Peptiq

Legal

Privacy Policy

The short version: your health entries stay on your device, we run no analytics or advertising SDKs, and we have never sold personal information. The long version follows — written to be read, not to be survived.

Effective
1 September 2026
Last updated
1 September 2026
Version
1.0
Applies to
Peptiq for iOS & peptiq.app

1. Summary

This Privacy Policy explains how Peptiq ("Peptiq", "we", "us", or "our") handles information in connection with the Peptiq mobile application (the "App") and the website at peptiq.app (the "Site", together the "Services").

This summary is provided for convenience and does not replace the full policy below.

  • Your log stays with you. Entries you record — compounds, amounts, timestamps, and notes — are stored in the App's private storage on your device. They are not transmitted to us.
  • No account is required. You can use the App without giving us an email address, a phone number, or any other identifier.
  • No trackers. The App contains no advertising SDKs, no third-party analytics, and no cross-app tracking. We do not request the App Tracking Transparency permission because we do not track you.
  • No sale of data. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined under U.S. state privacy laws.
  • Deletion is immediate. You can erase everything from within the App at any time. See Account & Data Deletion.

2. Who we are

Peptiq is the developer and distributor of the App and the operator of the Site. For the purposes of the EU and UK General Data Protection Regulation, Peptiq is the data controller for the limited personal information described in this policy.

Postal address for privacy correspondence: [BUSINESS_MAILING_ADDRESS]. Email: privacy@peptiq.app.

3. Information we collect

We have designed the App so that the overwhelming majority of your information never reaches us at all. The table below is the complete picture.

CategoryExamplesWhere it livesDo we receive it?
Protocol & log data Compound names you type, amounts, schedule, timestamps, adherence history, free-text notes On your device; in your own iCloud account if you enable sync No. Never transmitted to Peptiq.
App preferences Theme, reminder times, units, export defaults On your device No.
Diagnostics you choose to send Crash logs and performance metrics shared through Apple, if you opted in to share analytics with developers in iOS Settings Apple's systems, then aggregated reports to us Only if you opted in, and only in aggregated or anonymised form.
Support correspondence Your email address, the content of your message, and any attachments or screenshots you choose to include Our email provider Yes, because you sent it to us.
Purchase records Whether a purchase or subscription is active, and aggregate sales reporting Apple's App Store systems Aggregate only. Apple processes payments; we never see your payment card, billing address, or full name.
Site request logs IP address, user agent, requested URL, timestamp — retained transiently by our hosting provider for security and abuse prevention Cloudflare edge infrastructure Indirectly, as standard infrastructure logging. Not used to build a profile of you.

4. What we never collect

To state it plainly, the App does not collect, request, or transmit any of the following:

  • Your name, postal address, phone number, or date of birth.
  • Precise or coarse location data. The App requests no location permission.
  • Your contacts, photos, microphone, camera roll, calendar, or health records from Apple Health.
  • Advertising identifiers (IDFA), device fingerprints, or any cross-app or cross-site tracking signal.
  • Behavioural analytics such as screen views, session recordings, funnels, or heatmaps.
  • Biometric data. Face ID and Touch ID authentication, if enabled, is performed entirely by iOS; we receive only a success or failure result and never the biometric itself.

5. Health information

Information about substances you take is sensitive. Under the GDPR it is a special category of personal data, and under several U.S. state laws it may qualify as consumer health data.

Our approach is to avoid holding it at all. Protocol and log data is written to the App's sandboxed storage on your device and is not transmitted to Peptiq under any circumstance, including for troubleshooting. When you export a report, the resulting file is generated on your device and handed to the iOS share sheet; where it goes next is entirely your choice, and we have no visibility into it.

Peptiq is not a covered entity or business associate under HIPAA. Information you record in a personal journal of this kind is generally not protected health information under HIPAA. If you share an exported report with your provider, the copy your provider holds becomes subject to their own obligations, not ours.

6. How we use information

We use the limited information we do receive only for these purposes:

  • To answer you. Support correspondence is used to diagnose your issue and reply.
  • To fix defects. Aggregated crash reports from Apple help us find and repair bugs.
  • To operate the Site. Infrastructure logs help us serve pages, block abuse, and mitigate denial-of-service attacks.
  • To meet legal obligations. For example, retaining records required by tax or consumer-protection law, or responding to a valid legal request.

