Privacy Policy
Last updated: 2026-07-05 · Version 2026-07-14 · Changelog
1. Our approach: your device first
Peplo is built device-first. Your vials, dose logs, reminder schedules, and preferences are stored on your device — in the iOS app's local storage or your browser's IndexedDB — and the app works without an account.
If you sign in, your stack data (vials, protocols, dose logs, and reminder schedules) syncs to infrastructure we operate so that reminders can be delivered and your data is available across devices (see Sections 3 and 6).
2. Data stored on your device
The following data is stored on your device and is not transmitted to us unless you sign in (which enables sync) or use the Export Data feature:
- Vial inventory (peptide name, mg, reconstitution mL, dates, notes, optional photo)
- Dose logs (vial reference, mcg, units, injection site, timestamp)
- Reminder schedules
- App preferences (unit system, syringe size, theme, onboarding state)
3. Data we collect server-side
We collect a limited set of data on our servers, separated by purpose:
- Account and billing. When you create an account, we receive your email address; Pro subscribers also have a Stripe customer identifier. Payment card details are handled by Stripe and never touch our servers.
- Synced stack data. For signed-in users, vials, protocols, dose logs, and scheduled doses are stored in our database so reminders can be computed and delivered and your data can follow you across devices.
- Push notification tokens. If you enable dose reminders, we store the device push token needed to deliver them (Apple Push Notification service on iOS, Web Push in the browser).
- Analytics events. We log a small set of typed events (e.g.,
scan_completed,protocol_generated,paywall_shown) to help us understand how the Service is used. We do not log personally identifiable information in these events. - Web vitals and error reports. Vercel Analytics collects aggregated performance metrics; uncaught errors may be logged for debugging.
- Optional AI inputs. If you use the vial label scan or lab upload features, the image or document you submit is sent to a third-party AI model (see Section 6) to extract its contents. Submitted files are not retained by us beyond the duration of the request.
4. Apple Health (HealthKit)
On iOS, you can optionally connect Apple Health. If you grant permission, Peplo reads only the metric types you approve (for example weight, body composition, and heart-rate variability) to display your trends alongside your protocol inside the app.
- Health data is never used for advertising or marketing, never sold, and never shared with data brokers.
- Health data is not disclosed to third parties except as necessary to provide the feature you requested, and never without your consent.
- You can revoke access at any time in iOS Settings → Health → Data Access & Devices, and remove imported values with the Clear All Data action in Settings.
5. Cookies and local storage
Peplo uses browser and app storage (cookies, IndexedDB, localStorage) for the following purposes:
- Authentication session tokens and client-side rate limiting.
- Theme and preference state.
- PostHog and Vercel Analytics may set first-party cookies for session continuity.
We do not use third-party advertising cookies or sell information to advertisers.
6. Third-party subprocessors
We rely on the following service providers. Each handles only the data necessary for its function and is contractually bound to confidentiality.
- Supabase — authentication and the sync database for signed-in users.
- Stripe — payment processing, billing management. Subject to Stripe's Privacy Policy.
- Anthropic — large-language-model inference for optional AI features. Anthropic does not train on customer data sent through the API.
- OpenAI — vision-model inference for the optional vial-label scan feature.
- OneSignal — push notification delivery for dose reminders. Receives the device push token and an internal account identifier (never your email or health data).
- Apple — final push notification delivery (APNs) on iOS.
- Vercel — hosting, edge runtime, and aggregated Web Vitals metrics.
- PostHog — product analytics events.
- Upstash — Redis-backed rate limiting and push subscription storage.
7. How we use data
We use the limited data we collect to:
- Operate, maintain, and improve the Service.
- Authenticate users and process payments.
- Compute and deliver the dose reminders you schedule.
- Detect and prevent abuse, fraud, or rate-limit violations.
- Communicate with you about your account, security, and material changes to the Service.
- Comply with legal obligations.
8. How we do not use data
We do not sell or rent your personal information. We do not share your data with advertisers. We do not use your protocol library, dose logs, health data, or other journal-style content to train AI models. Peplo does not sell or source peptides and has no commercial interest in what you choose to run.
9. Data retention
On-device data persists until you delete it (via the Clear All Data action in Settings, by deleting the app, or by clearing site data in your browser).
Server-side account data is retained while your account is active. Upon account deletion, we delete your personal data within thirty (30) days, except where retention is required by law (e.g., tax records for completed transactions).
10. Your rights (GDPR / CCPA / similar)
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated personal data.
- Export your data in a portable format (see the Export Data feature in Settings).
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at support@peplo.health. We will respond within thirty (30) days.
11. Children's privacy
The Service is not intended for children under the age of eighteen (18). We do not knowingly collect personal information from minors. If you believe a minor has provided us personal information, contact us at support@peplo.health and we will delete it promptly.
12. Security
We use industry-standard administrative, technical, and physical safeguards to protect data we hold on our servers, including TLS encryption in transit, encrypted storage at rest, and principle-of-least-privilege access controls. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you in accordance with applicable law.
13. International transfers
Our servers and subprocessors are located in the United States and the European Union. If you access the Service from another jurisdiction, your data may be transferred to, stored in, and processed in these locations. By using the Service, you consent to such transfers.
14. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in the Service or via email at least fourteen (14) days before they take effect. The "Last updated" date at the top of this policy reflects the most recent revision.
15. Contact
Questions, concerns, or requests about this Privacy Policy should be directed to support@peplo.health. If you are in the EU and wish to lodge a complaint with a supervisory authority, you may do so with the data protection authority in your country of residence.