N-of-1 Health — Privacy Policy
Effective date: 2026-07-16
Version: 0.1 — interim / pre-IRB
Applies to: Users of the N-of-1 Health mobile app and platform.
In short
N-of-1 Health, LLC ("N-of-1 Health," "we," "us") makes a mobile app that helps you track the peptides you choose to use — logging what you take, photographing the actual product, tracking metrics you care about, uploading your lab results, and getting reminders from an in-app assistant. You choose what to track, and you own the information you enter.
A few things we want to be clear about up front:
- This is observational. The app does not tell you what to take, how much, or when. It does not prescribe, diagnose, or give medical advice. It helps you keep track of what you decide to do and how you feel.
- We are not using your data for research right now. We are pursuing an independent ethics review (an IRB) for future observational research. Until that review is approved and in place, we do not use your information for research. If that changes, we will tell you and ask for your agreement first. (See "Research and the IRB.")
- We do not sell information that identifies you, and we never use your data for advertising. We want to be straight with you about our business model, though: in the future, under IRB oversight and only if you agree, we may sell or license de-identified research data — information stripped of anything that could reasonably tie it back to you — to research or commercial partners. We're telling you this now so it's never a surprise later. (See "Research and the IRB" and "De-identified data.")
This policy explains, in plain language, what we collect, how we use and protect it, who can see it, and the choices you have.
What we collect
- Peptide logs and photos. What you take, when you take it, and — if you choose — a photo of the actual peptide, vial, or label. Photos may show product details; only add what you're comfortable storing.
- Metrics you track. The measures you choose to log (for example sleep, weight, mood, energy, side effects, or a custom metric you create), and any notes you add.
- Lab results you upload. Images or PDFs of bloodwork or other lab reports, if you choose to upload them. This is sensitive health information; you decide whether to add it.
- Health and device data you connect (optional). If you connect Apple Health / HealthKit or a wearable, relevant data such as sleep, activity, or heart rate. Connecting is optional and you can disconnect at any time.
- Account information. The email address and credentials used to create and secure your account.
- Limited technical and usage information. Basic device and app-usage information needed to operate the app, keep it secure, and fix problems.
You choose what to enter. You do not have to log everything, and you can leave out anything you'd rather not store.
How we use your information
We use your information to:
- provide and operate the app — store your logs, photos, metrics, and labs, show you your own history and charts, and let you manage your account;
- power the in-app assistant, including adaptive reminders tuned to your usage and metrics you ask it to help build;
- maintain, secure, support, and improve the app;
- communicate with you about the service (for example reminders or support);
- meet our legal obligations.
We do not use your information to make medical decisions for you. The app organizes and summarizes what you enter; what you take and what you do about your health is up to you (and, if you have one, your own healthcare provider).
We do not use your information for research except as described in the next section.
Research and the IRB
We are building N-of-1 Health so that, in the future, de-identified information from many users could support observational research — studying patterns in how people use peptides and what they experience — under the oversight of an Institutional Review Board (IRB), an independent committee that reviews research to protect the people in it.
Part of our business model is to make this research data available to partners. Once the IRB is in place, and only with your consent, we plan to share, license, or sell de-identified research data (data that cannot reasonably be used to identify you — see "De-identified data") to research institutions and commercial partners. Selling data that identifies you is not part of our plan, and we do not do it. We're stating this plainly so that our "we don't sell information that identifies you" promise and our actual business model are consistent, and so nothing about how we make money is hidden from you.
That research use is not happening yet. As of the effective date above:
- We have not received IRB approval for research use of your data.
- We do not use, share, or sell your information for research. We use it only to run the app and provide the features described above.
- If and when the IRB approves an observational study, we will update this policy and ask for your agreement (informed consent) before any of your information is used, shared, or sold for research. Taking part will be voluntary, and you'll be able to use the app without taking part.
De-identified data
"De-identified" means information that does not identify you and cannot reasonably be used to identify you. We handle de-identified information in two distinct ways:
- Now, to run and improve the app. We may use de-identified information to operate, secure, evaluate, and improve the app. We do not sell or license de-identified data for this purpose.
