Privacy
Privacy policy
This site has no accounts, no sign-up, no comments, and no checkout, so the honest version of this policy is mostly a list of things we never receive. Here is what is left, and exactly where it goes.
Last updated · Questions: research@peptideworth.com
The short version
Who this policy is from
This policy covers peptideworth.com and everything served from it. The publisher is the website itself — there is no separate company name or corporate address to give you, and we would rather say so than print a shell. Anything in this document, including a request about your data, reaches a person at research@peptideworth.com.
The policy does not cover other people’s sites. Once you follow a link off Peptideworth, that destination’s own privacy policy applies and ours stops.
Start with what we never collect
Most privacy policies bury this. Peptideworth has no mechanism to collect the categories of personal data readers usually worry about, because the features that would collect them do not exist on the site:
- No accounts. No registration, no login, no password, no profile.
- No mailing list. There is no newsletter signup and no email capture anywhere on the site.
- No user-submitted content. No comments, no reviews, no forum, no uploads.
- No payments. No checkout, no card details, no payment processor. You never transact with us.
- No health information. We never ask for a condition, a medication, a weight, or a lab value, and there is no form that could receive one.
- No data sales. We do not sell, rent, or share personal information for money or for cross-context behavioral advertising.
If any of that changes — if a newsletter or a saved-comparison feature ever ships — this section is the first thing that gets rewritten, before the feature goes live.
What reaching a page unavoidably reveals
Loading any web page requires your device to send a request, and that request carries your IP address, your browser’s user-agent string, the page you asked for, and sometimes the page you came from. Our hosting provider handles that exchange to deliver the page and to keep the service running and secure. This is a property of how the web works rather than a choice we made, and it applies whether or not analytics are on.
We maintain no visitor database of our own from that traffic, build no profile, and attach no identifier to you across visits.
Analytics, and how to switch it off
The site uses Google Analytics 4 to understand which pages get read. It is configured with Google Consent Mode v2, and the default we set on every page load splits the four storage purposes rather than treating them as one decision. Analytics storage is granted — this is a US site written for US readers, and measurement starts when the page loads. Ad storage, ad user data and ad personalization are denied, on every page, for everyone, with no control anywhere on this site that grants them, because nothing here uses them.
So Google Analytics may collect usage data from the moment you arrive: pages viewed, time on page, approximate location derived from IP address, device and browser type, and the referring source. We see it as aggregated reporting. What it does not do is follow you off this site or feed an advertising audience — that is what the three denied purposes rule out.
Switching it off takes one tap and it is permanent on that device. Opting out does three things in the same action: it records the choice, it tells Google Analytics to stop, and it deletes the analytics cookies already in your browser. If your browser sends Global Privacy Control, we read that before anything else and never start measuring at all — no tap required.
Analytics is also inert when no measurement ID is configured for a deployment: the script is simply not rendered.
The switch, and where your choice is stored
This control is live. It reads the setting held on this device and changes it on the spot — there is no form to submit and nothing to email us about.
Checking this browser… This control reads the setting stored on your own device.
Your answer is written to your browser’s localStorage under the key cookie-consent, with a value of granted or denied. That entry stays on your device. It is not sent to us, it carries no identifier, and it is the only reason the notice does not reappear on your next visit.
Opting out is a real opt-out, not a deferral: it stores the choice, pushes the Consent Mode update that stops the measurement, and expires the Google Analytics cookies already set in this browser. Clearing this site’s data works too, but note which way it goes — it removes the cookie-consent entry along with everything else, and a browser with no entry is a measured browser again. An opt-out you want to keep is one you leave stored.
If your browser blocks local storage entirely, nothing can be recorded, so the notice shows on every visit and each visit starts measured. Two things soften that: such a browser is also discarding the analytics cookie between sessions, so nothing durable accumulates, and if it sends Global Privacy Control we read that instead and never start.
