Summary
This privacy notice for Blank Labs LLC, a Wyoming limited liability company ("Blank Labs," "we," "us," or "our"), explains how we process personal information when you use PeptidePal (formerly Pep Pal), including its research library, tracking tools, AI research assistant, health synchronization, progress photos, subscriptions, and Community Q&A.
Your complete protocol, dose-log, stack, and chat databases are stored locally on your device and are not conventionally cloud-synced. Selected protocol, dosing, demographic, health-observation, injection-site, conversation, community, product-usage, and attribution information is transmitted when needed for the features and purposes described below.
Our separate Consumer Health Data Privacy Policy provides additional detail about health-related data and applicable rights.
Information We Collect
Account information. When you sign in with Apple or Google, we receive an account identifier and an email address, which may be a relay address. We store account and authentication records through Supabase. We do not receive your Apple ID or Google account password.
Profile, onboarding, and health-related preferences. We collect information you provide about goals, experience level, obstacles, peptides of interest, check-in cadence, age, biological sex, height, and weight. We use this information to personalize PeptidePal and, as described below, some of it may be converted into coarse demographic bands for aggregate product features.
Local protocol and tracking databases. Complete protocol entries, dose logs, custom stacks, schedules, streak history, chat history, and local preferences are stored on your device. We cannot restore these complete databases after you uninstall the app or lose the device. Selected fields from them are transmitted for specific features, including the daily usage report and AI chat described below.
Daily protocol-usage reports. Once per day, PeptidePal may send one entry for each distinct peptide in your active protocols to our backend. A report may include peptide identity, raw scheduled dose, unit, frequency, delivery form, blend information, age/height/weight/BMI bands, biological sex, and goals. Reports are stored using a one-way hash of a device identifier rather than your Blank Labs account identifier and are used to generate aggregate product and community statistics. Aggregate results are suppressed unless enough distinct devices contribute.
Health observations and platform health data. Measurements you enter, such as weight, body fat, lean body mass, waist circumference, and mood, are synchronized to your private PeptidePal account. If you authorize Apple Health or Health Connect, PeptidePal reads the selected observations into its local database and synchronizes them to your private account. If you authorize write access, PeptidePal may also write supported observations back to the applicable health platform.
Progress photos. Photos you choose to capture are stripped of EXIF metadata before upload and stored in a private, account-scoped Supabase storage bucket. They are not displayed to Community members or sent to our AI or advertising providers.
Food-analysis inputs. If you use a food-scanning or food-search feature, the food photo or text you submit is sent through our backend to Anthropic to generate the requested analysis or search result. Food-analysis photos are separate from progress photos.
AI conversations and context. When you use AI chat, PeptidePal sends your message and the conversation supplied for context to our backend. It also automatically generates context from active protocols, including protocol and peptide names, dose amounts, units, and schedules. For supported injection-site questions, recent injection-site history may also be included. The backend sends this information to Anthropic to generate a response.
Community Q&A. We store questions, answers, votes, reports, blocks, a randomly generated pseudonym, an avatar, and moderation records. Questions, answers, votes, pseudonyms, and avatars are visible to other authenticated Community members but are not intended to be publicly indexed on the open web.
Subscription and referral information. We process information needed to determine entitlements and administer purchases made through Apple, Google Play, or Stripe. Depending on the purchase channel, this may include provider, product or plan, subscription status, price and currency, transaction or subscription identifier, current-period dates, trial dates, referral code, and redemption records. Apple, Google, and Stripe process payment methods; we do not receive complete card or store-payment credentials.
Analytics and advertising attribution. We and our providers process device-scoped identifiers, app version, environment, screens and features used, engagement counts, sign-in or registration completion, installs, app opens, trials, subscriptions, purchases, campaign attribution, and related events. We use Meta, AppsFlyer, and Appstack to measure advertising performance and attribute installs, registrations or logins, trials, subscriptions, and purchases. PeptidePal requests Apple App Tracking Transparency permission after you tap Start during onboarding. When you authorize tracking, we may send available sign-in-provider information to Appstack for advertising attribution, Meta campaign matching, and forwarding to Meta: your email address, including an Apple private-relay address; provider-supplied name; and verified phone number. Without ATT authorization, including when permission is denied, restricted, or not authorized, PeptidePal does not add email, name, or phone information to Appstack matching events. We do not share health goals, peptide experience, medical information, health observations, protocol contents, peptide identity, dose amounts, dose logs, injection-site history, progress photos, or free-text health information for advertising matching. AppsFlyer may receive a parameter-free first_dose_logged milestone. Appstack does not receive first-dose or dose-log events, including first_dose_logged. The AppsFlyer milestone contains no peptide, dose, protocol, measurement, name, email, phone, or account identifier.
