How OffGrid Dose Keeps Your GLP-1 Data Private (Local Health-Log Storage)
OffGrid Dose has no account, company-operated cloud sync, or server-side health database. Depending on your Apple and device settings, an encrypted device backup may include app data.
OffGrid Dose is a private GLP-1 tracker that stores its working health log on your iPhone with no app account, company-operated cloud sync, server-side health database, or in-app analytics SDK. Your injection logs, weight history, doses, side effects, and progress photos live in a local database and are not sent to OffGrid Dose through a health-log sync service. Apple-managed backups, purchases, the marketing website, and user-chosen exports are separate data flows.
That is a different model from almost every other health app. Most trackers encrypt your data and then upload it to company-operated cloud infrastructure. OffGrid Dose takes the simpler, stronger path: the app does not transmit your health data to its own servers. This article explains what "on-device" actually means in plain language, why it is fundamentally more private than an app-company cloud database, and exactly how the OffGrid Dose privacy architecture works.
What "On-Device" Actually Means
"On-device" can sound like marketing, so the useful question is which data flow the term describes.
Every time you log a GLP-1 injection — the date, time, medication, dose, and injection site — OffGrid Dose writes that record into a local database stored on your iPhone using Apple's SwiftData framework. SwiftData is Apple's standard, recommended technology for saving app data directly on a device. The same applies to your weight entries, titration history, side-effect notes, and any photos you add.
Crucially, the app does not send working health-log entries to an OffGrid Dose server. There is no sign-up screen, login, name, email, or password for an app account. Purchases, entitlement checks, updates, external links, optional Apple services, and user-chosen exports are distinct network flows. You can learn more about the whole approach on the what is OffGrid Dose page.
Offline Health-Log Workflow
Because the working health log is local, OffGrid Dose can log a dose, display your weight-loss chart, record injection sites, and review history with Wi-Fi and cellular service off. App Store transactions, entitlement checks, updates, external links, Apple-managed services, and user-chosen exports are distinct and may require connectivity.
Your Data Moves Only Where You Move It
On-device does not mean Apple device backup is impossible. Apple explains that iCloud Backup includes app data for downloaded apps, with the exact contents depending on the app and your settings. An encrypted device backup may therefore include OffGrid Dose app data, but OffGrid Dose does not control or guarantee that a particular record will be included or restored. The distinction matters: an Apple-managed device backup is not a copy in an OffGrid Dose database that the company can read, analyze, or monetize.
Why On-Device Beats Encryption-in-the-Cloud
"We encrypt your data" is the most common privacy claim in health apps. It sounds reassuring, and encryption is genuinely important. But encryption-in-the-cloud and on-device storage solve different problems. Local working storage removes an app-company health database from the threat model without removing every device, platform, purchase, export, or website risk.
When an app encrypts your data and then uploads it, a copy of your sensitive information still exists on someone else's servers. Encryption reduces the consequences of certain attacks, but the data is still there to be targeted. In most consumer-cloud designs, the company holds the keys, which means the company — and anyone who can compel, hack, or acquire the company — can potentially read your records.
On-device working storage takes a different angle: OffGrid Dose does not create a company-operated copy of the working health log. That reduces exposure to a breach of an OffGrid Dose health database, while device security, Apple-managed backup, purchase processing, and user-directed exports remain separate considerations.
| Question | Encryption-in-the-cloud | OffGrid Dose (on-device) |
|---|---|---|
| Is there a copy of my working health log in an app-company server database? | Yes | No OffGrid Dose server-side health database |
| Do I need an account, email, or password? | Almost always | No |
| Can a server breach expose my records? | Possible | No OffGrid Dose server-side health database |
| Can the company analyze or sell my working health log? | Depends on policy | OffGrid Dose does not receive the working health log through a sync service |
| Who holds the decryption keys? | Usually the company | Not applicable |
| Can core health-log functions work without internet? | Depends on the service | Yes; purchases, restores, entitlements, updates, external links, and optional Apple services may need a network |
This is also why "we don't sell your data" promises are weaker than they sound. A privacy policy is a statement of current intent that can change after an acquisition, a bankruptcy, or a new leadership decision. Architecture is harder to reverse. If a company does not receive the working health log through its service, it has no company-side copy of those entries to reclassify later. For a deeper comparison, see our guide on why your GLP-1 health data deserves better privacy.
