Effective Date: March 8, 2026
Last Updated: August 1, 2026
1. Introduction
Glone is a personal tracker for people on GLP-1 medications. Your health data stays on your iPhone and, if you use iCloud, in your own private Apple iCloud account. Our servers never receive it. We do not sell your data and we do not use it for advertising.
Glone is not a medical app and does not provide medical advice, diagnosis, or treatment. It is a personal wellness tracker. Always consult your healthcare provider before making any medical decisions.
Glone (“we,” “us,” or “our”) is a health and wellness application designed to help users track GLP-1 therapy, including injections, weight, body measurements, nutrition, water intake, and side effects.
Publisher: Glone App, Warsaw, Poland
Contact: support@glone.app
This Privacy Policy explains how we collect, use, store, and protect your information when you use the Glone mobile application (the “App”). By using the App, you agree to the practices described in this Privacy Policy.
Important: Glone is designed with a privacy-first approach. Your health and wellness data is stored on your device and, if you are signed in to iCloud, in your own private Apple iCloud account — Glone's servers never receive your health data. Data that we do collect on our servers is limited, encrypted in transit, and pseudonymized. We do not sell your data. We do not use your data for advertising.
You must be at least 18 years old to use Glone.
2. Data We Collect
Here is a simple overview of where your data lives. Your health data stays on your iPhone and in your own private iCloud. The only things on our servers are your sign-in account record, pseudonymized usage analytics, push notification tokens, and your meal schedule.
| Data | Where it is stored | Who can access it |
|---|---|---|
| Health data (weight, injections, body measurements, meals, water, symptoms) | Your iPhone (SwiftData) + your private iCloud (if signed in to iCloud) | Only you |
| Personal info (name, email, Apple ID) on device | Your iPhone (Keychain, hardware-encrypted) | Only you |
| Authentication account record (Apple User ID and email) | Our authentication provider (Supabase Auth) | Us, to sign you in and verify your device's requests |
| Profile and goal settings | Your iPhone + iCloud Key-Value Storage (if enabled) | Only you, across your devices |
| Usage analytics (which features you use) | Our server (Supabase), pseudonymized | Us, for product improvement only |
| Food photos (AI analysis) | In transit only, never stored | Our food-analysis service and OpenAI (processes and discards) |
| Subscription status | Apple + RevenueCat | Apple, RevenueCat, us |
| Push notification tokens | Our server (Supabase) | Us, to deliver notifications |
| Meal schedule (times only) | Our server (Supabase) | Us, for Live Activity updates |
2a. Account Data
When you sign in with Apple, we receive:
- Apple User ID, a unique identifier provided by Apple that is specific to your Apple account and to Glone
- Email address, which may be your real email or an Apple relay address, depending on your choice
- Display name, your first and last name as provided by Apple
Your Apple User ID, email, and display name are stored securely on your device in the iOS Keychain.
To establish an authenticated session, Glone completes Sign in with Apple through Supabase Auth, our authentication provider (hosted in the United States). During this exchange, the identity token issued by Apple — which contains your Apple User ID and, on first sign-in, your email address — is sent to Supabase Auth, which creates and stores an account record for you (your Apple User ID and email). This record is used only to authenticate you and to verify that requests to our servers come from your device. It is not used for advertising, is never sold, and is not shared beyond the providers described in Section 4. See Section 6 for how this record is handled when you delete your account.
2b. Health and Wellness Data
You may enter the following data within the App:
- Injection records, including medication name, dose, injection site, date, and time
- Weight entries, body weight measurements
- Body measurements, daily body-part measurements such as neck, chest, arm, waist, hips, and thigh
- Water intake, daily water consumption
- Food logs, meals, nutritional information, portion sizes
- Side effects and symptoms, type, severity, duration
- Personal goals, target weight, water goals, nutrition goals
All health and wellness data is stored on your device using SwiftData. If you are signed in to iCloud, this data is also synchronized to your own private iCloud account (Apple's CloudKit private database) so that it is backed up and available across your Apple devices. This synchronization is handled by Apple under your Apple ID; the data remains within your personal iCloud storage, and Glone's servers never receive it. You can control iCloud syncing for the App in iOS Settings > [your name] > iCloud.
