This Privacy Policy applies to the Pepteon Care mobile application
(the “App“) and the website
pepteoncare.com (the “Site“), together
the “Service.”
Pepteon Care helps you and a Pepteon-certified doctor see how your
body responds over time by bringing together your wearable data, your
at-home blood biomarker results, and your own check-ins into one health
record that your doctor uses to guide your care. Because that means we
handle sensitive health information, we want to be plain about what we
collect, why, who can see it, and the controls you have.
1. Who we are and how to
contact us
Pepteon Care is operated by Pepteon Management Services,
LLC (“Pepteon Care,” “we,”
“us,” “our“).
- Privacy & general contact: care@pepteoncare.com
If you have a question, a request about your data, or a complaint,
email us at the address above. You also always have the right to contact
your paired doctor directly about your care.
Pepteon Care operates the technology platform; clinical care is
provided by independent, licensed clinicians. Depending on the care
arrangement, Pepteon Care may act as a HIPAA Business
Associate to your treating provider. This Policy describes how
the Pepteon Care platform handles your information.
2. A quick summary
- We collect health data you choose to connect or
upload (Oura Ring, Apple Health, at-home blood biomarker
reports), information you enter (goals, check-ins,
messages to your doctor), and basic account and device
data. - We use it to provide the Service: build your
longitudinal health record, show you your trends, and let your paired
doctor review and adjust your protocol. - We share your health data with your paired
doctor and with service providers under
contract who help us run the Service. We do not
sell your personal information and we do not use your
health data for advertising. - Wearable data from Oura and Apple Health /
HealthKit is used only to provide the Service
— never sold, never used for ads, and never used to train advertising
models. See Sections 6 and 7. - De-identified, aggregate data may be used for
research only if you separately opt in. This is never
bundled into the consent you give to receive care. See Section 10. - You can access, export, and permanently delete your
account and data from within the App at any time. See
Section 12. - The Service is for adults (18+) only.
3. Information we collect,
by source
3.1 Health data you
connect or upload
| Source | How it’s collected | What we receive |
|---|---|---|
| Oura Ring | You authorize it through Oura’s secure OAuth2 sign-in (Oura API v2). You are always taken to Oura to grant access; we never see your Oura password. |
Sleep, readiness, heart-rate variability (HRV), resting heart rate, body-temperature deviation, blood-oxygen (SpO2), respiratory rate, and activity metrics. |
| Apple Health / HealthKit | You grant permission through Apple’s native Health permission sheet on your device. You choose which categories to share. |
Sleep, HRV, heart rate, workouts, and steps (only the categories you allow). |
| At-home blood biomarkers (RhythmHealth) | You export your own results from RhythmHealth and upload them to the App as a CSV (primary) or PDF/photo (parsed on our side). We do not scrape RhythmHealth or access your RhythmHealth account. |
Approximately 40 lab markers (for example hormones, metabolic, cardiovascular, kidney, and inflammatory markers) with their values, reference ranges, and prior-value trends. |
All of this is sensitive health information and is
collected only under your explicit consent, given at
the time you connect or upload each source.
3.2 Information you enter
- Your focus and goals (a short questionnaire — e.g.,
energy, sleep, recovery, hormones — plus a few quick questions such as
age, sex, and current peptides). - Protocol and adherence information you log (what
you’re taking, doses, timing). - Subjective check-ins (short, periodic
how-are-you-feeling entries). - Messages you exchange with your paired doctor
inside the App.
3.3 Account and device data
- Account data: your email address and, if you use
it, Sign in with Apple identifiers. (If you use Sign in
with Apple’s private-relay email, we receive only the relay
address.) - Your pairing code and the identity of the doctor
you are paired with. - Device and usage data: device type and
operating-system version, app version, crash logs, and basic in-app
event data used to keep the App working and secure. See Section 15 for
website analytics and cookies.
We do not derive vital signs from your phone’s
camera or sensors, and we do not collect your location beyond what is
strictly necessary for security and fraud prevention.
4. How we use your
information
We use your information to:
- Provide the Service — import and organize your
wearable and blood data, build one longitudinal health
record, and show you your trends and your “Pepteon Score” over
time. - Enable your care — make your record available to
your paired, Pepteon-certified doctor so they can
review your data, message you, and adjust your peptide protocol over
time. - Power doctor decision-support (the AI co-pilot) —
our AI co-pilot summarizes your record and suggests possible adjustments
to your doctor only. The co-pilot is
decision-support and education for a licensed clinician
— it is not a diagnosis, not a
treatment decision, and it never gives you a dose or a
patient-facing prescription. A human doctor always decides. See Section
8. - Communicate with you — service messages, reminders,
and check-in prompts. - Keep the Service safe and working —
troubleshooting, security, fraud prevention, and meeting our legal
obligations.
