Privacy Notice
Last updated: August 10, 2026
1. Who we are
SignalGLP is operated by SignWorks of Forest Hill, LLC (Maryland, USA), which acts as the data controller for personal data processed through the service. Contact: support@signalglp.com.
2. Personal data we collect and why
- Account data (name, email, login credentials, authentication identifiers) — to create and secure your account. Legal basis: performance of contract.
- Health and fitness data you provide or sync (weight, glucose readings, blood pressure, medications such as GLP-1 type and dose, meals, hydration, rides, rowing sessions) — to deliver dashboards, fuel plans, and AI coaching. Legal basis: performance of contract and your explicit consent for health data.
- Content you submit (coach messages, photos of labels or meals, notes) — to generate estimates, summaries, and coaching. Legal basis: performance of contract.
- Integration data (tokens and activity from Strava, Concept2, Gluco2Go, BP2Go, connected scales) — to sync your training and health signals. Legal basis: consent given when you connect the integration.
- Usage and technical data (device identifiers, IP address, log and telemetry data, error reports) — for security, fraud prevention, reliability, and product improvement. Legal basis: legitimate interests.
- Support communications — to answer your questions. Legal basis: legitimate interests.
- Marketing communications (if you opt in, e.g. waitlist signup) — legal basis: consent, withdrawable at any time.
We do not collect or store your payment card details. Payment data is collected and processed by Paddle.
3. Who we share data with
- Service providers / subprocessors — hosting, database, authentication, AI model providers, analytics, and error monitoring, acting on our instructions.
- Paddle.com, our Merchant of Record, for sale of the product, subscription management, payments, tax compliance, and invoicing.
- Integrations you connect, only to the extent needed to sync the data you authorize.
- Professional advisers (legal, accounting) and authorities where required by law.
We do not sell your personal data.
4. International transfers
We operate from the United States, and our providers may process data in the US and other countries. Where data is transferred from the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
5. Retention
We keep account and health data for as long as your account is active and for a limited period afterwards to handle disputes, legal, and tax obligations. Data is then deleted or anonymised. You can request deletion of your account and data at any time.
6. Your rights
Depending on where you live, you have rights to access, correct, delete, restrict, or port your data, to object to certain processing, to withdraw consent, and to opt out of marketing. UK/EEA residents may also complain to their supervisory authority. We respond within one month. Email support@signalglp.com to exercise a right.
7. Security
We use appropriate technical and organisational measures, including encryption in transit, row-level access controls tied to your user account, and restricted administrative access. No system is perfectly secure, but we work to protect your data and notify you of material breaches as required by law.
8. Cookies and local storage
We use essential cookies and browser storage to keep you signed in and to remember preferences. We may use limited analytics to understand feature usage. We do not use advertising cookies. You can clear or block cookies in your browser settings, though the app may not function correctly without essential ones.
9. Children
SignalGLP is not intended for anyone under 18.
10. Changes
We may update this notice. Material changes will be communicated in the app or by email.
