PepSense, Inc. ("PepSense", "we", "our") publishes this Consumer Health Data Privacy Policy as a separate and distinct document, as the Washington My Health My Data Act (RCW 19.373) and Nevada SB 370 (NRS 603A.400 et seq.) require. It covers only consumer health data. Everything else we collect, including account credentials, waitlist information, subscription records, and device logs, is described in our general Privacy Policy at pepsense.ai/privacy.
This policy applies to the pepsense.ai website, the PepSense iOS app, and the PepSense web application. It applies to every PepSense user, not only to residents of Washington and Nevada. We saw no reason to give people in other states weaker protection over the same data.
PepSense is a research and education product. We are not a health care provider, a pharmacy, a compounder, a manufacturer, a prescriber, a peptide vendor, or a telehealth service, and we are not covered by HIPAA. We do not supply any compound or diluent. That does not leave your data unregulated. The consumer health data laws described here apply to us directly, and every statement in this policy is a commitment we can be held to.
1. What counts as consumer health data in PepSense
Washington and Nevada define consumer health data broadly. It covers information linked or reasonably linkable to you that identifies your past, present, or future physical or mental health status, including health conditions, treatments, interventions, bodily measurements, symptoms, and the use or purchase of medication.
In PepSense, that definition reaches the following. This is the complete list of what we hold, written out item by item rather than as a category label, so you can see exactly what is covered.
- Compounds you add to your protocol, including the compound name, class, concentration, vial size, half-life, and the schedule you set
- Dose events, including the amount in milligrams, the units, the route of administration (injection, oral, nasal, or sublingual), the body site for injections, and the time the dose was logged
- Reconstitution calculator entries, meaning the values you type in (the amount of compound in the vial, the volume of diluent you are adding, and the amount you want to measure out) together with the volume or syringe-unit figure the calculator returns from those numbers, when you save an entry to your account
- Weight entries, with the unit and the date
- Side effects you describe in your own words, with a severity rating from 1 to 5, optionally linked to a specific dose
- Goal metrics: waist measurement, appetite, energy, skin clarity, hydration, and breakout count
- Progress photos of your body, with the date taken and the weight recorded at that time
- The text of the research questions you ask, which can itself reveal a health status, a symptom, or an intention, along with the AI answer and the conversation history in that thread
2. Why we collect each category, and exactly how it is used
Washington requires us to state the purpose of collection, including how the data will be used. Nevada requires us to state the manner of use. Below is the specific answer for each category. Every use listed is a feature you can see in the product.
| Category | Specific purposes and uses |
|---|---|
| Compounds in your protocol | Display your protocol on the Today and Protocol screens; group doses by compound; drive the schedule and the local dose reminders you turn on; generate your estimated-level charts, which are research estimates calculated from published half-life values and are shown for context only. Those charts are not dosing guidance and PepSense does not tell you how much to take. |
| Dose events | Build your dose history and adherence view; mark scheduled doses complete; power the reminders you enable; feed the estimated-level charts described above; let you associate a side effect with a specific dose. |
| Reconstitution calculator inputs and results | Perform the arithmetic that converts the numbers you enter into a corresponding volume or syringe-unit equivalent, and display that figure back to you; keep an entry you choose to save available in your account so you can look it up again and so the figure carries the compound label you gave it. The calculator is a unit-conversion utility. It operates only on values you supply. It does not recommend, suggest, select, validate, verify, or approve any amount, and it does not generate protocols, titration schedules, or frequency guidance. |
| Weight entries | Chart your weight over time against the starting weight you entered; pair a weight with a progress photo so the timeline reads correctly. |
| Side effects | Show your own side effect history with its severity ratings; let you see which dose an entry was linked to, if you linked one. |
| Goal metrics | Chart change over time on the goals you personally selected, so you can review your own trend. |
| Progress photos | Display your private photo timeline inside your account, in date order, with the weight recorded at the time. |
| Research question text, answers, and thread history | Retrieve relevant passages from our research library and generate an answer with citations; keep the earlier messages in a thread so follow-up questions make sense; keep your conversation history available to you when you return; count questions against the free-tier daily limit. |
3. Where this data comes from
There is one source: you. Every item listed in Section 1 arrives because you typed it, tapped it, selected it, or photographed it inside the PepSense app or web application. Nothing is collected passively or in the background.
