Privacy Policy
Effective July 26, 2026
This Privacy Policy explains how PineapplePeps accesses, stores, uses, shares, retains, and deletes information when you use the Android app.
At a glance
- PineapplePeps can be used without an account. Core tracking data is stored on your device. If Android system backup or device transfer is enabled, eligible local tracking data may also be backed up or transferred by Android; this is separate from PineapplePeps account sync.
- Google sign-in is optional. If you sign in, the app synchronizes the manual tracking data described below through Google Firebase.
- Health Connect access is optional and read-only. Imported Health Connect data stays in a separate database on your device and is excluded from Firebase sync, manual JSON exports, Android cloud backup, and Android device transfer.
- PineapplePeps does not contain advertising or analytics SDKs, and we do not sell personal or health data.
Data you enter
The app stores information you choose to enter so it can provide its tracking, charting, reminder, calculation, import, export, and reporting features.
- Peptide names and settings, including default dose, unit, frequency, half-life, time-to-peak, display color, visibility, order, and reconstitution presets.
- Injection logs, including peptide, dose, unit, date and time, injection site, side effects, and notes.
- Weight entries and notes.
- Daily water, protein, calorie, and note entries.
- Goals, display preferences, reminder schedules, and other app settings.
- CSV or JSON data you choose to import.
Optional account and cloud sync
If you choose Sign in with Google, Google and Firebase Authentication process your Google account identity to authenticate you. This may include your email address, name, profile information, authentication tokens, and a Firebase user identifier.
When signed in, PineapplePeps stores your peptides, injection logs, manually entered weights, daily logs, and app settings in Google Cloud Firestore under your Firebase user identifier. This is used only to back up and synchronize those records across your signed-in devices.
Imported Health Connect records are intentionally excluded from Firebase synchronization.
Optional Health Connect data
If you enable a Health Connect category and grant its Android permission, PineapplePeps reads the selected records so it can display health history, activity summaries, and charts alongside your tracking information. If you explicitly generate a report containing a weight chart or weight summary, the report may include imported Health Connect weight entries.
- Weight and body composition: weight, body fat, lean body mass, bone mass, and body water mass.
- Sleep: sleep sessions and stages.
- Activity: steps, exercise sessions, distance, and active calories burned.
- Record details: timestamps, units, source app, source device information, recording method, and Health Connect record identifier needed to display and de-duplicate records.
Optional bug reports
If you submit a bug report, PineapplePeps sends the report to Google Cloud Firestore and emails a copy to the PineapplePeps support inbox. A report includes the title, app area, description, steps, expected behavior, optional contact email, a randomly generated installation identifier, report reference, time submitted, and your Firebase user identifier if you are signed in.
Device diagnostics are off by default. If you explicitly select Include device diagnostics, the report also includes the app version, Android version, device manufacturer and model, locale, screen density, and whether you are signed in. Diagnostics do not include your tracking records or imported Health Connect records.
How data is used
- Provide the tracking, charting, reminder, calculator, import, export, report, Health Connect, and cross-device sync features you request.
- Authenticate signed-in users and keep each account's synchronized data separated.
- Investigate bug reports, respond when contact information is provided, protect the service, and maintain reliability.
- Comply with applicable law and enforce security when reasonably necessary.
Storage, backups, service providers, and sharing
Local data is stored in PineapplePeps databases and preferences on your Android device.
Android system backup and device transfer are separate from optional PineapplePeps account sync. When enabled in Android or device settings, Android may back up or transfer the PineapplePeps core tracking database, core app preferences such as display order and visibility, and reminder schedules. PineapplePeps excludes imported Health Connect records and preferences, along with other nonselected app and service state.
Manual Data Transfer creates a JSON copy only when you request it. The JSON includes peptides, injection logs, manually entered weights, daily logs, and core settings. It does not include Health Connect imports, reminders, device preferences, or account and sign-in information. You control where the exported JSON is copied, stored, or shared.
Optional sign-in and sync use Google Sign-In, Firebase Authentication, and Google Cloud Firestore. Optional bug reports use Cloud Firestore and an email delivery service. These providers may process technical service information, such as IP addresses, device or browser information, and security logs, under their own terms and privacy practices. See Google's Privacy Policy and Firebase privacy and security information.
PineapplePeps does not sell personal data, share data with advertising platforms or data brokers, or use Health Connect data for advertising, credit, or eligibility decisions. We may disclose information if required by law, to address fraud or security, or as part of a business transfer subject to appropriate safeguards.
The app can open third-party websites when you choose an external link. Those websites receive ordinary connection information and operate under their own privacy policies.
Health Connect commitments
- Access is requested only after you choose a category, and only for the data types needed for the visible feature.
- PineapplePeps reads but does not write or delete records in the Health Connect store.
- Health Connect data is used only to provide or improve user-visible health history, summaries, and charts.
- Health Connect data is not transferred to Firebase, included in bug reports, sold, or used for advertising. Health Connect weight may be included in a report you explicitly generate; PineapplePeps does not automatically send that report anywhere.
- You can revoke access at any time in Health Connect or Android settings. You can remove PineapplePeps' imported copies from Manage My Data without deleting the source records in Health Connect.
Your choices and deletion
- Use PineapplePeps without signing in by choosing Continue on this device.
- Enable only the Health Connect categories you want, revoke their permissions in Android settings, or delete imported copies through Manage My Data.
- Export peptides, injection logs, manually entered weights, daily logs, and core settings as JSON, or generate a report. The JSON does not include Health Connect imports, reminders, device preferences, or account information. A report may include imported Health Connect weight when weight reporting is selected. You control where an exported copy is stored or shared.
- Delete individual records in the app. When signed in, supported record deletions synchronize to your other devices.
- Delete All Data removes shots, weights, daily logs, and imported Health Connect copies. When signed in, the shot, weight, and daily-log deletions are also sent to your synced account. Peptides, settings, and the Firebase account are retained.
- Signing out stops synchronization but does not delete local data, cloud data, or the Firebase account.
- Delete Account in Manage > Account & Sync asks you to confirm your Google identity, then permanently deletes your Firebase account and associated Firebase cloud data. The data already stored on that device is kept and PineapplePeps switches to local-only mode. Because local data is retained, it may remain in or later be included in an Android system backup according to your device backup settings. This does not delete your Google account.
You can delete your account directly in PineapplePeps without contacting us. If you cannot access the app, request deletion of your Firebase account, associated cloud data, or a submitted bug report by emailing pineapple.peps@proton.me. Include enough information to locate and verify the account or bug-report reference. We may retain limited information when required for security, fraud prevention, legal compliance, or dispute resolution.
Retention
Local data remains until you delete it, clear the app's storage, or uninstall the app, subject to any Android backup that you have enabled. Synchronized data remains in Firebase until you delete the applicable records or request account deletion. Bug reports are kept only as long as reasonably necessary to investigate, respond, maintain security and reliability, and meet legal obligations. Exported copies remain wherever you choose to save or share them.
Security
We use Android app storage protections, authenticated per-user Firestore access rules, and encrypted network connections provided by Google and Firebase. No storage or transmission method is completely secure, so we cannot guarantee absolute security. Protect access to your device and Google account and avoid placing information you do not want processed in free-text fields.
Children
PineapplePeps is intended for adults and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can investigate and delete it.
Changes and contact
We may update this policy when the app or its data practices change. The effective date above will be revised, and material changes will be presented through the app or another appropriate notice.
Gray Research Group is the developer responsible for PineapplePeps and the data practices described in this policy. Questions, privacy requests, and deletion requests can be sent to pineapple.peps@proton.me.