Molecule
Privacy Policy
Last updated and effective: July 27, 2026
Radish Retail, LLC ("Radish", "we", "us", or "our") operates the Molecule mobile application and related services (collectively, the "Service"). This Privacy Policy explains what personal information we collect, how we use and disclose it, how long we keep it, and the choices and rights available to you.
This Privacy Policy is incorporated into our Terms of Service.
1. Summary
- Molecule stores the compounds you track, your vial records, your dose log, your dosing schedules, and your subscription status. Records of what you inject and when are health-related information, and we treat them accordingly.
- Progress photos never leave your device. There is no server table for them and no code path in the app that can upload one. They are stored locally and are included only in a file you personally choose to export or share.
- Molecule works offline. If you sign in, your vial shelf, dose log, and schedules sync to your private account so you can use more than one device.
- Molecule is not a medical device. It does not diagnose, treat, cure, or prevent any condition, and it does not recommend compounds or protocols.
- We do not sell personal information, show third-party ads, use advertising identifiers, or track you across other companies' apps or websites.
- Analytics record how the app is used, not what you take. Compound names, doses, and photos are not sent to our analytics provider. Session replay is not enabled.
- You can delete individual vials and dose records in the app, export everything to CSV, and request deletion of your account and its server data.
- We do not knowingly collect personal information from children under 18. Molecule is an adult-only app.
2. Information We Collect
2.1 Account information
- Authentication information. A Supabase user ID and, depending on how you sign in, an Apple or Google account identifier and the email address or name those providers give us. We do not offer password-based login and never receive your Apple or Google password.
- Guest accounts. Molecule may create an authenticated anonymous account so you can use the app before registering. If you later sign in, eligible local data may be associated with that account.
2.2 Health-related information you enter
The core of Molecule is a record of your own protocol. When you use the app you may create:
- Vial records. The compound or blend, vial size in milligrams, diluent type and volume, resulting concentration, the dose you set, reconstitution date, expiry, and how much remains.
- Dose log entries. The compound, amount, date and time, injection site, and any notes you add.
- Schedules and reminders. Dosing frequency and the reminder times you choose.
- Progress photos and milestones. Photos you take in the app and the milestones it derives from your log.
- Free text. Anything you type into notes, labels, or custom compound fields.
Information about substances you administer to yourself is sensitive. We do not use it for advertising, do not sell it, do not share it with data brokers, and do not disclose it to employers, insurers, or law enforcement except where we are legally compelled as described in section 6.
2.3 What syncs and what does not
- Synced when you are signed in. Vial records, dose log entries, and schedules are stored in a private Supabase database row scoped to your user ID, so the same shelf appears on your other devices. Deletions are recorded as deletions and propagate to your other devices.
- Never synced. Progress photos. There is no table for them and no upload path in the app. They stay in Molecule's storage on your device and are removed when you delete the photo or the app.
- Not signed in. If you never sign in, your vials, dose log, schedules, and photos remain on your device only.
2.4 Subscription information
Apple and RevenueCat provide app-user identifiers, product identifiers, purchase and restore results, entitlement status, trial and offer eligibility, purchase and expiration dates, renewal status, and related transaction and diagnostic metadata. We do not receive your full payment-card number.
2.5 Information generated automatically
- Usage analytics. App launches, screen views, onboarding and activation milestones, paywall views and taps, feature-flag and experiment exposure, and conversion timing. These events are defined against a fixed schema that carries no compound names, no doses, and no photos.
- Device and diagnostic data. Device model, operating system, app version, platform, locale, time zone, performance data, and sanitized error messages and stack traces.
- Server logs. IP address, request path, timestamp, response status, and security, rate-limit, or debugging metadata may appear in infrastructure logs.
2.6 Information we do not collect or use
- We do not collect precise GPS location.
- We do not access your contacts.
- We do not read or write Apple Health or HealthKit data.
- We do not record microphone audio.
- We do not use advertising identifiers, show third-party ads, or track you across other companies' apps or websites.
- We do not upload your progress photos, and we do not enable session replay or screen recording in our analytics.
3. Reference Content and Calculations
Molecule includes a reference catalog of compounds and a set of educational guides. Typical dosing ranges shown in the catalog exist so the calculator can flag an arithmetic mistake, such as milligrams entered where micrograms were meant or a misplaced decimal. They are not recommendations, and Molecule does not tell you what to take or how much.
Reconstitution and draw-volume calculations happen on your device from the numbers you enter. They may be wrong if the inputs are wrong. Verify every dose independently before administering anything. Most research peptides are not approved for human use in any jurisdiction, and the catalog states this for each compound where it applies.
4. How We Use Information
- provide the calculator, vial shelf, dose log, schedules, reminders, reference catalog, guides, photos, milestones, and export;
- sync your records between your own devices and restore them when you reinstall;
- process purchases, restores, trials, entitlements, and offer eligibility;
- schedule local reminder notifications if you enable them;
- debug, secure, rate-limit, monitor, and improve the Service;
- measure aggregate product performance, feature exposure, and conversion funnels;
- comply with law, enforce our Terms, and defend legal claims.
