Privacy Policy
Last updated: August 26, 2026
This policy covers two things: the website, where you can ask to join the Peakly test programme, and the Peakly app itself, which processes health data about you. It explains what is collected, why, on what legal basis, and how to get it back or have it destroyed.
1. Who is responsible
The controller for both the website and the app is Mert Filizay, Sommerstraße 54d, 81543 München, Germany. Email: hello@apppeakly.com. Write to that address with any question about your data, or to exercise any of the rights below.
2. What the website collects
When you ask for test access we store your email address and, if you give them, your name and which phone you use. We also record that you consented, the exact wording you agreed to, and when. We send you an email to confirm the address is really yours; nothing else is sent until you click it.
3. What the app collects (health data)
The app stores your account email and the data you enter: body weight, body fat percentage, fitness measurements such as VO2max, resting heart rate and one-rep maxes, your training sessions, and everything you log as food or drink. Under Article 9 GDPR this is special-category health data. We process it only on your EXPLICIT consent, which the app asks for separately and which you give by ticking a box that is never pre-ticked. Without that consent the app does not run. To estimate your basal metabolism the app also uses your age, sex and height; these are ordinary personal data (Article 6 GDPR), used to compute your calorie and protein targets, not special-category health data.
4. Smart features and transfer to the United States
The smart features (training plans, workout writing, calorie estimates, meal ideas) are optional and OFF unless you switch them on. If you consent, the relevant parts of your data (your goal, your sessions, your body weight and the food you describe) are sent to Anthropic PBC in the United States, which acts as our processor and does not use it to train its models. If you photograph a meal, or a product's nutrition label, that photograph is sent as well, for that one estimate: it is not uploaded to us, not stored anywhere, and not attached to the log that comes out of it. We keep the food and the numbers, never the picture. This is a transfer to a third country under Chapter V GDPR and rests on your consent (Art. 49(1)(a)). You can withdraw it at any time in the app under Settings, Privacy: the smart features stop immediately and everything else keeps working.
5. Why we process it, and on what basis
The email is used only to contact you about the test programme: to confirm your address, and to send you the invitation with the link and the installation steps. Your health data is used to run the app for you: to compute your calorie and protein targets, to plan and price your training, and to show you your own progress. The legal basis is your consent (Art. 6(1)(a) and, for health data, Art. 9(2)(a) GDPR). Nothing is used for advertising, and nothing is sold.
6. How long we keep it
The website signup is kept until the test programme ends, or until you use the deletion link in any of our emails, whichever comes first. Your app data is kept for as long as you have an account. Delete your account and every row attached to it is erased immediately and permanently.
7. Your rights
You can ask for access to your data, correct it, have it deleted, restrict or object to its use, and receive a copy in a portable format. The app gives you the last two directly: Settings, Privacy has a button that downloads everything we hold about you as a JSON file, and a button that deletes your account and all of it. You can withdraw any consent at any time, and withdrawing is as easy as giving it. You also have the right to complain to a supervisory authority.
8. Who else sees it
We use processors, not partners: Supabase (database and authentication, EU region), Vercel (website hosting), Resend (the emails we send you), and Anthropic (the smart features, United States, only with your consent). Each is bound by a data processing agreement. Nobody else receives your data, and it is never sold or used for advertising. One lookup goes outward and is worth naming: when a product label you scanned shows a barcode, our server asks Open Food Facts (an open, non-profit food database in France) what that barcode is. We send the number and nothing else; they never see you, your device or your account, and we store nothing of theirs. Their data is used under the Open Database License and credited where it is shown.
9. Email lists
There are three, and all of them are off until you switch them on: a weekly summary of your own training, product updates, and occasional news about Peakly. The legal basis for each is your consent (Art. 6(1)(a) GDPR); for the last one German law (§ 7 UWG) requires that consent in advance, which is why no box is ever ticked for you. Every email carries a link that removes you from that one list in a single click, without logging in, and without touching the others. We keep a record of what was sent to whom and when, so that we can prove what we did and never send the same thing twice.
Notifications
If you switch notifications on, your browser gives us a push subscription: an address for that one device, plus the keys we encrypt each message to. We store it, together with your time zone, so that a reminder arrives at the right hour where you actually are. The legal basis is your consent (Art. 6(1)(a) GDPR), and switching notifications off deletes the subscription rather than merely marking it inactive. We only ever notify you about sessions you put in your own calendar. There are no streaks, no reminders that you have not trained, and a day with nothing planned sends nothing at all. The message travels through your browser vendor's push service (Apple, Google or Mozilla, depending on your device), which relays it but cannot read it: the content is encrypted for your device's key alone.
Questions? Write to hello@apppeakly.com.