Fortly Consumer Health Data Privacy Policy

Effective date: September 29, 2026 ยท Last updated: September 2026

This policy explains how Fortly handles consumer health data, as Washington's My Health My Data Act, Nevada's consumer health data law and Connecticut's Data Privacy Act define it. Fortly is made by Wavista Apps, operated by William Tsao.

What we collect, and why

  • What you log, on your iPhone only. Your medication form and name, dose schedule, doses, dose labels and injection sites, weights and goal weight, activity level, protein and water goals, meals and meal photos, water, symptom check-ins and notes, and your weight from Apple Health if you turn it on. The app saves and processes these on your iPhone. They are never sent to us. Purpose: to show your logs, insights, reminders and the report you choose to make.
  • A meal photo and any note you add, only when you allow AI analysis and ask for an estimate. Purpose: to estimate the food in the photo. Our server holds them in memory during the estimate and does not store them.
  • That you use Fortly, tied to an anonymous ID: your subscription status, and our server's request records under a scrambled form of that ID. Using a GLP-1 app could suggest that you take a GLP-1 medication. Purpose: to provide your subscription, apply daily limits and measure how accurate estimates are.
  • Usage events, only if you turn on Share usage data: opening the app, the screens you see during setup and at the subscription offer, and that you logged a meal, never what you logged. Purpose: to find problems and improve the app.

We do not use consumer health data for any other purpose. We do not use it, or any other personal data, to train large language models or other AI models.

Where it comes from

From you, from your use of the app, from Apple Health if you turn it on (this stays on your iPhone), and from RevenueCat (your subscription status).

Who we share it with

We do not sell consumer health data, and we do not share it with anyone except these service providers, which process it only for us, under contract:

  • OpenAI: the meal photo and note, to make the estimate;
  • Fly.io and Supabase: our server and its database;
  • Cloudflare R2: encrypted backups of that database, which only we can read;
  • RevenueCat: your subscription;
  • PostHog: usage events, only if you turn on Share usage data;
  • Sentry: crash reports, with the values you log removed.

We have no affiliates. No third party collects your data across other apps or websites through Fortly.

Your rights

You can ask us to confirm whether we collect, share or sell your consumer health data, to get a copy of it with the list of everyone we shared it with and how to contact them, and to delete it. You can withdraw your consent at any time. You can review and change your logs in the app at any time.

  • To delete everything on your iPhone and withdraw your consent, use Settings, Delete my data. It also asks our server to delete what it holds. Encrypted database backups made before then are deleted automatically within 35 days.
  • To stop meal photos or usage events being sent, turn off Use AI analysis or Share usage data in Settings, Privacy.
  • For any other request, email [email protected] from Contact support in the app, so the email includes the anonymous ID we need to find your data.

We reply within 30 days. If a request is complex and we need more time, we tell you within those 30 days and reply within 45 more days. Requests are free up to twice a year.

Appeals

If we turn down your request, you can appeal by replying with "Appeal" in the subject line. We answer in writing within 45 days. If we deny your appeal, you can contact the Attorney General of Washington, Nevada or Connecticut, and our answer will tell you how.

Changes to this policy

We post the new version on this page with a new date. Before we collect a new category of consumer health data, or use it for a new purpose, we ask for your consent in the app.

Contact

[email protected]

Back to top