Privacy Policy

Effective date: [EFFECTIVE DATE]

This Privacy Policy describes how The Formularie ("we," "us," or "our") collects, uses, stores, and protects information from users ("you") of The Vial — Peptide Calculator mobile application and the website at theformularie.com (collectively, the "Service").

By using the Service, you consent to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

1. Who we are

The Service is operated by The Formularie, a New Mexico entity, with mailing address:

[MAILING ADDRESS]

Privacy questions and data-subject requests: [SUPPORT EMAIL]

2. Information we collect

2.1 Information you provide directly

2.2 Information collected automatically

2.3 Biometric data

When you enable biometric sign-in (Face ID, Touch ID, or fingerprint), we do not see or store your biometric data. Biometric matching happens entirely on your device. We store only an encrypted token in your device's secure keychain, which is unlocked by a successful biometric match. The token can be cleared at any time via the in-app Privacy Vault.

2.4 Information we do NOT collect

3. How we use your information

We use information for the following purposes:

We do not use your information for cross-app tracking, behavioral advertising, or sale to data brokers.

4. Third parties we share information with

We share specific subsets of your data with the following service providers, each bound by confidentiality and data-protection obligations.

ProviderData sharedPurpose
SupabaseAccount, profile, orders, protocols, outcome logs, encrypted vault payloadsPrimary backend database, authentication, file storage
StripePayment information, billing address, order amountPayment processing
Anthropic (Claude)Short text summaries of protocols / outcomes when you use AI featuresAI-generated educational text and insights
Google (if Google sign-in)Email address, name, profile pictureOAuth sign-in
Apple (if Face ID / Apple Sign-in)Biometric matching is on-device only; we receive only your verified identifierAuthentication
APNs / FCMAnonymous push token, notification payloadDeliver reminders you scheduled

We do not share your peptide protocols, outcome logs, symptoms, weight, mood, or sleep data with any party other than the service providers listed above, and only as necessary to provide the Service.

We may disclose information to comply with legal process, prevent fraud or harm, or in connection with a corporate transaction (merger, acquisition, asset sale), in which case we will notify you and give you the opportunity to delete your data before transfer.

5. AI features and your data

When you use a Pro AI feature, we send the AI provider a short text digest of the relevant data — for example, "Last 14 days: weight down 1.2 lbs, sleep 7.1h average, peptide A at 0.5 mg twice daily." We do not send raw logs, full medical history, or any field we don't need for the specific request.

The AI provider processes the request to produce text output and does not retain your data for model training. You can disable individual AI features in the in-app settings; if all AI features are disabled, no data is sent to the AI provider.

6. Data retention

7. Your rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise these rights, email [SUPPORT EMAIL] from the email address associated with your account. We will respond within 30 days.

If you are in the European Economic Area, United Kingdom, or Switzerland, you also have the right to lodge a complaint with your national data-protection authority. If you are in California, you have additional rights under the California Consumer Privacy Act (CCPA) including the right to opt out of "sales" of personal information — we do not sell personal information.

8. Security

We use industry-standard measures to protect your data:

No method of transmission or storage is 100% secure. If you suspect your account has been compromised, change your password immediately and email [SUPPORT EMAIL].

9. International data transfers

The Service is operated from the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US. By using the Service, you consent to this transfer.

For users in jurisdictions with data-export restrictions (such as the European Economic Area), our service providers (Supabase, Stripe, Anthropic) operate under standard contractual clauses or equivalent transfer mechanisms.

10. Children's privacy

The Service is not directed at children under 18 years of age, and we do not knowingly collect personal information from children. If you are under 18, please do not use the Service. If you believe a child has provided personal information to us, contact [SUPPORT EMAIL] and we will delete the information promptly.

11. Cookies and tracking

The mobile app does not use browser cookies. It stores small amounts of data locally on your device (using AsyncStorage and the iOS Keychain / Android Keystore) for sign-in state, theme preferences, and your protocol / outcome logs.

The website at theformularie.com uses minimal essential cookies for site functionality; we do not run third-party advertising or analytics cookies.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Effective date" at the top and notify you in-app, by email, or both at least 14 days before the new policy takes effect. Continued use of the Service after the new policy takes effect constitutes acceptance.

13. Contact us

For privacy questions, data-subject requests, or to report a concern:

Email: [SUPPORT EMAIL]
Mail: The Formularie, [MAILING ADDRESS]

We aim to respond to all privacy inquiries within 30 days.