OffGrid Dose has no account, company-operated cloud sync, or server-side health database. Depending on your Apple and device settings, an encrypted device backup may include app data.
Your GLP-1 health data — injection records, weight history, medication dosages, side effects, and progress photos — is among the most sensitive personal information you can generate. Yet most GLP-1 tracker apps store this data on cloud servers with account-based systems that expose it to risks most users never consider. On-device storage is the most effective way to protect this data, and understanding why requires looking at what is actually at stake.
The Rise of GLP-1 Medications and the Data They Generate
GLP-1 receptor agonists have become one of the most prescribed medication classes in the world. Semaglutide (sold as Ozempic and Wegovy) and tirzepatide (sold as Mounjaro and Zepbound) are used by millions of people for type 2 diabetes management and weight loss. As these medications have moved into the mainstream, an ecosystem of tracking apps has emerged to help users manage their treatment.
Every GLP-1 user generates a continuous stream of health data: weekly injection logs, daily or weekly weight measurements, dosage titration records, side effect reports, and in some cases body progress photos. Over a typical treatment course of 12 to 24 months, this adds up to a remarkably detailed medical profile.
The question is: where does all of this data go, and who can access it?
What Health Data Is at Stake
To understand the privacy implications of GLP-1 tracking, it helps to catalog exactly what these apps typically store.
Injection Records
Every time you log an injection, you create a timestamped record of a specific medication at a specific dose administered to a specific body site. Over months, this becomes a complete pharmaceutical administration history — the kind of detailed medication record that would normally exist only in a clinical chart maintained by your healthcare provider.
Weight and Body Composition
Regular weight entries create a longitudinal record of the values you entered. When stored beside medication and dose entries, the log provides dated context for a clinician to review, but it does not establish how your body responded to a pharmaceutical intervention or dosage.
Medication and Dosage Details
Your titration history records when you entered a move from one dose to another. Stored beside weight entries, it remains sensitive prescription-level context, but the record alone does not indicate treatment efficacy.
Progress Photos
Progress photos are the most sensitive data category in any GLP-1 tracker. These are literal images of your body, typically taken in minimal clothing to show physical changes over time. When stored in a GLP-1 app, they are linked to your medication records, weight data, and personal identity (if you have an account). The combination of identifiable body photos with detailed pharmaceutical records creates an extraordinarily sensitive dataset.
Side Effects and Symptoms
Logging nausea, fatigue, constipation, injection site reactions, or other side effects creates a medical symptom diary. This data, correlated with your specific medication and dosage, constitutes a personal adverse event record.
Behavioral Metadata
Beyond the health data you intentionally enter, most apps collect behavioral metadata: when you open the app, how long you spend on each screen, what features you use, when you stop using the app (potentially indicating you stopped your medication). This usage pattern data can reveal health behaviors and medication adherence.
How Most Health Apps Handle Your Data
The typical GLP-1 tracker app uses a cloud-based architecture with account-based authentication. Here is what that means in practice.
Account Creation and Identity Linking
When you create an account with an email address (or sign in with Apple/Google), you permanently link your identity to every piece of health data you subsequently enter. Your injection records, weight history, and medication details are no longer anonymous data — they are your data, associated with your identity on a remote server.
Cloud Storage
Most GLP-1 apps store your data on cloud infrastructure like Firebase (Google), AWS, or Azure. Your health records are transmitted from your phone to servers in data centers, where they are stored alongside the data of thousands or millions of other users. While this data is typically encrypted "in transit and at rest" (a standard security practice), it exists in a location you do not physically control and is managed by employees and systems you cannot audit.
Third-Party Analytics and SDKs
Many health apps embed third-party software development kits (SDKs) for analytics, crash reporting, attribution tracking, and advertising. Popular ones include Firebase Analytics, Mixpanel, Amplitude, AppsFlyer, and Facebook SDK. Each of these services receives some amount of data from the app — potentially including device identifiers, usage patterns, and in some cases health-related information.
A GLP-1 tracker that integrates with Firebase, for instance, sends usage data to Google's servers. The app may claim it does not "share health data with third parties," but the distinction between health data and usage metadata can be blurry when the app's sole purpose is health tracking.
