Skip to content
PeptideAgent

Privacy policy

PeptideAgent is built to work without knowing who you are. There are no reader accounts and no advertising or analytics trackers, and the agent keeps questions only without names, IP addresses, or other identifiers. This page explains what little we handle and why.

Last updated

What does this policy cover?

The PeptideAgent website, including the agent, the provider directory, the clinician tools, the public API, and the forms. "PeptideAgent", "we", and "us" mean the organization that runs the site. Sites we link to have their own policies. The terms of use also apply.

What do we collect, and when?

Most of the site collects nothing from you. Information reaches us only in these cases.

Reading pages

Pages load no advertising or analytics scripts and no tracking pixels, fonts are served from our own domain, and our code sets no cookies while you read. Our hosting provider, Vercel, receives standard request data, such as your IP address, browser user agent, and the address requested, and keeps request logs under its own policies. Each page also loads Vercel BotID, a bot check run by Vercel from our own domain; it is described under asking the agent below, and it sets no cookies.

Asking the agent

Your question goes to our server, which answers it from the cited records in our database (see the methodology). No AI model or outside service writes any part of an answer. To limit abuse, Vercel's firewall and our server count requests per IP address for a short window, and Vercel BotID runs a short check in your browser that tells our server whether the request looks automated. BotID sets no cookies and stores nothing in your browser.

To see what people ask and which questions the site cannot answer yet, we save the text of each question with the date it was asked (the day, not the time) and what the agent made of it: the peptides, states, and topics it recognized, whether it found a sourced answer, and the pages it pointed to. We also note three facts about the request: whether the question was typed, sent from an example button, asked as a follow-up, or sent from the search in the header; whether BotID judged it automated; and whether it came from this site's own pages. A follow-up that names no peptide is sent with the subject of the answer above it, shown in brackets after your question. Before saving, email addresses, phone numbers, web addresses, dates, and long numbers are removed from the text. We never save your IP address, browser user agent, cookies, or any account or device identifier with it, so a saved question cannot be linked back to you. The questions are stored with our database provider, Supabase, kept for up to 90 days, and used only to improve answers and decide what to write next. Please leave names, dates of birth, and other personal details out of your questions.

Searching

As you type in the agent box or the search in the header, suggested pages come from a list of page names your browser downloads once. The matching happens in your browser, so nothing you type is sent while you type. If you open a suggested page, we save what you had typed and the page you chose, handled like a question above: cleaned of personal details, dated by the day, never linked to you, and kept for up to 90 days.

Share links

Copy share link puts your question into the link, with any email address, phone number, or web address removed. Opening the link answers the question again from our current records, so the answer can differ from the one you saw if a record has changed since. We store nothing, but anyone with the link can read the question, so share it with care. Shared answer pages ask search engines not to index them.

Email alerts

If you subscribe, we collect your email address. When signups are switched on, we send it to beehiiv, our newsletter provider, with a tag naming the form you used. beehiiv then emails you a link to confirm, and your address joins the list only after you confirm. When signups are off, nothing is stored. To keep bots from signing up other people's addresses, the form uses a hidden field and Vercel BotID, which needs JavaScript; if either flags the signup, nothing is sent.

Applications, contact requests, and press requests

When these forms are switched on, submissions go to our internal intake. When they are off, nothing is stored, and the form points you to email or, for a contact request, the provider's website.

  • Provider applications: contact name, organization, provider type, state of primary license, license or permit number, website, and work email, used to verify the license and follow up.
  • Contact requests to a listed provider: your name, email, state, and an optional message. We note the provider and the directory page the request came from, and, with the consent the form asks for, pass your details to that provider so they can reach you. The form asks you to keep health details out.
  • Press requests: name, outlet, work email, topic, an optional deadline, and your question, used to answer you.

Every form uses a hidden bot field and short per-IP submission limits at Vercel's firewall and in our server's memory, and our code does not log what you submit.

