Privacy Policy

Last updated: 2026-08-20. Effective: 2026-08-20.

This is the Privacy Policy for Vialkeep, an iOS application published by Cloud Motion Lab LLC ("we", "our", "us"). It explains what we collect, why, who we share it with, how long we keep it, and the rights you have. We try to keep this readable. If a section is unclear, write to dev@slyapp.co.

The short version. Vialkeep is a calculator and a private record. The peptides you enter, the doses you calculate, the schedules you set, and the log you keep never reach a server we operate. They stay on your device, and if you turn on iCloud sync, in your own private iCloud account, which we cannot read. We receive anonymous usage counts and an anonymous subscription flag. That is all.

Notice at Collection (California)

We collect the following categories of personal information when you use Vialkeep: identifiers (Apple-issued anonymous user IDs), commercial information (purchase history within the app), and internet or other electronic network activity (anonymous in-app usage signals). We use this information to deliver the app, process purchases through Apple, prevent fraud and abuse, and improve features. Retention is described in the Retention section below. We do not sell your personal information and we do not share it for cross-context behavioral advertising. A summary of your California privacy rights and the route to exercise them appear in the State Privacy Rights section below.

What We Collect

Vialkeep is built to collect as little as possible. There are no user accounts, no logins, and no profile pages. You never give us an email address.

What We Deliberately Do Not Collect

This is a health-adjacent app, so the exclusions matter as much as the inclusions. Our analytics are configured so that no event payload carries a peptide name, a dose value, a concentration, a vial quantity, a body site, a date of administration, or any number or free text you typed into the app. If we ever needed to change that, it would be a material change to this policy and would be handled under the Changes section below, with advance notice.

We do not use advertising SDKs, we do not run App Tracking Transparency prompts, and we do not participate in any data broker, data co-operative, or audience-matching arrangement.

Health Data

Records you keep in Vialkeep about peptides, dosing, and administration can constitute health information, and in some jurisdictions consumer health data or special category data. We treat it that way.

Not Medical Advice

Vialkeep performs arithmetic on numbers you supply and keeps the record you create. It does not contain a database of dosing recommendations, it does not prefill a dose, and it does not suggest, endorse, or evaluate any protocol, product, or quantity. It is not a medical device, it is not a substitute for a licensed clinician, and its output is only as correct as the figures you enter. The full disclaimer is in the Terms of Use.

Why We Process Each Category, with Lawful Basis (EU and UK)

CategoryPurposeLawful basis (GDPR Art. 6)
Anonymous usage analyticsOperate and improve the appLegitimate interest, Art. 6(1)(f)
Subscription stateDeliver paid features you boughtPerformance of contract, Art. 6(1)(b)
Local and iCloud records you createProvide the calculator and the record you asked forPerformance of contract, Art. 6(1)(b); explicit consent for health information, Art. 9(2)(a)
Local notificationsDeliver a reminder you setConsent, Art. 6(1)(a), via the iOS permission prompt
Fraud, abuse, and security monitoringProtect users and the serviceLegitimate interest, Art. 6(1)(f); legal obligation, Art. 6(1)(c)

Subprocessors and International Transfers

The third-party services that process data on our behalf are listed below. None of them receives the health information described in the Health Data section. Where data crosses borders, the legal basis for the transfer is identified in the table.

SubprocessorPurposeRegionTransfer mechanism (EU and UK)
TelemetryDeckAnonymous usage analyticsEuropean Union (Germany)Adequacy, no transfer needed for EU and UK; GDPR direct application
RevenueCatSubscription state management, anonymized user IDs onlyUnited StatesEU-US Data Privacy Framework, with 2021 SCCs as backstop
Apple App Store, StoreKit, iCloud, CloudKitApp distribution, subscription processing, anonymous receipt, and the private iCloud database that holds your own recordsGlobal, governed by AppleApple's own Data Privacy Framework certification and SCCs, see Apple Privacy Policy

For transfers from the EU, UK, or Switzerland to the United States, we rely first on the EU-US Data Privacy Framework where the recipient is certified, and on the 2021 Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable) as a backstop. We monitor regulatory changes to the Data Privacy Framework and are prepared to switch to SCCs as the primary mechanism if the Framework is invalidated.

Retention

Exporting Your Data

Vialkeep can export your record as a CSV file from inside the app. The export is generated on your device and handed to the iOS share sheet, where you choose the destination. We never see the file. Once you send it somewhere, that destination's privacy policy governs it, not ours.

Sale, Sharing, and Global Privacy Control

We do not sell personal information for money or other valuable consideration, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended. We honor the Global Privacy Control browser signal where it reaches us. Because Vialkeep runs on iOS and does not use a website signup, the practical effect is that no opt-out signal is needed to stop a sale or share that we are not doing.