Privacy Policies and Their Limits
Privacy policies govern how companies handle your data, but they have significant limitations. Policies can be changed with notice. They typically include broad language about sharing data with "service providers" and "business partners." They generally permit data use for "improving our services" — which can encompass nearly anything. And in the event of a company acquisition or bankruptcy, user data is often treated as a business asset that transfers to the acquiring entity.
Real Risks: Who Wants Your GLP-1 Data?
The concern about GLP-1 data privacy is not theoretical. Multiple categories of organizations have demonstrated interest in health data, and the mechanisms for accessing it are well-established.
Data Breaches
Health data breaches are increasingly common. The healthcare sector consistently ranks among the top targets for cyberattacks, and consumer health apps — which often have less robust security infrastructure than hospitals or insurance companies — represent attractive targets. A breach of a GLP-1 tracker database would expose users' medication records, weight histories, and potentially body photos.
In 2023 and 2024, several health and fitness apps experienced significant data breaches. The consequences for affected users included exposure of medical conditions, prescription information, and biometric data. Cloud-stored GLP-1 data faces similar risks.
Insurance Companies
Health and life insurance companies have a direct financial interest in knowing whether applicants and policyholders take GLP-1 medications. This information affects risk calculations, premium pricing, and coverage decisions. While there are legal restrictions on how insurers can obtain and use health data, the regulatory landscape is evolving and varies by jurisdiction. Data broker markets create indirect channels for health information to reach insurance companies.
Data Brokers and Other Third Parties
The data broker industry collects, aggregates, and resells personal information including health-related data. Consumer health app data that flows through analytics platforms or is exposed in breaches can end up in broker databases, available for purchase by insurers, employers, or other interested parties. Court orders and subpoenas can also compel companies to produce user data stored on their servers.
The On-Device Alternative: How It Works
On-device storage reduces the risks above because the app does not send your health data to the developer or a company-operated health database. Here is how the architecture works technically.
Local Database Frameworks
Apple's SwiftData (used by OffGrid Dose) is a native framework that stores structured data efficiently on the device's local storage. It supports complex queries and relationships between data entities — all without any network component.
Zero Server Architecture
An on-device health app can keep its working health entries out of a company-operated backend. That removes one company-side database from the threat model, but it does not remove device, Apple-managed backup, purchase, website, or user-directed export considerations. Read the product's current policy for the exact boundaries.
No Health-Record Measurement Pipeline
On-device health records can remain outside measurement services even when an app uses limited subscription or advertising measurement. OffGrid Dose does not send medication, dose, weight, symptom, photo, note, demographic, or injection-history content to its subscription or measurement partners.
Data Backup and Recovery
OffGrid Dose does not provide its own backup or recovery service. Apple explains that iCloud Backup can include app data for downloaded apps, but inclusion depends on the app and your Apple and device settings. An encrypted device backup may help with recovery, but no particular OffGrid Dose record is guaranteed to be included or restored.
How to Evaluate a Health App's Privacy
When choosing any health app — whether for GLP-1 tracking or another purpose — use this checklist to evaluate its privacy practices.
- Does it require an account? An account links your identity to your health data. No account means local storage.
- Where is data stored? Local working storage with no company-operated health database minimizes company access. "Encrypted in transit and at rest" indicates data moves through external infrastructure protected by standard security controls.
- What SDKs are embedded? Check App Store privacy labels to see what data types the app collects and whether they are linked to your identity.
- Can core health-log functions work without internet? That can indicate local working storage, but purchases, restores, entitlement checks, updates, external links, and optional platform services are separate network flows.
- What does the privacy policy say? Look for specifics about third-party data sharing, analytics partners (Firebase, Mixpanel), and data handling during acquisitions.
- Does the business model align with privacy? A paid app with no account has a clear model. A free app with no revenue source may monetize your data.
- What happens when you stop using the app? Deleting an app removes its local data from that device, but an Apple-managed backup may still include app data depending on settings and timing. Cloud retention is governed by the provider's policy.
OffGrid Dose: Privacy by Architecture
OffGrid Dose was designed as a private GLP-1 tracker from its foundation. It is not a cloud app with privacy features bolted on — it is an app where privacy is the architecture itself.
- No app accounts. No name, email, password, or sign-up is required for an OffGrid Dose account; the company does not receive working health-log entries through a sync service.
