1. What PepRep stores on your device
PepRep may store the vial details, plans, reminders, dose and event history, notes, injection sites, progress records, settings, and safety acknowledgements that you enter. This information is stored in the app's local storage. In the native iOS and Android apps, those records are encrypted at rest with a randomly generated key protected by the device Keychain or Keystore. Browser storage is protected by your browser and operating-system account, so use the web app only on a device you trust. Records are not automatically synced.
2. No advertising or behavioural analytics
PepRep does not include advertising SDKs and does not use behavioural analytics to build profiles or sell information. The optional Ask feature is disabled in the version 1 build.
3. Optional encrypted cloud backup
If you choose cloud backup, PepRep creates a password-encrypted backup on your device and uploads the ciphertext to PepRep's private Supabase project. The password and derived encryption key never leave your device. Supabase stores your passwordless account email, an internal user identifier, the encrypted file, and manifest metadata such as file size, checksum, format version, and creation time. The selected project region is Singapore (ap-southeast-1).
Cloud backup is optional, manual, and not live sync. PepRep cannot recover a forgotten backup password or inspect the content of a password-encrypted backup.
4. Notifications, exports, and files
Reminders are scheduled locally by your device. Plaintext CSV and JSON exports are unencrypted and leave PepRep only when you choose where to share them. Local encrypted backup files leave the app only when you save or share them yourself.
5. Your choices and deletion
- Use Settings → Erase all data to remove records stored by PepRep on the device.
- Delete individual encrypted cloud backups from Settings.
- Use Delete cloud account in Settings to permanently remove the Supabase account, its encrypted backup files, and backup manifests. Local records remain until you erase them.
- Delete exports or backup files you previously saved in other apps or storage services.
6. Security and service providers
Supabase provides optional authentication, database, and encrypted-object storage. Access is restricted with row-level security and private storage policies. Session tokens are stored using the iOS Keychain or Android Keystore through Expo SecureStore. No system is risk-free, so keep your device secure and use a strong, unique backup password.
7. Medical information and children
PepRep is a measurement and personal record-keeping tool, not a healthcare provider. It is not directed to children. Do not use it to store another person's information without appropriate authority and consent.
8. Changes and support
Material changes will be reflected by the date above. For technical support or a privacy concern, visit the PepRep support page. Do not post personal health information in a public support request.