The reconstitution calculator is no exception. Every figure it returns is arithmetic performed on numbers you supplied yourself. It is not an inference we draw about you, not a recommendation, and not information obtained from anyone else.
We want to be equally clear about the sources we do not use. We do not receive consumer health data about you from data brokers, advertising platforms, marketing partners, health care providers, insurers, pharmacies, laboratories, peptide vendors, wearables, or connected devices. We do not read Apple Health or HealthKit; the Apple Health row in Settings is an inactive placeholder and every weight entry is manual. We do not derive or extrapolate health data about you from non-health information such as browsing behavior, purchases, or location.
4. What we share, and with whom
We do not share your consumer health data with any third party for that third party's own purposes. No category of your consumer health data is disclosed to advertisers, ad networks, analytics companies, attribution vendors, social media platforms, data brokers, employers, insurers, or researchers.
The only outside companies that come into contact with this data are the service providers listed below. Each acts strictly as our processor under a written contract that limits it to processing on our documented instructions, prohibits use for its own purposes, prohibits sale, requires appropriate security, and requires deletion or return of the data when our relationship ends. Under both Washington and Nevada law, disclosure to a processor bound by contract for the disclosed purpose is not "sharing." We keep our providers in that posture deliberately, because it is what lets us say honestly that we do not share your health data.
We are naming them anyway, along with the specific categories each one receives, so that you can see the full picture rather than a category label.
| Processor | Role | Consumer health data it receives |
|---|---|---|
| Supabase | Database, authentication, file storage, and serverless functions | All of it: compounds, dose events, saved reconstitution calculator entries, weight entries, side effects, goal metrics, progress photo files, and your full question and answer history |
| Anthropic (Claude API) | Generates research answers with citations | The text of your question, the earlier messages in that same thread, and the research excerpts we retrieved. No name, no email, no account ID, and nothing from your protocol log or your calculator entries |
| Voyage AI | Converts your question for search and ranks candidate research passages | The text of your question only. No name, no email, no account ID, and nothing from your protocol log or your calculator entries |
| Vercel | Hosting for pepsense.ai and our API | API traffic in transit, which can include health data on its way between the app and our database. Vercel does not store your protocol data |
Providers that receive no consumer health data
For completeness, because people reasonably assume otherwise: RevenueCat receives your PepSense user ID, App Store transaction data, and entitlement status, and receives no health data. Apple receives your subscription transaction if you subscribe on iOS, and no health data. Google and Apple sign-in receive your authentication identity only. The Google Sheet behind the website waitlist holds a name, email address, and phone number and never touches protocol data. Google Fonts serves typefaces to the website and sees only your browser's request.
The narrow exceptions
We would disclose consumer health data outside this arrangement only when you direct us to, when we are legally compelled by a valid subpoena, court order, or other legal obligation and after reviewing whether the request is valid, or where necessary to protect against a genuine and imminent risk of harm. Where we are permitted to tell you about a legal demand, we will.
In a merger, acquisition, or sale of assets, consumer health data would continue to be handled under this policy. We would notify you before any material change and obtain fresh consent where the law requires it.
5. We do not sell consumer health data
PepSense does not sell consumer health data. We have never sold it, we have never received money or other valuable consideration in exchange for it, and we have no plan or intention to.
Washington and Nevada define a sale broadly enough to capture arrangements that never involve cash, including data exchanges with advertising platforms and partnerships paid for in services or access. That broader definition is the one we hold ourselves to. There is no arrangement of any kind under which a third party obtains your consumer health data in exchange for anything of value.
If PepSense ever contemplated a sale, saying so in an updated policy would not be enough and would not make it lawful. Washington law requires a separate, signed valid authorization from you before any sale can occur, on its own document, distinct from any consent you have already given. That authorization would have to identify the specific data to be sold, name and give contact information for both PepSense and the purchaser, describe the purpose of the sale and how the purchaser would gather and use the data, state that we may not condition your access to PepSense on signing it, state your right to revoke it and how, warn you that the data may be redisclosed and may then lose statutory protection, carry an expiration date no more than one year out, and be signed and dated by you. Nevada requires written authorization obtained before any sale as well.
