Privacy Policy
Logbook keeps your health data on your device. There is no account to create, no server to sync to, and nothing to opt out of.
- We collect nothing. The app has no backend. There is no server that receives your data, because there is no server.
- No accounts. You never register, sign in, or give an email address to use the app.
- No analytics, no tracking, no ads. No analytics or crash-reporting SDK is built into the app, and no advertising or tracking identifier is read or created.
- Your injections, weights, measurements, food, notes and photos never leave your device unless you personally export them.
- Two optional features send data out — a barcode number and a food search term. Both are off until you turn them on, and each is a separate switch.
Who this policy is from
Logbook (listed on the App Store as Logbook: GLP-1 Dose Tracker) is developed and published by an independent developer based in New Jersey, USA. This policy covers the Logbook mobile app for iOS and Android, and this website.
Privacy questions: privacy@doselogbook.com
What the app stores, and where
Everything you track is written to a database file inside the app's private storage on your phone:
- Injections, doses, medications, injection sites and supply counts
- Weights, body measurements and goals
- Food, water and fiber entries, saved meals and custom foods
- Activity you enter by hand
- Notes and side effects you record
- Progress photos and meal photos
- Your settings and reminder schedules
This storage is private to the app. Other apps on your phone cannot read it. Neither can the developer — there is no mechanism, technical or otherwise, by which any of it reaches us.
Photos
Progress photos and meal photos are re-encoded into the app's private storage when you add them. They are never added to your device photo library automatically, and they are never uploaded.
Location and camera metadata is removed. When a photo is imported, its EXIF metadata block — which typically includes GPS coordinates and camera details — is discarded before the file is written. Image orientation is applied to the pixels first, so the photo still displays correctly. This matters most for meal photos, which are often taken in restaurants or in someone's home. Nothing in a photo is sent anywhere to be recognised or identified; there is no image-recognition step in the app.
Reminders
Reminder notifications appear on your lock screen, where anyone holding your phone can see them. Their wording therefore never includes medication names, doses, weights or targets. This is enforced by an automated test, not only by convention.
Health Connect and Apple Health
If you choose to connect it, Logbook can read the following from Health Connect (Android) or HealthKit (iOS):
- Steps, active energy and workouts
- Body weight
- Dietary calories, protein, fiber and water — and only if you point a specific metric at it
How that data is handled:
- Read-only. The app only ever requests
READaccess. It never requests permission to write to your health record, and never writes to it. - Never stored. Health data is read live when a screen needs to display it, and is discarded when you leave. It is not copied into the app's database.
- Never transmitted. It is not sent anywhere, by any route, for any purpose.
- Never logged.
- Never used for advertising, and never shared with or sold to any third party. Health data is not used for any purpose beyond displaying it to you inside the app.
- Optional and revocable. Connecting is a deliberate action you take. You can revoke it at any time in your device's Health Connect or Apple Health settings, without going through Logbook. The app cannot detect or resist that revocation — it simply falls back to the numbers you enter by hand.
The app is fully functional without ever connecting to either service.
The two features that send anything off your device
Both are off by default. They are separate switches, because what they send differs in kind, and agreeing to one is not agreeing to the other. Both use Open Food Facts, a free and open food database.
1. Barcode lookup — Settings → Food
- What is sent: a barcode number, over HTTPS, to
world.openfoodfacts.org, with a fixed app identifier as the user agent. That is the whole request. No health values, no account, no device or installation identifier, nothing about your weight, doses, photos or targets. - When: only when you scan a product the app's bundled offline database does not recognise. Most scans resolve on-device and send nothing at all. Before the request is made, the app tells you the exact barcode it is about to send.
- What is kept: nothing. The result fills in a number and is then discarded. There is deliberately no scan history and no cache, because that would amount to a record of what you eat.
- With it off: no request is ever made. Scanning still works offline, and an unrecognised code falls through to manual entry.
2. Live food search — Settings → Food
- What is sent: the words you type into the food search
box, over HTTPS, to
world.openfoodfacts.org. Only searches of three or more characters, and only once you stop typing. Nothing else accompanies the query. - What is kept: nothing — no search history, no result cache. Results are discarded when you close the search. Saving a food to your own list is a separate, explicit action that writes only to your device.
