Privacy Policy

PepLoop Privacy Policy

Operated by Zeno Productions. Effective June 2, 2026.

PepLoop ("PepLoop", "we", "us") is a peptide education and self-tracking app operated by Zeno Productions. This policy explains what we collect, how we use it, and the choices you have. PepLoop is informational only and is not medical advice.

Information we collect

  • Account information. Your email and name, provided when you sign in with Apple, Google, or email.
  • Onboarding answers. The goals, demographics (such as age and sex), lifestyle inputs (activity, sleep, stress), diet, experience, and health history flags you choose to provide so we can tailor suggestions.
  • Activity you log. Your dose logs, how you feel ratings, saved peptides, and cycles.
  • Scan photos. When you take a scan, the photo is used for analysis as described below.
  • Device and diagnostic data. Basic technical information, and a push notification token if you enable notifications.
  • Abuse prevention data. A non-reversible (hashed) form of your IP address and timestamps, used only to rate limit scans. We never store your raw IP address.

How scans and photos work

When you take a scan, your photo is sent to our analysis provider (Anthropic) to generate text based suggestions. The photo is processed to produce that text and is not retained on our servers after the analysis. The photo itself stays on your device, and only the text result is saved on your device so you can review it later. You can delete any scan from your timeline at any time.

We do not create, extract, or store facial recognition templates or other biometric identifiers from your photos, and we do not use them to identify you. The image is used only to generate the suggestions described above. Anthropic processes the image to return that text and does not use your data to train its models.

How we use your information

  • To generate peptide suggestions and personalize your experience.
  • To save your tracking history and show your progress over time.
  • To create and manage your account and your subscription.
  • To send notifications you have opted into (such as a daily check in).
  • To prevent abuse and protect the service.
  • To comply with legal obligations.

Legal basis for processing (EEA and UK)

Where the GDPR or UK GDPR applies, we rely on these legal bases: your consent for analyzing your photos and for processing the health related answers you choose to provide (you can withdraw consent at any time); performance of a contract to run your account and subscription; and our legitimate interests in keeping the service secure and preventing abuse. Your photos and health related information are treated as sensitive, and we process them only with your explicit consent.

How your information is shared

We do not sell your data, and we do not share identifiable information with advertisers. We use a small set of service providers that process data only to provide their part of the app:

  • Anthropic. Analyzes your scan photo to produce text suggestions.
  • Supabase. Authentication, database, and hosting for your account and tracking data.
  • RevenueCat. Manages subscriptions and purchase status.
  • Apple and Google. Sign in providers when you choose them.
  • Expo. Delivers push notifications if you enable them.

We may also disclose information if required by law, or to protect the rights, safety, and security of our users and the service.

Where your data lives and how it is protected

Account and tracking data are stored with Supabase (a managed Postgres database). Access is protected by row level security, so each account can reach only its own data, and data is encrypted in transit. Depending on your account, data may be processed in the United States or the European Union.

Some of our providers (such as Anthropic and Supabase) are based in the United States, so your data may be transferred and processed there. Where required for data originating in the EEA or UK, these transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

How long we keep it

We keep your account and tracking data for as long as your account is active. Abuse prevention records (the hashed IP and scan timestamps) are purged automatically on a short schedule. When you delete your account, the deletion is permanent and propagates to backups within 30 days.

Your privacy rights

Depending on where you live (including the EEA, the UK, and California), you have rights over your personal data. We honor these rights regardless of your location:

  • Access and portability. Request a copy of the personal data we hold about you.
  • Correction. Ask us to correct inaccurate information.
  • Deletion. Delete your account and data at any time from Settings; deletion runs on our servers and is permanent. You can also ask us to delete your data.
  • Withdraw consent. Withdraw consent to photo analysis or health data processing at any time, without affecting processing already carried out.
  • Object or restrict. Object to, or ask us to restrict, certain processing.
  • No sale or sharing. We do not sell or share your personal data, and we do not use sensitive information for anything other than providing the app.

You can manage or cancel your subscription in your App Store account settings, and turn notifications on or off in your device settings. To exercise any right, contact us at the email below. If you are in the EEA or UK and believe we have mishandled your data, you also have the right to lodge a complaint with your local data protection authority.

Children

PepLoop is intended for adults (18 and older). We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us and we will remove it.

Health disclaimer

PepLoop is informational and educational. The peptides, protocols, and matches it surfaces are not a diagnosis, a prescription, or a recommendation to take any substance. Always consult a licensed clinician before starting, stopping, or changing any therapy.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will surface them in the app. The effective date at the top reflects the latest version.

Contact

Zeno Productions
Email: support@zenoproductions.com

© 2026 Zeno Productions. PepLoop and the PepLoop mascots are part of the PepLoop app.