Legal

Privacy Policy

Peptide Health Lab is an education site. The one place it handles health information is the Stack Builder intake, and this page explains exactly what that intake collects, what happens to it, how long it is kept, and how to delete it.

Last updated August 3, 2026

Who we are and what this policy covers

Peptide Health Lab ("PHL", "we", "us") is an education and discovery property operated by RevivaGo LLC. It is not a pharmacy, not a clinic, and not a diagnostic tool. It does not sell peptides and does not prescribe.

Because no healthcare treatment happens here, PHL is not a HIPAA covered entity and the information you give the Stack Builder is not protected health information under HIPAA. That is not a loophole and we do not treat it as one. PHL is a consumer health-data controller under state consumer-health-data laws, including Washington's My Health My Data Act and its equivalents, and this policy is written to those obligations: a real published policy, an enforced retention rule, encryption at rest, and a deletion path you can use yourself without asking anyone.

This policy covers the peptidehealthlab.com property only. RevivaGo's own services have their own separate privacy policy, and the two data sets are kept apart by design.

What we collect

Account information. To create an account we collect your email address and password, your name, and optionally a phone number.

Stack Builder intake. The intake is optional. You can read every page on this site without it. If you complete it, we collect exactly this and nothing more:

  • Your date of birth. The Stack Builder is for adults; we compute your age from it and never store the age separately.
  • Your biological sex.
  • Diagnosed conditions you list, or your explicit statement that you have none.
  • Medications you list, with an optional amount and how often you take them, or your explicit statement that you take none.
  • Supplements you list, on the same terms.
  • Which of the nine goals you selected.
  • Anything you type into the free-text "symptoms you want to fix" box.
  • Blood-work files you choose to upload: up to three, PDF or image, 10 MB each. This step is optional and skippable.
  • Your US state, if you ask the site to show you provider options for it. On your intake we treat that as health-adjacent information and protect it the same way. If you separately join a provider waitlist, that signup keeps its own copy of the state as ordinary marketing contact information. See What survives deletion.

Your assessment. The stack assessment the site generates from your intake is derived health information, and it is stored and protected on the same terms as the intake it came from.

Why we collect it

One purpose: generating your stack assessment so you can review it with a licensed provider. We do not collect anything the assessment does not need, and we do not use your intake for anything else: not advertising, not audience building, not profiling.

How your assessment is generated

This is the one place your health information leaves our servers, so we are going to be specific about it rather than hide it behind "third-party service providers".

Your assessment is generated by a large language model. The request goes to OpenRouter, a model-routing service, which forwards it to the company running the model we have configured, currently Anthropic's Claude. That is two outside processors, not one: OpenRouter carries and routes the request, and the model provider processes it to write the assessment. When you ask for an assessment, we decrypt your intake and send a single request containing:

  • your age, biological sex, listed conditions, medications, supplements, selected goals, and your free-text symptoms;
  • the contents of any blood-work files you uploaded, attached to that request in readable form;
  • our own compound reference material, written for this tool. It covers the same compounds the site covers, and it also carries the protocol ranges reported in the research literature, which we do not publish as page copy.

We deliberately do not send your date of birth (only the age computed from it), your name, your email address, your phone number, your state, or any account identifier. The request is made for that one assessment. What comes back is checked against a fixed structure, screened, and then encrypted and stored in your account.

If you would rather no part of your health information ever be processed this way, do not run the Stack Builder. The rest of the site is open to you either way, and you can delete an intake you have already submitted at any time.

What we deliberately do not do

  • No lab parsing of any kind. We do not run OCR on your blood work, do not extract biomarker values from it, and have nowhere to put them if we did: no parsed-value fields exist. An uploaded file is stored as encrypted bytes, and it is decrypted in exactly two situations: when an assessment is generated from it, and when you yourself download it back. There is no third path.
  • No RevivaGo admin surface. Nobody browses PHL health data from RevivaGo's admin tools. It is not searchable there, it does not appear in any RevivaGo screen, and it does not flow through RevivaGo's medical-review process, mailers, or risk scoring.
  • No sync with RevivaGo medical profiles. If you hold both, you enter your information twice. That is deliberate: the two properties are separate consent contexts and we will not quietly merge them.

How it is protected

Intake answers are encrypted at rest. Every health field on your intake is encrypted in the database: date of birth, biological sex, conditions, medications, supplements, goals, symptoms, the state you asked us to find providers in, and your generated assessment. Reading those columns straight out of the database returns ciphertext, which is asserted by an automated test rather than promised in prose.

The one exception, and it is not health data. A provider-waitlist signup is a marketing contact record, and it stores its two-letter state in plain form rather than encrypted. That is deliberate: the only thing we do with those rows is count how many people are waiting in each state, and a column we cannot read is a column we cannot count. Nothing about your intake, your uploads, or your assessment sits in that record. See What survives deletion.

Uploaded files are encrypted before they are stored. Your blood work is encrypted with AES-256-GCM inside our application, and only the encrypted result is written to storage. Our storage provider only ever holds an opaque blob under a random filename. There are no public links to these files and no shareable links of any kind: the only way to read one back is an authenticated request by the account that uploaded it, which decrypts the file on our server at that moment. The real filename and file type are themselves stored encrypted.

Logs and audit records carry counts, never content. Every intake field name is on the application's log-filter list, so health answers never reach a log line. When data is deleted or purged we record that it happened, for which account, and how many files were involved. We never record a field value, a filename, or any part of what you wrote.

