Privacy policy.
Effective 5 September 2026 · Last updated 27 August 2026 · Tech Quarters Pty Ltd, Australia
This Privacy Policy explains what data Peptmate collects, how it is used, and the choices you have. Peptmate is operated by Tech Quarters Pty Ltd (ABN provided on request), Australia. By using Peptmate you agree to this policy. If you do not agree, do not use the app.
Scope of this policy
This policy covers two things, and they collect different data:
- The Peptmate iOS app — your account, what you log, and the analytics the app sends. Described in Part 1.
- The peptmate.com website — the marketing pages, the free calculators, and the business enquiry and affiliate application forms. Described in Part 2.
You can use one without the other, and nothing joins your website visit to your app account unless you send us a form. Everything from How we use your information onwards applies to both.
Part 1 — the Peptmate app
What Peptmate is
Peptmate is an iOS application that helps you keep a private record of research peptides you choose to track: a personal library, reconstitution and dose details, logged doses, and journaling of subjective effects such as mood, weight, and free-text reflections.
Peptmate does not provide medical advice. All content in the app is descriptive and educational only.
Information we collect in the app
We collect only the information you provide directly through the app, plus minimal device-level telemetry needed to run the service. We do not collect data from advertising networks or background sensors.
Account information
- Email address (your login identifier)
- Optional display name, date of birth, biological sex, height
- Account creation date and last login timestamp
Sign-in providers
You can create your account with email and password, Sign in with Apple, or Google Sign-In. If you use Apple or Google, we receive only your basic profile from them: your name and your email address (Apple lets you hide your real address behind a private relay address, which works fine with Peptmate). We never receive your Apple or Google password, and we get no access to anything else in those accounts. We send nothing back to Apple or Google about how you use Peptmate.
Data you choose to log
- Peptides in your library (name, vial strength, dose, schedule)
- Logged doses (date, time, injection site, optional note)
- Weight entries, mood entries, and journal reflections you write
- Peptide lifecycle events (added, reconstituted, refilled, marked finished)
- Preferences (notifications, units, time format, appearance)
You decide what to enter. You can leave any field blank.
Device and usage information
- App version, iOS version, and device model (when you submit feedback)
- In-app analytics events (which screens you open, when you log a dose, when you complete onboarding). Event names are factual; we do not capture screen contents or your written text in analytics.
App analytics, and what leaves our own systems
Current status (24 August 2026). The PostHog SDK is present in the app bundle, but it is switched off: no PostHog project is provisioned and the app ships a placeholder token, so nothing described in this section is sent anywhere yet. It takes effect only after the 14-day notice described under Changes to this policy has run, and this note will be removed when it does.
Analytics events are recorded in our own Supabase database, described below. A limited subset is also sent to PostHog, a product-analytics provider we use to understand how people move through the app — for example, how many people finish onboarding, or where they leave the subscription screen.
What we send to PostHog is restricted by an explicit list built into the app. It covers app opens, screen views, onboarding steps, sign-in and account events, and the subscription flow.
We deliberately do not send PostHog anything about your peptide use or health:
- Not your dose amounts, and not the fact that you logged a dose at all
- Not the names of peptides in your library
- Not your weight, mood, or journal entries
- Not your promo or affiliate codes, only whether one was used
PostHog also receives an identifier for your account that is scrambled before it leaves your phone, so PostHog cannot link its records to your Peptmate account or database records. Your events are stored on PostHog’s EU infrastructure. Session replay and error tracking, both of which would capture screen contents, are switched off.
You can turn this off at any time in Settings → Share usage data. Turning it off stops any data reaching PostHog, from the very next event. Peptmate’s own analytics, in our own database, continue either way — they are part of running the service.
What the app does not collect
- No access to your contacts, photos, microphone, camera, calendar, or location
- No advertising, and no third-party advertising SDKs. The only third-party SDK in the app that can carry usage data is PostHog, described above
- No Apple HealthKit access
- No tracking across other apps or websites, and no advertising or data-broker relationships with anyone
- We never sell or rent your data to anyone
If you signed up with a creator code
Current status (1 September 2026). Nothing in this section happens yet. No creator can see anything about the people who used their code, because the screen that would show it has not been built and the data is not sent anywhere. It takes effect only after the 14-day notice described under Changes to this policy has run, and this note will be removed when it does.