State Privacy Rights, Summary

If you live in a U.S. state with a comprehensive consumer privacy law, you have the rights below. The current list of states is California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Washington residents also have rights under the My Health My Data Act, addressed in the Health Data section above.

Because we hold no identifier that links to you, the practical answer to a right-to-know or right-to-delete request about your Vialkeep records is that we do not have them and cannot retrieve them. The data is yours, on your device and in your iCloud, and you can read, correct, export, and delete it directly. To exercise any right against us, email dev@slyapp.co with the words "Privacy Request" in the subject line and tell us which app and what you want. We respond within 45 days, with one 45-day extension where reasonably needed. If we deny a request, you may appeal by replying to the same thread within 60 days. We will respond to the appeal within 45 days. If you are not satisfied, California residents may contact the California Privacy Protection Agency, and other state residents may contact their state Attorney General. Texas, Maryland, Oregon, and other state laws apply regardless of any revenue threshold; we treat all U.S. residents the same.

Rights Under GDPR and UK GDPR

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the rights of access, rectification, erasure, restriction of processing, portability, objection, and not to be subject to a decision based solely on automated processing that has legal or similarly significant effects. We do not engage in such automated decision-making, and Vialkeep contains no recommendation engine of any kind. To exercise a right, email dev@slyapp.co. You may also lodge a complaint with your local supervisory authority. The lead authority for users in the EU is the data protection authority of the country where you are habitually resident. UK users may complain to the Information Commissioner's Office. We will respond within one month of receipt and may extend by two further months for complex requests, with notice.

Children's Privacy and COPPA 2026

Vialkeep is not directed to children and is not appropriate for them. Under the Children's Online Privacy Protection Act Final Rule amendments, biometric identifiers including fingerprints, faceprints, voiceprints, retina or iris patterns, gait, and DNA are personal information when collected from a child under 13. We do not knowingly collect any personal information, biometric or otherwise, from a child under 13. If we learn that we have, we will delete it within 30 days. If you believe a child has provided us with personal information, contact dev@slyapp.co and we will delete it promptly. For users between 13 and 16 in jurisdictions that require parental consent for personal-data processing, we rely on the Apple platform's Declared Age Range signal where it is available.

Notifications

Reminders in Vialkeep are local notifications scheduled by the app on your device. They are not push notifications, they do not travel through a server, and no notification content is transmitted anywhere. You can grant or revoke notification permission at any time in iOS Settings. Revoking it stops reminders and leaves the rest of the app working.

Subscription and Payment Data

All purchases in Vialkeep are processed by Apple under Apple's Media Services Terms. We never see your credit card number, billing address, or Apple ID. We receive an anonymous receipt confirming an active subscription, which the app uses to unlock paid features. Payment data is governed by the Apple Privacy Policy.

Security and Breach Notification

We use commercially reasonable administrative, technical, and physical safeguards to protect personal information. No system is perfectly secure. If we determine that a personal-data breach affecting your information has occurred, we will notify you and applicable regulators in accordance with applicable law. For users in the EU and UK, our notification window is 72 hours after we become aware, in line with GDPR Article 33. For U.S. users, we follow the notification rules of your state. Because the health information described above never reaches our infrastructure, a breach of our infrastructure cannot expose it.

Data Storage

Data on your device is stored using standard Apple frameworks (SwiftData, UserDefaults, Keychain). If you enable sync, the same records are stored in the private database of your iCloud account through CloudKit, under Apple's encryption and access controls. Data we send to subprocessors is stored on their infrastructure; the location and retention are listed in the Subprocessors table. We do not operate our own user-data servers for Vialkeep.

Changes to This Policy

We may update this Privacy Policy. For material changes, including expansion of categories collected, any collection of health information by us, new subprocessors that change data flow, new regions, or changes to dispute-resolution rules referenced here, we will give at least 30 days' advance notice through an in-app banner and, where available, the email address associated with your Apple ID, and will update the effective date at the top of this page. Minor changes such as typographical or formatting fixes may be made without separate notice. Continued use of the app on or after the effective date of an updated version constitutes acceptance.

Contact, EU and UK Representative

For privacy questions, complaints, or rights requests: dev@slyapp.co. Our registered postal address is Cloud Motion Lab LLC, 30 N Gould St Ste R, Sheridan, Wyoming 82801, United States. We currently process EU and UK personal data at a scale below the threshold that requires a designated GDPR Article 27 or UK GDPR representative. If your processing is in scope of those requirements, the same contact email is the route to a response. We will appoint and publish a representative if and when our processing reaches that threshold.