Privacy Policy & Health Data Notice
Last updated: July 12, 2026
Peptilot is a tracking and educational tool for peptide and GLP‑1 protocols. This policy explains what we collect, why, where it lives, and how you delete it. It is written to be read.
Plain-language summary
- You sign in with just an email address — there is no password to store.
- The health-related data in Peptilot is the data you choose to enter: doses, compounds, injection sites, weight, hydration, side effects, nutrition, check‑ins, bloodwork, progress photos, notes.
- Your data is stored on our own servers in the European Union (Germany).
- We do not sell your data, show ads, or share your data for advertising — and the apps contain no third‑party analytics or attribution SDKs.
- AI features run server‑side through OpenAI's API, only when you use them. OpenAI does not use API data to train its models unless an API customer explicitly opts in, and we do not opt in.
- Apple Health / Health Connect sync is optional, permission-based, and limited to weight.
- Deleting your account in the app permanently erases your data — immediately from live systems, and from short-lived backups within 35 days.
- Peptilot is for adults 18+ and is not medical advice.
This summary is for convenience; the full policy below controls.
1. Who we are
Peptilot is operated by [legal entity name, registered address — complete before launch] ("Peptilot", "we", "us"). We are the data controller for the personal data described in this policy under the EU General Data Protection Regulation (GDPR). You can reach us at hello@peptilot.com.
This policy covers the Peptilot apps (iOS, Android, web at app.peptilot.com), this website (peptilot.com), and support conversations. By creating an account you agree to this policy, which is incorporated into our Terms of Service.
2. Not medical advice
Peptilot provides tracking, organization, and educational features only. It is not a healthcare provider or a medical device, and nothing in the app — including calculations, reminders, AI responses, or educational content — is medical advice, diagnosis, treatment, or dosing instructions. Always consult a qualified healthcare professional. The full disclaimer is in the Terms.
3. What we collect
Account data
Your email address (used for passwordless sign-in codes and essential service messages), account identifiers, session tokens, and basic settings (units, timezone, goals). We deliberately do not ask for your name.
Health-related tracking data you enter
Compounds and vials you track, dose logs and schedules, protocols and titration plans, injection sites, side effects, weight, hydration, nutrition entries, daily check‑ins, bloodwork results, progress photos, notes, and reminders. Under the GDPR this is special-category (health) data — we process it only because you choose to enter it, on the basis of your explicit consent (Art. 9(2)(a) GDPR).
AI feature inputs
If you use Pep Bot, your messages; if you use the AI meal scan, the meal photo you submit; if you use AI insights, a de‑identified summary of your recent tracking aggregates. Sent to our AI provider only when you invoke the feature (see section 6).
Apple Health / Health Connect (optional)
With your permission, we read weight entries and can write your logged weight back. Imported weight entries are stored in your Peptilot account like any weight entry you type in. You can revoke access at any time in system settings. See section 7 for our platform commitments.
Subscription data
Subscription and entitlement status, product identifier, and purchase metadata from Apple, Google, and RevenueCat (and Stripe, for web subscriptions when available). We never receive your full payment card details.
Device and technical data
App version, device platform, a push‑notification token if you enable reminders, and standard server logs (IP address, request metadata) used for security, abuse prevention, and debugging. We run no third-party analytics, attribution, or advertising SDKs in the apps.
Support
Whatever you choose to send us by email. Please don't include more health detail than needed; we use support messages only to help you and keep records where legally required.
4. What we do not do
- We do not sell personal data or health data — to anyone, in any form.
- We do not share your data for advertising, and we show no ads.
- We do not use third-party analytics or attribution tools.
- We do not use your personal data to train AI models, and our AI provider is contractually barred from doing so with API data.
- We do not use geofencing, location tracking, or background location of any kind.
- We do not send Apple Health / Health Connect data to advertising platforms, data brokers, or resellers.
If any of this ever changes, we will update this policy first and obtain any consent the law requires.
5. How we use your data
- To run Peptilot: authenticate you, store and sync your tracking data across your devices, and show it back to you.
- To send sign-in codes and essential service emails.
- To deliver reminders and notifications you enable.
- To provide AI features you invoke (Pro).
- To manage subscriptions and entitlements.
- To keep the service secure, prevent abuse, and debug failures.
- To respond when you contact us, and to comply with legal obligations.
Legal bases under the GDPR: performance of our contract with you (Art. 6(1)(b)); your explicit consent for health data and optional features (Art. 9(2)(a), Art. 6(1)(a)); our legitimate interests in securing and maintaining the service (Art. 6(1)(f)); and legal obligations (Art. 6(1)(c)). You can withdraw consent at any time by deleting the relevant data or your account.