We do not use your health data for advertising, and
we do not sell it. See Sections 6, 7, and 9.
Medical disclaimer: Pepteon Care supports the
relationship between you and your doctor. It is not a substitute
for professional medical advice, diagnosis, or treatment, and
it is not for medical emergencies. Always follow your doctor’s guidance
and call your local emergency number in an emergency.
5. Consent and legal bases
Our handling of your health data is grounded in your explicit
consent, collected separately for each purpose so your choices
stay meaningful:
- (a) Connect / upload consent — to store your
wearable and blood data. - (b) Care-record consent — to build your
longitudinal record and share it with your paired doctor for your
care. - (c) Research consent (separate, optional opt-in) —
to contribute de-identified data to research. This is
never bundled with (a) or (b). See Section 10.
You can withdraw any consent at any time (see Sections 11 and 12).
Withdrawing consent to store or share data needed for care may mean we
can no longer provide the Service or that your doctor can no longer
treat you through the App; we’ll tell you when that’s the case.
6. Oura Ring data —
specific disclosures
This section describes exactly how we handle data from your
Oura Ring, obtained through the Oura API
(v2) after you authorize it with Oura’s OAuth2
sign-in.
- What we access: sleep, readiness, HRV, resting
heart rate, body-temperature deviation, SpO2, respiratory rate, and
activity — only after you grant access. - Why: solely to provide the Service
— to show you your wearable trends and to let your doctor see how your
body is responding over time. - We do not sell your Oura data, and we do
not provide raw Oura data to third parties for
their own use. - No advertising use. We never use Oura data for
advertising or to build advertising profiles. - Grounded in your consent. Our use of Oura data is
based on the access you grant and can be revoked by you at any
time. - Disconnect and delete. You can disconnect
Oura at any time from the App’s data-sources screen. When you
disconnect, we stop importing new Oura data, and you can choose to
delete the Oura data we already imported. You can also
revoke access directly in your Oura account. - Research use of any Oura-derived data occurs
only in de-identified, aggregate form and only if you separately
opt in (Section 10), consistent with Oura’s terms. - Retention: we keep imported Oura data as part of
your health record per Section 11, and delete it on the timelines
described there or when you delete it.
7. Apple
Health / HealthKit data — specific disclosures
This section describes how we handle data from Apple Health
(HealthKit), which you grant through Apple’s native permission
sheet on your device.
- What we access: only the categories you allow —
sleep, HRV, heart rate, workouts, and steps. - Why: solely to provide the Service
to you and your care team. - We will never use HealthKit data for advertising or
marketing, and we will never sell it or
disclose it to data brokers. - We will not use HealthKit data for any purpose other than
providing the Service, consistent with Apple’s requirements and
the App Store Review Guidelines. - We will not share HealthKit data with any third
party that would use it in a way inconsistent with Apple’s requirements,
and we do not store HealthKit data in iCloud or use it
beyond what’s described here. - You control it: you can change or revoke HealthKit
permissions at any time in the Apple Health app or your
device Settings, and you can delete imported data in the Pepteon Care
App. - We use standard HealthKit for this version; we do
not request Apple’s clinical “health records” (FHIR)
entitlement.
8. The AI co-pilot —
how it uses your data
- The co-pilot is doctor-facing decision-support, not
a patient-facing medical device. It summarizes your record and may
suggest protocol adjustments to your
doctor, always with its reasoning and sources shown so the
doctor can judge them. - The co-pilot never gives you a diagnosis or a dose.
A licensed human doctor makes every care decision. - The AI vendor that powers the co-pilot processes your data
only to generate suggestions for your doctor and, under
our contract, does not use your data to train its
models. See Section 9.
9. How we share your
information
We share your information only as described here. We do not
sell your personal information.
-
With your paired doctor / provider. Your health
record is made available to the Pepteon-certified doctor you are paired
with, for your care. -
With service providers (subprocessors). We use
vetted vendors under contract to run the Service. Where they handle
protected health information, we require appropriate contractual
protections, including Business Associate Agreements
(BAAs) where required by law.Type of vendor What they help with PHI involved? Contract Cloud hosting / database Store your record and data Yes Under contract; BAA where required AI / co-pilot vendor Generate doctor-facing suggestions Yes Under contract; no training on your data; BAA where required Email / SMS / notifications Service and reminder messages Possibly Under contract; BAA where required Payments / billing Process payments Limited (billing, not clinical) Under contract with a third-party processor Product analytics / crash reporting Keep the App working Minimized / de-identified where possible Under contract We put appropriate agreements, including BAAs where required, in
place before a vendor handles protected health information. -
For legal reasons. We may disclose information
if required by law, to comply with a lawful request, or to protect the
rights, safety, and security of users, the public, or Pepteon
Care. -
Business transfers. If we’re involved in a
merger, acquisition, or asset sale, information may transfer as part of
that transaction, subject to this Policy and applicable law.
