PepTrak is a research protocol tracking application operated by PepTrak LLC, a California limited liability company ("we," "us," or "our"). Our principal address is in San Diego, California.
PepTrak is designed exclusively as a research use only (RUO) tool. It assists researchers and licensed professionals in tracking, logging, and organizing information about peptide compounds for research and scientific reference purposes only. Nothing in this application constitutes medical advice, and no compounds or protocols referenced within it are intended for human use.
We collect the following categories of information when you use PepTrak:
- Account Information: Name and email address provided during registration or checkout.
- Research Intake Data: Information entered during the protocol questionnaire, including research goals, biometric parameters (height, weight, age range), activity patterns, sleep quality, and prior research experience. This data is used solely to generate a personalized research protocol.
- Research Tracking Logs: Dose tracking entries, adherence records, side effect observations, and research notes you log within the app. This data is stored locally on your device and may be transmitted to our servers if you enable sync features.
- Payment Information: Billing name, email, and payment method details processed via Stripe. We do not store full card numbers — all payment processing is handled by Stripe, Inc.
- Device & Usage Data: Browser type, device type, operating system, IP address, pages visited, and feature usage patterns. Collected to improve app performance and user experience.
- Communications: Any messages you send to our support team or through in-app feedback channels.
Local Storage: The majority of your research tracking data (protocols, dose logs, tracker history) is stored locally in your browser's localStorage and does not leave your device unless you explicitly use a sync or export feature.
We use your information for the following purposes:
- Protocol Generation: Your research intake data is transmitted to our AI research system to generate a personalized research compound protocol. This data is processed in real time and not retained by the AI system beyond the duration of the request.
- Research Advisor (Alex): Tracker summaries and protocol context may be sent to our research advisor system to provide contextually relevant research guidance. This data is processed per-session and is not used for AI training.
- Subscription Management: Billing and account data is used to manage your subscription, process payments, and communicate about your account.
- Service Improvement: Aggregated, anonymized usage data is used to improve app features, fix bugs, and optimize the research experience.
- Legal Compliance: We may use or disclose data as required by applicable law, regulation, legal process, or governmental request.
We do not sell your personal data. We do not share your research intake data, tracking logs, or personal information with third-party advertisers or data brokers. Your research data is yours.
Research tracking data is stored primarily in your browser's local storage. Where server-side storage is used (account data, subscription records), data is stored on secured infrastructure provided by Cloudways and protected by industry-standard encryption (TLS in transit, AES-256 at rest).
We implement reasonable administrative, technical, and physical security measures to protect your data. However, no system is completely secure. We encourage you to use a strong, unique password and to contact us immediately if you suspect unauthorized access to your account.
We retain your account data for as long as your account is active. Research tracking data stored locally persists until you clear your browser data or use the "Reset All Data" function within the app. Upon account deletion request, we will delete your server-side data within 30 days.
PepTrak uses the following third-party services. Each has its own privacy policy governing how they handle data:
- Anthropic (Claude API): Our AI research protocol generation and advisor features are powered by Anthropic's Claude API. Research intake data and session context is transmitted to Anthropic to generate responses. Anthropic does not use API data to train its models. See anthropic.com/privacy.
- Stripe, Inc.: All payment processing is handled by Stripe. We do not store payment card details. See stripe.com/privacy.
- Vercel: The PepTrak application is hosted on Vercel's infrastructure. See vercel.com/legal/privacy-policy.
- Cloudways: Backend infrastructure and database hosting. See cloudways.com/privacy.
When you interact with the Alex research advisor or protocol generation features, your research context (goals, tracking data, protocol information) is transmitted to Anthropic's API to generate responses. This data is used solely for generating your response and is not retained or used for model training per Anthropic's API terms.
You have the following rights with respect to your personal data:
- Access: You may request a copy of the personal data we hold about you.
- Correction: You may request correction of inaccurate or incomplete data.
- Deletion: You may request deletion of your account and associated server-side data. Local data can be cleared at any time using the "Reset All Data" option in your Account settings.
- Data Portability: You may request your data in a portable format.
- Opt-Out: You may opt out of non-essential communications at any time by contacting us or using unsubscribe links in emails.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
PepTrak is a research platform intended for use by adults aged 18 and older. We do not knowingly collect personal information from individuals under the age of 18. If you are under 18, you may not use PepTrak.
If we become aware that we have collected personal data from a minor, we will take prompt steps to delete that information. If you believe we have inadvertently collected data from a minor, please contact us at [email protected].
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request information about the categories and specific pieces of personal data we collect, use, disclose, and sell.
- Right to Delete: You may request deletion of your personal data, subject to certain exceptions.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- Right to Opt-Out of Sale: We do not sell personal information. You therefore do not need to opt out of any sale of your data.
To submit a CCPA request, email [email protected] with the subject line "CCPA Request." We will respond within 45 days.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Effective" date at the top of this page and, where appropriate, notify you via email or an in-app notice.
Your continued use of PepTrak after any changes constitutes acceptance of the updated Privacy Policy. We encourage you to review this page periodically.
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
We respond to all privacy requests within 30 days.
