Privacy Policy
Effective date: August 16, 2026
Pepia is a private protocol-tracking and educational app for iPhone. This Privacy Policy explains what information Pepia collects, why we use it, when it is shared, how it is protected, and the choices available to you.
Pepia handles sensitive health-related information. We designed the service to collect what is needed to operate the features you choose, not to sell personal information or build advertising profiles.
Information we collect
Account and profile information
When you create an account, we may collect your email address, display name, authentication identifier, and sign-in information provided by the method you choose. If you use Sign in with Apple, Apple may provide a relay email address instead of your personal email address.
Your onboarding profile may include age or birth date, sex, height, starting and goal weight, unit preferences, time zone, goals, activity level, diet style, and the areas you choose to track.
Protocol and health-related information
Pepia stores information you enter to use its tracking features, including:
- protocols, compounds or medications, schedules, and cycle notes;
- planned and completed doses, dates, amounts, injection sites, notes, and status;
- vial and supply information, including strength, volume, storage details, and expiration dates;
- weight, body measurements, meals, hydration, activity, sleep, wellbeing, and other journal entries you choose to record;
- optional progress photos and their dates; and
- reminder preferences and notification settings.
Some records are saved on your device first so Pepia can work offline. When you are signed in and connected, supported records sync to Pepia's cloud service so they can be restored and used across your devices.
Chat and educational requests
If you use Ask Pepia, the messages you submit and relevant context from your active protocol or logged history are sent through Pepia's secure backend to OpenAI to generate an educational response. Do not enter information that is not needed for your question.
Pepia does not use Ask Pepia to diagnose, prescribe, or recommend a dose or titration. Chat responses may be incomplete or incorrect and are not a substitute for advice from a qualified healthcare professional.
Purchases
Subscriptions are purchased and managed through Apple's App Store. Pepia receives entitlement information needed to determine whether a subscription is active. We do not receive or store your full payment-card details.
Notifications and device access
If you allow notifications, Pepia schedules dose and supply reminders through Apple's notification services. If you choose a progress photo, Pepia accesses only the photo you select through the iOS photo picker. You can change these permissions in iOS Settings.
Product analytics and diagnostics
Pepia uses PostHog only if you explicitly enable the optional Share app diagnostics or Share diagnostics control. Until you opt in, PostHog is configured not to collect analytics, diagnostics, or screen replay. After you opt in and authenticate, Pepia identifies the analytics user only with the stable Supabase account UUID.
With your permission, Pepia sends a limited set of product events such as starting or completing onboarding steps, creating an account, viewing the paywall, starting checkout or a subscription, creating the first protocol, logging the first dose, and returning on day two. The only custom event details are the numeric onboarding step position and total number of steps. Pepia does not add email addresses, compound names, dose values, symptoms, measurements, photos, notes, journal entries, or Ask Pepia messages as custom properties on these events.
Your permission also enables PostHog session replay in screenshot mode. Session replay records what appears on screen and what you tap to help us diagnose problems. Text, images, and sandboxed views are not automatically masked, so a replay may include health entries, notes, chat content, or progress photos that are visible while recording. Pepia displays a persistent Replay indicator while recording is active. Automatic screen-view and app-lifecycle event capture remain disabled. PostHog may also process crash and diagnostic information needed to detect and fix app errors.
This permission is optional and is not required to use Pepia. You can withdraw it at any time in Profile → Data & privacy → Product diagnostics. Turning it off stops future PostHog analytics, diagnostics, and session replay collection.
Customer support
Pepia uses Crisp to provide in-app customer support. If you contact us through the support chat, Crisp processes the message and any contact information, phone number, or photo you choose to submit so we can respond. Please do not include peptide or medication names, dose details, symptoms, measurements, journal content, or other sensitive health information in a support conversation unless it is necessary for your request.
Website information
The Pepia website does not currently use advertising trackers or cross-site profiling. Like most websites, its hosting and network providers may process basic request information such as IP address, browser type, requested page, and timestamps to deliver and secure the site.
How we use information
We use personal information to:
- create and secure your account;
- save, sync, restore, and display the records you enter;
- calculate and show organizational estimates, trends, streaks, schedules, and remaining supply;
- schedule the reminders you request;
- verify subscription access;
- provide Ask Pepia and other educational features;
- understand completion of key product flows and diagnose app errors;
- respond to support, privacy, and account requests;
- protect Pepia from misuse, fraud, or security threats; and
- meet legal obligations and enforce our Terms of Use.
We do not sell or rent your personal information. We do not use your health-related information for third-party advertising, and we do not track you across apps or websites owned by other companies for advertising purposes.
When information is shared
We share information only as needed to provide Pepia, at your direction, or when legally required. Current service providers include:
- Supabase — account authentication, database hosting, secure file storage, synchronization, and backend functions. Supabase Privacy Policy
- Apple — Sign in with Apple, App Store subscriptions, device permissions, and notification delivery. Apple Privacy Policy
- Google — Google account authentication when you choose Sign in with Google. Google Privacy Policy
- RevenueCat — subscription entitlement and purchase-status management. RevenueCat Privacy Policy
- OpenAI — processing Ask Pepia messages and the app context sent with a request. OpenAI Privacy Policy
- PostHog — optional product analytics, unmasked session replay, crash reporting, and diagnostics after your explicit permission. PostHog Privacy Policy
- Crisp — in-app customer-support conversations and attachments you choose to submit. Crisp Privacy Policy
These providers process information under their own terms and our service arrangements. We may also disclose information if we reasonably believe disclosure is required by law, necessary to protect someone's safety, or needed to protect the rights and security of Pepia and its users.
If Pepia is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to appropriate confidentiality and notice requirements.
Storage, security, and retention
Pepia uses encrypted network connections, authentication controls, per-account database access rules, and private file-storage rules intended to prevent one user from accessing another user's synced records or photos. No service can guarantee absolute security, so please use a strong, unique password and protect access to your device and Apple account.
We generally retain account and synced app data while your account is active. Analytics, diagnostic, and support records are retained according to our configured provider settings and for only as long as reasonably needed to understand product use, resolve support requests, improve reliability, prevent abuse, or meet legal obligations. Information may remain for a limited period in security logs or provider backups until those systems complete their normal deletion cycle, or longer when retention is required by law or needed to resolve disputes.
Your choices and rights
You can review or change many profile, protocol, reminder, and tracking records directly in Pepia. You can deny or revoke photo and notification permissions in iOS Settings. You can enable or disable PostHog analytics, diagnostics, and session replay at any time in Profile → Data & privacy → Product diagnostics. You can sign out at any time.
You can permanently delete your Pepia account from Profile → Data & Privacy → Delete account. Account deletion removes your Pepia authentication account, synced records, and cloud progress photos and clears Pepia's local account data. Deleting your account does not automatically cancel an App Store subscription; subscriptions must be managed separately in your Apple account.
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal information, or to object to certain processing. To make a request, email support@pepia.co. We may need to verify your identity before completing a request.
International data transfers
Pepia and its providers may process information in countries other than the one where you live. Where required, we use legally recognized safeguards for international transfers. Local privacy laws may differ from those in your country.
Children's privacy
Pepia is not directed to children. You must be at least 18 years old, or the age of legal majority where you live, to create an account. We do not knowingly collect personal information from children. If you believe a child has provided information to Pepia, contact us so we can investigate and delete it.
Changes to this policy
We may update this Privacy Policy as Pepia changes. We will post the revised policy here, update the effective date, and provide additional notice in the app when a change is material.
Contact
For privacy questions, data requests, or complaints, contact support@pepia.co.
Pepia