peptmate.
HomeFeaturesInside the appFree toolsFAQ
Download on theApp Store
← Back to Peptmate

Privacy policy.

  • Effective 30 September 2026
  • Last updated 22 September 2026
  • Tech Quarters Pty Ltd, Australia
Legal
  • Privacy policy
  • Terms of use
  • Medical disclaimer
  • Rewards programme terms

This Privacy Policy explains what data Peptmate collects, how it is used, and the choices you have. Peptmate is operated by Tech Quarters Pty Ltd (ABN provided on request), Australia. By using Peptmate you agree to this policy. If you do not agree, do not use the app.

Scope of this policy

This policy covers two things, and they collect different data:

  • The Peptmate mobile app, on iOS (App Store) and Android (Google Play) — your account, what you log, and the analytics the app sends. Described in Part 1. Both apps store the same records and sync to the same account; where a platform differs, it is called out there.
  • The peptmate.com website — the marketing pages, the free calculators, and the business enquiry and affiliate application forms. Described in Part 2.

You can use one without the other. The things that join them are described below: a form you send us, and the referral and rewards programme, which is keyed to your Peptmate account and to the email address you give if you opt in to rewards. Everything from How we use your information onwards applies to both.

Part 1 — the Peptmate app

What Peptmate is

Peptmate is a mobile application, for iPhone and for Android, that helps you keep a private record of research peptides you choose to track: a personal library, reconstitution and dose details, logged doses, and journaling of subjective effects such as mood, weight, and free-text reflections.

Peptmate does not provide medical advice. All content in the app is descriptive and educational only.

Information we collect in the app

We collect only the information you provide directly through the app, plus minimal device-level telemetry needed to run the service. We do not collect data from advertising networks or background sensors.

Account information

  • Email address (your login identifier)
  • Optional display name, date of birth, biological sex, height
  • Account creation date and last login timestamp

Sign-in providers

You can create your account with email and password, Sign in with Apple, or Google Sign-In. If you use Apple or Google, we receive only your basic profile from them: your name and your email address (Apple lets you hide your real address behind a private relay address, which works fine with Peptmate). We never receive your Apple or Google password, and we get no access to anything else in those accounts. We send nothing back to Apple or Google about how you use Peptmate.

Data you choose to log

  • Peptides in your library (name, vial strength, dose, schedule)
  • Logged doses (date, time, injection site, optional note)
  • Weight entries, mood entries, and journal reflections you write
  • Peptide lifecycle events (added, reconstituted, refilled, marked finished)
  • Preferences (notifications, units, time format, appearance)

You decide what to enter. You can leave any field blank.

Device and usage information

  • App version, operating-system version (iOS or Android), and device model (when you submit feedback)
  • In-app analytics events (which screens you open, when you log a dose, when you complete onboarding). Event names are factual; we do not capture screen contents or your written text in analytics.

App analytics, and what leaves our own systems

Current status (24 August 2026). The PostHog SDK is present in the app bundle, but it is switched off: no PostHog project is provisioned and the app ships a placeholder token, so nothing described in this section is sent anywhere yet. It takes effect only after the 14-day notice described under Changes to this policy has run, and this note will be removed when it does.

Analytics events are recorded in our own Supabase database, described below. A limited subset is also sent to PostHog, a product-analytics provider we use to understand how people move through the app — for example, how many people finish onboarding, or where they leave the subscription screen.

What we send to PostHog is restricted by an explicit list built into the app. It covers app opens, screen views, onboarding steps, sign-in and account events, and the subscription flow.

We deliberately do not send PostHog anything about your peptide use or health:

  • Not your dose amounts, and not the fact that you logged a dose at all
  • Not the names of peptides in your library
  • Not your weight, mood, or journal entries
  • Not your promo or affiliate codes, only whether one was used

PostHog also receives an identifier for your account that is scrambled before it leaves your phone, so PostHog cannot link its records to your Peptmate account or database records. Your events are stored by PostHog on US infrastructure, under the standard contractual clauses in our agreement with them. If you are in the EU, UK, EEA or Switzerland this is a transfer outside your region. Session replay and error tracking, both of which would capture screen contents, are switched off.

