---
title: "Who Can Actually See Your GLP-1 Data | Peptyn"
description: "What HIPAA does not cover, which law actually applies to health apps, and how to check an App Store privacy label yourself."
canonical: "https://peptyn.orlyn.ai/articles/glp1-app-data-privacy"
last-updated: "2026-08-16"
---

# Who Can Actually See Your GLP-1 Data

*What HIPAA does not cover, which law actually applies to health apps, and how to check an App Store privacy label yourself.*

Educational · Not medical advice · 18+

You start a protocol, you download something to keep track of it, and somewhere in the sign-up flow you read the phrase "we may share your data with our partners." That is the moment the question arrives: who now knows what is in my fridge?

Published 15 August 2026 · 10 min read · 9 sources

The answer is knowable. Not by trusting a marketing page, but by reading two documents that every iOS app is required to expose, and by checking one screen on your own phone that the developer does not control. This is how to do that.

Start with the thing most people get wrong.

## HIPAA does not cover the app you downloaded

HIPAA protects health information held by health plans, most health care providers, and health care clearinghouses. Those three groups are what the law calls covered entities. It also reaches the companies that handle health data on their behalf, called business associates.[1]

It does not reach much further. The FTC's guidance for health app developers puts it plainly: the HIPAA Rules "likely wouldn't apply to consumer health information maintained in an app that isn't offered by a HIPAA covered entity or its business associate, even if the health information originated from a covered entity or business associate."[1]

Read that last clause again, because it is the part that surprises people. Your prescriber is HIPAA-covered. The prescription they wrote is HIPAA-covered inside their systems. The moment you retype that information into an app you found yourself, it leaves the protected bucket. The data did not change. The holder did.

So an app that describes itself as HIPAA compliant is either a covered entity's product, or is using the phrase loosely. Loose use of it is not harmless. When the FTC took action against GoodRx, one of the specific allegations was that the company "displayed a seal at the bottom of its telehealth services homepage falsely suggesting to consumers that it complied with" HIPAA.[3]

## What actually applies instead

Two things, and neither is optional for the developer.

**Section 5 of the FTC Act** prohibits unfair or deceptive acts or practices. The FTC's own example is close to the bone: "if you develop an app and share consumers' health information with third parties after telling or implying to consumers that their information will be kept private, you could be violating the FTC Act."[1] The trigger is the gap between the promise and the practice. An app that quietly sells your data while promising nothing has a smaller problem than an app that promises privacy and then does the same thing.

**The FTC's Health Breach Notification Rule** requires covered entities to notify consumers, the FTC, and sometimes the media after certain breaches of personal health record information.[2] This rule is commonly described as a narrow edge case. It is not. The FTC's position is that the Rule "applies to most health apps that aren't covered by HIPAA because most developers of health apps are acting as 'health care providers' by furnishing health care services or supplies, in this case, apps, to consumers."[1]

The FTC also treats the definition of breach more broadly than you might expect. Its guidance describes a breach as "any incidents of unauthorized access, including sharing of identifying health information, without consumers' authorization."[1] Sharing without permission counts. A hacker is not required.

So the honest summary is: your GLP-1 log is not medical-record data in the legal sense, but the app holding it is not in a lawless zone either. What it is missing is anyone checking in advance.

## What enforcement actually looks like

In February 2023 the FTC brought its first enforcement action under the Health Breach Notification Rule, against GoodRx.[3] The details are worth knowing because they describe the exact failure mode people are worried about.

According to the FTC's complaint, GoodRx had told users since at least 2017 that it would never share personal health information with advertisers, and then shared it with Facebook, Google, Criteo, Branch, and Twilio. In August 2019 it compiled lists of users who had purchased particular medications, including those used to treat heart disease and blood pressure, and uploaded their email addresses, phone numbers, and mobile advertising IDs to Facebook so those profiles could be identified. It then used that information to target those same users with health-related ads.[3]

The proposed order carried a $1.5 million civil penalty and a permanent prohibition on sharing user health information with third parties for advertising.[3]

Note the shape of this. The violation ran for years. It was surfaced by an outside watchdog in February 2020. The enforcement action landed in 2023. The FTC does not inspect apps before they ship and does not certify them. It arrives afterward, sometimes long afterward. Nothing in that process helps you on the day you are deciding what to install.