Some people find Peptmate through a creator or partner and enter that person’s code when they sign up or subscribe. If you did, we report a limited, deliberately coarse summary of your subscription back to that creator, so they can see that their audience is subscribing and be paid for it.
This is the only situation in which anything about your use of Peptmate is reported to someone outside Tech Quarters. If you did not enter a creator code, none of this applies to you.
What the creator sees. One row, which is you, carrying only:
- An opaque reference — a meaningless string of characters, not your name, not your email address, and not your Peptmate user id
- The month you joined — the month only, never the day
- Your plan tier — for example monthly or annual
- Whether your subscription is currently active or has lapsed
- How many months you have been subscribed
- What your subscription has earned that creator
That is the complete list. If a field is ever added to it, this section changes in the same release.
What the creator never sees.
- Your name, your email address, or your Peptmate user id
- The day you joined, or any day-level date at all
- Your device, your location, or your IP address
- Anything you log in the app. No doses, no peptides, no weights, no feelings, no journal entries, no reminders, no notes — nothing health-related of any kind, ever. None of it leaves our systems and none of it is part of this report.
- Anything about any other Peptmate user, and no comparison between creators
Where the reference comes from. The opaque reference is generated separately for each creator. If two different creators were ever associated with the same code, the same person appears to each of them under a completely unrelated reference, so two creators cannot compare lists and work out who is on both.
Why the month, and not the date. A creator knows when they published the video or post that brought someone in. A join date would let them match a row to a particular day’s audience; a join month does not. For the same reason we do not report the time of day, the device, or anything that could be lined up against a creator’s own records.
Small groups are not shown at all. Being given a reference instead of a name is not the same as being anonymous. A creator with several hundred referred members learns nothing about any individual from a row like this. A creator with three could reasonably work out which friend each row is, what they pay, and whether they cancelled.
So where a creator has referred fewer than five people, no rows are shown to them at all — not the largest few, not a partial list, nothing. They see only their total earnings, and a plain sentence explaining that individual rows are withheld because the group is too small. Showing four rows and hiding the fifth would reveal the fifth by subtraction, so it is all or nothing.
If you would rather not be included, contact us at the address at the end of this policy. You can also delete your account at any time in Settings, which removes your data as described under How long we keep your data.
Part 2 — the peptmate.com website
Website analytics
The website uses privacy-preserving, aggregated analytics provided by Vercel, who also host the site. This records the page path, referring site, approximate country, device type and browser. It sets no cookies, collects no personal information, and builds no profile of you.
Alongside it we use PostHog — the same product-analytics provider and the same EU-hosted project as the app — to understand how people move through the site: which pages are read, which buttons are pressed, and where people leave the two forms. PostHog acts as our processor and may not use the data for its own purposes.
- Purpose. Measuring the site: pages viewed, calls to action pressed, App Store taps, calculator use, and progress through the enquiry and application forms.
- Region. Events are sent to PostHog’s EU infrastructure, the same region the app uses, and are routed through peptmate.com rather than direct to PostHog.
- What is never sent. No value you type into a field. When a form step fails validation we record which fields failed, never what you entered. Calculator inputs are never sent — only the fact that a calculator was used.
- Identity. Most visits are anonymous and no person profile is created. A profile is created at only two moments — when you submit the business enquiry form, and when you submit the affiliate application — and it is keyed on a one-way hash of your email address, never the address itself.
- Session replay is off. We do not record your screen or your typing.
Your consent, and how to opt out
- If you are in the EU, UK, EEA or Switzerland, nothing is sent to PostHog until you accept the banner shown on your first visit. Decline and no analytics events are captured at all.
- Elsewhere, including Australia, analytics start on load and you can opt out at any time using the opt-out control on this page. Opting out takes effect immediately and clears any PostHog cookie.
- We honour Global Privacy Control everywhere. If your browser sends a GPC signal we treat it as an opt-out, whichever region you are in, without you having to do anything else.
- Using the forms never requires analytics consent. Declining or opting out does not stop you sending us an enquiry or an application.