Certain profile and goal settings (for example, your name, gender, birth date, height, weight, medication and schedule preferences, and your water, nutrition, and activity goals) are additionally synchronized across your Apple devices using Apple's iCloud Key-Value Storage. As with the SwiftData sync above, this data stays within your own private iCloud account and is never sent to Glone's servers.
Your health and wellness data is not sent to Glone's servers. The only exceptions are described in Section 2c and Section 9 (the optional AI food analysis feature, which transmits a food photo you choose to a processing service) and Section 2d (writing selected values back to Apple HealthKit at your request).
2c. Food Photos
When you use the AI food analysis feature, you may take or select a photo of your meal. This photo is:
- Compressed on your device before transmission
- Sent to Glone's food-analysis service, which forwards it to OpenAI's API for nutritional analysis
- Not stored by Glone on any server after the analysis completes
- Not stored by OpenAI (OpenAI does not use API submissions for model training)
The photo is transmitted together with a device identifier and, if you are signed in, your authentication token, which our service uses solely to apply usage limits and prevent abuse; these are not forwarded to OpenAI. No health data, name, or email is sent with the photo.
2d. Apple HealthKit Data
With your explicit permission, the App may:
Read the following data from HealthKit:
- Body weight
- Exercise minutes (Apple Exercise Time)
- Height
- Water intake
Write the following data to HealthKit:
- Body weight
- Body Mass Index (BMI)
- Water intake
- Activity (workouts you log)
- Nutrition (calories, protein, carbohydrates, fat)
- Symptoms and side effects you log (such as nausea, fatigue, and headache)
HealthKit access requires your explicit authorization through the iOS permissions dialog. You can revoke access at any time in iOS Settings > Privacy & Security > Health > Glone.
3. How We Use Your Data
We use your data only to make the App work for you. We never use it for advertising, never sell it, and never build profiles about you for sale.
We use your data solely to provide and improve the App's functionality:
- Track your GLP-1 therapy: display injection schedules, history, and reminders
- Monitor health metrics: show weight trends, nutrition summaries, and progress toward goals
- Authenticate you: use your Apple sign-in and session to keep you signed in and to verify that requests to our servers come from your device
- AI food analysis: send food photos to OpenAI's vision model to estimate nutritional content
- Nutrient verification: query the USDA FoodData Central API to verify and supplement nutritional data
- HealthKit synchronization: read body weight, exercise minutes, height, and water intake, and write body weight, BMI, water intake, activity, nutrition (calories, protein, carbohydrates, fat), and logged symptoms back to HealthKit
- Personalize goals: adapt daily targets based on your profile and preferences
- Send notifications: remind you about injections, water intake, activity, and meals (only if you enable notifications)
- Manage subscriptions: verify your subscription status and entitlements through RevenueCat to provide access to premium features
- Product analytics: understand usage patterns to improve the App (see Section 10)
We do not use your data for advertising, marketing to third parties, or building user profiles for sale.
4. How We Share Your Data
We do not sell your data. Period. We only share limited, specific data with the services that make the App work.
We do not sell your personal data. We do not share your data with advertisers.
We share limited data with the following third parties, strictly for App functionality:
OpenAI (United States): compressed food photos only, for AI nutritional analysis via OpenAI's vision model.
USDA FoodData Central (United States): food item names only, for nutritional data verification.
Apple (United States): Apple ID authentication, HealthKit data, and payment processing, for sign in, health data sync, and subscriptions. Your iCloud backup and sync of App data occurs within your own Apple account.
RevenueCat (United States): your Apple User ID and subscription transaction data (product purchased, purchase date, expiration, renewal status) are shared with RevenueCat, Inc. to manage subscription entitlements and enable cross-device subscription restoration. RevenueCat does not receive your health data, name, email, or any wellness information. RevenueCat's privacy policy: https://www.revenuecat.com/privacy/
Supabase (United States): our backend provider. Supabase hosts:
- Authentication: your account record (Apple User ID and email) used to sign you in and verify your device's requests (see Section 2a).
