Last updated: May 12, 2026
This Privacy Policy describes how the Pep Pal mobile application ("Pep Pal", "we", "us", or "our") handles information about you ("you" or "user"). For the purposes of the EU/UK General Data Protection Regulation (GDPR/UK GDPR) and similar laws, the publisher of Pep Pal is the data controller.
If you have questions or wish to exercise any privacy rights described below, email us at snapit.foranything@gmail.com. We aim to respond to verified requests within 30 days.
We do not require an account, email, or phone number to use Pep Pal.
We do not run advertising, analytics, or third-party tracking SDKs in this build.
We do not sell or share your personal information.
We do not "track" you across other apps or websites as defined by Apple's App Tracking Transparency framework. We do not request the AppTrackingTransparency permission.
Almost all data — your profile, stack, reminders — is stored only on your iPhone and never leaves your device unless you choose to share it.
The following data is stored locally on your iPhone using Apple's standard UserDefaults and UserNotifications frameworks. It is not transmitted to us or any third party unless you actively share it:
Profile preferences — display name (optional, set during onboarding), goals, experience level, injection comfort, research preference, preferred reminder time, appearance, and haptics settings.
Stack entries — peptide identifiers from our catalog, your chosen dosage strings, frequency strings, start date, notes, and reminder times.
Onboarding completion flag.
Locally cached subscription status (so we don't need to hit RevenueCat on every launch).
You can delete all of the above at any time using "Delete Account" in Settings.
Subscriptions and receipt validation — RevenueCat
When you start, restore, or cancel a subscription, the App Store sends a receipt to RevenueCat, Inc. ("RevenueCat"), our subscription management processor. RevenueCat verifies entitlement and tells the app whether to unlock Pep Pal Pass features. The data RevenueCat receives is limited to:
Your anonymous, randomly generated RevenueCat App User ID (we do not log you in with your real identity).
The original Apple-issued transaction identifier from your receipt.
The product identifier you purchased.
Limited device metadata used to scope entitlement (device model, OS version, app version, country code, language, install timestamp).
RevenueCat is a U.S.-based service. RevenueCat's privacy policy: https://www.revenuecat.com/privacy
App Store and in-app purchases — Apple
All purchases are handled by Apple. Apple's privacy practices govern the collection and use of payment data and your Apple ID. We never see your full payment details, name, or billing address. Apple's privacy policy: https://www.apple.com/legal/privacy/
Diagnostics — Apple (only if you opted in at iOS setup)
If you opted in to "Share with App Developers" in iOS Settings → Privacy & Security → Analytics & Improvements, Apple may send us aggregated, anonymized crash reports for Pep Pal. We use these solely to fix crashes. You can disable this in iOS Settings at any time.
We have no other third-party data recipients.
To deliver core features (display your stack, fire reminders, render the calendar and blood-level charts).
To verify and apply your Pep Pal Pass entitlement.
To respond to your support requests, if you email us.
To detect and fix crashes and bugs (limited to anonymized diagnostics from Apple).
We do not use your information for profiling, automated decision-making with legal effect, targeted advertising, or any other secondary purpose.
Where GDPR or UK GDPR apply, we rely on the following legal bases under Article 6:
Performance of a contract (Art. 6(1)(b)) — processing necessary to deliver Pep Pal and your Pep Pal Pass subscription.
Legitimate interests (Art. 6(1)(f)) — limited diagnostics to maintain a reliable app and prevent fraud, balanced against your privacy interests.
Consent (Art. 6(1)(a)) — for optional iOS permissions such as notifications. You can withdraw consent in iOS Settings at any time without affecting prior processing.
We do not process special-category data (such as health data) on our servers. The dosage and protocol notes you store are kept on your device and are under your control.
If you grant notification permission, Pep Pal schedules local notifications for your dosing reminders. These notifications are generated and delivered by iOS directly from your device. We do not operate a remote push server and never see when, or whether, your reminders fire. Revoke notification permission in iOS Settings → Notifications → Pep Pal.
Location data of any kind.
Contacts, photos, microphone, or camera input.
Identifiers for advertising (IDFA). We do not display ads.
HealthKit data — HealthKit integration is not enabled in this build.
Browsing history outside the app.
Biometric identifiers (Face ID/Touch ID happen entirely on-device and are never shared with us).
Per Apple's App Store privacy disclosure framework, Pep Pal's data practices are:
Data Used to Track You: None.
