← GLPath

Privacy Policy

Version 1.4 · Effective August 5, 2026

1. Who controls your data

The data controller for GLPath is Costin Alexiu, a natural person, based in Bucharest, Romania. For anything about your data or this policy, email glpath@glpath.pro.

2. What we collect

3. Why we process it, and on what legal basis

We process your account and billing data to provide the service you signed up for and to fulfil our contract with you (GDPR Article 6(1)(b)). We process all of your health data — everything you log about your body, your medication, and your photos — only on the basis of your explicit consent (Article 9(2)(a)), which you give during registration and can withdraw at any time. We process technical security logs on the basis of our legitimate interest in keeping GLPath secure and available (Article 6(1)(f)).

4. Who else sees it

We use the following services to run GLPath, and nothing else touches your data:

We run no advertising and no third-party trackers, and we never sell your data. The only usage statistics we keep are our own cookieless counts described in §5.

4a. AI-assisted meal estimation

If you use the optional AI meal-estimation feature, the meal description you type and/or a photo of your meal is sent to Anthropic, our AI provider, to estimate nutrition values (calories, protein, carbs, sugars, and fat). This happens only when you actively use the feature — manual meal logging never involves Anthropic at all.

A photo you submit for AI estimation is held only in a short-lived private server-side temporary location during processing and deleted immediately afterwards — never kept as a permanent copy, never made public. The analysis itself runs in memory; only the resulting nutrition estimate — plain numbers, which you can review and edit before saving — is stored in your account.

4b. Health sync (Apple Health / Health Connect)

If you enable Health Sync in Settings, GLPath reads weight, water, and active energy data from Apple Health (iOS) or Health Connect (Android) and stores what you choose to sync as ordinary log entries in your GLPath account. GLPath never writes data back to Apple Health or Health Connect. You can disable Health Sync at any time in Settings; disabling it stops future reads but does not delete data already imported.

This data moves directly from your device to our server — no third-party service sits in between, and Apple and Google never receive anything from GLPath in this process. Synced entries are covered by the same consent, retention, export, and deletion rules as everything else you log.

4c. Administrative access

Day-to-day, the operator sees only account metadata (for example your email address and subscription status) when providing support. Your health values are hidden from administrative screens by default; they can be revealed only through a deliberate action that requires a stated reason and writes a permanent audit-log entry before anything is shown. We access the minimum necessary, only to support you or keep the service safe.

5. Cookies and cookieless statistics

GLPath uses only essential cookies: a session cookie, a CSRF (XSRF) token, and — if you tick "remember me" — a login-remembering cookie. These are required for the app to function, so no cookie banner is shown. Your theme choice is stored in your browser's local storage, not a cookie.

To understand how many people visit, we keep cookieless counts: each visit is recorded under a technical identifier derived from your connection that is re-scrambled every day, cannot be reversed back to you, and cannot link your visits across days. From your IP address we derive only an approximate location (country and city) for aggregate statistics — the IP address itself is not stored with your visit. None of this is shared with anyone or joined to your account's health data. Separately, if you are signed in, we also store the country and city derived from your IP address (a two-letter country code and an approximate city name — never the IP address itself) on your account profile, so we can understand where our users are from and improve the service; it is not shared with anyone.

6. Where your data is stored

Your data is stored on our server in Bucharest, Romania, within the EU. In normal operation, we don't transfer your data outside the European Economic Area, with one exception: if you choose to use the optional AI-assisted meal estimation feature described in §4a, the meal text and/or photo you submit for that single request is transferred to Anthropic PBC in the United States. This transfer is being placed under standard contractual clauses (data processing agreement in progress — see §4a and our subprocessor list for status). It happens only when you actively choose to use the feature; manual meal logging never leaves the EEA.

Separately, push-notification delivery (Google) and in-app purchases (Google Play or the Apple App Store, depending on your device) are operated by those providers on their own global infrastructure. They handle only the technical and payment data described in §4 — your health data is never part of what they process.

7. How long we keep it

We keep your data for as long as your account exists. When you delete your account, your data — including your photos — is erased immediately. We also run nightly, access-restricted backups of the database for disaster recovery; a deleted account's data fully drops out of those backups within 14 days.

8. Your rights

9. Children

GLPath is not intended for anyone under 18, and we don't knowingly collect data from children.

10. International users

We apply this same GDPR-based standard to every user, wherever you're located. If you're in the United Kingdom, we apply the equivalent protections under UK GDPR. If you're in the United States, the same rules apply: GLPath is not medical advice, we never sell your data, and you have the same access, correction, and deletion rights described above.

11. Complaints

If you have concerns about how we handle your data, we'd like the chance to address them first at glpath@glpath.pro. You can also lodge a complaint with Romania's supervisory authority, ANSPDCP (www.dataprotection.ro), or with the data protection authority in your own EU country.

12. Changes to this policy

If we make material changes to this policy, we'll ask you to re-consent through the same in-app consent flow before you continue using GLPath.