Which means the check has to be yours.

## How to read an App Store privacy label

Every app on the App Store has to answer Apple's privacy questions before it can be submitted or updated.[4] Those answers become the App Privacy section on the product page, below the screenshots and description.

The answers are sorted into buckets, and the bucket a data type lands in matters more than the data type itself:

- **Data Used to Track You.** Linked with third-party data for targeted advertising or advertising measurement, or shared with a data broker.
- **Data Linked to You.** Collected and tied to your identity or account.
- **Data Not Linked to You.** Collected, but not connected to your identity.
- **Data Not Collected.** The developer declared nothing in that category.

Two Apple definitions do the real work here, and neither means what the everyday word means.

"Collect," in Apple's phrasing, "refers to transmitting data off the device in a way that allows you and/or your third-party partners to access it for a period longer than what is necessary to service the transmitted request in real time."[4] Data that never leaves your phone is not collected. This is why an app can hold a year of intimate logs and still show very little on its label. The label is not an inventory of what the app knows. It is an inventory of what the app sends.

"Tracking," per Apple, "occurs when data collected about you or your device is linked with third-party data for targeted advertising or advertising measurement purposes," or when it "is shared with a data broker." Apple explicitly excludes the case "when the data is linked solely on your device and is not sent off the device in a way that can identify you or your device."[5]

So a label reading Health, Linked to You, and nothing under tracking describes an app that has your health data on its servers, attached to your account, and is not currently selling it. A label with an Advertising ID or Precise Location under Data Used to Track You describes an app whose business model includes you. Neither is illegal. They are different deals, and you get to pick.

## The label is self-reported, so verify it

Apple prints the caveat on every product page: "This information has not been verified by Apple." Its longer explainer adds that the section covers data collected "during normal app usage, but it may not describe all of the developer's practices," and lists conditions under which a developer is not required to declare a data type at all.[6]

That is a real limit, and it is where most privacy articles stop. There is one more step available to you.

Turn on App Privacy Report, in Settings, Privacy and Security, App Privacy Report. On iOS 15.2 and later it records how often each app touches your location, camera, microphone, and other permissions, and it logs each app's network activity, including the web domains that app contacts.[7] The report is generated by iOS, stored encrypted on your device, and only starts collecting after you switch it on, so give it a few days of normal use.

Then open it and read the domain list for your tracking app. You are not auditing the code. You are asking a much simpler question: does the list of companies this app talks to look like the list its label and policy describe? An app claiming to keep everything local that is contacting an ad network has told you something its label did not.

## A checkable method

Before you commit to a GLP-1 or peptide tracking app:

1. Open the App Store listing and scroll to App Privacy.
2. Look at what sits under **Data Used to Track You**. Empty is the answer you want. Anything here means your data is being linked with outside data for advertising or handed to a data broker.[5]
3. Look at what sits under **Data Linked to You**. This is the app's server holding something tied to your identity. Health here is not automatically bad, but it means a breach involves you by name.
4. Do not treat **Data Not Collected** as a red flag. Under Apple's definition, an app that keeps your logs on your device has nothing to declare.[4] Local storage is the strongest posture available, not a missing feature.
5. Open the privacy policy linked from the same page. Find the section naming the specific vendors, not the generic phrase "trusted partners." A policy that will not name its analytics provider has answered you.
6. Check what happens to features that must leave the device, such as an AI assistant or a photo scanner. Ask whether the content is stored, and for how long, and where.
7. After a week of use, open App Privacy Report and compare the domains against what you just read.[7]

Step 5 is the one that separates apps. Any app can write "we value your privacy." Far fewer will name the vendor, state the lawful basis, and give a retention period.

## What Peptyn's own label says

Applying the method to this app, since it would be a strange article otherwise. With one deliberate refusal: this section is not going to transcribe our own privacy label for you.

That is not evasion, it is the whole argument. An article telling you that self-reported labels need checking has no business asking you to accept its own label secondhand, and a transcription here would be stale the next time the questionnaire is republished. Open the listing and read the App Privacy section yourself.[8] It takes about twenty seconds, and if what you find there disagrees with anything below, trust the listing and not this page.