We do not use your information for profiling, automated decision-making with legal or similarly significant effects, advertising, or model training.

7. Legal bases for processing (EEA and UK)

ProcessingLegal basis
Responding to your support requestLegitimate interests (Art. 6(1)(f)) — communicating with users who contact us; and performance of a contract (Art. 6(1)(b)) where it relates to the App's function
Providing the App itselfPerformance of a contract (Art. 6(1)(b)) under our Terms of Use
Aggregated crash diagnosticsConsent (Art. 6(1)(a)), given through your iOS analytics-sharing setting and withdrawable there at any time
Security logging and abuse preventionLegitimate interests (Art. 6(1)(f)) — keeping the Services available and secure
Complying with lawLegal obligation (Art. 6(1)(c))

Because health-related entries stay on your device and are never transmitted to us, we do not process special category data under Article 9 in the ordinary course of providing the App. If you voluntarily include health details in a support email, we process them on the basis of your explicit consent (Art. 9(2)(a)) solely to answer you, and we delete them on the schedule described in section 11.

8. Sharing and disclosure

We do not sell your personal information, and we never have. We share information only in these narrow circumstances:

  • Service providers. A small number of vendors process data on our behalf under contract, limited to what they need. Our current providers are Apple (app distribution, payments, aggregated crash reporting), Cloudflare (website hosting and security), and our email provider (support correspondence).
  • Legal requirements. We may disclose information if compelled by valid legal process, or where necessary to protect our rights, the safety of users, or the public. We will challenge requests that appear overbroad and, where legally permitted, notify affected users.
  • Business transfer. If Peptiq is involved in a merger, acquisition, or asset sale, information may transfer to the successor. Any successor remains bound by this policy for previously collected information, and we will give notice before your information becomes subject to a materially different policy.

We do not share personal information with data brokers, advertising networks, or social media platforms, and we place no advertising or social sharing pixels in the App or on the Site.

9. iCloud sync

The App offers optional synchronisation across your own Apple devices using Apple's CloudKit private database. This feature is off unless you enable it.

  • Data syncs into your iCloud account, not ours. Peptiq has no ability to read a private CloudKit database.
  • If you have Advanced Data Protection enabled in your Apple Account, this data is end-to-end encrypted and not readable by Apple either.
  • Apple's handling of iCloud data is governed by the Apple Privacy Policy.
  • Turning sync off stops future synchronisation; deleting your data in the App removes it from the synced set.

10. Device permissions

The App requests as little as possible. Each permission is optional and the App remains usable if you decline.

PermissionWhyIf you decline
NotificationsTo deliver reminders you scheduled. Notifications are composed and scheduled locally on your device.The App works normally; you simply receive no reminders.
Face ID / Touch IDTo lock the App behind biometric authentication if you turn that on.The App opens without a biometric prompt.
iCloudTo sync across your own devices.Your data stays on a single device.

The App does not request location, contacts, camera, microphone, photo library, Bluetooth, or Apple Health access.

11. Data retention

  • Your log data: retained on your device until you delete it or remove the App. We hold no copy and therefore have no retention period to apply.
  • Support emails: retained for up to 24 months from the last message in the thread, then deleted. You may ask us to delete a thread sooner.
  • Site request logs: retained by our hosting provider for a short period — typically no more than 30 days — for security and abuse prevention.
  • Records we must keep by law: retained for the period the applicable law requires, then deleted.

12. Security

We take reasonable and appropriate technical and organisational measures to protect information, including:

  • Storing App data inside the iOS application sandbox, protected by hardware-backed file encryption tied to your device passcode.
  • Serving all Site traffic over HTTPS with HSTS, and setting a strict Content Security Policy.
  • Minimising collection so that a breach of our systems could not expose a health log we never held.
  • Limiting employee and contractor access to support correspondence on a need-to-know basis.

No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you and the relevant supervisory authorities where required by law and without undue delay.