- Later, as research data (gated behind the IRB and your consent). Once the IRB is in place and only if you agree, we may share, license, or sell de-identified research data to research and commercial partners, as described in "Research and the IRB." This is how we intend to support the work financially.
In all cases, the data must be genuinely de-identified before it leaves our systems for a partner, we do not attempt to re-identify it, and we require partners not to attempt to re-identify it either.
Who can see your information
- You.
- N-of-1 Health staff who need access to operate and support the app, under confidentiality obligations and least-privilege access.
- Service providers (sub-processors) we use to run the app. They process your information only to provide their services to us, under their data-processing terms, and may not use it for their own purposes. Current providers include:
- Railway (cloud hosting and database) — stores your account and the health information you enter, in a managed PostgreSQL database. The database runs with encryption at rest at the storage layer, and all traffic between the app and our servers is encrypted in transit (TLS). We have a signed data-processing agreement with Railway, which contractually limits Railway to processing your data only on our instructions and bars it from using your data for its own purposes.
- Anthropic (AI assistant) — when you use the in-app assistant, the messages you send it (and relevant context) are processed by Anthropic's models to generate a response. Anthropic processes this as our service provider under its commercial terms and data-processing agreement, and does not use your inputs or the assistant's outputs to train its models.
- Expo / EAS (mobile app build and delivery) — the toolchain we use to build the app and deliver it (and any over-the-air updates) to your device. In normal use Expo/EAS handles app build artifacts and update delivery, not the health information you enter — that goes to our own database, not to Expo. It may receive limited technical information tied to builds or updates (for example update-delivery and basic diagnostic data).
- Secure file storage for photos and lab uploads — peptide photos and lab-result files are stored in encrypted, access-controlled file storage. These files are kept encrypted and access-restricted, separate from where they are displayed to you.
- Apple — because the app is distributed through Apple (App Store / TestFlight), standard app-store, device, and diagnostic information may be handled by Apple under its own terms. If you connect Apple Health, that data flows from your device into the app under the permissions you grant, and you can revoke it in iOS settings at any time.
We may also disclose information if required by law, or to protect the rights, safety, and security of our users or N-of-1 Health.
We do not sell information that identifies you, share it with advertisers, or use it for advertising or marketing unrelated to the service. (Our plan to sell de-identified research data, post-IRB and with your consent, is described in "Research and the IRB" and "De-identified data.")
How we protect your information
Your information is stored using industry-standard administrative, technical, and physical safeguards, including encryption in transit and at rest, with access limited to people and systems that need it. Sensitive files such as lab uploads and peptide photos are stored encrypted with restricted access. N-of-1 Health is directly responsible for protecting your information and for limiting how it may be used.
No system can be guaranteed to be perfectly secure. As with any digital tool that handles health information, there is some risk to data privacy, which is why we limit what we collect, encrypt what we store, and restrict who can access it.
Your choices and rights
- Voluntary use. Using the app is voluntary. You can stop logging, disconnect Apple Health / a wearable, or stop using the app at any time, for any reason.
- Access and correction. You can ask to see the information we hold about you and ask that it be corrected.
- Deletion. You can delete individual entries, and you can ask us to delete your account and associated data. Some information may need to be retained where required by law or for a legal hold.
- Withdrawal. Because no research is happening pre-IRB, there is nothing to withdraw from today. Once research is live under the IRB, you'll be able to decline or withdraw from research separately from your general use of the app.
- How to exercise these rights. Contact us using the details below.
How long we keep your information
We delete identifiable data within 30 days after you delete your account or request deletion, except where law requires retention or for a legal hold.
Children
The app is intended for adults (18+) only. It is not directed to children, and we do not knowingly collect information from anyone under 18.
Changes to this policy
If we make material changes to how we handle your information — including any change related to research use once the IRB is in place — we will update this policy and, where appropriate, let you know through the app. The "Effective date" above shows when this version took effect. Material changes affecting research use will be accompanied by a request for your consent, as described in "Research and the IRB."
Contact us
Questions about the app or your data, or to exercise your rights: support@joinnof1.com