ShotSync for iOS

Privacy Policy

Your health data stays on your device. This policy explains exactly what ShotSync collects, stores, and shares.

Effective date: April 23, 2026 · Last updated: May 3, 2026

Who we are

ShotSync is developed and published by Weight Loss Rankings (MEAS Partners, LLC), an independent publisher at weightlossrankings.org. For privacy-related questions, contact us at hello@weightlossrankings.org.

Data we collect

Personal health data (stored locally only)

ShotSync lets you log health information including weight, injection doses, injection sites, side effects, mood, and daily check-in notes. All of this data is stored locally on your device using AsyncStorage. It never leaves your phone unless you initiate an iOS backup through Apple.

  • We do not upload your personal health data to any server.
  • We do not have access to your personal health data.
  • We cannot recover your data if you delete the app.

Anonymous aggregate data (opt-in peer comparison)

If you enable the peer comparison feature, ShotSync sends anonymous, aggregate data points to our database. These data points include:

  • Drug type (e.g., semaglutide, tirzepatide)
  • Week number on treatment
  • Weight change as a percentage

This data contains no personally identifiable information — no name, no email, no device identifier, no IP address logging. It is used solely to generate the peer comparison curves shown in the app. You can opt out of contributing anonymous data at any time in Settings.

What we do NOT collect

  • No account creation required — no email, name, or password
  • No contact information of any kind
  • No third-party analytics SDKs (no Google Analytics, no Mixpanel, no Amplitude)
  • No advertising identifiers (no IDFA, no AdID)
  • No location data
  • No device fingerprinting

Data storage

  • Personal health data: Stored locally on your device via AsyncStorage. Encrypted at rest by iOS data protection when your device has a passcode set.
  • Anonymous peer data: Stored on Supabase (US-East region, encrypted at rest, encrypted in transit via TLS). Contains no personally identifiable information.
  • Cloud backup: ShotSync does not independently back up your data to any cloud service. If you use iCloud or iTunes backup, your local app data may be included in your iOS device backup per Apple’s standard behavior.

AI features (Pro and Pro+)

Several Pro and Pro+ features call Anthropic’s Claude API to return an estimate, an answer, or a summary. The exact data sent per feature:

  • AI Coach (Pro+): your typed question, the currently active peptide context, and the verified research summary for that peptide. No personal health log data is sent. Conversation history is kept on your device for 30 days, then auto-deleted.
  • Meal Scan (Pro+, Lifestyle tab): the meal photo you capture is sent — via our Supabase Edge Function relay, keyed only to your anonymous device UUID — to Anthropic’s Claude vision model for macro estimation (calories, protein, carbs, fat). No weight, no dose history, no other personal health data is included in the request. The photo is not retained on Anthropic’s servers after the response and is not retained by us. Only the returned macro estimate is stored locally in your meal log (and on Supabase if you opted into Cloud Sync, see below). We separately log anonymous token-usage counts and the confidence band of each scan to monitor cost and quality — this telemetry contains no image, no food items, and no macros.
  • Body Scan (Pro+): the body photo you capture plus your height, weight, sex, and age. Photo is not retained on Anthropic’s servers after the response. The numeric result (body fat percentage and confidence band) is stored locally; the photo is stored in the app’s local FileSystem and is never uploaded to our servers unless you opted into Cloud Sync. Limited to one scan per seven days.
  • AI Insight (Pro+): aggregated summaries of your last 30 days (totals and counts only — no raw entries, no photos) are sent to Claude to generate a daily insight card.

Anthropic does not train its models on your inputs. Inputs sent via our API key are governed by Anthropic’s commercial terms (anthropic.com/legal/commercial-terms), which prohibit training on customer data and provide a 30-day API log retention with no human review by default.

All AI estimates are not clinical measurements. Body Scan body fat percentages, Meal Scan macros, and AI Coach answers are intended for trend tracking and general guidance, not diagnostic decisions. Always confirm important values with a clinical-grade method and consult your provider.

Cloud Sync (optional, Pro and Pro+)

If you enable Cloud Sync in Settings, ShotSync uploads your tracking data (doses, weights, side effects, check-ins, vials, measurements, meal logs, body scan results) to our Supabase backend so you can restore on another device. The upload is keyed to a per-device anonymous UUID; we do not collect a name, email, or other identifier. Body Scan and Meal Scan photos are uploaded only when Cloud Sync is enabled. You can disable Cloud Sync and delete server-side data at any time from Settings.

