Privacy Policy

Last updated: July 9, 2026

This Privacy Policy explains how peptidio ("peptidio," "we," "us," or "our") collects, uses, discloses, and protects information when you use the peptidio mobile application, website, and related services (collectively, the "Service"). The Service is operated by SlyckAI ("Operator"). By using the Service, you acknowledge that you have read and understood this Policy.

The Service is intended for adults aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected such information, please contact us at info@slyckai.com and we will delete it.

1. Information We Collect

We collect only the information needed to operate, secure, and improve the Service. The categories below correspond to the App Store "App Privacy" nutrition label.

1.1 Information you provide

  • Account credentials. Email address; password hash (we never store your plaintext password); if you use Sign in with Apple or Google, the limited identifiers those providers return to us (typically: opaque user id, email, optional name).
  • Profile data. Date of birth (used only to verify you are 18 or older), optional display name, optional avatar image, optional biological sex / height / weight, research goals, experience level, route preferences, and any conditions you elect to disclose for personalization.
  • Research log content. Peptides you choose to track, dose amounts, schedules, route of administration, start/end dates, your weekly check-in scores, free-text notes, journal entries, and any photos you upload (for example, vial-label photos uploaded to the Vial Scanner).
  • AI Coach interactions. The text of messages you send to the AI Coach, the responses we return, and the AI session identifier. To give more relevant answers, we may include limited context from your own account (such as your stated goals, nutrition targets, and current protocol) in the request we send to our AI provider. We retain a history so you can review past conversations and so we can investigate misuse.
  • Photos you submit for AI analysis. Photos you upload to the Vial Scanner (images of vial labels) and to the meal-photo calorie estimator (images of food) are stored in our storage bucket and sent to our AI provider (see Section 4) to generate the identification or nutrition estimate you requested.
  • Onboarding assessment answers. The answers you give during the intake questionnaire are sent to our AI provider (see Section 4) to generate the educational peptide match shown at the end of onboarding.
  • Reviews and community submissions. Any rating, written review, or community post you submit (publicly visible to other registered users).
  • Support correspondence. The contents of email or in-app messages you send us, plus your contact details.

1.2 Information collected automatically

  • Device and technical data. Device model, OS version, app version, language, time zone, IP address (truncated where feasible), crash diagnostics, and approximate timestamps for security-relevant events.
  • Usage data. Screens viewed, features used, taps, search queries inside the Service, referral source, and similar product-analytics events. We do not use third-party advertising SDKs.
  • Cookies and similar technology (web only). Strictly-necessary session cookies used to keep you signed in. We do not use advertising cookies.

1.3 Information from third parties

  • Apple / Google sign-in providers. When you authenticate via Sign in with Apple or Sign in with Google, the provider returns a verified identifier and your email. We do not receive your password or social graph.
  • Payment processors. When you purchase a subscription on iOS, Apple (via In-App Purchase) processes the transaction and RevenueCat reconciles entitlement state. We receive the resulting metadata (subscription tier, period end, status) but never receive your full payment-card details.
  • Analytics and reliability vendors. Aggregated, de-identified telemetry from the vendors listed in Section 4.

We do not collect precise GPS location, contacts, microphone audio, HealthKit records, or biometric identifiers. We do not purchase personal information from data brokers.

2. How We Use Information

We use the information described above only for the following purposes:

  1. Provide the Service. Create and authenticate your account; render your dashboard, logs, recommendations, and AI Coach conversations; sync data across your devices.
  2. Personalize content. Generate the post-onboarding recommendation and surface community insights relevant to your stated goals.
  3. Process subscriptions. Manage your subscription state, restore purchases, and respond to billing-related events (renewals, cancellations, refunds, billing issues).
  4. Communicate with you. Send transactional notices (sign-in confirmations, receipts, account-security alerts) and, only if you opt in, occasional product-update emails. You can unsubscribe from product emails at any time.
  5. Improve and secure the Service. Investigate crashes, debug errors, detect abuse, prevent fraud, and develop new features. Where feasible we use aggregated or de-identified data for these purposes.
  6. Comply with law. Respond to lawful requests from public authorities, enforce our Terms of Service, and exercise legal rights.

We do not use your personal information to train third-party generative-AI models. The inputs we send to our AI provider — your AI Coach messages (with the limited account context described in Section 1.1), the photos you submit to the Vial Scanner and meal-photo estimator, and your onboarding assessment answers — are sent only to generate the output you requested; the provider's enterprise terms prohibit using them for model training (see Section 4).

3. Legal Bases for Processing (EEA / UK Users)

If you are located in the European Economic Area or the United Kingdom, we process your personal information on the following legal bases under the GDPR / UK GDPR:

  • Contract — to provide the Service you signed up for (Article 6(1)(b)).
  • Legitimate interests — to operate, secure, and improve the Service, prevent abuse, and conduct product analytics in a way that does not override your rights (Article 6(1)(f)).
  • Consent — for any optional processing that requires it (for example, marketing emails), which you can withdraw at any time (Article 6(1)(a)).
  • Legal obligation — where we must process information to comply with applicable law (Article 6(1)(c)).