You can turn this off at any time in Settings → Share usage data. Turning it off stops any data reaching PostHog, from the very next event. Peptmate’s own analytics, in our own database, continue either way — they are part of running the service.

What the app does not collect

  • No access to your contacts, microphone, camera, calendar, or location
  • No access to your photo library. Where you add a picture — a profile photo, or the background of a milestone card you choose to share — your phone’s own photo picker opens and hands the app only the single image you picked. A profile photo is stored with your account; a milestone photo stays on your device and is discarded when you close the card
  • No advertising, and no third-party advertising SDKs. The only third-party SDK in the app that can carry usage data is PostHog, described above
  • No Apple HealthKit access
  • No tracking across other apps or websites, and no advertising or data-broker relationships with anyone
  • We never sell or rent your data to anyone

On Android

Your records are kept on your device so the app works without a connection. Peptmate opts out of Android’s automatic backup to Google Drive, so your doses, weights, journal entries and sign-in token are not copied into your Google account. Reinstalling and signing in restores your records from our servers instead.

The Android app asks for: internet and network access; permission to post notifications, which is how dose reminders reach you; permission to schedule those reminders at an exact time, so a reminder set for 8:00 arrives at 8:00; permission to be told when the phone has restarted, so your reminders survive a reboot; and the vibration, wake-lock and home-screen badge-count permissions a reminder needs to announce itself. That is the complete list. It does not ask for the camera, the microphone, your photo library, your contacts or your location.

If you signed up with a creator code

Current status (1 September 2026). Nothing in this section happens yet. No creator can see anything about the people who used their code, because the screen that would show it has not been built and the data is not sent anywhere. It takes effect only after the 14-day notice described under Changes to this policy has run, and this note will be removed when it does.

Some people find Peptmate through a creator or partner and enter that person’s code when they sign up or subscribe. If you did, we report a limited, deliberately coarse summary of your subscription back to that creator, so they can see that their audience is subscribing and be paid for it.

There are two other situations in which something about your use of Peptmate reaches someone outside Tech Quarters, and both are different in kind: a friend’s referral code being used, and the rewards programme, which sends an email address to a separate commercial brand. Both are described in the next section. Apart from those three, nothing about your use of Peptmate is reported to anyone outside Tech Quarters. If you did not enter a creator code, nothing in this section applies to you.

What the creator sees. One row, which is you, carrying only:

  • An opaque reference — a meaningless string of characters, not your name, not your email address, and not your Peptmate user id
  • The month you joined — the month only, never the day
  • Your plan tier — for example monthly or annual
  • Whether your subscription is currently active or has lapsed
  • How many months you have been subscribed
  • What your subscription has earned that creator

That is the complete list. If a field is ever added to it, this section changes in the same release.

What the creator never sees.

  • Your name, your email address, or your Peptmate user id
  • The day you joined, or any day-level date at all
  • Your device, your location, or your IP address
  • Anything you log in the app. No doses, no peptides, no weights, no feelings, no journal entries, no reminders, no notes — nothing health-related of any kind, ever. None of it leaves our systems and none of it is part of this report.
  • Anything about any other Peptmate user, and no comparison between creators

Where the reference comes from. The opaque reference is generated separately for each creator. If two different creators were ever associated with the same code, the same person appears to each of them under a completely unrelated reference, so two creators cannot compare lists and work out who is on both.

Why the month, and not the date. A creator knows when they published the video or post that brought someone in. A join date would let them match a row to a particular day’s audience; a join month does not. For the same reason we do not report the time of day, the device, or anything that could be lined up against a creator’s own records.

