Privacy Policy
Peptide Vault
Last updated 2026-08-21
Your regimens, logs, journal, and Health data stay on your iPhone. Two things leave only when you choose to send them: a Coach message, and a feedback note.
Peptide Vault is built by Jacob Teague. This page explains what data the app collects, how it is stored, and what rights you have. We do not sell personal information, and user-entered app content is never shared with other users.
What stays on your device
Peptide Vaultis local-first. There is no account to create. The following data is kept in iOS local storage on your iPhone, protected by your device passcode and Apple's app sandbox, and never leaves the device:
- Regimen entries (compounds, doses, frequency, time)
- Dose logs and journal notes
- Reconstitution calculator inputs
- Data read from Apple Health (such as weight), if you grant access
- Subscription status and app settings
Two narrow exceptions, both requiring an explicit action from you. First, if you turn on the Coach share toggle described below, the names of your tracked compounds and a stack summary are included with your Coach messages. Second, if you write and send a note through the in-app feedback form, that note — and an email address only if you type one — is sent to us. Nothing else in this list ever leaves your device.
Delete the app and this data goes with it. You can also clear data without deleting the app from the app's Settings.
Apple Health
With your permission, Peptide Vault can read selected Apple Health data — for example body weight — to display it alongside your logs. Access is read-only: the app never writes anything to Apple Health.
Health data never leaves your device. It is not sent to our servers, to Coach, to any analytics or attribution service, or to any other third party. You can revoke access anytime in iOS Settings → Health → Data Access & Devices.
Coach (optional AI research assistant)
Coach is an optional Pro feature: a research-assistant chat. It only runs when you choose to use it. When you send a message, the text you typed is sent to our server, which forwards it to the OpenAI API to generate a reply.
By default, the message you type is the only thing sent. If you turn on the in-chat share toggle, the names of the compounds you track and a summary of your stack — which otherwise stay on your device — are included so answers can reference them. Your journal entries, notes, dose logs, and Apple Health data are never sent to Coach, with or without the toggle. You can turn the toggle off at any time.
We do not store your Coach messages on our server; they are processed only to generate the reply. OpenAI handles forwarded messages under its API data policy, which does not use API data to train its models by default. There is no account: Coach requests carry a random per-install identifier used only for rate limiting, and it is not linked to your name, email, or identity.
Feedback you send us
Peptide Vault includes an optional feedback form, reachable from Settings → About Peptide Vault → Send feedback and from a one-time prompt after your fifth logged dose. It never sends anything on its own.
When you tap Send, the app transmits exactly four things: the note you wrote, the app's version number, a random identifier generated on this device so we can see that several notes came from the same install, and — only if you typed one into the optional field — an email address so we can reply. That random identifier is separate from the one used for analytics and cannot be joined to it; we convert it to a one-way hash on arrival and never store the original.
As with any request sent over the internet, our server also sees the IP address the note arrives from. It is used only to limit how many submissions one network can send, it is turned into a one-way hash before anything is written down, and it is never stored alongside your note.
Your dose logs, protocols, compounds, journal entries and Apple Health data are never included, with or without an email address. The server rejects any submission carrying a field outside that list.
Notes are stored in our database, hosted by Supabase, and are readable only by Jacob Teague. A copy may also be emailed to us through Resend and delivered to a Google mailbox. We keep notes for as long as they remain useful for improving the app, and delete them on request — email jacobteague50@gmail.com and, if you left an address, we can find and remove your note.
Analytics and attribution
Peptide Vault uses PostHog and AppsFlyer to understand how the app is used and which marketing campaigns lead to installs. These tools receive a device identifier, a random per-install user ID, and product-interaction events such as app opened, onboarding steps, paywall viewed, and feature usage.
The advertising identifier (IDFA) is disabled and the app does not track you across other companies' apps or websites, so iOS shows no tracking prompt — there is nothing to opt out of at the OS level because cross-app tracking is off by design. Analytics events never include your regimen entries, dose logs, journal text, Health data, or Coach messages.
Purchase history is processed through RevenueCat to make your subscription work and for our own revenue analytics. The app has no accounts. The only place it can receive an email address is the optional reply-to field on the in-app feedback form, described above.
