Skip to content

Privacy Policy

Last updated: 2026-08-13

Who we are

Peptidia ("Peptidia", "we", "us", "our") is an educational service operated from Quebec, Canada. Privacy questions, data-access requests, and consent withdrawals can be directed to our designated privacy officer at privacy@peptidia.app.

What we collect

Account data: email address and sign-in identifier (Apple ID / Google ID / magic link). If you use email/password sign-in, password authentication is handled by Supabase; Peptidia does not receive or store your plaintext password.

Profile data: display name and the primary outcome goals selected during onboarding. During onboarding we also ask for an age range (used only to confirm you are 18 or older — we never ask for or store a date of birth), an optional sex question you can skip, your country, and your peptide-experience level; these answers personalize the flow on your device and are not stored on our servers. An optional preferred name, initial journal weight baseline, and journal-reflection reminder preference also stay on your device. We do not ask for height because V1 has no proportionate use for it.

Sensitive health-adjacent data: outcome goals (sleep, recovery, longevity, etc.), self-reported safety conditions used to gate Pro features (pregnancy, breastfeeding, active cancer history), notable observations entered freely in the wellness journal, and daily mood / sleep / energy / optional weight metrics. The initial weight baseline reaches the server only if you intentionally save it as part of a journal entry. Journal metrics never affect library ranking, evidence grades, or AI recommendations.

App-generated data: AI coach conversation history, audit log entries for sensitive actions (subscription changes, data deletion).

Subscription metadata: RevenueCat subscriber identifier, Apple original transaction identifier, current subscription status. We do not receive your credit card details — those are held by Apple.

Device and notification data: the optional daily journal reminder is scheduled locally and stores its chosen time on your device. If you explicitly enable Research Watch notifications during onboarding or in Settings, we store your preference and an Expo push token tied to the app installation so we can deliver dose-free evidence-update digests. The token is reassigned when accounts change on the device, retired when Expo reports it invalid, and no advertising identifiers are collected.

Diagnostic data: crash reports and performance traces (Sentry), collected to maintain a stable, secure service. Peptidia disables default PII collection and applies automated redaction to emails, credentials, user identifiers, URLs, and nested diagnostic context before sending an event; browser session replay is disabled. No automated filter can be guaranteed perfect, so do not place sensitive personal information in an error report or support message unless necessary. Product-analytics events (PostHog) are collected only if you opt in — analytics is off by default. In the iOS app, you can change this in Settings → Privacy & data. On the website, use the Analytics privacy control at the bottom of the page. Where possible, diagnostic data is not linked to your identity.

What we don't collect

  • Advertising identifiers (no IDFA, no ad-tracking).
  • Location data.
  • Photos, contacts, calendar, or microphone data.
  • Anything from HealthKit (V1 doesn't request HealthKit access).
  • Payment-instrument details.

How we use it

  • Deliver the product: show you a personalized library, run the AI assistant, store your journal, track your subscription state.
  • Operate safely: detect abuse, enforce rate limits, monitor errors, maintain audit logs of sensitive actions.
  • Improve the product: measure feature usage in aggregate via PostHog — only with your consent. Analytics is opt-in and can be withdrawn anytime in Settings.
  • Communicate with you: transactional emails (welcome, account deletion confirmation), launch announcement (if you opted in).
  • Send Research Watch notifications: deliver a dose-free digest when our automated PubMed or ClinicalTrials.gov index detects a new source record or material trial-status/result change — only if you opt in. Automated source records are not medical conclusions.

We do not sell or rent your data. We do not share data with third-party advertisers.

