OptyPeptides
Product Capabilities Plans About Blog
Admin Login Request Demo
Product Capabilities Plans About Blog Admin Login Request Demo

Privacy Policy

Last updated October 2, 2026

OptiSelf LLC makes OptyPeptides. This policy explains what we collect, how we use, share and may sell it, how long we keep it, and the choices you have.

1. Who we are and what this covers

OptiSelf LLC (“OptiSelf”, “we”, “us”) makes OptyPeptides: the iPhone and Android apps, the clinic admin portal, this website, and the services behind them.

How we handle your information depends on how you use OptyPeptides:

  • Through a clinic. If you joined with a clinic’s code, that clinic is your healthcare provider. If the clinic is subject to HIPAA, we handle your health information on its behalf as its business associate, and the clinic’s Notice of Privacy Practices also applies. If it isn’t subject to HIPAA, state consumer health privacy laws apply instead; section 10 and our Consumer Health Data Privacy Policy cover them.
  • On your own (personal account). If you use OptyPeptides without a clinic, HIPAA doesn’t apply. State consumer health privacy laws do; section 10 and our Consumer Health Data Privacy Policy cover them.

This policy doesn’t cover a clinic’s own systems, or services you connect yourself, such as Whoop or Oura.

2. Information we collect

InformationExamplesWhere it comes from
AccountName, email, password (stored only as a secure hash), clinic code, Apple or Google sign-in identifierYou
Health profileAge, sex, height, weight, goals, experience level, health conditions, current medicationsYou, in onboarding and settings
Treatment trackingPeptides and protocols, doses (amount, date, route, injection site), supply reminders, wellbeing check-ins, notesYou and your clinic
Lab results and documentsLab reports (PDFs and photos), biomarker values read from them, body composition scansYou or your clinic; body composition can sync from InBody through your clinic
Health and fitness dataSteps, active energy, heart rate variability, resting heart rate, blood oxygen, weight, sleep, recovery, strainApple Health, Android Health Connect, Whoop, Oura or Garmin, only if you connect them
MessagesConversations with the in-app AI assistant; messages with your clinicYou and your clinic
Device and securityPush token, device type, app version, IP address, sign-in and security eventsYour device and our servers
Crash reports (Android)Error type and where in the app it happened, never the error’s text or your health dataGoogle Firebase Crashlytics

Clinic staff using the portal: we also collect your name, work email, role, two-factor settings and a record of what you access.

We don’t collect precise location or contacts, and the apps contain no advertising. The iPhone app doesn’t collect your advertising ID; the Android app doesn’t from version 1.5.9. Our website and clinic signup pages use Google Analytics, which stays off when your browser sends a Global Privacy Control signal or you opt out on Your Privacy Choices. No page that shows health information uses it.

3. How we use information

  • Run the app: sync your protocols, doses, labs and history; send the reminders you set; show trends and progress.
  • Support your clinic’s care: let your clinic see and manage your treatment, labs and messages (section 4).
  • AI features: the assistant, reading lab reports and summaries. These run on Amazon Bedrock in our own AWS account, under our Business Associate Agreement with AWS. Names, contact details and ID numbers are masked in what the AI returns, and your assistant chats never leave our AWS account.
  • Research data program: where your clinic takes part, create de-identified data, and sell data as section 5 allows.
  • Keep accounts secure and meet legal obligations.

We don’t use protected health information, or any information that identifies you, to train or improve any AI model. Neither AWS nor the model’s maker, Anthropic, uses what you send or receive to train any model, and Anthropic never sees it. Where your clinic takes part in the research data program, we may also use the de-identified data to train and test our own models.

We don’t use your information for advertising, and buyers in our data program may not use what they receive for advertising either.

4. How we share information

With your clinic. If you joined through a clinic, its authorized staff can see and manage your profile, treatment, labs, check-ins and messages, and can export your record.

