AgentMClose
VintSnaptitraCitedSitePriceSiblinyLanyardTariffShieldPopSnap

titra — Privacy Policy

Last updated: 30 August 2026 (rev. 4)

Introduction

titra is a GLP-1 medication tracking app. Using it means sharing some information with us — and depending on the features you enable, with a small number of service providers that help us run the app. We take that responsibility seriously.

This policy explains what we collect, how we use it, who we share it with, and your rights. We've kept it as plain as possible.

Questions? Email hello@agentm.co.uk.

What We Collect (and Why)

Health data (optional) — If you choose to track your health in titra, we process the information you enter: medication doses, injection sites, side effects and notes, weight entries, and any wellness data you add. This is used solely to provide the app's tracking and insight features. If you enable Cloud Sync, this data is stored in Google Firebase (Cloud Firestore), encrypted in transit and encrypted at rest by Google. Without Cloud Sync, everything stays on your device and nothing is transmitted to us.

Account information (Cloud Sync only) — If you create a Cloud Sync account, we collect an email address and Firebase Authentication generates an account identifier (a Firebase UID). You can sign in with an email address and password, with Google, or with Apple. If you use Sign in with Apple you may choose Apple's private relay address, in which case we never receive your real email. Without Cloud Sync there is no account and no identifier stored on our servers.

Apple Health / Health Connect (optional) — With your explicit permission, titra can import the following data from Apple Health or Android Health Connect: steps, active and total calories, resting heart rate and heart rate variability, sleep, body weight, body fat percentage, hydration, nutrition (protein and dietary energy), and workout activity. This data is displayed locally and is never transmitted to our servers unless you enable Cloud Sync, in which case it syncs only to your own private account area.

Analytics — We use PostHog (EU Cloud) to understand how features are used and improve the app. Analytics events include things like "dose logged" or "export used" — they do not include health entries, medication details, or free-text notes. If you are signed in with Cloud Sync, events are associated with your Firebase account identifier (UID). You can opt out of analytics at any time in Settings.

Crash and error reporting — We use Sentry to capture crashes and errors so we can fix them. Sentry may automatically collect device type, OS version, app version, IP address, and a session identifier as part of standard crash context. We apply scrubbing rules to reduce unnecessary data capture, but standard crash reporting metadata — including IP address — may be processed by Sentry. No health data or free-text content is included in crash reports. See Sentry's privacy policy for their data handling practices.

Subscription information — Subscriptions are processed by Google Play or the Apple App Store. We do not receive your payment card details. Subscription status is managed through RevenueCat, which receives only an anonymous app user ID and subscription metadata.

Device and technical information — We and our service providers may automatically collect limited technical information such as device type, OS version, app version, and network metadata. This is used to keep the app reliable and secure.

How We Use Your Data

We use your data to provide titra's features, keep the app reliable and secure, understand how features are used so we can improve them, manage your subscription, and comply with legal obligations.

We do not use your health data for targeted advertising. We do not share your health entries with advertising networks or data brokers.

We may in the future use aggregated, anonymised data for purposes including research partnerships or product development. If we do this, it will be based on data that is designed not to be linkable back to you, and we will give notice and update this policy before doing so.

If you are in the European Economic Area or the United Kingdom, we process your information under the following legal bases:

  • Contract: To provide titra's core features — saving your data, enabling sync, delivering subscription features.
  • Legitimate interests: To keep titra reliable and secure, debug issues, improve performance, and understand how the app is used (including anonymised analytics) so we can improve it.
  • Consent: For optional features where consent is required — Health Connect / Apple Health imports and certain analytics. You can withdraw consent at any time in Settings.
  • Legal obligation: To comply with applicable laws and respond to lawful requests.

Where We Store Your Data

Data Where Notes
Health entries (no sync) On your device only Nothing leaves your phone
Health entries (Cloud Sync) Google Firebase — Cloud Firestore Private to your account; encrypted in transit and at rest
Account record (Cloud Sync) Google Firebase Authentication Email address and Firebase UID
Analytics PostHog (EU Cloud) No health data included
Crash reports Sentry (US) May include device metadata and IP address
Subscription status RevenueCat Anonymous ID and subscription metadata only

International Data Transfers

Your data may be stored or processed in the United States or other locations where our service providers operate. Our Firebase Cloud Functions run in the EU (europe-west1); Google may process Firebase data in other regions in accordance with its own terms. Where required — for example under UK GDPR and EU GDPR — we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by regulators, together with the UK International Data Transfer Addendum, to protect data transferred internationally.

