Privacy Architecture
No account. No email. No server. Protocol is built on a simple architectural constraint: the app has no cloud infrastructure to receive your data, so there is no infrastructure to breach, subpoena, or monetize.
This is not a privacy policy. This is how the app is built.
Most apps that claim "privacy" use cloud storage with encryption. Your data leaves your phone, travels to their servers encrypted, and lives there encrypted. If the company is breached, the attacker gets encrypted data. If the company receives a subpoena, they hand over your records. If the company changes its privacy policy, the new terms apply to data it already holds.
Protocol does not have servers. When you log a dose, that log is written to a SQLite file on your device. Nothing is transmitted. There is no Protocol server that could receive a subpoena. There is no Protocol database that could be breached. The data does not exist anywhere except on the phone in your hand.
The tradeoff is real: if you lose your phone without a backup, you lose your logs. iCloud and Google Drive backups are encrypted by Apple and Google under your personal account credentials, not by Protocol. That is the honest version of what on-device storage means.
Protocol does not ask for an email address at any point. There is no login screen. You download the app and start tracking. Every feature, including the free tier, is accessible without identifying yourself.
Apps that require accounts link your health behavior to an identity. PeptIQ and PepTracker both require accounts. That linkage is what makes cloud-based apps useful for cross-device sync. It is also what makes them a data-privacy concern. Protocol made the opposite choice.
Protocol lets you replace the app icon with a generic shield icon on your home screen. The change is purely cosmetic — it does not affect any in-app functionality. The purpose is simple: a peptide tracking app named "Protocol" is identifiable to anyone who glances at your phone. The shield icon is not.
No other app in this category offers this. It matters for users who track compounds with social or professional consequences.
Protocol can generate a formatted PDF or CSV export of your complete dose history, protocol configuration, vial inventory, and lab work. That export goes directly from your phone to wherever you send it: email, AirDrop, message, whatever your provider uses.
Nothing is shared automatically. Nothing is visible to your doctor until you send the export yourself. You control what gets shared and when.
No. Protocol requires no account, no email address, and no login to use any core feature. Download it, open it, and start tracking. Nothing is required before your first dose log.
All data — compounds, protocols, dose logs, vial inventory, injection site history, lab work, and notes — is stored in a SQLite database on your device. There is no server, no cloud sync, and no backup infrastructure that Protocol controls. If you want a backup, it goes to your personal iCloud or Google Drive, encrypted by Apple or Google under your account.
Protocol is not a healthcare provider and is not required to be HIPAA compliant. The more relevant question is whether your data can be accessed by anyone other than you. The answer is no: Protocol has no server infrastructure that could be subpoenaed, breached, or sold. On-device storage is not governed by HIPAA because Protocol never receives your data in the first place.
Protocol does not embed analytics SDKs (like Meta Pixel or Amplitude) that track in-app behavior and send it to advertisers. App-open habits, compound names, and dosing patterns are not transmitted to third parties. Standard iOS and Android system analytics (crash reports) may be enabled by your OS settings, but those are governed by Apple and Google, not Protocol.
Stealth Mode replaces the Protocol app icon with a generic shield icon on your home screen, making it non-identifiable to anyone who picks up your phone. This is relevant for users who prefer not to have a peptide tracking app visibly displayed. The change is cosmetic only and affects nothing inside the app.
If you delete Protocol without first exporting your data, your logs are gone. There is no server backup to restore from. Export your history as a CSV or PDF before deleting. This is the tradeoff of on-device storage: you have complete control and complete responsibility.
Only if you share it. Protocol lets you export your complete dose history, protocol setup, vial inventory, and lab work as a formatted PDF or CSV. You control what you share and with whom. Nothing is visible to your healthcare provider unless you send it to them directly from the app.