Fortly privacy policy

Fortly: GLP-1 Protein Tracker · Effective date: September 29, 2026 · Last updated: September 2026

Fortly's Consumer Health Data Privacy Policy is on its own page.

The short version

  • What you log in Fortly (meals, doses, injection sites, weights, water, symptoms and notes) is saved on your iPhone. It is not sent to our server.
  • Only if you allow AI analysis, a meal photo you choose, and any note you add, goes through our server to OpenAI to estimate the protein. Our server does not keep them.
  • Apple Health is optional. Nothing from Apple Health leaves your iPhone.
  • Usage analytics are off unless you choose to share them.
  • No account, no ads, no tracking, and we never sell your data.

Who we are

Fortly is made by Wavista Apps, operated by William Tsao, an individual based in California, USA. Contact: [email protected].

What stays on your iPhone

Fortly has no account. It saves these only in the app's storage on your iPhone:

  • your profile: units, medication form and name, dose schedule, current and goal weight, activity level, and protein and water goals;
  • meals (foods, portions, protein, calories, carbs and fat, and the meal photo if you took one), your saved favorites and water;
  • weights, doses (medication, your dose label, injection site and notes) and daily symptom check-ins (nausea, constipation, tiredness and appetite, and notes);
  • your reminder settings. Reminders are scheduled on your iPhone; we do not use push notifications from a server.

During setup, Fortly asks for your permission before it saves this health information, on the "Your health information" screen. You can withdraw it at any time with Settings, Delete my data, which erases it from your iPhone.

The doctor report PDF is made on your iPhone only when you create it, and the copy is removed when the share sheet closes. You decide where to send it.

If you back up your iPhone to iCloud or a computer, the backup includes this data, as it does for any app. Apple's privacy policy covers those backups.

What leaves your iPhone, and who receives it

Our server and OpenAI (meal photo estimates)

Photo estimates need your permission. The app asks on a consent screen before the first estimate, and nothing is sent if you choose Not now. You can still log meals by hand without AI.

When you snap or pick a meal photo with AI analysis allowed:

  • The app shrinks the photo and removes its metadata, including any location, then sends it to our server with any note you add (up to 300 characters, for example "about half eaten").
  • Our server removes any remaining metadata and sends the photo and note to OpenAI to estimate the foods, portions, protein, calories, carbs and fat.
  • Our server keeps the photo and note in memory only while it gets your estimate. It does not save them or write them to its logs.
  • OpenAI receives the photo and note, but not your name or the app's anonymous ID. We send each request with OpenAI's storage option turned off (store=false), so OpenAI does not keep it as a stored conversation. OpenAI does not use API data to train its models. It may keep API data for up to 30 days only to check for misuse, and then deletes it.

The estimate is sent back to your iPhone. The app keeps the meal photo on your iPhone, with the meal, until you delete the meal.

Every request to our server carries the app's anonymous ID (a random ID created by RevenueCat, see below), so the server can check your subscription and daily limit. Our server also keeps:

  • A record of each estimate: the time, the feature, which kind of AI answered, whether it worked, how long it took, its cost, the confidence of the answer and your answer to "Was this estimate close?" if you give one. It is tied to a scrambled form of the anonymous ID (a salted hash), not the ID itself, and it never includes the photo, the note or the foods. Records are deleted after 90 days.
  • Daily usage counts, tied to the scrambled ID, deleted after 90 days.
  • Your subscription status: the anonymous ID with the product, the expiry date, whether it is a trial and whether it was a test purchase. RevenueCat sends this to our server when your subscription changes. We keep it until you use Delete my data.

Our server uses your IP address for a moment, in memory, to limit how many requests one connection can make. It does not save it in its database or its logs. Our server runs on Fly.io, and its database is hosted by Supabase, both in the United States. Every hour we save a backup copy of that database in a separate private storage bucket at Cloudflare R2. Each copy is encrypted before it is uploaded, with a key that only we hold, so Cloudflare cannot read it. We use backups only to recover the database if something goes wrong.

Withdraw your permission at any time in the app: Settings, Privacy, Use AI analysis. An estimate that is still uploading is stopped.

RevenueCat (subscriptions)

RevenueCat runs the subscription for us. It receives the app's random anonymous ID, your App Store purchase records (what you bought, when, its price, and trial and renewal status) and technical details such as the iOS and app version. Its software also sends the identifier for vendor, an ID that Apple gives our apps on your iPhone. RevenueCat never gets your name, email or payment card. If you installed the app from an ad on the App Store (Apple Ads), Apple tells RevenueCat which ad campaign, ad group and search keyword led to the install, so we can see whether our ads pay for themselves. This is Apple's own ad attribution: it does not use the advertising identifier and needs no tracking permission. Apple handles payment.

PostHog (usage analytics, only if you choose)

Analytics are off unless you tap Share usage data during setup or turn it on in Settings, Privacy. Until then, the app does not even start PostHog. If you turn it on, PostHog receives, tied to the anonymous ID:

  • events such as opening the app, setup steps viewed, permission answers, your AI and analytics choices, when the subscription screen was shown, trials, purchases and restores, when an estimate started, finished (how long it took, its confidence) or failed (an error code), your thumbs answer, and review prompts;
  • that you logged a meal (its source, the number of items and how many you edited) or added a favorite;
  • details the PostHog software adds, such as the app version, iOS version, device model, language, time zone and screen size.