Data Linked to You: Purchases (anonymous purchase history retained by RevenueCat for entitlement verification). Used for "App Functionality".
Data Not Linked to You: Diagnostic data (crash logs sent to us by Apple only with your iOS-level opt-in).
These disclosures match the responses provided in App Store Connect.
On-device data persists until you delete the app or use "Delete Account" in Settings. Tapping "Delete Account" wipes your profile, stack entries, reminders, onboarding state, and the locally cached subscription status, and cancels every scheduled local notification.
RevenueCat retains the anonymous purchase records associated with your App User ID for the duration of your subscription and for any period required by Apple's developer agreements or applicable tax/accounting laws (typically up to 7 years). You can request deletion of these records by emailing snapit.foranything@gmail.com — note that deletion may forfeit access to any active subscription on this Apple ID.
Support emails are retained for as long as needed to resolve your inquiry and then deleted within 12 months.
Subject to applicable law, you have the right to:
Access — request a copy of the personal information we hold about you.
Rectification — correct inaccurate or incomplete information.
Erasure ("right to be forgotten") — request that we delete your personal information.
Restriction — ask us to limit how we use your information.
Portability — receive your information in a structured, machine-readable format. Pep Pal provides this directly via "Export Stack Data" in Settings.
Objection — object to processing based on our legitimate interests.
Withdraw consent — at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, email snapit.foranything@gmail.com. We will verify your request and respond within 30 days. You will not be discriminated against for exercising any privacy right.
If you are a California resident, the California Consumer Privacy Act and the California Privacy Rights Act give you the following additional rights:
The right to know what personal information we collect, use, disclose, and (where applicable) sell or share.
The right to delete personal information, subject to certain exceptions.
The right to correct inaccurate personal information.
The right to opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information as defined by the CCPA, and we have not done so in the past 12 months.
The right to limit the use of sensitive personal information. We do not collect sensitive personal information as defined by the CCPA.
The right not to be discriminated against for exercising your privacy rights.
To submit a verifiable request, email snapit.foranything@gmail.com with the subject "California Privacy Request".
If you are in the EU, EEA, UK, or Switzerland, you have the rights described in the "Your Rights" section above. You may also lodge a complaint with your local data protection supervisory authority. A list of EU authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. The UK supervisory authority is the Information Commissioner's Office (https://ico.org.uk).
Where personal information is transferred outside the EU/EEA or UK (for example, to RevenueCat in the United States), the transfer is protected by Standard Contractual Clauses approved by the European Commission and the UK ICO, plus supplementary measures where appropriate.
Pep Pal is offered globally, and our service providers (notably RevenueCat and Apple) are located in the United States. Where information is transferred from the EU/EEA, UK, or other jurisdictions with cross-border transfer rules to the United States, those transfers rely on appropriate safeguards such as Standard Contractual Clauses or the relevant adequacy decisions, where they apply.
Local data is stored using Apple's standard UserDefaults and is protected by the iOS data-protection class assigned to the app (typically encrypted while the device is locked). RevenueCat connections use TLS. We restrict access to support email and account systems to authorized personnel.
No system is perfectly secure. In the event of a breach affecting your information, we will notify you and any required regulators in line with applicable law.
Pep Pal is not directed to, and we do not knowingly collect personal information from, children. Peptide protocols are not appropriate for users under 18 and the App Store age rating reflects this. We do not knowingly market to or collect information from anyone under the age of 13 in the United States (COPPA) or under the relevant digital-consent age in other jurisdictions. If you believe a child has provided information, contact us at snapit.foranything@gmail.com and we will delete it promptly.
Pep Pal is a native iOS app and does not use cookies, web beacons, pixel tags, or browser-based tracking technologies.
Delete all on-device data at any time via Settings → Delete Account.
Cancel your subscription via iOS Settings → Apple ID → Subscriptions.
Revoke notification permission via iOS Settings → Notifications → Pep Pal.
Disable haptics in Settings → Haptic feedback.
Export a copy of your stack data via Settings → Export stack data.
We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date at the top of this page and, where required by law, communicated to you through the app or a notice. Continued use of Pep Pal after a change indicates acceptance of the updated policy.
Pep Pal is an informational tool, not medical advice. Peptide protocols can have serious health implications. Always consult a licensed clinician before starting, stopping, or stacking peptides. Citations in Pep Pal are provided for educational reference and do not constitute endorsement.
Questions, complaints, or privacy requests? Email snapit.foranything@gmail.com.