How We Use Information
We use information to create and secure accounts; provide protocol, dose, health, photo, chat, injection-site, and Community features; synchronize supported observations; personalize the app; generate AI responses; moderate and protect Community Q&A; calculate aggregate product and community statistics; provide support; administer subscriptions and referrals; measure product performance and advertising effectiveness; prevent abuse and fraud; debug and secure the service; and comply with legal obligations.
AI Features and Processing
AI responses are generated by a large language model and may be inaccurate, incomplete, or outdated. PeptidePal's AI is designed for general research and is configured to refuse personalized dose, titration, protocol, cycle, and stack recommendations. It is not medical advice.
Blank Labs does not persist AI messages or responses as server-side chat history. The response is returned to and stored on your device. Our current provider is Anthropic, PBC. Anthropic does not use commercial API inputs and outputs to train its generative models by default. Its standard API retention generally deletes inputs and outputs within 30 days, subject to contractual settings and exceptions for law, safety, and Usage Policy enforcement. Content flagged for suspected policy violations may be retained longer under Anthropic's policies.
Your account email and Supabase user identifier are not included in these AI requests. The Anthropic retention practices described above also apply when Anthropic processes food-analysis inputs or Community content. If we change AI providers or materially change the context sent, we will update this notice.
Community Q&A
Community participation is pseudonymous, not anonymous to Blank Labs: posts are associated with your authenticated account while the account exists, but other members see a generated pseudonym and avatar rather than your account email. Do not post information that directly identifies you or another person.
Community posts are screened by automated moderation before publication. Questions and answers are sent through our backend to Anthropic for that screening, and questions are also processed to generate a concise title and topic classification. Members can report content and block other members. We use Community information to operate, moderate, secure, and improve the forum. We do not use profile health goals, medical history, protocols, dose values, health observations, or progress photos to rank Community content or target advertising within Community.
You can delete your own posts before deleting your account. If you delete your account, your Community profile, pseudonym, votes, and account association are removed, but published questions and answers may remain in disassociated form under a generic member identity.
Service Providers and Other Recipients
- Apple Inc. — Sign in with Apple, App Store purchases, push notifications, Apple Health integration, and platform attribution services.
- Google LLC. — Sign in with Google, Google Play purchases, Health Connect integration, and Google Cloud hosting.
- Supabase Inc. — authentication, Postgres database, and private file storage.
- Anthropic, PBC. — AI response generation from messages, food photos or text, and automatically generated protocol or injection-site context; Community moderation; and question-title and topic generation.
- Superwall Inc. — paywall presentation, purchase and entitlement support, and paywall analytics.
- Stripe, Inc. — direct web checkout, subscription billing, and payment processing.
- TelemetryDeck GmbH. — device-scoped product analytics and engagement counts.
- Meta Platforms, Inc. — limited app-event and campaign-attribution measurement, including campaign matching using contact information sent through Appstack only after ATT authorization.
- AppsFlyer Ltd. — install, registration or login, trial, subscription, purchase, campaign-attribution information, and a parameter-free first_dose_logged milestone.
- Appstack. — install, registration or login, trial, subscription, purchase, and campaign-attribution information. After ATT authorization, matching events may include the available sign-in-provider email, provider-supplied name, and verified phone number described above. Appstack does not receive first-dose or dose-log events.
- Whop. — advertising attribution and conversion measurement from lead, registration, and purchase events. Depending on the event and available attribution context, Whop may receive an email address, an internal account identifier, Whop or campaign identifiers, click and campaign parameters, IP address, user agent, purchase value, and currency. Whop supports conversion reporting to Meta.
- Resend. — delivery of transactional, support, survey, and other service-related emails.
- Other Community members. — content and pseudonymous profile information you choose to publish in Community Q&A.
We may also disclose information when required by law, to investigate abuse or security incidents, to protect rights and safety, or as part of a corporate transaction subject to appropriate safeguards.
