1. Summary
This Privacy Policy explains how Peptiq ("Peptiq", "we", "us", or "our") handles information in connection with the Peptiq mobile application (the "App") and the website at peptiq.app (the "Site", together the "Services").
This summary is provided for convenience and does not replace the full policy below.
- Your log stays with you. Entries you record — compounds, amounts, timestamps, and notes — are stored in the App's private storage on your device. They are not transmitted to us.
- No account is required. You can use the App without giving us an email address, a phone number, or any other identifier.
- No trackers. The App contains no advertising SDKs, no third-party analytics, and no cross-app tracking. We do not request the App Tracking Transparency permission because we do not track you.
- No sale of data. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined under U.S. state privacy laws.
- Deletion is immediate. You can erase everything from within the App at any time. See Account & Data Deletion.
2. Who we are
Peptiq is the developer and distributor of the App and the operator of the Site. For the purposes of the EU and UK General Data Protection Regulation, Peptiq is the data controller for the limited personal information described in this policy.
Postal address for privacy correspondence: [BUSINESS_MAILING_ADDRESS]. Email:
privacy@peptiq.app.
3. Information we collect
We have designed the App so that the overwhelming majority of your information never reaches us at all. The table below is the complete picture.
| Category | Examples | Where it lives | Do we receive it? |
|---|---|---|---|
| Protocol & log data | Compound names you type, amounts, schedule, timestamps, adherence history, free-text notes | On your device; in your own iCloud account if you enable sync | No. Never transmitted to Peptiq. |
| App preferences | Theme, reminder times, units, export defaults | On your device | No. |
| Diagnostics you choose to send | Crash logs and performance metrics shared through Apple, if you opted in to share analytics with developers in iOS Settings | Apple's systems, then aggregated reports to us | Only if you opted in, and only in aggregated or anonymised form. |
| Support correspondence | Your email address, the content of your message, and any attachments or screenshots you choose to include | Our email provider | Yes, because you sent it to us. |
| Purchase records | Whether a purchase or subscription is active, and aggregate sales reporting | Apple's App Store systems | Aggregate only. Apple processes payments; we never see your payment card, billing address, or full name. |
| Site request logs | IP address, user agent, requested URL, timestamp — retained transiently by our hosting provider for security and abuse prevention | Cloudflare edge infrastructure | Indirectly, as standard infrastructure logging. Not used to build a profile of you. |
4. What we never collect
To state it plainly, the App does not collect, request, or transmit any of the following:
- Your name, postal address, phone number, or date of birth.
- Precise or coarse location data. The App requests no location permission.
- Your contacts, photos, microphone, camera roll, calendar, or health records from Apple Health.
- Advertising identifiers (IDFA), device fingerprints, or any cross-app or cross-site tracking signal.
- Behavioural analytics such as screen views, session recordings, funnels, or heatmaps.
- Biometric data. Face ID and Touch ID authentication, if enabled, is performed entirely by iOS; we receive only a success or failure result and never the biometric itself.
5. Health information
Information about substances you take is sensitive. Under the GDPR it is a special category of personal data, and under several U.S. state laws it may qualify as consumer health data.
Our approach is to avoid holding it at all. Protocol and log data is written to the App's sandboxed storage on your device and is not transmitted to Peptiq under any circumstance, including for troubleshooting. When you export a report, the resulting file is generated on your device and handed to the iOS share sheet; where it goes next is entirely your choice, and we have no visibility into it.
Peptiq is not a covered entity or business associate under HIPAA. Information you record in a personal journal of this kind is generally not protected health information under HIPAA. If you share an exported report with your provider, the copy your provider holds becomes subject to their own obligations, not ours.
6. How we use information
We use the limited information we do receive only for these purposes:
- To answer you. Support correspondence is used to diagnose your issue and reply.
- To fix defects. Aggregated crash reports from Apple help us find and repair bugs.
- To operate the Site. Infrastructure logs help us serve pages, block abuse, and mitigate denial-of-service attacks.
- To meet legal obligations. For example, retaining records required by tax or consumer-protection law, or responding to a valid legal request.