6. How we obtain your consent, and how you withdraw it
Under Washington and Nevada law, consent means a clear affirmative act that is freely given, specific, informed, opt-in, voluntary, and unambiguous. It cannot come from accepting general terms of use, from a pre-checked box, from deceptive design, or from your silence or inaction. We built the consent flow to that standard.
Before you can log your first dose, weight, side effect, metric, or photo, or save your first reconstitution calculator entry, PepSense presents a consent screen dedicated to consumer health data. It is separate from the Terms of Use checkbox and separate from the general Privacy Policy. Nothing is pre-checked. You can decline and still use the research features.
- The consent screen tells you the categories of consumer health data we collect, using the same list as Section 1 of this policy
- It tells you the purpose of collection and the specific ways the data will be used, matching Section 2
- It names the categories of entities that will process the data, matching Section 4
- It tells you how to withdraw consent, and where in the app to do it
- We record the date and time of your consent and the version of this policy that was shown to you
Withdrawing consent
You can withdraw your consent at any time, and it is no harder than giving it was. In the app, open Settings and withdraw consent to health data collection. You can also email support@pepsense.ai with the subject "Withdraw consent" from the address on your account.
Withdrawing consent stops future collection. It does not by itself erase what is already stored, because those are two different requests and we would rather not guess which one you meant. To remove what already exists, delete individual entries in the app, or delete your account, or send us a deletion request under Section 7. Withdrawal does not affect the lawfulness of processing that happened before you withdrew.
New categories and new purposes
If we ever want to collect a category of consumer health data that is not listed in Section 1, or use an existing category for a purpose not listed in Section 2, we will disclose it and ask for fresh affirmative consent before that collection or use begins. We will not quietly repurpose data you already gave us, and we will not treat continued use of the app as agreement.
7. Your rights over your consumer health data
These rights come from the Washington My Health My Data Act and Nevada SB 370. We extend all of them to every PepSense user regardless of where you live. Exercising them is free, at least twice in any 12 month period, and we will never charge you, downgrade your service, or treat you differently for asking.
Every right below reaches every category listed in Section 1, including saved reconstitution calculator entries and the figures the calculator returned from them.
- Confirm and access. Ask whether we collect, share, or sell your consumer health data, and get a copy of the data we hold about you.
- List of third parties. Ask for a list of all third parties and affiliates with whom we have shared or sold your consumer health data, including active contact information for each. Today that list is the four processors named in Section 4, and we will confirm it against your specific account when you ask.
- Withdraw consent. Withdraw your consent to further collection or sharing, as described in Section 6.
- Review and correct. Review your consumer health data and request changes to it. Most of it you can edit yourself in the app, including saved reconstitution calculator entries, which you can edit or delete individually.
- Delete. Have your consumer health data deleted, including saved reconstitution calculator entries, including from archived and backup systems, and have us instruct our processors to delete their copies.
What deletion actually does, described honestly
When you delete an entry in the app, including a saved reconstitution calculator entry, or delete your account, or send us a deletion request, the data is removed from our live systems right away and is no longer retrievable in the product.
Backups are the part most policies gloss over, so here is the accurate version. Our database provider keeps rolling point-in-time backups on a retention window of up to 30 days. Those snapshots cannot be edited record by record; they age out on a rotation. Deleted consumer health data therefore stops existing in our backup estate once the snapshots taken before your deletion cycle out of that window, which completes within 30 days of your request. During that window the data sits in encrypted backup storage and is not used for any purpose, is not returned to the product, and is restored only in a disaster recovery event. If a restore ever occurred within that window, we would re-apply pending deletions immediately afterward.
We also instruct our processors to delete their copies. Anthropic and Voyage AI hold question text only under their commercial API terms and do not retain it for training, and neither one ever receives your calculator entries. Supabase and Vercel delete on our instruction under their data processing agreements and their own backup rotations. We cannot audit another company's storage in real time, so we describe this as an instruction we issue and a contractual obligation they owe us, not as an instantaneous guarantee we can personally verify.
