Privacy Policy & Health Data Notice

Last updated: July 12, 2026

Peptilot is a tracking and educational tool for peptide and GLP‑1 protocols. This policy explains what we collect, why, where it lives, and how you delete it. It is written to be read.

Plain-language summary

This summary is for convenience; the full policy below controls.

1. Who we are

Peptilot is operated by [legal entity name, registered address — complete before launch] ("Peptilot", "we", "us"). We are the data controller for the personal data described in this policy under the EU General Data Protection Regulation (GDPR). You can reach us at hello@peptilot.com.

This policy covers the Peptilot apps (iOS, Android, web at app.peptilot.com), this website (peptilot.com), and support conversations. By creating an account you agree to this policy, which is incorporated into our Terms of Service.

2. Not medical advice

Peptilot provides tracking, organization, and educational features only. It is not a healthcare provider or a medical device, and nothing in the app — including calculations, reminders, AI responses, or educational content — is medical advice, diagnosis, treatment, or dosing instructions. Always consult a qualified healthcare professional. The full disclaimer is in the Terms.

3. What we collect

Account data

Your email address (used for passwordless sign-in codes and essential service messages), account identifiers, session tokens, and basic settings (units, timezone, goals). We deliberately do not ask for your name.

Health-related tracking data you enter

Compounds and vials you track, dose logs and schedules, protocols and titration plans, injection sites, side effects, weight, hydration, nutrition entries, daily check‑ins, bloodwork results, progress photos, notes, and reminders. Under the GDPR this is special-category (health) data — we process it only because you choose to enter it, on the basis of your explicit consent (Art. 9(2)(a) GDPR).

AI feature inputs

If you use Pep Bot, your messages; if you use the AI meal scan, the meal photo you submit; if you use AI insights, a de‑identified summary of your recent tracking aggregates. Sent to our AI provider only when you invoke the feature (see section 6).

Apple Health / Health Connect (optional)

With your permission, we read weight entries and can write your logged weight back. Imported weight entries are stored in your Peptilot account like any weight entry you type in. You can revoke access at any time in system settings. See section 7 for our platform commitments.

Subscription data

Subscription and entitlement status, product identifier, and purchase metadata from Apple, Google, and RevenueCat (and Stripe, for web subscriptions when available). We never receive your full payment card details.

Device and technical data

App version, device platform, a push‑notification token if you enable reminders, and standard server logs (IP address, request metadata) used for security, abuse prevention, and debugging. We run no third-party analytics, attribution, or advertising SDKs in the apps.

Support

Whatever you choose to send us by email. Please don't include more health detail than needed; we use support messages only to help you and keep records where legally required.

4. What we do not do

If any of this ever changes, we will update this policy first and obtain any consent the law requires.

5. How we use your data

Legal bases under the GDPR: performance of our contract with you (Art. 6(1)(b)); your explicit consent for health data and optional features (Art. 9(2)(a), Art. 6(1)(a)); our legitimate interests in securing and maintaining the service (Art. 6(1)(f)); and legal obligations (Art. 6(1)(c)). You can withdraw consent at any time by deleting the relevant data or your account.

6. AI features

Pep Bot, AI insights, compound import, and the AI meal scan run server-side through OpenAI's API. Inputs are sent only when you invoke a feature: a Pep Bot message, a meal or inventory image, import text, or de‑identified aggregates used for insights. We do not send your email address or account ID. Requests set store: false, so Peptilot does not ask OpenAI to persist response application state. OpenAI states that API data is not used to train its models unless the API customer explicitly opts in; standard abuse-monitoring logs may retain customer content for up to 30 days. See OpenAI's API data controls. AI output can be wrong; it is informational only and never medical advice.

7. Apple Health & Health Connect commitments

If you connect a health platform, we commit that data obtained through it:

These commitments override anything broader elsewhere in this policy.

8. Who processes data for us

We share data only with service providers that help us run Peptilot, under contracts that restrict them to processing on our instructions:

ProviderPurposeData involvedLocation
Hetzner Online GmbHServer hosting (our database and API)All account and tracking dataGermany (EU)
OpenAIAI features you invokePep Bot messages, meal or inventory images, import text, de‑identified aggregatesUSA*
CloudflareSending sign-in code emailsEmail address, the codeEU/USA*
RevenueCatSubscription managementEntitlement status, purchase metadataUSA*
Apple / GoogleApp distribution, billing, push deliveryPurchase data, push tokensUSA*

*Where a provider processes data outside the EU/EEA, we rely on appropriate safeguards — the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses. We may also disclose data if required by law or to protect the rights and safety of users, the public, or Peptilot; and, if Peptilot is ever part of a merger or acquisition, data may transfer to the successor subject to this policy and your rights, including deletion.

9. Where your data lives & security

Your account and tracking data (including progress photos) live on our servers in Germany. Transport is encrypted with TLS; access is scoped so every request only ever reads the signed-in account's rows; sign-in is passwordless (one-time email codes), so there is no password of yours to breach. No system is perfectly secure — if a breach requires notification under applicable law, we will notify you and the supervisory authority as required.

10. Retention & deletion

11. Your rights (GDPR)

You have the right to:

To exercise any right, use the in-app controls or email hello@peptilot.com. We verify requests against the account email and respond within the statutory deadline (one month, extendable as the GDPR allows).

12. United States users

Depending on your state (including California, Colorado, Connecticut, Nevada, Oregon, Texas, Virginia, Washington), you may have rights to know, access, correct, delete, and port your data, and to opt out of sale, sharing, targeted advertising, or profiling. Our answer is simple: we do not sell or share personal data or consumer health data, and we do not advertise — so there is nothing to opt out of. Regarding Washington's My Health My Data Act: we do not sell consumer health data and do not use geofencing around health facilities. To exercise any state right or appeal a decision, email hello@peptilot.com (subject: "Privacy Request"); if unsatisfied, you may contact your state Attorney General.

13. Cookies

The web app uses one essential, httpOnly session cookie to keep you signed in — nothing else. This marketing site sets no cookies at all; it stores only your light/dark theme choice locally on your device. There are no advertising or cross-site tracking cookies anywhere, so there is no cookie banner to click.

14. Age requirement

Peptilot is for adults 18 or older. We do not knowingly collect data from anyone under 18 and will delete it if we learn we have.

15. Changes to this policy

We may update this policy as Peptilot evolves. The current version always lives at peptilot.com/privacy; for material changes we will notify you by email or in-app notice, and re-ask consent where the law requires it.

16. Contact

[legal entity name, registered address — complete before launch]
Email: hello@peptilot.com