GrowthUp
Privacy Policy
Last updated: 4 August 2026
Who we are
GrowthUp, contactable at support@growthup.app. This policy covers the GrowthUp iOS app.
What we store on our servers
- Your account identifier from Sign in with Apple, and the email address Apple provides. If you chose "Hide My Email", we only ever see Apple's relay address.
- Your display name, if you enter one.
- Your username, if you pick one, and your display name. This is how other people find you.
Finding people, and being found
Signed-in users can search for other people by the first letters of a username or a name, and see the matching person's display name, username and profile photo so they can tell who they are adding. The add-a-friend screen can also show a short Suggested list of people — ordered by how many friends you have in common (you see the number, never which friends) — before anything is typed. Both surfaces show the same three things and nothing else: no figures, no protocol, nothing you have shared with friends. Both are limited in number and require an account.
You can turn this off: Profile → Sharing & Privacy → Let people find me in search. With it off you will not appear in anyone's search results or suggestions, and only someone who already knows your exact @username can send you a request. It is on by default.
Adding someone is still a request, and they still have to accept it. Being findable does not share a single one of your figures — that is governed entirely by the switches described below.
- Your protocol: the items you add, their amounts, units, schedules, reminder times, vial and reconstitution details, and remaining quantities.
- Your dose history: which doses you marked taken, skipped or missed, and when.
- Your buy list and your notification preferences.
- Your profile photo, if you add one. Note that profile photos are stored in a bucket that serves them over public URLs — do not use a photo you would not want to be reachable by link.
- Your friends list, and any friend requests you have sent or received.
- Your sharing settings — the switches under Sharing & Privacy.
Our backend is Supabase. Data is held there under their security controls. Nothing above is readable by another user except through the friends feature described next.
What friends can see
Nothing, unless you turn it on. Every switch under Sharing & Privacy starts off, and a friend only exists once one of you has sent a request and the other has accepted it.
When you do turn something on, a friend can see your display name, your username, and your profile photo, plus whichever of these you enabled: your consistency score, your current streak, your total doses logged, whether you have completed today, and your achievements. Separately, you can choose to show the compounds in your protocol and their schedule.
You can also share Apple Health figures, each behind its own switch: your steps, your sleep, your workouts, your weight and your resting heart rate. These are read from Health on your device and stored on our server so that a friend can see them without your phone being open. That is what the switch does — leaving it off means the figure is never sent.
Friends never see a dose. Not an amount, not a vial strength, not a quantity — the app publishes no dose figure, yours or anyone else's, and the queries that serve your friends do not select one. The figures a friend can see are the ones listed above and nothing else.
The weekly board
If you share steps or sleep, they also appear on a leaderboard among the friends you have accepted, which resets every Monday in your own timezone, and last week's result is recorded so a finished week can still be shown. The same switches govern it: a friend who cannot see your steps cannot see you on the board.
We may send you a notification about where you stand — for example that a friend is ahead of you this week. It is worked out from what you are allowed to see, never from figures somebody has switched off, it respects your quiet hours, and it never tells anyone that they are ahead of a named friend. Turn it off under Profile → Notifications.
Turning a switch off stops it immediately, and removing a friend removes their access in both directions. Which of your numbers a friend may see is decided on our server, not in the app — a switch you have left off means the value is never sent, not that it is sent and hidden.
Moments are the exception, and it is deliberate. A Moment is something you make and post; it is not a figure measured about you and published on your behalf. The switches on this screen cover the second kind. If you post a Moment with a number in it — your steps, your sleep, a streak — the circle you posted it to sees that number for 24 hours, whatever those switches say. The composer tells you so at the moment you post.
Apart from GrowthUp AI, described below, we do not show your protocol, your logs or your figures to anyone else: not to other users, and not to anyone outside the friends you have accepted.
GrowthUp AI
If your plan includes the assistant and you have turned it on, asking it a question sends your own GrowthUp data to a third-party AI provider so that it can answer: the names, amounts, schedules, reminder times and remaining supply of the items in your protocol — including items you have marked private, because those are hidden from your FRIENDS and not from your own assistant — plus your dose history and adherence figures, your buy list, your age, biological sex, height and weight, and the Apple Health summary described below. Your name, your username, your email, your brand names and anything belonging to your friends are not sent.
Nothing is sent until you have agreed to it. The first time you open the assistant you are shown exactly what leaves the device and asked to accept; that agreement is recorded per account, so a second account on the same phone is asked for itself.
We do not store your conversations. They are kept on your device only, which also means they do not follow you to a new phone, and clearing a conversation removes it. What we do keep is a record of USE, with no content in it at all: which model answered, how many tokens it took, how long it took, whether it succeeded, and which conversation it belonged to. Not one word of what you asked or what it answered. We use those counts to watch cost and reliability. They are deleted with your account.