Sale, Advertising, and Tracking
We do not sell personal information to data brokers or exchange consumer health data for monetary consideration. We use limited app, device, subscription, milestone, and conversion events with Meta, AppsFlyer, Appstack, and Whop to attribute installs and measure Blank Labs' advertising. PeptidePal requests Apple App Tracking Transparency permission after you tap Start during onboarding. When you authorize tracking, we may send available sign-in-provider information to Appstack for advertising attribution, Meta campaign matching, and forwarding to Meta: your email address, including an Apple private-relay address; provider-supplied name; and verified phone number. Without ATT authorization, including when permission is denied, restricted, or not authorized, PeptidePal does not add email, name, or phone information to Appstack matching events. Whop receives the identified lead, registration, purchase, and attribution information described above and supports conversion reporting to Meta. We do not include progress photos, health measurements, complete protocols, peptide identity, or raw dose values in the PeptidePal conversion payload sent to Whop.
We do not share health goals, peptide experience, medical information, health observations, protocol contents, peptide identity, dose amounts, dose logs, injection-site history, progress photos, or free-text health information for advertising matching. AppsFlyer may receive a parameter-free first_dose_logged milestone. Appstack does not receive first-dose or dose-log events, including first_dose_logged. The AppsFlyer milestone contains no peptide, dose, protocol, measurement, name, email, phone, or account identifier. PeptidePal does not intentionally collect IDFA without permission. Advertising and attribution technologies may use other platform, campaign, or device-scoped signals. Whether an applicable privacy law characterizes a particular attribution flow as a "sale," "sharing," or targeted advertising depends on that law; you may contact us to exercise any applicable opt-out right.
Retention
- Complete local protocol, dose, stack, and chat histories remain until you clear them, delete your account through the app, reset the app, or uninstall it.
- Account, profile, health-observation, and progress-photo records remain while your account is active or until you delete an item, subject to limited backup, security, legal, accounting, and fraud-prevention retention.
- Daily protocol-usage reports use a hashed device identifier rather than your account identifier and may remain in aggregate product-research records.
- Published Community questions and answers may remain after account deletion in disassociated form unless you delete them first.
- Referral and transaction records may be retained or detached from your account as needed for accounting, fraud prevention, and legal compliance.
- Analytics and attribution providers retain information under their own contracts and retention practices.
- Whop conversion records held by Blank Labs or Whop may include an email address, internal account identifier, purchase information, and attribution context and may be retained as reasonably necessary for attribution, accounting, fraud prevention, legal compliance, and dispute resolution.
- Anthropic retention is described in the AI Features and Processing section above.
Security and International Transfers
We use safeguards including TLS, authenticated requests, private storage, row-level database security, and access controls. No security measure is perfect, and we cannot guarantee absolute security.
If we determine that a security incident requires notice, we will notify affected individuals and regulators as required by applicable law.
Blank Labs and its providers may process information in the United States and other countries, which may provide different levels of data protection. We will take measures required by applicable law for cross-border transfers.
Minors
PeptidePal is intended only for adults aged 18 and older. PeptidePal does not currently perform independent age or identity verification. If you believe a minor has provided personal information, contact us so we can investigate and delete it as appropriate.
Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a portable copy of personal information; withdraw consent; object to or opt out of certain processing; and appeal a refusal. These rights may be subject to legal exceptions and identity verification.
Email [email protected] from the address associated with your account and describe your request. You can delete your account in the app under Settings → Delete Account. Additional health-data rights and appeal instructions appear in our Consumer Health Data Privacy Policy.
Account and Data Deletion
In-app account deletion removes your authentication record, profile, account-linked health observations, and progress photos. Local-data clearing may vary by platform and app version; uninstalling PeptidePal removes remaining local application storage from that device. Referral, transaction, conversion, and attribution records may be detached or retained for accounting, fraud prevention, legal compliance, and dispute resolution. Published Community questions and answers may remain in disassociated form, and device-scoped usage records may not be linked to your account. You may email us to request review of additional identifiable records, including Whop conversion records associated with your email address or account identifier.
Account deletion does not cancel an Apple, Google Play, or Stripe subscription. See our Data Deletion page and the Subscriptions section of our Terms of Service.
Global Privacy Control
PeptidePal is a mobile app and does not receive browser-based Global Privacy Control signals. The `blanklabs.io` website does not use a GPC signal to change mobile-app attribution settings or backend conversion measurement. You may email us to exercise an opt-out right that applies to you. Platform privacy and advertising settings may provide additional controls.
Changes and Contact
We may update this notice as our practices or legal obligations change. We will post the revised notice with a new date and provide additional notice when required.
Contact Blank Labs LLC, a Wyoming limited liability company, at [email protected].