Privacy Policy
Effective: 14 September 2026.
Summary
Peptisy does not require an account. We do not operate a server that stores your dose logs, vial data or reports. These records stay on your device and sync only through your own Apple iCloud private database, if you turn that on. Messages you choose to send to support are handled separately, as described below.
What we do not collect
Peptisy does not automatically send compound names, dose amounts, weights or other health entries from your records to a server operated by Peptisy. Optional iCloud sync uses your own private database, which Apple encrypts and Peptisy cannot read. You control any records you export or share.
Apple Health
If you turn on the optional Health setting, Peptisy reads your weight from Apple Health on your device only, to show it alongside your dose log. Peptisy never stores this data or syncs it to iCloud. If you turn on the optional write setting, Peptisy adds the weight entries you log in the app to Apple Health; it never writes any other data there.
Analytics
The app and this website use PostHog's EU-hosted, cookie-free behavioral analytics. On the website, PostHog records only explicit calculator, language, and App Store link events. It does not record page views. The website also offers optional Google Analytics measurement of page views, App Store link clicks, language changes, and calculator completion. Google Analytics does not load until you allow it, and you can change that choice through Analytics preferences in the footer. Enhanced measurement and advertising signals are disabled. When allowed, Google Analytics uses a first-party client identifier and collects session statistics, approximate location, and browser and device information. An IP address is used at collection time to derive approximate location and is discarded before it is logged by Google Analytics. Peptisy limits the page value to the origin and path and limits the referrer value to the referring site's origin. URL queries, referring paths, and fragments are removed. Public page paths and titles can contain medication names or health topics. These describe the content visited, not the medication a visitor uses. Calculator entries, user-entered compound names, dose amounts, weights, and other personal health inputs are never sent. Withdrawing Google Analytics consent disables further measurement and removes its first-party cookies; it does not delete data already sent. Both website analytics tools stay off when your browser sends a Do Not Track or Global Privacy Control signal.
App analytics controls
In the iOS app, usage analytics and crash reporting are enabled by default. You can switch both off during onboarding or in Settings, and you can continue setup with them off. This app setting is separate from the website's Analytics preferences. While app analytics is enabled, Peptisy sends explicit usage events, such as onboarding progress and purchase-flow outcomes, with an app-generated identifier. The onboarding question about where you heard about Peptisy requires a choice to continue; your selected category is sent once after successful onboarding completion only if app analytics is enabled at that time. This is your own report of how you found Peptisy, not independently verified install attribution. It does not include a free-text response, medication names, dose amounts or other personal health entries. Switching app analytics off stops subsequent usage events and crash reporting; it does not delete information already sent.
Crash reports
While the app analytics setting is enabled, the app sends crash reports to Sentry, hosted in the EU. Crash reports are scrubbed before they leave your device: no dose data, no health data, no user info, no file paths, and no screenshots. A crash report includes your device and OS model and an anonymous install identifier, not your name or any other information that identifies you.
Purchases
Subscriptions and the lifetime purchase are processed by Apple through the App Store and managed with RevenueCat. RevenueCat receives purchase and receipt information, an anonymous app user ID, and your device's vendor identifier (IDFV) to activate your entitlement and support Restore Purchases. Apple does not provide Peptisy or RevenueCat with your name, email address or payment card details through this purchase flow.
Apple Ads install measurement
Starting with app version 1.0.4, Peptisy enables Apple's standard AdServices install attribution through RevenueCat after onboarding is complete, only while the app analytics setting is on. RevenueCat receives Apple's attribution token and uses Apple's campaign, ad group and keyword information, when available, alongside purchase history to measure which Apple Ads campaigns lead to subscriptions. This does not send your medication names, dose amounts, health records or photos. Peptisy does not request IDFA access or detailed attribution through App Tracking Transparency.
Switching app analytics off immediately stops usage events and crash reports and prevents Apple Ads attribution collection from being enabled on future app launches. An attribution transfer already enabled through the RevenueCat SDK may finish or retry during the current app session; this setting cannot withdraw data already sent. This Apple Ads integration receives attribution data; it does not send RevenueCat subscription lifecycle events to Apple Ads.
Support and feedback
Sending feedback is optional. When you choose Send in Report a problem or Suggest a feature, the app sends your selected category, message, optional reply email address, app version, operating system version, device model and app language to our feedback service on Cloudflare. The service forwards this information to our support inbox through Cloudflare Email Routing so we can review your request and respond. Your IP address is retained in the feedback service's memory to limit repeated requests. The service does not currently enforce a fixed deletion period for those in-memory addresses. This submission is separate from usage analytics and is sent only when you choose to send it, even if app analytics is switched off.
The app does not automatically attach your dose logs, health records or photos to feedback. Anything you type into the message is included, so please avoid sending health information or other sensitive details. If you contact us through your email app instead, we receive the email address and content you send. Deleting records in Peptisy does not delete support correspondence; contact [email protected] about that correspondence.
Request logging for the feedback Worker is disabled. Previously stored logs may remain subject to the provider's retention settings. This does not eliminate Cloudflare's other processing or the IP-address retention described above.
Identifiers
The app uses app-generated identifiers: a PostHog install ID, a RevenueCat app user ID, and your device's vendor identifier (IDFV). If you allow Google Analytics on the website, Google sets first-party analytics identifiers on peptisy.com to distinguish visits. These identifiers are not linked to the app, your name, or calculator entries. Peptisy does not use them to track you across other websites. The iOS app does not track you across apps or websites and does not show an App Tracking Transparency prompt.
Data you control
You can export or delete your data at any time from within the app. Deleting the app removes local data; iCloud data is managed through your Apple ID.
Children's privacy
The Peptisy app is intended for adults aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has sent us personal data, contact [email protected] so we can review the request.
Changes to this policy
Peptisy may update this policy. Material changes will be reflected here with a new effective date.
Contact
Questions about this policy: [email protected].