Privacy Policy
Peptid AI · Last updated: 2026-05-26
Plain Language Summary
The short version
- • Peptid AI is a tracking, organisation, and educational app for peptide and GLP-1 related information.
- • It is not a medical device and does not provide medical advice, diagnosis, or dosing instructions.
- • The app works offline first, then syncs your tracking data to your private account on our backend (Supabase, hosted in the EU) so it's available across your devices. An anonymous account is created automatically — you can sign in to keep your data if you change devices.
- • Apple Health and Health Connect are optional and read-only. If you connect them, the metrics we read (weight, body fat, sleep, water, steps, active energy) sync to your private account so you can see them in the app — we never write back to your health store, never sell this data, and never use it for ads or AI training.
- • We do not sell your data.
- • We do not share your data for advertising, profiling, or cross-site tracking.
- • We do not use your data to train AI models.
- • You may access, correct, export, or delete your data at any time.
- • If we're ever acquired, your data transfers under the same protections — and any new uses require notice and your consent where law requires.
This summary is for convenience only. The full Privacy Policy below controls.
1.Who is responsible (controller)
Peptid AI is operated by Alex Kem, a registered small business under § 19 UStG, based in Bad Salzuflen, Germany. As the data controller within the meaning of Art. 4(7) GDPR, we are responsible for the processing of personal data described in this Policy.
Postal address and legal details: see the imprint.
Privacy contact: [email protected]
2.Where this policy applies
- The Peptid AI mobile app (iOS and Android)
- The Peptid AI website (peptideia.app)
- Support communications you send us
3.Medical disclaimer
Peptid AI provides tracking, organisation, educational, and informational features only. Peptid AI is not a healthcare provider, medical device, pharmacy, or telehealth service. Any information provided through the App — including educational summaries, calculations, estimates, reminders, or tracking insights — is for informational and organisational purposes only. Always consult a qualified healthcare professional before making health-related decisions.
4.What we process
Account information (only if you create an account)
- Name (if provided), email address, authentication provider (Apple/Google), account ID, basic settings.
Onboarding choices
- Goals, baseline metrics, peptide experience, preferences.
Tracking data (synced to your account)
- Peptide and protocol names; vial inventory and reconstitution details; dose logs; injection sites; side effects / symptoms / journal entries; sleep, recovery, body metrics; bloodwork values and attached reports; progress photos and daily check-ins; notes, reminders, custom entries.
The app caches this data on your device so it works offline, then syncs it to your private account on our backend (Supabase, hosted in the EU) so it is available across your devices. You can also export a copy at any time to your own iCloud / Google Drive / Files. We never sell it or use it for advertising or AI training.
Apple Health & Health Connect (optional, with your permission)
With your explicit permission, Peptid AI reads (read-only) from Apple Health (HealthKit) on iOS and Health Connect on Android. We read only weight, body-fat percentage, sleep, water intake, steps, and active energy. We never write to your Apple Health or Health Connect store.
The metrics we read are saved to your private account on our backend (Supabase, EU-hosted) so they appear in the App, sync across your devices, and can be used by the in-app AI Coach as context when you ask it a question. We do not use this data to train AI models, and we do not use it for advertising, profiling, or cross-context behavioural advertising. We never sell it or share it with data brokers. You can grant or revoke this access at any time in your device's Apple Health or Health Connect settings; revoking it stops further syncing but does not delete data already stored in Peptid AI. To delete data already in the App, use the in-app delete options or the account-deletion page.
AI Coach & photo scanning
When you use the AI Coach, the food/label photo scanner, or the barcode tools, the text and images you submit are sent through our backend (Supabase Edge Functions) to third-party AI providers — DeepSeek, OpenAI, and Google (Gemini) — solely to generate your response. Under those providers' API terms, this input is not used to train their models. Please don't submit anything you wouldn't want processed this way. Barcode lookups query the public Open Food Facts database.
Subscription & payment information
Apple or Google processes your payment. We never see your card number. We receive a billing identifier so we can grant the entitlement you paid for.
Device & diagnostic information
- Device model, OS version, app version, anonymised crash reports via Sentry (≤ 90 days), basic request logs for security (≤ 30 days), IP at the time of request.
Contact form
When you contact us via the website form we receive your name, email, subject category, and message. Delivery is handled by FormSubmit.co on our behalf.
What we do NOT collect
We do not collect special categories of data (race, ethnicity, religion, sexual orientation, biometric identifiers). Peptid AI is for adults 18 and over, and we do not knowingly collect data from anyone under 18.
5.Purposes and legal bases (GDPR Art. 6 & 9)
- Performance of contract — Art. 6(1)(b): providing the App and subscription you purchased.
- Legitimate interest — Art. 6(1)(f): anti-abuse, anonymised diagnostics, security monitoring. You may object — see “Your rights”.
- Consent — Art. 6(1)(a) / Art. 9(2)(a): optional features (e.g., cloud backup, optional analytics). Any processing of health data beyond what is essential to provide the service relies on your explicit consent.
- Legal obligation — Art. 6(1)(c): retaining purchase records as required by German tax and consumer law.
