Privacy Policy
Privacy Policy
Last updated: July 15, 2026
The short version. Eden GLP is built to keep your health information private. What you log in the app, such as doses, medications, schedules, weight, body metrics, protein, water, activity, notes, how you feel, and any faith reflections, is stored on your device only. There is no account and no sign-in, and we do not receive, store, or have access to your health data. The app uses the network only in a few narrow, described cases and includes no advertising. To improve the app it collects anonymous, non-identifying usage analytics, which never include the values or contents of what you log, and which you can turn off in Settings. We never sell your information.
1. Who We Are
Eden GLP (store listing: "Christian GLP-1 Weight Tracker") is operated by Marshall Matters Ventures Pte. Ltd., a Singapore company with UEN 202603347K. Our registered address is 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051. In this policy, "Eden GLP", "we", "us", and "our" refer to Marshall Matters Ventures Pte. Ltd.. "You" refers to anyone who uses the app, visits our website, or contacts us.
For privacy questions or to exercise your rights, contact us at .
2. What This Policy Covers
This policy applies to the Eden GLP app for iOS and Android and the website at edenglp.com. It does not cover third-party services, app stores, device platforms, or websites that we do not control. Those third parties have their own privacy policies.
3. Our Core Privacy Model: Your Data Stays on Your Device
Eden GLP is a local-first app. The information you enter to track your journey is stored locally on your device using the operating system's app storage. This includes, for example: medications and compounds you add, dose amounts and schedules, dose logs, weight and body measurements, protein, water, and activity entries, check-ins and how-you-feel entries, personal notes, goals and profile settings, reminder settings, and any faith-layer settings or reflections.
We do not operate an account system for the app, we do not require you to sign in, and we do not upload, sync, or back up this information to our servers. We cannot see it and we do not hold a copy of it. Because it lives on your device, it is covered by your device's own protections, such as your passcode and device encryption, and by any device backup you choose to make through Apple or Google.
4. When the App Uses the Network
The app works primarily offline. It contacts the network only in the specific cases below, and it does not attach your identity or your health history to those requests.
Food and nutrition lookups (Open Food Facts)
When you scan a barcode or look up a packaged food, the app sends the barcode or product query to Open Food Facts (world.openfoodfacts.org), a third-party open database of food products, to retrieve nutrition information. That request includes the barcode or query and the standard technical details any web request carries, such as your IP address, which Open Food Facts processes under its own privacy policy. We do not attach your name, your logs, or your health data to these lookups.
Reminders and notifications
Dose and check-in reminders are scheduled locally on your device by its operating system. We do not run a push-notification server, we do not send you push notifications, and we do not collect a device push token. If you turn notifications off in your device's settings, the app stops scheduling local reminders.
Apple Health (optional)
If the app offers Apple Health import and you choose to enable it, the app reads the specific data you permit, for example weight, from Apple Health on your device through Apple's HealthKit, so you do not have to re-enter it. Data read from Apple Health stays on your device and is not sent to us. You control this access in the iOS Health and Privacy settings, and you can revoke it at any time.
Camera
The app uses the camera, with your permission, to scan food barcodes and nutrition labels. Images are processed on your device for scanning and are not uploaded to us.
Anonymous usage analytics (PostHog)
To understand how the app is used and where people run into trouble, the app sends anonymous, non-identifying usage events to PostHog, a product-analytics provider, on its European Union cloud. These events cover things like which screens you open, which features you use, the kind of entry you make (for example, that you logged a weight or a dose, and its source), your progress through onboarding, coarse profile settings (your journey type such as GLP-1, your units, your activity level, and whether you have set a goal, but never the goal figure), your app version and platform (iOS or Android), and the type of any app error. They are tied only to a random identifier generated on your device, never to your name or an account (there is no account). We do not send the values or contents of what you log: no weight, dose, or measurement numbers, no notes, no goal figures, no error messages or diagnostics text. IP-based location is disabled. This is on by default; you can turn it off at any time under Settings, in the Privacy section ("Share anonymous usage data"). PostHog processes this data on our behalf under its own privacy terms.
5. What We Do Not Do
- We do not sell or rent your personal information.
- We do not use advertising identifiers such as Apple's IDFA or Google's Advertising ID, or any advertising or ad-tracking SDK, and we do not show ads.
- We do not collect analytics that identify you, and our usage analytics never include the values or contents of what you log: no weight, dose, or measurement numbers, no notes, and no goal figures. You can turn usage analytics off in the app's settings.
- We do not track you across other companies' apps or websites, and we do not build advertising or identity profiles of you.
- We do not upload your health data, doses, weight, or notes to our servers.
6. Information We Do Handle
Because the app is local-first, the personal information we as a company actually come into contact with is limited to the following.
- Website request data. When you visit edenglp.com, our hosting and delivery providers process technical information such as IP address, request time, requested URL, referrer, browser and device details, and response status, for delivery, security, and troubleshooting. The website does not set advertising cookies and does not embed cross-site tracking pixels.
- Support messages. If you email us, we receive what you send: your email address, your message, and anything you choose to include such as screenshots, device model, and app version. We use this to respond and to fix problems.
- App store information. If you download the app from the Apple App Store or Google Play, Apple or Google processes information about the download, your device, crash reports, and usage under its own policies and may share aggregate or limited information with us as the developer. We do not control that processing.
- Anonymous product analytics. If you leave usage analytics on, we receive anonymous, non-identifying usage events through PostHog (see "Anonymous usage analytics" above): screen and feature usage, the kind of entry you make (for example, that you logged a weight or a dose), your progress through onboarding, coarse profile settings (journey type such as GLP-1, units, activity level, and whether a goal is set), app version and platform, and the type of any app error, tied only to a random on-device identifier. This never includes the values or contents of what you log (no weight, dose, or measurement numbers, no notes, no goal figures, and no error message text), and you can turn it off in the app's settings.
