Version 1.1Effective 7 September 2026

Privacy Policy

Lagom is a log-keeping app for people using GLP-1 medication. This page describes exactly what it stores, who can read it, and how to get rid of it.

The short version

Lagom stores the health facts you choose to log so that it can show them back to you. Your health data is readable by your account and by nobody else's. We do not sell it, we do not share it with advertisers or use it for advertising of any kind, and we do not use it to train models. Lagom does not give medical advice.

Who is responsible

The data controller is KodBerry Solutions AB (org. nr 559468-5454), Småbjörksvägen 27, 163 42 Spånga, Stockholm, Sweden — “KodBerry” below — operating Lagom. For any privacy question, or to exercise any right described below, contact contact@trylagom.app. You can also send a message from the app, under Profile → Help & Support.

What we store

Account. Your email address, the name you give us, and an optional profile photo. Email addresses are held by our authentication provider so we can sign you in — with an emailed code, or with a password if you set one (stored only as a salted hash, never readable by anyone).

Health data you log (special-category data). Only what you enter:

  • Onboarding answers — the questions asked when you first set up the app. Until you sign in, these live only on your device; they sync when you create an account, and the on-device copy is then cleared.
  • Body and profile facts — date of birth, height, gender, time zone, and your unit preferences.
  • Health profile — any conditions you select from a fixed list, and free-text allergies and other medications.
  • Medication plan — medication, dose, how often you take it, whether it is an injection or a tablet, and the date you started.
  • Doses — when you took each one, the dose, the injection site, your weight at the time if recorded, and any note.
  • Weight entries — the value, the date, an optional note, and an optional progress photo.
  • Water entries — volume and time.
  • Activity — daily step counts you type in, and workouts (type, duration, and the calorie estimate computed when you log one). Lagom does not read steps from your phone or watch; there is nothing here you did not type.
  • Symptoms — which symptom, an intensity from 1 to 5, when, and any note.
  • Goals — your water, steps and goal-weight targets, if you set them.
  • Daily check-ins — how you felt that day (fine, or had symptoms) and, if you answer the optional questions, whether you were hungry, whether you drank alcohol, and whether you ate late.

Support messages.The text you send through Help & Support, plus the app version, so we can reproduce what you saw. A support message cannot be edited or deleted after sending; it is removed when your account is.

Operational records. Our servers keep technical logs of requests and sign-ins — account identifiers, timestamps, and the network addresses involved — to run, secure and debug the service. Your health entries are never written to those logs.

What we do not collect

Lagom does not collect location, contacts, health data from Apple Health or Google Fit, advertising identifiers, or device fingerprints. The mobile app requests only three permissions, each tied to something you asked for: camera and photo library so you can add photos yourself, and notifications if you turn reminders on. Reminders are scheduled entirely on your device — your reminder times and notification settings never reach our servers. There are no analytics, advertising or session-recording tools in the app or this portal — nothing to opt out of, because nothing is there.

Photos

Progress photos are optional. They are stored in a private bucket, filed under your account, and are never served from a public address — the app fetches them through signed links that expire within an hour. Nobody browsing the internet can reach them, and no other Lagom user can read them.

Your profile photo is different: it is stored at a public address, like an avatar on most services, so anyone who has its exact link can fetch it. The link is not guessable and is not listed anywhere, but do not use a profile photo you would not show to another person.

Sharing a report

You can create a link that lets someone — typically your clinician — view one report about you without signing in. This is the only way any health data ever leaves your account, and it only happens because you created the link.

  • The report shows your name, date of birth, medication and dose history, weight, symptoms, hydration, and the conditions, allergies and other medications from your health profile, for the period you chose when you created it. That period is frozen — the link can never grow to show more.
  • Anyone who holds the link can open the report until it expires. Links expire after at most 30 days — the limit is enforced by the database itself — and you can revoke one early in the app.
  • The app shows you how many times a link has been opened and when it was last opened, so you can see whether your clinician read it and notice if a link has leaked. We do not record who opened it.

Who can read your data

Access is enforced by the database itself, using row-level security, rather than by application code that could forget to check. Every health record carries your account id, and every policy on those tables requires that id to equal the signed-in user's.

