My GLP Shot, a privacy-first injection tracker.
My GLP Shot is a privacy-first GLP-1 and peptide injection tracker: an installable PWA with end-to-end encrypted cloud sync. All cryptography runs in the browser, and the server only ever sees opaque ciphertext, never the data itself.
Repo stats
Live hourly, from the local checkout and the GitHub API.
Why I built it
Injection and dosing data is sensitive, so I built My GLP Shot so the server never gets to read it. All cryptography runs in the browser: the master password derives both an authentication key and an encryption key, Bitwarden-style, so the server only ever holds opaque ciphertext and auth hashes. Forget the password and the cloud copy is unrecoverable by design, because there is nothing on the server that could decrypt it, only the local data on the device survives.
[Why I built My GLP Shot specifically, in my words]
What it does
- Body-diagram injection mapping and a dose heatmap.
- Weight and mood tracking, streaks.
- A reconstitution calculator for dosing math.
- Doctor share links and PDF export (Premium).
- Multi-device sync, supply tracking, body measurements, lab tracking and plateau detection (Premium).
- Installable as a PWA, works offline, single-device cloud backup on the free tier.
Stack and architecture
The frontend is vanilla HTML, CSS and JavaScript with Chart.js and IndexedDB, no framework and no build step. The backend is Python 3.11 and Flask with SQLite, containerized via Docker. Cryptography is PBKDF2-SHA-256 at 600,000 iterations plus AES-GCM 256, entirely client-side through the Web Crypto API. It's hosted behind nginx and Cloudflare.
Status
Live at myglpshot.com, free tier plus $1.99/month or $19.99/year Premium with a 14-day free trial. MIT licensed.