Privacy
Last updated: August 15, 2026
The short version: Peptimist stores your health and tracking history on your device by default. We do not sell personal data. Features that need an outside service, including AI food estimates, barcode product lookup, speech recognition, purchases and optional analytics, send only the information described below.
Information stored on your device
Peptimist works without an account. Your profile and what you log, including shots, food, water, fasting times, supplements, activity, weight, side effects, progress and photos you attach to weigh-ins, are stored locally rather than in a Peptimist cloud database. Android cloud backup is disabled. You can edit, backfill or delete supported records in the app. The app can also create a shot-history CSV and a visit-summary PDF.
On iOS, if you connect Apple Health, weight values you choose to import are copied into Peptimist's local database. Step totals are read from Apple Health on demand and are not copied. Peptimist does not write to Apple Health or send Apple Health data to our servers.
Protein targets and the optional maintenance-calorie estimate are calculated on your device. Profile inputs, calculated results, and numerical target amounts are not sent to Peptimist or Mixpanel.
AI food logging
AI logging is optional and available only during a trial or paid subscription. Before the first AI request, Peptimist identifies the outside services and information involved and asks you to allow AI data sharing. If you choose “Not now,” nothing is sent. You can revoke permission for future requests in Me → Privacy.
When you choose to send a meal description or meal photo, the text, image, and a random app-scoped identifier are sent over HTTPS to Peptimist's service hosted by Vercel. The text and image are passed to Google's Gemini API to produce a macro estimate; the app-scoped identifier is passed separately to RevenueCat to confirm that AI access is active. Peptimist does not write the submitted text or image to its own server database and disables Gemini's normal interaction storage for these requests. Google may nevertheless retain submitted prompts, contextual information (including an attached meal photo), and generated responses for up to 55 days for abuse monitoring, safety, security, and required legal or regulatory disclosures. Google says data logged for that purpose is not used to train or fine-tune AI models other than models used specifically for policy enforcement; flagged content may be reviewed by authorized Google personnel. Vercel, Google, and RevenueCat otherwise process limited data under their own security and retention terms.
Voice input
If you tap the microphone, Peptimist asks for microphone permission and uses the speech-recognition service available on your device. Depending on the device and installed language model, Apple or Google may process the audio on-device or through its speech service. Peptimist does not persist the audio recording. The resulting text remains editable and is sent to Peptimist AI only if you choose to send it.
Barcode product lookup
Barcode recognition happens on your device; Peptimist does not capture or upload a barcode image. A decoded food barcode is sent to Open Food Facts to retrieve editable nutrition information. When you scan a supplement with a numeric UPC or EAN, only that decoded product number is sent over HTTPS to the NIH Dietary Supplement Label Database and, when needed, Open Food Facts to look up an editable product name. Amazon inventory labels are recognized on-device and are not sent to either lookup service. Peptimist does not send your profile, supplement schedule, reminders, or tracking history with a lookup request. Database results may be incomplete or out of date and are not an endorsement, recommendation, dose instruction, or interaction check.
When you type a food search, the search terms are sent over HTTPS to Open Food Facts Search-a-licious to return editable food matches. Peptimist does not include your profile or tracking history with the search. Like any internet service, these lookup providers receive network information such as the request IP address and may keep access or query logs under their own policies.
Usage analytics and install attribution
If “Share app usage data” is enabled, the app uses Mixpanel with a random device identifier, not your name or email, to record a small set of named events such as install, onboarding completion, the fact that a protein target was revealed (without the number), first log and AI trial conversion. The app instructs Mixpanel not to use the request IP address for geolocation. It does not use advertising identifiers, session replay, or automatic screen recording. On Android, Google Play may provide campaign fields such as source, campaign, and content from the link that led to installation. We use these fields to measure whether Peptimist content leads to installs. You can stop future app analytics at any time in Peptimist's Privacy settings.
Subscriptions
Apple or Google handles payment details. Peptimist does not receive your card number. RevenueCat receives a random app-scoped identifier, product and purchase history, subscription status, renewal status, and related store transaction information so Peptimist can unlock AI and restore purchases. Peptimist currently uses the same random app-scoped identifier for Mixpanel and RevenueCat so subscription and conversion events can be measured without using a name, email address, advertising identifier, or Peptimist account. Store and purchase records may be retained where required for billing, fraud prevention, tax, or legal compliance.
The waitlist: what we do with your email
- We use it to tell you when Peptimist launches and, at most, send a couple of pre-launch updates.
- We do not sell or rent your email.
- Supabase processes and stores your email, platform choice, campaign tags and referring site only to operate the waitlist and measure launch attribution.
- To unsubscribe, just reply to any email we send or write to support@peptimist.aiand we'll delete your address.
Website analytics
We use Mixpanel to count page views and waitlist signups, along with the platform choice, campaign tags and referring site associated with those events, so we know which of our posts people actually found useful. The waitlist event does not include your email. No session replay, no autocapture, no ad trackers. If your browser sends the "Do Not Track" signal, we skip analytics entirely.
Deletion and retention
“Delete data & close account” removes Peptimist's local profile, history, and photos and returns the app to onboarding. Because there is no Peptimist account, this does not cancel a store subscription or erase records held by Apple, Google, RevenueCat, or analytics and service providers. You can cancel a subscription through the store that sold it. Email us to request deletion of a waitlist address or other information you previously sent directly to Peptimist.
Security
Peptimist limits collection to the services above and uses HTTPS for network requests. No system can guarantee absolute security, but we do not sell data or use it for third-party advertising.
Questions
Email support@peptimist.ai. A human reads it.
Peptimist is a tracking and education companion. Not medical advice.