Peptide-powered wellness.
Direct-pay telehealth, 48 states + DC.
TelePeptide Health
Effective Date: April 3, 2026 · Last Revised: August 21, 2026
This policy governs personal data collected through our website and marketing communications. For Protected Health Information collected during clinical intake, see our Notice of Privacy Practices.
TelePeptide Health ("TelePeptide," "we," "us," or "our") is a New Jersey-based telehealth technology and marketing platform headquartered in Fort Lee, NJ. This Privacy Policy governs information we collect through our website, intake and visit-setup forms, consultation requests, customer-support channels, and marketing communications. TelePeptide is not your medical provider: clinical care is delivered by an independent contracted medical group, and the clinical records created during your care are held by that group on its own secure, HIPAA-covered platform under its Notice of Privacy Practices (see our Terms § 10). Information you provide to TelePeptide through our own channels is governed by this Privacy Policy, and we may collect, retain, use, and share it as described below.
Because TelePeptide is not your clinical provider and is not a HIPAA covered entity, you should never send Protected Health Information or clinical details — medical history, conditions, medications, body metrics, symptoms, lab results, or clinical photographs — to TelePeptide through email, SMS, chat, support tickets, website forms, or any other TelePeptide channel. Enter health information only into the contracted medical group's HIPAA-covered platform. If you voluntarily or inadvertently transmit PHI to TelePeptide outside that platform, you do so on your own initiative and at your own risk: such transmission is unsolicited, does not create a covered-entity, business-associate, or treatment relationship with TelePeptide, and you are solely responsible for the disclosure. To the fullest extent permitted by law, TelePeptide disclaims any and all liability arising from PHI you send it outside the medical group's platform, and may delete, disregard, or redirect that information to the medical group without retaining it.
We collect information you provide to us, information generated through your use of our services, and information from third-party sources. The categories below are illustrative, not exhaustive, and may expand as our services evolve: (a) Contact and identity data — name, email address, phone number, and state of residence; (b) Visit-setup data — date of birth, biological sex, mailing address, the program and plan you select, self-reported details you enter while setting up a visit (which may include health-adjacent information such as height, weight, or screener responses that we relay to the contracted medical group), and other details you choose to provide; (c) Payment data — billing name, address, and payment card details processed and stored by our PCI-DSS-compliant third-party payment processor (we do not store full card numbers on our own systems), plus transaction, settlement, and payment-failure records (such as amount, status, decline codes, card type, and last four digits); (d) Marketing interaction data — email open events, link clicks, unsubscribe status, and campaign history; (e) Technical, device, and attribution data — IP address (which we may store in truncated or hashed form), browser and device type, pages visited, referring page, approximate location or country, and campaign attribution details such as the ad campaign, search terms, or click identifiers (e.g., gclid/fbclid) that brought you to the site, which we may store in a first-party cookie and associate with your inquiry; (f) Prospect and business-contact data sourced from third-party directories and enrichment services (e.g., Apollo.io / Origami) — name, professional title, employer, business email, LinkedIn URL, and location; (g) Saved visit-setup progress — if you begin our visit-setup questionnaire and provide your email or phone number, we may save your in-progress answers (including contact details, program selection, and self-reported information such as height and weight) so you can resume where you left off, including from a resume link we may send you, and we retain that saved progress for as long as reasonably necessary for that and related business purposes; (h) Communications data — emails, text messages (including messages you send to our numbers), chat and support interactions, form submissions, and call notes, which we may monitor, record, and retain for quality, training, security, and record-keeping purposes; (i) Partner, applicant, and business-relationship data — information submitted in partner program applications, payout and tax details for partners, and information you provide if you apply to work with us; and (j) any other information you choose to provide to us through any channel. You may request deletion at any time (Section 9). Clinical care records — medical history, diagnoses, prescriptions, and clinician communications — are created and held by the contracted medical group on its own HIPAA-covered platform; any information you nonetheless provide to TelePeptide directly may be retained and used as described in this Policy.
