Security & your data
Last updated: August 14, 2026
SignalGLP holds fueling, training, and biometric data — the kind of information you should be careful about handing to anyone. This page describes, in plain language, how that data is handled. It is written by the operator of the app, SignWorks of Forest Hill, LLC, and describes current practice rather than any certification or third-party audit.
Your data is scoped to your account
Every record you create — meals, hydration, rides, rowing sessions, weight, blood pressure, glucose, labs, coach conversations — is stored against your user ID. Access is enforced at the database level with row-level security policies, not just in the app interface. A request carrying another user's session cannot read your rows.
Data is stored in a managed Postgres database hosted in the United States. Traffic between your device and SignalGLP is encrypted in transit over HTTPS, and the database is encrypted at rest by the hosting provider.
Payments never touch our servers
Memberships are processed by Stripe. Card numbers are entered directly into Stripe's hosted checkout and are never transmitted to, or stored by, SignalGLP. We retain only a Stripe customer reference, the plan you selected, and your subscription status so the app knows whether your membership is active.
Who else processes your data
- Supabase — database, authentication, and file storage for your account records.
- Stripe — payment processing and subscription billing.
- AI model providers — when you chat with the coach, scan a nutrition label, or ask for an estimate, the relevant context (your recent metrics and the message or photo you sent) is transmitted to a large language model provider to generate the response. Coaching content is not used to train third-party models.
- Strava, Concept2, BP2Go, Gluco2Go, and Renpho links — only used if you explicitly connect them, and only to pull your own activity or reading data into your account.
- Email delivery — transactional email (sign-in links, receipts, weekly insights if enabled) is sent through our email provider.
SignalGLP does not sell your data, does not share it with advertisers, and does not use your health records to market to you or anyone else.
Coach memory and how to turn it off
If coach memory is enabled, SignalGLP writes a short nightly summary of your day so the coach can recall patterns over time. You can disable coach memory and delete stored memories at any time from Settings. Weekly insights can be switched off in the same place.
Export and deletion
You own your data. Email support@signalglp.com from your account address to request a full export or permanent deletion of your account and all associated health records. Deletion requests are honored within 30 days, and removing your account removes your rows from the production database.
Reporting a security issue
If you believe you have found a vulnerability, email security@signalglp.com with enough detail to reproduce it. Please give us a reasonable window to fix the issue before disclosing it publicly. Reports are read by a human — there is no bug bounty program at this stage, but responsible reports are genuinely appreciated and credited if you want them to be.
What we do not claim
SignalGLP is not HIPAA-certified, SOC 2-audited, or ISO-certified, and we will not display badges implying otherwise. We are not a covered entity or a medical device. If your situation requires a formal compliance posture, this is the honest answer rather than a reassuring one.
