleanup. On your device: Keychain entries (Apple ID, email, name) are erased, all app settings are cleared, and all health and wellness records (injections, weight entries, body measurements, food logs, water intake, symptoms, and related records) are deleted, including their copies in your private iCloud. On our servers: your authentication account record (Apple User ID and email), your device's push notification tokens, its meal schedule, and its device-ownership record are deleted. Analytics events, which carry only a pseudonymized identifier and no directly identifying information, are retained in aggregate as described below. This action cannot be undone.

App deletion: if you delete the App from your device, iOS automatically removes all associated local data (SwiftData, UserDefaults, App Group). Data already synchronized to your iCloud is managed through your iCloud settings, and any server-side records described above are handled as described under Account deletion.

Analytics: pseudonymized analytics events on Supabase may be retained in aggregate to understand product usage. Because these events are stored under a pseudonymized identifier and contain no directly identifying content, they cannot on their own directly identify you.

7. Your Rights

You are in control. Most of your data lives on your iPhone and in your own iCloud, so you can view, edit, and delete it directly. For the limited data on our servers, email us and we will handle your request.

For Users in the European Economic Area (GDPR)

Under the General Data Protection Regulation, you have the right to:

Most of your data is stored on your device and in your own iCloud, so you can directly view, edit, and delete it within the App and through your iCloud settings. For the limited data we hold on our servers (your authentication account record and pseudonymized analytics), contact us at support@glone.app to exercise these rights.

Supervisory Authority: You have the right to lodge a complaint with the Polish Data Protection Authority (UODO), ul. Stawki 2, 00-193 Warsaw, Poland. Website: uodo.gov.pl

Legal Basis for Processing (Art. 6 GDPR)

For Users in California (CCPA)

Under the California Consumer Privacy Act, you have the right to:

For Users in Washington State (MHMDA)

Under the Washington My Health My Data Act, you have the right to:

To exercise any of these rights, contact us at support@glone.app.

8. Apple HealthKit

HealthKit data is treated with the highest level of protection. With your permission we read weight, exercise minutes, height, and water intake, and write your logged wellness values back. It is never used for ads and never sold.

HealthKit data displayed in Glone is for personal wellness tracking only. It is not a medical measurement and should not be used as a substitute for medical devices or professional health assessments.

This section specifically addresses Apple's requirements for HealthKit data.

Data types we access:

Our commitments regarding HealthKit data:

9. AI Food Analysis

When you snap a photo of your meal, we analyze it with AI to estimate calories and nutrients. The photo is processed and immediately discarded. We never store it.

AI-generated nutritional estimates are approximate and are provided for general informational purposes only. They should not be used for medical dietary requirements, allergy management, or any health condition that requires precise nutritional tracking. Always consult a healthcare professional or registered dietitian for medical nutrition needs.

Glone offers an optional AI-powered food analysis feature. Here is how it works.

Technology used: OpenAI's vision model (via OpenAI API), accessed through Glone's food-analysis service.

What is sent to OpenAI:

What is NOT sent to OpenAI:

Data handling: The photo first goes to Glone's food-analysis service, which forwards it to OpenAI for analysis. Along with the photo, the request includes a device identifier and, if you are signed in, your authentication token; our service uses these solely to apply usage limits and prevent abuse, and they are not forwarded to OpenAI. OpenAI's API data usage policy states that data submitted via the API is not used to train their models. Photos are processed in real-time and are not stored by Glone or OpenAI after processing.

Nutrient verification (USDA): After AI analysis, food item names may be sent to the USDA FoodData Central public API to verify and supplement nutritional values. Only food names are sent, no personal information.

Your control: AI food analysis is entirely optional. You can always enter food data manually. You can edit AI-generated nutritional estimates at any time.

10. Product Analytics

We collect information about which features are used so we can improve the App. These events are pseudonymized with a keyed hash before storage, and they never contain your name, email, health records, or food photos.

We use Supabase to collect product analytics to understand how the App is used and to improve it. Examples of events include feature usage counts, screen views, and general usage patterns.

Analytics events are pseudonymized, not anonymous. Each event carries an identifier derived from your Apple User ID and device. Before storage, this identifier is transformed on our servers into a pseudonym using a keyed cryptographic hash (HMAC-SHA256) with a secret key held only by us, so that all of one user's events share a stable pseudonym without exposing the underlying identifier in the stored data. This lets us understand product usage without our analytics database directly identifying you by name, email, or Apple ID.

What this means for you:

Because the pseudonym is derived from a stable identifier, analytics data is personal data under laws such as the GDPR, and you may exercise the rights described in Section 7.

Separately, device push notification tokens (APNs tokens) are stored on Supabase to enable delivery of notifications and Live Activity updates. These tokens are technical device identifiers assigned by Apple and are used only to deliver notifications you have enabled.

11. International Data Transfers

Glone is based in Poland (EU). Some limited data is processed in the United States by the services that power specific features. Your health and wellness data never leaves your device and your own iCloud.

Glone App is based in Warsaw, Poland (European Union). Some data may be transferred outside the EEA:

Your health and wellness data is not transferred to Glone's servers or to non-EU third parties. It stays on your device and, if you use iCloud, within your own private Apple iCloud account.

12. Children's Privacy

Glone is intended for users aged 18 and older. We do not knowingly collect personal information from children under 18. Glone tracks GLP-1 medications, which are prescribed to adults.

If we learn that we have inadvertently collected data from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at support@glone.app.

13. Cookies and Tracking

The iOS app does not use advertising SDKs or cross-app tracking. The website uses only essential cookies.

The App does not use cookies, web beacons, or pixel trackers. The App does not use any advertising SDKs or tracking frameworks. The App does not participate in cross-app tracking (ATT is not requested because we do not track).

Our website (glone.app) uses only essential cookies necessary for website functionality. No analytics or advertising cookies are used on the website.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App before the changes take effect. We encourage you to review this Privacy Policy periodically.

The “Last Updated” date at the top of this page indicates when this Privacy Policy was last revised.

15. Contact Us

Questions? Concerns? We are happy to explain anything in more detail. Just email us.

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Glone App

Warsaw, Poland

Email: support@glone.app

For data protection complaints in the EU, you may also contact the Polish Data Protection Authority (UODO):

ul. Stawki 2, 00-193 Warsaw, Poland

Website: uodo.gov.pl