Privacy Policy
Last updated: 2026-08-20 · Version 2026-08-07 · Changelog
1. Our approach: your device first
Peplo is built device-first. Your vials, dose logs, reminder schedules, and preferences are stored on your device — in the iOS app's local storage or your browser's IndexedDB — and the app works without an account.
If you sign in, your stack data (vials, protocols, dose logs, and reminder schedules) syncs to infrastructure we operate so that reminders can be delivered and your data is available across devices (see Sections 4 and 7).
2. Who we are and our role
Peplo is operated by Peplo Health LLC, a New Jersey limited liability company. Under the New Jersey Data Privacy Act (the "NJDPA") and comparable state privacy laws, we are the controller of the personal data described in this policy — we determine what personal data is collected and why.
The service providers listed in Section 7 act as processors: they process personal data only on our documented instructions, for the purposes we specify, under written agreements that require confidentiality, security safeguards, and deletion or return of the data at the end of the engagement. They are not permitted to use your data for their own purposes.
You can reach us about anything in this policy at support@peplo.health. That address is monitored and is the mechanism you should use to exercise the rights described in Section 11.
3. Data stored on your device
The following data is stored on your device and is not transmitted to us unless you sign in (which enables sync) or use the Export Data feature:
- Vial inventory (peptide name, mg, reconstitution mL, dates, notes, optional photo)
- Dose logs (vial reference, mcg, units, injection site, timestamp)
- Reminder schedules
- App preferences (unit system, syringe size, theme, onboarding state)
4. Data we collect server-side
We collect a limited set of data on our servers, separated by purpose:
- Account and billing. When you create an account we collect your email address and your first and last name. You may optionally provide a phone number; it is not required, and you can create and use an account without one. Pro subscribers also have a Stripe customer identifier. Payment card details are handled by Stripe and never touch our servers.
- How we hold your name and phone number. These are stored in a single table in our database, readable only by you: access is enforced at the database level so that one account cannot read another's details. We do not sell them, we do not share them with advertisers, and they are stripped from analytics before any event leaves your device (see below). If you delete your account, they are deleted with it — see Section 9.
- What providing a name means, stated plainly. Before you give us a name, the health information described below sits under an email address. After, it sits under a name. That makes the data identified rather than pseudonymous, and it is a real change in what a breach or a lawful demand would expose. We ask for it so the Service can address you like a person rather than an inbox; you can ask us to correct or erase it at any time under Section 9.
- Phone numbers are not used to contact you today. We collect one only if you offer it, and we currently send no SMS of any kind — the field exists for dose reminders by text message, which we have not built yet. Until we do, a number you provide is stored and otherwise unused. If we begin sending texts, we will update this policy first and reminders will remain opt-in.
- Synced stack data. For signed-in users, vials, protocols, dose logs, and scheduled doses are stored in our database so reminders can be computed and delivered and your data can follow you across devices.
- Health and wellness data you choose to enter. Subjective check-ins, side-effect logs, body-composition measurements, uploaded lab or DEXA results, and metrics you import from Apple Health or a connected wearable. This is sensitive data under the NJDPA — see Section 11.
- Push notification tokens. If you enable dose reminders, we store the device push token needed to deliver them (Apple Push Notification service on iOS, Web Push in the browser).
- Analytics events. We log a small set of typed events (e.g.,
scan_completed,protocol_generated,paywall_shown) to help us understand how the Service is used. We do not log personally identifiable information in these events, and we strip a denylist of identifying and health-revealing fields before any event leaves your device. - Web vitals and error reports. Vercel Analytics collects aggregated performance metrics; uncaught errors may be logged for debugging.
- Optional AI inputs. If you use the vial label scan or lab upload features, the image or document you submit is sent to a third-party AI model (see Section 7) to extract its contents. Submitted files are not retained by us beyond the duration of the request.
5. Apple Health (HealthKit)
On iOS, you can optionally connect Apple Health. If you grant permission, Peplo reads only the metric types you approve (for example weight, body composition, and heart-rate variability) to display your trends alongside your protocol inside the app.
- Health data is never used for advertising or marketing, never sold, and never shared with data brokers.
- Health data is not disclosed to third parties except as necessary to provide the feature you requested, and never without your consent.
- You can revoke access at any time in iOS Settings → Health → Data Access & Devices, and remove imported values with the Clear All Data action in Settings.
6. Cookies, local storage, and opt-out signals
Peplo uses browser and app storage (cookies, IndexedDB, localStorage) for the following purposes:
- Authentication session tokens and client-side rate limiting.
- Theme and preference state.
- PostHog and Vercel Analytics may set first-party cookies for session continuity.
We do not use third-party advertising cookies, do not sell information to advertisers, and do not run targeted advertising.
