Privacy Policy

Last updated: 28 May 2026

This Privacy Policy explains what information PeptideKit (“we”, “us”, the “app”) collects, why we collect it, where it is stored, and what choices you have. PeptideKit is an iOS application intended for adults 18 and older. PeptideKit is information and calculation tooling; it is not medical advice.

1. Information we collect

1.1 Account identifiers

When you sign in with Apple, we receive an opaque user identifier from Apple and, if you choose to share it, your name and a relay or real email address. If you sign in with an email magic link, we store the email address you provide. We never store passwords because PeptideKit does not use them.

1.2 Profile attributes you enter

During onboarding and inside the app you may enter optional profile attributes such as display name, units preference, and time-zone. You can edit or remove these at any time.

1.3 Dose log entries

Dose log entries you create — including peptide name, amount, timestamp, and any notes you add — are stored on your device and, if you opt in, synchronised to your private iCloud or to our backend so you can use them across your own devices. We do not read, share, or sell these entries.

1.4 Subscription state

Purchases are processed by Apple. Subscription status is mirrored to RevenueCat, our subscription infrastructure provider, so the app can determine which features to unlock. We receive the subscription tier, renewal status, and the App-Store-issued transaction identifiers. We do not receive your payment card details.

1.5 Product analytics

PeptideKit sends product-analytics events to PostHog (for example, “calculator_used”, “dose_logged”, “paywall_viewed”). These events help us understand which features are useful. We do not include your dose log content, your email address, or any free-text fields in analytics events. Events are tied to a pseudonymous identifier.

1.6 Diagnostic information

If the app crashes, anonymised crash reports may be sent to Apple on your device’s settings. We do not collect device identifiers such as IDFA.

2. Where your data lives

  • Supabase— account records, dose log entries (if you enable cloud sync), and subscription mirror. Hosted in the European Union by default.
  • RevenueCat— subscription receipts and entitlement state.
  • PostHog— pseudonymous product-analytics events.
  • Apple— Sign in with Apple credentials, App Store purchase records, and any iCloud sync you enable.

3. How we use your data

  • To run the calculator and dose log features you use.
  • To authenticate you and protect your account.
  • To deliver and enforce subscription entitlements.
  • To diagnose issues and improve the product.
  • To send reminders you have configured inside the app.

We do not use your data for advertising. We do not sell or rent your data.

4. Retention

We keep your data for as long as you have an account. If you delete your account, your dose log entries and profile are deleted from our backend within thirty days, and analytics events tied to your pseudonymous identifier are disassociated. Backups expire on a rolling thirty-five day window.

5. Your rights

You can export your dose log and profile at any time from inside the app. You can delete your account — which removes your account record, profile, and dose log entries — from inside the app. You may also contact us at shrivastava.utkarsh4517@gmail.com to exercise any rights granted to you by applicable law, including access, correction, portability, and deletion.

6. No sale of data

We do not sell your personal information, and we do not share it with advertising networks or data brokers.

7. Children

PeptideKit is not directed at children under the age of 18 and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.

8. Security

Data in transit is encrypted with TLS. Data at rest in our backend is encrypted using the provider’s default mechanisms. Access to production systems is restricted to authorised personnel.

9. Changes to this policy

We may update this policy from time to time. When we do, we will update the “Last updated” date at the top and, if the changes are material, surface a notice inside the app.

10. Contact

For any privacy question or request, email shrivastava.utkarsh4517@gmail.com. We respond within three business days.