We do not use your dose log or vial records to make automated decisions that produce legal or similarly significant effects, and we do not use them to train publicly released AI models.
5. How We Disclose Information
We disclose information only as described in this policy. We do not sell personal information. We require service providers that receive personal information to process it only for authorized services, security, support, or legal compliance, and to provide the same or equivalent protections described in this policy and required by applicable law.
5.1 Service providers
| Provider | Purpose | Data received |
|---|---|---|
| Supabase | Authentication, database, and sync for the vial shelf, dose log, and schedules | User and provider IDs, email or name where supplied by Apple or Google, vial records, dose entries, schedules, and technical logs. Not progress photos. |
| Apple | Sign in with Apple, App Store subscriptions, app distribution, and platform services | Apple account identifiers and optional name or email, subscription transactions, trial and offer eligibility, renewal and cancellation status, and diagnostics managed by Apple |
| Google sign-in | Google OAuth identifiers where used | |
| RevenueCat | Subscription entitlement, offerings, purchase and restore, and refund consumption responses | Anonymous or Supabase-linked app user ID, product and transaction identifiers, entitlement and offer status, and diagnostics |
| PostHog | Product analytics, feature flags, experiment assignment, and sanitized error tracking | Pseudonymous or Supabase-linked user ID, device and app metadata, schema-defined event properties, and sanitized error messages. No compound names, doses, notes, or photos. Session replay is not enabled. |
| Vercel, Expo/EAS, and infrastructure providers | Hosting, domains, networking, security, builds, and app delivery | IP addresses, request logs, app and build metadata, and device or platform data |
5.2 Business transfers
If Radish is acquired, merged, reorganized, financed, or sells assets, information may be transferred as part of that transaction, subject to applicable law.
5.3 Legal and safety
We may disclose information to comply with law or valid legal process, protect rights and safety, prevent fraud or abuse, or enforce our Terms.
5.4 With your consent
We may disclose information for another purpose that we explain when requesting your consent.
6. Refund Consumption Data
If you ask Apple for a refund, Apple may ask us for consumption information to help it decide. Where that request is enabled, RevenueCat answers on our behalf with information such as your entitlement status, purchase and renewal dates, and a coarse measure of how much you used the app. We do not send your dose log, vial records, notes, or photos to Apple as part of a refund request.
7. Your Rights and Choices
- Access, correction, export, and deletion. You may request access to, correction of, export of, or deletion of your personal information by contacting us. Molecule also has a built-in CSV export of your full log.
- Record deletion. You can delete individual vials, dose entries, and photos in the app at any time.
- Account deletion. Email privacy@radish.software to delete your account and its server records.
- Working without an account. You can use Molecule without signing in, in which case nothing syncs to our servers.
- Photos. Progress photos are local. Deleting a photo in the app or deleting the app removes them.
- Reminders. Reminders are local and optional. You can disable them in Molecule or in device settings.
- Subscriptions. Manage or cancel an App Store subscription in Apple account settings. Deleting your Molecule account does not cancel an Apple subscription or stop renewal.
- Analytics rights. Contact us to exercise an opt-out or objection right for non-essential analytics where applicable.
California residents and residents of other U.S. states with privacy laws may have rights to know, access, correct, delete, and obtain a copy of personal information; to limit certain uses of sensitive personal information; to opt out of sale or sharing; and to receive equal service. We do not sell personal information or share it for cross-context behavioral advertising.
Where GDPR or UK GDPR applies, you may have rights to access, rectify, erase, restrict, object, portability, withdraw consent, and complain to a supervisory authority. Health-related information is a special category of data under those laws, and where they apply we rely on your explicit consent to process the protocol records you choose to enter.
8. Retention
- Vial records, dose entries, and schedules remain until you delete them or delete your account.
- Progress photos remain on your device until you delete them or remove the app. We never hold a copy.
- Analytics and diagnostic events are retained under our analytics provider's configured retention schedule.
- RevenueCat and Apple retain transaction records under their own legal obligations and policies.
Limited copies may remain in encrypted or access-restricted backups, security records, or records we must retain for law, fraud prevention, accounting, or dispute handling. Those copies are isolated from ordinary product use and are deleted under the applicable retention schedule.
9. Security
We use HTTPS, Supabase authentication, row-level security scoped to your user ID, server-side authorization, input validation, and access controls. Keeping progress photos entirely on the device is itself a security decision: data that is never uploaded cannot be exposed by a server breach. No transmission or storage method is perfectly secure, and we cannot guarantee absolute security.
10. Children
Molecule is intended only for adults. It is not directed to children, and users under 18 are not permitted to use the Service. If you believe a minor has provided personal information, contact privacy@radish.software.
11. International Transfers
Radish is based in the United States. We and our providers may process information in the United States and other countries. Where required, we use appropriate transfer mechanisms and service-provider commitments.
12. Changes to This Policy
We may update this Privacy Policy. If a change is material, we will provide notice by email, in-app notice, app update notes, or another reasonable method where required. The effective date above identifies the current version.
13. Contact
Privacy: privacy@radish.software
Legal: legal@radish.software
Support: support@radish.software