Small groups are not shown at all. Being given a reference instead of a name is not the same as being anonymous. A creator with several hundred referred members learns nothing about any individual from a row like this. A creator with three could reasonably work out which friend each row is, what they pay, and whether they cancelled.

So where a creator has referred fewer than five people, no rows are shown to them at all — not the largest few, not a partial list, nothing. They see only their total earnings, and a plain sentence explaining that individual rows are withheld because the group is too small. Showing four rows and hiding the fifth would reveal the fifth by subtraction, so it is all or nothing.

If you would rather not be included, contact us at the address at the end of this policy. You can also delete your account at any time in Settings, which removes your data as described under How long we keep your data.

If you used a friend’s referral code, or shared your own

This is different from the creator programme above, and the difference is who is on the other end. A creator is a business partner on a signed agreement. A referrer is an ordinary Peptmate customer, exactly like you — a friend, a training partner, someone in a group chat — and what they are shown about you is far less than what a creator is shown.

Every Peptmate account gets a referral code. Someone setting up the app can enter a friend’s code, and that friend can then see a small amount about it — two counts in the app, and, if they open the referrals dashboard on the web, one row per person with a few signals of activity on it. Both are set out below, because they are different.

What is recorded when a code is entered

Entering a code writes a record, and it is a record about two people at once.

About you, the person entering the code. Your Peptmate user id, the code you entered, and the moment you entered it. Later, if and when the referral activates — which needs you to have entered the code when you created your account, finished setting the app up, added at least one peptide and logged doses on three separate days, all within 14 days of creating your account — that record is stamped as activated, together with the moment it happened and which dose completed the third day. Nothing else about any of those doses is copied into it: not what you took, not how much, not when you took it. Nothing you logged before you entered the code counts towards it.

About the referrer, the person whose code it was. Their own code, which is generated from their profile name, and the running total of how many people have entered it and how many of those have activated.

One referrer, once. The record is written the first time and never rewritten. A second code entered later is ignored rather than replacing the first, and your own code cannot be used on your own account. It works that way so that who referred whom cannot be quietly changed afterwards, including by us: a record that can be reassigned is a record that can be taken off the person it belongs to.

Where it is stored. These records live in our own Supabase database, alongside the rest of your account and under the same row-level security. If you opt in to rewards, a second record of the same relationship is kept by the store described below, holding your email address, your tier and your counts. The two together are what lets a reward be worked out in one place and honoured in the other.

This is not the creator attribution above. A creator code and a referral code are typed into the same box and look identical, but they are two different records answering two different questions. The creator attribution described in the previous section is unchanged by any of this, and nothing in the referral records is reported to a creator.

What the referrer sees in the app

Two counts, and nothing else:

  • How many people entered their code
  • How many of those have activated — that is, have got going with Peptmate: finished setting the app up, added at least one peptide and logged doses on three separate days, all within 14 days of creating their account

That is the complete list for the app. Both numbers are their own. In the app they see no rows and no list — whatever they see, they see about a group, never about a person — and the app shows them no rank, no leaderboard position, no total across other people, and no comparison with anybody.

The second number counts only people who entered a code when they created their account. If you were already using Peptmate before you entered someone’s code, you are never counted in it — not then and not later — so a referrer learns nothing at all about anyone who was already using Peptmate. Nothing you logged before you entered the code counts towards it either.

The second number is also updated once a day rather than as you log, so it does not report the moment you did anything.

What the referrer sees on the referrals dashboard

A referrer who has opted in to rewards can sign in to a dashboard on the Peptmate website. It shows more than the app does, and this is the part worth reading carefully.

It lists one row for each person who entered their code. So unlike the app, the dashboard does tell a referrer that you exist as a distinguishable person among the people they referred. Each row carries:

  • A label we generate, such as “Member 8F2A”. It is not your name, not your email address and not your user id, and it is scrambled differently for each referrer, so two referrers comparing screens cannot work out that a row on one is the same person as a row on the other
  • Whether the referral is still setting up or has activated, and the dates of each
  • When we last saw any activity from that account — a date, not what the activity was
  • How many separate sessions that account has had in the app
  • How many doses have been logged — a count, and only a count

The last three are there because the reward depends on them. A referral only counts once the person has genuinely started using Peptmate, and a referrer who cannot see whether their friend has opened the app cannot tell the difference between a friend who needs a nudge and a programme that is not working.

