Privacy Policy

Last updated: July 26, 2026

1. Introduction

Smart Peptide Tracker ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Service").

Smart Peptide Tracker is operated as a sole proprietorship based in Texas, United States. For data protection purposes, we are the data controller of your personal information.

2. Information We Collect

Account Information

  • Email address
  • Display name (if provided)
  • Authentication provider information (Google, Apple, or email/password)

User-Generated Content

  • Peptide inventory and supply information
  • Research protocols and schedules
  • Dose log entries and tracking data
  • Progress measurements (weight, body measurements, mood, energy, notes)
  • Progress photos (compressed and stored within your encrypted account data)
  • Custom peptide information, overrides, and custom half-life values
  • Research appointments and lab work (dates, locations, and notes)
  • Supplier information (names, websites, ratings, and notes)
  • Lab/biomarker results (marker values, reference ranges, lab names)
  • Cost records, including inventory costs, supplier orders, and optional amounts paid for labs. Lab cost amounts are not included in Amino lab snapshots or Health Reports.
  • Community content: reviews, protocol templates, research programs, peptide requests, mentorship messages, and display names you choose to share publicly

Health Data (with your permission)

  • When you connect Apple HealthKit (iOS) or Google Health Connect (Android), we may read weight, body fat percentage, blood pressure, blood glucose, sleep duration and stages, resting heart rate, activity/steps/calories, and blood oxygen saturation (SpO2). HRV and body temperature are currently available only through Apple HealthKit and are not requested from Health Connect on Android.
  • Health data is read-only. We do not write data back to HealthKit or Health Connect.
  • Health data is stored within your encrypted account data in Cloud Firestore
  • Health data is never sold or used for advertising. Selected biomarker context is sent for AI processing only after a separate, explicit opt-in
  • You can disconnect health data access at any time in your device settings

Payment Information

  • We do not directly collect or store credit card or bank account numbers
  • Payments are processed by Stripe (web), Apple (iOS via StoreKit), or Google (Android via Play Billing)
  • We receive and store transaction identifiers, product IDs, and purchase verification status to manage access and prevent purchase replay
  • For physical-product orders, Stripe provides the shipping name, email, and address needed for fulfillment
  • For referrals, we store your referral code, point balance, point ledger, order qualification status, gift and reward status, and program terms acceptance
  • Referral links may store a code and 30-day expiration in the browser. We use Stripe transaction references and delivery status to award, delay, reverse, and reconcile points. Payment card numbers remain with Stripe
  • To detect duplicate or unusual referral activity, we may compare one-way protected versions of checkout email, shipping address, and payment-card fingerprint. Administrators may review referral account IDs, balances, order status, risk signals, and reward status

Automatically Collected Information

  • Technical error reports and diagnostics may include an error message, stack information, page, app version, user agent, session identifier, and recent troubleshooting breadcrumbs
  • Push notification tokens may be stored when notification delivery is enabled
  • Firebase Analytics, Performance Monitoring, and Crashlytics are disabled by default in the current app build
  • Controlled cost telemetry is disabled by default and is used only during an explicitly enabled support diagnostic session

3. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Sync your data across devices via encrypted cloud storage
  • Send schedule reminders and dose notifications (if enabled)
  • Display health trends and protocol impact analysis on your Progress page
  • Power the AI Research Assistant chatbot (see AI Services below)
  • Facilitate community features (reviews, templates, mentorship)
  • Process purchases and manage access status
  • Detect and prevent technical issues and abuse
  • Diagnose errors, prevent abuse, and improve reliability

4. Data Storage and Security

Your data is stored securely using Google Firebase services (data centers located in the United States):

  • Firebase Authentication for secure login
  • Cloud Firestore for data storage
  • Firebase Analytics and Performance Monitoring only after affirmative analytics consent
  • Firebase Cloud Messaging for push notifications

Synced research data is encrypted at rest using AES-256. The encryption key is not stored in plaintext and access requires your PIN or recovery key. Choose a strong PIN, protect your recovery key, and keep your devices secure.

