← Back to Peptmate

Privacy policy.

Effective 5 September 2026 · Last updated 27 August 2026 · Tech Quarters Pty Ltd, Australia

This Privacy Policy explains what data Peptmate collects, how it is used, and the choices you have. Peptmate is operated by Tech Quarters Pty Ltd (ABN provided on request), Australia. By using Peptmate you agree to this policy. If you do not agree, do not use the app.

Scope of this policy

This policy covers two things, and they collect different data:

You can use one without the other, and nothing joins your website visit to your app account unless you send us a form. Everything from How we use your information onwards applies to both.

Part 1 — the Peptmate app

What Peptmate is

Peptmate is an iOS application that helps you keep a private record of research peptides you choose to track: a personal library, reconstitution and dose details, logged doses, and journaling of subjective effects such as mood, weight, and free-text reflections.

Peptmate does not provide medical advice. All content in the app is descriptive and educational only.

Information we collect in the app

We collect only the information you provide directly through the app, plus minimal device-level telemetry needed to run the service. We do not collect data from advertising networks or background sensors.

Account information

Sign-in providers

You can create your account with email and password, Sign in with Apple, or Google Sign-In. If you use Apple or Google, we receive only your basic profile from them: your name and your email address (Apple lets you hide your real address behind a private relay address, which works fine with Peptmate). We never receive your Apple or Google password, and we get no access to anything else in those accounts. We send nothing back to Apple or Google about how you use Peptmate.

Data you choose to log

You decide what to enter. You can leave any field blank.

Device and usage information

App analytics, and what leaves our own systems

Current status (24 August 2026). The PostHog SDK is present in the app bundle, but it is switched off: no PostHog project is provisioned and the app ships a placeholder token, so nothing described in this section is sent anywhere yet. It takes effect only after the 14-day notice described under Changes to this policy has run, and this note will be removed when it does.

Analytics events are recorded in our own Supabase database, described below. A limited subset is also sent to PostHog, a product-analytics provider we use to understand how people move through the app — for example, how many people finish onboarding, or where they leave the subscription screen.

What we send to PostHog is restricted by an explicit list built into the app. It covers app opens, screen views, onboarding steps, sign-in and account events, and the subscription flow.

We deliberately do not send PostHog anything about your peptide use or health:

PostHog also receives an identifier for your account that is scrambled before it leaves your phone, so PostHog cannot link its records to your Peptmate account or database records. Your events are stored on PostHog’s EU infrastructure. Session replay and error tracking, both of which would capture screen contents, are switched off.

You can turn this off at any time in Settings → Share usage data. Turning it off stops any data reaching PostHog, from the very next event. Peptmate’s own analytics, in our own database, continue either way — they are part of running the service.

What the app does not collect

If you signed up with a creator code

Current status (1 September 2026). Nothing in this section happens yet. No creator can see anything about the people who used their code, because the screen that would show it has not been built and the data is not sent anywhere. It takes effect only after the 14-day notice described under Changes to this policy has run, and this note will be removed when it does.

Some people find Peptmate through a creator or partner and enter that person’s code when they sign up or subscribe. If you did, we report a limited, deliberately coarse summary of your subscription back to that creator, so they can see that their audience is subscribing and be paid for it.

This is the only situation in which anything about your use of Peptmate is reported to someone outside Tech Quarters. If you did not enter a creator code, none of this applies to you.

What the creator sees. One row, which is you, carrying only:

That is the complete list. If a field is ever added to it, this section changes in the same release.

What the creator never sees.

Where the reference comes from. The opaque reference is generated separately for each creator. If two different creators were ever associated with the same code, the same person appears to each of them under a completely unrelated reference, so two creators cannot compare lists and work out who is on both.

Why the month, and not the date. A creator knows when they published the video or post that brought someone in. A join date would let them match a row to a particular day’s audience; a join month does not. For the same reason we do not report the time of day, the device, or anything that could be lined up against a creator’s own records.

Small groups are not shown at all. Being given a reference instead of a name is not the same as being anonymous. A creator with several hundred referred members learns nothing about any individual from a row like this. A creator with three could reasonably work out which friend each row is, what they pay, and whether they cancelled.

So where a creator has referred fewer than five people, no rows are shown to them at all — not the largest few, not a partial list, nothing. They see only their total earnings, and a plain sentence explaining that individual rows are withheld because the group is too small. Showing four rows and hiding the fifth would reveal the fifth by subtraction, so it is all or nothing.

If you would rather not be included, contact us at the address at the end of this policy. You can also delete your account at any time in Settings, which removes your data as described under How long we keep your data.

Part 2 — the peptmate.com website

Website analytics

The website uses privacy-preserving, aggregated analytics provided by Vercel, who also host the site. This records the page path, referring site, approximate country, device type and browser. It sets no cookies, collects no personal information, and builds no profile of you.