PostHog never receives what you log: no foods, amounts, medication or dose details, weights, symptoms, photos or notes, and nothing from Apple Health. It is not told when you log a dose or a check-in, make a report or connect Apple Health. It does not receive your setup answers either, and it does not record which screens you open. Session recording, touch tracking and location lookup from your IP address are turned off. PostHog does not store your IP address.

Turn it off at any time in Settings, Privacy, Share usage data.

Sentry (crash reports)

If the app crashes or hits an error, it sends a report to Sentry so we can fix it: what went wrong and where in the app, the device model, iOS and app version, and a random ID Sentry makes for the install. For about 1 in 10 sessions it also sends performance timings. Reports do not include the anonymous ID. Before a report is sent, the app cuts a failed database save down to the kind of action and the table name, so a report never includes what you were saving (such as foods, weights, symptoms or notes). It also leaves out request details and console logs. Sentry does not store your IP address.

Apple

Apple handles the App Store, payments and, if you use them, Apple Health and iPhone backups, under Apple's own privacy policy.

Email to support

If you email us, we receive your email address, your message and the details that Contact support adds (app version, iOS version and the anonymous ID). We use them only to help you. We keep support emails for 2 years after your last message, then delete them. Cloudflare forwards them to our Gmail (Google) inbox.

Apple Health

Apple Health is optional and off until you turn it on in Settings, Apple Health. If you allow it:

  • Fortly reads your body weight, from 90 days before you started using the app, to show your weight trend.
  • Fortly saves the protein, calories and water you log to Apple Health. When you edit or delete a meal or water entry, it updates Apple Health too.

Data from Apple Health stays on your iPhone. It is never sent to our server, OpenAI, PostHog, Sentry or anyone else, and it is never used for ads or analytics. You can change Fortly's access at any time in the Health app. Delete my data cannot remove data already saved in Apple Health; delete it in the Health app.

Permissions

  • Camera and photos: only to take or choose a meal photo.
  • Notifications: for dose and check-in reminders. They are discreet by default and do not show details on the Lock Screen unless you turn that on.
  • Apple Health: as above.

Fortly does not use your location, contacts or microphone.

How long data is kept

  • On your iPhone: until you delete it, use Delete my data or delete the app.
  • Meal photos and notes on our server: not stored, only held in memory during the estimate.
  • At OpenAI: up to 30 days, only for misuse checks.
  • Request records and usage counts on our server: 90 days.
  • Encrypted backups of our server's database: hourly copies for 3 days and daily copies for 35 days, then deleted automatically. Anything removed from the database, including by Delete my data, is gone from every backup within 35 days.
  • Subscription status on our server: until you use Delete my data.
  • RevenueCat: for as long as we offer the app, so your subscription can be restored.
  • PostHog: up to 1 year, or until you use Delete my data.
  • Sentry: 30 days.

Delete my data

Open Settings and tap Delete my data. The app deletes everything it saved on your iPhone right away (your logs, profile, meal photos, reports and settings), cancels its reminders (a reminder before a free trial ends stays, like the subscription), turns analytics off on that iPhone for good and starts again from the beginning. Then it asks our server to:

  • ask PostHog to delete your analytics profile and its events;
  • delete your subscription status record;
  • remove the scrambled ID from your request records, so they can no longer be tied to you (they are still deleted at 90 days);
  • delete your usage counts from earlier days. Today's count stays until it expires, so daily limits still work.

Backups made before the deletion still hold the old records until those copies are deleted, at most 35 days later. Nobody can read a backup without our encryption key, and we use backups only to recover the database after a failure.

If your iPhone is offline or our server cannot be reached, the app tries again by itself. While the deletion is waiting for our server, Settings shows it and offers Email support. If you delete the app before then, it can no longer finish this step, so first email us from Contact support (it adds the anonymous ID we need) and we will delete the server copy.

Delete my data does not cancel your subscription and does not delete RevenueCat's purchase record, so you can still restore your subscription. It cannot remove data already saved in Apple Health. To ask for your RevenueCat record to be deleted too, email us.

Your requests

You can email [email protected] to ask what we hold about you, or to delete it. Send the email from Contact support in the app so it includes the anonymous ID; we cannot find your data without it, because we do not know your name. We reply within 30 days.

What we do not do

We do not sell your personal information or share it for advertising. The app has no ads and does not track you across other companies' apps or websites. We do not collect, use or sell personal data to train large language models, and OpenAI does not use API data to train its models.

The app does not track you across other companies' apps or websites, so there is nothing for a Do Not Track signal to turn off, and the app does not respond to one.

Children

Fortly is for adults. It is not directed to children, and we do not knowingly collect data from children under 13. If you think a child has used the app, email us and we will help delete the data.

Where the law requires it, the app asks Apple for your age range. The answer stays on your iPhone, is used only to apply age protections, and is never sent to us or anyone else. If Apple says you are under 13, or you choose not to share your age range where it is required, the app turns off usage analytics, Apple Ads attribution (see RevenueCat above), the AI features that send photos to our server and OpenAI, and your answers about AI results.

Security and where data is processed

The app talks to our server and service providers over encrypted connections (HTTPS). Our server stores the anonymous ID only in scrambled form, except in the subscription record. Our server, its database and our service providers process data in the United States. Database backups are encrypted before upload and kept in Cloudflare R2's Eastern North America region.

Changes to this policy

If we change this policy, we will post the new version here with a new effective date. If a change affects how we use data you already gave us, we will tell you in the app first.

Contact

[email protected]

Back to top