01What Information We Collect
Peptigrity collects the minimum data required to operate an independent review platform. We do not sell products, process payments, or run targeted advertising, which means most commercial data practices do not apply.
Information you provide
When you register an account, we collect your email address and username. Email is never displayed publicly. When you submit reviews, lab tests, or discussions, the content you post is published with your username.
Information collected automatically
When you visit Peptigrity, we automatically log IP address, browser type, device type, and pages visited for security, abuse prevention, and aggregate analytics. These logs are retained for 90 days.
Information we do not collect
Peptigrity does not collect payment information, shipping addresses, purchase history, or prescription data. We are not an ecommerce platform and have no reason to hold that information.
02How We Use Information
We use the information we collect for 4 specific purposes:
- Platform operation. Authenticating your account, publishing your contributions, delivering notifications you opt into.
- Moderation. Identifying duplicate accounts, spam, and abuse. IP addresses help us detect ban evasion.
- Aggregate analytics. Understanding which pages are most useful, where users come from, how long they stay. No individual-level tracking is sold or shared.
- Legal compliance. Responding to valid legal process, subpoenas, and court orders as required by law.
04Third-Party Services
Peptigrity uses a small number of third-party service providers, each with a specific purpose:
- Cloud hosting. Our infrastructure runs on a commercial cloud provider. They see encrypted traffic metadata but not application-level data.
- Email delivery. We use a transactional email provider to send account notifications. They receive your email address and message content to deliver it.
- Image hosting. Lab test Certificate of Analysis images are stored on a CDN. The CDN sees image requests and referrer headers.
We do not use Google Analytics, Facebook Pixel, or any advertising SDK.
06Data Retention
Different categories of data have different retention rules:
- Account data (email, username) - retained as long as your account is active, deleted within 30 days after account deletion.
- Public contributions (reviews, lab tests, posts) - retained permanently as part of the public record, even after account deletion. Attribution can be anonymized upon request.
- Access logs - 90 days.
- Email notifications - delivery logs retained 30 days.
07Your Rights (GDPR / CCPA)
If you are in the European Union, United Kingdom, or California, you have specific rights regarding your personal data. Peptigrity honors the strictest applicable standard for all users regardless of location.
GDPR (EU / UK)
- Right to access - request a copy of the data we hold about you.
- Right to rectification - correct inaccurate data.
- Right to erasure - delete your account and associated data (public contributions are preserved in anonymized form).
- Right to data portability - export your data in machine-readable format.
- Right to object - opt out of analytics and notifications.
CCPA (California)
- Right to know - what data we collect and how we use it (this policy describes it).
- Right to delete - request deletion of personal information.
- Right to non-discrimination - we do not discriminate against users who exercise their rights.
- Right to opt-out of sale - not applicable, we do not sell data.
To exercise any right, email privacy@peptigrity.com. We respond within 30 days as required by GDPR, and faster when possible.
08Children's Privacy
Peptigrity is not directed at children under 18. We do not knowingly collect data from minors. If we learn a user is under 18, we delete the account and associated data within 72 hours.
09Changes to This Policy
We may update this policy. Material changes will be announced on the homepage with a 30-day notice period. The “Last updated” date at the top of this page reflects the current version. Substantive changes require users to re-accept updated terms before continued use.
10Contact Us
Questions about this policy or your data:
- Email: privacy@peptigrity.com
- Data Protection inquiries (EU/UK): dpo@peptigrity.com
- Mailing address: On file with our legal counsel. Provided upon verified request.