Peptide Vault · Optional community
What you choose to share.
Last updated September 25, 2026
This notice supplements the Peptide Vault privacy policy for the optional community, operated by Jacob Teague. The app and Peptide Vault website share the same community. Submissions are sent to our server for moderation and, if approved, shown publicly to readers on both.
Joining is a separate choice
You can read approved posts without a community profile. To post, reply, like, report or block members, choose a display name and accept the current community rules. No email, password, real name or subscription identifier is required.
The app creates a random community credential and saves it securely on your device. Our server stores a one-way hash of that credential, a random profile ID, your chosen name, rules acceptance version, creation date and active or banned status. This identity is separate from billing. The credential is not a cloud login and has no email recovery; if it is lost, we cannot authenticate the old profile from a new device. Secure device storage may survive reinstalling the app.
The website uses an essential, first-party cookie to hold a random community credential. It is sent over HTTPS and cannot be read by page scripts. A separate browser profile has a cookie lasting up to one year, set when that browser profile is created or changed. Using the same display name does not link profiles. Clearing cookies, switching browsers or using a new device may make an unlinked profile inaccessible.
Optional app and website linking
You can use your app’s existing community profile on the website by approving a short-lived pairing code in the app. The code expires after five minutes and can link only one browser session. Your original app credential stays on your device; it is never transferred to the website. We store the pairing request, chosen browser label, a one-way hash of the separate browser credential, the linked profile reference and session dates. A linked browser session lasts up to 30 days. You can revoke individual linked browsers from the original app, or unlink the current browser on the website.
A linked browser uses the same display name, posts, likes, private submission statuses, rules consent and blocked-member list as the app. Linking does not merge a separate browser profile or transfer subscriptions, purchase history, tracking records or private Coach chats. Only the original profile credential can approve more browsers or delete the shared community profile. Pending and expired pairing records are removed by daily cleanup after at least one day; approved pairing records remain while their browser session is active.
What is sent
We store the text you intentionally submit, its author and thread references, submission and expiry dates, moderation status and any reason shown to you. We also store reports and blocked-member relationships to provide those controls. Approved text, display names and post dates are visible to other readers; pending and rejected submissions are visible only to their author and authorized moderators.
Community does not automatically upload your protocols, vial cabinet, journal, Apple Health records, doses, symptoms, photos or purchase history. If you type health details into a community post, you are choosing to submit those details for possible public sharing. Avoid identifying or sensitive details. Other readers can copy or screenshot approved content.
A like stores the relationship between your community profile and the post, together with its creation date. Readers see a like count, not a public list of people who liked a post. You can remove your like; deleting your profile also removes its likes. Likes on expired posts are removed when those posts are cleared by daily cleanup. We keep a small per-profile request counter to limit repeated like changes.
Activity and optional phone alerts
When you like a post or an approved reply appears, its author can see your display name and that interaction in a private activity list. A reply can also notify the original conversation author. We store the related member and post references, activity date and whether the recipient has read it. These records are removed with the related post or profile. Removed, expired, blocked or unapproved content is excluded from current activity.
Phone alerts are optional and separate from dose reminders. If you enable them, we store a random installation ID, its Expo push token, your Community profile reference and your separate likes and replies preferences. Expo and Apple or Google process notification delivery. Notification text is generic; we do not send post text, member names, health records or purchase details in notifications. The payload includes opaque identifiers so the app can open the conversation after checking its current availability.
You can turn Community alerts off or choose which interactions alert you in the app. Deleting your Community profile removes its device registrations and queued alerts. Registrations unused for 90 days expire and are removed during the next notification maintenance pass. Delivery records last no longer than the related Community post. An alert already handed to the phone notification service cannot always be recalled after a post is removed or a member is blocked.
Approved posts and replies can be shared using a public website link. Anyone with the link can read available approved content without creating a profile. Removed, expired, hidden or unavailable posts are not shown through these links. Copies or screenshots already made by others are outside our control.
Moderation and service providers
Authorized moderators review submissions that need a decision and reports from members. Local word checks flag possible abuse, medical instructions, promotion, sourcing, spam or personal information.
If you explicitly accept the September 15, 2026 automated-screening notice, we may send only the text of your submitted post or reply to OpenAI for safety screening and community-rule checks. We do not include your display name, profile ID, credential, earlier conversation, private Coach chats, tracker records or purchase information. Details you type into the submitted text are part of that text and will be included; avoid sensitive or identifying details.
Posts and replies that pass our checks may appear automatically. Uncertain, flagged or unchecked submissions wait for an authorized moderator, including when the service is unavailable. Existing members and older app versions stay on human review until explicit screening consent is recorded. Automated screening can make mistakes and does not verify medical facts. OpenAI processes submitted text under its API data controls; our application hosting and Supabase database also process community requests and data to run this feature. We do not sell community information or use it to personalize advertising.
For security and abuse prevention, requests pass through our hosting infrastructure, which may process technical information such as IP addresses. The website forwards the visitor IP securely to our community service for signup and pairing rate limits. These limiters store a keyed hash derived from the request IP, rather than the raw IP in community tables. Community content and credentials are not included in analytics events. The website community does not load advertising pixels or behavioral analytics.
Expiry and retention
Threads stop appearing after 30 days; replies inherit the original thread’s expiry. A shorter recent-activity preview in the app does not change this lifetime. A daily cleanup removes expired conversation records. Profiles remain until you delete them; block relationships remain until unblocked or a related profile is deleted.
Flagged, reported, rejected or removed content may be captured in a separate restricted moderation record. It contains the submitted text, a pseudonymous author reference, review flags and the reason for retention. It does not contain the community credential or its hash. This evidence expires 30 days after its first capture and is removed by the daily cleanup, including when the public post or profile was already deleted. Moderator action records follow the same 30-day retention window. Expired records await the next daily cleanup; routine provider backups are not a live community archive.
Deleting and blocking
You can remove your own posts from the original app or browser, or a linked browser. Their text is replaced with a short placeholder in storage; the removed post and replies beneath it stop appearing in the current feed and shared links. Deleting your community profile from its original app or browser revokes its credential and all linked sessions, removes its name, likes and block relationships, and replaces its posts with placeholders attributed to a deleted member. Restricted moderation evidence may remain for the limited period above. Deleting the app, unlinking a browser or clearing cookies alone does not delete server-side community content; use the community profile deletion control first.
Blocking hides that member’s content from your authenticated feed and prevents interaction with their content. Reports and blocked-member lists are not public. Publicly shared information may remain in copies made by other readers.
Age and privacy requests
The community is for adults aged 18 or older. For questions, a privacy request or a concern about a child’s information, contact jacobteague50@gmail.com. Include a post or profile reference where possible. We may need enough information to verify ownership before acting; please do not send private medical records.