Scope
This Consumer Health Data Privacy Policy explains how Blank Labs LLC, a Wyoming limited liability company ("Blank Labs," "we," "us," or "our"), collects, uses, and discloses consumer health data through PeptidePal. It supplements our PeptidePal Privacy Policy and is intended to provide the disclosures required by consumer health privacy laws, including Washington's My Health My Data Act, where those laws apply.
PeptidePal is a research, reference, tracking, and community product. It is not a healthcare provider, covered entity, or business associate under HIPAA, and it does not provide diagnosis or treatment.
Consumer Health Data We Collect
Depending on the features you use, we may collect or process the following categories of consumer health data:
- Goals and profile information: age, biological sex, height, weight, goals, experience level, obstacles, peptides of interest, and check-in preferences.
- Protocol and dosing information: peptide identity, dose amount and unit, frequency, delivery form, schedule, protocol composition, dose-history counts, and injection-site history.
- Health observations: measurements you enter or authorize PeptidePal to read from Apple Health or Health Connect, such as weight, body fat, lean body mass, waist circumference, and related observations.
- Progress photos: photos you choose to capture and upload to track changes over time.
- Food-analysis inputs: food photos or food-search text you choose to submit to an AI-powered food feature.
- AI conversations: messages you send, prior messages supplied for conversational context, and automatically included context about active protocols and recent injection sites.
- Community content: health-related questions, answers, votes, reports, and other interactions you choose to submit in Community Q&A.
- Product and attribution events: device-scoped events and counts that may reveal use of a health-related app or feature, including a milestone indicating that a first dose was logged.
Sources of Consumer Health Data
We collect consumer health data directly from you; from your use of PeptidePal's protocol, tracking, photo, chat, and community features; from Apple Health or Health Connect when you authorize access; from your device and app interactions; and from information derived from those sources, such as coarse demographic bands, protocol summaries, dose counts, and aggregate usage statistics.
Why We Collect and Use It
We collect and use consumer health data to provide the features you request, including account personalization, protocol and dose tracking, health synchronization, progress tracking, AI research responses, injection-site rotation support, Community Q&A, account deletion, and customer support.
We also use limited device-scoped protocol and dosing information to calculate aggregate community usage statistics and limited app, purchase, and conversion events to understand product engagement and measure the effectiveness of Blank Labs' advertising. AppsFlyer and Appstack receive a parameter-free event indicating that a first dose was logged. Whop receives identified lead, registration, purchase, and attribution information, which may include an email address and internal account identifier, and supports conversion reporting to Meta. We do not include progress photos, health measurements, complete protocols, peptide identity, or raw dose values in the PeptidePal conversion payload sent to Whop.
How Data Is Stored and Transmitted
Your complete protocol, dose-log, stack, and chat databases are stored locally on your device and are not conventionally cloud-synced. Selected information from those databases is nevertheless transmitted when required by a feature you use.
- Once per day, PeptidePal may send active-protocol peptide identity, raw scheduled dose, unit, frequency, delivery form, coarse demographic bands, and goals to our backend. These reports are stored using a one-way hash of a device identifier rather than your Blank Labs account identifier and are used for aggregate statistics.
- When you use AI chat, PeptidePal sends the conversation and automatically generated context about active protocols and recent injection sites through our backend to our AI provider.
- If you use a food-scanning or food-search feature, the food photo or text you submit is sent through our backend to our AI provider.
- Health observations you enter or authorize PeptidePal to read from Apple Health or Health Connect are synchronized to your private PeptidePal account.
- Progress photos are uploaded to private, account-scoped cloud storage after metadata stripping.
- Community questions and answers are stored on our servers, sent to our AI provider for moderation and, for questions, title and topic generation, and displayed under a pseudonym to other authenticated members.
Disclosures and Recipients
We disclose consumer health data or health-related app information to the following categories of recipients for the purposes described above:
- Cloud and database processors: Supabase and Google Cloud host account data, health observations, photos, community content, backend requests, and related service infrastructure.
- AI provider: Anthropic processes chat messages, conversation history, food photos or text, and protocol or injection-site context to generate AI responses. Anthropic also processes Community questions and answers for moderation and processes questions to generate titles and topic classifications.
- Health platforms: Apple Health and Health Connect provide or receive selected health observations when you authorize the applicable read or write permission.
- Analytics and attribution providers: TelemetryDeck receives device-scoped product events and counts. Meta, AppsFlyer, and Appstack receive limited install, app-open, registration, purchase, or attribution events; AppsFlyer and Appstack also receive a parameter-free event indicating that a first dose was logged. Whop receives lead, registration, purchase, and attribution information, which may include email, an internal account identifier, Whop or campaign identifiers, click and campaign parameters, IP address, user agent, purchase value, and currency, and supports conversion reporting to Meta.
- Subscription providers: Apple, Google, Stripe, and Superwall process subscription, purchase, entitlement, paywall, and transaction information.
- Other Community members: questions, answers, votes, pseudonyms, and avatars you publish are visible to authenticated Community members.
- Legal and safety recipients: we may disclose information when required by law or when reasonably necessary to protect users, the service, or the public.
We do not sell consumer health data. We do not use geofences around healthcare facilities to identify or collect consumer health data.
Retention and Deletion
- Local protocol, dose, stack, and chat histories remain on your device until you clear them, delete your account through the app, reset the app, or uninstall it.
- Account-linked health observations and progress photos remain until you delete the item or your account, subject to limited backup, security, legal, and fraud-prevention retention.
- Daily protocol-usage reports are keyed to a hashed device identifier rather than your account identifier and may remain in aggregate product-research records.
- Published Community posts remain after account deletion in disassociated form and are displayed under a generic member identity unless you delete them before deleting your account.
- Blank Labs does not retain a server-side AI chat history. Anthropic's standard API retention generally deletes inputs and outputs within 30 days, subject to its contractual, legal, safety, and abuse-prevention exceptions.
- Analytics, attribution, subscription, support, security, and transaction records are retained as reasonably necessary for their stated purposes and as required by law.
- Whop conversion records held by Blank Labs or Whop may be account-linked and may remain after account deletion where reasonably necessary for attribution, accounting, fraud prevention, legal compliance, or dispute resolution. You may request review of identifiable records through the contact method below.
See our Data Deletion page for account-deletion instructions.
Your Consumer Health Data Rights
Subject to applicable law, you may have the right to confirm whether we collect, share, or sell your consumer health data; access that data; receive information about recipients; withdraw consent from future collection or sharing; and request deletion. You may not be discriminated against for exercising these rights.
You can delete your account in PeptidePal under Settings → Delete Account. To make another consumer health data request, email [email protected] from the email address associated with your account and describe your request. We may request information reasonably necessary to authenticate you.
If we refuse to act on a request, you may appeal by replying to our decision or emailing [email protected] with the subject "Appeal consumer health data decision." We will process requests and appeals within the periods required by applicable law.
Changes to This Policy
We may update this policy when our practices or legal obligations change. We will post the revised policy with a new effective date and provide any additional notice or consent required by law before collecting, using, or sharing new categories of consumer health data or using existing data for materially new purposes.
Contact
Blank Labs LLC is a Wyoming limited liability company. Questions and requests may be sent to [email protected].