Why This Matters Specifically for GLP-1 Data
GLP-1 tracking data is unusually revealing. It is not step counts or water intake — it is a longitudinal medical record.
GLP-1 receptor agonists such as semaglutide (Ozempic, Wegovy) and tirzepatide (Mounjaro, Zepbound) are among the most prescribed medications in the world (FDA prescribing information for Ozempic). When you track one of these, you generate a continuous stream of sensitive signals: that you take a specific prescription drug, your dose and titration schedule, your weight trajectory over many months, your side effects, and possibly body photos.
In the United States, most consumer health apps are not covered by HIPAA, which generally applies to healthcare providers, plans, and their business associates (U.S. Department of Health and Human Services). That means a typical cloud-based tracker may have different obligations from your clinician. Keeping working health entries out of an app-company database reduces one category of company-side exposure; it does not remove every device, backup, purchase, export, or website consideration.
Built for Real GLP-1 Workflows
Privacy does not mean a stripped-down app. OffGrid Dose supports Ozempic, Wegovy, Mounjaro, Zepbound, compounded semaglutide and tirzepatide, and custom medications. It handles dose-change markers, side-effect logging, and structured injection-site history locally. You can see the full capability list on the features page.
About the Website Analytics (Honest Clarification)
To be transparent: the marketing website at offgriddose.com uses pseudonymous website analytics. Those services can process first-party identifiers plus usage, browser, device, session, interaction, and diagnostic data; Microsoft Clarity can also process DOM playback data for session replays and aggregate heatmaps. The current services and their official policies are listed in the privacy policy.
The iOS app is different. It contains no in-app behavioral-analytics SDK and does not send the working health log to an OffGrid Dose database. Browsing the website and using the app are separate data flows. Apple-managed backups, purchases, optional Apple services, and user-chosen exports also have their own boundaries. If a term in this article is unfamiliar, the glossary defines on-device storage, SwiftData, HIPAA, and related concepts in plain language.
Frequently Asked Questions
Does OffGrid Dose receive my working health log?
No. The iOS app stores its working data on-device and has no account, company-operated cloud sync, server-side health database, or analytics inside the app. OffGrid Dose does not receive your injection logs, weight, doses, side effects, or photos.
What happens to my data if I lose my phone?
OffGrid Dose has no separate account or server-side recovery service. Depending on your Apple and device settings, an encrypted device backup may include app data and may be available when setting up another iPhone. OffGrid Dose cannot guarantee that any particular record will be included or restored.
How does on-device storage change company-side exposure?
Encryption reduces certain risks, but a cloud app still keeps a copy of data in its service. OffGrid Dose does not operate a server-side database for working health-log entries, so that company database is absent from the threat model. Device access, Apple-managed backups, purchases, website analytics, and user-chosen exports remain separate considerations.
Does the app work without internet?
The working-health features — logging doses, viewing charts, recording injection sites, and reviewing history — are available without company cloud sync. Connectivity may still be needed for App Store transactions, entitlement checks, updates, external links, or Apple-managed services.
Which medications and devices are supported?
OffGrid Dose supports Ozempic, Wegovy, Mounjaro, Zepbound, compounded semaglutide and tirzepatide, and custom meds. It requires iOS 18.0 or later and is iPhone only. Pricing is 4.99 dollars per week with a 3-day free trial, or 39.99 dollars per year with a 1-month free trial.
This article is for informational and privacy-education purposes only and does not constitute medical advice. Dosing, side effects, and treatment decisions should always be discussed with and verified by your prescriber.
Related Articles
Track this with OffGrid Dose
Log every dose, rotate injection sites, and watch your weight trend in a private local working log.
GLP-1 tracker →