The dose figure is a number and nothing more. What you logged, how much, which peptide, on what schedule and at what time are not shown, are not sent for this, and are not held anywhere the dashboard can reach. A count of three says somebody has logged three times. It does not say what.

A dash on the dashboard means we could not read a figure, not that it is nought.

What the referrer never sees, anywhere

  • Your name, your email address or your Peptmate user id
  • Anything you log in the app. No peptides, no doses, no amounts, no schedules, no weights, no moods, no journal entries, no notes. The dashboard carries a count of logged doses and nothing about any of them
  • Your device, your location, or your IP address
  • The time of anything you did. The dashboard shows dates, never clock times, and the activation figure is worked out once a day rather than as you log
  • Anything about any other Peptmate user, including anybody they did not refer themselves
  • Any rank, leaderboard position or comparison with other referrers

There is no screen that could show them any of this, and the data is not sent.

What you are never told about them

The same rule runs in both directions. We tell you nothing about the person whose code you used — not their name, not their account, not their code back to you. If you did not already know who gave you the code, Peptmate will not tell you.

What a label and a few figures can still tell someone

A generated label is not the same as anonymity, and with small numbers it stops being one.

If someone gives their code to exactly one person, then the single row on their dashboard is about that one person. They already know who they sent the code to, so the label identifies them by elimination — and the figures beside it then say that that person has been recording doses in a peptide-tracking app, roughly how often, and when they were last active.

That is a real disclosure and we are not going to describe it as anonymous. It is also bounded, and the bound is the part that matters: it says how much and when, and never what. Not what you are taking, not how much of it, not on what schedule, not what you wrote down.

We are telling you this plainly because for a referrer with a handful of referrals these figures are not anonymous. The creator report above solves the same problem by withholding rows entirely below five people; the referral dashboard carries no such threshold today.

If that matters to you, the control is simple and entirely yours. Nobody can add you to their count without you typing their code, and you have three options, none of which costs you anything:

  • Skip the code. The step that asks for one is optional, skipping it is one tap, Peptmate works identically without it, and nothing is recorded.
  • Enter it later, or not at all. Nothing about your account depends on it.
  • Ask us to remove it. Contact us at the address at the end of this policy.

What we never do with it

We do not use your referral record to advertise to you, we do not sell it, and we do not share it with anyone outside Tech Quarters. It is not connected to anything you log.

Your own code, and what it discloses

Your code is your first name followed by three digits — SARAH123 for a Sarah. So the code itself tells whoever you send it to that your first name is Sarah. That is accepted because you choose who to send it to, and it is the reason your code is shown to you and nowhere else: never on a leaderboard, never in a shared report, never on a public page, never to another customer who did not receive it from you.

If your profile name has fewer than three letters our alphabet recognises, the code starts PEPT instead and discloses nothing about your name.

Codes changed format in September 2026, and every code issued before then was reissued. Nothing anybody had already shared was broken: we kept every old code working, pointing at the same person it always did, and we do not reissue a retired code to anybody else. If you gave somebody your old code, it still works.

Apart from that one change, a code does not change — including if you rename your profile — because a code you have already given out cannot be recalled.

The rewards programme, and the store the rewards are held at

Referring people can earn a reward. The reward is not money and it is not paid by us: it is store credit and discounts at EPAU (shop.epauofficial.com), a separate commercial brand that runs an online store. Peptmate holds no balance and pays nothing out.

Opting in is a separate, deliberate step, and it is optional. Referring somebody does not opt you in. Nothing about you is sent to the store, and no account is created for you there, until you opt in and give an email address for it.