- With it off: the on-device food database works exactly as before. Online results are strictly additional, and any failure simply means that section is absent.
Open Food Facts is an independent service with its own privacy practices, which govern any request your device makes to it. Its data is crowd-sourced and carries no accuracy warranty. Attribution appears in the app under Settings → About.
Purchases
Logbook offers a one-time optional upgrade. Purchases are handled entirely by Apple's App Store or Google Play — the app never sees your payment details, and no server of ours is involved, because there isn't one. What crosses that boundary is a product identifier and the store's own transaction data.
The app deliberately attaches no user identifier to a purchase, so no stable handle for you is ever created. Apple and Google collect their own data through their billing systems under their own privacy policies; that is outside our control, and is disclosed here for completeness. What they see is a purchase, not the contents of a health app.
Backups and export
You can export your data or create a backup archive. When you do, the app builds the file and hands it to your system share sheet — you choose where it goes, whether that is Files, iCloud Drive, Google Drive, email, or somewhere else. Restoring reads a file you pick through the system file picker.
The app never integrates with a cloud storage provider, and never uploads a backup on its own initiative. Once you export data, it lives in a location you chose, governed by whatever service you put it in.
On Android, the operating system's automatic backup and device-to-device transfer are switched off for this app, so your database, preferences and photos are not uploaded by the OS on your behalf.
What the app does not have
- No user accounts, logins or profiles held anywhere but your phone
- No analytics, telemetry, crash reporting or usage measurement
- No advertising, ad identifiers, or third-party ad or tracking SDKs
- No microphone access — the permission is explicitly removed from the app, so voice input cannot ship audio to a speech service
- No sale or sharing of personal information, in any sense used by any privacy law. There is nothing held to sell or share.
Deleting your data
Individual entries can be deleted inside the app at any time.
To remove everything, uninstall Logbook. Because all of your data lives in the app's private storage on your device, uninstalling deletes the database and every photo along with it. This is permanent, and cannot be undone by us — we hold no copy to restore from. If you want to keep your history, export it before uninstalling.
Data you exported yourself, and any backup you saved into another service, sits outside the app and has to be deleted wherever you put it.
Children
Logbook is not directed to children. It is intended for adults tracking their own prescribed treatment, and it is not designed or marketed for anyone under 13 — or under 16, where that is the applicable threshold. No information is knowingly collected from children and, as above, none is collected from anyone.
Your rights
Privacy laws such as the GDPR and the CCPA give you rights to access, correct, export and delete personal information a company holds about you, and to know whether it is sold or shared.
Logbook holds none. There is no database of users, so there is no record to retrieve, correct, delete, or refuse to sell. Your data is already entirely in your possession: you can view it in the app, export it in readable formats (CSV, JSON and PDF), and delete it by removing entries or uninstalling. If you have a question about any of this, write to privacy@doselogbook.com.
Security
Your data sits in app-private storage, protected by your device's own security model and disk encryption — which is why a device passcode and an up-to-date OS are the most effective things you can do to protect it.
The honest framing: the usual risk for a health app is a breach of the company's servers holding thousands of people's records. That risk does not exist here, because those servers do not exist. What remains is the security of your own device, and physical access to an unlocked phone.
Legal status: not a medical device, and not HIPAA
Logbook is a personal wellness-tracking tool. It does not provide medical advice, diagnosis, or dosing recommendations, and it is not a medical device. Always follow the guidance of your healthcare provider.
HIPAA governs healthcare providers, health plans, and their business associates. Logbook is a consumer app with no such relationship, so HIPAA does not apply to it, and no claim of HIPAA compliance is made here or anywhere else. That is a statement about which law applies — not about how carefully your data is handled.
Changes to this policy
If this policy changes, the updated version will be posted here with a new "last updated" date. If a change ever means the app starts doing something materially different with your data — a new outbound connection, for example — that will be disclosed in the app as well, not only here, and anything new that sends data off your device will be off until you turn it on.
Contact
Privacy questions: privacy@doselogbook.com
App support: support@doselogbook.com