Peptalk Privacy Policy
How Peptalk handles information in the iOS app and backend gateway.
Effective Date
Effective date: August 28, 2026
Overview
Justin Nam operates Peptalk ("Peptalk," "we," "us," or "our"). Peptalk is a harm-reduction memory and research assistant for adults tracking peptide-related goals, dose logs, source evidence, and safety events.
Summary
- Peptalk can use Apple or Google account sign-in for account and payment management.
- Peptalk does not currently use advertising SDKs, tracking SDKs, HealthKit, location, contacts, camera, photos, or direct payment-card collection.
- Optional chat dictation uses the microphone and Apple Speech Recognition. Peptalk prefers on-device transcription when available and does not store the audio recording. Transcribed text stays in the chat draft until you send it.
- Peptalk stores durable app memory locally on your device in PeptalkMemory.json. Chat history is stored locally in PeptalkChatHistory.json.
- Cloud backup is off by default. It is a separate choice from AI/Data Consent and from your Apple subscription.
- If you turn on cloud backup in Settings while signed in, Peptalk stores a snapshot of that local journal and chat history for your Peptalk account so you can restore it after sign-in on another device.
- When you use chat or guided research features, Peptalk sends your message and relevant Peptalk memory to the Peptalk backend so the app can generate a response, use evidence search, and assemble memory updates.
- The Peptalk backend uses third-party services, including AWS infrastructure and DeepInfra. If you turn on cloud backup, the snapshot is stored in Supabase via that gateway.
- Peptalk is not emergency care, medical care, diagnosis, treatment, prescribing, or a dose-selection calculator.
Information You Provide
- Chat messages and free-form notes, including text produced by optional chat dictation.
- Peptide interests, goals, cycle context, schedules, dose logs, routes, timing, side-effect notes, source evidence, vendor or COA questions, and safety events.
- Guided research answers such as goals, current medications, health conditions, weight context, GLP-1/GIP history, injury context, source status, or other peptide-relevant context.
- Account information returned by Apple or Google sign-in, such as provider user ID, email address, display name, provider email verification status, and Peptalk session token metadata.
- Support information if you contact us directly, such as your email address and the content of your request.
On-Device Storage
Peptalk stores durable memory locally on your device for peptide interests, goals, dose logs, schedules, source evidence, and safety events, and stores chat history locally so conversations can be restored when you reopen the app. The current app does not use HealthKit, iCloud, or CloudKit for this memory. Removing local memory can be done by using Memory Wipe in Peptalk settings, deleting supported saved items when the app flow supports it, or uninstalling the app.
Cloud Backup
- Cloud backup is off unless you turn it on in Settings.
- Turning it on requires a signed-in Peptalk Apple or Google account. It is separate from AI/Data Consent and from App Store subscription status.
- When it is on, Peptalk uploads a snapshot of local journal memory (profile, peptides, goals, dose logs, schedules, source evidence, safety events) and capped chat history through the Peptalk AWS gateway, which stores that snapshot in Supabase Postgres for your account id.
- Local files remain the working copy. Cloud backup is for restore after sign-in on another phone, not live multi-device sync.
- You can turn the toggle off to stop new uploads. Memory Wipe can delete the stored snapshot for that account. Sign-out stops uploads and does not erase local memory.
- Snapshots are sent over TLS and stored with Supabase at-rest encryption. This is not a HIPAA-covered service.
Backend and Third-Party Processing
- When you use chat or guided research features, Peptalk transmits your message and relevant local memory to the Peptalk backend.
- The backend uses this information to generate responses, retrieve evidence, assemble validated memory updates, and apply rate limiting, abuse prevention, reliability, and security controls.
- Peptalk currently uses AWS services including CloudFront, AWS WAF, Lambda, CloudWatch, and S3; DeepInfra for language-model responses; Apple services for Sign in with Apple, App Store distribution, TestFlight, optional chat dictation via Speech Recognition, and Apple-controlled diagnostics or analytics where applicable; Google Sign-In for Google account authentication; and Supabase Postgres only when you opt in to cloud backup.
