# Why a GLP-1 tracker should not have a server

Updated 23 August 2026 · Written by the Penwise team

Think about what is in a GLP-1 log after a year. A prescription drug, dated, with dose changes. Your weight, weekly. Your body composition. Symptoms, moods, cravings, sleep. It is a medical record you assembled yourself, and it is more revealing than most of what is actually in your medical file. The question of where it is stored deserves more thought than it usually gets.

## What a medication log actually reveals

Individually these are unremarkable data points. Together they are not.

- That you are taking a prescription medication, which one, and at what dose.
- The dates you started, increased, paused and stopped.
- Your weight over time, and often your body composition and measurements.
- How often you are adherent, and when you are not.
- Symptoms, appetite, mood and sleep, dated to the day.
- Enough of a pattern to infer things you never wrote down.

That is a profile that insurers, employers, advertisers and data brokers would all find valuable in different ways. It is not a reason for alarm, and it is a reason to be deliberate.

## A policy is a weaker promise than an architecture

Most apps answer this concern with a privacy policy. Policies are worth reading and they are worth very little as a guarantee, because they describe an intention that can change.

A policy can be rewritten at the next funding round. A company can be acquired, and the data goes with it. A company can close, and its assets are sold. A perfectly honest company can be breached. And a company holding data can be compelled to produce it regardless of what it promised you.

None of that requires anyone to act in bad faith. It only requires the data to exist somewhere other than your device.

> The stronger claim is not “we will not look at your data”. It is “we do not have your data”. Those are different sentences and only one of them survives a change of management.

## What “on-device” actually means

Penwise takes the second position, and it is worth being precise about what that involves rather than waving at it.

- **No account**: No email address, no password, no sign-up screen. The app works the moment you install it. There is no identity to attach a record to, because there is no identity.
- **No server for health data**: Every dose, weight, symptom and note is written to the app's private storage on your device, protected by the operating system's own encryption. It is never transmitted to us, because there is nowhere for it to go.
- **No third-party tracking SDKs**: No ad networks, no third-party attribution frameworks, no outside analytics reading your health data. If a creator referred you, the one thing the app sends us is a random install id together with the creator's code or link, so the creator can be paid. Crash reporting is opt-in, off by default, capped, kept locally for you to read, and strips file paths, email addresses and web addresses first.
- **Your export, your keys**: The only things that leave the phone are files you export yourself. A backup is always encrypted on the device before it is written, with a passphrase only you hold, and we hold no keys. A CSV, JSON or PDF export is a readable file you choose where to send.

There are also the local protections that matter when the risk is somebody picking up your phone: the app can lock behind Face ID, Touch ID, a fingerprint or the device passcode; a privacy shield covers the screen before the operating system takes its app-switcher snapshot, so your numbers never appear in the task switcher; and on Android screenshots and screen recording are blocked while locked.

## The honest cost

This design is not free, and anyone who tells you otherwise is selling something. Removing the server removes real conveniences.

- **No cloud sync.** Your history does not appear on a second device on its own. You move it with an exported backup.
- **No web app.** There is nothing to log into from a laptop, because there is nothing to log into.
- **No password reset, and no recovery.** If you lose your backup passphrase, the backup is unreadable. We cannot help, because we hold no keys. That is not a support policy we could relax; it is arithmetic.
- **Losing the phone without a backup means losing the data.** The same property that stops us from having it stops us from restoring it.
- **Support is harder.** We cannot look at your data to diagnose a problem, which occasionally makes a support conversation slower.

Those are genuine trade-offs and for some people they are the wrong ones. If cross-device sync is essential to how you work, a cloud tracker is the right answer and it is better to know that now.

## What to check in any app, including ours

1. **Does it require an account?** If yes, the data is on a server by definition.
2. **Read the app store data-safety declaration.** Both stores require developers to declare what is collected and shared, and it is often more revealing than the marketing page.
3. **Look for the word “anonymised”.** Aggregate health data is notoriously easy to re-identify, and the word does a lot of quiet work in privacy policies.
4. **Ask what happens on acquisition or closure.** The answer is almost always that the data transfers as an asset.
5. **Check whether export is free.** An app that charges you for your own history has told you what it thinks the relationship is.
6. **Check the retention policy.** How long is your data kept after you delete the account, and what does “delete” actually delete?

