← Back to My Peptide Tracker
Privacy Policy

Calculator drafts stay local. Account records stay private.

Effective August 7, 2026

Free calculator

The anonymous calculator stores its versioned draft in browser local storage on that device so it can reopen offline. The draft is not a medical record, is not logged as a dose, and does not make a Neon database request. You can clear it from the calculator at any time.

Private account tracker

When you create an account, Neon Auth manages sign-up, verified email, Google sign-in, sessions, and password recovery. Compounds, schedules, logs, vial inventory, progress, journal entries, bloodwork metadata, expenses, settings, and recovery snapshots are stored in Neon Postgres under your account. Database row-level security restricts each row to its authenticated owner.

Bloodwork PDFs and images are stored in a private Cloudflare R2 bucket and are downloaded only through an authenticated ownership check. They do not receive public file URLs.

First-run setup answers—such as your goal, experience, peptide source, provider interest, wearable and bloodwork habits, age range, assigned sex, and approximate monthly spend—are stored with your private account settings to personalize the app. They are not public and are excluded from the compact tracker context sent to LUNA. Until setup is finished, a bounded draft stays only in this browser session and is cleared after successful completion.

Routine Box NFC tags

A Routine Box tag contains only a random HTTPS link. It does not contain your name, medication names, doses, or account details. When you claim a tag, its hashed identifier, box name, account ownership, enabled or disabled status, and selected tracker medication IDs are stored in Neon under your account.

Tapping a claimed tag requires your authenticated tracker session. When exactly one assigned scheduled dose is due, opening the tag link logs it automatically and offers Undo and Edit details. If the dose is injectable, its site is left unrecorded until you add one. Multiple doses, missing details, or other exceptions open a review screen instead. Disconnecting a box, erasing the tracker, or deleting the account releases its private assignment.

When you use LUNA

LUNA is optional. When you send a message, the message and recent conversation turns are sent through our protected server endpoint to OpenAI so a response can be generated. Conversations are not saved by My Peptide Tracker and clear when you leave or reload LUNA.

If you ask LUNA to create a tracker draft, you may paste a plan or attach up to two screenshots. That text and those screenshots are sent through an authenticated extraction endpoint and are not saved by My Peptide Tracker. LUNA returns a structured draft; only the tracker records you explicitly review and confirm are saved. A recovery snapshot is created first.

If Tracker context is enabled, the request may also include a compact summary of upcoming schedule items, recent dose counts, adherence, active inventory, numeric progress ratings, and recent injection sites. Free-text notes, journal text, existing tracker attachments, suppliers, lot numbers, purchase prices, audit history, and bloodwork are excluded. A screenshot is included only when you attach it to a tracker-draft request. You can turn Tracker context or LUNA itself off in Settings.

OpenAI processing

LUNA requests use the OpenAI API with response storage disabled. OpenAI states that API data is not used to train its models by default, but data may be retained in abuse-monitoring logs for up to 30 days unless different account-level data controls apply. Review OpenAI's current API data controls for details.

Operational data

To prevent abuse and control cost, we keep anonymous counters such as request date, request count, token totals, and estimated cost. Device and network identifiers are transformed with a keyed one-way hash; raw IP addresses, messages, model answers, and tracker records are not stored in the counter database. Old counter rows are removed after approximately 400 days.

A secure, HttpOnly device cookie is used for rate limiting. It cannot be read by app JavaScript and expires after one year. Clearing site cookies removes it.

Security

Provider credentials are stored as encrypted hosting secrets and are never sent to the browser. LUNA requests are limited by device, network, and monthly app budgets. We do not place credentials in local storage, backups, source maps, client code, or application logs.

Your choices

  • Use and clear the free calculator without creating an account.
  • Use the tracker without using LUNA.
  • Turn compact Tracker context on or off at any time.
  • Clear the current LUNA conversation from the LUNA panel.
  • Disable the LUNA entry point in Settings.
  • Rename, reassign, disable, or disconnect a claimed Routine Box.
  • Export your signed-in tracker as JSON or CSV.
  • Erase tracker records while keeping your account, or delete the account and its private data.
  • Download or erase an old IndexedDB device tracker; it is never imported automatically.

Offline behavior and legacy data

Only the public calculator and its static assets are available offline. Auth pages, private tracker screens, APIs, and attachments are network-only and are excluded from the service-worker cache. Older IndexedDB records remain untouched on the device until you explicitly download or erase them in Settings.

Medical and product links

The calculator and LUNA provide arithmetic, general information, and tracker summaries, not medical advice, diagnosis, or treatment. This consumer record-keeping app does not claim HIPAA compliance. Links to the Routine Box open the Med Storage Box storefront, whose own privacy terms apply after you leave this app.

Questions or changes

We may update this policy as the app changes. Material updates will be reflected by a new effective date. For privacy questions, use the contact options at Med Storage Box.