An answer from the assistant is not medical advice, is not written or checked by us, and can be confidently wrong. See the Medical Disclaimer.
Moments
A Moment you post is stored on our servers: the photo or video if there is one, the caption, and the figure if it is a stat. We also store which emoji anyone reacted with, and which of your friends' Moments you have watched — the person who posted it is shown how many people watched, never a list of names.
A Moment is deleted 24 hours after you post it, and the photo or video file is removed from storage within about fifteen minutes of that. Deleting a Moment yourself removes both immediately. A Moment that was reported, or that you reported, is kept for up to seven days so it can be reviewed, and is then deleted.
Blocking and reporting
Blocking somebody removes the friendship in both directions, deletes their reactions on your Moments and yours on theirs, and stops them finding you or asking again. The person you blocked is not told. Reporting stores a copy of what you reported — including the caption and the picture — so that it can be looked at after the original has expired.
Apple Health
GrowthUp requests read-only access. It cannot write to Health, and it never reads your medical records, medications or diagnoses — only steps, sleep, workouts, weight and resting heart rate.
What it reads is used first to draw your own screens. Where you have turned on the matching sharing switch, the figure is also stored on our server so your friends and the weekly board can show it, as described above. With every switch off, nothing from Health is shared with another user.
So that a friend's number is not stale, the app may read Health and update those figures in the background — including while you are not using it. It reads nothing it could not read with the app open. You can revoke Health access at any time in the Health app, under Sharing → Apps → GrowthUp.
What stays only on your device
- Your date of birth. Note that if you use GrowthUp AI, your AGE — worked out from that date, never the date itself — and your biological sex are sent with your question, as described above.
- Your local cache of vial and reconstitution details.
- Your conversations with GrowthUp AI.
Product analytics
In the app, we use PostHog to see how it is actually used, so we can tell which parts work and which are quietly failing. It runs in our own PostHog project. The data is not sold, not given to advertisers, and not used to follow you around other companies' apps or websites.
What goes to it: the screen you are looking at, a short list of product events — adding an item, completing or skipping a dose, restocking, creating a stack, posting a Moment, taking a screenshot of the app, and the fact that you asked GrowthUp AI a question, never what you asked — along with crash and error reports and your device model, OS version and app version. Because our servers see your IP address, an approximate location is derived from it: country and city, not your device's location, which we never ask for.
These are tied to your account by the same identifier used elsewhere in the app, and your email, name and username are attached to it, so that the same person on two devices reads as one person rather than two.
What does not go to it: your protocol and what is in it, your dose history, your Apple Health readings, the Moments themselves, your date of birth, and the text of anything you write — including your conversations with GrowthUp AI.
On this website, we use Counter.dev, a privacy-friendly page-view counter. It does not use cookies and does not collect anything that identifies you — only aggregate counts of visits and pages viewed.
What we do not do
- We do not sell your data.
- We do not share it with advertisers, and we do not use it for advertising.
- We do not track you across other companies' apps or websites. The analytics described above cover your use of GrowthUp and nothing else.
- We do not access your contacts, your camera roll beyond a photo you explicitly pick, or your location. The camera and microphone are used only while you are on the Moment camera screen. A Moment can be taken there or chosen from your photo library — in both cases only the single photo you pick is ever read, and the app is never given access to the rest of your library. Where a photo you choose carries the place and time it was taken, that information is removed before the photo leaves your phone: we re-save it as a plain image first, so what reaches our servers is the picture and nothing else.
Why we store it
To run the app for you: to show your protocol on every device you sign in on, to send the reminders you asked for, and to work out how much you have left. And, only where you have switched it on, to show the friends you have accepted what you chose to share with them.
How long
Until you delete it. Removing an item deactivates it. Deleting your account removes your profile, your protocol, your logs, your buy list, your notification preferences, your sharing settings, your shared progress figures, the Health figures we stored for you and their day-by-day history, your friendships in both directions, your friend requests either way, your profile photo, and the content-free record of your GrowthUp AI usage. Your finished weekly results and the record of notifications we sent you go with your account itself. If any part of that fails we tell you so on the spot rather than reporting success.
Your choices
- Choose what friends can see, or share nothing at all: Profile → Sharing & Privacy.
- Remove a friend at any time: their profile → Remove friend. Access ends for both of you.
- Delete your account and its data: Profile → Delete Account.
- Revoke Health access: the Health app, under Sharing → Apps → GrowthUp.
- Turn off reminders: Profile → Notifications, or iOS Settings.
- Stop notifications about friends and the weekly board, keeping your own dose reminders: Profile → Notifications → Friends and the weekly board.
- Request a copy of your data, or ask a question: support@growthup.app.
Children
GrowthUp is for adults 18 and over. We do not knowingly collect data from children.
Changes
If this policy changes materially we will show you the new version in the app.