What a medication log actually reveals
Individually these are unremarkable data points. Together they are not.
- That you are taking a prescription medication, which one, and at what dose.
- The dates you started, increased, paused and stopped.
- Your weight over time, and often your body composition and measurements.
- How often you are adherent, and when you are not.
- Symptoms, appetite, mood and sleep, dated to the day.
- Enough of a pattern to infer things you never wrote down.
That is a profile that insurers, employers, advertisers and data brokers would all find valuable in different ways. It is not a reason for alarm, and it is a reason to be deliberate.
A policy is a weaker promise than an architecture
Most apps answer this concern with a privacy policy. Policies are worth reading and they are worth very little as a guarantee, because they describe an intention that can change.
A policy can be rewritten at the next funding round. A company can be acquired, and the data goes with it. A company can close, and its assets are sold. A perfectly honest company can be breached. And a company holding data can be compelled to produce it regardless of what it promised you.
None of that requires anyone to act in bad faith. It only requires the data to exist somewhere other than your device.
What “on-device” actually means
Penwise takes the second position, and it is worth being precise about what that involves rather than waving at it.
No account
No email address, no password, no sign-up screen. The app works the moment you install it. There is no identity to attach a record to, because there is no identity.
No server for health data
Every dose, weight, symptom and note is written to the app's private storage on your device, protected by the operating system's own encryption. It is never transmitted to us, because there is nowhere for it to go.
No tracking SDKs
No ad networks, no attribution frameworks, no third-party analytics reading your health data. Crash reporting is opt-in, off by default, capped, kept locally for you to read, and strips file paths, email addresses and web addresses first.
Your export, your keys
The only copy that leaves the phone is a backup you export yourself, encrypted on the device before it is written, with a passphrase only you hold. We hold no keys.
There are also the local protections that matter when the risk is somebody picking up your phone: the app can lock behind Face ID, Touch ID, a fingerprint or the device passcode; a privacy shield covers the screen before the operating system takes its app-switcher snapshot, so your numbers never appear in the task switcher; and on Android screenshots and screen recording are blocked while locked.
The honest cost
This design is not free, and anyone who tells you otherwise is selling something. Removing the server removes real conveniences.
- No cloud sync. Your history does not appear on a second device on its own. You move it with an exported backup.
- No web app. There is nothing to log into from a laptop, because there is nothing to log into.
- No password reset, and no recovery. If you lose your backup passphrase, the backup is unreadable. We cannot help, because we hold no keys. That is not a support policy we could relax; it is arithmetic.
- Losing the phone without a backup means losing the data. The same property that stops us from having it stops us from restoring it.
- Support is harder. We cannot look at your data to diagnose a problem, which occasionally makes a support conversation slower.
Those are genuine trade-offs and for some people they are the wrong ones. If cross-device sync is essential to how you work, a cloud tracker is the right answer and it is better to know that now.
What to check in any app, including ours
- Does it require an account? If yes, the data is on a server by definition.
- Read the app store data-safety declaration. Both stores require developers to declare what is collected and shared, and it is often more revealing than the marketing page.
- Look for the word “anonymised”. Aggregate health data is notoriously easy to re-identify, and the word does a lot of quiet work in privacy policies.
- Ask what happens on acquisition or closure. The answer is almost always that the data transfers as an asset.
- Check whether export is free. An app that charges you for your own history has told you what it thinks the relationship is.
- Check the retention policy. How long is your data kept after you delete the account, and what does “delete” actually delete?
These are the same questions as in how to choose a GLP-1 tracker, sharpened for this one issue.
Why this is not a marketing position
It would be commercially easier to have a server. Sync sells, a web dashboard demos well, and usage analytics make product decisions much simpler than guessing does. We build without them because the alternative is asking people to trust a promise, and this is a category where the people most in need of a good tracker are often the ones least willing to hand a medication history to a startup.
The result is an app that cannot betray you in that particular way, because the capability does not exist. Everything else in Penwise – the level curves, the pen handling, the insights, the watch apps – runs on the device, on your own data, without any of it going anywhere.
A tracker that never receives your data
No account, no sign-in, no server. Free core tracker with full export, forever.
Common questions
Is there a GLP-1 tracker that does not need an account?
Where does Penwise store my health data?
Can Penwise recover my data if I lose my phone or my passphrase?
Does Penwise use analytics or advertising SDKs?
Is the on-device database encrypted?
What about Apple Health and Health Connect?
Penwise is a tracking and education tool, not a medical device. Nothing on this page is medical advice, a diagnosis or a recommendation to start, stop or change a dose. Dosing decisions belong to you and your clinician. Ozempic, Wegovy, Rybelsus, Saxenda and Victoza are trademarks of Novo Nordisk; Mounjaro, Zepbound and Trulicity are trademarks of Eli Lilly. Penwise is not affiliated with, endorsed by or connected to either company.