7. How We Use Information
We use the limited information above to deliver and secure the website, respond to support requests, diagnose and fix bugs, understand aggregate reliability and crash trends from Apple and Google, comply with legal obligations, and protect our rights and our users. We do not need, and do not use, your on-device health data for any of this.
8. Legal Bases for Processing (EEA/UK)
For users in the European Economic Area and the United Kingdom, the bases we rely on under the GDPR are:
- Legitimate interests (Article 6(1)(f)): operating and securing the website, preventing abuse, responding to support, and understanding anonymous, aggregate usage to improve the app's reliability and design. You can object, and you can turn off in-app usage analytics in the app's settings (see Your Privacy Rights).
- Consent (Article 6(1)(a)): device permissions you grant, such as notifications, camera, and Apple Health. You can withdraw consent at any time in your device's settings.
- Legal obligation (Article 6(1)(c)): retaining records we are required to keep and responding to lawful requests.
Outside the EEA/UK, we rely on equivalent bases under applicable law, including consent and our legitimate interests in operating and improving the service.
9. Sensitive Health Information
Doses, medications, weight, and related entries are sensitive health information, and we take that seriousness into account by keeping it on your device rather than collecting it. We do not receive this information, so we do not process it as a data controller in the ordinary course. If you choose to send us health details in a support message, we will handle that message with care and use it only to help you.
10. Faith Features
Eden GLP includes an optional faith layer, such as a short reflection, a shot-day blessing, and quiet-time prayers. These features are optional, you can turn them all the way off, and any related settings or content are stored locally on your device like the rest of your data. Faith features never gate your ability to log or track, and they are never required to use the app.
11. Service Providers
We use a small number of providers to run the website, the app's analytics, and support: hosting and delivery through Amazon Web Services (Amazon S3, Amazon CloudFront, AWS Certificate Manager, and Route 53), email and support tooling, anonymous product analytics through PostHog (hosted on its European Union cloud), and Apple and Google for app-store distribution and crash reporting. Open Food Facts serves nutrition lookups when you use that feature. Providers are expected to process information only as needed to provide their service and to meet their own legal obligations.
12. International Transfers
We are based in Singapore, and our providers may process information in Singapore, the United States, the European Economic Area, the United Kingdom, or other locations where they operate. Our product-analytics provider, PostHog, is configured to process the app's anonymous usage data on its European Union cloud. Where personal data of EEA, UK, or other protected users is transferred outside their region, we rely on appropriate safeguards such as Standard Contractual Clauses in our agreements with providers, in accordance with GDPR Chapter V. Because your health data stays on your device, it is not part of these transfers.
13. Retention
Your on-device data remains on your device until you delete it or remove the app. We do not hold a copy to retain. Website server logs and support messages are kept only as long as reasonably needed for security, troubleshooting, legal, and record-keeping purposes, and then deleted or aggregated.
14. Your Choices and Controls
Because your health data lives on your device, you control it directly:
- Delete individual entries in the app, or remove the app to delete its local data from your device.
- Manage camera, notification, and Apple Health permissions in your device's settings at any time.
- Turn the faith layer off entirely in the app's settings.
15. Your Privacy Rights
Subject to applicable law, you have rights over the personal information we hold about you, which, as described above, is primarily website logs and support messages, not your on-device health data. To exercise any of these rights, contact us at . We may need to verify your identity before completing a request.
Under Singapore PDPA
You may request access to, and correction of, the personal data we hold about you, and you may withdraw consent for processing that relies on consent. We respond in accordance with the Personal Data Protection Act 2012.
Under EU/UK GDPR
If you are in the EEA or the UK, you have the rights of access, rectification, erasure, restriction, data portability, and objection to processing based on legitimate interests, as well as the right to withdraw consent where processing relies on it. You may also lodge a complaint with your local supervisory authority.
Under CCPA/CPRA (California)
We do not sell or share your personal information as those terms are defined under California law. California residents may request to know the categories and specific pieces of personal information we hold, request deletion, and exercise these rights without discriminatory treatment.
16. Security
Our strongest privacy protection is structural: we keep your health data on your device instead of collecting it, so there is no central store of it to breach. On the device, your data is protected by your device's app storage and its own protections. For the website and support, we use reasonable technical and organizational measures such as HTTPS, restricted access, and provider security controls. No system is perfectly secure, and we cannot guarantee that information will never be accessed without authorization.
17. Data Breach Notification
If a data breach affecting personal information we hold occurs, we will notify the relevant authorities and affected users in accordance with applicable law, including the GDPR (notifying the competent supervisory authority within 72 hours of becoming aware of a qualifying breach) and Singapore's PDPA (under the Personal Data Protection (Notification of Data Breaches) Regulations 2021).
18. Children
Eden GLP is not intended for children under 13, and we do not knowingly collect personal information from children under 13. The app is a tracking tool for people managing a GLP-1 or peptide regimen, which is a decision made with a qualified prescriber. If you believe a child has provided personal information to us, contact us and we will take appropriate steps.
19. Do Not Track
There is no consistent industry standard for "Do Not Track" signals, so our website may not respond to them. Where legally required, we honor applicable privacy choices through the mechanisms required in that jurisdiction.
20. Changes to This Policy
We may update this policy from time to time. If we make material changes, we may notify you through the app, the website, or another reasonable method. The "Last updated" date shows when this policy was last revised.
21. Contact
If you have questions, requests, or complaints about this policy or our privacy practices, contact us at .
Marshall Matters Ventures Pte. Ltd.
UEN: 202603347K
60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051