Gireta is now available in

Download Now

Privacy Policy

Last updated /

Sep 27, 2025

Privacy Policy 

Last updated 2026. This explains what Gireta collects, how it's used, and the controls you have over your data. It applies to the Gireta mobile app and the website at gireta.com.

What we collect


Account
Email address, display name, and handle. Birth year, sex, height, and weight if you provide them during onboarding. 

Health and sensitive content.

Compounds you choose to track, dose logs (date, time, amount, route, optional injection site), vial inventory (size, expiry, cost), reconstitution presets, side-effect logs, daily check-ins (subjective energy, mood, sleep, hunger), photo journal entries and scans, baseline measurements you record, and any free-text notes you write. Apple Health metrics (weight, body fat, sleep, heart rate, HRV, steps, active energy) if you grant the Apple Health permission. We treat all of this as sensitive personal information.

App activity
Push notification token (so we can deliver reminders you've enabled), in-app interactions needed to operate the Service, and anonymized crash reports if you have not disabled them.

  

Purchase history
Whether you have an active subscription, plan, renewal status, and a RevenueCat customer identifier. We do not see or store your payment card.

What we don't collect

We do not collect your payment card details — those stay with Apple. We do not use cross-app or cross-site advertising trackers and do not request App Tracking Transparency permission. We do not sell or rent your personal information. We do not run third-party advertising on health screens.

How we use your data

To operate the Service: store your protocols, doses, vials, scans, journal entries, and check-ins so they persist across sign-ins; deliver push notifications you've enabled; surface trends against your own baseline; show you community content and your own history; let our AI assistant describe data you've already logged when you ask.For safety and trust: detect spam, abuse, and content that violates our Terms; respond to legal requests when required. For service improvement: aggregate, de-identified usage signals and crash reports help us fix bugs and prioritize features. You can opt out of crash reports in Settings → Privacy.

  

Apple Health

If you grant Apple Health access, Gireta reads selected biometric types (weight, body fat, sleep, heart rate, HRV, steps, active energy) so the trend card can render against your own baseline without manual entry. Reads happen on your device. Gireta does not write to Apple Health. You can revoke access at any time in iOS Settings → Privacy & Security → Health → Gireta.

  

Service providers

We rely on the following providers to operate Gireta. Each processes data on our behalf under their own data agreements. Apple App Store and RevenueCat (subscription billing and entitlement management), Better Auth (sessions), our managed Postgres host (account and content storage), Cloudflare R2 (photo storage), OpenAI (AI assistant features; inputs are not used for model training under the API terms), Expo (push notification delivery), Resend (transactional email), and Sentry (optional crash reporting; disabled by default in development).

  

Data we share

We share data with the providers above only as needed to run the Service. We share data with law enforcement only when legally required. We do not sell or rent personal data. We do not share any health or sensitive content with third parties for their own marketing.

  

Where your data lives

Account, protocol, and journal data is stored on managed servers in the United States. Photos uploaded for scans, journal entries, chat messages, posts, and profile pictures are stored on Cloudflare R2, with content delivered from the closest region. If you access Gireta from outside the United States, your data will be transferred to and processed in the United States.

  

Your rights

You can: (a) access and review your data inside the app at any time; (b) export every protocol, dose log, journal entry, check-in, side-effect log, and reconstitution preset as a single JSON bundle from

Settings → Privacy → Export my data; (c) delete your account at Settings → Privacy → Delete account, which permanently erases your profile, scans, journal, posts, and comments. We honor verified GDPR and

CCPA requests. EU residents may also lodge a complaint with their local supervisory authority.

  

Data retention

We retain your data for as long as your account is active. When you delete your account, we delete your profile and content within 30 days. Backups expire on a rolling 30-day basis. We may retain a minimal record of subscription transactions for accounting and tax compliance.

  

Children

Gireta is for adults only. We do not knowingly collect data from anyone under 18. If you believe a minor has signed up, email help@gireta.com and we will remove the account.

  

Security

We use HTTPS in transit, encryption at rest where the provider supports it, and the same authentication primitives Apple recommends for iOS apps. Photos and journal entries are tied to your account; we do not share them with other users unless you explicitly post them to the community. No system is perfectly secure; we encourage you to use a strong password and to enable two-factor on your email address.

  

Changes to this policy

We may update this policy from time to time. Material changes will be communicated in-app and by email to the address on file. Continued use of the Service after a change constitutes acceptance.

  

Contact

  help@gireta.com

On this page