Peptides Academy Education Courses Blogs Leaderboard Pricing

Privacy Policy

How we collect, use, and protect your information

Last updated: August 24, 2026

Introduction

Peptides Academy is the trade name under which FNA Enterprise LLC, a Florida limited liability company (Florida fictitious name registration G26000059170), operates the Peptides Academy service. In this privacy policy, "FNA Enterprise LLC," "Peptides Academy," "we," "us," or "our" all refer to the same entity. This privacy policy explains how we collect, use, disclose, and safeguard information when you visit our websites (peptidesacademy.co and peptidesacademy.shop), use the Peptides Academy mobile application built with Expo and React Native (the "mobile app"), or otherwise use our services.

Some practices described below apply only to the websites or only to the mobile app. We identify those differences where they matter. By accessing or using our platform, you acknowledge this policy. If you do not agree, please discontinue use of the service.


Information We Collect

Account information

When you create an account, we collect your email address, username, and authentication information. Authentication is handled by Supabase. We do not receive or store your password in plaintext. The mobile app stores its signed-in session token in operating-system protected secure storage so you can remain signed in. You can create an account with an email address and password, or by signing in with Google or with Apple. If you sign in with Apple and choose to hide your email address, Apple gives us a relay address ending in @privaterelay.appleid.com instead of your own; we treat that relay address as your email address.

Profile and community information

Peptides Academy includes community surfaces: a leaderboard, available on our websites and in the mobile app, and a friends list. You can set a display name, a username, and a profile image, either by choosing one of the images bundled with the app or by entering the web address of an image. Your display name, username, profile image, level, XP, current streak, achievement count, completed unit count, and founding-member badge are visible to other signed-in learners on the leaderboard, in member search, and through friend requests and friends lists. A shortened leaderboard is also visible to people who are not signed in: it shows the top ten learners' display names, the first letter of their usernames, and the same XP, level, streak, achievement, unit, and founding-member values. Your email address is never shown to other learners, and other learners cannot find you by email address. There is no messaging between learners. A display name, username, and profile image are optional, you can change them at any time in your profile settings, and deleting your account removes them.

Reports and blocks

The mobile app lets you report an AI chatbot answer or another learner's profile, and lets you block another learner. When you file a report, we record who filed it, the account reported (a chatbot answer has no author account, so that field is left empty), which surface the report came from, the reason you selected, and an excerpt of the reported content of up to 2,000 characters. Filing a report about a learner also blocks that learner. When you block a learner, we record the block. Reports and blocks are stored on our servers so that a person can review a report and so that a block applies to your account wherever you sign in.

Purchase information

Website purchases are processed by Stripe. Mobile-app purchases, where they are offered, are processed by the app store that delivered the app: Google Play Billing on Android and Apple's in-app purchase system on iOS. We do not receive or store your complete card number, bank-account details, or the payment credentials held by either app store. We receive transaction information needed to validate access and support purchases, which may include the product identifier, purchase token or transaction identifier, order information, subscription status, and expiration time, and we associate that information with your Peptides Academy account. We also send the app store a pseudonymous token derived from your account identifier by a one-way hash, so that a purchase can be matched to the right account. We send the app store nothing else about you: no email address, no name, and no learning progress.

Mailing list and quiz funnel data

When you interact with our landing page quiz funnel or subscribe to our mailing list, we collect your email address, self-reported knowledge level, and peptide interest area. This information is used to personalize your experience and send relevant educational content.

Quiz and exercise data

We collect and store quiz attempts, scores, completion status, and exercise results associated with your account. This data is used to track your learning progress, generate certificates, calculate XP and achievements, and improve our educational content.

AI chatbot data

When you use our AI chatbot feature, Blorb (powered by Anthropic's Claude API), we process the messages you submit. Your message and up to the last ten turns of the conversation are sent to our server, which forwards them to Anthropic as our AI provider so that a reply can be generated. They are subject to Anthropic's privacy policy, and we do not grant Anthropic permission to train its models on your messages. We do not send Anthropic your account identifier, email address, or name alongside the request.