We do not share your Oura or HealthKit data for
third-party advertising, and we do not provide raw wearable data to
third parties for their own purposes.
10.
De-identified research use — separate, optional opt-in
We believe your data can help advance the science of how peptide
protocols affect real bodies. But that is entirely optional and
separate from your care.
- Research use applies only to de-identified, aggregate
data — information from which direct identifiers have been
removed, using a recognized de-identification standard, so it does not
identify you. - You must separately and affirmatively opt in.
Research consent is a distinct choice, presented on its
own, and is never bundled into the consent you give to
receive care. Declining has no effect on your care or your
access to the Service. - You can withdraw your research opt-in at any time
in the App. Withdrawing stops future contribution; data already
de-identified and aggregated into research sets may not be retrievable,
and we’ll explain this at the point of consent. - Research use of any Oura- or **HealthKit-**derived
data is further limited by those providers’ terms. - We do not sell identifiable health data for
research or any other purpose.
11. How long we keep
your data (retention)
We keep your information for as long as needed to provide the Service
and to meet legal, clinical-recordkeeping, and safety obligations.
- Your health record is retained while your account
is active and for any period required by applicable medical-record
retention laws, coordinated with your treating provider. - Wearable data you disconnect can be deleted at
disconnect time (Sections 6, 7). - Account and usage data is retained for as long as
needed for the purposes described in this Policy and as required by
law. - De-identified aggregate research data may be
retained in aggregate form for research purposes. - When you delete your account (Section 12), we delete or de-identify
your personal data within 30 days, except where we must
keep certain records to meet legal or clinical-recordkeeping
obligations, in which case we isolate and protect that data until it can
be deleted.
12. Your
rights and choices — including in-app deletion
You are in control of your data. From within the App you can:
- Access and review all the data in your record.
- Export your data (Profile → Export my data) in a
portable, machine-readable format. - Delete your account and all associated personal
data (Profile → Delete my account/data). Deletion is available
in-app, as required by Apple, and initiates permanent
deletion subject only to the legal/clinical-record exceptions in Section
11. - Manage connected sources — connect or
disconnect Oura, Apple Health, or RhythmHealth, and
delete imported data. - Manage your care pairing — see, message, or unpair
from your doctor.
Depending on where you live, you may also have rights under
applicable privacy and consumer-health-data laws (for example, the
California Consumer Privacy Act/CPRA and the Washington My Health My
Data Act) to access, correct, delete, or restrict processing of your
data, and to not be discriminated against for exercising them. To
exercise any right, use the in-app tools above or contact us at
care@pepteoncare.com. We
will verify your request before acting on it.
We do not use your data for automated decisions that produce
legal or similarly significant effects without human
involvement — your doctor is always in the loop (Section
8).
13. How we protect
your information (security)
We use administrative, technical, and physical safeguards designed to
protect your information, including encryption in transit and at rest,
access controls and least-privilege / minimum-necessary access, audit
logging, secure authentication (including Sign in with Apple), and
vendor security review. No system is perfectly secure, and we cannot
guarantee absolute security. If we learn of a breach affecting your
information, we will notify you and applicable authorities as required
by law.
14. Children
The Service is intended for adults 18 and older. It
is not directed to children, and we do not knowingly
collect personal information from anyone under 18. If we learn we have
collected data from a minor, we will delete it.
15. Cookies and
website analytics (pepteoncare.com)
Our website may use cookies and similar technologies
for basic functionality and, where enabled, to understand how the site
is used. The mobile App does not use advertising
cookies, and we do not use health data for advertising anywhere. Where
required, we will present a consent choice for non-essential
cookies.
16. International and
cross-border data
Pepteon Care is operated from the United States, and your data is
processed and stored in the United States. If care is
ever delivered through a provider or infrastructure located outside the
U.S., your information may be transferred to and processed in that
country, and we will apply appropriate safeguards and disclose this here
before any such transfer occurs.
17. Changes to this Policy
We may update this Policy. If we make material changes, we will
notify you in the App and/or by email and update the “Last updated”
date. For changes that materially affect how we use your health data, we
will seek your consent where required. Continued use after an update
means you accept the revised Policy, to the extent permitted by law.
18. Contact us
Questions or requests: care@pepteoncare.com.