What crosses to the store when you opt in, and afterwards. Your email address. Your Peptmate referral code. Which rung of the ladder you have reached and how many activated referrals sit behind it. The amount of a credit, when one is earned. And a reference for each message so it cannot be applied twice. That is the complete list. If a field is ever added to it, this section changes in the same release.

Your referral code is generated from your profile name, so sending it tells the store your first name. There is no version of the code that does not, and it is sent because it is what ties the two records together.

What never crosses.

  • Your Peptmate user id
  • Your name as you entered it, beyond whatever the code itself carries
  • Your date of birth, sex, height or weight
  • Your device, your location, or your IP address
  • Anything you log in Peptmate. No peptides, no doses, no schedules, no moods, no journal entries, no reminders, no notes
  • Anything about the individual people you referred, or about any other Peptmate user

What the store creates, and what it does not. The store creates an account under the email address you gave, so the credit has somewhere to sit, and sends us back the customer id it created so the two records can be matched later. That account has no password, and we are never signed in to it. Opting in does not sign you in to anything, does not give Peptmate access to the store, and does not give the store access to Peptmate. To use the account you go to the store yourself and set it up in the ordinary way.

The store is not one of our processors. It is a separate business, the account is its own, and what it does with that account is governed by its own privacy policy rather than by this one. We are telling you its name rather than calling it “a partner” because you cannot check a company you have not been told the name of.

The reward itself is not described here. What is earned, when, and on what conditions is set out in the Rewards programme terms, not in this policy. This section is only about the data.

How long the referral records are kept, and how to have yours removed

  • The record of who referred whom. Kept for as long as the accounts involved exist. It is deliberately append-only: it cannot be edited, re-dated or deleted through the app, by you or by us, which is the same property that stops anyone quietly changing who referred whom. Deleting your account removes your account data as described under How long we keep your data; ask us if you also want the referral record removed, and we will do it by hand and confirm when it is done.
  • The counts shown to a referrer. Derived from those records, so they fall when a record is removed.
  • Anything already sent to the store. Held by the store under its own policy and its own retention, not ours. Ask us and we will pass an erasure request on; you can also ask the store directly.

If you would rather not be included

Not entering a code is the whole opt-out for referrals, and it is available at the moment you are asked. Not opting in to rewards is the whole opt-out for the store, and nothing reaches it until you do. If you have already done either, contact us at the address at the end of this policy. Deleting your account removes your data as described under How long we keep your data.

Part 2 — the peptmate.com website

Website analytics

The website uses privacy-preserving, aggregated analytics provided by Vercel, who also host the site. This records the page path, referring site, approximate country, device type and browser. It sets no cookies, collects no personal information, and builds no profile of you.

Alongside it we use PostHog — the same product-analytics provider and the same US-hosted project as the app — to understand how people move through the site: which pages are read, which buttons are pressed, and where people leave the two forms. PostHog acts as our processor and may not use the data for its own purposes.

  • Purpose. Measuring the site: pages viewed, calls to action pressed, App Store taps, calculator use, and progress through the enquiry and application forms.
  • Region. Events are sent to PostHog’s US infrastructure, the same region the app uses, and are routed through peptmate.com rather than direct to PostHog. If you are in the EU, UK, EEA or Switzerland this is a transfer outside your region; it is covered by the standard contractual clauses in our agreement with PostHog, and it happens only if you accept the banner described below.
  • What is never sent. No value you type into a field. When a form step fails validation we record which fields failed, never what you entered. Calculator inputs are never sent — only the fact that a calculator was used.
  • Identity. Most visits are anonymous and no person profile is created. A profile is created at only two moments — when you submit the business enquiry form, and when you submit the affiliate application — and it is keyed on a one-way hash of your email address, never the address itself.
  • Session replay is off. We do not record your screen or your typing.

Your consent, and how to opt out

  • If you are in the EU, UK, EEA or Switzerland, nothing is sent to PostHog until you accept the banner shown on your first visit. Decline and no analytics events are captured at all.
  • Elsewhere, including Australia, analytics start on load and you can opt out at any time using the opt-out control on this page. Opting out takes effect immediately and clears any PostHog cookie.
  • We honour Global Privacy Control everywhere. If your browser sends a GPC signal we treat it as an opt-out, whichever region you are in, without you having to do anything else.
  • Using the forms never requires analytics consent. Declining or opting out does not stop you sending us an enquiry or an application.

The forms on this website

Two forms collect personal information. Both are optional — you can read every page on the site without using either.

Business partner enquiry, on the business page. We collect your contact name, work email, company, a website or social handle, an optional message, and your tick confirming we may contact you about your enquiry.

Affiliate application, on the creators pages, across four steps:

  • Your full name, email and country, plus your Australian state if you give one
  • The platforms you create on, your handle or URL on each, and a follower band rather than an exact number
  • The niches you cover, and a short description of your audience
  • Optionally, how you would work with us and any existing partnerships, plus your acceptance of the partner terms

Alongside either form we record a partner code if you arrived through one, the campaign parameters and referring page that brought you, the page you landed on, a hash of your IP address, and the PostHog identifiers for your session so a submission can be matched to the visit that produced it. That is a field on a form, and it is a different thing from the user-to-user referral records described in Part 1, which are keyed to a Peptmate account rather than to a website visit.

Neither form ever asks for bank details, an ABN, a phone number, a date of birth, a postal address, or screenshots of your follower counts. If we accept your application, payout details are collected separately, afterwards.

Submissions reach a person through an internal Telegram alert containing your name and your enquiry, so we can keep the promise on those pages to reply to everyone.

Part-finished applications, and how long we keep them

The affiliate application saves your answers as you go. A record is created when you finish the first step, before you have submitted anything, so you can close the tab and pick up where you left off. Resuming uses a token held in a strictly functional cookie that expires after 30 days, and a copy in your browser’s local storage.

  • If you never submit it, the part-finished application is deleted 60 days after you last touched it.
  • We will never contact you about it. A part-finished application is not marketing consent. It is never added to a mailing list, and we do not send “finish your application” reminders.
  • If you submit it and we do not accept it, we keep the record, because it is the record of an application you made and of the terms you accepted at the time. You can ask us to erase it.

We send marketing email only to people who have separately opted in to receive it. Ticking a form’s consent box so that we can reply to your enquiry is not that opt-in.

Documents you send with a business enquiry

If you send us a document to support a business partner enquiry — a business registration, a certificate of currency, a certification, a company profile or a price list — it is handled differently from the rest of your enquiry, and it is deleted on a schedule rather than kept.

The file goes straight from your browser into private storage. It is never public, it has no shareable address, and the only way it can be opened is by a member of our team through a link that expires after a minute.

How long we keep it depends on what happened to your enquiry, and the clock starts again if you send us another document:

  • If nobody has picked your enquiry up, or we are still working on it — the document is deleted 60 days after the last activity on your enquiry.
  • If we decide not to go ahead — the document is deleted 30 days after that decision. That window is there so a decision can be reconsidered; after it the file has no purpose and we do not keep it.
  • If we accept the enquiry — the document is deleted 12 months after that. A registration extract or a certificate of currency stops describing anything current long before then, and holding an old copy is not something we do.

We keep the enquiry; we delete the file. The record of what you asked us and what we decided survives, because that is the record of a conversation you chose to start. The document attached to it does not.

Deleting our record of a document deletes the file itself. No separate copy is left behind.

You can ask us to erase a document sooner, at any time, without waiting for any of the periods above.

Cloudflare Turnstile

Both forms are protected by Cloudflare Turnstile, which checks that a submission comes from a person rather than a bot. Cloudflare receives your IP address and signals about your browser in order to score the request, and returns a pass or a fail to us. It shows no puzzles, sets no advertising cookie, and does not build a profile of you across sites. Cloudflare’s privacy policy is at cloudflare.com/privacypolicy.