We do not store the text of your chatbot messages or of the chatbot's replies. For each request we record technical information only: your account identifier, your IP address, which model answered, an outcome status and error category, whether a safety filter applied, response time, reply length, the number of internal document lookups, and whether the request was retried. There is one exception: if you report a chatbot answer, an excerpt of that answer of up to 2,000 characters is stored with your report so that a person can review it.

Chatbot use is rate-limited to prevent abuse, counted per account when you are signed in and per IP address when you are not. Signed-in learners without a chat subscription can send five chatbot messages per day; subscribers are not subject to that daily limit.

IP address

We collect your IP address for the purposes of chat rate limiting, security monitoring, fraud prevention, and compliance with applicable law. Separately, Meta and Microsoft receive advertising data after the applicable consent choice, while Reddit may receive an initial page-visit measurement before that choice and subsequent conversion data unless you decline or opt out. This is described in the "Meta Pixel and Conversions API", "Reddit Pixel and Conversions API", and "Microsoft Advertising (Universal Event Tracking)" sections below. You can suppress subsequent advertising sharing using the "your privacy choices" link in the footer of every page.

Referral data

If you participate in our referral program, we collect referral codes and track referral relationships between users. This data is used to administer the referral program and award applicable benefits.

Community sentiment data

We aggregate publicly available data from public Reddit posts and other public forums to compute community sentiment ratings for peptides discussed on our platform. No personally identifiable information (PII) is collected in this process. Sentiment data reflects aggregated public opinion and is not derived from user accounts on our platform.

Usage data

On the websites, browser localStorage may hold learning progress, quiz scores, preferences, and purchase status. In the mobile app, operating-system protected secure storage holds authentication and onboarding state, while app-private cache storage may hold downloaded course content, catalog data, and progress snapshots needed for faster or offline-tolerant loading. Account progress and entitlements are also transmitted to and stored in Supabase when you sign in; the local copy is not the authoritative billing record.

Mobile experiment and product analytics

The mobile app uses limited first-party analytics to compare onboarding designs and understand whether people complete onboarding, view membership options, start checkout, encounter a broad purchase outcome, continue with limited access, or begin a first lesson. The app creates a random app-scoped identifier and random session identifier for this purpose. These identifiers are not advertising identifiers and are not linked to your Peptides Academy account, email address, or username. Analytics requests use the app's public project credential and do not forward your signed-in account session token.

The accepted analytics fields are restricted to a fixed list: experiment and app version, assigned onboarding variant, generic screen name and step number, annual or monthly plan selection, whether store billing and an annual trial were shown as available, a low-detail action source or outcome category, platform, build number, and event timestamps. We do not collect your selected peptide topic, knowledge level, onboarding or claim-check answer, course or peptide identifier, quiz answer, free text, URL, receipt, price, raw error message, email address, username, account identifier, or advertising identifier in this analytics system.

Analytics transmission begins only after you confirm that you are 18 or older and is then on by default. You can turn it off at any time under settings & legal > anonymous app analytics. Turning it off stops future collection and sends a device-held deletion capability that deletes the random identifier's experiment assignment and stored events. The service retains only one-way suppression hashes of the erased random identifier and deletion capability so delayed uploads cannot recreate the deleted record; these hashes contain no event data and are not used for analytics. If you later turn analytics back on, the app creates a new random identifier and deletion capability while preserving your assigned onboarding design. Because this analytics identifier is not linked to your account, deleting your account alone does not identify that separate anonymous record; use the analytics switch or contact us if you also want it erased. Request infrastructure may process an IP address transiently for abuse prevention, but the experiment database receives only a short-lived, rotating keyed hash rather than the raw address.

