The legal version of this is in our Privacy Policy. This page is the plain-English version — what we actually built, in language you can verify against the app itself.
The default: local-first, on your device
When you install PeptideLab, the core tracking works offline. Protocols, dose logs, side effects, biomarkers, custom compounds, measurements — all of it lives in a database on your phone first.
You can use the core app without ever adding an email address, and you can track offline. At first launch the app creates an anonymous account— a random identifier with no email, name, or contact details — and by default your tracking data is backed up to our servers under it, so a lost or replaced phone doesn’t mean lost data. If you’d rather keep everything on the phone, one toggle in Settings → Privacy & Data turns backup off, and the app works identically without it.
We chose this architecture because health data is sensitive and because we believe the burden of proof is on us to justify any moment your data leaves your phone. This page is that justification, item by item — what leaves, why, and how to turn each piece off.
When data does leave your device
A few things can cause your data to leave your device. Each one is optional, and each happens because of something you turn on or choose to use.
Cloud backup (on by default, one toggle to turn off)
Your tracking data is backed up to our servers — under your anonymous account from first launch, or under your email account once you add one — so you can restore your protocols on a new phone. You can turn this off at any time in Settings → Privacy & Data, and the app works identically with it off.
When backup is on:
- Your tracking data is copied to encrypted storage on our servers.
- Data is encrypted in transit and at rest.
- It’s there for one purpose: to let you restore it on another device.
- We do not analyze it. We do not run product reports against it. We do not use it to make decisions about features.
- You can turn it off at any time. Turning it off stops new data from leaving your phone; your last backup stays stored until you delete your account, so an accidental toggle never destroys anything.
If you’d prefer that we cannot read your backup at all — meaning end-to-end encryption with a key only you hold — that capability is on our roadmap. Today, our cloud backup is encrypted in storage but technically readable by our systems. We don’t read it, but we want to be honest that we technically could. When we ship key-based encryption, we’ll surface it as a clearly labeled option.
Accounts: anonymous by default, email optional
Every install gets an anonymous account — a random identifier with no email, name, or contact details attached. It exists so your backup, subscription, and settings have something to belong to. Adding an email address (via magic link) or Apple/Google sign-in is optional: it is what lets you sign back in if you lose the phone, and use PeptideLab on more than one device. We do not store passwords. If you add an email, the data under your anonymous account carries over.
Anonymous accounts that never back anything up are deleted after about 30 days; anonymous backups that show no activity for about 180 days may be deleted too. Adding an email exempts your account from that cleanup.
Lab Assistant AI (optional)
Lab Assistant is an optional AI feature, off until you choose to use it. When you ask it something, PeptideLab sends relevant information from your data — the context needed to answer what you asked — to our third-party AI provider, Anthropic, which generates the response. This only happens when you use Lab Assistant. If you never use it, nothing goes to Anthropic.
Anthropic processes this API data according to its own applicable commercial / API terms and data-retention settings. We don’t use your Lab Assistant conversations to train PeptideLab’s own models. We’re not going to claim Anthropic keeps nothing or stores nothing — what happens to API data on their side is governed by their terms and the retention settings in place, and we’d rather point you there than overpromise.
What we collect that isn’t your tracking data
To operate and improve the app, we collect a small amount of operational information:
- Crash and error diagnostics so we can fix bugs.
- Usage events— for example, “the calculator screen was opened” — so we can see what features are used and what might be broken. These events do not contain the contents of your tracking data. Logging a dose of BPC-157 at 250mcg sends us “a dose was logged,” not the compound name or amount.
- A few profile details, attached to those events:your biological sex, your age (an exact age in years, not a range), and an approximate region derived from your IP address (not precise location). We attach these so we can understand who finds PeptideLab useful and where people drop off during setup — including before you create an account, and merged into your account if you make one. They stay separate from the contents of your tracking data above: knowing your age doesn’t tell us what you logged.
- Device and app version information so we can debug platform-specific issues.
Analytics is consent-gated, and you can turn it off entirely — events and the profile details above — in Settings → Privacy & Data.
What we do not do
We do not:
- Sell your data, or share it with data brokers.
- Use your tracking data for advertising.
- Use your tracking data or your Lab Assistant conversations to train PeptideLab’s own machine-learning models. (If we ever add a feature that learns from user data, it will require a separate opt-in with its own explanation, and we’ll explain exactly what data is involved.)
- Run cross-app tracking pixels, advertising trackers, or anything else that would let third parties profile you based on your activity in PeptideLab.
How to get your data back
You can:
- Export individual protocols as PDF or CSV at any time from inside the app.
- Disable cloud backup to stop syncing. Your last backup stays stored until you delete your account, so flipping the toggle by accident never costs you your data.
- Delete your accountentirely, in-app. This removes your auth record, your profile, and all your server-side tracking data immediately. There’s no email-support detour and no waiting period.
A comprehensive “download all my data in one file” export is on our roadmap. Until then, individual exports cover most needs.
When you’re not sure
Send us a question at support@peptidelabapp.com. We answer privacy questions in plain English.