We use your information to: (a) respond to intake submissions and consultation requests; (b) coordinate care with licensed clinicians and compounding pharmacies; (c) process payments and manage subscriptions; (d) send marketing emails about our programs, health content, and updates — only where you have consented or where permitted by law; (e) honor unsubscribe requests and maintain suppression lists; (f) analyze campaign performance and improve, develop, and personalize our services; (g) comply with legal obligations including HIPAA, CAN-SPAM, and applicable state telehealth regulations; (h) prevent fraud, abuse, and security incidents; and (i) for any other purpose disclosed to you at the time of collection or otherwise compatible with these purposes, as permitted by applicable law.
If you submitted your email address through our intake form, consultation request, or any other form on this site, you consent to receive marketing emails from TelePeptide Health. All marketing emails comply with the CAN-SPAM Act (15 U.S.C. § 7701 et seq.): they clearly identify TelePeptide as the sender, include our physical mailing address, and include a functional one-click unsubscribe link. We honor opt-out requests within 10 business days. You can unsubscribe at any time by clicking the link in any email or emailing help@telepeptide.org. If we source your contact information from a third-party directory (e.g., Apollo.io), we treat it as a cold outreach and include all required CAN-SPAM disclosures in the first message. We do not send emails to individuals who have previously opted out or whose email has hard-bounced.
If you provide your mobile number and consent (by checkbox, by proceeding on a page where text-message consent is disclosed, by texting us first, or by other means permitted by law), you may receive text messages (SMS) from or on behalf of TelePeptide and the contracted medical group — including account, appointment, identity-verification, care-coordination, order and delivery messages; enrollment, visit-setup, and checkout reminders and follow-ups; billing and renewal notices; and, where you have given the applicable consent, informational and promotional messages. Messages may be sent using automated technology or manually by a member of our team, from any number we or our service providers use. Consent to text messages is not a condition of purchasing any service. Message and data rates may apply and message frequency varies. You can opt out at any time by replying STOP to any message, and reply HELP for help; carriers are not liable for delayed or undelivered messages. We record the consent language shown to you, its version, and the time of your consent, and we log messages you send to our numbers. We do not sell your mobile number, and we do not share it with third parties for their own marketing. Text messaging is not a secure or encrypted channel: do not send health information by SMS (see Section 1a). Messages from TelePeptide are not intended to contain clinical details — medical questions and clinical information belong on the contracted medical group's secure, HIPAA-covered platform. Full SMS terms are in our Terms & Conditions §9a.
We may share your information with service providers, contractors, and business partners that support the operation, improvement, and marketing of our services, each under appropriate written agreements. These include, without limitation, the following categories: (a) A PCI-DSS-compliant third-party payment processor that serves as TelePeptide's merchant of record — payment processing and subscription management; (b) Resend — transactional and marketing email delivery; (c) Supabase — cloud database and backend infrastructure; (d) Apollo.io — business contact data platform used to source prospect information (name, professional title, employer, and business email) from publicly available professional directories for marketing outreach purposes; (e) Origami — a contact intelligence and data enrichment service used to verify, supplement, and score prospect records in our marketing database, including appending professional attributes such as industry, title, and employer from aggregated public sources; (f) A contracted telehealth infrastructure provider — we work with a third-party telehealth enablement network that provides the licensed clinician network, clinical workflow infrastructure, and credentialing services that allow TelePeptide to connect patients with qualified providers. this contracted medical group collects and holds all clinical data directly on its own HIPAA-covered platform; TelePeptide shares with it only the non-clinical setup identifiers in Section 2 and does not route PHI to it; (g) Licensed compounding pharmacies — for prescription fulfillment; (h) Vercel — cloud hosting and edge delivery; (i) Twilio — text-message delivery and inbound message handling; (j) cold-outreach and email-sequencing platforms (e.g., Instantly.ai) — delivery and reply-tracking for business outreach; (k) AI infrastructure providers (e.g., Groq) — processing for the non-clinical AI uses described in Section 6, protected by technical guardrails; (l) Google — analytics and advertising (Section 7) and cloud productivity, storage, and spreadsheet services we use to operate the business (e.g., Google Workspace / Drive / Sheets, including business records and lead exports); (m) security, anti-abuse, and performance vendors (e.g., Cloudflare Turnstile CAPTCHA, Upstash rate-limiting); and (n) other service partners and subcontractors ("subprocessors") that support the operation and delivery of our services — including specialized or "bespoke" vendors engaged for specific functions such as care coordination, identity or eligibility verification, communications and SMS delivery, payouts and tax reporting for partners, shipping and logistics, and customer support. Each subprocessor acts under a written data-processing agreement (and, where a subprocessor creates, receives, maintains, or transmits PHI on behalf of a covered entity, a Business Associate Agreement), is permitted to use your information only to perform services for us or the contracted medical group, and is required to safeguard it and not use it for its own purposes. We may add or change specific subprocessors from time to time; the categories of recipients and the purposes described here remain the same, and clinical PHI continues to reside only on the contracted medical group's HIPAA-covered platform. We do not sell your personal information to any third party, ever.