Mobile notification data

If you grant notification permission, the mobile app can schedule study, streak, quest, credit, and trial reminders on your device. The reminder content and timing are scheduled locally by the app. Peptides Academy does not currently store a mobile push token in its database or send server-originated push notifications. You can disable notifications in your device settings.

Automatically collected information

When you visit our websites or the mobile app connects to our APIs, our hosting and infrastructure providers may automatically collect standard request and security-log data, such as your IP address, device or browser type, requested resource, and timestamps. This data is used for security, abuse prevention, and performance purposes.


How We Use Your Information

We use the information we collect to:

  • Create and manage your account
  • Process purchases and grant access to paid content
  • Track your learning progress, quiz results, and exercise completion
  • Generate completion certificates
  • Communicate with you about your account or purchases
  • Schedule local mobile-app reminders when you grant notification permission
  • Send marketing and educational communications (if you have opted in)
  • Provide AI chatbot responses to your inquiries
  • Show your display name, username, and profile image to other learners on community surfaces
  • Review reports of chatbot answers and member profiles, and enforce blocks between accounts
  • Administer referral programs
  • Rate-limit chatbot usage and prevent abuse
  • Analyze website traffic and usage patterns via Google Analytics and Microsoft Clarity
  • Measure whether our educational advertising on Meta, Reddit, and Microsoft Advertising leads to signups and purchases
  • Compare mobile onboarding designs and improve the mobile signup and membership funnel using limited first-party analytics
  • Improve our platform and educational content
  • Detect and prevent fraud, abuse, or security incidents
  • Comply with applicable legal obligations

We do not sell your personal information for money. However, we share a limited subset of online-activity and identifier data with Meta (Facebook/Instagram), Reddit, and Microsoft Advertising for ad-attribution measurement and educational-content retargeting. Meta and Microsoft sharing follows the applicable consent choice; Reddit may receive an initial page visit before that choice and subsequent events unless you decline or opt out. Because this is disclosure to advertising networks for cross-context behavioral advertising, it qualifies as "sharing" (and may be treated as a "sale") under the California Consumer Privacy Act as amended by the CPRA. See the advertising-platform sections below for the exact data shared and how to opt out. You can suppress subsequent sharing at any time using the "your privacy choices" link in the footer, and we honor Global Privacy Control browser signals as a valid opt-out before loading advertising pixels.


Third-Party Services

We use the following third-party services to operate our platform:

Google Analytics

We use Google Analytics (measurement ID: G-J16JDD67M2) to analyze website traffic and usage patterns. Google Analytics sets tracking cookies on your device (including _ga and _gid cookies) that collect information such as your IP address, browser type, pages visited, time spent on pages, and referring URLs. This data is used to understand how visitors interact with our platform so that we can improve our content and user experience. Google may use this data in accordance with Google's privacy policy. You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on.

Microsoft Clarity

We partner with Microsoft Clarity to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay so we can improve our product. Website usage data is captured using first-party and third-party cookies and other tracking technologies to determine the popularity of products and online activity. This information is also used for site optimization, fraud and security purposes. Clarity does not collect any text you enter into form fields, and we have masking enabled to suppress sensitive content by default. For more information about how Microsoft collects and uses your data, see the Microsoft Privacy Statement. You can opt out of Microsoft Clarity by declining analytics cookies in our cookie banner, or globally via the Digital Advertising Alliance opt-out page (select Microsoft).

Meta Pixel and Conversions API

We use the Meta Pixel (a small browser script from Meta Platforms, Inc., the parent of Facebook and Instagram) and the Meta Conversions API (server-to-server event reporting) to measure how well our educational ads perform. These tools help us understand which ads led you to our courses so we can spend our advertising budget on what actually works. We do not use these tools to advertise peptide products, dosing, sourcing, treatments, or outcomes, our ads promote peptide-science education only.