  • You — through the app and this portal.
  • Other users— never. Team and shared-workspace features exist in the underlying platform but no Lagom health table consults them, deliberately, so a shared workspace can never become a route to somebody's medical history.
  • Whoever holds a share link you created — that one report, until the link expires or you revoke it.
  • Our support staff — only the support messages you send us, alongside your account name and email. Our administrative tools cannot read doses, weight, water, symptoms or your onboarding answers. Your onboarding answers are the most tightly held table we have: even our server-side service credentials hold no privileges on it.
  • Infrastructure — the processors listed below, under contract, to run the service.

If you enable two-factor authentication, your health records become unreadable until you have completed the second factor, on the web and in the app alike.

Where your data lives, and who processes it

Your data is stored with Supabase in the European Union, in a data centre in Stockholm, Sweden (AWS eu-north-1). That is where it lives for every user, wherever in the world you use Lagom from. The processors that handle it for us:

  • Supabase — database, authentication, and file storage. This is where your data lives.
  • Resend — sending sign-in codes and other transactional email.
  • Apple and Google — app distribution, under their own privacy policies.

Some of these companies are based in the United States, so limited personal data — an email address to deliver a sign-in code — can be transferred outside the European Economic Area. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses in our agreement with the processor, or by the processor's certification under the EU–US Data Privacy Framework. Your health records themselves stay in the Stockholm database.

Lagom currently ships no third-party analytics, advertising or session-recording software. Should that change, this list changes first, with a new version of this page.

What we never do

  • Sell your data, or share it with data brokers or advertisers.
  • Use your health data for advertising or marketing of any kind, in Lagom or anywhere else.
  • Use your health data to train machine-learning models.
  • Give you medical advice. Lagom shows your own data back to you, and offers general educational information with its source named. It does not diagnose, does not recommend doses, and is not a substitute for your clinician.

Cookies

This portal sets only the cookies it needs to work: one that keeps you signed in, and small preference cookies remembering your language, your colour theme, and whether the sidebar is open. There are no advertising or tracking cookies, so there is nothing here to consent to or opt out of. Clearing them signs you out.

The mobile app uses no cookies at all.

Legal basis

Where the GDPR applies: we process your account data because it is necessary to perform our contract with you (Article 6(1)(b)), and operational logs on our legitimate interest in keeping the service secure and working (Article 6(1)(f)). Your health data is special-category data, and we process it on the basis of your explicit consent (Article 9(2)(a)), which you give when you choose to log it. You can withdraw that consent at any time — delete the entry, or delete your account — and withdrawal does not affect the lawfulness of processing before it.

How long we keep it

We keep your data for as long as your account exists, and no longer:

  • Delete an entry and it is gone immediately.
  • Share links expire after at most 30 days regardless, and die with your account.
  • Delete your account and every record described above — health entries, photos, support messages — is removed at once. Database backups kept by our hosting provider roll off on their own schedule, within 30 days.

Deleting your account

Deletion is built into the app: Profile → Account → Delete account. It removes your progress photos from storage first, then the account itself, and every health record cascades away with it. Nothing is retained, and nothing needs our approval — the button does the whole job. If you cannot reach the app, email contact@trylagom.app from your account's address and we will delete it for you.

Your rights

You can see everything Lagom holds about you inside the app and in this portal, correct any of it by editing the entry, and delete your account as described above. If you would rather have a copy as a file — the GDPR calls this portability — or want anything else erased, email us and we will do it. Where the GDPR applies you also have the right of access, to object, to restrict processing, and to withdraw consent at any time.

You also have the right to lodge a complaint with a supervisory authority. Ours is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se; if you live elsewhere in the EEA you can complain to your own national authority instead.

For users in the United States

Lagom is not a healthcare provider, health plan or clearinghouse, and is not a “covered entity” or “business associate” under HIPAA — the data you log here is not “protected health information” in HIPAA's sense. It is protected as this policy describes, which applies to every user regardless of country.

Children

Lagom is not for people under 18, and the app only offers dates of birth at least 18 years back. If you believe a child has created an account, tell us and we will remove it.

Changes to this policy

This page carries a version number and an effective date. Material changes get a new version and notice in the app before they take effect.

See also the Terms of Use.