Last updated: July 11, 2026
GLP Companion is a privacy-first tracker for GLP-1 injections, medication reminders, weight, side effects, meal estimates, health-record explanations, companion chat, and doctor-ready summaries.
Sign in with Apple is optional. You can choose Continue without Apple for local guest access and add Sign in with Apple later from Settings. The Apple sign-in identity, when used, stays in the device Keychain and is not sent to our backend; Ehi does not retain the Apple authorization code, access token, or refresh token.
The data controller for backend privacy requests is Gracious Ikhine, Tisina 3g, 9251 Tisina, Slovenia (EU). Privacy and data-rights contact: graciousvictorious@gmail.com.
Your logs are stored on your device. If you connect Apple Health, the app requests body-weight access only and does not send Apple Health data to our backend.
AI features run only when you choose them and the exact current consent version for that purpose is present. The four separate purposes are: Health Result Explainer; medication-label refinement; meal photo estimate; and GLP Coach plus weekly review. Consent for one purpose never enables another. Health-record and medication-label routes send only text you reviewed and confirmed, OCR confidence/edit state, language/region, a pseudonymous app-install identifier, and App Attest verification. The meal route sends the selected compressed meal photo, optional hint, and limited profile/goal/target/recent-side-effect context. Companion sends your message, up to 12 recent turns, minimized confirmed context/on-device memory when personalization is enabled (which can include optional mood, energy, and strength-session entries), or a compact weekly digest. AI output is educational and reflective, not diagnosis, treatment, prescription, or dosing advice.
Requests are relayed through Vercel AI Gateway with zero-data-retention requested and a route-specific provider allowlist. Health records use MiniMax M2.7 through Together AI or Fireworks, with OpenAI GPT-5 mini through Azure as retry. Medication refinement and GLP Coach use DeepSeek V4 Flash through DeepInfra or Fireworks; DeepSeek V4 Pro retry can use Fireworks, Baseten, Together AI, or DeepInfra. Meal scan uses Alibaba Qwen3-VL Instruct through DeepInfra. The backend is designed not to store prompts, selected photos, food names, AI responses, full health logs, or companion memory for public launch. It may keep pseudonymous operational metadata such as route, model/provider, token counts, cost, request status, and rate-limit/spend state. Companion operation can additionally retain agent session/risk/action metadata, SHA-256 hashes of user/assistant messages (not their text), queued-notice payload/delivery status, and any feedback rating/reason submitted. This is used for app functionality, continuity, abuse prevention, billing controls, and reliability—not advertising or tracking.
Health-record photos, medication-label photos, and unconfirmed OCR are read on device and are not uploaded. Medication barcodes are read on device without a third-party lookup; the raw code is not uploaded or saved and never enters an AI request. Meal photos are uploaded only for the meal-scan feature after its separate consent. Progress photos are saved on device; if you export a backup, the export can include those progress photos so the backup is complete.
Apple processes subscription payments. To unlock, restore, and protect paid features, the app sends Apple StoreKit entitlement evidence to our backend, such as the signed transaction payload, transaction identifiers, product identifier, expiration or renewal state, environment, Apple app account token where available, a random server-issued App-Attest install identity, and Apple App Attest assertions. The backend uses this to verify access, prevent abuse, apply creator attribution if you entered a code, operate subscription support, rate-limit AI, and protect monthly spend. Apple remains the payment processor: we do not receive your card number, bank details, Apple Account password, or Apple payment credentials.
If you enter a creator code, the backend may receive the creator code, App Store transaction identifier, verified app-account/install identity, and device-attestation assertion so the creator can be credited. A temporarily undelivered hint is kept in a ThisDeviceOnly Keychain outbox and is synchronously suppressed and removed when you request deletion. These purchase, referral, and attestation records are not advertising identifiers and are not used for cross-app tracking.
Local health logs remain on your device unless you delete them or export them yourself. Backend operational records are kept only as long as needed for subscription access, abuse prevention, support, legal, accounting, and reliability purposes. Companion memory is stored on device for public launch. You can export local data, delete records, clear companion memory, and delete app data from Settings.
When you choose Delete account & all data (or Delete all data as a guest), the app first durably snapshots Apple-verified purchase identities, erases local records, and queues one App-Attest-authenticated backend erasure workflow. Each request atomically tombstones the current server install identity, any server-authenticated former install identities, and the included Apple-verified historical app-account tokens before purging agent, entitlement, and App Attest key rows. Creator codes and direct transaction linkage are scrubbed; a keyed transaction-accounting pseudonym, token/status/credit/refund state, and token lifecycle timestamps are retained only to prevent duplicate credit and apply an exact later refund or reversal. Keychain retry material (the pending marker, verified transaction candidates, and server-signed install-deletion capabilities) is ThisDeviceOnly, contains no health content, and is removed after the full backend erasure confirms. A later Buy or Restore first obtains a one-time, key-bound transaction intent; only a current direct-purchase JWS presented with an intent issued after the latest erasure can reactivate service. Offline, interrupted, or partially batched erasure remains pending and retries on launch or foreground.
If GDPR or similar privacy law applies, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data processed by the developer. Because the app is local-first, most health data can be controlled directly on your device. For backend privacy requests, use the privacy and data-rights contact listed above.
You can export local data, delete records, clear companion memory, and withdraw any one AI purpose immediately in Settings → Privacy & AI consent. Withdrawal blocks future requests for that purpose without changing the other purposes; it does not delete already-saved local results. After a signed-in deletion, Ehi uses Apple's documented manual fallback because it retained no revocable Apple token: the app keeps a reminder and Apple Account action for Apple Account → Sign-In & Security → Sign in with Apple → Ehi (which may appear as “Ehi: GLP Companion”) → Stop Using Apple ID. Ehi observes Apple's credential-revoked notification, clears any remaining local identity, and returns to signed-out state. Uninstalling removes the app's SwiftData records, caches, exports, and UI data; iOS Keychain retry markers or pseudonymous deletion authority may survive reinstall only long enough to finish an already-requested erasure or require an explicit Restore. They contain no health content and are cleared when their purpose completes.
Email graciousvictorious@gmail.com or call +386 40 841 784.