Data shared with Meta: a hashed (one-way SHA-256 transformed) version of your email address, your IP address, your browser user-agent, the URL you visited, the page-load and any purchase event with its dollar amount and a generic course identifier (e.g., "ghk-cu"), and Meta's own first-party cookies (`_fbp`, `_fbc`) if present. We do not send peptide-content beyond the generic course identifier, health claims, dosing data, lab results, signup-form answers, quiz answers, or any other sensitive information.

Consent and gating: for visitors in the European Economic Area, the United Kingdom, and Switzerland, the Meta Pixel only loads after you affirmatively accept advertising cookies in our cookie banner. For visitors outside those regions the pixel may load by default, and you can opt out at any time via the "your privacy choices" link in our footer. Server-side Conversions API events fire only for actions you knowingly initiate (signing up, purchasing) and use the same consent state. If your browser sends a Global Privacy Control signal, the pixel never loads and no Meta sharing occurs.

Opt out: you can withdraw consent at any time using the "your privacy choices" link in the footer of every page. Opening it lets you turn off analytics and advertising cookies (including the Meta Pixel and Conversions API), which flips your stored consent to declined, revokes Google analytics/ad consent, and stops further pixel loading; this applies even if you previously accepted. You can also decline cookies in our banner, or set Meta's Ad Settings to limit ad personalization. For full details on how Meta processes data, see Meta's Privacy Policy and the Meta Pixel privacy notice.

Reddit Pixel and Conversions API

We use the Reddit Pixel (a small browser script from Reddit, Inc.) and the Reddit Conversions API (server-to-server event reporting) to measure how well our educational ads on Reddit perform, so we can spend our advertising budget on what actually works. We do not use these tools to advertise peptide products, dosing, sourcing, treatments, or outcomes, our ads promote peptide-science education only.

Data shared with Reddit: a hashed (one-way SHA-256 transformed) version of your email address, a hashed account identifier, your IP address, your browser user-agent, the Reddit ad click identifier (`rdt_cid` / `_rdt_cid`) if present, the page-visit event, a course-view or add-to-cart event carrying a generic course identifier (e.g., "ghk-cu") and its dollar amount, a lead event if you join our mailing list (a bare signal that a signup happened, carrying a zero dollar amount and the currency (USD), and no email address from your browser), and any purchase event with its dollar amount and a generic course identifier. We do not send peptide-content beyond the generic course identifier, health claims, dosing data, lab results, signup-form answers, quiz answers, or any other sensitive information.

Consent and gating: the Reddit Pixel may load and send an initial page-visit measurement before you make a cookie-banner choice. Choosing decline or opting out through "your privacy choices" suppresses subsequent Reddit Pixel events. Server-side Conversions API events fire only for actions you knowingly initiate (signing up or purchasing) and use the recorded consent state. If your browser sends a Global Privacy Control signal, the pixel never loads and no Reddit sharing occurs.

Opt out: you can stop subsequent Reddit Pixel and Conversions API events at any time using the "your privacy choices" link in the footer of every page. You can also send a Global Privacy Control browser signal, which prevents the Reddit Pixel from loading. For details on how Reddit processes data, see Reddit's Privacy Policy.

Microsoft Advertising (Universal Event Tracking)

We use Microsoft Advertising's Universal Event Tracking tag (UET, a small browser script from Microsoft Corporation) to measure how well our educational ads on Bing and the Microsoft Advertising network perform, so we can spend our advertising budget on what actually works. We do not use this tool to advertise peptide products, dosing, sourcing, treatments, or outcomes, our ads promote peptide-science education only.

Data shared with Microsoft: your IP address, your browser user-agent, the URL you visited, Microsoft's own first-party UET cookies (`_uetsid`, `_uetvid`), the Microsoft ad click identifier (`msclkid`) if you arrived from a Microsoft ad, a page-load event for each page you view, a lead event if you join our mailing list (a bare signal that a signup happened, carrying no email address and no other data), and, if you complete a purchase, a purchase event carrying its dollar amount, the currency (USD), and the Stripe transaction identifier. We do not send your email address in any form (hashed or otherwise), peptide names, course identifiers, health claims, dosing data, lab results, signup-form answers, quiz answers, or any other sensitive information. We share a narrower set of data with Microsoft than with Meta or Reddit: no email address and no course identifier.

