Legal

PeptidePal Consumer Health Data Privacy Policy

Effective September 11, 2026

On this page
  1. Scope
  2. Consumer Health Data We Collect
  3. Sources of Consumer Health Data
  4. Why We Collect and Use It
  5. How Data Is Stored and Transmitted
  6. Disclosures and Recipients
  7. Retention and Deletion
  8. Your Consumer Health Data Rights
  9. Changes to This Policy
  10. Related Policies and Contact

Scope

This Consumer Health Data Privacy Policy explains how Blank Labs LLC, a Wyoming limited liability company ("Blank Labs," "we," "us," or "our"), collects, uses, and discloses consumer health data through PeptidePal. It supplements our PeptidePal Privacy Policy and is intended to provide disclosures required by consumer health privacy laws, including Washington's My Health My Data Act, where those laws apply.

PeptidePal is a research, reference, tracking, and community product. It is not a healthcare provider and does not provide diagnosis or treatment.

Consumer Health Data We Collect

Depending on the features you use, we may collect or process:

  • Goals and profile information: age, biological sex, height, weight, goals, experience level, obstacles, peptides of interest, and check-in preferences.
  • Protocol and dosing information: peptide identity, dose amount and unit, frequency, delivery form, schedule, blend details, protocol composition, dose-history counts, and injection-site history.
  • Health observations: measurements you enter or authorize PeptidePal to read from Apple Health or Health Connect, such as weight, body fat, lean body mass, waist circumference, mood, and related observations.
  • Progress photos: photos you choose to capture and upload to track changes over time.
  • AI conversations: messages you send, prior messages supplied for conversational context, automatically included active-protocol context, and injection-site history for supported questions.
  • Community content: health-related questions, answers, votes, reports, and other interactions you choose to submit in Community Q&A.
  • Product and attribution events: device-scoped or pseudonymous events and counts that may reveal use of a health-related app or feature, including a parameter-free milestone indicating that a first dose was logged.

Sources of Consumer Health Data

We collect consumer health data directly from you; from your use of PeptidePal's protocol, tracking, photo, chat, and Community features; from Apple Health or Health Connect when you authorize access; from your device and app interactions; and from information derived from those sources, such as coarse demographic bands, protocol summaries, dose counts, and aggregate usage statistics.

Why We Collect and Use It

We collect and use consumer health data to provide features you request, including account personalization, protocol and dose tracking, health synchronization, progress tracking, AI research responses, injection-site rotation support, Community Q&A, account deletion, and customer support.

We also use limited device-scoped protocol and dosing information to calculate aggregate community usage statistics and limited app events to understand product engagement and measure the effectiveness of Blank Labs' advertising. We do not send advertising partners your name, readable email, progress photos, complete protocol, peptide identity, raw dose value, or health measurements. AppsFlyer and Appstack currently receive a parameter-free first_dose_logged milestone once per install; a dedicated consent gate for that milestone is not currently implemented.

How Data Is Stored and Transmitted

Your complete protocol, dose-log, stack, and chat databases are stored locally on your device and are not conventionally cloud-synced. Selected information from those databases is nevertheless transmitted when required by a feature.

Once per day, PeptidePal may send active-protocol peptide identity, raw scheduled dose, unit, frequency, delivery form, blend details, coarse demographic bands, biological sex, and goals to our backend. Reports use a one-way hash of a device identifier rather than your Supabase account identifier. Aggregate reads use minimum-cohort suppression.

When you use AI chat, PeptidePal sends the conversation and automatically generated context about active protocols and, for supported questions, recent injection sites through our backend to Anthropic. There is no per-send control for this context today. Blank Labs does not retain a server-side chat history.

Health observations you enter or authorize PeptidePal to read from Apple Health or Health Connect synchronize to your private PeptidePal backend account. With platform permission, PeptidePal may also write supported observations back to the applicable health platform.

Progress photos are stripped of EXIF metadata and uploaded to private, account-scoped storage. Community questions and answers are stored on our servers and displayed under a pseudonym to authenticated members.

Disclosures and Recipients

  • Cloud and database processors: Supabase and Google Cloud host account data, health observations, photos, Community content, backend requests, and related infrastructure.
  • AI provider: Anthropic processes chat messages, conversational context, and protocol or injection-site context to generate AI responses.
  • Health platforms: Apple Health and Health Connect provide or receive selected health observations when you authorize the applicable permission.
  • Analytics and attribution providers: TelemetryDeck receives device-scoped product events and counts. Meta, AppsFlyer, and Appstack receive limited install, app-open, registration, purchase, or attribution events; AppsFlyer and Appstack also receive the parameter-free first-dose milestone.
  • Subscription providers: Apple, Google, Stripe, and Superwall process subscription, purchase, entitlement, paywall, and transaction information.
  • Other Community members: questions, answers, votes, pseudonyms, and avatars you publish are visible to authenticated members.
  • Legal and safety recipients: we may disclose information when required by law or reasonably necessary to protect users, the service, or the public.

We do not sell consumer health data. We do not use geofences around healthcare facilities to identify or collect consumer health data.

Retention and Deletion

  • Local protocol, dose, stack, and chat histories remain on your device until you clear them, delete your account through the app, reset the app, or uninstall it.
  • Account-linked health observations and progress photos remain until you delete the item or account, subject to limited backup, security, legal, accounting, and fraud-prevention retention.
  • Daily protocol-usage reports use a hashed device identifier rather than your account identifier and may remain in product-research records. A specific retention period has not been verified.
  • Published Community posts may remain after account deletion in disassociated form under a generic member identity unless you delete them first.
  • Blank Labs does not retain a server-side AI chat history. Anthropic's standard API retention generally deletes inputs and outputs within 30 days, subject to contractual, legal, safety, and abuse-prevention exceptions.
  • Analytics, attribution, subscription, support, consent, security, transaction, legal, and backup records may remain as applicable.

Account deletion may not reach device-hash reports or provider records that are not linked to your account. See our Data Deletion page for instructions and exceptions.

Your Consumer Health Data Rights

Subject to applicable law, you may have the right to confirm whether we collect, share, or sell your consumer health data; access that data; receive information about recipients; withdraw consent from future collection or sharing; and request deletion. You may not be discriminated against for exercising these rights.

You can delete your account in PeptidePal under Settings → Delete Account. To make another consumer health data request, email help@blanklabs.io from the address associated with your account and describe your request. We may request information reasonably necessary to authenticate you. The authenticated self-service export currently returns health observations only and is not comprehensive.

If we refuse to act on a request, you may appeal by replying to our decision or emailing help@blanklabs.io with the subject "Appeal consumer health data decision." We will process requests and appeals within the periods required by applicable law.

These rights and contact pathways do not imply that PeptidePal currently provides a generalized in-app health-data consent or withdrawal control. Feature-specific platform permissions and deletion controls apply where the product provides them.

Changes to This Policy

We may update this policy when our practices or legal obligations change. We will post the revised policy with a new effective date and provide any additional notice or consent required by law before collecting, using, or sharing new categories of consumer health data or using existing data for materially new purposes.