We do not use your information for profiling, automated decision-making with legal or similarly significant effects, advertising, or model training.
7. Legal bases for processing (EEA and UK)
| Processing | Legal basis |
|---|---|
| Responding to your support request | Legitimate interests (Art. 6(1)(f)) — communicating with users who contact us; and performance of a contract (Art. 6(1)(b)) where it relates to the App's function |
| Providing the App itself | Performance of a contract (Art. 6(1)(b)) under our Terms of Use |
| Aggregated crash diagnostics | Consent (Art. 6(1)(a)), given through your iOS analytics-sharing setting and withdrawable there at any time |
| Security logging and abuse prevention | Legitimate interests (Art. 6(1)(f)) — keeping the Services available and secure |
| Complying with law | Legal obligation (Art. 6(1)(c)) |
Because health-related entries stay on your device and are never transmitted to us, we do not process special category data under Article 9 in the ordinary course of providing the App. If you voluntarily include health details in a support email, we process them on the basis of your explicit consent (Art. 9(2)(a)) solely to answer you, and we delete them on the schedule described in section 11.
8. Sharing and disclosure
We do not sell your personal information, and we never have. We share information only in these narrow circumstances:
- Service providers. A small number of vendors process data on our behalf under contract, limited to what they need. Our current providers are Apple (app distribution, payments, aggregated crash reporting), Cloudflare (website hosting and security), and our email provider (support correspondence).
- Legal requirements. We may disclose information if compelled by valid legal process, or where necessary to protect our rights, the safety of users, or the public. We will challenge requests that appear overbroad and, where legally permitted, notify affected users.
- Business transfer. If Peptiq is involved in a merger, acquisition, or asset sale, information may transfer to the successor. Any successor remains bound by this policy for previously collected information, and we will give notice before your information becomes subject to a materially different policy.
We do not share personal information with data brokers, advertising networks, or social media platforms, and we place no advertising or social sharing pixels in the App or on the Site.
9. iCloud sync
The App offers optional synchronisation across your own Apple devices using Apple's CloudKit private database. This feature is off unless you enable it.
- Data syncs into your iCloud account, not ours. Peptiq has no ability to read a private CloudKit database.
- If you have Advanced Data Protection enabled in your Apple Account, this data is end-to-end encrypted and not readable by Apple either.
- Apple's handling of iCloud data is governed by the Apple Privacy Policy.
- Turning sync off stops future synchronisation; deleting your data in the App removes it from the synced set.
10. Device permissions
The App requests as little as possible. Each permission is optional and the App remains usable if you decline.
| Permission | Why | If you decline |
|---|---|---|
| Notifications | To deliver reminders you scheduled. Notifications are composed and scheduled locally on your device. | The App works normally; you simply receive no reminders. |
| Face ID / Touch ID | To lock the App behind biometric authentication if you turn that on. | The App opens without a biometric prompt. |
| iCloud | To sync across your own devices. | Your data stays on a single device. |
The App does not request location, contacts, camera, microphone, photo library, Bluetooth, or Apple Health access.
11. Data retention
- Your log data: retained on your device until you delete it or remove the App. We hold no copy and therefore have no retention period to apply.
- Support emails: retained for up to 24 months from the last message in the thread, then deleted. You may ask us to delete a thread sooner.
- Site request logs: retained by our hosting provider for a short period — typically no more than 30 days — for security and abuse prevention.
- Records we must keep by law: retained for the period the applicable law requires, then deleted.
12. Security
We take reasonable and appropriate technical and organisational measures to protect information, including:
- Storing App data inside the iOS application sandbox, protected by hardware-backed file encryption tied to your device passcode.
- Serving all Site traffic over HTTPS with HSTS, and setting a strict Content Security Policy.
- Minimising collection so that a breach of our systems could not expose a health log we never held.
- Limiting employee and contractor access to support correspondence on a need-to-know basis.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you and the relevant supervisory authorities where required by law and without undue delay.
13. Your privacy rights
Depending on where you live, you may have some or all of the following rights:
- Access — to know whether we process your personal information and obtain a copy.
- Rectification — to correct inaccurate or incomplete information.