Consent and gating: for visitors in the European Economic Area, the United Kingdom, and Switzerland, the UET tag only loads after you affirmatively accept advertising cookies in our cookie banner. For visitors outside those regions the tag may load by default, and you can opt out at any time via the "your privacy choices" link in our footer. We do not use Microsoft's "consent mode", which would load the script before your choice and report a denied signal. If the recorded consent state is anything other than accepted, the script is never loaded, no UET cookies are set, and no data reaches Microsoft. If your browser sends a Global Privacy Control signal, the tag never loads and no Microsoft advertising sharing occurs.

Opt out: you can withdraw consent at any time using the "your privacy choices" link in the footer of every page, which stops the tag from loading on subsequent page views. You can also decline cookies in our banner, send a Global Privacy Control browser signal, or limit ad personalization in Microsoft's ad settings. For details on how Microsoft processes data, see the Microsoft Privacy Statement.

Supabase

Provides authentication, database, and serverless-function services for the websites and mobile app. Your email, username, learning progress, entitlements, and other account data are stored on Supabase's infrastructure, which is hosted on servers located in the United States. See Supabase's privacy policy for details.

Stripe

Handles payment processing for purchases made on our websites. When you make a website purchase, you interact with Stripe's secure payment infrastructure. See Stripe's privacy policy for details.

Google Play

Handles Android mobile-app subscription checkout, payment credentials, renewal, cancellation, and applicable refund workflows. Google sends us limited purchase and subscription data so we can validate and provide access; it does not send us your complete payment-card details. See Google's privacy policy for details.

Apple

Handles iOS mobile-app in-app purchase checkout, payment credentials, renewal, cancellation, and applicable refund workflows, and provides the Sign in with Apple option. Apple sends us limited purchase and subscription data so we can validate it and grant access; it does not send us your complete payment-card details. If you use Sign in with Apple and hide your email address, Apple operates the relay that forwards our mail to you. See Apple's privacy policy for details.

Expo

Provides mobile-app build, update-delivery, and on-device notification-scheduling infrastructure. When the mobile app checks for or downloads an update, Expo may process technical request data such as app version, platform, IP address, and device or installation identifiers. The current mobile app does not request or store an Expo push token and does not use Expo to send server-originated push messages. See Expo's privacy policy for details.

Cloudflare

Provides hosting, CDN, and security services. Cloudflare may collect standard web analytics data. Content is distributed via Cloudflare's global content delivery network. See Cloudflare's privacy policy for details.

Resend

We use Resend (Resend, Inc.) as our email delivery service provider to send transactional emails (such as account, purchase, and security notifications) and, where you have opted in, educational and marketing emails. To do this, Resend processes your email address and related email-engagement events (such as deliveries, opens, and clicks). See Resend's privacy policy for details.

Anthropic

Our AI chatbot feature uses Anthropic's Claude API. When you submit messages to the chatbot, your messages are transmitted directly to Anthropic for processing as our AI provider. We do not grant Anthropic permission to train its models on your messages. See Anthropic's privacy policy for details.

Google Fonts

We load the Inter typeface from Google Fonts. This may result in your browser making requests to Google's servers. See Google's privacy policy for details.