- Product analytics: usage events (feature usage, screen views) that carry a pseudonymized identifier derived from your Apple User ID and device (see Section 10).
- Push notification tokens (APNs): device identifiers used solely to deliver notifications and Live Activity updates you have enabled.
- Meal schedule data: your meal-timing configuration, used to drive server-scheduled Live Activity updates.
No health data (injections, weight, body measurements, food logs, symptoms) is stored on Supabase.
We may also disclose data if required by law, court order, or governmental regulation, or to protect our legal rights.
5. Data Storage and Security
Your health data is protected by Apple's encryption on your iPhone and in your own private iCloud. The limited data on our servers (your account record, analytics, push tokens, and meal schedule) travels over encrypted connections, and analytics identifiers are pseudonymized with a keyed hash.
On-Device Storage
- Keychain: Apple User ID, email, and display name are stored with hardware-level encryption
- SwiftData: all health and wellness data is stored in a local database on your device
- UserDefaults: app preferences and settings
- App Group container: shared data for widgets (stays on the same device)
Your iCloud (under your Apple account)
- Your health and wellness data (SwiftData) is synchronized to your own private iCloud (Apple CloudKit private database) when you are signed in to iCloud.
- Selected profile and goal settings are synchronized across your devices using iCloud Key-Value Storage.
- This data stays within your personal Apple iCloud account. Glone's servers do not have access to it.
Server-Side Storage (Supabase)
- Your authentication account record (Apple User ID and email), used to sign you in and verify your device's requests.
- Product analytics events, stored under a pseudonymized identifier (see Section 10).
- Device push notification tokens (APNs) and meal schedule configurations, used to deliver notifications and server-scheduled Live Activity updates.
- No health data (injections, weight, body measurements, food logs, symptoms) is stored on our servers.
Encryption
- All network communications use HTTPS (TLS 1.2+)
- On-device Keychain uses iOS hardware encryption
- SwiftData uses iOS Data Protection (encrypted at rest when device is locked)
- iCloud synchronization is encrypted in transit and at rest by Apple under your Apple account
- Analytics identifiers are pseudonymized on our servers using a keyed cryptographic hash (HMAC-SHA256) with a secret key held only by us
6. Data Retention
Your data stays until you delete it. When you delete your account, we erase everything on your device and in your private iCloud, and we also delete your account record, push tokens, meal schedule, and device record from our servers.
On-device data is retained until you delete it within the App or delete the App itself. Data synchronized to your own iCloud is retained by Apple under your Apple account until you delete it in the App (which removes it from iCloud too) or manage it through your iCloud settings.
Account deletion: when you delete your account in the App (Settings > Delete Account), we perform a complete cleanup. On your device: Keychain entries (Apple ID, email, name) are erased, all app settings are cleared, and all health and wellness records (injections, weight entries, body measurements, food logs, water intake, symptoms, and related records) are deleted, including their copies in your private iCloud. On our servers: your authentication account record (Apple User ID and email), your device's push notification tokens, its meal schedule, and its device-ownership record are deleted. Analytics events, which carry only a pseudonymized identifier and no directly identifying information, are retained in aggregate as described below. This action cannot be undone.
App deletion: if you delete the App from your device, iOS automatically removes all associated local data (SwiftData, UserDefaults, App Group). Data already synchronized to your iCloud is managed through your iCloud settings, and any server-side records described above are handled as described under Account deletion.
Analytics: pseudonymized analytics events on Supabase may be retained in aggregate to understand product usage. Because these events are stored under a pseudonymized identifier and contain no directly identifying content, they cannot on their own directly identify you.
7. Your Rights
You are in control. Most of your data lives on your iPhone and in your own iCloud, so you can view, edit, and delete it directly. For the limited data on our servers, email us and we will handle your request.
