System notice:We're temporarily pausing new orders for scheduled maintenance. Please bear with us — we'll be back shortly. Your existing subscription and medication schedule are unaffected.

Online Tracking Technologies

Last updated: February 2026 · Disclosure required by HHS OCR 2024 Online Tracking Technology Bulletin

Plain-language summary

We use a small number of third-party tools to keep the site working and to help us measure anonymous usage patterns. We never share your name, email, date of birth, medical history, weight, prescriptions, or any other Protected Health Information (PHI) with any tracker, advertising network, or social-media platform. We do not run advertising pixels (no Meta Pixel, no Google Ads, no TikTok Pixel, no LinkedIn Insight Tag).

Trackers we use

Necessary (always on)

Strictly necessary

Why we use it: Login session cookies + CSRF token. Required for the site to work — there's no opt-out, but they only live in your browser and contain no PHI.

What it receives: Authentication token (random string), tab session id (random string). Nothing identifying.

How to opt out: Not applicable — cookies are deleted when you log out or clear your browser.

PostHog (product analytics)

Analytics — REQUIRES YOUR CONSENT

Why we use it: Anonymous page-view counts and feature-usage metrics that help us improve the product.

What it receives: A one-way SHA-256 hash of your account id (we cannot reverse it), your role (patient / admin / prescriber / etc), the page path with all URL parameters stripped, and a coarse-grained event name (e.g. 'checkout_started'). Configured with: autocapture OFF, session recording OFF, IP address OFF, masked inputs ON. We have manually blocklisted $ip and $referrer.

How to opt out: Decline 'analytics' in the cookie banner, or open it again from the footer and toggle off.

Sentry / GlitchTip (error monitoring)

Necessary for service reliability

Why we use it: When the site crashes, we record the JavaScript stack trace so we can fix the bug.

What it receives: The error message, the file/line where it happened, the page URL (with all query parameters stripped), and your browser version. We run a PHI scrubber that redacts anything that looks like an email, phone, address, dose number, or weight before the error is sent.

How to opt out: Sentry only fires on actual errors and never receives PHI by design. If you want it fully off, decline analytics in the cookie banner — Sentry's PII features are also gated by that toggle.

What we do NOT do

  • We do not run Meta Pixel, Google Ads tag, TikTok Pixel, LinkedIn Insight, X/Twitter Pixel, or any advertising tracker.
  • We do not record your session video, capture form input values, or send mouse-movement data to any third party.
  • We do not share PHI with chat widgets, marketing tools, A/B test tools, or heat-map providers.
  • We do not sell, rent, or trade your data with any third party — full stop.

Change your mind

You can re-open the consent banner any time by clearing your browser's localStorage for this site, or by emailing us at the address below.

Request data removal

To delete or export your tracking-tool footprint, email privacy@glpflo.org with the subject line “Tracking data removal”. We respond within 30 days (HIPAA §164.524 / §164.526).

We respect your privacy.

We use cookies for essential site functionality (always on), and — only with your permission — for product analytics that help us improve your experience. We do not use advertising trackers and we never share Protected Health Information with third-party trackers. Privacy policy · Online tracking disclosure