Cookies and Device Storage

Cookies

We use the following types of cookies:

  • Essential cookies: our authentication provider (Supabase) sets session cookies to maintain your login state. These cookies are strictly necessary for the service to function.
  • Analytics cookies: Google Analytics sets tracking cookies (including _ga, _gid, and related cookies) to collect anonymized usage data about how visitors interact with our platform. The _ga cookie persists for up to 2 years; the _gid cookie persists for 24 hours. Microsoft Clarity sets first-party cookies (including _clck and _clsk) to enable session replay and heatmaps; _clck persists for up to 1 year, _clsk for 1 day.
  • Advertising cookies and identifiers: Meta's `_fbp` and `_fbc` cookies, Reddit's `_rdt_cid` click-id cookie, and Microsoft's `_uetsid` and `_uetvid` UET cookies may be used for ad measurement and attribution. The `_uetsid` session cookie expires after 24 hours and the `_uetvid` visitor cookie persists for up to 13 months; both are set by Microsoft's tag, and only after the applicable consent choice. Our first-party code writes the Meta and Reddit click-id cookies only after consent, while Reddit's pixel may independently receive an initial page visit before the banner choice. Advertising identifiers are not initialized when your browser sends a Global Privacy Control signal.
  • Consent management: Google Analytics, Microsoft Clarity, Meta, Microsoft Advertising (UET), and first-party optional analytics retain the geo-gated consent behavior described above. The Reddit Pixel is an exception: it may send an initial page visit before the banner choice. Declining or using "your privacy choices" suppresses subsequent Reddit events, and Global Privacy Control prevents the pixel from loading.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using certain features of the service. You can opt out of Google Analytics cookies specifically by using the Google Analytics Opt-out Browser Add-on.

The cookie, website analytics, session-replay, and advertising-pixel practices above apply to our websites. The native mobile app does not use browser cookies, Google Analytics, Microsoft Clarity, Meta Pixel, or Reddit Pixel.

Local storage

We use browser localStorage to store:

  • Your theme preference (dark or light mode)
  • Learning progress and quiz scores
  • Purchase unlock status
  • Gamification data (XP, streaks, achievements)
  • Cookie consent status
  • A persistent anonymous visitor identifier (`pa_visitor_id`) used to link your first-party site activity across visits and, if you create an account, to your account
  • Marketing attribution data for the source of your visit: UTM campaign parameters and ad click identifiers, including Meta's `fbclid`, Google's `gclid`, Reddit's `rdt_cid`, and Microsoft's `msclkid`. The Microsoft click identifier is stored only in this first-party record on your device; we do not write a separate cookie for it

This website data is stored on your device and can be cleared through your browser settings.

Mobile app storage and cache

The mobile app uses operating-system protected secure storage for account session tokens, onboarding state, a random experiment identifier, and the random deletion capability used to erase that experiment data. It also uses app-private cache storage for downloaded educational content, queued privacy-bounded analytics events, and temporary or stale-while-revalidate copies of account, catalog, progress, and course data. This improves startup speed and limited offline continuity. Account data may still be synchronized with Supabase as described above. You can remove on-device copies by clearing the app's storage in your device settings or uninstalling the app, subject to your operating system's backup and restore behavior.


Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Consent: we process your data based on your consent for marketing communications (including mailing list subscriptions and quiz funnel opt-ins), and for optional analytics and advertising cookies (including Microsoft Clarity, the Meta Pixel, and the Microsoft Advertising UET tag), which load only after you accept them in our cookie banner. You may withdraw your consent at any time by clicking "unsubscribe" in any email, using the "your privacy choices" link in the footer, or contacting us.
  • Contractual necessity: we process your data as necessary to perform our contract with you, including creating and managing your account, processing purchases, granting access to paid content, tracking learning progress, and generating certificates.
  • Legitimate interest: we process data based on our legitimate interests for site analytics (Google Analytics), limited first-party mobile product analytics, security monitoring, fraud prevention, rate limiting, service improvement, and aggregating community sentiment data from public sources. Our legitimate interests do not override your fundamental rights and freedoms, and the mobile analytics control described above lets you object and erase that app-scoped analytics record.
  • Legal obligation: we may process your data to comply with applicable legal obligations, such as tax reporting, responding to lawful requests from public authorities, or complying with court orders.