These are the same questions as in [how to choose a GLP-1 tracker](https://penwiseapp.com/en/guides/best-glp-1-tracker-apps), sharpened for this one issue.

## Why this is not a marketing position

It would be commercially easier to have a server. Sync sells, a web dashboard demos well, and usage analytics make product decisions much simpler than guessing does. We build without them because the alternative is asking people to trust a promise, and this is a category where the people most in need of a good tracker are often the ones least willing to hand a medication history to a startup.

The result is an app that cannot betray you in that particular way, because the capability does not exist. Everything else in Penwise – the [level curves](https://penwiseapp.com/en/guides/how-long-does-mounjaro-stay-in-your-system), the [pen handling](https://penwiseapp.com/en/guides/glp-1-pen-click-chart), the insights, the watch apps – runs on the device, on your own data, without any of it going anywhere.

**A tracker that never receives your data** No account, no sign-in, no server. Free core tracker with full export, forever.

## Common questions

**Is there a GLP-1 tracker that does not need an account?**

Penwise has no account and no sign-in. There is no email address, no password and no sign-up screen; the app works the moment you install it, and the fourteen-day trial starts without a card.

**Where does Penwise store my health data?**

In the app's private storage on your device, protected by the operating system's own encryption. It is never transmitted to us. The only things that leave the phone are files you export yourself: a backup is always encrypted before it is written, with a passphrase only you hold, while a CSV, JSON or PDF export is a readable file you choose where to send.

**Can Penwise recover my data if I lose my phone or my passphrase?**

No. We hold no keys and no copy, so there is nothing for us to restore from. That is the direct cost of the architecture and we would rather state it plainly than quietly keep a copy to make support easier.

**Does Penwise use analytics or advertising SDKs?**

No ad networks, no third-party attribution frameworks and no outside analytics on health data. If a creator referred you, the app sends us a random install id together with the creator's code or link, which is how creators get paid and carries nothing about you. Separately, the website counts a visit to a creator's link (a hashed IP address, browser, referring page, country and language; the hash, browser and referrer are deleted after 90 days) and keeps your email address only if you sign up for the newsletter. Crash reporting is opt-in and off by default, capped in size, stored locally for you to read, and strips file paths, email addresses and web addresses before anything is written.

**Is the on-device database encrypted?**

The accurate statement is that your health data stays on the device, inside the app's private storage, protected by the operating system's own encryption, and that backups are encrypted by Penwise before they leave. We do not claim more than that.

**What about Apple Health and Health Connect?**

Those are on-device platforms you already control, and the sync is optional. Penwise only reads what you permit and never writes to them, and turning it off changes nothing about the rest of your log.

Penwise is a tracking and education tool, not a medical device. Nothing on this page is medical advice, a diagnosis or a recommendation to start, stop or change a dose. Dosing decisions belong to you and your clinician. Ozempic, Wegovy, Rybelsus, Saxenda and Victoza are trademarks of Novo Nordisk; Mounjaro, Zepbound and Trulicity are trademarks of Eli Lilly. Penwise is not affiliated with, endorsed by or connected to either company.

## Keep reading

- [How to choose a GLP-1 tracker app](https://penwiseapp.com/en/guides/best-glp-1-tracker-apps): Twelve questions worth asking before you put a year of medication history into an app, and what the honest answers look like.
- [A Shotsy alternative, and how to bring your history with you](https://penwiseapp.com/en/guides/shotsy-alternative): What Penwise does that Shotsy does not, what it costs instead, and the guided import that brings your shots, weights and side effects across.
- [A Zepbound tracker for the whole tirzepatide ladder](https://penwiseapp.com/en/guides/zepbound-tracker): Tracking Zepbound (tirzepatide) for weight management: six strengths, two pen designs, the thirty-day clock, and reading weight against the dose you were on.
- [Tracking Rybelsus and the other oral semaglutide tablets](https://penwiseapp.com/en/guides/rybelsus-tracker): Oral semaglutide has no site, no pain and no clicks – but a strict fasting window, a daily cadence and three different dose ladders that are not interchangeable.