Where it lives

Our database is hosted by Supabase in Montreal (ca-central-1, Canada). Other sub-processors process data in their own regions:

Sub-processorPurposeRegion
VercelWeb/API hostingUS
CloudflareDNS, edge proxyGlobal
Apple App Store / RevenueCatiOS subscriptionsUS
AnthropicAI assistant inferenceUS
Voyage AIVector embeddingsUS
ResendTransactional emailUS
PostHogProduct analyticsUS
SentryError trackingUS
Upstash RedisRate limitingRegion per project
Expo PushiOS push deliveryUS

For users in the European Economic Area, transfers to the US occur under Standard Contractual Clauses where applicable. For users in Quebec, our practices are governed by the Act respecting the protection of personal information in the private sector (Bill 25).

Your rights

You have the right to:

  • Access and port the personal data we hold about you — export it yourself in-app via Settings → Privacy & data → Download my data, or email privacy@peptidia.app.
  • Correct inaccurate data (edit profile in-app, or email us).
  • Delete your account and user-owned content via Settings → Delete Account in the iOS app, or by emailing us. In-app deletion begins immediately; emailed requests are handled within the response period required by applicable law. Limited de-identified security records and transaction records that Apple, a payment processor, or Peptidia must retain for legal, fraud-prevention, or accounting purposes may remain for the applicable retention period.
  • Object to processing for non-essential purposes (e.g., analytics), where applicable.
  • Withdraw consent at any time for processing that depends on it — turn product analytics or Research Watch notifications off in Settings → Privacy & data in the iOS app, use the website’s Analytics privacy control, and manage marketing email in the same place.

EEA / UK residents may also lodge a complaint with their local data-protection authority. Quebec residents may complain to the Commission d'accès à l'information du Québec.

Retention

  • Account data is retained for the active life of your account.
  • Sensitive health-adjacent data (journal entries, goals) is retained while the account is active and is automatically purged 12 months after subscription cancellation or expiry, unless you delete the account sooner.
  • Audit log entries are retained for 24 months then anonymized.
  • Diagnostic data (Sentry, PostHog) is retained only for the configured processor retention period and is then deleted or de-identified; Peptidia periodically reviews those settings and keeps no diagnostic event longer than reasonably necessary for security, debugging, or aggregate product analysis.
  • Research Watch push preferences and tokens are retained while the account is active and the feature is enabled. Opt-out disables delivery immediately; invalid tokens and account-owned tokens on deletion are removed.

Children

Peptidia is not intended for users under 18. Onboarding includes an age gate. We do not knowingly collect data from minors; if you believe we have, contact us at privacy@peptidia.app and we will delete it.

Cookies

The marketing site uses minimal cookies (preference + anti-CSRF). No advertising cookies. If you allow website analytics, the consent choice and anonymous analytics identifier are stored in your browser’s local storage rather than an advertising cookie. The iOS app does not use cookies.

Security

Data is encrypted at rest (Supabase default) and in transit (TLS). Access to production infrastructure is restricted to the founder. Sensitive operations are logged to an audit log.

If a confidentiality incident affects personal information, we will take reasonable measures to reduce the risk of injury and prevent recurrence. Where the incident presents a risk of serious injury, we will promptly notify the Commission d’accès à l’information and affected persons as Quebec law requires, subject to the lawful investigation exception. We maintain the required confidentiality-incident register for at least five years from the date we became aware of each incident. Where the GDPR applies, its separate supervisory-authority deadline may be 72 hours.

Legal rights and remedies

This Policy does not waive or limit any mandatory privacy, consumer-protection, Civil Code, or other legal right or remedy. Peptidia does not require a Quebec privacy dispute to be submitted to arbitration, restrict access to a court, prohibit a class action, or impose a class-action waiver. After a dispute arises, the parties may separately and voluntarily agree to mediation or arbitration where permitted by law.

The Terms of Service contain Peptidia's warranty disclaimer, lawful limitation-of-liability language, narrow indemnification provision, termination rights, governing law, and dispute-resolution terms. Those provisions remain subject to all mandatory privacy and consumer protections.

Changes

We will notify you of material changes by email and update the "Last updated" date above.

Contact

Privacy questions, rights requests, or breach inquiries: privacy@peptidia.app.