Skip to content
Peak Streak

Privacy Policy

Peak Streak · Effective from 12 July 2026

This policy explains how the Peak Streak mobile app and peakstreak.app collect, use, disclose and protect personal data. It also explains your choices and rights. It covers the first public release and does not describe a disabled integration as active.

1. Controller and contact details

The controller is Marcin Tobała Digital Media, Służba Polsce 4/18, 32-200 Miechów, Poland, VAT/NIP: PL6591489319. For a privacy request or complaint, email support@peakstreak.app or use the contact details on Peak Streak Support.

Peak Streak is established in Poland and does not require a separate representative in the European Economic Area. If UK GDPR applies and a UK representative must be appointed, the UK storefront will not launch until the representative's verified details are added here.

2. When this policy applies

This policy applies when you use the app, create a Peak Streak account, join a Friend or Crew feature, contact support, visit peakstreak.app or submit a form made available there. Apple and Google separately control the account, store, billing and transaction processing they determine under their own notices.

You can use supported guest features without creating a cloud account. Data that remains only on your device is not collected by us. It becomes data we process if you sign in and back it up to your account, share it through a connected feature or send it to support.

3. Personal data we process

The data depends on the features and choices you use:

  • Account and sign-in data — email address, password hash held by our authentication provider, Apple or Google sign-in identifier, display name, Peak Streak account ID and authentication events. We do not receive your Apple or Google password, ask for your date of birth or store an age declaration.
  • Profile and preferences — built-in avatar, optional profile photo or background, language, time zone, privacy choices, consent records, notification settings and versioned acceptance records for the Terms and Community Guidelines. A policy-acceptance record identifies the policy type and version, source and acceptance time; it is not an age record.
  • Challenge, Journey, event, fitness and wellness data — challenges and programs you join; commitments and targets; sets, reps, timers, water and other entries; check-ins, rest days, streaks, event participation and results, rewards, reflections, progress, completion source and timestamps.
  • Friends, Crew and community data — invitations and relationships; Crew membership, roles and daily status; Team Streak and Shield outcomes; reactions, rescue actions and private Crew Feed notes; mute and block choices; reports, report reasons, moderation decisions and the related audit trail.
  • Photos and other user content — an optional profile image and content you deliberately submit. The release does not use photo proof for challenge completion and does not allow links in Crew Feed notes.
  • Purchase and entitlement data — product, store, transaction reference, storefront locale and currency, Premium entitlement, trial and subscription status. Apple or Google processes payment details; we do not receive your full card or bank details.
  • Push data — notification permission and preferences, app-instance token, routing data, delivery state and limited delivery records. Notification previews avoid private Crew Feed text and detailed fitness or wellness values.
  • Diagnostics, security and network data — device and operating-system type, app version, installation identifier where needed, IP address in ordinary server logs, error details, stack traces, performance information, security events, rate-limit events and abuse-prevention signals. The release is designed to redact tokens, email addresses, account IDs and private user content before diagnostic transmission.
  • Optional product analytics — only after opt-in, an allowlist of product events and coarse app context is sent to PostHog EU using a pseudonymous installation identifier. We do not include names, email addresses, Crew Feed text, challenge targets, photos or fitness and wellness values. Autocapture and session replay are disabled.
  • Optional marketing attribution — the AppsFlyer SDK is present in the public mobile release. On Android, it does not initialise or start before the separate Peak Streak marketing-attribution opt-in. On iOS, choosing that opt-in leads to Apple's App Tracking Transparency request, and the SDK starts only if Apple reports the status as authorised. If the status is denied, restricted or not yet determined, Peak Streak does not start the iOS AppsFlyer SDK or its RevenueCat attribution bridge. After the applicable gate is satisfied, AppsFlyer performs automatic install and session measurement and may receive an AppsFlyer installation identifier, IP address, app and device characteristics, operating-system information, install referrer, campaign and ad-engagement information and public campaign destination. On Android, this can include the Google Advertising ID (GAID). On iOS, the AppsFlyer installation ID and IDFA may be used only while ATT is authorised. The mobile client sends only paywall view with technical release-channel context. It removes feature, source, surface and invitation context and never sends challenge starts or completions, check-ins, wins, Crew or shared-day progress, Events, Hydration, health, fitness or habit data. The mobile client does not send a purchase or revenue event directly to AppsFlyer. Once the separately validated RevenueCat-to-AppsFlyer production connection is enabled, RevenueCat may send subscription lifecycle events, product identifier, revenue amount and currency directly to AppsFlyer, including initial purchase, trial conversion, renewal, cancellation, refund or another lifecycle category configured for the integration. RevenueCat receives only the AppsFlyer installation ID and sharing filter for this connection, not IDFA, IDFV, GAID or IP. On iOS, that server-to-server bridge is also disabled unless ATT is authorised. Until the provider connection and applicable permission gate are enabled, those events are not sent. We also send a consent signal that advertising personalisation is not permitted. We do not send AppsFlyer a Peak Streak or Supabase account ID, name, email address, private Crew or invite token, challenge target, fitness or wellness value or Feed content.
  • Apple tracking disclosure — Apple defines advertising measurement that links app or device data with third-party campaign data as tracking. Peak Streak therefore declares Tracking: Yes in App Store privacy details for iOS users who grant both choices, even though advertising personalisation remains off. No iOS AppsFlyer tracking occurs after ATT denial or restriction.
  • Support, privacy and moderation correspondence — messages, request type, attachments you choose to provide, verification steps, case status, our response and necessary delivery records.
  • Website and waitlist data — security logs and, if a waitlist form is made available and you submit it, your email address, submission time and referral code. We do not add a waitlist address to unrelated marketing without a separate lawful basis.