Third parties with access to your data
Peptide Vault has no accounts and builds no profile of you, but a small, fixed set of service providers does receive the limited data described above so the app can work. We only use providers that are required, by their agreement with us and their own published commitments, to protect that data at least as strongly as this policy promises: to use it solely to deliver the service we asked them for, to keep it confidential and secure, not to sell it, and not to repurpose it for their own advertising.
PostHog — product analytics. Receives a random per-install identifier and product-interaction events such as app opened, onboarding step completed, paywall viewed, and feature usage.
AppsFlyer — install attribution. Receives campaign metadata and anonymous install identifiers. The advertising identifier (IDFA) is disabled, so the app does not track you across other companies' apps or websites.
RevenueCat — subscription state. Receives purchase and subscription status so that Pro unlocks on your device. RevenueCat learns that you subscribed, never what you entered in the app.
OpenAI — Coach message processing only, and only when you have chosen to use Coach. It receives the message text you typed, plus your compound names and stack summary if you have turned on the in-chat share toggle, in order to generate the reply. OpenAI handles it under its API data policy, which does not use API data to train its models by default.
Supabase — database hosting, for feedback notes only. Receives and stores a note you chose to send: its text, the app version, a one-way install hash, and your email address only if you typed one. No other Peptide Vault data is stored there.
Resend — email delivery, and only for a feedback note you have sent. Receives the note text and your email address if you supplied one, in order to deliver a copy of it to us.
Google — the mailbox that copy is delivered to. Receives the same note text and, if you supplied one, your email address.
None of these providers receive your regimen entries, dose logs, journal text, or Apple Health data. We do not sell personal information, and we do not share your data with any third party not named here.
Data retention — how long your data is kept
Your protocols, dose logs, journal entries, reconstitution inputs, and any Apple Health data the app reads live only on your iPhone. We hold no copy, so there is nothing on our side to retain. They stay on your device until you remove them: delete the app, or use Settings → Delete all my data. Either action removes them immediately and permanently, and neither is recoverable by us. Feedback notes are the exception: once you tap Send, we hold that copy. Deleting the app does not delete a note you already sent; email us and we will remove it.
Coach messages are not stored on our server. Each message is processed in the request that carries it, forwarded to OpenAI to generate the reply, and then dropped — we keep no chat history. Anything forwarded is retained and deleted by OpenAI under its own API data policy.
Analytics and attribution events are retained by PostHog and AppsFlyer under their standard retention schedules and deleted on those schedules. These events carry only a random per-install identifier and campaign metadata; they are not linked to your name, email, or any account, because the app has none.
Purchase and subscription records are retained by RevenueCat and by Apple for as long as needed to keep your subscription working and to satisfy their own legal, accounting, and tax obligations.
Purchases
Paid subscriptions are processed by Apple through the App Store. The app receives a purchase status signal from RevenueCat, the purchase management provider, which validates purchase receipts from Apple. RevenueCat learns that you purchased — never what you entered in the app. Manage or cancel anytime in iOS Settings → Apple ID → Subscriptions.
Not a medical device
Peptide Vault is a passive tracking tool. It is not a medical device and does not provide medical advice, diagnosis, or treatment. Only use it to log regimens, doses, or activities that have been directed by a licensed healthcare provider or that you have independently chosen to track for personal reference. Always consult a qualified healthcare provider before starting, changing, or stopping any protocol.
Your rights
- Delete your data:delete the app from your device — everything stored on it goes with it. You can also clear data from the app's Settings without deleting the app. Anything you chose to send us from inside the app, such as a feedback note, is not covered by that — email jacobteague50@gmail.com and we will delete it.
- Export your data: where supported, export your data from Settings → Data → Export.
Children
This app is not directed to children under 13. We do not knowingly collect information from children.
Changes to this policy
If this policy changes, we will update the "Last updated" date at the top of this page. Material changes will also be surfaced in the app.
Contact
For any question about privacy, data handling, or data deletion requests: jacobteague50@gmail.com. For help using the app, managing a subscription, or restoring a purchase, see Peptide Vault support.