Legal

Privacy Policy

Effective: 9 June 2025 Last updated: 9 June 2025 Controller: General Office Sp. z o.o.
Back to home

1. Introduction

Welcome to Peptino ("App", "Service"). Peptino is a research-tracking and personal organisation tool that helps users log and monitor their own compound protocols, inventory, and progress metrics. It is not a medical device and does not provide medical advice.

This Privacy Policy explains how GENERAL OFFICE SP. Z O.O. ("we", "us", "our", "Company"), a company incorporated under Polish law (KRS registered; NIP: 5252873150, REGON: 389731305), with its registered office at Plac Bankowy 2, 00-095 Warszawa, Poland, collects, uses, stores, and protects your personal data when you use Peptino.

By installing or using the App you acknowledge that you have read and understood this Policy. If you do not agree, please discontinue use and delete the App.

2. Data Controller

FieldDetails
ControllerGENERAL OFFICE SP. Z O.O.
Registered addressPlac Bankowy 2, 00-095 Warszawa, Poland
NIP5252873150
REGON389731305
Contact e-mailcontact@peptino.app

For all privacy-related requests, write to contact@peptino.app with the subject line "Privacy Request".

3. Data We Collect

3.1 Data you provide directly

CategoryExamplesWhere stored
Account dataE-mail address, name (optional)Supabase (cloud) + device
Protocol & dose dataCompound names, dose amounts, schedules, dose logsDevice (primary); Supabase (sync, if enabled)
Inventory dataVial details, amounts, expiry datesDevice (primary); Supabase (sync, if enabled)
Progress metricsBody weight, body-fat percentage, personal goalsDevice (primary); Supabase (sync, if enabled)
Profile preferencesUnits of measure, language, app themeDevice (primary); Supabase (sync, if enabled)

3.2 Data collected automatically

CategoryExamplesPurpose
Analytics eventsScreen views, feature interactions (no PII)Product improvement
Crash & diagnostic dataError messages, device OS versionStability monitoring
Purchase dataSubscription status, transaction identifiersEntitlement management
Device identifiersAnonymous device IDAnalytics, fraud prevention

We do not collect precise location data, contacts, photos, or any camera/microphone data.

4. Special Category Data

Dose logs, weight, and body-composition records may constitute health-related data within the meaning of Article 9 GDPR. We process such data on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you grant by accepting this Policy and actively entering the data. You may withdraw consent at any time by deleting your data (see §9).

5. Legal Bases for Processing

PurposeLegal basis (GDPR Art. 6)
Providing the App and its core featuresArt. 6(1)(b) — performance of a contract
Cloud sync and backupArt. 6(1)(a) — consent
Analytics and product improvementArt. 6(1)(f) — legitimate interests
Subscription and payment managementArt. 6(1)(b) — performance of a contract
Legal obligations (e.g. accounting)Art. 6(1)(c) — legal obligation
Security monitoring and fraud preventionArt. 6(1)(f) — legitimate interests

6. How We Use Your Data

We do not sell, rent, or share your personal data with third parties for marketing purposes.

7. Third-Party Services

ServiceProviderPurposeData sent
SupabaseSupabase Inc. (USA)Authentication, cloud database syncAccount data, synced protocol/inventory/progress data
RevenueCatRevenueCat Inc. (USA)Subscription managementPurchase receipts, anonymous app user ID
PostHogPostHog Inc. (USA / EU cloud)Product analyticsAnonymous usage events, device OS
Apple / GoogleApple Inc. / Google LLCApp distribution, in-app paymentsAs per platform policies

All data transfers to processors outside the EEA are governed by Standard Contractual Clauses (SCCs) or an equivalent adequacy mechanism.

8. Data Storage and Security

Despite these measures, no system is perfectly secure. We recommend using a strong, unique password for your account.

9. Data Retention

Data typeRetention period
Account & synced dataUntil you delete your account
Local device dataUntil you uninstall the App or use "Delete all data"
Analytics events24 months (anonymised; no individual deletion possible)
Support correspondence3 years from last contact
Accounting/transaction records5 years (legal obligation under Polish law)

10. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights:

To exercise any right, e-mail contact@peptino.app with the subject "GDPR Request — [Right]". We will respond within 30 calendar days.

11. Children's Privacy

Peptino is intended for adults only. We do not knowingly collect data from individuals under the age of 18. If you believe a minor has provided personal data, please contact us immediately and we will delete it.

12. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified via an in-app notice or e-mail at least 14 days before taking effect. Continued use of the App after the effective date constitutes acceptance of the revised Policy.

13. Contact

GENERAL OFFICE SP. Z O.O.
Plac Bankowy 2, 00-095 Warszawa, Poland
E-mail: contact@peptino.app

This document was prepared in accordance with Regulation (EU) 2016/679 (GDPR) and the Polish Act on Personal Data Protection of 10 May 2018.