Privacy
Privacy policy
Effective date: October 8, 2026
Vialist ("we", the publisher of the Vialist app) is a personal peptide/therapy dose log for iOS (bundle app.vialist.ios). This policy explains, in plain language, what the app stores and the only ways anything ever leaves your phone.
What Vialist stores
Vialist stores the health-related entries you type in. All of it lives in a local database and in the app's own folder on your device only. There is no cloud database, no account, and no sync. It stores:
- Therapies/protocols, including dose steps (titration), several dose times a day, and an optional instruction note you write.
- Vials and supplies, logged doses, and recorded losses (a vial or dose that was wasted, spilled, or lost).
- Vial purchase details you choose to enter: price and currency, vendor, lot number, and purchase and expiry dates.
- Certificate of analysis (COA) documents you attach to a vial, a photo or a PDF, stored in the app's own folder. The database keeps only the file name, type, size, and location of each one.
- Daily check-ins: mood, energy, sleep, libido, appetite, weight, side effects, and body measurements (body fat, waist, blood pressure, and pulse).
- Labs.
- Your settings, such as units, reminders, and whether app lock and discreet reminders are on.
Each record gets a random identifier created on your device; there is no device, advertising, or vendor ID. Vialist doesn't collect your name, email, or any contact information. None is asked for anywhere in the app. The app's folder is marked so that it is left out of iCloud and computer backups.
Camera and your files
Vialist uses the camera in two places, both only after you tap the action and allow camera access:
- Scanning a vial label. On the dose screen you can scan the QR code on a Vialist vial label to pick that vial. The code holds only a Vialist vial identifier. The camera image is read on the phone to decode the code and is not saved.
- Photographing a certificate. When you attach a certificate (COA) to a vial, you can take a photo of it. The photo is saved only in the app's own folder, not in your Photos library.
You can also attach a certificate by choosing a photo or PDF from Files or your library with the iOS document picker. Vialist reads only the single item you pick, copies it into the app's own folder, and removes the temporary copy it made. Photos (JPEG, PNG, or HEIC) and PDFs of up to 8 MB are accepted. Camera images and certificate files stay on your phone, and nothing is uploaded. Vialist does not browse or read your photo library.
What leaves your device, and only when you choose
Nothing leaves your phone automatically. The only ways data can leave are actions you start:
- Backup export. Settings can export your data as a JSON or CSV file, written to the app's folder on your phone and handed to iOS's share sheet. It leaves your phone only if you pick a destination in that share sheet (for example, saving to Files, AirDrop, or emailing it yourself). The backup holds your records and the details of each certificate, but not the certificate photos or PDFs themselves. The file also stays in Vialist's folder on your phone until you uninstall the app. See "Protecting your data" for password protection.
- Doctor report. You can make a PDF summary to share with a clinician. The PDF is generated on your phone (with
expo-print, which renders the PDF on the device and does not upload anything) and handed to the iOS share sheet. You choose the period and what to include. Injection sites, vendors, lots and prices, and your notes are off by default, and so is the full dose log. The temporary PDF file is deleted from the phone after the share sheet closes. The report goes only where you send it. - Protocol template. On a protocol you can share it as a template file. A template holds the compound, dose, steps, and schedule only. It does not include logged doses, dates, supplies, or your reminder time, and your instruction note is left out unless you turn on "Include my note". The file is written to a temporary location, handed to the share sheet, and goes only where you send it.
- Vial label. You can share a printable label for a vial as an image. It carries the details you recorded for that vial and a QR code with its identifier, and it goes only where you send it.
- Shared summary. You can build a plain-text summary (for a coach or clinician, say) by choosing a date range and exactly which therapies, doses, check-in fields, or labs to include. Nothing is added unless you pick it, and the on-screen preview is exactly the text that would go out. It leaves your phone only through the iOS share sheet, and only if you tap Share.
- Feedback. The in-app Feedback screen lets you write a message and, only if you turn on "Attach diagnostics" for that send, include technical details: app version, phone/OS, record counts, and recent error codes. Diagnostics are built to exclude every health-related field. Compound names, doses, dates you logged, symptoms, injection sites, and lab values are all filtered out, and any error text is scrubbed of health-related words, quoted text, dates, and dosage-looking numbers before it's ever stored. Feedback is sent only through the iOS share sheet, to whatever app or address you choose. There is no in-app inbox and no built-in feedback address collecting these messages.
- Receipt image. If you generate a stack receipt, the app can save that image to your Photos library at your request. That is a local write to your own device.
- Reference links. Some compound reference screens link to outside sources. If you tap one, it opens in your browser, which is then subject to that site's own policy. Vialist sends nothing from your log when you do.
Once you share a file, the app or person you send it to controls it. Vialist cannot recall it.
Protecting your data
- Password-protected backups. When you export a JSON backup, Vialist asks you to set a password (at least 10 letters, digits, or spaces) by default, and encrypts the file with AES-256-GCM. The key is derived from your password with PBKDF2-SHA256 (310,000 iterations) and a random salt. You can turn password protection off in Settings, after a warning, and then the JSON file is saved unencrypted. Restoring a protected backup asks for the password. The password is never stored on your phone or written into the file, so a forgotten password cannot be recovered and neither we nor anyone else can open that backup for you. CSV exports are not encrypted.
- iOS Data Protection. Vialist sets the Complete protection class on the database, certificate files, and backup files in its folder, so iOS keeps them unreadable while the phone is locked.
- App lock (optional, off by default). You can require Face ID, Touch ID, or your passcode to open the log. Face ID and passcode checks are handled by iOS; Vialist never receives your biometric data.
