Privacy Policy
Version 2026-06-21
Peak State Labs takes the data you give us seriously. This policy explains what we collect, why, who else touches it, and what control you have. Plain English, no fluff.
What we collect
You give us, and we store:
- Account info: name, email, password hash, role.
- Protocol and dosing data: the peptide schedules your coach assigns and the doses you log as taken.
- Training data: workout sessions, sets, reps, weights, PRs.
- Nutrition data: macro targets, meal logs (text + macros), AI-generated meal plans, metabolic type quiz responses.
- Body data: weight logs, optional body measurements, optional progress photos.
- Check-in data: AI-personalized weekly check-in questions and your answers, plus optional photos.
- Community content: posts, comments, reactions, optional shared photos.
- Device data needed for push notifications: a Web Push subscription endpoint and the device's user-agent string, only if you opt into reminders.
- Basic technical logs from hosting and database providers (IP, request timestamps), used to keep the Service running and secure.
What we don't collect
- No payment info goes through the portal.
- No tracking cookies for advertising. No third-party ad networks.
- No location data beyond standard server-side IP logs.
- No health data shared with insurers, employers, or marketing partners — ever.
Why we collect it
- To run the features you see (tracker, charts, AI suggestions, reminders).
- To let your coach support you (admin role can see your data inside the portal).
- To send you Web Push reminders if you opted in.
- To keep the Service secure and debug issues.
Who else touches your data (sub-processors)
We rely on a handful of vetted vendors. None of them sell data:
- Supabase (US) — database, authentication, file storage for photos.
- Vercel (US) — application hosting and edge delivery.
- Anthropic (US) — Claude AI model that generates check-in questions, meal estimates, workout plans, and coaching responses. We send only the minimum context needed for each call. Per Anthropic's API policies, your data is not used to train their models.
- Web Push services (Apple, Google, Mozilla) — relay the encrypted push payload to your device if you opt into reminders.
- cron-job.org — triggers the reminder cron on schedule. They only know the URL they call, not your data.
Photos
Progress photos you upload to your weekly check-in are private — stored in a private Supabase Storage bucket scoped so only you and your coach (admin role) can read them. We use short-lived signed URLs to display them.
Photos you choose to share to the community feed are visible to other authenticated clients. Their storage paths are unguessable but the photos themselves are not encrypted at rest in a way that prevents staff at our sub-processors from technically accessing them. Treat anything you post to community as visible to your fellow clients.
How long we keep it
As long as your account exists. If you ask us to delete your account, we remove your data within 30 days, except where retention is required by law.
Your rights
You can ask us to:
- Export your data (we'll send you a copy of everything stored under your account).
- Correct anything inaccurate.
- Delete your account and the data associated with it.
- Stop sending you push reminders (or just toggle them off in the app).
Email drewdeorsey@gmail.com for any of the above. We'll respond within 30 days.
Security
All data in transit is encrypted (TLS). Row-level security policies on the database scope every read and write to either the owning user or admin role. Passwords are hashed by Supabase Auth. Push payloads are encrypted with VAPID. Despite our care, no system is 100% secure — if something goes wrong we'll tell you promptly.
Children
The Service is not for anyone under 18.
Changes
Material changes will bump the version number and you'll be re-prompted to accept at next login.
Contact
Questions? drewdeorsey@gmail.com.