- On-device working storage. Health entries use Apple's SwiftData locally; there is no company cloud-sync service or server-side health database. Apple-managed backups depend on user settings.
- Health records stay outside measurement. RevenueCat subscription processing and ATT-authorized advertising measurement never receive the working health log. App Store purchases, entitlement checks, Apple-managed services, website analytics, and user-chosen exports are separate data flows.
- Offline health-log workflow. Logging and reviewing working health entries does not depend on company cloud sync. Connectivity may still be needed for purchases, entitlement checks, updates, links, or Apple-managed services.
- On-device progress photos. Body photos are stored locally with a comparison slider and are not uploaded by the app to an OffGrid Dose server.
- Visual body map. Eight color-coded zones summarize logged site history and recency only. The map does not determine tissue readiness, safety, absorption, or effectiveness, and the app does not recommend an injection site.
- Dose-change markers. Weight charts place each entered titration step as a dated marker beside weight and reported-symptom entries; the view does not establish causation.
- 10-second check-in flow. Minimal friction for daily tracking.
The app is a free download with in-app purchase options. Apple shows the current access terms in the App Store and in the app.
The business model is straightforward: you pay for the software. There is no secondary revenue from your health data because OffGrid Dose does not receive it.
Frequently Asked Questions
Is my GLP-1 tracker data protected by HIPAA?
In most cases, no. HIPAA protects health information held by covered entities (healthcare providers, health plans, and their business associates). Consumer health apps that you download from the App Store are generally not covered entities and are therefore not bound by HIPAA's privacy and security rules. Your GLP-1 tracker app can likely do things with your data that your doctor or insurer cannot. This is why evaluating the app's own privacy practices is essential.
Can insurance companies see my GLP-1 tracker data?
Direct access to your app data by insurance companies is unlikely under normal circumstances. However, data breaches, data broker markets, and broad data sharing through analytics networks can create indirect channels through which health-related information may surface. Keeping working health entries out of an app-company database reduces that exposure, but it does not eliminate device, backup, export, purchase, or website-related risks.
What is the safest way to track GLP-1 injections?
A strong privacy approach is to use a tracker with no app account, no company health database, and no health-record uploads. OffGrid Dose meets those criteria while keeping its working database on-device; an Apple-managed device backup may still include app data depending on user settings. Other models can reduce risk through private platform storage, end-to-end encryption, limited analytics, and clear deletion controls.
Should I be worried about progress photos in health apps?
Yes, this deserves serious consideration. Progress photos in GLP-1 tracking apps are highly sensitive — they are identifiable body images linked to your medication records and weight data. If these photos are uploaded to cloud servers, they face all the same risks as any cloud-stored data: breaches, unauthorized access, and potential exposure. OffGrid Dose stores progress photos in its on-device database and does not upload them to a company-operated service. If you use a different app that syncs photos to the cloud, understand that you are trusting that company with some of the most sensitive images you can create.
Does on-device storage mean I will lose my data if my phone breaks?
It can. OffGrid Dose has no company-operated recovery service. Depending on your settings, an encrypted Apple device backup may include app data and may be available when you set up another iPhone, but a particular record is not guaranteed to be included or restored. Review your Apple backup settings before relying on a backup.
Key Takeaways
- GLP-1 health data includes injection records, medication dosages, weight history, side effects, and body photos — all uniquely sensitive information
- Most GLP-1 tracker apps store this data on cloud servers with account-based systems, exposing it to breach, legal, and data broker risks
- Consumer health apps are generally not covered by HIPAA, leaving your data with fewer protections than clinical records
- On-device working storage avoids creating an OffGrid Dose server-side health database while Apple-managed backups and other distinct services retain their own boundaries
- When evaluating a health app, check for account requirements, data storage location, embedded analytics SDKs, and offline capability
- OffGrid Dose documents an account-free model with local working health storage, no company-operated cloud sync, and no health-record uploads to measurement services
- The tradeoff of on-device storage is that OffGrid Dose provides no company-operated sync or recovery; Apple-managed device backup behavior depends on your settings
This article is for informational purposes only and does not constitute medical advice. Always consult your healthcare provider regarding your medication and treatment plan.
Related Articles
Track this with OffGrid Dose
Log every dose, rotate injection sites, and watch your weight trend in a private local working log.
Ozempic tracker →