The forms on this website
Two forms collect personal information. Both are optional — you can read every page on the site without using either.
Business partner enquiry, on the business page. We collect your contact name, work email, company, a website or social handle, an optional message, and your tick confirming we may contact you about your enquiry.
Affiliate application, on the creators pages, across four steps:
- Your full name, email and country, plus your Australian state if you give one
- The platforms you create on, your handle or URL on each, and a follower band rather than an exact number
- The niches you cover, and a short description of your audience
- Optionally, how you would work with us and any existing partnerships, plus your acceptance of the partner terms
Alongside either form we record a partner or referral code if you arrived through one, the campaign parameters and referring page that brought you, the page you landed on, a hash of your IP address, and the PostHog identifiers for your session so a submission can be matched to the visit that produced it.
Neither form ever asks for bank details, an ABN, a phone number, a date of birth, a postal address, or screenshots of your follower counts. If we accept your application, payout details are collected separately, afterwards.
Submissions reach a person through an internal Telegram alert containing your name and your enquiry, so we can keep the promise on those pages to reply to everyone.
Part-finished applications, and how long we keep them
The affiliate application saves your answers as you go. A record is created when you finish the first step, before you have submitted anything, so you can close the tab and pick up where you left off. Resuming uses a token held in a strictly functional cookie that expires after 30 days, and a copy in your browser’s local storage.
- If you never submit it, the part-finished application is deleted 60 days after you last touched it.
- We will never contact you about it. A part-finished application is not marketing consent. It is never added to a mailing list, and we do not send “finish your application” reminders.
- If you submit it and we do not accept it, we keep the record, because it is the record of an application you made and of the terms you accepted at the time. You can ask us to erase it.
We send marketing email only to people who have separately opted in to receive it. Ticking a form’s consent box so that we can reply to your enquiry is not that opt-in.
Documents you send with a business enquiry
If you send us a document to support a business partner enquiry — a business registration, a certificate of currency, a certification, a company profile or a price list — it is handled differently from the rest of your enquiry, and it is deleted on a schedule rather than kept.
The file goes straight from your browser into private storage. It is never public, it has no shareable address, and the only way it can be opened is by a member of our team through a link that expires after a minute.
How long we keep it depends on what happened to your enquiry, and the clock starts again if you send us another document:
- If nobody has picked your enquiry up, or we are still working on it — the document is deleted 60 days after the last activity on your enquiry.
- If we decide not to go ahead — the document is deleted 30 days after that decision. That window is there so a decision can be reconsidered; after it the file has no purpose and we do not keep it.
- If we accept the enquiry — the document is deleted 12 months after that. A registration extract or a certificate of currency stops describing anything current long before then, and holding an old copy is not something we do.
We keep the enquiry; we delete the file. The record of what you asked us and what we decided survives, because that is the record of a conversation you chose to start. The document attached to it does not.
Deleting our record of a document deletes the file itself. No separate copy is left behind.
You can ask us to erase a document sooner, at any time, without waiting for any of the periods above.
Cloudflare Turnstile
Both forms are protected by Cloudflare Turnstile, which checks that a submission comes from a person rather than a bot. Cloudflare receives your IP address and signals about your browser in order to score the request, and returns a pass or a fail to us. It shows no puzzles, sets no advertising cookie, and does not build a profile of you across sites. Cloudflare’s privacy policy is at cloudflare.com/privacypolicy.
IP addresses
We never store your raw IP address. When you send a form, your IP is normalised and immediately turned into an irreversible hash using a secret salt, and only that hash is written down. It cannot be turned back into your address, and it is used for one thing: spotting abuse and rate-limiting floods of submissions.
We also read the approximate country your request arrives from, to decide whether you must be shown the consent banner and for coarse analytics. That is not stored against your form record. Routine server request logs, which contain IP addresses as any web server’s do, are kept for up to 30 days and then discarded.
Cookies on the website
- No advertising cookies, and no cross-site tracking cookies, ever.
- The Vercel analytics set no cookies at all.
- PostHog sets a first-party cookie only where analytics are permitted — which, in regions that require consent, means after you have accepted.