Data sharing

We operate under a strict no-sharing policy for personal data:

  • We do not sell, rent, trade, or share personal health data with anyone.
  • Anonymous aggregate data is used only to power the peer comparison feature within the app.
  • Affiliate links to telehealth providers (powered by Katalys/RevOffers) may track click events for commission attribution purposes. No health data is shared with affiliate partners — only the fact that a click occurred.

Third-party services

ServicePurposeData received
SupabaseAnonymous peer comparison databaseDrug type, week number, weight change % (no PII)
Katalys / RevOffersAffiliate link trackingClick events on provider links (no health data)
AppleStandard iOS platform servicesPer Apple’s own privacy policy

Your rights and controls

  • Delete all data: Go to Settings > scroll to bottom > Delete All Data. This permanently removes all locally stored health data from your device.
  • Opt out of peer data: Go to Settings > toggle off “Contribute Anonymous Data.” Previously submitted anonymous data points cannot be individually identified or deleted because they contain no identifying information.
  • No account to delete: ShotSync does not create user accounts. There is no account to close or delete.

Children’s privacy

ShotSync is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. GLP-1 medications discussed in the app are prescription drugs intended for adult use under medical supervision.

HIPAA notice

ShotSync is a personal health tracking tool. Weight Loss Rankings (MEAS Partners, LLC) is not a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA). We are not a healthcare provider, health plan, or healthcare clearinghouse. ShotSync is a consumer wellness application, not a medical device or electronic health record system.

International users and transfers

Our peer-comparison database (Supabase) is hosted in the United States. The only data that ever leaves your device is the anonymous aggregate described above (drug type, week number, weight-change percentage) — no name, email, device identifier, or IP-level log is attached. By contributing anonymous peer data, you consent to its transfer to and processing in the US. Transfers to the US rely on Standard Contractual Clauses executed between us and our processor (Supabase), as permitted under Chapter V of the EU General Data Protection Regulation (GDPR) and the equivalent UK regime.

European Economic Area, United Kingdom, and Swiss users

If you use ShotSync from the EEA, the UK, or Switzerland, the following applies in addition to everything above.

Data controller. MEAS Partners, LLC, 131 Continental Dr, Ste 305, Newark, DE 19713, USA. Contact: hello@weightlossrankings.org. We have not appointed an EU or UK representative because the app does not require an account, does not collect contact information or any device or advertising identifier, does not target EU/UK residents specifically, and processes nothing outside your device other than the anonymous aggregate peer-comparison data points described above, which by design cannot be linked back to you as a natural person.

Legal basis for processing (GDPR Article 6). For the anonymous aggregate peer-comparison data points (drug type, week number, weight-change percentage) — to the extent they are considered personal data at all — we rely on legitimate interests (Article 6(1)(f)): our interest is delivering the peer-comparison curves inside a free, account-free tracker, and the processing is strictly minimal, cannot identify you, and does not override your fundamental rights. For the local on-device reminder notifications and any push notifications you choose to enable, we additionally rely on your consent (Article 6(1)(a)), which you may withdraw at any time by revoking notifications in iOS Settings.

Your rights. Because ShotSync does not tie the anonymous peer-comparison data to you, to any device identifier, or to any contact information, we are not in a position to locate, export, rectify, restrict, or erase individual rows on your behalf — once a data point is contributed it is, by design, indistinguishable from every other contribution. You nevertheless retain the full set of GDPR / UK GDPR rights in principle (access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests): to assert any of them, or to stop further contributions immediately, toggle off “Contribute Anonymous Data” in Settings and, optionally, email hello@weightlossrankings.org. All of your actual health data lives only on your device and can be erased with Settings > Delete All Data. You also have the right to lodge a complaint with your national supervisory authority (in the UK, the Information Commissioner’s Office).

Automated decision-making. We do not make any decisions that produce legal or similarly significant effects on you using automated processing or profiling. Clinical calculators, pharmacokinetic curves, and peer-comparison charts produce outputs from inputs you enter on-device; none of those outputs are clinical recommendations (see our Terms of Service).

Retention. Locally stored health data (weight, doses, sites, side effects, check-ins) is retained on your device until you delete it, delete the app, or wipe the device — we have no server copy. Contributed anonymous peer-comparison data points are retained indefinitely in non-identifying aggregate form; they cannot be individually located or removed because no identifier is attached.

Changes to this policy

We may update this privacy policy from time to time. The effective date at the top of this page indicates when the policy was last revised. We encourage you to review this page periodically. Continued use of ShotSync after changes constitutes acceptance of the updated policy.

Contact

For questions about this privacy policy or ShotSync’s data practices, contact us at hello@weightlossrankings.org.

Related: Terms of Service · Support · ShotSync Home · WeightLossRankings.org Privacy Policy