International Data Transfers

Your personal data is stored and processed in the United States. Specifically:

  • Supabase: our primary database and authentication provider hosts data on servers located in the United States (us-west-1 region).
  • Cloudflare: content is distributed via Cloudflare's global content delivery network (CDN), which may cache and serve content from servers located in various countries.
  • Stripe: payment processing is handled by Stripe, which processes data in the United States and other jurisdictions.
  • Google: website analytics and Google Play transaction data are processed by Google in the United States and other jurisdictions.
  • Anthropic: AI chatbot data (via Anthropic's Claude API) is processed by Anthropic in the United States and other jurisdictions.
  • Microsoft: Microsoft Clarity session and heatmap data, and Microsoft Advertising (UET) ad-measurement data, are processed by Microsoft in the United States and other jurisdictions.
  • Expo: mobile update-delivery and notification-token infrastructure may process technical request data in the United States and other jurisdictions.

If you are located outside the United States (including in the EEA, UK, or Switzerland), your personal data will be transferred to and processed in the United States, which may not provide the same level of data protection as your jurisdiction. By using the service, you consent to this transfer. Where required by applicable law, we rely on appropriate safeguards for such transfers, including standard contractual clauses adopted by the European Commission.


Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access - request a copy of the personal data we hold about you
  • Correction - request correction of inaccurate data
  • Deletion - request deletion of your personal data and account
  • Portability - request your data in a portable format
  • Opt-out - opt out of any marketing communications

You can delete a signed-in account in the mobile app under settings, use our account deletion page, or contact us at contact@peptidesacademy.co to exercise these rights. Deleting an account does not cancel a Google Play subscription; cancel it separately in Google Play subscriptions to stop future renewals. We will respond to other privacy requests within 30 days (or such shorter period as may be required by applicable law).

You can separately stop and erase mobile experiment analytics under settings & legal > anonymous app analytics. This control does not require an account.


European Residents (GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following additional rights under the General Data Protection Regulation (GDPR) and equivalent local laws:

  • Right to object - you may object to our processing of your personal data based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
  • Right to restrict processing - you may request that we restrict the processing of your personal data in certain circumstances (e.g., while we verify the accuracy of your data).
  • Right to withdraw consent - where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint - you have the right to lodge a complaint with your local data protection supervisory authority.
  • Right to data portability - you may request to receive your personal data in a structured, commonly used, and machine-readable format.

FNA Enterprise LLC acts as the data controller for the purposes of GDPR. Our contact information is: contact@peptidesacademy.co.


California Residents (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to know: you have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to delete: you have the right to request the deletion of personal information we have collected about you, subject to certain exceptions permitted by law (such as information needed to complete a transaction or comply with a legal obligation).
  • Right to correct: you have the right to request that we correct inaccurate personal information we maintain about you.
  • Right to opt-out of sale or sharing: you have the right to opt out of the "sale" or "sharing" of your personal information. We share limited identifiers and internet-activity information with Meta, Reddit, and Microsoft Advertising for cross-context behavioral advertising and attribution. You can suppress subsequent sharing using the "your privacy choices" link in the footer, and we honor Global Privacy Control signals before loading advertising pixels.
  • Right to non-discrimination: we will not discriminate against you for exercising your CCPA/CPRA rights.

Categories of personal information collected: identifiers (email, username, IP address, online and advertising identifiers), commercial information (purchase records), internet activity (browsing history, interactions with our site), and inferences (quiz results, learning progress).

Categories shared for cross-context behavioral advertising: we may share identifiers and internet-activity information, including page visits and conversion events, with Meta, Reddit, and Microsoft Advertising as described above. Declining or exercising the opt-out suppresses subsequent events; a Global Privacy Control signal prevents the advertising pixels from loading.

No monetary sale of personal information: FNA Enterprise LLC does not sell your personal information to third parties for monetary consideration, and we do not knowingly share or sell the personal information of consumers under 16 years of age. Our advertising-network sharing is described above and can be limited through our privacy controls.

