Skip to content

Consumer Health Data Privacy Policy

Effective Date: September 22, 2026
Contact: help@peptade.com


This policy is a supplement to the Peptade Privacy Policy (https://www.peptade.com/privacy). It is published as a separate document because laws such as the Washington My Health My Data Act, Nevada Senate Bill 370, and the consumer-health-data provisions of the Connecticut Data Privacy Act require one, and it describes the same practices in the terms those laws use. Where this policy and the Privacy Policy overlap, they say the same thing; where they appear to differ, the more protective statement applies.


1. Scope and Who We Are

This Consumer Health Data Privacy Policy explains how Peptade ("we", "our", "us") collects, uses, shares, and protects consumer health data through the Peptade mobile application ("App"). It applies to everyone who uses the App, and it sets out the rights that residents of Washington, Nevada, Connecticut, and any other jurisdiction with a consumer-health-data law can exercise.

Peptade is a personal tracking, record-keeping, and education tool for people who have chosen to research or use peptides. Peptade is not a healthcare provider, is not a medical device, and is not a "covered entity" or "business associate" under HIPAA. For questions about this policy, contact us at help@peptade.com.

2. What "Consumer Health Data" Means Here

"Consumer health data" is personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health status. In Peptade that includes information you enter, upload, scan, import, or generate that describes your body, your health goals, your use of any compound, or your health-related habits, and any biometric data derived from your facial photo. It also includes information that could reveal that you use a health-related app or feature.

3. Consumer Health Data We Collect

Depending on the features you use, we may collect the following consumer health data. Every category is optional in the sense that you can decline to use the feature that produces it.

  • Profile and goals: age / date of birth, gender, height, weight, activity level, physique level, self-reported improvement goals, peptide experience level, skin and hair inputs, sleep quality, daily step goal, and typical bedtime.
  • Facial photo and biometric data: a single front-facing selfie you provide to run the personalized stack generator, and the facial geometry and characteristics derived from it. See the Privacy Policy, Section 4A, for the biometric-specific terms.
  • Personalized stack: the compounds listed for you, their regulatory tier, the rationales, and your stack history, together with the profile answers used to generate them.
  • Compound, dosing, and inventory data: the compounds you track (catalog or custom), dose amounts and units, dosing mode, titration schedules, doses per day, cycle patterns and dates, total and remaining amounts, bacteriostatic water volume, reconstitution date, half-life and peak-time values, and free-text notes.
  • Dose and injection logs: when you log a dose, the compound, amount, unit, and time, and — optionally — the injection site, body side, an approximate on-body location you tapped on a body map, a pain level, and notes.
  • Nutrition data: food entries, portion estimates, calories, macronutrients and micronutrients, saved foods and meals, and your nutrition goals. Meal, menu, and barcode photos are used for identification and are not stored as images.
  • Sleep, hydration, exercise, and body-weight data: bedtime, wake time, sleep duration, self-rated sleep quality, the derived Sleep Score and deep-sleep estimate; water logged and your hydration goal; workouts, exercises, and sets and the derived muscle-recovery map; and weight entries.
  • Activity data from Apple Health (iOS only): steps, active and basal energy, exercise minutes, distance, heart-rate metrics, sleep, weight, hydration, and dietary energy — only if you connect Apple Health, and only the types you authorize. There is no health-platform integration in the Android App.
  • AI assistant conversations: the messages you send to the in-app assistant, together with the snapshot of your own in-app data that is sent with them so the assistant can answer in context.
  • Certificate of Analysis records: documents you attach to a compound, the fields recorded from them, the batch numbers you type from your vials, your own answer to whether they match, and the contents of any code you scan from packaging. These reveal which compounds you track.
  • Side-effect and wellness log: symptoms, energy, mood, and notes you enter. These are stored on your device only and are not uploaded to our servers.
  • Product-usage events: first-party analytics events, associated with your account identifier, that record which screens and features you used. Some of these reveal that you used a health-related feature — for example, that you logged a dose, generated a stack, or viewed a compound's page, including which compound. They never include the values you entered.