Universal opt-out mechanisms. Peplo honors browser-level opt-out signals, including Global Privacy Control (GPC) and Do Not Track. When we detect one of these signals, the Service does not load optional product analytics or web-vitals measurement at all for that browser or device. No action is required from you beyond enabling the signal in your browser or extension, and we do not ask you to re-consent afterwards. See Section 11 for how this satisfies the NJDPA's universal opt-out requirement.
7. Processors and the categories of third parties we disclose to
We rely on the following service providers. Each is a processor acting on our instructions, handles only the data necessary for its function, and is contractually bound to confidentiality.
- Supabase (authentication and database) — authentication and the sync database for signed-in users. Receives your email address and your synced stack and health data.
- Stripe (payment processor) — payment processing and billing management. Receives your email address and payment details; receives no health data. Subject to Stripe's own privacy policy.
- Anthropic (AI inference) — large-language-model inference for optional AI features. Receives the inputs you submit to those features and relevant protocol context; receives no email address, credentials, or payment data. Anthropic does not train on customer data sent through the API.
- OpenAI (AI inference) — vision-model inference for the optional vial-label scan feature. Receives only the image you submit.
- OneSignal (push notification delivery) — receives the device push token and an internal account identifier, never your email or health data.
- Apple (push notification delivery) — final push delivery (APNs) on iOS.
- Vercel (hosting and infrastructure) — hosting, edge runtime, and aggregated Web Vitals metrics.
- PostHog (product analytics) — typed product analytics events. Receives no email address, no free-text notes, and no biomarker, dose, or route values.
- Upstash (infrastructure) — Redis-backed rate limiting and push subscription storage.
We may also disclose personal data to legal and professional advisers, or to a government authority, where we are required to do so by law or valid legal process, and to an acquirer in connection with a merger, acquisition, or sale of assets (in which case this policy continues to apply until you are given notice of any change).
8. How we use data
We use the limited data we collect to:
- Operate, maintain, and improve the Service.
- Authenticate users and process payments.
- Compute and deliver the dose reminders you schedule.
- Display your own trends, analytics, and AI-generated summaries back to you.
- Detect and prevent abuse, fraud, or rate-limit violations.
- Communicate with you about your account, security, and material changes to the Service.
- Comply with legal obligations.
We do not process personal data for any purpose that is not reasonably necessary to, and compatible with, the purposes listed above without first obtaining your consent.
9. How we do not use data
We do not sell your personal data, and we have not sold personal data in the preceding twelve (12) months. We do not process personal data for targeted advertising. We do not use profiling to make decisions that produce legal or similarly significant effects concerning you. We do not share your data with advertisers or data brokers.
We do not use your protocol library, dose logs, health data, or other journal-style content to train AI models. Peplo does not sell or source peptides and has no commercial interest in what you choose to run.
10. Data retention
On-device data persists until you delete it (via the Clear All Data action in Settings, by deleting the app, or by clearing site data in your browser).
Server-side account data is retained while your account is active. Upon account deletion, we delete your personal data within thirty (30) days, except where retention is required by law (e.g., tax records for completed transactions).
11. New Jersey Data Privacy Act
This section applies to New Jersey residents acting in an individual or household context and is provided under the New Jersey Data Privacy Act, N.J.S.A. 56:8-166.4 et seq. We apply it as our baseline for all users, regardless of where you live and regardless of whether we meet the NJDPA's processing thresholds in a given year.
Categories of personal data we process.
- Identifiers — email address, internal account identifier, Stripe customer identifier, device push token.
- Sensitive data — data revealing a mental or physical health condition, treatment, or diagnosis: your vials, protocols, dose logs, side-effect and check-in entries, body-composition measurements, uploaded lab or imaging results, and any metrics you import from Apple Health or a wearable.
- Commercial data — subscription tier, billing interval, and purchase history.
- Technical and usage data — device and browser information, aggregated performance metrics, and typed product analytics events that carry counts, flags, and normalized compound slugs only.
- Content you submit to AI features — questions, uploaded vial-label images, and uploaded lab documents.
Purposes of processing. Each category is processed only for the purposes listed in Section 8. The categories of third parties we may disclose personal data to, and the specific categories each receives, are itemized in Section 7.
Sensitive data and consent. Peplo processes health data only after you affirmatively choose to provide it — by entering a vial, logging a dose, completing a check-in, uploading a lab result, or granting Apple Health or wearable permissions. We ask separately for each source, we do not pre-check those choices, and we do not use interface designs intended to obscure or subvert your decision. You may withdraw consent at any time by disconnecting the source, deleting the data in the app, or using Clear All Data in Settings; withdrawal is as easy as granting consent and does not affect processing that already occurred.