How to opt out (two or more methods): we provide more than one designated method to opt out of the "sale" or "sharing" of your personal information: (1) the "your privacy choices" opt-out link in the footer of every page; (2) emailing us at contact@peptidesacademy.co; and (3) sending a Global Privacy Control (GPC) browser signal, which we automatically honor as a valid opt-out for the browser sending it. You do not need to create an account to exercise any of these.

Request metrics: FNA Enterprise LLC is a small business that does not buy, sell, or share the personal information of 10 million or more California consumers in a calendar year, so we are not required to compile or publish the annual consumer-request metrics described in 11 CCR 7102. We will provide information about requests we received on request where required by law.

To submit a CCPA/CPRA request, contact us at contact@peptidesacademy.co or use the "your privacy choices" link in the footer. We will verify your identity before processing your request and respond within 45 days.


Data Security

We implement reasonable technical and organizational measures to protect your personal information. Data transmission is encrypted via HTTPS/TLS. Authentication and password credential protection are handled through Supabase's secure infrastructure, and the mobile app stores session tokens in operating-system protected secure storage.

However, no method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.


Data Retention

We retain your personal data for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. Specific retention periods are as follows:

  • Account information (email, username, password hash): retained for as long as your account is active. Upon account deletion request, deleted within 30 days.
  • Purchase records: records we must retain are kept for up to 7 years after the transaction date for tax, accounting, fraud-prevention, and legal compliance. Google Play and Stripe retain their own transaction records under their policies.
  • Learning progress, quiz data, and exercise results: retained for as long as your account is active. Deleted upon account deletion.
  • Chat data and logs: we do not store the text of chatbot messages or replies. Chat request telemetry is kept for as long as necessary to operate, secure, and improve the chat feature, and the IP address recorded with a chat request is removed after 30 days. Daily chat usage counts, which include an IP address for signed-out use, are deleted after 30 days. Chatbot text is retained only where you have reported an answer, as part of that report.
  • Reports and blocks: a report and its content excerpt are kept for as long as necessary to review it, act on it, and identify repeated abuse. A report you filed is deleted when your account is deleted; a report filed about you is kept for review with your account identifier removed from it. A block is kept until it is lifted or either account is deleted.
  • IP address logs (for rate limiting and security): retained only for as long as necessary for rate limiting, security, fraud prevention, and legal-compliance purposes, after which they are deleted or de-identified in the ordinary course of business.
  • Google Analytics data: retained for 14 months in accordance with Google's data retention settings, after which it is automatically deleted.
  • Mobile experiment analytics: experiment events and their app-scoped assignments are automatically deleted after 90 days without activity, and are deleted sooner when you turn off anonymous app analytics in the mobile app. After erasure, one-way suppression hashes of the random identifier and deletion capability are retained solely to prevent delayed or replayed requests from recreating the deleted record; they contain no events and are not used for measurement.
  • Referral data: retained for as long as the referral program is active and your account exists.
  • Mailing list data: retained until you unsubscribe, at which point your email is removed from active mailing lists within 10 business days.
  • Certificates: retained indefinitely to allow verification, unless you request deletion.

If you request account deletion, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes as described above.

Website localStorage persists until you clear it or your browser data. Mobile-app secure storage and cache data persist until the app replaces them or you clear the app's storage or uninstall the app, subject to operating-system backup and restore behavior.


Children's Privacy

Our platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us and we will delete it.


Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated "last updated" date. Continued use of the platform after changes constitutes acceptance of the updated policy.


Contact Us

If you have questions about this privacy policy or our data practices, contact us at:

FNA Enterprise LLC d/b/a Peptides Academy
email: contact@peptidesacademy.co

Peptides Academy: your peptide academy for interactive learning. Making peptide science accessible through research-sourced content.

Courses Peptide education Blogs Browse peptides a-z Pricing Leaderboard Peptide basics Peptides & your body How peptides work Clinical evidence History of peptides Reconstitution calculator Privacy policy Terms of service Disclaimer Age suitability

© 2026 Peptides Academy. For educational purposes only. Not medical advice.