TelePeptide's backend systems store the data described in Section 2. (a) Supabase — our cloud database — holds contact, marketing, visit-setup, and relationship data (such as the patient or voucher identifier returned by the contracted medical group). Your clinical care records reside on the medical group's own HIPAA-covered platform. (b) Resend — our email provider — sends transactional and marketing messages; as a matter of policy we do not intentionally include clinical details (medications, doses, labs, or diagnoses) in marketing emails or SMS. Clinical records are processed on the contracted medical group's platform under that group's own agreements. Direct clinical-records privacy questions to the contracted medical group; for data TelePeptide holds, contact legal@telepeptide.org.
TelePeptide Health uses AI-assisted tools in non-clinical contexts across our business, and may expand these uses over time. Current uses include, without limitation: (a) Marketing content generation — AI language models assist in drafting marketing copy, campaign content, and communications; (b) Lead research, enrichment, and scoring — our internal pipeline uses AI to research and score prospective contacts using publicly available and licensed professional information (title, employer, industry); (c) Customer-support operations — inbound support inquiries may be classified and routed with automated tools, and responses may be AI-drafted for human review before sending; and (d) analytics and operational automation. We apply technical guardrails (including redaction and filtering) designed to keep Protected Health Information out of AI tools that are not covered by an appropriate agreement. We do not use AI to make clinical decisions, evaluate patient eligibility, or assist in prescribing; all clinical decisions are made solely by licensed clinicians. If we introduce AI tools into clinical workflows in the future, we will update this policy and ensure any such tool operates under a HIPAA-compliant Business Associate Agreement.
With your consent (given through our cookie banner), we use the following tracking technologies, which may set first-party and third-party cookies: (a) Google Analytics 4 — site usage analytics; (b) Google Ads conversion and remarketing tags — measure ad performance and build remarketing audiences; (c) Meta (Facebook) Pixel — measures ad performance; we enable Meta's "Limited Data Use" restriction on all pixel data; and (d) TikTok Pixel — measures ad performance. None of these load unless you choose "Accept all" in our cookie banner, and choosing "Decline non-essential" (or sending a Global Privacy Control browser signal) keeps all of them off. HEALTH-PRIVACY SAFEGUARDS: we design our configuration so that third-party advertising pixels (such as Meta and TikTok) do not load on pages that could imply a health condition or medication interest — including intake, program, quiz, blog, and portal pages — regardless of your consent choice; site-usage analytics (such as GA4) may run more broadly. We do not use third-party session-replay or session-recording tools on this site. Conversion events we send to ad platforms server-side are designed to contain only a one-way hashed email address and an event name — not health information, page URLs, medication or condition names, or browser identifiers. We do not have Business Associate Agreements with advertising platforms, which is why our configuration is designed to keep health-related information from being transmitted to them. INDEPENDENT OF COOKIE CONSENT, we also use strictly-necessary first-party mechanisms to operate the site and measure our own marketing: first-party cookies for session state, language preference, and site access; a first-party attribution cookie recording the campaign, referrer, landing page, and click identifiers that brought you to us (retained for approximately 90 days and associated with your inquiry if you submit one); and server-side logs of requests to key pages that record the page, referrer, browser type, approximate country, and a truncated or hashed form of your IP address for security, anti-abuse, and traffic measurement. You can opt out of the consent-based technologies at any time through our cookie-consent controls, your browser settings, Google's ad settings, or Meta's ad preferences.
