Effective Date: April 16, 2026 (v2)
PeptideOS+ ("the App," "we," "us") is built with privacy as a core principle. We do not collect, store, or process personally identifiable information (PII). This policy explains what data we handle, where it is stored, and how you consent to that handling.
The first time you open PeptideOS+, you are shown an in-app privacy disclosure screen that lists — in plain language — exactly what data leaves your device and what stays local. You must tap “I Agree & Continue” before the App creates any server-side account or transmits any data. No Supabase session, anonymous user ID, or community post is created prior to your explicit consent.
You may withdraw your consent at any time by using Settings > Data > Delete All Data or by uninstalling the App.
PeptideOS+ does not collect your name, email address, phone number, physical address, date of birth, or any other personally identifiable information. Your identity within the App is represented solely by a pseudonymous UUID and a randomly generated anonymous handle (e.g., Swift-Falcon-2847).
If you choose to sign in with Apple, authentication is handled exclusively through Apple's Sign in with Apple service. We encourage the use of Apple's "Hide My Email" feature. We receive only the opaque user identifier provided by Apple and do not request name or email scopes. Sign in with Apple is optional — the App is fully functional without it, using anonymous authentication.
After you consent, the following is stored on our servers (hosted by Supabase) under your pseudonymous UUID:
That is the full list. We do not upload or store your protocols, dose logs, compliance data, daily check-in entries, supply counts, or calculator history.
Certain features require data to pass through our server in real time to reach a third party. This data is not stored by us after the request completes:
Everything below is stored locally using SwiftData and iOS FileManager. It is never transmitted to our servers:
Progress photos are especially protected: they are stored exclusively in the App's local sandbox via iOS FileManager and are never uploaded to any service.
If you grant permission, PeptideOS+ reads HealthKit data (sleep, heart rate, weight) to enhance wellness tracking. This data is read-only and processed on-device. We do not write to HealthKit and we do not upload HealthKit data to our servers.
All network communication uses TLS encryption. Database access is protected by Supabase row-level security policies ensuring users can only access their own data. Authentication tokens are stored in the iOS Keychain with kSecAttrAccessibleWhenUnlockedThisDeviceOnly. Local data is protected by iOS device encryption.
PeptideOS+ is rated 13+ and is not intended for use by children under 13. We do not knowingly collect data from children under 13.
We may update this privacy policy from time to time. Material changes will be posted within the App and on our website, and you will be prompted to review and re-consent if the changes materially expand our data handling. Continued use of the App after non-material changes constitutes acceptance.
For privacy-related questions or data deletion requests, contact us at privacy@peptideos.app.