We implement industry-standard security measures to protect your personal information. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

5. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We do not use your data for advertising. We may share information only in the following circumstances:

  • Service Providers: Google Firebase (hosting, authentication, storage, callable processing, optional analytics, and notifications), Stripe (web payments and physical-order fulfillment), Anthropic (user-requested AI processing), Apple, and Google (store purchase processing)
  • AI Services: Only when you request an AI feature, Firebase may send the selected input to Anthropic's Claude API. Depending on the feature and your choices, this can include your question, protocol or inventory context, separately approved biomarker context, a selected lab file, a vial-label image, or a selected body-estimator photo and form values. The app shows feature-specific disclosure and consent before optional sensitive context or an image is sent. Chat questions, response-source metadata, and feedback may be stored for quality and safety review. Anthropic's Privacy Policy applies to its processing.
  • Shared Content: When you use the Share feature to share your inventory or protocols via link, a snapshot of that data is stored in a publicly accessible document. Only the data you explicitly choose to share is included.
  • Webrequests: When you configure a Webrequest, Firebase relays selected event data to the HTTPS endpoint you choose. Depending on your subscriptions, a payload may contain account or profile identifiers and selected dose, protocol, inventory, or supply details. We store the configuration, encrypted endpoint headers, event payloads, and delivery diagnostics. Event and delivery records are normally removed after seven days, and the configuration and logs are deleted with your account. The destination operator receives the data under its own privacy practices. You are responsible for choosing and securing that destination.
  • Community Content: Reviews, templates, research programs, and peptide requests you submit are visible to other users. Display names are optional.
  • Consistency Ranks: If you opt in, we store a private 28-day ranking aggregate and show signed-in members a server-created alias, comparison group, adherence percentage, consistency badge, relative rank, and optional account badge. Protocol names, daily records, account IDs, and partner-profile data are not shown. Rankings are based on member-entered records and are not independently verified. You can leave at any time, which removes the public row and private ranking aggregate.
  • Health Reports: When you generate a PDF health report, the document is created on your device and is not uploaded to our servers. The PDF contains unencrypted personal data including protocol details, biomarker values, and optionally progress photos. You are responsible for how you share or distribute the exported report.
  • Legal Requirements: When required by law or to protect our rights
  • With Your Consent: When you explicitly authorize sharing

6. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of your personal data
  • Export: Export your data in JSON format (available in Settings)
  • Deletion: Delete your account and deletable account data, subject to the limited retention described below
  • Correction: Update or correct your personal data within the app
  • Data Portability: Receive your data in a structured, machine-readable format
  • Restrict Processing: Request that we limit how we use your data
  • Object: Object to certain types of data processing
  • Withdraw Consent: Withdraw previously given consent at any time
  • Analytics Choice: Analytics collection remains disabled unless you provide affirmative consent
  • Disable Notifications: Turn off push notifications in your device settings

To exercise these rights, use the Settings menu in the app, visit the Account and Data Deletion page, or contact us at the email below.

For California Residents (CCPA)

We do not sell your personal information as defined by the California Consumer Privacy Act. You have the right to know what data we collect, request deletion, and not be discriminated against for exercising your privacy rights.

For European Residents (GDPR)

Our legal basis for processing your data is: (a) performance of our contract with you (providing the Service), (b) your consent (for health data access and optional features), and (c) our legitimate interests (analytics, security, service improvement). Your data is transferred to and stored in the United States. By using the Service, you consent to this transfer. You have the right to lodge a complaint with your local data protection authority.

7. Partner Add-on and Multi-Profile Data

The Partner Add-on allows you to manage inventory and protocols for additional people from your account. You are responsible for obtaining consent from any person whose data you enter into the Service. We process this data under the same security and privacy protections as your primary account data.

8. Data Retention

We retain account data while your account is active. When you delete your account, authentication, encrypted sync data, recovery snapshots, community records linked to your account, messages, AI logs and feedback, error logs, notifications, and other deletable account records are removed. Public share snapshots contain no account identifier and can remain accessible until their automatic expiration, no more than eight days after creation. Consistency Ranks entries expire after 72 hours without a refresh and are removed when you leave or delete your account.

We retain only the records needed for physical-order fulfillment, refunds, tax, fraud prevention, legal duties, and store purchase replay protection. Purchase replay records are de-identified by removing the account user ID. A server-only deletion-safety tombstone containing the former internal account ID and deletion timestamps is retained to prevent cached sessions from recreating deleted data. When a referral account is deleted, one-way protected checkout identity signals and unresolved referral debt or review status may be retained for up to seven years to prevent repeated reward abuse. These protected signals are not displayed to other users. Aggregated information that no longer identifies you may also be retained.

9. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy within the app and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

Email: