Privacy Policy

What we collect, why we collect it, who else sees it, and how to get it back or delete it. Written to be read, not to be survived.

The short version. We store the protocol you build, the doses you tick off, and your conversations with the Guru. We do not run any advertising or analytics trackers — none, not one. We do not sell your data. You can download everything or delete your account from the Account page at any time, without asking us.

Who we are

DoseIQ is operated by , . For anything in this policy, write to .

What we collect

Because you gave it to us

  • Your email address and password. Passwords are hashed by our authentication provider — we never see or store the plain text, and we cannot recover it for you.
  • A display name and time zone, if you set them. Both optional; the time zone is used so reminders arrive at the right hour.
  • Your protocol. The compounds you add, vial sizes, doses, frequency, route and timing.
  • Your dose history. Which doses you marked taken, and when.
  • Reminders you set up.
  • Your conversations with the Peptide Guru, including the questions you type and the answers it gives.
  • Share links you create, and what they point at.
This is health information. A list of compounds and doses says something real about your body and your choices. We treat it that way, and this policy is written on that basis.

Because it happens automatically

  • Standard server logs from our hosting and database providers — IP address, browser type, timestamps. Ordinary infrastructure logging, used for security and debugging.
  • Local storage in your browser. Your protocol, your theme choice and recent Guru chats are kept on your own device so the app opens instantly and works when the network doesn't. This stays on your device. Clearing your browser data removes it.

What we deliberately do not collect

  • No advertising trackers. No Meta Pixel, no Google Ads tags, no remarketing of any kind.
  • No analytics product. We do not run Google Analytics or any equivalent.
  • No third-party cookies.
  • No location data, contacts, or device identifiers.
  • No payment card details. Those go directly to Stripe and never touch our servers — we only ever see the last four digits and the card brand, through Stripe's own interface.

Why we collect it

  • To run the product — calculate your doses, show what's due, track adherence, send reminders you asked for.
  • To answer your questions through the Guru, using your protocol as context so the answers are about you.
  • To take payment, if you subscribe to Pro.
  • To keep the service working and secure — diagnosing faults, preventing abuse.
  • To email you about your account — confirmations, password resets, billing, and material changes to this policy.

We do not use your protocol data to train any machine-learning model, our own or anyone else's.

Who else sees it

We use a small number of service providers. Each one gets only what it needs to do its job, and none of them may use your data for their own purposes.

ProviderWhat it doesWhat it receives
SupabaseDatabase and sign-inEverything listed above. Data is stored in the United States.
AnthropicPowers the Peptide GuruYour question, the relevant compound reference data, and — if you ask about your own protocol — the parts of it needed to answer.
StripePaymentsYour email and payment details, which you enter on Stripe's own page. We never receive your card number.
HostingerWebsite hostingServer logs only. No account data is stored here.
About the Guru specifically. When you ask a question, it is sent to Anthropic to generate the answer. Do not put anything in the chat you would not want leaving our systems — full name, address, or anything identifying beyond what the question needs. Ask about the compound, not about who you are.

We do not sell your data

We do not sell, rent or trade personal information, and we do not share it with advertisers, data brokers, or peptide suppliers. If that ever changes we will say so here before it happens and ask your permission first, because doing otherwise would be both dishonest and, under the FTC's Health Breach Notification Rule, unlawful.

The only other cases where we would disclose anything: when the law genuinely requires it, and if the business is ever sold — in which case the buyer inherits these same obligations, and you would be told before anything moved.

Your data, and what you can do with it

All of this works from Account → Your data without asking us or waiting on us.

  • Download everything. One button, complete export in a readable format.
  • Correct anything. Every field is editable.
  • Delete your account. One button. This removes your profile, protocol, dose history, reminders, share links and Guru conversations. It cannot be undone, so export first if you want a copy.
  • Revoke share links individually, at any time.
  • Turn off reminders, or object to any processing you disagree with, by writing to us.

Backups persist for up to 30 days after deletion, then age out. Records we are legally required to keep — payment records for tax purposes, for example — are retained for as long as the law requires and no longer.

Depending on where you live, PIPEDA, the GDPR or state laws such as the CCPA give you these rights explicitly. We extend all of them to everyone regardless of location, because operating two standards would be worse for everyone and harder for us.

How long we keep things

  • While your account is open: your protocol and history, so the adherence record stays meaningful.
  • Guru conversations: until you delete them or your account.
  • Server logs: around 30 days.
  • Billing records: seven years, as tax law requires.
  • Inactive accounts: if you don't sign in for two years we'll email you first, then delete the account if we hear nothing.

Security

  • Everything travels over HTTPS.
  • Passwords are hashed, never stored in readable form.
  • Row-level security is enforced in the database itself, so one account cannot read another's rows even if the application layer has a bug.
  • Payment details never reach our servers.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach affects your information we will notify you, and the FTC, without unreasonable delay and within 60 days of discovering it, as the Health Breach Notification Rule requires.

Age

DoseIQ is for adults. It is not intended for anyone under 18, and we do not knowingly collect information from minors. If we learn we have, we delete it. If you believe a minor has created an account, tell us and we will remove it.

Changes to this policy

If we change anything material — particularly anything affecting who receives your data — we will email you before it takes effect, not after. The date at the top always reflects the current version.

Contact

Questions, requests, or complaints: . We aim to answer within 30 days.

In Canada you may also complain to the Office of the Privacy Commissioner. In the UK or EU, your national data protection authority.

This policy describes DoseIQ only. It is not legal advice, and it does not cover any site we link to.