Zeppy

Privacy Policy

Last updated 2 September 2026 · Version 1.1

Zeppy is a personal tracker for GLP-1 and related medications. It holds information about your health, so this policy explains exactly what is stored, who can reach it, how long it is kept, and how to get it back or delete it.

What Zeppy stores

Everything below is entered by you, except where noted.

  • Your email address and a hashed password. The password itself is never stored.
  • Medication plans: the medication, dose, route, and schedule you set.
  • Dose and injection logs, including injection site and any notes you write.
  • Weight entries and optional body measurements.
  • Symptom logs and their severity.
  • Hunger, craving, energy, and mood check-ins.
  • Nutrition entries: protein, water, calories, fiber.
  • Medication supply, refill and expiry settings, and cost if you enter it.
  • An optional emergency card: a contact name and phone number, notes for a helper, and whether it can be opened from the lock screen.
  • Your display preferences: units, date and time format, theme, timezone.
  • Records of exports, reports, consent, and deletion requests.
  • Security metadata such as sign-in times and blocked cross-account access attempts. This never contains health values.

Why it is stored

To show you your own history, trends, schedule, and supply; to send the reminders you turn on; and to build the exports and summaries you ask for.

Zeppy does not sell your data, does not share it with advertisers, and does not use it to profile you. There are no third-party analytics or tracking scripts in the app.

Who can see your data

You can. Zeppy is built so that no other account can read, search, export, edit, or delete your records — every request is scoped to the signed-in account on the server, and a client cannot ask for someone else's data by changing an id.

There is no admin or support screen that displays your health records. Whoever operates the server can, like any database administrator, reach the underlying database directly; Zeppy does not claim otherwise.

Reminders and third parties

If you turn on dose reminders, your browser registers with its vendor's push service, and Zeppy sends notifications through it. That vendor receives the delivery request and its timing. Depending on your browser this is one of:

Notification text is deliberately generic — it never contains a medication name, a dose, or any other health value — so the content of a reminder discloses nothing even in a notification shade or to the delivery service.

Turning reminders off removes the registration.

  • fcm.googleapis.com
  • android.googleapis.com
  • updates.push.services.mozilla.com
  • web.push.apple.com
  • .notify.windows.com

Connected sources

If this deployment has it enabled, you can connect an external source (currently a Withings account, or Health Connect via the Zeppy Android app) so weight and body-composition readings are logged automatically. This is opt-in per source and does nothing until you connect one.

Connecting a Withings account sends you to Withings to approve access; Zeppy's server then fetches your weight and body-composition readings from Withings' API and stores the access credentials Withings issues, encrypted, on this server. Withings sees Zeppy's requests and their timing. The only hosts contacted are:

Imported readings are ordinary entries: the same retention, deletion, and export rules apply as to entries you type, and each shows where it came from. Health Connect readings are read on your own Android device by the Zeppy app and sent only to this server.

Disconnecting a source deletes Zeppy's stored access credentials immediately and stops new readings. Entries already imported remain yours until you delete them.

  • wbsapi.withings.net
  • account.withings.com

How long it is kept

Your active data is kept until you delete it. When you delete a record it disappears from the app immediately and is then permanently removed on the schedule below by a job that runs daily.

  • Deleted health records: hidden immediately, permanently erased after 30 days.
  • Data exports (JSON/CSV): expire after 24 hours.
  • Provider reports (PDF): expire after 7 days.
  • Account deletion: completes after a 30-day grace period, during which you can cancel it.
  • Security metadata (no health values): kept up to 365 days.
  • Encrypted database backups: kept up to 14 days. Data you delete can remain in a backup until it ages out.

Getting your data out, or deleting it

From Account you can export everything Zeppy holds about you as JSON or CSV, and you can delete your account. Deleting requires entering your password again, and starts the grace period above so an accidental deletion can be undone.

Individual records can be deleted at any time from the entry itself.

Security

Passwords are stored using a slow, salted hash. Sessions use random tokens, and only a hash of each token is stored, so a database copy does not yield working sessions. Health values are never written to application logs.

Health values are stored unencrypted at the column level inside the database, protected by database access control and disk encryption where the host provides it. Database backups are encrypted. Access credentials for connected sources (such as a linked Withings account) are stored encrypted and are never included in exports.

If you believe you have found a security problem, please write to [email protected].

If there is ever a data breach

If Zeppy's operator confirms that your data was accessed, disclosed, or lost without authorisation, you will be told. The notice goes to the email address on your account (or, where that is not possible, is posted where you sign in), without undue delay and no later than 72 hours after the breach is confirmed.

The notice says what happened, which kinds of data were involved, what has been done about it, what you can do (for example, changing your password or signing out other devices from Account → Security), and how to reach the operator with questions. Where a law requires notifying an authority as well, the operator does that too.

The operator keeps a written record of every confirmed incident: what was affected, who was told, and when. That record holds no health values. Security concerns: [email protected].

AI features

Zeppy has no AI features enabled. Nothing you enter is sent to a language model or any other AI provider. If that ever changes, this policy will be updated first and you will be asked to accept it.

Email

Zeppy does not send email. There is no marketing list and no automated mail. Password resets are handled by the operator on request — see the support page.

Changes to this policy

If this policy changes in a way that affects how your data is handled, you will be asked to review and accept it the next time you open the app.

Questions about this policy: [email protected].