Consumer health data policy
Version 2026-09-01 · effective 1 September 2026
What health data PepStepper collects, why, who it goes to, and how to get rid of it. This is a standalone document because Washington’s My Health My Data Act requires one, and because burying it inside a general privacy policy would defeat the point.
What counts as health data here
Anything you enter that describes what you are taking or how your body is changing. Concretely:
- Compounds on your stack, and the vials you have reconstituted
- Doses you log: amount, time, injection site, and any note
- Schedules and titration plans you build
- Measurements — weight, body fat, circumferences
- Progress photographs, if you upload any
Why we collect it
To do the arithmetic you asked for and show it back to you. Concentration, the marks to draw, doses remaining, when a vial empties, when its beyond-use date arrives, and reminders if you turn them on.
That is the entire purpose. It is not used to build a profile of you, it is not analysed in aggregate to sell anybody insights, and it is not used to train anything.
What we do not do
These are commitments, not aspirations:
- We do not sell health data. Not to anyone, at any price, in any form.
- We do not share it with advertisers, data brokers, or analytics companies.
- No page that displays your compounds, doses, measurements or photos loads any analytics or advertising script. The application is a separate deployment that does not contain them.
- We do not use it to target advertising to you anywhere.
Who it reaches, and why
Three processors, each for one job, and none of them for advertising:
- Supabase — the database, authentication and file storage. Your data lives here, protected by row-level security so a query can only return your own rows.
- Vercel — runs the application. It processes requests; it does not hold your data.
- Resend — sends email, and only if you have reminders switched on. By default those emails do not name a compound.
- Stripe — payments. Stripe never receives health data; it receives an email address, an amount and a card, and PepStepper never sees the card.
Notifications and what they say
A reminder says “you have a dose due” by default. It does not name the compound, because a lock screen is visible to whoever is nearby and an email is visible to your mail provider.
You can turn compound names on in settings if you would rather have them. That is a deliberate choice you make, not the default.
Photographs
Progress photos are stored in a private bucket that only your own account can read. There is no public URL for them.
When the app shows you one it creates a signed link that expires after sixty seconds. A link copied out of the page, pasted into a chat, or left in a browser history is dead within the minute.
Your rights
You can see everything we hold — it is the app. You can export your log at any time, subscribed or not.
You can delete your account from settings. That removes your rows, your stored photographs and your account itself. The deletion refuses to run at all if it cannot also remove the files, so it cannot half-succeed and leave photographs behind.
The one exception is financial records. Credit-ledger entries and referral records survive a deletion because a payment dispute can arrive weeks afterwards and we have to be able to answer it. Referral records are anonymised — the link to your account is removed.
To exercise any of this by email rather than in the app, write to privacy@pepstepper.com.
Where data is held
On infrastructure in the United States. If you are outside the US, using PepStepper means your data is processed there.
Consent
You are asked to agree to this document before entering any health data, and the version you agreed to is recorded with the date. If this document changes materially you will be asked again — an old consent is not carried forward to a new policy.
Questions about this document, or a request about your own data: privacy@pepstepper.com.