6. AI features
Pep Bot, AI insights, compound import, and the AI meal scan run server-side through OpenAI's API. Inputs are sent only when you invoke a feature: a Pep Bot message, a meal or inventory image, import text, or de‑identified aggregates used for insights. We do not send your email address or account ID. Requests set store: false, so Peptilot does not ask OpenAI to persist response application state. OpenAI states that API data is not used to train its models unless the API customer explicitly opts in; standard abuse-monitoring logs may retain customer content for up to 30 days. See OpenAI's API data controls. AI output can be wrong; it is informational only and never medical advice.
7. Apple Health & Health Connect commitments
If you connect a health platform, we commit that data obtained through it:
- will never be sold;
- will never be used for advertising, marketing, or use-based data mining;
- will never be shared with third parties except as needed to operate the feature you asked for and as permitted by Apple's HealthKit and Google's Health Connect rules;
- is limited to the data types you authorize (currently weight), used only for the app's tracking features.
These commitments override anything broader elsewhere in this policy.
8. Who processes data for us
We share data only with service providers that help us run Peptilot, under contracts that restrict them to processing on our instructions:
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting (our database and API) | All account and tracking data | Germany (EU) |
| OpenAI | AI features you invoke | Pep Bot messages, meal or inventory images, import text, de‑identified aggregates | USA* |
| Cloudflare | Sending sign-in code emails | Email address, the code | EU/USA* |
| RevenueCat | Subscription management | Entitlement status, purchase metadata | USA* |
| Apple / Google | App distribution, billing, push delivery | Purchase data, push tokens | USA* |
*Where a provider processes data outside the EU/EEA, we rely on appropriate safeguards — the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses. We may also disclose data if required by law or to protect the rights and safety of users, the public, or Peptilot; and, if Peptilot is ever part of a merger or acquisition, data may transfer to the successor subject to this policy and your rights, including deletion.
9. Where your data lives & security
Your account and tracking data (including progress photos) live on our servers in Germany. Transport is encrypted with TLS; access is scoped so every request only ever reads the signed-in account's rows; sign-in is passwordless (one-time email codes), so there is no password of yours to breach. No system is perfectly secure — if a breach requires notification under applicable law, we will notify you and the supervisory authority as required.
10. Retention & deletion
- Your data is kept while your account is active. You can edit or delete individual entries anytime.
- Deleting your account (Settings → Delete account) permanently and immediately erases your account and all tracking data from live systems — a hard delete, not a deactivation.
- Encrypted backups age out on a rolling basis within 35 days of deletion.
- Purchase records held by Apple, Google, RevenueCat, or Stripe follow their retention schedules and legal obligations (tax, accounting, fraud prevention).
- De-identified, aggregated data that cannot be linked back to you may be retained.
11. Your rights (GDPR)
You have the right to:
- access your data (the app itself shows it; a PDF export is built in);
- rectify inaccurate data (edit in the app);
- erase your data (in-app account deletion, or email us);
- receive a portable copy (data portability);
- restrict or object to certain processing;
- withdraw consent at any time, without affecting prior processing;
- complain to a supervisory authority — in Germany, the data protection authority of our registered state, or the authority where you live.
To exercise any right, use the in-app controls or email hello@peptilot.com. We verify requests against the account email and respond within the statutory deadline (one month, extendable as the GDPR allows).
12. United States users
Depending on your state (including California, Colorado, Connecticut, Nevada, Oregon, Texas, Virginia, Washington), you may have rights to know, access, correct, delete, and port your data, and to opt out of sale, sharing, targeted advertising, or profiling. Our answer is simple: we do not sell or share personal data or consumer health data, and we do not advertise — so there is nothing to opt out of. Regarding Washington's My Health My Data Act: we do not sell consumer health data and do not use geofencing around health facilities. To exercise any state right or appeal a decision, email hello@peptilot.com (subject: "Privacy Request"); if unsatisfied, you may contact your state Attorney General.
13. Cookies
The web app uses one essential, httpOnly session cookie to keep you signed in — nothing else. This marketing site sets no cookies at all; it stores only your light/dark theme choice locally on your device. There are no advertising or cross-site tracking cookies anywhere, so there is no cookie banner to click.
14. Age requirement
Peptilot is for adults 18 or older. We do not knowingly collect data from anyone under 18 and will delete it if we learn we have.
15. Changes to this policy
We may update this policy as Peptilot evolves. The current version always lives at peptilot.com/privacy; for material changes we will notify you by email or in-app notice, and re-ask consent where the law requires it.
16. Contact
[legal entity name, registered address — complete before launch]
Email: hello@peptilot.com