Privacy Policy

Last updated February 2026

Peppy stores health-adjacent information that you choose to enter. This page explains what we hold, why, and how you remove it.

What we collect

  • Account data: email address and, if you enter one, a display name.
  • Protocol data: peptides, doses, schedules, vials, dose logs, check-ins, notes, and any bloodwork or progress photos you upload.
  • Assistant conversations and the feedback you leave on replies.
  • Basic technical logs needed to keep the service running and secure.

How it is protected

Every table enforces row-level security, so your records are only readable by your own authenticated account. Uploaded files live in private storage buckets reachable only through short-lived signed links issued to you.

What we never do

  • We do not sell your data.
  • We do not share your protocol data with advertisers or data brokers.
  • We do not use your protocol data to train third-party models.

Processors

We use infrastructure providers for hosting, database, authentication, file storage, model inference for the assistant, and payment processing. They process data only to deliver those functions.

Your controls

Settings includes a full export in JSON and CSV, and account deletion. Deletion removes your database records and your uploaded files, and cannot be undone.

Contact

Questions about this policy can be sent from the Settings page in the app.