With service providers that run parts of OptyPeptides, under contracts limiting them to that work:

ProviderWhat they doWhat they receive
Amazon Web ServicesHosting, database, file storage, backups, email, encryption keys, AI (Bedrock)All app data, encrypted; BAA in place
Google WorkspaceStaff email, including the privacy inboxMessages you send us; BAA in place
Apple and Google (push)Deliver reminders and messagesPush token and notification text; our notifications don’t name your treatments
Apple and Google (sign-in)Verify your identity if you use their sign-inYour identity from that provider only
Google Firebase Crashlytics (Android)Crash reportingError type and location, device model, app version, an install ID
StripeClinic subscription billingClinic billing contacts only
Cloudflare (Turnstile)Bot protection on the clinic signup pagesIP address and browser signals from people signing a clinic up; never app or health data

With buyers in our research data program, as section 5 describes.

With services you connect. If you connect Whoop, Oura, Garmin, Apple Health or Health Connect, we read only the data you authorize. You can disconnect at any time.

With tools your clinic connects. A clinic can send alerts to tools it chooses, such as Slack or its own systems; the clinic is responsible for your information once it’s there. If your clinic connects its own InBody account, InBody sends us your body composition results; InBody works for your clinic, under the clinic’s own agreement with it.

For legal reasons, such as a valid court order, or to protect someone’s safety. We tell you when we’re allowed to.

If our business changes hands, in a merger, acquisition or asset sale. The new owner must honor this policy for information collected under it.

5. Our research data program and selling data

We run a research data program. As of the date of this policy, we haven’t sold any data. Here is when data can be sold, and how:

  • Clinic patients: only if your clinic takes part in the program, which it agrees to in its contract with us.
  • Personal accounts: not included today. Before that changes, we’ll update this policy, tell you in the app, and let you turn it off.
  • In the EU, EEA or UK: your data isn’t included unless you opt in.

De-identified data. We remove the details that identify you under HIPAA’s de-identification standard, by the Safe Harbor method or an expert’s determination: names, contact details, account and record numbers, device identifiers, full dates, small-area locations, photos and free text. We may then sell or license the result, alone or combined with other people’s data, to research organizations and to pharmaceutical, peptide and supplement companies. Every buyer signs a contract that bans re-identifying anyone, using the data for advertising, or reselling it to data brokers.

Information that identifies you. We would share it only for a specific research study you choose to join, with your separate, signed authorization for that study. That authorization names the study, its sponsor, its purpose, the data it uses, and that we’re paid; it ends when the study ends or after one year; it’s optional, and saying no never affects your access to the app or your care. You can withdraw it at any time, which stops future sharing. If you joined through a clinic, it’s a HIPAA authorization, and your clinic must also take part in the program.

What we never sell, in any form:

  • data from Apple Health or Android Health Connect;
  • data from Whoop, Oura or Garmin;
  • messages with your clinic or the AI assistant, clinical notes and uploaded documents;
  • passwords, sign-in details and security records.

You can opt out of any sale or sharing, for free, on Your Privacy Choices, through our privacy request page, or by emailing hello@optypeptides.com. A Do Not Sell or Share request also withdraws any research study authorization you’ve signed. Opting out works going forward: we leave your data out of any dataset created or delivered after we process your request. It doesn’t recall de-identified data already delivered, because that data can’t be linked back to you. The same applies if your clinic leaves the program. Your browser’s Global Privacy Control signal is honored on this website. You can also ask us for a list of everyone we sold your identifiable data to in the past 12 months.

6. Health information and HIPAA

If you joined through a clinic that is subject to HIPAA, your health information in OptyPeptides is protected health information (PHI). Your clinic is responsible for it, and we are its business associate. That means:

  • We use and disclose your PHI only to provide OptyPeptides, as our agreement with your clinic allows, and as you authorize.
  • Our research data program uses de-identified data, which isn’t PHI. We would disclose PHI in exchange for payment only for a specific research study you choose to join, with your signed HIPAA authorization, which says we’re paid (section 5).
  • Your HIPAA rights, to see your record, correct it, get a list of disclosures and ask for limits, are exercised through your clinic. We help it respond.
  • Joining a clinic with its code asks your permission to share your information with that clinic. If you don’t want that, you can use a personal account instead.
  • If there is a breach of your PHI, we tell your clinic, and it notifies you as HIPAA requires.

If you use a personal account, or your clinic isn’t subject to HIPAA, we still treat your health information as sensitive. If there’s a breach, we notify you and the authorities as the law requires.

