Security
Architecture
Peptimize is local-first. The app does not make network requests to transmit your entries, and there is no Peptimize account or Peptimize cloud synchronisation, so there is no server-side copy of your records to expose or breach. That is the security property this architecture exists to provide: a database that is never uploaded cannot be leaked from a server we do not have.
Version 1.x makes no automatic network requests at all. Version 2.0 adds two, for product analytics and for checking whether a subscription is active. Neither receives health or tracking data, and the app is built so that neither can - the Privacy Policy describes the mechanism.
The database holding your health and tracking records is also excluded from iCloud and Android cloud backup, so it is not copied to a third party's servers that way either.
Safeguards
Peptimize relies on security controls provided by iOS, Android and the user's device, which may include application sandboxing, file-protection classes, device passcodes, biometric access, operating-system encryption and permission controls. We use reasonable safeguards appropriate to the app's architecture. However, no method of storage or transmission is perfectly secure.
Data minimisation
Peptimize requests only permissions necessary for enabled features. It does not require GPS/device location, contacts, microphone, Bluetooth or advertising tracking. Notifications are requested only when you enable reminders. In version 2.0 and later, access to Apple Health or Health Connect is optional, read-only, and requested only if you choose to connect it.
No advertising or behavioural tracking
Peptimize does not contain advertising SDKs, cross-app tracking or behavioural profiling, and collects no advertising identifier on either platform. It contains no crash-reporting or remote-logging service. The product analytics added in version 2.0 are disclosed in full in the Privacy Policy and can be switched off in the app. Any further SDK that transmits information will be identified, assessed and disclosed there before release.
Device security
Device-level security settings, backups, operating-system protections, passcodes, and physical device access all affect the security of your information. You can reduce risk by:
- using a strong device passcode and biometric lock;
- keeping the device operating system and Peptimize updated;
- not sharing an unlocked device with others;
- reviewing device backup, screenshot and photo-sync settings;
- removing sensitive information from support screenshots; and
- using the in-app delete-all function before disposing of or transferring a device.
Report an issue
No app or device is completely secure, and Peptimize cannot guarantee absolute security or recover local records after device loss, deletion or corruption. If you believe you have discovered a security issue, email support@peptimize.xyz with the subject "Security Report" and avoid including unnecessary health information. We aim to acknowledge genuine reports within five business days, but this is a target rather than a guarantee.