Skip to content
Penwise

Why a GLP-1 tracker should not have a server

Think about what is in a GLP-1 log after a year. A prescription drug, dated, with dose changes. Your weight, weekly. Your body composition. Symptoms, moods, cravings, sleep. It is a medical record you assembled yourself, and it is more revealing than most of what is actually in your medical file. The question of where it is stored deserves more thought than it usually gets.

Updated 23 August 2026 · Written by the Penwise team

What a medication log actually reveals

Individually these are unremarkable data points. Together they are not.

That is a profile that insurers, employers, advertisers and data brokers would all find valuable in different ways. It is not a reason for alarm, and it is a reason to be deliberate.

A policy is a weaker promise than an architecture

Most apps answer this concern with a privacy policy. Policies are worth reading and they are worth very little as a guarantee, because they describe an intention that can change.

A policy can be rewritten at the next funding round. A company can be acquired, and the data goes with it. A company can close, and its assets are sold. A perfectly honest company can be breached. And a company holding data can be compelled to produce it regardless of what it promised you.

None of that requires anyone to act in bad faith. It only requires the data to exist somewhere other than your device.

What “on-device” actually means

Penwise takes the second position, and it is worth being precise about what that involves rather than waving at it.

No account

No email address, no password, no sign-up screen. The app works the moment you install it. There is no identity to attach a record to, because there is no identity.

No server for health data

Every dose, weight, symptom and note is written to the app's private storage on your device, protected by the operating system's own encryption. It is never transmitted to us, because there is nowhere for it to go.

No tracking SDKs

No ad networks, no attribution frameworks, no third-party analytics reading your health data. Crash reporting is opt-in, off by default, capped, kept locally for you to read, and strips file paths, email addresses and web addresses first.

Your export, your keys

The only copy that leaves the phone is a backup you export yourself, encrypted on the device before it is written, with a passphrase only you hold. We hold no keys.

There are also the local protections that matter when the risk is somebody picking up your phone: the app can lock behind Face ID, Touch ID, a fingerprint or the device passcode; a privacy shield covers the screen before the operating system takes its app-switcher snapshot, so your numbers never appear in the task switcher; and on Android screenshots and screen recording are blocked while locked.

The honest cost

This design is not free, and anyone who tells you otherwise is selling something. Removing the server removes real conveniences.

Those are genuine trade-offs and for some people they are the wrong ones. If cross-device sync is essential to how you work, a cloud tracker is the right answer and it is better to know that now.

What to check in any app, including ours

  1. Does it require an account? If yes, the data is on a server by definition.
  2. Read the app store data-safety declaration. Both stores require developers to declare what is collected and shared, and it is often more revealing than the marketing page.
  3. Look for the word “anonymised”. Aggregate health data is notoriously easy to re-identify, and the word does a lot of quiet work in privacy policies.
  4. Ask what happens on acquisition or closure. The answer is almost always that the data transfers as an asset.
  5. Check whether export is free. An app that charges you for your own history has told you what it thinks the relationship is.
  6. Check the retention policy. How long is your data kept after you delete the account, and what does “delete” actually delete?

These are the same questions as in how to choose a GLP-1 tracker, sharpened for this one issue.

Why this is not a marketing position

It would be commercially easier to have a server. Sync sells, a web dashboard demos well, and usage analytics make product decisions much simpler than guessing does. We build without them because the alternative is asking people to trust a promise, and this is a category where the people most in need of a good tracker are often the ones least willing to hand a medication history to a startup.

The result is an app that cannot betray you in that particular way, because the capability does not exist. Everything else in Penwise – the level curves, the pen handling, the insights, the watch apps – runs on the device, on your own data, without any of it going anywhere.

A tracker that never receives your data

No account, no sign-in, no server. Free core tracker with full export, forever.

Common questions

Is there a GLP-1 tracker that does not need an account?
Penwise has no account and no sign-in. There is no email address, no password and no sign-up screen; the app works the moment you install it, and the fourteen-day trial starts without a card.
Where does Penwise store my health data?
In the app's private storage on your device, protected by the operating system's own encryption. It is never transmitted to us. The only copy that leaves the phone is a backup you export yourself, encrypted before it is written with a passphrase only you hold.
Can Penwise recover my data if I lose my phone or my passphrase?
No. We hold no keys and no copy, so there is nothing for us to restore from. That is the direct cost of the architecture and we would rather state it plainly than quietly keep a copy to make support easier.
Does Penwise use analytics or advertising SDKs?
No ad networks, no attribution frameworks and no third-party analytics on health data. Crash reporting is opt-in and off by default, capped in size, stored locally for you to read, and strips file paths, email addresses and web addresses before anything is written.
Is the on-device database encrypted?
The accurate statement is that your health data stays on the device, inside the app's private storage, protected by the operating system's own encryption, and that backups are encrypted by Penwise before they leave. We do not claim more than that.
What about Apple Health and Health Connect?
Those are on-device platforms you already control, and the sync is optional. Penwise reads and writes only what you permit, and turning it off changes nothing about the rest of your log.

Penwise is a tracking and education tool, not a medical device. Nothing on this page is medical advice, a diagnosis or a recommendation to start, stop or change a dose. Dosing decisions belong to you and your clinician. Ozempic, Wegovy, Rybelsus, Saxenda and Victoza are trademarks of Novo Nordisk; Mounjaro, Zepbound and Trulicity are trademarks of Eli Lilly. Penwise is not affiliated with, endorsed by or connected to either company.

Occasional updates, nothing else.

New features, what we are working on, and the odd thing we learn about GLP-1 tracking. A few times a year at most.

We only use your address for this newsletter. Unsubscribe from any email. Your health data is never involved: it stays on your phone.