- For chat and guided research, Peptalk does not persist full chat messages or app memory on the Peptalk backend after servicing a request. Operational logs may be created by infrastructure providers. The current AWS backend documentation sets CloudWatch log retention to 14 days. If you opt in to cloud backup, a snapshot of journal and chat history is stored in Supabase until you turn backup off and delete it, use Memory Wipe while backup is on, or request deletion. Third-party providers may process and retain data according to their own terms, privacy policies, and data processing agreements.
How We Use Information
- App functionality, including chat, memory, guided research, source evidence, safety-event tracking, and local context.
- Product personalization, such as tailoring responses to user goals, active compounds, saved context, and prior safety events.
- Account and payment management, including signing into a Peptalk account and linking future billing or purchase-management flows to that account.
- Security and reliability, including rate limiting, abuse prevention, debugging, and service monitoring.
- User support, if you contact us.
- Legal compliance and enforcement of our terms.
Sensitive Health Information
Peptalk may process user-provided health or medical information because users can enter medications, symptoms, dose logs, routes, conditions, reactions, and other health-related context. Peptalk is not a healthcare provider, health plan, pharmacy, drug manufacturer, or emergency service. Unless Justin Nam separately enters a covered relationship that says otherwise, Peptalk is not intended to operate as a HIPAA-covered entity or business associate.
AI Processing Consent
- Before Peptalk sends chat, guided research, or memory context to the backend and third-party AI providers, the app requires explicit AI/Data Consent. The consent screen names DeepInfra, explains what is sent, and requires an affirmative action before chat or guided research can continue.
- Cloud backup is a separate Settings choice. Accepting AI/Data Consent does not turn on cloud backup.
Disclosure of Information
- To service providers that help operate Peptalk, including AWS, DeepInfra, Apple, Google, and — if you opt in to cloud backup — Supabase.
- When you direct us to process information through the app.
- To comply with law, legal process, or enforceable government requests.
- To protect rights, safety, security, and service integrity.
- In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate protections.
Retention and Deletion
Local Peptalk memory remains on your device until you delete it, wipe memory through Peptalk, or uninstall the app. If you opt in to cloud backup, the stored snapshot remains until you delete it with Memory Wipe while backup is on, or until we process a deletion request. The Peptalk backend is designed to process chat and memory context for inference transiently for each request. Account session tokens and provider account identifiers may be retained as needed for account, payment, security, and support records. AWS operational logs are currently configured for 14-day retention in the production backend documentation. Support emails may be retained as long as reasonably needed for support, legal, security, or business records. To request deletion of information you have sent to us outside the local app, contact namjustin148@gmail.com.
Your Choices
- You can refuse microphone and speech-recognition permission. Chat still works by typing.
- You can avoid sending data to the backend by not using chat or guided research features.
- You can ask Peptalk to wipe saved app memory or use Memory Wipe in Peptalk settings.
- You can turn cloud backup off in Settings. Memory Wipe can delete the stored snapshot when backup is on.
- You can sign out of the account section in Peptalk settings.
- You can uninstall the app to remove local app data from your device.
- You can contact namjustin148@gmail.com for privacy requests.
- You can review privacy choices at https://d2774w1jqc988b.cloudfront.net/privacy-choices.
Children
Peptalk is for adults. It is not intended for children or minors. Do not use Peptalk if you are under 18.
Security
We use reasonable technical and organizational measures intended to protect information. No system is perfectly secure. Peptalk users should not submit emergency information or information they are unwilling to have processed by the backend and third-party providers.
International Processing
Peptalk and its providers may process information in the United States and other countries where they operate. By using Peptalk, you understand that information may be processed outside your location.
Changes
We may update this policy. The effective date above will change when we publish updates. Material changes should be reflected in the App Store listing and in-app privacy disclosures.
Contact
Justin Nam 423 N Donahue Drive, Auburn, AL 36832 namjustin148@gmail.com https://d2774w1jqc988b.cloudfront.net/privacy