IP addresses

We never store your raw IP address. When you send a form, your IP is normalised and immediately turned into an irreversible hash using a secret salt, and only that hash is written down. It cannot be turned back into your address, and it is used for one thing: spotting abuse and rate-limiting floods of submissions.

We also read the approximate country your request arrives from, to decide whether you must be shown the consent banner and for coarse analytics. That is not stored against your form record. Routine server request logs, which contain IP addresses as any web server’s do, are kept for up to 30 days and then discarded.

Cookies on the website

  • No advertising cookies, and no cross-site tracking cookies, ever.
  • The Vercel analytics set no cookies at all.
  • PostHog sets a first-party cookie only where analytics are permitted — which, in regions that require consent, means after you have accepted.
  • Your consent choice, and the token that lets you resume a part-finished application, are stored on your own device. The resume cookie is HTTP-only and expires after 30 days.

The calculators

The free calculators on the website run entirely in your browser. The values you enter are not transmitted to us, are not sent to any analytics provider, and are not stored.

Your choices on the website

  • Opt out of analytics at any time, using the control on this page or by turning on Global Privacy Control in your browser.
  • Ask what we hold. Email us and we will tell you what a form submission of yours contains.
  • Ask us to delete it. Email we@peptmate.com and we will erase your enquiry or application, submitted or not. You do not need an account to ask.

How we use your information

  • Authenticate you and let you sign in across devices
  • Show your library, dose history, weight chart, and journal back to you
  • Deliver the reminder notifications you configure (scheduled locally on your phone)
  • Improve the app and the website by reviewing aggregated analytics
  • Reply to the enquiries and applications you send us, and assess them
  • Respond to feedback or support requests you send
  • Report the coarse subscription summary described under If you signed up with a creator code to that creator, and pay them, if you entered one
  • Add one to the two counts described under If you used a friend’s referral code, or shared your own, shown to the person whose code you entered, if you entered one
  • Work out which rung of the rewards ladder you have reached, and, if you have opted in, send the store described in that section what it needs to hold the reward for you

We do not use your data for advertising, profiling, or any purpose other than running Peptmate.

Where your data is stored

Your app data lives in two places: locally on your iPhone in the app’s sandboxed storage, and on Supabase, our backend infrastructure provider, which hosts our database. Supabase’s data processing terms are at supabase.com/privacy. Row-level security on every table means you can only ever access your own data; other Peptmate users cannot see your information. The one exception is the coarse summary described under If you signed up with a creator code, which carries no name, no email address, no user id and nothing you log — and which applies only if you entered such a code.

Enquiries and applications sent through the website are stored in the same Supabase database, reachable only by us. Analytics events are stored by PostHog on US infrastructure, under the standard contractual clauses in our agreement with them.

The referral records described in Part 1 are held in that same Supabase database. If you opt in to rewards, a second copy of the parts listed in that section is also held by the store named there, on that store’s own systems and under its own policy.

Service providers we use

  • Supabase hosts our database and authentication service.
  • Vercel hosts peptmate.com and provides its aggregated analytics.
  • Resend delivers our account emails (confirmation links, password resets). It processes your email address for delivery and nothing else.
  • Apple and Google act as sign-in providers if you choose them.
  • PostHog provides product analytics for the app and the website, stored on PostHog’s US infrastructure under standard contractual clauses. It receives only the limited, health-free events described in Parts 1 and 2, and you can switch it off.
  • Cloudflare provides the Turnstile bot check on the website’s two forms.
  • Telegram carries the internal alert that tells us a website form has been submitted.
  • Discord carries the internal alert that tells us a new account has been created. It receives your Peptmate user id and nothing else — no email address, no name, and nothing you have logged.
  • Klaviyo runs our marketing email. Every Peptmate account becomes a Klaviyo profile, whether or not you asked for marketing email. When you sign up we send Klaviyo your email address, your first name if you gave one, your Peptmate user id, and a small set of account facts used to group people for a send: how you signed in, when you signed up, whether your email is confirmed, whether you are on the free or premium tier, whether you finished onboarding, and your creator code if you used one. The “Email me tips and updates” switch controls whether you are subscribed to marketing sends — not whether the profile exists. Turn it off and we record you as unsubscribed; the profile stays until you delete your account. Klaviyo never receives anything you log: no doses, no weights, no journal entries.