Clinician verification

To open the clinician tools, you enter an NPI and a last name. We send only the NPI to the public NPPES NPI Registry run by the Centers for Medicare and Medicaid Services, and compare the last name on our server. A match with an active individual NPI sets the session cookie described below. We keep no database of clinicians, and medications typed into the interaction checker are used for that one request and not stored.

Public API

The API needs no account. To enforce its limit of 60 requests a minute per IP address, the server counts requests per IP address, or per API key once keys are issued, in working memory only.

Outbound and affiliate links

Affiliate placements are turned off today. If they are switched on, a sponsored link passes through a redirect on our site that records the time, the page and placement of the click, and the product clicked, with no IP address, browser details, or cookie. That record goes to our server logs and may be forwarded to our internal reporting. The destination address carries UTM tags and a sub ID naming the page the click came from.

What do we not collect?

  • No accounts or passwords. The only gate is the optional clinician NPI check.
  • No health records. We never ask for medical records, a medical history, or patient identifiers. A condition or medication you mention to the agent is used for that answer and may be kept, as part of the question text and without identifiers, in the query log described above.
  • No advertising or behavioral tracking. No analytics service, ad network, tracking pixel, or cross-site cookie runs on the site, and we build no visitor profiles.
  • No sale of personal information. We do not sell or rent it, and we share it with a listed provider only when you send that provider a contact request.

How do we use what we collect?

Only to run the feature you used: answering your question, sending the list you joined, handling an application, contact request, or press request, verifying a clinician, enforcing rate limits, and replying when you write to us. Saved agent questions, which carry no identifiers, are also used to improve answers and plan new pages. Never for advertising.

Who else processes it?

  • Hosting, firewall, and bot checks: Vercel, which keeps standard request logs, runs the firewall rate limits, and runs BotID.
  • Database: Supabase, which stores saved agent questions without identifiers.
  • Newsletter: beehiiv, when signups are switched on.
  • NPI lookups: the NPPES NPI Registry, which receives the NPI.
  • Listed providers: the provider you choose, when you send it a contact request.

Each handles data under its own terms and privacy policy. We may also disclose information when the law requires it.

Does the site use cookies or local storage?

Only for two functional purposes.

  • Theme. If you switch between light and dark mode, your choice is saved in your browser's local storage. It never leaves your device.
  • Clinician session. After a successful NPI check we set one cookie, pa_clinician, holding your NPI, the taxonomy (specialty) description from the registry, and the time it was issued. It is signed so any change is rejected, is HttpOnly so page scripts cannot read it, is sent only over secure connections, and expires after 30 days or when you sign out. Nothing about the session is kept on our servers.

We set no other cookies and use none for advertising or analytics.

How long do we keep it?

  • Agent questions and picked search suggestions: up to 90 days, stored with Supabase, without IP addresses or other identifiers.
  • Share links: not stored by us; the question lives in the link.
  • Rate limit counts: at Vercel's firewall and in server memory, for a short window.
  • Theme choice: in your browser until you clear site data.
  • Clinician session: in the cookie on your device, up to 30 days.
  • Email address: on the list until you unsubscribe. Write to us to have it deleted entirely.
  • Applications, contact requests, and press requests: only as long as needed to handle them, and deleted on request.
  • Hosting logs, firewall logs, and BotID checks: under Vercel's own policies.

What are my choices?

  • Use the site without giving us anything. The reference pages, the agent, the API, and the downloads need no account or email.
  • Unsubscribe with the link in any newsletter email.
  • Sign out of the clinician tools, or delete the cookie in your browser.
  • Write to hello@peptideagent.ai to ask what we hold about you, or to have it corrected or deleted. Often the answer is that we hold nothing.

Is the site meant for children?

No. PeptideAgent is not directed to anyone under 18, and we do not knowingly collect information from children. If you believe a child has sent us personal information, write to us and we will delete it.

Will this policy change?

When our practices change, we will update this page and the date at the top.

How do I contact PeptideAgent about privacy?

Email hello@peptideagent.ai with privacy questions and requests. Press: press@peptideagent.ai. See also the terms of use and the medical disclaimer.