Skip to content

Legal

Privacy policy

What DB Peptide collects, why it collects it, and how to get it back or delete it.

Last updated 27 July 2026

The short version

You can read this entire site without an account and without accepting any cookie. We collect an email address only if you subscribe or sign in to the tracker, and analytics only where you have consented or where consent is not legally required.

Everything you log in the tracker is yours. Export it as JSON in one click, or delete all of it in one click.

What we collect

  • Newsletter: your email address, the page you subscribed from, and confirmation timestamps. Stored in our own database so we are never locked into an email provider.
  • Tracker account: your email address, held by Supabase Auth. We never see or store a password — sign-in is by magic link or Google OAuth.
  • Tracker data: protocols, compounds, dose logs and body weight entries that you enter yourself.
  • Analytics: Google Analytics 4 collects standard usage data — pages viewed, approximate location, device and browser, and referrer.
  • Region signal: a `dbp_geo` cookie recording only whether your request came from a region where a consent banner is required. It contains no identifier.

Cookies and consent

We implement Google Consent Mode v2. For visitors in the EU, UK, EEA and Switzerland — detected from the country code Cloudflare attaches to the request — analytics storage defaults to denied and nothing is set until you choose. Visitors elsewhere have analytics storage granted by default and can opt out at any time by rejecting in the banner.

Advertising storage is denied by default for everyone, everywhere, and we do not run advertising cookies on this site.

Two functional items are stored in your browser and never sent to us: your consent choice, and the fact that you dismissed the first-visit research notice.

How tracker data is protected

Every tracker table has row-level security enabled in Postgres, and every policy requires the row owner to match the authenticated user. A signed-in account physically cannot read another account’s rows — this is enforced by the database, not by application code that could be bypassed.

We do not sell, rent or share tracker data. It is not used for advertising, not shared with suppliers, and not used to build a profile of you.

Your data, on demand

  • Export: the "Your data" tab in the tracker downloads every row we hold for you as JSON.
  • Delete: the same tab deletes all tracker data immediately and irreversibly.
  • Unsubscribe: every newsletter email carries a one-click unsubscribe link.
  • Anything else: write to [email protected] and we will action access, correction or deletion requests.

Who processes data for us

  • Supabase — authentication and database hosting for the tracker and subscriber list.
  • Railway — application hosting.
  • Cloudflare — DNS, CDN and TLS termination.
  • Zeptomail — transactional email (magic links, double opt-in, welcome).
  • Zoho Campaigns or MailerLite — newsletter delivery to confirmed subscribers only.
  • Google Analytics — usage analytics, subject to your consent choice.
  • Sanity — content management for the blog.

Retention

Subscriber records are kept until you unsubscribe, after which the address is retained only to honour that unsubscribe. Tracker data is kept until you delete it or close your account. Analytics data follows Google Analytics 4 default retention.

Children

This site is intended for adults aged 18 or over. We do not knowingly collect information from anyone under 18. If you believe a child has provided information, write to us and we will delete it.

Changes

Material changes to this policy will be reflected in the last-updated date above. Continued use after a change constitutes acceptance of the revised policy.