Introduction
Agonist is a personal tracking and research tool. It is not a medical device. It does not provide medical advice. This Privacy Policy describes how Agonist (“we,” “us”) handles information when you use our iOS app or website at agonist.app.
By using Agonist you agree to the practices described here. If you do not agree with any part of this policy, do not use the app.
Information we collect
We collect only what we need to make the app work for you.
- Account data. Email address, password hash, and authentication tokens from Sign in with Apple if you choose it. We never see your Apple password.
- Protocol data. Peptides you track, doses you log, vials you reconstitute, and injection sites you record.
- Health metrics. Read from Apple Health only with your explicit permission — for example HRV, sleep, weight, and heart rate. These are displayed on your device and are not uploaded to our servers.
- Subscription data. Your plan, renewal date, and payment status. Payment card numbers are processed and stored by Stripe (web) or Apple (iOS via StoreKit) — we never receive or store them.
- No analytics. The iOS app contains no analytics or advertising SDK and sends no usage telemetry.
- Crash reports. Only Apple’s own crash reporting, which you control in iOS Settings → Privacy → Analytics. No advertising IDs.
How we use it
We use your information to:
- Run the library, vial records, and dose dashboard.
- Sync your protocol data — peptides, vials, schedules, and dose logs — to your private account so it survives reinstalls and device changes. Nutrition, hydration, and workout logs are stored on your device.
- Send transactional emails — account confirmations, billing receipts, security alerts. No marketing unless you opt in.
- Comply with legal obligations and respond to valid legal process.
We do not sell your data. Ever. We do not share your protocol contents with advertisers, data brokers, insurers, or any third party for marketing purposes. Your dose logs and journal entries are yours.
Storage & encryption
Your data is encrypted at rest in our Supabase Postgres database and encrypted in transit over TLS 1.3. Row-level security policies enforce that only you can read your records.
Two kinds of storage, clearly split. Your protocol records — peptides, vials, schedules, and dose logs — sync to your own private Agonist account, protected by row-level security so no one else can read them. Your nutrition diary, hydration, workouts, and body measurements are stored on your device only and are not uploaded to our servers.
Apple Health integration
Apple Health integration is opt-in. When you grant permission, Agonist reads only the specific HealthKit types you authorize — heart rate variability, sleep, body weight, and any lab values you have manually entered into Health.
Apple Health data stays on your device. Agonist reads it to display your trends and never uploads it to our servers. You can revoke HealthKit permission at any time from iOS Settings.
We never write to HealthKit. We only read what you grant us.
Third-party services
We use a small set of vendors to run the product. Each one handles a specific job and is bound by its own privacy terms.
- Supabase. Hosts the database and authentication. Data lives in US-East. Encrypted at rest, TLS in transit.
- Stripe. Processes web subscription payments. PCI-DSS Level 1. We never receive your card number.
- Apple App Store. Purchases and subscriptions on iOS are processed by Apple through the App Store. We do not directly store your payment card information.
- Open Food Facts & USDA FoodData Central. When you scan a food barcode or search foods, the barcode or search term is looked up through our server. No account identity or health data is sent to these providers.
- Resend. Sends transactional emails — receipts, password resets, security alerts. Resend processes only your email address and the message body we generate.
A full list of subprocessors with their privacy policies is available on request.
Your rights
You own your data. Under GDPR (if you are in the EU/UK), CCPA (if you are a California resident), and as a matter of our own policy for everyone else, you have the right to:
- Access. See every piece of data we hold about you.
- Export. Request a complete copy of your synced records anytime by emailing privacy@agonist.app. In-app export is planned.
- Correct. Edit anything inaccurate.
- Delete. Permanently delete your account and all synced records directly inside the app — Settings → Delete Account. Deletion is irreversible.
- Object. Tell us to stop processing your data for a specific purpose, where the law gives you that right.
- Withdraw consent. Where we rely on your consent (Apple Health, marketing emails), you can revoke it at any time.
To exercise any of these rights, email privacy@agonist.app. We respond within thirty days.
Children
Agonist is for adults only. You must be at least eighteen years old to create an account. We enforce an age gate at signup and do not knowingly collect data from anyone under eighteen. If we learn that we have, we will delete it.
Changes to this policy
We will update this policy from time to time. When we make a material change, we will notify you by email and through the app at least thirty days before it takes effect. The “Last updated” date at the top of this page always reflects the current version.
Contact
Privacy questions, data requests, or anything else related to this policy — write to us at privacy@agonist.app. We read every message.