Alongside it we use PostHog — the same product-analytics provider and the same EU-hosted project as the app — to understand how people move through the site: which pages are read, which buttons are pressed, and where people leave the two forms. PostHog acts as our processor and may not use the data for its own purposes.

Your consent, and how to opt out

The forms on this website

Two forms collect personal information. Both are optional — you can read every page on the site without using either.

Business partner enquiry, on the business page. We collect your contact name, work email, company, a website or social handle, an optional message, and your tick confirming we may contact you about your enquiry.

Affiliate application, on the creators pages, across four steps:

Alongside either form we record a partner or referral code if you arrived through one, the campaign parameters and referring page that brought you, the page you landed on, a hash of your IP address, and the PostHog identifiers for your session so a submission can be matched to the visit that produced it.

Neither form ever asks for bank details, an ABN, a phone number, a date of birth, a postal address, or screenshots of your follower counts. If we accept your application, payout details are collected separately, afterwards.

Submissions reach a person through an internal Telegram alert containing your name and your enquiry, so we can keep the promise on those pages to reply to everyone.

Part-finished applications, and how long we keep them

The affiliate application saves your answers as you go. A record is created when you finish the first step, before you have submitted anything, so you can close the tab and pick up where you left off. Resuming uses a token held in a strictly functional cookie that expires after 30 days, and a copy in your browser’s local storage.

We send marketing email only to people who have separately opted in to receive it. Ticking a form’s consent box so that we can reply to your enquiry is not that opt-in.

Documents you send with a business enquiry

If you send us a document to support a business partner enquiry — a business registration, a certificate of currency, a certification, a company profile or a price list — it is handled differently from the rest of your enquiry, and it is deleted on a schedule rather than kept.

The file goes straight from your browser into private storage. It is never public, it has no shareable address, and the only way it can be opened is by a member of our team through a link that expires after a minute.

How long we keep it depends on what happened to your enquiry, and the clock starts again if you send us another document:

We keep the enquiry; we delete the file. The record of what you asked us and what we decided survives, because that is the record of a conversation you chose to start. The document attached to it does not.

Deleting our record of a document deletes the file itself. No separate copy is left behind.

You can ask us to erase a document sooner, at any time, without waiting for any of the periods above.

Cloudflare Turnstile

Both forms are protected by Cloudflare Turnstile, which checks that a submission comes from a person rather than a bot. Cloudflare receives your IP address and signals about your browser in order to score the request, and returns a pass or a fail to us. It shows no puzzles, sets no advertising cookie, and does not build a profile of you across sites. Cloudflare’s privacy policy is at cloudflare.com/privacypolicy.

IP addresses

We never store your raw IP address. When you send a form, your IP is normalised and immediately turned into an irreversible hash using a secret salt, and only that hash is written down. It cannot be turned back into your address, and it is used for one thing: spotting abuse and rate-limiting floods of submissions.

We also read the approximate country your request arrives from, to decide whether you must be shown the consent banner and for coarse analytics. That is not stored against your form record. Routine server request logs, which contain IP addresses as any web server’s do, are kept for up to 30 days and then discarded.

Cookies on the website

The calculators

The free calculators on the website run entirely in your browser. The values you enter are not transmitted to us, are not sent to any analytics provider, and are not stored.

Your choices on the website

How we use your information

We do not use your data for advertising, profiling, or any purpose other than running Peptmate.

Where your data is stored

Your app data lives in two places: locally on your iPhone in the app’s sandboxed storage, and on Supabase, our backend infrastructure provider, which hosts our database. Supabase’s data processing terms are at supabase.com/privacy. Row-level security on every table means you can only ever access your own data; other Peptmate users cannot see your information. The one exception is the coarse summary described under If you signed up with a creator code, which carries no name, no email address, no user id and nothing you log — and which applies only if you entered such a code.

Enquiries and applications sent through the website are stored in the same Supabase database, reachable only by us. Analytics events are stored by PostHog on EU infrastructure.

Service providers we use

None of these providers may use your data for their own purposes, and we have no advertising or data-broker relationships with anyone.

How long we keep your data

Your rights

If you are in the EU, UK, or California, you have additional rights under GDPR, UK GDPR, and CCPA respectively. Peptmate does not sell personal information. To exercise any right, email us.

Children’s privacy

Peptmate is not intended for anyone under 17, and we do not knowingly collect information from anyone under 17. If you believe a minor has signed up, contact us and we will delete the account.

Changes to this policy

If we materially change how we collect or use your data, we will update this page and the effective date above, and notify active users in the app or by email at least 14 days before the change takes effect.

Contact

Email: we@peptmate.com
Tech Quarters Pty Ltd, Australia