- Erasure — to have your information deleted.
- Restriction and objection — to limit or object to certain processing, including processing based on legitimate interests.
- Portability — to receive information you provided in a structured, machine-readable format.
- Withdrawal of consent — at any time, without affecting processing already carried out.
- Non-discrimination — we will never degrade the Services because you exercised a privacy right.
Because your log lives on your device, you can exercise access, portability, and erasure instantly and without involving us: use the App's export function for a copy, and Settings → Data & Privacy → Erase All Data to delete.
For anything else, email privacy@peptiq.app. We respond within 30 days (or 45 days where U.S. state law permits an extension, with notice to you). We may need to ask for limited information to verify your request; we use it only for verification and delete it afterwards. You may use an authorised agent where the law permits.
If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
14. Notices for U.S. state residents
This section applies to residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comparable comprehensive privacy laws.
- Categories collected in the past 12 months: identifiers limited to an email address, but only where you emailed us; internet or network activity limited to Site request logs; and the contents of communications you send us. We do not collect the other statutory categories.
- Sale and sharing: we have not sold personal information, and we have not shared it for cross-context behavioural advertising or targeted advertising, in the past 12 months. We do not sell or share the personal information of minors under 16.
- Sensitive personal information: we do not collect sensitive personal information for the purpose of inferring characteristics, and we do not use or disclose it beyond the purposes permitted by law. Consumer health data you record is not transmitted to us.
- Opt-out preference signals: the Site honours the Global Privacy Control signal. Since we do not sell or share personal information, there is nothing to opt out of.
- Appeals: if we decline a request, you may appeal by replying to our decision or writing to privacy@peptiq.app with "Appeal" in the subject line. We respond to appeals within 45 days and will tell you how to contact your state attorney general if you disagree.
California "Shine the Light": we do not disclose personal information to third parties for their own direct marketing purposes.
15. Children's privacy
The Services are intended for adults and are rated accordingly on the App Store. They are not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact privacy@peptiq.app and we will delete it promptly. We comply with the Children's Online Privacy Protection Act (COPPA) and, for users in the EEA and UK, with the applicable age of digital consent.
16. International data transfers
We operate from the United States, and our service providers may process information in the United States and other countries whose data protection laws differ from those where you live. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical measures such as encryption in transit and data minimisation. You may request a copy of the relevant safeguards by emailing us.
17. This website
The Site is a static website hosted on Cloudflare Workers. It sets no cookies and loads no third-party scripts, fonts, or images — every asset is served from this domain.
The Site stores a single item in your browser's local storage, named peptiq-theme, which
records whether you chose the light or dark appearance. It contains no identifier, is never
transmitted anywhere, and clearing your browser data removes it. Because it is strictly necessary to
deliver a preference you requested, it does not require consent under the ePrivacy Directive.
Cloudflare processes Site requests as our hosting provider and may retain transient logs, including IP addresses, for security purposes. See the Cloudflare Privacy Policy.
18. Apple App Store privacy labels
Apple requires developers to declare data practices on each App Store product page. Our declaration is as follows, and it is consistent with this policy:
| Apple category | Our declaration |
|---|---|
| Data used to track you | None. |
| Data linked to you | None. |
| Data not linked to you | Diagnostics (crash data), and only where you have opted in to share analytics with developers in iOS Settings. |
If a future release changes what the App collects, we will update both the App Store labels and this policy before that release ships.
19. Changes to this policy
We may update this policy to reflect changes to the Services or the law. The "Last updated" date at the top always reflects the current version. If we make a material change — for example, if we ever began collecting a new category of personal information — we will provide prominent advance notice in the App and on this page, and where required by law we will seek your consent before the change takes effect. Continued use after an update means you accept the revised policy.
20. Contact us
Questions, requests, or complaints about privacy:
- Privacy enquiries
- privacy@peptiq.app
- General support
- support@peptiq.app
- Postal address
[BUSINESS_MAILING_ADDRESS]- Response time
- Within 30 days, and usually within 2 business days
See also our Terms of Use, Medical Disclaimer, and Account & Data Deletion instructions.