- App-switcher cover. When Vialist goes to the background, the iOS app switcher shows the Vialist mark instead of your screen.
- Discreet reminder text (optional, off by default). Notifications say only "Reminder", never a compound or protocol name.
- Plain app icon (coming). A plain, neutral app icon is listed in Settings, but this version still shows the Vialist icon.
No accounts, no tracking
Vialist has no sign-in, no user accounts, and no backend server. It contains no analytics SDK, no crash-reporting SDK, and no advertising SDK, and it shows no App Tracking Transparency prompt because nothing tracks you.
Third-party code in the app
Vialist uses a small set of Expo/React Native modules and two cryptography libraries, all running locally on your phone:
expo-sqlite,expo-crypto,react-native-view-shot: local storage, random identifiers and random bytes, and local rendering of receipts and labels.@noble/ciphers,@noble/hashes: AES-256-GCM encryption and PBKDF2 key derivation for password-protected backups.expo-camera: scans vial label QR codes and photographs certificates. Images stay on the phone.expo-document-picker: lets you pick a certificate, a backup, or a template file. It reads only what you pick.expo-print: makes the doctor report PDF on the phone.qrcode-generator: draws the QR code on a vial label.expo-local-authentication: asks iOS to check Face ID, Touch ID, or your passcode for app lock.expo-alternate-app-icons: switches the home screen icon.expo-localization: reads your phone's region to choose the paper size and formats.expo-notifications: schedules local reminders only. The app never registers for push notifications.expo-media-library,expo-file-system,expo-sharing: saving a receipt to Photos at your request, local file read/write, and the iOS share sheet.expo-iap: Apple's native StoreKit purchase bridge, used only to talk to Apple's store.expo-application,expo-constants: read the app's own name and version on the phone.
No analytics, advertising, crash-reporting, or cloud-sync SDK is included anywhere in the app, and none of the modules above, including the UI, navigation, font, and animation libraries not listed individually, ever receive or transmit your data. They run on-device only.
Reminders
Reminders are scheduled locally using iOS's notification system. Unless you turn on discreet reminder text, a reminder can show the compound and dose for that entry, but it stays in your phone's own notification tray. Vialist has no server and does not register for or receive push notifications.
Purchases
Vialist is free to use, with an optional upgrade called Vialist Pro (monthly, yearly, or lifetime). Apple processes every payment. Vialist never receives your card number, billing details, or Apple ID, and has no account of its own to attach a purchase to.
Whether Pro is active is read on your phone from StoreKit, Apple's purchase framework. No receipt or purchase record is sent to any Vialist server, because Vialist has no server. Apple's own privacy policy covers what Apple collects when you buy.
Children
Vialist is for adults 18 and older and is not directed to children.
Deleting your data
Delete everything at any time from Settings > Delete all data, which removes your vials, therapies, doses, losses, check-ins, labs, and certificate files from the device. Uninstalling the app removes its local database entirely. There is no server copy to delete.
Medical disclaimer
Vialist is a personal record-keeping tool. It does not diagnose, treat, or prescribe, and it does not recommend doses. Any level estimates or lab reference ranges shown are drawn from what you logged, for your own records. They are not clinical interpretation. Talk to a licensed clinician about your therapy.
Where Apple's App Privacy answers come from
Vialist's App Store "App Privacy" label is completed from this same review of what the app stores and transmits. It should not show anything beyond what this policy describes.
Changes to this policy
If this policy changes, the updated version will be posted at https://vialist.io/privacy with a new effective date.
Apple Health
Apple Health is optional and off by default. Vialist asks iOS for access only when you tap Connect in Settings, and you choose which types to read.
- Read-only. Vialist reads from Apple Health. In this version it never writes anything to Health and has no background access.
- Types read. Body weight, body fat percentage, waist circumference, blood pressure, resting heart rate, heart rate variability, sleep, and steps. Data from Apple Watch, Oura, Whoop, Garmin and other apps reaches Vialist only through Apple Health.
- Your entries come first. Health never replaces a value you typed. Imported values are labelled "From Apple Health".
- Stays on your phone. What Vialist reads is used on the device and is never uploaded. It leaves your phone only through share actions you start yourself (a backup, a doctor report, or a shared summary), and only if included in them.
- Remove or revoke any time. Settings > Apple Health > Remove imported values deletes only values that came from Health. Turn off access in iPhone Settings > Health > Data Access & Devices > Vialist.
Changes in this version
Effective October 8, 2026, this policy now reflects the following:
- Added the Purchases section for the optional Vialist Pro upgrade. Apple processes payments and purchase status is read on your phone.
- Vialist uses the camera to scan vial label QR codes and to photograph certificates. Images stay on your phone. The earlier statement that Vialist has no camera access was out of date and has been removed.
- You can pick a certificate photo or PDF from Files or your library. Vialist reads only the item you pick.
- Added what Vialist stores: recorded losses, body measurements, vial purchase details, certificate documents, dose steps and several dose times, and instruction notes.
- Added the ways data can leave your phone by your choice: the doctor report PDF, protocol templates, and vial labels.
- Added password-protected JSON backups (AES-256-GCM), with a note that a forgotten password cannot be recovered and that CSV exports are not encrypted.
- Added iOS Data Protection, optional app lock, the app-switcher cover, and optional discreet reminder text. The plain app icon is listed as coming.
- Rebuilt the list of third-party modules to match the current app.
Contact
Questions about this policy or your data: support@vialist.io.