One thing survives, and you should know about it. Our servers keep a de-identified log of question and answer text so we can review answer quality and catch retrieval failures. Those rows carry no user ID, no email address, and no account link. Because there is no identifier on them, we cannot locate yours to delete, and account deletion does not remove them. This log covers the research question feature only and contains no protocol data and no calculator entries. If you would prefer your questions not appear in that log, avoid putting identifying details into what you type, and write to support@pepsense.ai so we can talk about options.
8. How to exercise your rights, our timelines, and appeals
Most of these rights you can exercise yourself, immediately, inside the app. Open Settings to withdraw consent, export your data, or delete your account. On the protocol, calculator history, weight, side effect, metric, and photo screens you can edit or delete individual entries directly.
For anything else, email support@pepsense.ai with the subject "Consumer Health Data Request" and tell us which right you are exercising. You can also write to us at 914 N San Francisco St, Flagstaff, AZ 86001.
We will ask you to verify your identity, normally by confirming that you control the email address on the account. We ask for the minimum needed to be confident the request is really yours, we do not use verification information for anything else, and we delete it afterward. If we cannot verify you, we will tell you why rather than simply going quiet. An authorized agent may submit a request on your behalf with your written permission, and we may contact you to confirm it.
- We respond within 45 days of receiving your request.
- If we need more time because the request is complex or you have made several, we may extend once by 45 additional days, and we will tell you within the first 45 days that we are doing so and why.
- Requests are free of charge at least twice in any 12 month period. If a request is manifestly unfounded or excessive, or repeated beyond that, we may charge a reasonable fee or decline, and we will explain the reason in writing.
If we deny your request: the appeal
If we deny a request in whole or in part, our response will state the reason and will explain how to appeal, in plain language and with a working link.
To appeal, reply to our decision or email support@pepsense.ai with the subject "Consumer Health Data Appeal." A person who was not involved in the original decision reviews the appeal. We will respond in writing within 45 days of receiving it, setting out our decision and the reasoning behind it.
If we deny your appeal, we will include in that written denial a conspicuous link to the Washington State Attorney General's complaint form, at www.atg.wa.gov/file-complaint, so you can submit a complaint. Washington residents may file there regardless of whether we included the link. Nevada residents may submit a complaint to the Nevada Office of the Attorney General, Bureau of Consumer Protection, at ag.nv.gov. Residents of other states may complain to their own attorney general. Filing a complaint does not cost you anything and does not require our permission.
Nothing in this section changes the dispute resolution and arbitration terms in our Terms of Use at pepsense.ai/terms, which remain the authoritative source on those subjects. The appeal process above is a regulatory right and is available to you independently of them.
9. Reviewing your data and requesting changes
Nevada law requires us to describe the process for reviewing and requesting changes to your consumer health data, so here it is specifically.
To review it: open the app and look at the Protocol, Today, Analytics, calculator history, and photo timeline screens, which display everything in your account in readable form. To receive a copy in a portable file instead, use the export option in Settings or email support@pepsense.ai.
To change it: edit or delete individual compounds, dose events, saved reconstitution calculator entries, weight entries, side effects, goal metrics, and progress photos directly on those screens. Nothing is locked and you do not need our involvement. Editing a saved calculator entry simply re-runs the arithmetic on the new numbers you enter. As everywhere else in the product, we do not evaluate those numbers, and the correction is yours to make.
If something cannot be corrected in the app, email support@pepsense.ai describing what is wrong and what it should say. We will make the correction and confirm it, or explain in writing why we cannot, within the 45 day timeline in Section 8. If we decline, you can appeal under the same section.
10. Third-party tracking and geofencing
Nevada requires a disclosure about third-party tracking, and the honest answer is that there is none.
No advertising SDK, analytics SDK, attribution SDK, crash reporter, session replay tool, heat mapping tool, tag manager, or marketing pixel runs in the PepSense iOS app, the web application, or on pepsense.ai. There is no Meta pixel, no Google Ads remarketing tag, and no TikTok pixel. We do not collect an advertising identifier and we do not present an App Tracking Transparency prompt, because there is nothing to track. The one third-party request the website makes is to Google Fonts for typefaces; the mobile app bundles its fonts and makes no such request. The web app sets a strictly necessary authentication cookie so you stay signed in, and it is not used for analytics or advertising.