None of the providers above may use your data for their own purposes.

EPAU is deliberately not on that list. It is not a processor acting for us: it is a separate commercial brand, the store account it creates under your email address is its own, and what it does with that account is governed by its own privacy policy. Nothing reaches it unless you opt in to rewards, and what it receives is listed in full under If you used a friend’s referral code, or shared your own.

We have no advertising or data-broker relationships with anyone.

How long we keep your data

  • Your account. Kept as long as your account exists. When you delete your account in Settings, your data is permanently removed from our live database within minutes, including your authentication record. Encrypted backups of that database are kept for 7 days and expire on their own; nothing is ever restored from them except to recover the service after a failure.
  • Referral records, and the rewards link. The record of who referred whom, and its activation stamp, are kept for as long as the accounts involved exist, and are append-only rather than editable. If you opted in to rewards, the store holds your email address, your tier and your counts under its own retention. Both are described, with how to have them removed, under If you used a friend’s referral code, or shared your own.
  • Part-finished affiliate applications. Deleted 60 days after you last touched them, as described in Part 2.
  • Submitted enquiries and applications. Kept as the record of the enquiry or application you made, and erased on request.
  • Documents sent with a business enquiry. Deleted on a schedule, never kept indefinitely: 60 days if the enquiry is untouched or still open, 30 days after we decide not to go ahead, 12 months after we accept. Described in full in Part 2.
  • Server request logs. Up to 30 days. They do not contain your personal content.

Your rights

  • Access. Everything Peptmate stores about you is visible in the app. For an exported copy, or for a form you sent us, email us.
  • Correct. Edit any field directly in the app, or email us about a form submission.
  • Delete. Settings → Delete account. Immediate and permanent, and the email address becomes reusable for a fresh account. You can also ask us to delete your account without installing the app, by writing to we@peptmate.com from the address on the account. For website enquiries and applications, email us.
  • Sign out at any time without deleting. Your data stays on the server; sign in again to restore it.
  • Opt out of third-party analytics. In the app, Settings → Share usage data. On the website, the opt-out control on this page, or Global Privacy Control. Either takes effect immediately and needs no account change.

If you are in the EU, UK, or California, you have additional rights under GDPR, UK GDPR, and CCPA respectively. Peptmate does not sell personal information. To exercise any right, email us.

Children’s privacy

Peptmate is not intended for anyone under 18, and we do not knowingly collect information from anyone under 18. If you believe a minor has signed up, contact us and we will delete the account.

Changes to this policy

If we materially change how we collect or use your data, we will update this page and the effective date above, and notify active users in the app or by email at least 14 days before the change takes effect.

Contact

Email: we@peptmate.com
Tech Quarters Pty Ltd, Australia

peptmate.

Takes the thinking out of peptides.

Peptmate is a research and information companion. It doesn't give medical advice, and dosing decisions stay with you and your healthcare professional.

Product

  • Features
  • FAQ

Free tools

  • Reconstitution calculator
  • Dosage calculator
  • Bacteriostatic water
  • Syringe unit converter

Learn

  • Guides
  • Tools compared

Company

  • About
  • Rewards
  • Contact
Made in Australia.© 2026 Peptmate by Tech Quarters Pty Ltd.
Privacy
policy
Terms of
use
Medical
disclaimer
Rewards programme
terms