7. How we protect information

  • Encryption: in transit and at rest, including the database, file storage, backups and servers. Especially sensitive information, such as medications, clinical notes, messages, AI summaries and the notes you write, is encrypted again with dedicated keys. On your phone, the app’s stored data is encrypted and left out of device backups (on Android, from version 1.5.9).
  • App lock: the apps lock at launch and after 15 minutes away, and unlock with your face, fingerprint or passcode. Lock-screen notifications don’t name your treatments. On Android, the lock and screenshot blocking come with version 1.5.9.
  • Access control: clinic staff must use two-factor authentication, see only their own clinic’s patients, and have access based on role. Access to patient information is recorded in audit logs that can’t be edited or deleted. Our own staff’s access is limited and logged.
  • Backups: kept in a second AWS region; restores are tested.

No system is perfectly secure. If a breach affects your information, we’ll respond as section 6 describes.

8. How long we keep information

  • Open accounts: kept while your account is open.
  • Personal accounts: deleting your account (Account → Delete account) ends your access right away. We delete your information on request: email hello@optypeptides.com.
  • Clinic-linked accounts: deleting your account removes you from the app. Your clinic keeps its medical record as the law requires.
  • Clinics that leave: the clinic gets a copy of its records, which are deleted after a 30-day grace period.
  • Backups: daily backups expire after 35 days, monthly backups after one year.
  • Audit logs: access and security logs are kept for at least six years. Records HIPAA requires us to keep, such as signed authorizations and de-identification documentation, are kept for at least six years.
  • De-identified data doesn’t identify you, so we may keep it, and buyers may keep what they received, after your account is deleted.
  • On your phone: signing out removes your information from the device.

9. Your choices and rights

In the app you can:

  • see and correct your profile and health information;
  • delete your account;
  • disconnect Whoop, Oura or Garmin, and turn off Apple Health or Health Connect in your phone’s settings;
  • turn off notifications.

You can also use our privacy request page, email hello@optypeptides.com, or use Your Privacy Choices, to ask for a copy of your information, a correction or deletion, to opt out of sale or sharing, or to limit our use of your sensitive information. We verify it’s you and reply within 45 days (we may extend once by up to 45 more, and tell you why). If we refuse, you can appeal from the same page or by replying to our decision; we answer appeals within 45 days. If you joined through a clinic, requests about your medical record go to the clinic.

We won’t treat you differently for using these rights.

If you’re in the EU, EEA or UK, you also have the right to data portability, to object to or restrict processing, and to complain to your local data protection authority. We process your information to provide the service you signed up for, and your health information with your explicit consent.

10. State notices

  • Texas: NOTICE: We may sell your sensitive personal data.
  • Washington and Nevada: our Consumer Health Data Privacy Policy explains how we collect, share and may sell consumer health data, and your rights under those laws. We would sell consumer health data that identifies you only with your signed authorization for a research study, which expires after one year at most.
  • California: in the past 12 months we have not sold or shared personal information. You can opt out of any future sale or sharing, and limit our use of sensitive personal information, on Your Privacy Choices.
  • Other states with privacy laws (including Colorado, Connecticut, Virginia and Oregon): you have the rights in section 9. We would sell sensitive data that identifies you only with your consent, and we honor Global Privacy Control as an opt-out on this website.

11. Children, storage, changes and contact

  • Children: OptyPeptides is for adults 18 and over. We don’t knowingly collect information from children. If you think a child has made an account, contact us and we’ll delete it.
  • Where it’s stored: in the United States on AWS, with backups in a second US region. If you use OptyPeptides from outside the US, your information is transferred to and processed in the US.
  • Changes: if we make a material change, including any change to how we sell data, we’ll tell you in the app or by email before it takes effect. The date at the top shows when this policy last changed.
  • Contact: OptiSelf LLC. Email hello@optypeptides.com.
OptyPeptides

The clinical management platform for peptide-based wellness practices. Built by OptiSelf LLC.

Patent Pending

U.S. Provisional Patent Applications Filed May 2026

Product

How It Works Capabilities Plans Request Demo

Company

About Contact Instagram

Legal

Privacy Policy Terms of Use Do Not Sell or Share My Personal Information Limit the Use of My Sensitive Personal Information Consumer Health Data Privacy Policy Privacy Requests
© 2026 OptiSelf LLC. All rights reserved.