Peptidly

Privacy Policy

Last updated: 2026-04-08

WHO WE ARE

Peptidly is a personal peptide cycle tracker operated by Peptidly. This Privacy Policy explains what data Peptidly collects, why we collect it, who we share it with, and the rights you have over your information.

By using Peptidly, you agree to the practices described here.

WHAT WE COLLECT

Account information
- Your email address
- (If you sign in with Google) your Google account identifier and the email associated with it

Health and tracking data
- The peptides and compounds you choose to track
- Vial inventory: vial size, BAC water volume, remaining quantity, opened date
- Cycle plans: start date, end date, frequency, scheduled injection times
- Dose logs: which dose, when scheduled, when actually taken, dose amount
- Optional fields you may add: notes, injection sites, mood tags
- Notification preferences

Technical data
- Device model, operating system version, app version (collected by our crash reporting service when an error occurs)

What we do NOT collect
- Your physical location
- Your contacts, photos, or files
- Advertising identifiers
- Browsing history
- Biometric identifiers
- Any data from other apps on your device

HOW WE USE YOUR DATA

We use your data only to provide the tracking features of the app: showing your cycles, scheduling reminders, deducting from your vial inventory when you log a dose, computing your supply forecast, and synchronizing your records across devices.

We do NOT use your data for marketing, profiling, behavioural advertising, or sale to third parties.

WHERE YOUR DATA IS STORED

Your data lives in two places:

1. Locally on your device, in an encrypted SQLite database that only Peptidly can access.

2. On our cloud backend hosted by Supabase, in the West EU (Ireland) region. Data is encrypted in transit (TLS) and at rest (Supabase managed encryption). Row-level security policies ensure that only your authenticated session can read or write your records.

THIRD PARTIES WE SHARE WITH

- Supabase (database and authentication provider) — receives all your account and tracking data so we can sync it across devices and provide cloud backup.
- Google Sign-In (only if you choose to sign in with Google) — Google processes your sign-in identity for authentication.
- Sentry (crash reporting) — when the app encounters a runtime error, we send Sentry a stack trace, your device model, OS version, app version, and your user identifier and email so we can diagnose and fix the bug.

We do NOT share your data with advertisers, data brokers, marketing platforms, or analytics vendors.

YOUR RIGHTS

You can:
- Access your data — everything Peptidly has about you is visible inside the app on the screens you use to manage it
- Correct any record by editing it in the app
- Export your data as JSON via Settings → Data → Export Data
- Permanently delete your account and all associated data via Settings → Account → Delete Account

Account deletion is irreversible and removes your auth.users record and all associated data within 30 days.

DATA RETENTION

We retain your data for as long as your account is active. When you delete your account, all associated records are removed within 30 days.

Backups taken before the deletion may persist for up to 30 additional days before they are rotated out.

CHILDREN AND AGE OF CONSENT

Peptidly is not intended for use by anyone under the age of 18. The app is restricted to adults because of the nature of the content (peptide tracking) and the associated health risks. Although UK GDPR sets the digital age of consent at 13, our minimum age requirement of 18 is stricter and applies regardless of jurisdiction. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us at norbertcsibitech@gmail.com and we will delete it promptly.

CHANGES TO THIS POLICY

If we change this Privacy Policy, we will update the "Last updated" date above and notify you in the app. Continued use after the update constitutes acceptance of the new policy.

CONTACT US

If you have questions about this Privacy Policy or want to exercise any of your rights, contact us at:

norbertcsibitech@gmail.com