Privacy Policy
Who we are
This Privacy Policy explains how BITBILLION TECHNOLOGIES (OPC) PRIVATE LIMITED ("Peptimize", "we", "us" or "our") handles information when you use the Peptimize mobile application, visit peptimize.xyz, or contact us.
Registered office: HD-023, WeWork Cinnabar Hills, Embassy Golf Links Business Park, Challaghatta, Bengaluru, Karnataka 560071.
For privacy questions or requests, contact us at support@peptimize.xyz.
Scope
This Policy applies to the Peptimize iOS and Android applications, the Peptimize website, and support communications. It does not apply to third-party websites, research papers, regulatory resources, or services that may be linked from Peptimize.
Which version you have
This Policy covers both versions of the app that are in use. The difference between them is narrow but real, so it is set out here rather than left for you to infer.
- Version 1.x makes no automatic network requests at all. Nothing described under App analytics or Subscriptions applies to it, and it has no Apple Health or Health Connect features.
- Version 2.0 and later adds three things: optional read-only access to Apple Health or Health Connect, limited product analytics, and an optional paid subscription. Each has its own section below.
What did not change. Personal health and tracking records remain local and are not uploaded to a Peptimize account or cloud-sync service. There is still no account and no login in either version. You can check which version you have in Profile, at the bottom of the screen.
What data Peptimize stores on your device
Peptimize is a local-first app. It does not require a user account, does not use Peptimize cloud synchronisation, and does not send your entries or any other information you record to us. Personal tracking records you enter in the app remain stored locally on your device and are not transmitted to a Peptimize account or Peptimize-operated cloud database. Version 1.x goes further and makes no automatic network requests at all; version 2.0 makes the two narrow exceptions described in What data leaves your device, neither of which receives anything you record.
Separately, if you choose to tap an external link - for example a source cited in the Research Library - that opens the page in your browser, which is subject to your device's own internet connection and that website's own practices.
Local app records may include:
- medication or substance names, dose amount, date, time, route, schedule, notes and adherence status;
- injection body-site records and rotation history;
- weight and progress entries;
- symptom, side-effect, appetite and food-noise entries;
- protein, water and other nutrition-tracking entries;
- medication inventory and remaining-dose information;
- in version 2.0 and later: supplements, body measurements, height and BMI, and any records imported from Apple Health or Health Connect; and
- local reminder settings, app preferences and other information you choose to record.
Peptimize does not request GPS or device-location permission. References to an "injection site" mean a location on the body, not a geographic location.
Apple Health and Health Connect
Version 2.0 and later can read health records you have already recorded elsewhere, so you do not have to enter the same numbers twice. This is entirely optional. Every feature in the app works without it, you are never asked for it during setup, and you can turn it off at any time in your device's Health settings or in Profile.
- What can be read. Weight, body fat, lean body mass, waist measurement and height; steps, distance, active energy, exercise minutes and sleep duration; and nutrition entries including protein, water, calories, carbohydrates, fat and fibre. You choose which of these to allow, one at a time, in your device's own permission screen.
- Reading only. Peptimize does not write anything back to Apple Health or Health Connect and does not request permission to. It cannot change or delete records held there.
- Where it goes. Imported records are stored in the same local database as the entries you type in, and are treated identically: shown in your history, counted in your totals and used for the on-device charts and analysis. They are not transmitted to us and are not sent to any third party.
- Not used for advertising, and never sold. Health data is not used for advertising, is not shared with advertisers or data brokers, and is not sold. It is not sent to a Peptimize account or cloud-sync service, because there is none.
Deleting Peptimize data, or the app itself, does not delete anything from Apple Health or Health Connect. Those records belong to the platform and are managed there.
What data leaves your device
In version 1.x, none of it. That version includes no analytics, no cloud sync, no crash reporting and no account features, and it makes no automatic network requests.
In version 2.0 and later: exactly two services receive anything, and neither receives health or tracking data of any kind:
- Firebase / Google Analytics receives limited product-usage information - see App analytics.
- RevenueCat receives subscription status if you buy a subscription - see Subscriptions.
There is still no crash-reporting service, no advertising or attribution service, no cloud sync and no account service in any version. If one is ever added, this Policy will be updated before it is enabled.
Separately from the app, we may receive limited information outside the local app database:
- Support communications. If you contact us, we may receive information you voluntarily provide, such as your name, email address, message, app version, device model, screenshots or diagnostic details. Please remove or obscure health information that is not necessary for the support request.
- Website technical information. When you visit peptimize.xyz, our hosting, content-delivery, security or domain providers may automatically process limited technical information such as IP address, browser type, device type, requested pages, timestamps and security logs. This is used to deliver and protect the website, diagnose faults and prevent abuse.
- Website analytics. The website uses Google Analytics to measure which pages are useful, subject to your choice. This is described in full in Website analytics and cookies below. It involves no advertising cookies and no cross-site behavioural tracking.
App analytics
Version 2.0 and later sends limited product-usage analytics through Firebase (Google Analytics) so we can see which parts of the app people actually use and where they get stuck. Version 1.x does not.
