1. Scope
This Privacy Policy applies to the PepPlanner iOS app, its App Store landing pages, PepPlanner-operated APIs, and support channels (together, the "Services"). PepPlanner LLC ("PepPlanner," "we," "us") is responsible for the data practices described here.
PepPlanner is an educational research and organization tool. It is not a medical provider, pharmacy, or emergency service.
2. Data we collect
Account and contact data
Depending on how you sign in, we may receive and store:
- Your name when Apple provides it during sign-in.
- Your email address.
- Authentication provider, provider user identifier, and PepPlanner session identifiers.
- Email verification challenge information used to complete sign-in.
Device-local check-in data
A check-in can contain a title, private notes, date and time, once, daily, weekly, or monthly cadence, completion state, and reminder state. The app stores check-ins on your device. The check-in feature does not upload this content to PepPlanner's API or an AI model.
PepAI data
After you agree to the in-app disclosure, PepPlanner sends your message and an opaque conversation identifier to the PepPlanner service. Secure sign-in is used separately to confirm access. The response and current messages exist only in the in-memory PepAI screen; the app does not save a conversation history. PepPlanner's API and AI providers may process and log requests and responses to operate, secure, and troubleshoot their services.
Purchase data
Apple processes App Store purchases. PepPlanner may receive product identifiers, transaction identifiers, entitlement status, expiration dates, and verification timestamps. We do not receive your complete payment-card number from Apple.
Technical and support data
We and our service providers may process IP address, request time, endpoint, response status, device or app version, crash or diagnostic information, and security events. If you contact support, we process the message and any attachments or account details you provide.
3. How we use data
We use data to:
- Create and secure your account and verify sign-in.
- Store check-ins locally, schedule generic on-device reminders, and create a Premium plain-text export when you request it.
- Provide the six-lesson research library.
- Provide educational PepAI responses after you give permission.
- Verify Premium entitlements and restore App Store purchases.
- Respond to support, privacy, and source-correction requests.
- Detect abuse, troubleshoot failures, protect the Services, and comply with law.
- Improve reliability and usability using aggregated or de-identified analysis where practical.
We do not sell personal information. We do not use account, check-in, or PepAI data for targeted advertising. The app's current release policy does not include third-party behavioral advertising or cross-app tracking.
4. PepAI and model processing
Before the first PepAI message is sent, the in-app disclosure names Cloudflare Workers AI, Google Gemini, and Groq as processors that may receive the message. PepAI sharing is optional. Nothing is sent to an AI processor unless you choose Agree and continue.
After you agree, the app sends the message and an opaque conversation identifier through PepPlanner's API. Secure sign-in is used separately to confirm that you can use PepAI; the app does not add your email address or local check-in content to the model message. Do not include sensitive personal information you do not want processed.
PepAI messages are not written to local storage. The app offers no conversation-history or chat-archive feature, and messages remain only in the current in-memory screen. PepPlanner's API, Cloudflare infrastructure, Google Gemini, or Groq may create operational, safety, or security logs and retain them under their applicable policies.
AI output may be inaccurate. PepAI does not provide personalized diagnosis, treatment selection, instructions about what to take, or preparation instructions.
5. Service providers and disclosures
We disclose data only as needed to operate the Services, process your request, protect users, complete a transaction, or comply with law. Providers may include:
- Apple: Sign in with Apple, StoreKit purchases, TestFlight, App Store distribution, and device services.
- Google Gemini: PepAI model processing when selected by the service.
- Supabase: hosted database and account-related records.
- Cloudflare: website and API hosting, network security, operational logs, and Workers AI.
- Resend: account verification and service email delivery.
- Groq: PepAI model processing when selected by the service.
These providers process data under their own terms and privacy policies. We may also disclose information to professional advisers, regulators, courts, law enforcement, or a successor in a corporate transaction when legally permitted or required.
6. Storage and retention
Check-ins, reminder state, and PepAI sharing permission are stored locally until you remove them, use Delete local app data, or remove the app. Current PepAI messages exist only in memory while the PepAI screen is active and are not saved by the app.
Account and StoreKit entitlement records are stored in PepPlanner's hosted systems while your account is active and as needed to provide the Services. We may retain limited transaction, security, backup, legal, and operational records for legitimate business or legal requirements. API or provider logs and backups may persist for a limited period before aging out under applicable retention practices.
7. Your choices and account deletion
- Check-ins: edit or delete individual check-ins in the app.
- Reminders: turn a check-in reminder on or off and manage PepPlanner's notification permission in iOS Settings. Reminder text is generic and does not include a check-in title or private notes.
- Export: Premium members can create a plain-text export of local check-ins.
- PepAI permission: revoke sharing permission in Settings. Revocation prevents new messages from being sent until you agree again.
- Subscription: manage or cancel an App Store subscription through Apple.
- Delete local app data: use this separate Settings action to remove local check-ins, local preferences, scheduled reminders, and PepAI sharing permission from the device.
- Delete account: open Account in PepPlanner, choose Delete account, and confirm. Apple accounts may require a fresh Apple authorization so PepPlanner can revoke the associated Apple token before deleting PepPlanner account records. Account deletion does not automatically remove local app data from the device.
You may also email privacy@pepplanner.org with an access, correction, deletion, or privacy request. We may need to verify your identity. Your rights may vary by location, and applicable law may allow or require us to retain certain records.
8. Security
We use measures intended to protect data, including encrypted network transport, session authentication, access controls, provider security features, and in-app privacy controls. No storage or transmission method is completely secure, and we cannot guarantee absolute security.
Protect your device passcode and account credentials. Contact us promptly if you believe an account or device has been compromised.
9. Age limits
PepPlanner is intended for adults and is not directed to children under 18. We do not knowingly collect personal information from a child under 13. If you believe a child has provided information, contact us so we can investigate and delete it as appropriate.
10. International processing
PepPlanner and its providers may process data in the United States and other countries. Those locations may have data-protection rules different from your home jurisdiction.
11. Changes to this policy
We may update this policy as the Services or legal requirements change. We will post the updated version here, change the "last updated" date, and provide additional notice when required.
12. Contact
Privacy questions and requests: privacy@pepplanner.org
General support: support@pepplanner.org or pepplanner.org/support