This matters more here than it would elsewhere. Under the FTC Health Breach Notification Rule, disclosing identifiable health information to an advertising or analytics vendor without your authorization is itself a reportable breach, with no attacker required. Keeping tracking technology away from health data screens, including the reconstitution calculator, is a design decision, not a preference.
On geofencing: we do not use it. We collect no location data of any kind, the app never requests location permission, and there is no geofencing code in it. We do not build a virtual boundary around any hospital, clinic, pharmacy, provider office, or other place where health services are delivered, and we do not use location to identify or track you, to collect consumer health data, or to send you health-related messages. Washington prohibits this outright, Nevada prohibits it within 1,750 feet of a health care provider, and Vermont will prohibit it within 1,850 feet from 2028. All three are irrelevant to us because we have no location capability to misuse.
11. Who can access your data, and what our processors are contractually required to do
Access to consumer health data inside PepSense is restricted to the employees and contractors who need it to fulfill the purposes described in Section 2, and to no one else. That means the small number of people who operate the database and respond to support requests you send us. Access to production systems requires multi-factor authentication and is logged. Personnel with access are bound by confidentiality obligations and by internal rules that prohibit browsing user data out of curiosity or using it for any purpose outside this policy. We review who holds access when roles change.
Every processor named in Section 4 operates under a written data processing agreement. Those agreements require the processor to process consumer health data only on our documented instructions and only for the purposes we specify; prohibit it from using the data for its own purposes, including model training and product development; prohibit it from selling or sharing the data; require appropriate technical and organizational security measures; restrict onward engagement of subprocessors without our authorization; require it to assist us in responding to your rights requests; and require it to delete or return the data at the end of the engagement.
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of consumer health data, as Nevada law requires. In practice that includes encryption in transit using TLS, encryption at rest by our database and storage providers, row-level security policies scoped to the owning account so one user's health records and saved calculator entries are not readable by another, progress photos held in a private storage bucket served only through short-lived signed links and never publicly addressable, and server-side handling of API keys so they are not shipped in the app bundle. We do not store consumer health data in iCloud, CloudKit, or iCloud backup. No system is perfectly secure, and we will not claim otherwise, but these are the specific measures in place rather than a general assurance.
12. Effective date and how we tell you about changes
The effective date of this policy is stated at the top of this page and always reflects the version currently in force. We keep prior versions and will provide one on request.
For minor edits, such as clarifying wording or fixing a typo, we update this page and the effective date.
For material changes, meaning any change to the categories of consumer health data we collect, the purposes we use it for, the categories of third parties who receive it, or your rights and how you exercise them, we will notify you before the change takes effect. Notice goes to the email address on your account and appears inside the app. We will not apply a material change retroactively to consumer health data we already collected, and where a change involves a new category or a new purpose, we will ask for fresh, unbundled, opt-in consent first rather than treating your continued use of PepSense as agreement.
13. How to reach us
Questions about this policy, requests to exercise any right in Section 7, and appeals under Section 8 all go to the same place. Email is the fastest route and reaches us directly.
We read every message sent to support@pepsense.ai. Formal requests are answered on the timelines in Section 8.
Contact us
PepSense, Inc.
Attn: Consumer Health Data Requests
914 N San Francisco St, Flagstaff, AZ 86001
support@pepsense.ai
226-887-5798
For requests, use the subject line "Consumer Health Data Request." For appeals, use "Consumer Health Data Appeal."
Washington residents may file a complaint with the Washington State Attorney General at www.atg.wa.gov/file-complaint. Nevada residents may contact the Nevada Office of the Attorney General, Bureau of Consumer Protection, at ag.nv.gov.
This policy covers consumer health data only. Our general Privacy Policy is at pepsense.ai/privacy and our Terms of Use, which govern disputes, are at pepsense.ai/terms. This policy lives at pepsense.ai/consumer-health-data-privacy and is linked separately from our homepage, as Washington law requires.