No sale, targeted advertising, or significant-effect profiling. As stated in Section 9, we do not sell personal data, process it for targeted advertising, or profile you in furtherance of decisions producing legal or similarly significant effects. Because we do none of these things, there is no such processing for you to opt out of.
Universal opt-out mechanism. Consistent with the NJDPA's universal opt-out requirement (effective July 15, 2025), Peplo recognizes user-selected opt-out signals, including Global Privacy Control (GPC) and Do Not Track, sent by your browser, an extension, or your device. We apply the signal automatically, without authentication and without asking you to confirm. In practice it disables all optional product analytics and web-vitals measurement for that browser or device; it does not disable the storage strictly necessary to sign you in, keep your preferences, or deliver the reminders you scheduled.
Your rights. Subject to verification, you have the right to:
- Confirm whether we process your personal data, and access that data.
- Correct inaccuracies in your personal data.
- Delete personal data concerning you.
- Obtain a copy of your personal data in a portable, readily usable format (see the Export Data feature in Settings).
- Opt out of the sale of personal data, processing for targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects.
How to exercise them. Email support@peplo.health with the subject line Privacy Request. We will respond within forty-five (45) days. Where reasonably necessary because of the complexity or volume of requests, we may extend that period once by a further forty-five (45) days and will tell you why within the first period. Requests are free up to once per twelve-month period. We may ask for information sufficient to verify that the request is yours; if we cannot authenticate it, we will tell you and may decline to act. You may use an authorized agent, in which case we may require proof of your written authorization.
Appeals. If we refuse to act on your request, our response will explain why and how to appeal. To appeal, reply to that response or email support@peplo.health with the subject line Privacy Appeal. We will respond in writing within sixty (60) days, explaining the reasons for our decision. If we deny the appeal, that response will also give you a method to contact the New Jersey Division of Consumer Affairs to submit a complaint — you can reach the Division directly at njconsumeraffairs.gov.
Minors. The Service is restricted to users eighteen (18) and older (see Section 13), so we do not knowingly process the personal data of any consumer under eighteen. We therefore never sell, target-advertise to, or profile a consumer we know or suspect to be between thirteen (13) and seventeen (17) years of age.
Material changes. The process by which we notify you of material changes to this policy, and the effective date of each version, are set out in Section 17.
12. Rights in other jurisdictions
If you are covered by the EU/UK GDPR, the California Consumer Privacy Act, or another comprehensive privacy law, you may have rights comparable to those in Section 11 — including access, correction, deletion, portability, objection to or restriction of certain processing, and withdrawal of consent. Use the same contact route in Section 11 and tell us which law you are relying on.
Where a right in this section conflicts with a right in Section 11, we apply whichever is more protective of you.
13. Children's privacy
The Service is not intended for children under the age of eighteen (18). We do not knowingly collect personal information from minors. If you believe a minor has provided us personal information, contact us at support@peplo.health and we will delete it promptly.
14. Security
We use industry-standard administrative, technical, and physical safeguards to protect data we hold on our servers, including TLS encryption in transit, encrypted storage at rest, and principle-of-least-privilege access controls. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you in accordance with applicable law.
HIPAA. Peplo Health LLC is not a covered entity or business associate under HIPAA, and the health data you enter into Peplo is not protected health information under that law. We nonetheless apply HIPAA-aligned administrative, technical, and physical safeguards to health data as a matter of policy, and we treat that data as sensitive data under Section 11.
15. International transfers
Our servers and subprocessors are located in the United States and the European Union. If you access the Service from another jurisdiction, your data may be transferred to, stored in, and processed in these locations. By using the Service, you consent to such transfers.
16. Governing law
This Privacy Policy is governed by the laws of the State of New Jersey, without regard to its conflict-of-laws rules. Any dispute arising out of or relating to this policy is subject to the dispute-resolution provisions in Section 17 of the Terms of Service, which require binding individual arbitration before the American Arbitration Association seated in New Jersey and place every dispute not subject to arbitration in the exclusive jurisdiction of the state and federal courts located in New Jersey.
Nothing in this section limits your right to exercise the rights in Section 11, to appeal a denial, or to complain to the New Jersey Division of Consumer Affairs, a state attorney general, or any other supervisory authority with jurisdiction over you. Those routes are unaffected by the arbitration agreement.
17. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in the Service or via email at least fourteen (14) days before they take effect. The "Last updated" date at the top of this policy reflects the most recent revision, and every revision is recorded with its effective date in the legal changelog.
18. Contact
Questions, concerns, or requests about this Privacy Policy should be directed to support@peplo.health, which is the active electronic mail address we maintain for this purpose. New Jersey residents may also contact the New Jersey Division of Consumer Affairs. If you are in the EU and wish to lodge a complaint with a supervisory authority, you may do so with the data protection authority in your country of residence.