Haftra

Privacy Policy

Effective: 26 July 2026 · Last updated: 30 July 2026

The short version

  • You can use Haftra without an account. In that mode no health data ever leaves your device.
  • With an account your records are backed up to a private space only you can read; progress photos still stay on the device.
  • No ads, no tracking, no third-party analytics. The app contains no advertising or third-party analytics SDK of any kind. We measure which screens get used on our own server, and that measurement contains none of your health data.
  • We do not sell, rent or share your data for marketing.
  • Your progress photos are never uploaded, under any circumstances.
  • You can permanently delete your account and every record from inside the app.

1. Using Haftra without an account

On first launch you can choose to continue without creating an account. In that mode your injections, weight, side effects, blood glucose readings, daily tracking and settings are stored only in your phone's own storage. That data is never transmitted to us or to any server. Deleting the app deletes it.

2. Data processed when you create an account

If you want your records backed up across devices, or you want to use the anonymous community feature, you can create an account with Apple or with an email address. Only then is the following data processed:

DataWhySource
E-mail address To create your account and verify sign-in The address you enter, or the one Apple provides if you use Sign in with Apple
Your name and gender selection To greet you and, if you choose, provide personal context for body-composition readings (both are optional) Only what you choose in the app. Gender includes a “Prefer not to say” option. We do not take the name Apple offers when you sign in with Apple.
Health records: injections, weight, blood glucose, side effects, daily tracking and treatment settings Backup and sync across your devices What you enter in the app, plus what you import from the Health app

These records are protected in the database by row-level security: technically, only your own session can read your own rows. No other user can query your records.

Progress photos are never uploaded. Even with an account they stay on your device only; they are not part of the backup.

3. Sign in with Apple

When you sign in with Apple, Apple sends us only a user identifier scoped to our app and an email address. That identifier is generated for Haftra alone — you get a different one in another developer's app — so it cannot be used to track you across apps.

4. Technical data kept for session security

Our authentication layer records your IP address and a client identifier containing your app version and operating system version each time you sign in. This is so we can spot unauthorised attempts to reach your account and prevent abuse.

5. The Health app

With your permission, Haftra reads the weight, blood glucose and body-fat measurements you select from the Health app, so you do not have to re-enter what your smart scale or glucose app already recorded. Body-fat access is requested separately from its button on the Progress screen.

6. Anonymous community signals

If you choose to share a side effect with the community, its name, severity and date are recorded alongside your medication. The feature is protected as follows:

To be explicit: your report is stored in the database linked to your account identifier. This is necessary — otherwise one person could skew a summary by reporting the same symptom over and over. The anonymity comes not from the row being identity-free but from that table granting no read access to any user: the app only ever receives aggregated counts, and those counts are grouped to make it harder to infer any individual. No other user can see what you reported.

7. Progress photos

Progress photos are stored on your device only, with file protection enabled. Even with an account, these photos are not synced, not uploaded, and cannot be seen by us.

8. Reminders

Injection, hydration and weigh-in reminders are scheduled on your phone and fire on your phone. We do not use remote (push) notifications, so we hold no notification token for you, and your reminder times are never sent to a server in order to be delivered.

9. PDF and CSV exports

The doctor summary (PDF) and the data export (CSV) are generated on your device and never pass through our servers. The file goes only where you send it; once you share it, what happens to it is between you and whoever you shared it with.

10. Who your data is shared with

We do not sell your data and we do not share it with anyone for marketing. We use a single service provider:

Supabase

Authentication and database infrastructure

When you create an account, your email address, your name, your health records and the side-effect reports you share are held in a PostgreSQL database managed by Supabase. The database is hosted in the European Union (Frankfurt, eu-central-1). Supabase processes this data solely to provide the service.

Usage measurement

On our own server, with no health data in it

So we can see where the app is hard to get through — which setup screen people give up on, for instance — we record short, fixed event names against your account: onboarding_reached_dose, screen_progress, injection_logged and the like. The name, the time it happened and the app version are all that is stored.

What is never stored: your dose, your weight, your symptoms, your notes, your blood glucose, or any text you typed yourself. Event names come from a fixed list inside the app, and the database will only accept a name in that form — so health data cannot be written here even by mistake.

These rows live in the same Supabase project as your health records, on our own infrastructure. They are never sent to a third party and never used for advertising or profiling. If you use Haftra without an account, no events are recorded at all. Deleting your account deletes them too.

Beyond that, no advertising, crash-reporting, tracking or third-party analytics service is used. The app's only third-party dependency is Supabase's official client library.

We may have to disclose data where legally compelled (for example a court order). If such a request arrives we will inform you, unless the law forbids it.

11. Retention and deletion

12. Exercising your rights

Depending on where you live, you may have rights under the GDPR and/or Turkey's Law No. 6698 (KVKK) to access, correct, delete, restrict the processing of, and port your data. For access and deletion the app itself is the fastest route: the data is already visible to you and the delete button is in Settings. For anything else, write to destek@haftra.app.

13. Children

Haftra is intended for tracking a prescribed treatment and is not designed for users under 18. We do not knowingly collect data from anyone under 18.

14. Changes to this policy

If we update this policy we will change the date on this page, and we will notify you in the app for any significant change. You can request the previous version from the support address.

15. Contact

For anything privacy-related:

destek@haftra.app

Medical notice. Haftra is not a medical device. It does not diagnose, treat or recommend any dose, and it does not replace a healthcare professional.