- Your consent choice, and the token that lets you resume a part-finished application, are stored on your own device. The resume cookie is HTTP-only and expires after 30 days.
The calculators
The free calculators on the website run entirely in your browser. The values you enter are not transmitted to us, are not sent to any analytics provider, and are not stored.
Your choices on the website
- Opt out of analytics at any time, using the control on this page or by turning on Global Privacy Control in your browser.
- Ask what we hold. Email us and we will tell you what a form submission of yours contains.
- Ask us to delete it. Email we@peptmate.com and we will erase your enquiry or application, submitted or not. You do not need an account to ask.
How we use your information
- Authenticate you and let you sign in across devices
- Show your library, dose history, weight chart, and journal back to you
- Deliver the reminder notifications you configure (scheduled locally on your phone)
- Improve the app and the website by reviewing aggregated analytics
- Reply to the enquiries and applications you send us, and assess them
- Respond to feedback or support requests you send
- Report the coarse subscription summary described under If you signed up with a creator code to that creator, and pay them, if you entered one
We do not use your data for advertising, profiling, or any purpose other than running Peptmate.
Where your data is stored
Your app data lives in two places: locally on your iPhone in the app’s sandboxed storage, and on Supabase, our backend infrastructure provider, which hosts our database. Supabase’s data processing terms are at supabase.com/privacy. Row-level security on every table means you can only ever access your own data; other Peptmate users cannot see your information. The one exception is the coarse summary described under If you signed up with a creator code, which carries no name, no email address, no user id and nothing you log — and which applies only if you entered such a code.
Enquiries and applications sent through the website are stored in the same Supabase database, reachable only by us. Analytics events are stored by PostHog on EU infrastructure.
Service providers we use
- Supabase hosts our database and authentication service.
- Vercel hosts peptmate.com and provides its aggregated analytics.
- Resend delivers our account emails (confirmation links, password resets). It processes your email address for delivery and nothing else.
- Apple and Google act as sign-in providers if you choose them.
- PostHog provides product analytics for the app and the website, stored on its EU infrastructure. It receives only the limited, health-free events described in Parts 1 and 2, and you can switch it off.
- Cloudflare provides the Turnstile bot check on the website’s two forms.
- Telegram carries the internal alert that tells us a form has been submitted.
- Klaviyo sends our marketing email, and receives your address only if you have separately opted in to receive it.
None of these providers may use your data for their own purposes, and we have no advertising or data-broker relationships with anyone.
How long we keep your data
- Your account. Kept as long as your account exists. When you delete your account in Settings, your data is permanently removed from our servers within minutes, including your authentication record.
- Part-finished affiliate applications. Deleted 60 days after you last touched them, as described in Part 2.
- Submitted enquiries and applications. Kept as the record of the enquiry or application you made, and erased on request.
- Documents sent with a business enquiry. Deleted on a schedule, never kept indefinitely: 60 days if the enquiry is untouched or still open, 30 days after we decide not to go ahead, 12 months after we accept. Described in full in Part 2.
- Server request logs. Up to 30 days. They do not contain your personal content.
Your rights
- Access. Everything Peptmate stores about you is visible in the app. For an exported copy, or for a form you sent us, email us.
- Correct. Edit any field directly in the app, or email us about a form submission.
- Delete. Settings → Delete account. Immediate and permanent, and the email address becomes reusable for a fresh account. For website enquiries and applications, email us.
- Sign out at any time without deleting. Your data stays on the server; sign in again to restore it.
- Opt out of third-party analytics. In the app, Settings → Share usage data. On the website, the opt-out control on this page, or Global Privacy Control. Either takes effect immediately and needs no account change.
If you are in the EU, UK, or California, you have additional rights under GDPR, UK GDPR, and CCPA respectively. Peptmate does not sell personal information. To exercise any right, email us.
Children’s privacy
Peptmate is not intended for anyone under 17, and we do not knowingly collect information from anyone under 17. If you believe a minor has signed up, contact us and we will delete the account.
Changes to this policy
If we materially change how we collect or use your data, we will update this page and the effective date above, and notify active users in the app or by email at least 14 days before the change takes effect.
Contact
Email: we@peptmate.com
Tech Quarters Pty Ltd, Australia