No health value, medication name, dose, weight, symptom, appetite score, measurement or note is ever included. This is not only a policy commitment. The app carries a fixed list of the events it may send and, for each one, a fixed list of the values each field may take. Anything outside those lists is discarded before anything is sent, so a health value cannot be included by mistake.
- What is recorded. Which screens are opened, which features are used, how far setup got, whether a purchase or restore succeeded or failed and for what broad reason, and app-level events such as first open, session start, updating and uninstalling.
- What is recorded about your settings. Your interface language, light or dark theme, whether reminders are switched on, whether a health integration is connected, and whether you have a Pro subscription. Which health metrics you connected is not recorded, and nor is anything read from them.
- What is deliberately not recorded. The medications or supplements you track, the number of them, any value you log, and which event prompted the app to ask you for a review - because that would in itself describe your progress.
- Identifiers. Firebase assigns a random identifier to each installation. It is not linked to your name, email or any account, because the app has none. No advertising identifier is collected, on either platform - the ability to read one is left out of the app entirely.
Your choice. App analytics can be switched off in Profile. Doing so stops both our own events and Firebase's automatic ones, takes effect immediately, and costs you no functionality.
Subscriptions
Version 2.0 and later offers an optional paid subscription, Peptimize Pro. Purchases are made through the App Store or Google Play; we never see or handle your payment details, which are held by Apple or Google under their own privacy policies.
We use RevenueCat to check whether a subscription is active. RevenueCat receives your purchase and subscription status and a random identifier for your installation, so the app can tell whether to unlock the paid features and so a purchase can be restored if you change or reset your device.
- No health or tracking data is sent to RevenueCat, and the app is built so that none can be: the optional fields it offers for attaching customer information are not used at all.
- No account, and nothing to link to. The identifier is generated on the device and is not connected to an email address, a name, or anything you have entered.
- Not used for advertising. Subscription data is not used for advertising and is not sold.
Deleting your local data does not cancel a subscription and does not remove your purchase history from Apple, Google or RevenueCat - a subscription is cancelled through your App Store or Google Play account. This is deliberate: it is what allows a subscription you have paid for to still be recognised afterwards.
Website analytics and cookies
peptimize.xyz uses Google Analytics 4 to understand which pages people find useful - for example how many people read a particular molecule reference, or go on to open the App Store listing. This section applies to the website only; the app is covered by App analytics above, and neither one ever receives what you record in the app.
- What is recorded. Pages viewed, the referring page, approximate location derived from your IP address at country and city level rather than precisely, device and browser type, and a small set of deliberate interactions - opening the App Store link, opening the QR code, or following a citation out to an external source.
- Cookies. Google Analytics sets first-party cookies, with names beginning “_ga”, so a returning browser can be recognised. They are not advertising cookies and are not read by other websites.
- No advertising. Advertising storage, ad personalisation and Google Signals are switched off. We do not run ads, do not build advertising profiles, and do not use this data for cross-site behavioural tracking.
- No health data. Nothing you enter in the app reaches analytics. The page addresses recorded here identify public reference content, not you.
Your choice. If you are in the European Economic Area, the United Kingdom or Switzerland, analytics stays off until you accept it in the banner shown on your first visit, and declining costs you nothing on the site. Elsewhere analytics is on by default and you can switch it off at any time through the Cookie Preferences link in the footer of every page. We also honour the Global Privacy Control signal: if your browser sends one, analytics stays off without you doing anything.
Google acts as our processor for this data and may process it outside your country, including in the United States. See Google’s Privacy Policy and Google’s browser opt-out add-on.
How your data is used
Your on-device data is used to provide the features you request, such as recording entries, showing history, and generating reminders. Information we receive outside the local app database is used only as reasonably necessary to:
- respond to support, privacy and legal enquiries;
- investigate bugs and maintain the reliability and security of Peptimize;
- operate, secure and improve the website and app;
- understand which features are used, so we can decide what to build and what to fix;
- determine whether a subscription is active, and restore a purchase you have already made;
- prevent fraud, abuse or unlawful use; and
- comply with applicable law, lawful requests and legal obligations.
Peptimize does not sell health or treatment-entry data and does not share it with advertisers. If you use Share Logging Report, the app generates a PDF of your records on your device; that report is created and shared only when you choose, using your device's own share options, and is not sent to Peptimize. Any copy you save or send then sits outside the app and is no longer governed by the app's local-only design.
Legal bases for processing
If you are in the European Economic Area, the United Kingdom or Switzerland, data protection law requires us to have a lawful basis for each thing we do with personal data, and to tell you what it is. This section does that. It applies only to the narrow set of information we actually receive - the table below has no row for your health and tracking records, and that omission is the point.
Your health and tracking records have no legal basis listed because we never receive them. They are created and stored on your device and are not transmitted to us. We are not a controller of them, we cannot read them, and the special-category conditions that would otherwise apply to health data under Article 9 never arise. Nothing in this section changes that.
- App analytics (Firebase) - legitimate interests. Understanding which features are used and where people get stuck, so we know what to build and what to fix. No health or tracking data is included, nothing is linked to an identity, and you can switch it off in Profile at any time.