4. How We Share Information

We do not sell or rent your personal information. We share it only with the categories of recipients below, under contractual confidentiality and data-protection commitments:

  • Service providers and sub-processors. We use the following vendors to host, process, and operate the Service:
    • Supabase, Inc. — managed database and authentication.
    • Vercel, Inc. — application hosting and serverless compute.
    • RevenueCat, Inc. — subscription state management and Apple In-App Purchase reconciliation.
    • Apple, Inc. — In-App Purchase processing, Sign in with Apple, and (if you opt in) push-notification delivery.
    • Google LLC — Sign in with Google (only if you choose this method).
    • xAI, LLC — artificial-intelligence inference for our AI features. We send xAI: (i) your AI Coach messages, together with the limited account context described in Section 1.1; (ii) images you upload to the Vial Scanner and to the meal-photo calorie estimator; and (iii) your onboarding assessment answers used to generate the educational peptide match. This can include health-related information you have chosen to provide. xAI processes these inputs only to generate the output you requested, and xAI's terms with us prohibit training their models on your data. See xAI's privacy policy at https://x.ai/legal/privacy-policy.
    • Resend, Inc. — transactional email delivery.
    • Upstash, Inc. — rate-limiting and ephemeral caches.
    • Cloudflare, Inc. — image storage and edge content delivery.
  • Other users (only where you choose). Reviews, ratings, and community posts you submit are visible to other registered users. Your private logs, journal, AI Coach history, and account email are never shared with other users.
  • Legal and safety. We may disclose information when required by law, subpoena, or court order; to enforce our Terms or this Policy; to protect the rights, property, or safety of any person; or to investigate suspected fraud or abuse.
  • Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction, subject to the protections in this Policy.

We require every service provider to (i) process personal information only on documented instructions from us, (ii) maintain appropriate security, and (iii) not use the data for their own independent purposes.

5. International Data Transfers

We are based in the United States and our service providers may store and process personal information in the United States, the European Union, and other countries. Where we transfer personal information from the EEA, UK, or Switzerland to a country that has not received an adequacy decision, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.

6. Data Retention

We retain personal information only for as long as necessary to provide the Service and for the purposes described in this Policy.

  • Account and profile data: retained until you delete your account.
  • Logs, journal, AI Coach history: retained until you delete the item, delete your account, or 36 months of account inactivity (whichever is shorter), unless we are required by law to retain longer.
  • Subscription transaction records: retained for at least 7 years to comply with tax and accounting laws.
  • Backups: purged on a rolling 30-day cycle after deletion of the underlying record.
  • Security and abuse logs: retained up to 18 months.

When you delete your account (in-app: Account → Delete my account; or by emailing info@slyckai.com), we permanently delete or irreversibly anonymize your personal information from active systems within 30 days, and from backups within an additional 30 days. We retain only the minimum information required to satisfy legal, tax, or fraud-prevention obligations.

7. Your Privacy Rights

Depending on where you live, you may have the following rights with respect to your personal information:

  • Access — request a copy of the personal information we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete information.
  • Deletion — ask us to delete your personal information.
  • Restriction or objection — ask us to limit or stop certain processing.
  • Portability — receive your information in a structured, machine-readable format. (You can also use the in-app "Download my data" button at any time.)
  • Withdraw consent — where we rely on consent, you may withdraw it at any time without affecting prior processing.
  • Lodge a complaint — file a complaint with your local data-protection authority.

To exercise any of these rights, email info@slyckai.com. We will respond within 30 days. We do not discriminate against users who exercise their privacy rights.

California residents (CCPA / CPRA)

In addition to the rights above, California residents have the right to know the specific pieces of personal information we have collected about them, the right to opt out of the "sale" or "sharing" of personal information (we do not sell or share personal information for cross-context behavioral advertising), and the right not to receive discriminatory treatment for exercising privacy rights.

The categories of personal information we have collected in the past 12 months are: identifiers (email, account id), customer records (profile data), internet/electronic-network activity (usage data), commercial information (subscription state), inferences (recommendation tags), and user-generated content (reviews, logs).

8. Security

We implement administrative, technical, and physical safeguards designed to protect your information, including: encryption in transit (TLS 1.2+); encryption at rest for databases and object storage; least-privilege access controls; auditable service-role keys; rate-limiting and abuse monitoring; mandatory code review; and a documented incident-response process. No system is impenetrable; you are responsible for keeping your account credentials secure and notifying us immediately if you suspect unauthorized access.

9. Children's Privacy

The Service is intended only for adults aged 18 or older. We require date of birth at signup and block accounts that do not meet this threshold. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe a minor has provided us with personal information, please contact info@slyckai.com and we will delete it.

10. Third-Party Links

The Service may contain links to third-party websites, including peptide vendors in the Marketplace. We do not control and are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and update the "Last updated" date above. If we make a material change, we will provide additional notice (for example, in-app or by email) before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

12. Contact Us

If you have questions, requests, or concerns about this Policy or our privacy practices, contact us at:

SlyckAI — peptidio Email: info@slyckai.com