We do not use your personal health data to train AI models, sell it, share it for cross-context behavioural advertising, or process it for any purpose beyond what is described in this Policy.
6.Sharing & processors
We do not sell, rent, or share personal data with brokers. We use a minimal set of processors strictly to operate the service:
- Supabase — app backend (EU region): authentication, the database and storage that hold your account and tracking data, and the Edge Functions that route AI requests.
- DeepSeek, OpenAI, Google (Gemini) — process the text and images you submit to the AI Coach and scanners, only to generate your response; not used to train their models.
- Open Food Facts — public food database queried for barcode lookups.
- Apple App Store / Google Play — app distribution and in-app purchases.
- Vercel — website hosting.
- Sentry — anonymised crash diagnostics (event IDs only).
- FormSubmit.co — contact-form delivery.
- Optional manual export — when you export a copy of your data, it is saved to the location you choose (e.g. your own iCloud / Google Drive / Files).
Each processor is bound by contract (Auftragsverarbeitungsvertrag / DPA + Standard Contractual Clauses where applicable). We do not use Google Analytics, Firebase Analytics, Mixpanel, AppsFlyer, Meta Pixel, TikTok Pixel, or any advertising SDK.
7.International transfers
Our primary backend (Supabase) is hosted in the EU. Some processors may store or process data outside the European Economic Area — in particular the AI providers that handle AI Coach and scanner requests (OpenAI and Google in the United States, DeepSeek in China). Where this happens, transfers are protected by the European Commission's Standard Contractual Clauses (SCCs) together with supplementary measures as required by the EDPB and the CJEU's Schrems II decision. Only the content you submit to those features is processed this way; you can avoid these transfers by not using the AI Coach or photo/label scanners.
8.Retention
- Your tracking data: kept until you delete it. Wipe it in-app under Settings → tap your profile → Delete account (or Settings → Data → Delete my data to clear data while keeping the account).
- Account record: deleted within 30 days of an account-deletion request.
- Subscription records: retained for the period required by German tax law (typically 10 years per § 147 AO).
- Crash diagnostics: up to 90 days, then auto-deleted.
- Anti-abuse logs: up to 30 days, then auto-deleted.
- Support emails: up to 24 months from last interaction.
9.Your rights (GDPR / UK GDPR)
Under GDPR and UK GDPR, you have the right to:
- Access (Art. 15) — request a copy of your data.
- Rectification (Art. 16) — correct inaccurate data.
- Erasure (Art. 17) — “right to be forgotten”.
- Restriction (Art. 18) — limit how we use your data.
- Portability (Art. 20) — receive your data in a machine-readable format.
- Object (Art. 21) — to processing based on legitimate interest.
- Withdraw consent (Art. 7(3)) — at any time, without affecting prior processing.
- Lodge a complaint with your supervisory authority. In Germany this is your state DPA (for North Rhine-Westphalia: LDI NRW) or the BfDI for federal matters.
To exercise any right, email [email protected] or use the account-deletion page. We respond within 30 days as required by Art. 12(3) GDPR.
10.Users outside the EU
Where Peptid AI is available outside the EU, we honour comparable rights granted by your local law:
- United Kingdom: UK GDPR rights as listed above; complaints to the ICO.
- California (CCPA / CPRA): right to know, delete, correct, opt out of sale/sharing (we do neither), limit use of sensitive personal information (we don't collect any), non-discrimination.
- Washington & Nevada: rights under the Washington My Health My Data Act and Nevada consumer-health-data law apply to users in those states; we do not sell consumer health data.
- Brazil (LGPD), Canada (PIPEDA / Quebec Law 25), Australia (Privacy Act 1988), other countries: comparable rights of access, correction, deletion, and consent are honoured.
To exercise any of these rights, use the same email address. We honour Global Privacy Control (GPC) signals where applicable.
11.Do Not Sell / Share / Track
We do not sell personal information. We do not share personal information for cross-context behavioural advertising. We do not engage in cross-site tracking.
12.Security
Data on your device is protected by your device's OS-level encryption. Server infrastructure uses TLS 1.2+ in transit and AES-256 at rest. We follow industry-standard administrative, technical, and physical safeguards. In the unlikely event of a breach affecting your data, we will notify the relevant supervisory authority and you in line with Art. 33–34 GDPR.
13.Children
Peptid AI is intended for adults 18 and over, consistent with our Terms of Service. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
14.Automated decision-making
We do not make decisions that significantly affect you using solely automated processing (Art. 22 GDPR). We do not profile you for advertising.
15.Business transfers
If Peptid AI or substantially all of its assets are involved in a merger, acquisition, financing, sale of assets, or similar transaction, user information may transfer to the acquiring or successor entity. Any future use of personal data remains subject to applicable law, required notices, your rights, and any consent or opt-out required.
16.Changes
Material changes will be surfaced in-app and reflected in an updated effective date. For substantive changes that affect your rights, we will seek fresh consent where required.
17.Contact
Email: [email protected]
Web form: peptideia.app/contact
Postal address & legal entity: see the imprint.