For Users in the European Economic Area (GDPR)
Under the General Data Protection Regulation, you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate personal data
- Erasure: request deletion of your personal data (“right to be forgotten”)
- Data portability: receive your data in a structured, machine-readable format
- Restriction: request that we limit processing of your data
- Object: object to processing of your personal data
- Withdraw consent: withdraw consent at any time where processing is based on consent
Most of your data is stored on your device and in your own iCloud, so you can directly view, edit, and delete it within the App and through your iCloud settings. For the limited data we hold on our servers (your authentication account record and pseudonymized analytics), contact us at support@glone.app to exercise these rights.
Supervisory Authority: You have the right to lodge a complaint with the Polish Data Protection Authority (UODO), ul. Stawki 2, 00-193 Warsaw, Poland. Website: uodo.gov.pl
Legal Basis for Processing (Art. 6 GDPR)
- Consent (Art. 6(1)(a)): for HealthKit access, AI food analysis, and product analytics
- Contract performance (Art. 6(1)(b)): for providing the App's core functionality, including authentication and subscription management
- Legitimate interest (Art. 6(1)(f)): for improving the App based on pseudonymized analytics and for securing our services
For Users in California (CCPA)
Under the California Consumer Privacy Act, you have the right to:
- Know what personal information we collect and how we use it
- Delete your personal information
- Opt-out of sale: we do not sell personal information, so no opt-out is necessary
- Non-discrimination: we will not discriminate against you for exercising your rights
For Users in Washington State (MHMDA)
Under the Washington My Health My Data Act, you have the right to:
- Consent before collection of health data
- Access your health data
- Delete your health data
- Withdraw consent for health data processing
To exercise any of these rights, contact us at support@glone.app.
8. Apple HealthKit
HealthKit data is treated with the highest level of protection. With your permission we read weight, exercise minutes, height, and water intake, and write your logged wellness values back. It is never used for ads and never sold.
HealthKit data displayed in Glone is for personal wellness tracking only. It is not a medical measurement and should not be used as a substitute for medical devices or professional health assessments.
This section specifically addresses Apple's requirements for HealthKit data.
Data types we access:
- Read: body weight, exercise minutes (Apple Exercise Time), height, water intake
- Write: body weight, body mass index, water intake, activity (workouts), nutrition (calories, protein, carbohydrates, fat), and logged symptoms
Our commitments regarding HealthKit data:
- HealthKit data is not used for advertising or marketing.
- HealthKit data is not sold to data brokers or any third parties.
- HealthKit data obtained from Apple Health is not stored on any Glone server or in iCloud by Glone. (Health data you enter directly in the App may sync to your own private iCloud as described in Section 2b; that is separate from data read from Apple Health.)
- HealthKit data is not shared with third parties except as required to provide core App functionality (writing data back to HealthKit).
- HealthKit data is used solely to display health metrics within the App and to write relevant wellness values (weight, BMI, water intake, activity, nutrition, and logged symptoms) back to HealthKit.
- Access to HealthKit requires your explicit opt-in and can be revoked at any time through iOS Settings.
9. AI Food Analysis
When you snap a photo of your meal, we analyze it with AI to estimate calories and nutrients. The photo is processed and immediately discarded. We never store it.
AI-generated nutritional estimates are approximate and are provided for general informational purposes only. They should not be used for medical dietary requirements, allergy management, or any health condition that requires precise nutritional tracking. Always consult a healthcare professional or registered dietitian for medical nutrition needs.
Glone offers an optional AI-powered food analysis feature. Here is how it works.
Technology used: OpenAI's vision model (via OpenAI API), accessed through Glone's food-analysis service.
What is sent to OpenAI:
- A compressed photo of your food
- A structured prompt requesting nutritional analysis
What is NOT sent to OpenAI:
- Your name, email, or Apple ID
- Your health data (weight, injections, symptoms)
- Your location
Data handling: The photo first goes to Glone's food-analysis service, which forwards it to OpenAI for analysis. Along with the photo, the request includes a device identifier and, if you are signed in, your authentication token; our service uses these solely to apply usage limits and prevent abuse, and they are not forwarded to OpenAI. OpenAI's API data usage policy states that data submitted via the API is not used to train their models. Photos are processed in real-time and are not stored by Glone or OpenAI after processing.
