governance manual
Privacy Policy
What we collect
Our submission form is designed to collect the minimum information necessary to support the archive's mission: broad demographic categories, information about peptide use, and a free-text description of your experience. We do not ask for your name, email address, phone number, street address, username, or wallet address, and the form has no field for any of them.
What we don't collect
We do not store your exact IP address alongside your submission. Security and rate- limiting systems may briefly process a hashed, salted version of your IP address to prevent abuse; this is never linked to your submission content, is retained only briefly, and access to it is restricted.
How your submission is protected
- Connections to the public site are protected in transit by the production hosting platform.
- Administrative sign-in requires a password and a time-based one-time authenticator code.
- Administrative access is restricted through role-based permissions.
- Governed moderation, publication, account, security, and other administrative actions covered by the audit system are recorded in audit history.
- Raw database records are not exposed through the public archive or dashboard interfaces.
How your submission may be published
If approved, your observation may be published anonymously in the Observational Archive and reflected in aggregated dashboard statistics. Direct quotation only happens if you opt in during submission. Before publication, we remove personal identifiers, supplier information, purchasing information, promotional language, and direct medical instructions, while preserving the meaning of what you shared.
Withdrawing your submission
You'll receive a one-time withdrawal code after submitting. Using it removes your observation from public view and from future dashboard totals. Because submissions are anonymous, we have no way to verify or recover a lost code, and no way to identify or withdraw a submission without one.
Data retention
Anonymous submissions are retained as archive records for research continuity and audit integrity. If a submission is withdrawn using its withdrawal code, the underlying record is retained but is excluded from public display and future aggregate statistics. Audit records are retained to preserve the history of governed actions. Hashed rate-limiting identifiers are temporary security records and are eligible for deletion after their applicable rate-limit window expires. Backup retention is managed as an operational infrastructure control and is verified separately from application-level retention enforcement.
How we do not use your data
We do not use submissions to target you or anyone else with medical or product advertising. We do not sell data. We do not accept funding from peptide manufacturers, distributors, or sellers.
Research use
Aggregated, de-identified data may be shared with external researchers through a documented request-and-review process. Raw, individual submissions are never shared externally.
Contact
Questions about this policy, or requests related to your submission, can be sent through our Contact page.