- Subscription status (RevenueCat, Apple, Google) - performance of a contract. Unlocking the paid features you bought, and restoring that purchase if you change or reset your device. It is what delivers the subscription you paid for.
- Support communications - legitimate interests, and performance of a contract where your message concerns a subscription. Answering the question you asked us.
- Website technical and security logs - legitimate interests. Delivering the site, keeping it available, and preventing abuse.
- Website analytics - consent in the EEA, the UK and Switzerland, where nothing is set until you accept it in the banner; legitimate interests elsewhere, with an opt-out through Cookie Preferences in the footer of every page.
- Records kept to meet a legal duty - legal obligation. Tax and accounting records, and responding to lawful requests where we are obliged to.
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and have kept the processing to what is needed for it: no health data, no advertising, no profiling, no data brokers, and an opt-out you control. You may object to processing based on legitimate interests at any time - see Your choices and rights. Where we rely on consent, you may withdraw it at any time, and doing so does not affect anything done before you withdrew it.
Sharing and service providers
We do not sell personal information. In version 2.0 and later, two service providers receive information from the app itself: Google, for the product analytics described above, and RevenueCat, for subscription status. Neither receives health or tracking data. We may also share limited information received through the website or support channels with service providers that help us operate hosting, email, security, customer support or legal/compliance functions. These providers are expected to process information only for the relevant service and under appropriate confidentiality and data-protection obligations. We may also disclose information when required by law, to respond to valid legal process, to protect rights or safety, or in connection with a genuine corporate transaction.
International processing
Some website, email, analytics, subscription or support service providers may process information in countries other than your own, including in the United States. Where required, we use reasonable safeguards for international transfers. The app's personal tracking database is not transferred anywhere: it stays on your device, and no version of Peptimize uploads it to us. Depending on your location, you may have rights under frameworks such as GDPR, UK GDPR, CCPA/CPRA, or India's DPDP framework for any information we do hold through support or website interactions.
Retention
Local app records remain on your device until you delete individual records, use the in-app delete-all function, or remove the app, subject to device-level backup or transfer behaviour described below.
Support communications are generally retained for up to 24 months after the last interaction, unless a shorter period is appropriate or a longer period is required for security, dispute-resolution, or legal purposes. Website security logs are retained for the period reasonably necessary for security and operations, according to the relevant provider's configuration.
App analytics are retained by Google for the period set on our Google Analytics property, after which the event-level records expire. Subscription records are retained by RevenueCat for as long as needed to recognise and restore a purchase, and by Apple or Google under their own policies. Neither set contains health or tracking data.
Device backups and transfers
Your device's operating system, backup settings, migration tools or third-party backup services may create copies of app data outside the active installation. Peptimize does not control platform-level backups or transfers.
The database holding your health and tracking records is deliberately excluded from iCloud backup on iOS and from Android's cloud backup, so those records are not copied to either company's servers. One consequence is worth knowing before you need it: because they are not in the cloud backup, setting up a new device from one will not restore them. If you want to keep a copy, use Share Logging Report to export a PDF first.
Your choices and rights
- You may review and manage your entries directly in the app.
- You may delete local app data through the in-app deletion controls.
- In version 2.0 and later, you may switch app analytics off in Profile at any time.
- In version 2.0 and later, you may decline or withdraw Apple Health and Health Connect access at any time, in your device settings. The app keeps working without it.
- You may generate a PDF of your records with Share Logging Report and save or send it yourself.
- Depending on your location and applicable law, you may have rights relating to information we hold through support or website interactions, including access, correction, deletion, withdrawal of consent, objection, restriction, portability or complaint to a regulator.
To make a request, email support@peptimize.xyz. We may need to verify your identity. Because Peptimize never receives the local app database, we are unable to access, retrieve or delete records that exist only on your device - the in-app deletion controls are the only thing that can reach them.
Security
We use reasonable measures appropriate to the app's architecture, including protections provided by the operating system such as application sandboxing and device access controls. No method of storage or transmission is completely secure. You are responsible for protecting your device with a strong passcode, keeping the operating system updated, and controlling access to device backups and screenshots.
Children
Peptimize is intended for adults aged 18 years or older. It is not directed to children, and we do not knowingly invite children to provide personal information. If you believe a child has sent us personal information, contact us so we can take appropriate action.
Third-party links and sources
The Research Library and other parts of Peptimize may link to third-party sources. Their privacy practices are governed by their own policies. We are not responsible for third-party privacy, security, availability or content.
Changes
We may update this Privacy Policy as the app changes. The version date at the top of this page will reflect the latest revision.
Contact and complaints
Privacy Contact / Grievance Officer, BITBILLION TECHNOLOGIES (OPC) PRIVATE LIMITED
Email: support@peptimize.xyz
Postal address: HD-023, WeWork Cinnabar Hills, Embassy Golf Links Business Park, Challaghatta, Bengaluru, Karnataka 560071
You may also complain to the competent data-protection authority in your jurisdiction where applicable.