Nutrient verification (USDA): After AI analysis, food item names may be sent to the USDA FoodData Central public API to verify and supplement nutritional values. Only food names are sent, no personal information.
Your control: AI food analysis is entirely optional. You can always enter food data manually. You can edit AI-generated nutritional estimates at any time.
10. Product Analytics
We collect information about which features are used so we can improve the App. These events are pseudonymized with a keyed hash before storage, and they never contain your name, email, health records, or food photos.
We use Supabase to collect product analytics to understand how the App is used and to improve it. Examples of events include feature usage counts, screen views, and general usage patterns.
Analytics events are pseudonymized, not anonymous. Each event carries an identifier derived from your Apple User ID and device. Before storage, this identifier is transformed on our servers into a pseudonym using a keyed cryptographic hash (HMAC-SHA256) with a secret key held only by us, so that all of one user's events share a stable pseudonym without exposing the underlying identifier in the stored data. This lets us understand product usage without our analytics database directly identifying you by name, email, or Apple ID.
What this means for you:
- Analytics data is encrypted in transit (HTTPS/TLS).
- Analytics identifiers are pseudonymized with a keyed hash before storage.
- Analytics data is used solely to improve the App. It is never sold and is never used for advertising.
- Analytics events do not contain your name, email address, health records, or food photos.
Because the pseudonym is derived from a stable identifier, analytics data is personal data under laws such as the GDPR, and you may exercise the rights described in Section 7.
Separately, device push notification tokens (APNs tokens) are stored on Supabase to enable delivery of notifications and Live Activity updates. These tokens are technical device identifiers assigned by Apple and are used only to deliver notifications you have enabled.
11. International Data Transfers
Glone is based in Poland (EU). Some limited data is processed in the United States by the services that power specific features. Your health and wellness data never leaves your device and your own iCloud.
Glone App is based in Warsaw, Poland (European Union). Some data may be transferred outside the EEA:
- Food photos (AI analysis): transferred to Glone's food-analysis service and OpenAI in the United States. Legal basis is your explicit consent (Art. 49(1)(a) GDPR), as you initiate each analysis.
- Food item names: transferred to USDA in the United States. These are public food database queries.
- Authentication and analytics: your authentication account record and pseudonymized analytics events are stored on Supabase in the United States. Legal basis is contract performance (Art. 6(1)(b) GDPR) for authentication and legitimate interest / consent (Art. 6(1)(a)/(f) GDPR) for analytics.
- Subscription data: Apple User ID and transaction data are transferred to RevenueCat in the United States. Legal basis is contract performance (Art. 6(1)(b) GDPR), as subscription management is necessary to provide paid App features.
- Push tokens and meal schedules: transferred to Supabase in the United States to deliver notifications and Live Activity updates.
Your health and wellness data is not transferred to Glone's servers or to non-EU third parties. It stays on your device and, if you use iCloud, within your own private Apple iCloud account.
12. Children's Privacy
Glone is intended for users aged 18 and older. We do not knowingly collect personal information from children under 18. Glone tracks GLP-1 medications, which are prescribed to adults.
If we learn that we have inadvertently collected data from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at support@glone.app.
13. Cookies and Tracking
The iOS app does not use advertising SDKs or cross-app tracking. The website uses only essential cookies.
The App does not use cookies, web beacons, or pixel trackers. The App does not use any advertising SDKs or tracking frameworks. The App does not participate in cross-app tracking (ATT is not requested because we do not track).
Our website (glone.app) uses only essential cookies necessary for website functionality. No analytics or advertising cookies are used on the website.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App before the changes take effect. We encourage you to review this Privacy Policy periodically.
The “Last Updated” date at the top of this page indicates when this Privacy Policy was last revised.
15. Contact Us
Questions? Concerns? We are happy to explain anything in more detail. Just email us.
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
Glone App
Warsaw, Poland
Email: support@glone.app
For data protection complaints in the EU, you may also contact the Polish Data Protection Authority (UODO):
ul. Stawki 2, 00-193 Warsaw, Poland
Website: uodo.gov.pl