How Long We Keep Your Data

Data type Retention
On-device health data Until you delete it or uninstall the app
Cloud Sync health data Until you delete your account or request deletion
Analytics Retained per PostHog's standard retention settings
Crash logs Retained for a limited period for debugging, then deleted or aggregated
Subscription records Retained as required to manage subscriptions and resolve disputes

Third-Party Services

titra uses the following third-party services. This list is provided in full to comply with applicable privacy laws including the Washington My Health My Data Act and similar statutes requiring explicit disclosure of all processors.

Service Purpose Data received Health data? Policy
Google Firebase (Authentication, Cloud Firestore, Cloud Functions) Account sign-in and cloud sync storage Email address, Firebase UID, and your synced health entries (only if Cloud Sync is enabled) Yes — private to your account, encrypted in transit and at rest firebase.google.com/support/privacy
RevenueCat Subscription management Anonymous app user ID and subscription status only No revenuecat.com/privacy
PostHog (EU Cloud) Product analytics Feature usage events (e.g. "dose logged") and account ID if signed in. No health data or free-text content. No posthog.com/privacy
Sentry Crash and error reporting Stack traces, device OS/version, app version, session identifier, and standard crash metadata which may include IP address. No health data or free-text content. No sentry.io/privacy
AppsFlyer Install attribution and ad campaign measurement Install source, device type, OS version, app version, and in-app conversion events (e.g. onboarding completed, subscription started). No health data or free-text content. No appsflyer.com/legal/privacy-policy

We do not use advertising networks or data brokers to serve ads within the app or to share user data for targeting purposes. If we add a new third-party service, this list will be updated and an in-app notice will be shown.

Who We Share Data With

We share data only with the service providers listed above, who are permitted to use it only to provide their services to us. We do not sell your personal data or health data. We do not share your health entries with advertisers or ad networks.

We may also disclose information if required by law, legal process, or to protect rights, safety, and security.

Corporate transactions: If titra is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice where required by law.

Smart Insights Features

titra+ includes features such as the Medication Level Tracker, Side Effect Patterns, and Dose Journey Planner. These run entirely on your device using pharmacokinetic models — your data is not sent to external services for processing.

Security

App lock uses a PIN hashed with SHA-256 — your PIN is never stored in plain text. Biometric authentication is handled by your device's secure enclave. Cloud Sync data is transmitted over TLS and stored encrypted at rest. No method of transmission or storage is 100% secure, but we work hard to protect your information.

Your Privacy Choices

You can manage many choices directly in the app's Settings, including exporting your data, deleting your account and all synced data, and opting out of product analytics. You can also request deletion of your account and data from the web, or email us to make a data request.

Your Rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, restrict or object to certain uses, and withdraw consent at any time. If you are in the EU/EEA, you also have rights under GDPR including data portability and the right to lodge a complaint with a supervisory authority. If you are in California, you have rights under the CCPA. If you are in Washington state or Nevada, you have rights under health data privacy laws specific to those states.

To exercise any of these rights, use the Settings screen in the app or contact us at hello@agentm.co.uk. We may need to verify your request before fulfilling it. If we deny a request you can appeal by replying to our response, and if you are still unsatisfied you may contact your relevant regulator.

Children

titra is not intended for children under 13 (or the applicable minimum age in your region). We do not knowingly collect data from children.

Data Controller

titra is the data controller responsible for your information under this Privacy Policy. For any privacy questions or requests, contact us at hello@agentm.co.uk.

Changes to This Policy

We may update this policy from time to time. The latest version will always be available at this URL. We will notify users of material changes through an in-app notice.

Contact

Questions about your data or this policy? Email us at hello@agentm.co.uk

Kept with the app’s source code and published here unchanged, apart from the contact address.

How AgentM handles data across all its products