Privacy
Handle keeps what you record about your GLP‑1 treatment so it can reflect it back to you and, when you choose, to your prescriber. It also uses service providers for sign-in, subscriptions and optional food-photo estimates. This page explains those uses.
What Handle stores
Your account: an email address or phone number, a display name if you give one, your timezone and weight unit, and how you signed up (email, Google, Apple or phone).
Your treatment record: the medication and dose you tell it you are on, your treatment status, each dose you log, your daily and weekly check‑in answers, weights, food, drinks and training you enter, the symptoms you choose to track, notes you write against a day, and the care details you enter — your prescriber’s name and number, review dates, and any targets they set.
Handle does not read your health data from your phone, a watch or any other service, and it does not use it to train anything.
Where it is kept
Records are held in a database run by Supabase on Amazon Web Services, in the United States. Sign‑in credentials are held by Supabase Auth; Handle does not store your password. The database is not reachable from the internet with the app’s own key — every read and write goes through Handle’s server, over an encrypted connection.
Who can see it
You can view your record when signed in. With Premium, you can choose to generate a consultation report and share its link. Anyone holding that link can open the report while the link and your Premium access remain active. The report contains summaries and an optional note you choose to include; your private daily notes are excluded. You can revoke a link at any time. Copies someone has already downloaded or printed cannot be recalled.
Handle does not display ads inside the treatment app or sell your treatment record. Service providers process information to run the features described here. Our own staff can reach the database to run and repair the service; that access is logged.
Newsletter
Handle’s GLP‑1 newsletter is sent through Kit, an email service provider. You join it when you sign up for a free guide on one of our pages, and new Handle accounts are added to it automatically. Kit receives your email address, and the first word of your display name if your account has one; nothing from your treatment record is sent.
Every email has an unsubscribe link, and deleting your Handle account also removes you from the list. Handle does not sell your email address.
Campaign measurement
On campaign pages under /lp/, Handle uses OpenAI’s advertising measurement and Google Analytics for Firebase to measure page visits, newsletter sign-ups, app-preview interactions and clicks to the App Store, including attribution of those actions to our ads. Measurement is on by default on these pages. You can turn it off with “Measurement preferences” at the bottom of any campaign page, and it stays off when your browser sends a Global Privacy Control or Do Not Track signal. Turning it off does not affect your access to Handle. Neither integration is installed on signed-in treatment screens or shared reports, and Handle does not send your treatment record, account identifiers or contact details with these events.
While measurement is on, the pixel sends browser and network information to OpenAI and uses first-party cookies to associate activity with an ad: __oppref lasts up to 30 days and __obref up to 365 days, subject to your browser settings. Events are marked to opt out of future user-level personalization. Google Analytics receives browser information, a campaign-page address, permitted advertising attribution parameters and, on the free food guide pages, a sign-up event that names the offer and never your email address. Its campaign cookies are limited to /lp/ and expire after 30 days. Google signals and ad personalization are disabled; we do not set a Google user ID or user properties. Turning measurement off disables future collection and removes campaign attribution cookies; it does not recall events already sent.
The free food guide pages ask for an email address, so they never load OpenAI’s pixel script, which can detect contact details on a page. They send each measured event through OpenAI’s image tag instead: the event name, a random event ID and, if you arrived from an OpenAI ad, that ad’s click reference, which Handle keeps in a first-party handle_campaign_oppref cookie for up to 30 days. Nothing else on the page is read or sent.
Reports you share
Doctor reports summarise your recorded information without sending it to an AI provider. Private daily notes are excluded. Anyone holding an active report link can read that fixed copy; you can revoke the link, but downloaded or printed copies cannot be recalled.
An earlier report-review feature used Google Gemini to select comparisons from health-related counts and dates. That feature was retired on 25 September 2026. It excluded names, contact details, account identifiers, report links, food labels, custom symptom names and notes. Previously generated annotations are no longer displayed; their original snapshots remain stored with the shared reports.
Optional food-photo estimates
If you choose to scan food with Premium, the selected photo is sent to Google Gemini to estimate its nutrients. Handle removes image metadata and resizes the photo before sending it. No account history or treatment record accompanies it. Handle does not retain the image; Google processes the photo under its own service terms. The photo does not stay only on your device.
Handle stores the scan attempt and estimate so you can review it and retry safely. An estimate becomes a food entry only when you review and save it. Cancelling the review creates no food entry; it does not delete the stored estimate.
Subscriptions
Apple processes App Store purchases. RevenueCat uses your Handle account identifier and purchase information to verify subscription access. Handle stores the verified access state and records of subscription checks. Your treatment record and food photos are not sent to RevenueCat by Handle’s server.
Deleting your account
From Account you can delete your account. Everything recorded under it is removed at once — your treatment record, your care details, and your sign‑in — and it cannot be restored. A note that the account existed and was deleted is kept, with no health data in it.
Deleting your Handle account does not cancel an App Store subscription or erase Apple’s or RevenueCat’s purchase records. Manage or cancel the subscription in your Apple account. Contact [email protected] about personal information held by our service providers.
What Handle does not do
- It does not diagnose, and it does not change your dose or tell you to.
- It does not contact your prescriber, your pharmacy or anyone else for you.
- It does not send your treatment record with a food photo or a subscription check.