No system is perfectly secure, and we do not claim otherwise.

How long we keep it

Intake data is kept while it is in use and is deleted 24 months after you last updated it. Editing any part of your intake resets that clock, and we mean any part. That includes the parts that are not typed answers: uploading or removing a blood-work file resets it, and generating a new assessment resets it.

This is enforced by a job that runs every day, not by anyone remembering. When a profile passes the 24-month mark the job destroys the intake, the assessments generated from it, and the encrypted files attached to it, and records a content-free note that it did so.

How to delete it

You do not have to email anyone or wait. Sign in, open the Stack Builder intake, and choose "Delete my health data". You will get a confirmation screen telling you exactly what is about to go, and then it goes.

The control lives inside the intake itself. Open the Stack Builder, sign in, and it is on your saved health profile. We do not link straight to it from here because the page is behind your sign-in, which is the point of it.

Deletion is immediate and happens while you wait. Your intake answers, every assessment generated from them, and every uploaded file and its encrypted bytes are destroyed in that request. It is not queued for later and it cannot be undone.

Your account survives. Deleting your health data does not close your account or sign you out, and you can start a fresh intake immediately.

What survives deletion

One thing deliberately does not get deleted, and we would rather tell you plainly than let you discover it.

If there are no providers in your state yet, the site offers to email you when that changes. Joining that waitlist stores an email address, a two-letter state, and the campaign tags from how you first arrived, and nothing else. There is no health information in that record: no intake answers, no uploads, no assessment.

That record holds its contents as ordinary marketing contact data, in plain form rather than encrypted, including the state. We are telling you because the section above says your state is encrypted, and that is true of the state on your intake, not of this one. The reason is mundane: the only use for these rows is counting how many people are waiting in each state, and a column we cannot read is a column we cannot count.

Because it is a marketing contact record rather than health data, and because you asked us specifically to email you when providers launch, a waitlist signup survives both health-data deletion and account deletion. Deleting it alongside your health data would silently break the thing you asked for. To come off a waitlist, email us at [email protected] and we will remove the record. The deletion confirmation screen says the same thing, in the same words.

Who we share it with

We never sell your health information. Not to anyone, for any price, in any form, including any de-identified or aggregated form.

We never share it with a compound vendor or supplier. No seller of any kind receives your intake, your uploads, your assessment, or anything derived from them. That is the same firewall that keeps commercial links off every page on this site.

The processing described in How your assessment is generated is the only transfer of your health information off our servers, and it exists to produce the assessment you asked for.

Beyond that, we disclose information only where the law requires it, and we keep the right to transfer account records to a successor if the business is ever sold or reorganised, under this same policy.

Email, consent, and campaign tags

There is exactly one marketing consent on this site, and it is the checkbox at signup offering occasional offers from partner suppliers. It is unchecked by default, it is never required, and consent is recorded only when you tick it yourself.

What that consent covers is narrow and worth stating precisely. It authorises us to send you offers using your contact details. It does not authorise sharing any health information. A consented contact carries no intake answers, no uploads and no assessment, and there is no mechanism on this site that could attach them. Ticking the box does not change how your health data is stored, shared, retained, or deleted. You can withdraw it by emailing [email protected].

Campaign tags. If you arrive from an ad, an email, or a link that carries campaign parameters, we keep the first set we see for your visit and attach them to your account or your waitlist signup, so we know which efforts are worth repeating. They describe where you came from, never anything about your health.

Analytics and cookies

We use Google Analytics 4 to understand which pages get read and which routes through the site work. It is the same measurement property RevivaGo's other sites use, so aggregate traffic across our properties is counted in one place. It records ordinary web analytics such as pages viewed, referring links, approximate location, device and browser. When you are signed in, it also records a one-way hashed identifier so a returning visit is not counted twice.

No intake answer, no uploaded file, and no part of your assessment is ever sent to analytics. We do not run advertising pixels or ad-retargeting tags on this property.

We use cookies for the things the site cannot work without: keeping you signed in, protecting forms against forgery, and remembering the campaign tags described above. The only other cookie is the analytics cookie set by Google. Your browser's own privacy settings and any tracker-blocking extension you use will block the analytics cookie without affecting anything else on the site.

Backups

Deletion removes your data from the live system immediately. Encrypted backups of the database and storage are kept for operational recovery, and deleted data leaves those backups as they roll off on the standard backup schedule. We do not restore deleted health data from a backup into the live system.

Your choices and how to reach us

  • Read without an account. Every research page on this site is public. The intake is optional.
  • Skip any step. Blood-work upload is optional, the free-text box is optional, and you can leave the intake unfinished.
  • See what we hold. Your intake is visible to you inside the Stack Builder whenever you are signed in.
  • Delete it yourself. Immediate, in-product, described above.
  • Ask us anything else by email. A copy of your data, a correction, deletion of your whole account, or removal from a waitlist.

Depending on where you live you may have additional rights over consumer health data, including the right to confirm what we hold, to obtain a copy, to have it deleted, and to withdraw a consent you previously gave. Exercising them costs nothing and we will not treat you differently for it. Email [email protected] and we will respond within the time your state's law allows.

The Stack Builder is for adults. We do not knowingly collect health information from anyone under 18; if you believe we have, email us and we will delete it.

Changes to this policy

When this policy changes we update the date at the top of the page. We hold ourselves to a stricter rule internally: no promise appears on this page unless something in the software actually enforces it, so a change here is a change to how the site works, not a change of wording.