4. Where Consumer Health Data Comes From

We collect consumer health data directly from you (what you type, tap, photograph, or upload), from your use of the App (logs, events, and the results the App derives from what you entered, such as a Sleep Score), and from Apple Health, only if you connect it and only for the data types you authorize. We do not buy consumer health data, do not obtain it from data brokers, and do not infer health conditions about you from other sources.

5. Why We Collect and Use It

We collect and use consumer health data only for the following purposes:

  • To provide the features you use: compound and dose tracking, injection-site history, reminders, the research library, the personalized stack, the AI assistant, the calculators, nutrition, sleep, hydration, exercise and body-weight tracking, Certificate of Analysis record-keeping, and Apple Health sync.
  • To personalize those features to you: for example, matching the catalog to the goals you selected, or letting the assistant answer using your own logged data.
  • To keep the App working and secure: detecting fraud and abuse, rate-limiting the AI services, diagnosing crashes and errors, and understanding which features are used so we can improve them.
  • To meet legal obligations and to establish, exercise, or defend legal claims.

We do not use consumer health data for advertising, for marketing to you, to build profiles for anyone else, to make decisions about your eligibility for anything, or to sell to anyone. We do not use it for medical diagnosis, clinical assessment, or health-risk evaluation. AI providers process it in real time to return a result and do not retain it or train on it under our processing arrangements with them.

6. How It Is Stored and Transmitted

  • On your device: the App keeps a local copy of your tracking data so screens load instantly and work offline. Authentication tokens are held in the device's secure storage (iOS Keychain or Android Keystore). The side-effect and wellness log exists only on your device.
  • On our servers: your account data is stored on Supabase infrastructure (hosted on Amazon Web Services in the United States), encrypted in transit and at rest, with row-level security policies designed so that only your own account can read your rows. Photos and documents are held in private storage buckets scoped to your account.
  • To AI providers: when you use an AI feature, the specific inputs described in the Privacy Policy, Section 4, are sent from our servers — never directly from your device — through OpenRouter to OpenAI's models, processed in real time, and not retained by them.
  • To Apple Health (iOS only): values you log in the App may be written to Apple Health on your device if you have connected it. We do not store Apple Health data in iCloud.

7. Who Receives Consumer Health Data

We share consumer health data only with the service providers that need it to deliver a feature you used, under contracts that limit them to processing it for us. No affiliate of Peptade receives it. The recipients, and what each receives, are:

Recipient What it receives
Supabase (hosting) All server-stored consumer health data, as our database, storage, authentication, and server-function provider.
OpenRouter / OpenAI (AI) Only the inputs for the AI feature you are using at that moment: the facial photo and profile for stack generation; your message and in-app data snapshot for the assistant; a meal or menu photo, or food text, for nutrition; one page of a COA document for transcription. Real-time processing only; no retention; no training.
Sentry (error monitoring) Diagnostic events associated with your account identifier when something goes wrong. Configured not to collect additional personal information.
Apple (Apple Health) Values you log that the App writes back to Apple Health, only if you connect it.
Superwall (subscription screens) A limited set of attributes used to decide which subscription screen you see: the improvement goals and experience level you selected during onboarding, your sex, and an age band (for example "25–34"). It does not receive your date of birth, height, weight, facial photo, dose or injection logs, or any tracking data.
PostHog (product analytics) Product-usage events associated with your account identifier, some of which reveal that you used a health-related feature (Section 3). Session replays are recorded with all images and all typed text masked before they leave your device. You can opt out in the App's Privacy settings.

Not recipients of consumer health data: Apple's App Store and Google Play (billing — receive your store transaction and nothing about your health), RevenueCat (subscription entitlements — receives your account identifier and purchase information only), Meta, TikTok, and Appstack (advertising measurement — receive app-level events such as install, sign-up, and purchase, and your device's advertising identifier only with your App Tracking Transparency permission on iOS, or while analytics is switched on on Android; never your health, biometric, facial-photo, compound, or dose data), the USDA FoodData Central database (receives food names only), and Open Food Facts (receives a barcode number only).

