What we collect
Privacy policy
The processors are named, the retention periods are stated, and where we reserve a right we are not yet using, it says so.
Last updated
This policy is incorporated into the terms of service. Accepting those accepts this.
1. Who controls your data
Stratum Applications Corporation, 1629 K Street NW, Suite 300, Washington, DC 20006, United States, is the controller. Privacy enquiries: [email protected].
2. The short version
The app handles an account and whatever you choose to record in it. Some of what you record is health data, and we say so rather than calling it something else. To run the app at all, some of it goes to the processors named in section 5, including Google, which provides the language model behind Corbin.
We may use analytics and measurement tools, and we may show advertising, on the public site and in the app. We may de-identify and aggregate what users record and sell or license that de-identified information to third parties. We do not sell information that identifies you. Sections 7, 11 and 15 say exactly what that means and how to opt out.
3. The public site, cookies and similar technologies
You can read the corpus, the conditions, the glossary and the tools without an account.
Strictly necessary storage, always present and not optional, because the
service does not work without it: sp-theme, remembering whether you chose light
or dark; and sp_returning, a cookie holding the single value 1 so the header can
say "open the app" rather than "start free". Neither identifies you. In the app, an
authentication token keeps you signed in. Clearing site data removes them.
Analytics, measurement and advertising technologies. We may use cookies, pixels, tags, SDKs, local storage and similar technologies, our own and third parties', to understand how the service is used, to measure performance, and to select and measure advertising. These are not strictly necessary. Where the law requires consent we ask before setting them, and you can change your answer at any time through the cookie controls on the site.
If you would rather not be measured at all, most browsers let you block or delete cookies, and the service will still work.
4. What the app collects
- Account — email address, an authentication credential and account timestamps. Passwords are stored only as a hash; we never see yours.
- Profile, which is health data — display name, date of birth, biological sex, height, conditions, relationship status, children, profession, stress level and goals, plus display preferences. Almost all of it is optional.
- Your records, most of which are health data — saved compounds, vials, protocols, dose logs and, on Ultra, journal entries including side-effect notes, food logs, weigh-ins, laboratory panels and progress photographs.
- Corbin conversations — your messages, Corbin's replies and per-message token counts used for metering.
- Forum — your chosen handle and anything you post. Posts are public.
- Commerce — where you use cart or order features, the items and vendors concerned and any resulting commission record.
- Billing — your Stripe customer and subscription identifiers, tier, status and period dates. We never receive or store your card number.
- Operational logs — ordinary web-server and edge records such as IP address, timestamp and user agent, kept briefly for security, abuse prevention and debugging.
5. Third parties we send data to, by name
This list is exhaustive as at the effective date, and we update it when it changes.
- Supabase — database, authentication, file storage and server functions. Holds everything in section 4 (a) to (f). Hosted in AWS ca-central-1, in Canada.
- Cloudflare — hosting, content delivery, TLS, rate limiting and protection against abuse. Sees request metadata including IP address.
- Stripe — payment processing, subscription management and the billing portal. You give your card details directly to Stripe; they do not pass through us.
- Google (Gemini API) — the language model behind Corbin, called at generativelanguage.googleapis.com. What is sent: the text of your message, the conversation so far, corpus material relevant to your question, and — where the question requires it and only then — material from your own saved profile and records, so that Corbin can answer about your own data. If you do not want your records sent to Google, do not ask Corbin about them; the rest of the app does not use Google at all.
- Google Workspace (SMTP relay) — delivery of authentication and account email. Sees your email address and the message.
Analytics and advertising vendors. We use none as at the effective date. When we add one we will name it here before or when it goes live, and where the law requires consent for the technology it uses, we will ask for that consent first.
We may also disclose data to professional advisers, and to a purchaser or successor in connection with a merger, acquisition, reorganisation or sale of assets.
6. Sharing with Stratum Applications Corporation and its group
Peptide Corpus is operated by Stratum Applications Corporation. Your information may be shared with Stratum Applications Corporation and with its parent, subsidiaries and affiliated companies, and may be processed and stored by them and on their systems, for operating and supporting the service, security and fraud prevention, billing and financial administration, customer support, product development, analytics, and compliance with legal obligations. Where information is handled by Stratum Applications Corporation or another group company, that company's own terms and privacy policy may also apply to it in addition to this policy.
7. Selling, sharing and advertising
What we may do:
- De-identified and aggregated information. We may de-identify and aggregate what users record and use, license, disclose, transfer and sell it to partners, advertisers and researchers, for any purpose. De-identified means it cannot reasonably be used to identify you: we take reasonable measures to keep it that way, we do not attempt to re-identify it, and we require recipients by contract not to attempt it either.
- Advertising. We may show advertising on the public site and in the app, and may use information about you to select and measure it. Using your personal information to target advertising across other businesses' sites and apps is "sharing" under California law; section 11 tells you how to stop it.
- Analytics and measurement, including third-party tools.
