Privacy Policy
Effective Date: August 25, 2026
1. Introduction
elephantmilk asia LLC (“we,” “us,” or “our”) operates the website and mobile application known as Pinnacle Pulse (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, including any health, biometric, and wearable data that may be processed by or in connection with Pinnacle Pulse.
By using the Service, you consent to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Account and Contact Data
When you create an account or join our waitlist, we may collect:
- Name
- Email address
2.2 Waitlist Data
When you sign up for our waitlist through the website, we collect:
- Email address (required)
- Name (optional)
- Source (e.g., hero section, pricing section, final CTA)
- UTM parameters (utm_source, utm_medium, utm_campaign) for marketing attribution
2.3 Health and Biometric Data (App)
When you use the Pinnacle Pulse application, the Service may process the following categories of health-related data. Much of this data is processed and stored on your device only:
- Peptide protocol data: substance names, dosage, unit (e.g., mcg, mg), injection site, protocol combinations
- Biometric inputs: heart rate variability (HRV), soreness scores (1–10), sleep duration and quality
- Body scan data: images from multi-angle captures, 3D avatar data, body measurements (e.g., shoulders, chest, waist, thighs in cm), morph metrics (e.g., chest, arms, waist, definition, vascularity)
- Skin scan photos: close-up photos of an area you choose (including an optional Face zone) to track skin over time
- Wearable sync data: resting heart rate, HRV, sleep score, step count, SpO₂, and similar metrics from connected devices (e.g., Xiaomi Smart Band 10, HUAWEI Band 10)
- Blood panel data (Pro tier): laboratory results such as testosterone, IGF-1, HGH, cortisol, and related biomarkers when you choose to integrate data from partner labs
Our AI forecasting (EvoEngine) runs on-device using TensorFlow Lite. Health and biometric data used for predictions are processed locally and do not leave your device unless you explicitly use features that sync data (e.g., cloud backup, if offered).
For a detailed, Apple App Store and Google Play-style breakdown of exactly what the app collects, see our App Privacy Details page.
2.4 Device and Usage Data
We may collect or receive:
- Device model and operating system
- Session identifiers
- Page or in-app event data (e.g., event_type, event_data) where applicable
2.5 Automatically Collected Data
When you use our website or app, we may automatically receive:
- IP address (used for rate limiting and security; not stored persistently for identification)
- Browser type and version
- Referral URLs and referring domains
2.6 Photos, Face Data, Skin Close-ups, and Third-Party Processing
Pinnacle Pulse does not use Face ID, TrueDepth, or facial mapping. We do not collect face data to unlock the device, identify you, or for advertising. Two kinds of photos may include a face:
- 3D body scans are full-body, head-to-toe images. Your face may appear as part of that photo. Pose detection runs on your device and is not uploaded as a face template. After you tap Allow, these photos are sent to fal.ai (Fal, Inc.) for 3D reconstruction and a copy is stored in Google Firebase linked to your account.
- Skin scans are close-ups of an area you choose (Face, neck, décolleté, hands, scar/spot, or other). The optional Face zone is a photo of your face, used only to track skin over time. Other zones are not face scans, though a close-up might still show part of the face. Skin photos are never sent to fal.ai. After you tap Allow, they are stored on your device and, if you are signed in, in Google Firebase linked to your account.
Collection: photos you capture or pick in the app.
Use: personal progress tracking (3D body model or skin comparison) — not identity, not device unlock, not advertising.
Sharing: only after an in-app Allow / Don’t allow dialog. Don’t allow means the photo is not uploaded (3D) or not saved or uploaded (skin).
Retention / deletion: until you delete the scan or delete your account in Profile & Settings. Deleting your account removes associated Firebase records.
3. How We Use Your Information
We use the information we collect to:
- Manage waitlist sign-ups and communicate product updates and launch information
- Provide, operate, and improve the Service
- Run AI and prediction features on your device (health data remains on-device for core forecasting)
- Analyze usage patterns and improve user experience (where analytics are used)
- Send transactional or marketing communications where you have opted in
- Comply with legal obligations and enforce our terms
4. On-Device Processing
Our EvoEngine and related forecasting features run on your device using TensorFlow Lite. Peptide logs and biometric data used for those predictions are processed locally. This is separate from optional photo features: 3D body-scan photos leave the device only after you Allow sharing with fal.ai, and skin close-ups (including Face) are stored in Firebase only after you Allow — they are never sent to fal.ai.
5. Data Sharing
We do not sell your personal information. We may share your information only in the following circumstances:
- Service providers: With vendors who assist in hosting, analytics, email delivery, or other operational needs, under contractual obligations to protect your data
- fal.ai (Fal, Inc.): Full-body 3D scan photos only, after in-app Allow, for 3D reconstruction. Skin photos (including Face close-ups) are not shared with fal.ai
- Google Firebase: Account-linked copies of scans and logs you save (including 3D results and skin close-ups after Allow), so you can view history across devices
- Legal requirements: When required by law, court order, or governmental authority
- Protection of rights: To protect our rights, your safety, or the safety of others, or to investigate fraud or violations of our terms
6. Data Retention
Waitlist data is retained until the launch of the product or until you request deletion. Photos and scan history you save in the app are kept until you delete the scan or your account. 3D body photos processed by fal.ai are retained on fal.ai’s systems according to their policy; we do not send skin close-ups to fal.ai. For other data stored on our systems, we retain it only as long as necessary to fulfill the purposes described in this policy or as required by law.
7. Your Rights
Depending on your location, you may have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data
- Data portability: Request your data in a structured, machine-readable format
- Opt-out: Unsubscribe from marketing communications or withdraw consent where applicable
To exercise these rights, contact us using the details in Section 13. We will respond in accordance with applicable law.
8. Cookies and Tracking
We use minimal tracking. UTM parameters and session identifiers may be used for attribution and basic analytics. We do not use cookies or similar technologies for advertising purposes on the waitlist or core app experience. Any future use of cookies or tracking will be disclosed and, where required, subject to your consent.
9. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a minor, please contact us and we will take steps to delete it.
10. International Data Transfers
Your information may be processed in countries other than your country of residence. We take appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms) to ensure that your data is protected in accordance with this Privacy Policy and applicable law.
11. Security Measures
We implement technical and organizational measures to protect your data, including encryption where applicable, rate limiting to prevent abuse, and access controls. Data that syncs to our systems is protected in transit and at rest. You are responsible for securing your device and account credentials.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Effective Date.” Material changes may be communicated via email or a prominent notice in the Service. Your continued use after the effective date constitutes acceptance of the updated policy.
13. Contact Information
For questions about this Privacy Policy or to exercise your privacy rights, contact:
elephantmilk asia LLC
Pinnacle Pulse
contact@pinnaclepulse.io