We may also disclose consumer health data where required by law, legal process, or an enforceable governmental request; to enforce our Terms; to detect and address fraud, abuse, or security issues; or as part of a merger, acquisition, financing, reorganization, or sale of assets — in which case the successor is bound by this policy, and any new use of consumer health data requires whatever notice, consent, or authorization applicable law demands.

8. What We Do Not Do

  • We do not sell consumer health data, and we never have. "Sell" here has the broad meaning used in consumer-health-data laws — any exchange for money or other valuable consideration. If that ever changed, we would first obtain the separate, signed authorization those laws require, and you could refuse it without losing access to the App.
  • We do not use consumer health data for advertising or marketing, and we do not share it with any advertising platform.
  • We do not use geofencing around any healthcare facility, or anywhere else, to identify, track, collect data from, or send messages to anyone.
  • We do not use consumer health data to make inferences about you for anyone other than you, and we do not build or share profiles from it.
  • We do not sell, share, or use Apple Health data for advertising, marketing, or any purpose other than the App's own tracking features, consistent with Apple's HealthKit rules.

9. Retention and Deletion

  • Server-stored consumer health data is kept for as long as your account is active.
  • The original facial photo file is deleted from our servers after 90 days. Biometric data derived from it is kept only while your account is active and is permanently deleted within 30 days of account deletion or withdrawal of AI-data consent.
  • Meal, menu, and barcode images are never stored.
  • Certificate of Analysis documents are kept until you delete the document, delete the compound it is filed under, use "Delete Data", or delete your account.
  • When you delete your account, all remaining consumer health data is permanently deleted from our primary systems within 30 days; encrypted backup copies may persist for up to 90 days before automatic purging.
  • The App's "Delete Data" option removes all of your tracking data — including COA documents and their files — while keeping your account and subscription.
  • Data you wrote into Apple Health remains in Apple Health under Apple's control; remove it there.
  • Analytics events already sent to PostHog are retained under that provider's retention schedule and are not personally identifiable once your account is deleted.

You can also ask us to delete all or part of your consumer health data by emailing help@peptade.com at any time — however long ago you last used the App, and whether or not it is still installed. The Delete Your Data page (https://www.peptade.com/delete-your-data) sets out every deletion path step by step.

10. Your Consumer Health Data Rights

Regardless of where you live, you may:

  • Confirm whether we collect, share, or sell consumer health data about you, and access that data.
  • Receive a list of the third parties and affiliates with whom we have shared or to whom we have sold your consumer health data, with a contact email for each. (Section 7 is that list; we have sold none.)
  • Withdraw consent to our collection and sharing of consumer health data, in whole or by feature — turn AI features off in Profile ▸ Privacy Settings ▸ Manage Consents, disconnect Apple Health, opt out of analytics in the same screen, or stop using a feature.
  • Delete your consumer health data, in whole or in part, including any copy held by our service providers and any archived or backup copy, within the timelines in Section 9.
  • Not be discriminated against for exercising any of these rights.

How to exercise them. Use the in-app controls above, or email help@peptade.com from the email address associated with your account — at any time, including long after you stopped using the App. We verify requests by matching the sending address to the account; we may ask a follow-up question if that is not enough to be sure it is you. You may use an authorized agent; we will require proof of the agent's authority. We respond within 45 days, and we will tell you within that time if we need up to 45 more days and why. We do not charge for a request unless it is manifestly unfounded or repetitive, and we tell you before charging.

Appeals. If we decline a request, we will explain why in writing. You may appeal by replying to that decision, or by emailing help@peptade.com with the subject line "Appeal — consumer health data". We will answer the appeal in writing within 45 days. If we deny the appeal, you may contact your state Attorney General: in Washington, the Office of the Attorney General (atg.wa.gov); in Nevada, the Office of the Attorney General (ag.nv.gov); in Connecticut, the Office of the Attorney General (portal.ct.gov/ag).

11. Changes to This Policy

We may update this policy from time to time. We will post the revised policy with a new effective date and notify you in the App of material changes. Where applicable law requires your consent or authorization before a change applies to consumer health data we already hold, we will obtain it before the new practice begins.

Questions about this policy: help@peptade.com.