We retain personal information for as long as reasonably necessary to provide services, operate and improve our business, comply with legal obligations, resolve disputes, and enforce our agreements — and as otherwise permitted by applicable law. Copies may persist in routine backups and audit logs for a period after deletion. Clinical intake records are held and retained by the contracted medical group under the medical-records-retention laws of the patient's state of residence (typically at least 7 years for adult records). Payment records are retained as required by applicable tax and financial regulations.
Depending on your state of residence, you may have the right to: (a) access a copy of the personal information we hold about you; (b) correct inaccurate information; (c) request deletion of your personal information (subject to legal retention obligations); (d) opt out of marketing communications at any time; (e) data portability where technically feasible. To exercise any of these rights, submit a request at /data-request — you enter your email address and we send a confirmation link to verify it's you — or email legal@telepeptide.org with your full name and email address. Deletion requests stop marketing communications immediately on confirmation. We will respond within 30 days. Note: deletion requests for PHI submitted during clinical intake are subject to the medical-records-retention laws of the patient's state of residence and to HIPAA.
Residents of California (CCPA/CPRA) and of other states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana) have rights regarding their personal information: to know and access the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of recipients; to correct inaccurate information; to delete personal information (subject to legal retention exceptions); to data portability; and not to receive discriminatory treatment for exercising these rights. Because we use Google Analytics, a Google Ads conversion tag, and — with your consent — Meta (Facebook) and TikTok advertising pixels, certain online identifiers and site-activity/conversion data are disclosed to those companies and may constitute "sharing" for cross-context behavioral advertising under the CCPA/CPRA. You can opt out at any time by selecting "Decline non-essential" in our cookie banner or by emailing legal@telepeptide.org, and we honor Global Privacy Control (GPC) browser signals as a valid opt-out of any sale or sharing. To exercise any right, use our verified request form at /data-request, or email legal@telepeptide.org from the address on file or provide enough information to verify your identity; an authorized agent may submit a request with proof of authorization. We respond within the timeframe required by your state's law (generally 45 days). If we deny a request you may appeal by replying to our response, and where your state provides one you may also contact your state Attorney General.
Some information you give us on this website — such as the wellness program you express interest in — may be considered "consumer health data" under the Washington My Health My Data Act, Nevada SB 370, and the Connecticut Data Privacy Act, even though it is not HIPAA Protected Health Information. We collect this limited, non-clinical interest information only with your consent and use it solely to route your inquiry and help set up your visit with the contracted medical group. We do not sell consumer health data, and we do not share it except with the service providers in Section 5 who help us deliver the service, or as required by law. You may request to access or delete the consumer health data we hold, and may withdraw consent, by emailing legal@telepeptide.org. Clinical health information you enter into the medical group's HIPAA-covered platform is governed by HIPAA and that group's Notice of Privacy Practices, not by this section.
We implement industry-standard security measures including TLS encryption in transit, encryption at rest for sensitive data, role-based access controls, audit logging, and HMAC-signed session tokens. However, no system is 100% secure. In the event of a data breach affecting your information, we will notify you as required by applicable law.
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a minor, contact legal@telepeptide.org immediately and we will delete it.
We may update this Privacy Policy from time to time. Material changes will be communicated by email or a notice on the site at least 15 days before they take effect. The "Last Revised" date at the top of this page reflects the most recent update.
Privacy questions and data requests: legal@telepeptide.org. Unsubscribe requests: help@telepeptide.org. General support: help@telepeptide.org.
TelePeptide Health · 2077 Center Ave, Fort Lee, NJ 07024 · legal@telepeptide.org