Calculator inputs never leave your browser
The reconstitution and dosage calculators run entirely on your device. The numbers you type — vial strength, water volume, and the dose you supply — are held in component state, converted by a plain arithmetic function, and displayed. There is no form submission, no network request, and no logging of any figure you enter. Close the tab and the values are gone.
This matters more here than on a generic site. What someone types into a peptide dosage calculator is close to health information, and the cleanest way to protect it is to never be in possession of it.
What happens when you click an outbound link
Affiliate links pass through a /go/ path on this domain, which looks up the destination, appends campaign tags identifying this site and the page area you clicked from, and redirects you. The tags describe the placement, not you.
That redirect increments one number: a counter of clicks per destination per day, so we can see that a link was used. It is an aggregate integer with no visitor identity in it. The request reaches the redirect carrying the same IP address and user agent any request carries, and neither is stored — nothing is written to that counter except the count. When no click-counting store is configured for a deployment, even that is skipped.
After the redirect you are on someone else’s site. What they set, log, or infer is governed by their privacy policy, and affiliate networks generally use their own cookie or identifier to attribute a referral. We do not receive your identity from that process — what comes back to us is commission reporting, not a list of people.
Who else is involved
Three categories of third party touch this site, and no others:
- Our hosting and delivery provider, which serves the pages and processes the request data described above.
- Google, as the analytics provider — unless you have opted out, and under Google’s own terms and privacy policy for the data it holds.
- Sites you choose to visit through an outbound link, including affiliate networks and the providers behind them.
There is no advertising network on this site, no social-media tracking pixel, no heatmap or session-replay tool, no chat widget, and no third-party comment system. We also do not disclose personal information to anyone for their own marketing.
How long anything is kept
We keep no visitor records ourselves. The click counters are aggregate daily totals per destination and contain nothing about any individual. Analytics data is held by Google under the retention controls applied to our property, and is subject to Google’s own deletion mechanisms. Server request logs are handled by our hosting provider under its operational retention practices, not ours.
We would rather state that boundary honestly than publish a precise-sounding retention period for data we do not hold.
Your rights, and the practical problem with exercising them here
Depending on where you live — the EU, the UK, California, and a growing list of US states — you may have rights to access, correct, delete, or port personal data about you, to object to or restrict its processing, and not to be discriminated against for asking. We will honor a valid request to the extent the law requires.
The practical difficulty is a good one to have: we usually hold nothing to give you. With no accounts and no contact capture, there is no record keyed to your name or email for us to look up. In most cases the useful actions are ones you control directly:
- Opt out of analytics with the switch above. It takes effect immediately, deletes the analytics cookies already set, and needs no request to us.
- Opt out of Google Analytics generally using Google’s own browser add-on, or block the script with your browser or an extension.
- Use browser-level signals. We honor Global Privacy Control as an opt-out on every page, ahead of anything stored, whether or not the law requires it of us.
- Write to us at research@peptideworth.com for anything else, including a request about correspondence you have sent us.
We describe mechanisms rather than advertise a compliance badge. This site holds no certification and has not been audited by anyone, and saying otherwise would be exactly the kind of unsourced claim the rest of it exists to avoid.
Children
Peptideworth is written for adults. It is not directed at children, we do not knowingly collect personal information from anyone under 18, and the site’s subject matter — unapproved substances and injectable preparations — is not appropriate for minors. If you believe a child has sent us personal information, contact us and we will delete it.
Transfers and security
The site is delivered from a global content network, so serving a page may involve infrastructure outside your country, and any analytics data collected before you opt out is processed by Google under its own international transfer arrangements. Pages are served over an encrypted connection.
Our strongest security control is structural rather than technical: with no accounts, no payment data, and no health information collected, there is no store of sensitive personal data here to breach. No system is perfectly secure, and we do not claim otherwise.
Changes to this policy
We update this page when what the site does changes. The date at the top records when that last happened, and because there is no mailing list we cannot notify you — the date is the notification. Continuing to use the site after an update means the revised policy applies.
Related reading: the terms of use, the affiliate disclosure, and the corrections policy if something on this page is wrong.