What we will not do:
- We will not sell information that directly identifies you — your name, your email address, your account credentials or your payment details.
- We will not sell or share your identified health information — your journal, dose logs, laboratory panels, progress photographs or the health fields in your profile — without your separate, express, opt-in authorisation. If we ever ask for that authorisation it will be a specific request, made apart from these documents, and refusing it will not cost you access to anything you have paid for.
- We will not publish your journal, dose logs or laboratory panels on a public page in any form that identifies you.
What the product does today. As at the effective date we run no advertising and no third-party analytics, and we have sold nothing to anyone. This section reserves a right rather than describing a current practice, and it is written that way so that beginning to exercise it is not itself a change of policy.
8. Why we are allowed to process it
Where the UK GDPR or EU GDPR applies: we process account, billing and operational data to perform our contract with you; security, abuse-prevention and product-improvement data under our legitimate interests; and health data — your profile, records, journal and anything of that nature you send to Corbin — on the basis of your explicit consent under Article 9(2)(a). You may withdraw that consent at any time by deleting the data or your account.
9. Where your data is, and transfers
Primary storage is in Canada (AWS ca-central-1). Our processors may process data in the United States and elsewhere. Where data is transferred out of the UK or the EEA we rely on the UK Addendum and the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies.
10. How long we keep it
- Corbin messages are hard-deleted after 30 days. This is enforced in the database, not by a policy someone has to remember.
- Your records, profile and account are kept until you delete them or your account. Deleting your account cascades: profile, vials, protocols, logs, journal, panels, photographs and Corbin history are permanently destroyed. Export first if you want a copy.
- Forum posts may remain visible after account deletion where they form part of a thread others contributed to; tell us and we will consider removal.
- Billing records are kept as long as tax, accounting and audit law requires.
- Operational logs are short-lived, on our providers' standard cycles.
11. Your rights
Subject to verification of your identity, you may ask us to give you a copy of your data, correct it, delete it, export it in a portable format, restrict or object to certain processing, or withdraw consent. Much of this you can do yourself in the app at any time. Write to [email protected] and we will respond within 30 days.
If you are in California, or a state with an equivalent law: you have the rights to know, access, correct, delete and port your personal information, and to opt out of its sale or sharing and of targeted advertising. To opt out, use the "Do Not Sell or Share My Personal Information" control on the site, send a Global Privacy Control signal (section 15), or write to [email protected]. We honour valid opt-outs, we do not discriminate against anyone for exercising a right, and you may use an authorised agent.
If you are in the UK or the EEA: you may complain to your supervisory authority. We would rather you told us first.
12. Security, and its limits
Data is encrypted in transit. Access is enforced at the database itself: every user table carries a row-level security policy keyed to your own authenticated identity, so one account cannot read another's rows even if the application layer were wrong. Administrative credentials never reach the browser.
No system is completely secure and we do not claim otherwise. If a breach affects your personal data we will notify you and any regulator as required by law.
13. HIPAA does not apply
Stratum is not a covered entity or a business associate under HIPAA, and the information you record is not protected health information under that statute. It is protected by this policy, by contract with our processors and by the technical controls in section 12 — not by HIPAA. We say so plainly because the alternative is that you assume a protection we are not offering.
14. Children
The service is not for anyone under 18 and we do not knowingly collect data from anyone under 18. If you believe a minor has an account, write to [email protected] and we will delete it.
15. Global Privacy Control and Do Not Track
We honour the Global Privacy Control. If your browser or an extension sends a GPC signal, we treat it as a valid request to opt out of the sale and sharing of your personal information and of targeted advertising for that browser, and you need do nothing else.
Do Not Track has no agreed meaning across the industry and we do not respond to it separately. Send GPC instead; it is the one that works.
16. Automated decisions
We do not make decisions about you by automated means that produce a legal effect or similarly significantly affect you. Corbin generates text in response to what you ask; it does not decide anything about your account, your pricing or your access.
17. Aggregate and de-identified information
We may create aggregate and de-identified information from anything users record — counts, totals, distributions, statistics and derived data sets that identify no individual and cannot reasonably be used to — and may use, publish, license, disclose, transfer and sell it for any purpose, including research, benchmarking, product development and advertising, and including to third parties. See section 10.3 of the terms.
Once information is genuinely de-identified it is not personal information, and this policy's restrictions on personal information do not apply to it. We take reasonable measures to keep it de-identified, we do not attempt to re-identify it, and our contracts require recipients not to attempt it either.
18. Changes
If this policy changes materially we will give at least 30 days' notice by email or in the app, and the effective date above changes with it.
19. Contact
[email protected]
Stratum Applications Corporation
1629 K Street NW, Suite 300, Washington, DC 20006, United States
Telephone +1 (202) 643-6467
These three documents are one agreement, effective 19 August 2026: the medical disclaimer, the terms of service and the privacy policy. The disclaimer and the privacy policy are incorporated into the terms, so accepting one accepts all three.