13. Your privacy rights

Depending on where you live, you may have some or all of the following rights:

  • Access — to know whether we process your personal information and obtain a copy.
  • Rectification — to correct inaccurate or incomplete information.
  • Erasure — to have your information deleted.
  • Restriction and objection — to limit or object to certain processing, including processing based on legitimate interests.
  • Portability — to receive information you provided in a structured, machine-readable format.
  • Withdrawal of consent — at any time, without affecting processing already carried out.
  • Non-discrimination — we will never degrade the Services because you exercised a privacy right.

Because your log lives on your device, you can exercise access, portability, and erasure instantly and without involving us: use the App's export function for a copy, and Settings → Data & Privacy → Erase All Data to delete.

For anything else, email privacy@peptiq.app. We respond within 30 days (or 45 days where U.S. state law permits an extension, with notice to you). We may need to ask for limited information to verify your request; we use it only for verification and delete it afterwards. You may use an authorised agent where the law permits.

If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.

14. Notices for U.S. state residents

This section applies to residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comparable comprehensive privacy laws.

  • Categories collected in the past 12 months: identifiers limited to an email address, but only where you emailed us; internet or network activity limited to Site request logs; and the contents of communications you send us. We do not collect the other statutory categories.
  • Sale and sharing: we have not sold personal information, and we have not shared it for cross-context behavioural advertising or targeted advertising, in the past 12 months. We do not sell or share the personal information of minors under 16.
  • Sensitive personal information: we do not collect sensitive personal information for the purpose of inferring characteristics, and we do not use or disclose it beyond the purposes permitted by law. Consumer health data you record is not transmitted to us.
  • Opt-out preference signals: the Site honours the Global Privacy Control signal. Since we do not sell or share personal information, there is nothing to opt out of.
  • Appeals: if we decline a request, you may appeal by replying to our decision or writing to privacy@peptiq.app with "Appeal" in the subject line. We respond to appeals within 45 days and will tell you how to contact your state attorney general if you disagree.

California "Shine the Light": we do not disclose personal information to third parties for their own direct marketing purposes.

15. Children's privacy

The Services are intended for adults and are rated accordingly on the App Store. They are not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact privacy@peptiq.app and we will delete it promptly. We comply with the Children's Online Privacy Protection Act (COPPA) and, for users in the EEA and UK, with the applicable age of digital consent.

16. International data transfers

We operate from the United States, and our service providers may process information in the United States and other countries whose data protection laws differ from those where you live. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical measures such as encryption in transit and data minimisation. You may request a copy of the relevant safeguards by emailing us.

17. This website

The Site is a static website hosted on Cloudflare Workers. It sets no cookies and loads no third-party scripts, fonts, or images — every asset is served from this domain.

The Site stores a single item in your browser's local storage, named peptiq-theme, which records whether you chose the light or dark appearance. It contains no identifier, is never transmitted anywhere, and clearing your browser data removes it. Because it is strictly necessary to deliver a preference you requested, it does not require consent under the ePrivacy Directive.

Cloudflare processes Site requests as our hosting provider and may retain transient logs, including IP addresses, for security purposes. See the Cloudflare Privacy Policy.

18. Apple App Store privacy labels

Apple requires developers to declare data practices on each App Store product page. Our declaration is as follows, and it is consistent with this policy:

Apple categoryOur declaration
Data used to track youNone.
Data linked to youNone.
Data not linked to youDiagnostics (crash data), and only where you have opted in to share analytics with developers in iOS Settings.

If a future release changes what the App collects, we will update both the App Store labels and this policy before that release ships.

19. Changes to this policy

We may update this policy to reflect changes to the Services or the law. The "Last updated" date at the top always reflects the current version. If we make a material change — for example, if we ever began collecting a new category of personal information — we will provide prominent advance notice in the App and on this page, and where required by law we will seek your consent before the change takes effect. Continued use after an update means you accept the revised policy.

20. Contact us

Questions, requests, or complaints about privacy:

Privacy enquiries
privacy@peptiq.app
General support
support@peptiq.app
Postal address
[BUSINESS_MAILING_ADDRESS]
Response time
Within 30 days, and usually within 2 business days

See also our Terms of Use, Medical Disclaimer, and Account & Data Deletion instructions.