What this page can tell you is where the data sits, because that is a design fact rather than a label claim. Protocols, dose logs, injection sites, vial inventory, weight entries, and goals are written to a database on your iPhone. There is no account system and no server holding them.[9] Under Apple's definition of collect, data that never leaves the device is not collected, so on-device records are not something a label has a category for.[4] They are included in your normal iCloud or device backups if you have those switched on, which is Apple's system rather than the app's.[9]

That is also the point in the method where an honest reading of any app's label gets counterintuitive. A short label is not evidence of a small app. It is evidence of an app that sends little, and it tells you nothing at all about how much the app knows.

Two features do leave the device, and the policy names them. When you ask the assistant a question or scan a vial label, that text or photo goes to a stateless endpoint and on to Microsoft Azure AI in an EU region, purely to generate the answer. Peptyn does not store it and it is not used to train a model. Microsoft may hold a transient copy for up to 30 days for platform abuse monitoring under its own terms.[9] That last sentence is the kind of detail this article has been arguing you should go looking for, so it belongs here rather than in a footnote.

The named vendors are the ones behind the label: PostHog for anonymous product analytics, EU-hosted, with an off switch in Settings that stops collection immediately; RevenueCat for subscription status tied to a random identifier; Sentry for crash reports, scrubbed of health terms; and AppsFlyer receiving Apple's aggregate SKAdNetwork numbers plus install and purchase events with amount and currency, with no advertising identifier and no tracking prompt.[9] None of them receive health data.

Check it rather than take it. The label and the policy are both one tap from the listing, and App Privacy Report will show you the domains.

## If a label looks wrong

If an app's privacy label and its privacy policy disagree, that discrepancy is the reportable thing. You can file a consumer complaint with the FTC at reportfraud.ftc.gov. Under the Health Breach Notification Rule, an app that shares identifying health information without your authorization and does not tell you may be in violation regardless of what its label claims.[1][2]

That process is slow and it is not really for your benefit today. Today, the useful move is smaller: read the label, read the policy, watch the domains, and pick accordingly. Those three take about ten minutes, and they are the only pre-purchase inspection anyone is going to do for you.

## References

1. Mobile Health Apps Interactive Tool. Federal Trade Commission, in conjunction with HHS OCR, ASTP/ONC, and FDA. <https://www.ftc.gov/business-guidance/resources/mobile-health-apps-interactive-tool>
2. Health Breach Notification Rule. Federal Trade Commission. <https://www.ftc.gov/legal-library/browse/rules/health-breach-notification-rule>
3. FTC Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising. Federal Trade Commission, February 1, 2023. <https://www.ftc.gov/news-events/news/press-releases/2023/02/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising>
4. App privacy details on the App Store. Apple Developer. <https://developer.apple.com/app-store/app-privacy-details/>
5. Privacy Definitions and Examples. App Store. <https://apps.apple.com/us/iphone/story/id1539235847>
6. Learn More About App Privacy. App Store. <https://apps.apple.com/us/iphone/story/id1538632801>
7. About App Privacy Report. Apple Support. <https://support.apple.com/en-us/102188>
8. Peptyn on the App Store, App Privacy section. <https://apps.apple.com/us/app/id6787705045>
9. Peptyn Privacy Policy. <https://peptyn.orlyn.ai/legal/privacy>

## Keep reading

- [The GLP-1 tracking spreadsheet: eight fields that matter](https://peptyn.orlyn.ai/articles/glp1-tracker-spreadsheet)
  The eight columns worth keeping, what each one answers months later, and the three moments a spreadsheet stops being the right tool.
- [What to bring to a GLP-1 follow-up](https://peptyn.orlyn.ai/articles/glp1-follow-up-visit-packet)
  How to turn your own records into a one-page packet, and which questions are worth a prescriber's time.
- [The glossary that will not do your math](https://peptyn.orlyn.ai/articles/peptide-glossary)
  Plain definitions from lyophilized to 503A, with sources. It defines every term and stops where the arithmetic starts.

This article is educational. It does not recommend doses, schedules, or products, and it is not medical advice. Every factual claim above is linked to its source. Questions about your own protocol belong with the prescriber who wrote it.

---

Source: <https://peptyn.orlyn.ai/articles/glp1-app-data-privacy>