4. Where the data comes from

We receive data directly from you; from the app and device when you use a feature; from accepted Friends or Crew members when they interact with you or report content; from Apple or Google when you use their sign-in or store services; from RevenueCat about the resulting entitlement; and from our security, hosting and delivery providers when they report an error, delivery event or abuse signal.

If you opt into marketing attribution, and on iOS also authorise ATT, AppsFlyer receives the permitted technical install and campaign data from the app, device, app store, install referrer and the advertising partner responsible for a campaign. When the validated revenue connection is enabled, it may also receive the subscription data described above from RevenueCat. We receive AppsFlyer's resulting attribution and aggregated campaign reports.

5. Fitness, wellness and health-related data

Peak Streak is designed for general fitness and wellness. We do not ask for diagnoses or medical records. Exercise, hydration, reflection and progress entries may nevertheless concern your general activity and wellbeing. We do not use them to diagnose a condition, infer a medical record or build a medical profile.

We use these entries only to provide the tracking, progress, safety and private social features you request. The Article 6 basis is performance of our contract with you. Do not enter diagnoses, medical records, symptoms, treatment information or another person's health information. If a future feature intentionally requests or infers special-category health data, we will complete the required assessment and introduce a separate explicit choice before enabling that processing.

We do not use fitness or wellness entries for targeted advertising, insurance or employment decisions, medical diagnosis, or solely automated decisions that produce legal or similarly significant effects. Do not place diagnoses, medical records or another person's health information in a Crew note.

6. Purposes and legal bases

  • Provide the service — create and secure an account, back up progress, calculate challenge and Crew outcomes, restore a workspace and provide requested support. Basis: performance of a contract, Article 6(1)(b).
  • Provide general fitness and wellness tracking — process the challenge entries you choose to save so we can calculate progress, restore your workspace and provide the private Crew features you request. Basis: performance of a contract, Article 6(1)(b).
  • Manage Premium — validate purchases, restore entitlements, provide paid access and handle purchase support. Basis: contract; legitimate interests in preventing entitlement fraud; and legal obligations for records we must retain.
  • Protect people and the service — rate limits, report and block tools, moderation, security, fraud prevention, diagnostics and incident response. Basis: our legitimate interests in a safe, reliable service; legal obligation where applicable; and establishment, exercise or defence of legal claims where necessary.
  • Send communications — account and security messages, responses you request, and optional reminders or Crew notifications you enable. Basis: contract for necessary service messages; your request or consent for optional reminders; legitimate interests for narrowly necessary security and safety notices.
  • Measure product use — the limited PostHog EU event allowlist only after opt-in. Basis: consent, Article 6(1)(a).
  • Measure paid marketing — attribute consented app installs and public campaign links, measure paywall views only and, after the validated provider connection is enabled, subscription revenue and lifecycle outcomes, and identify invalid advertising traffic through AppsFlyer. We do not use this processing to personalise advertising or build cross-company behavioural profiles. Basis: consent, Article 6(1)(a).
  • Operate and protect the website — deliver pages, prevent abuse and respond to requests. Basis: legitimate interests in a secure and available website.
  • Measure public website use — when configured and only after your analytics choice, understand aggregate traffic, campaign sources, engagement and technical performance. We exclude private /i/… app-link routes and do not attach a Peak Streak account ID. Basis: consent, Article 6(1)(a).
  • Measure and improve website campaigns — when configured and only after your marketing choice, attribute public-site and app-handoff actions, optimize campaign delivery and create advertising audiences using Google Ads, Meta Pixel or TikTok Pixel. We do not send health, fitness, habit, Crew, invite-token or account data from the website. Basis: consent, Article 6(1)(a).
  • Manage a waitlist — record and respond to a submission you choose to make. Basis: consent or steps you request before launch access, depending on the form shown.
  • Meet legal duties — respond to lawful requests and keep required tax, accounting, safety or dispute records. Basis: legal obligation and legal claims.

Where we rely on legitimate interests, the interests are service security, abuse prevention, reliable operation, defence of claims and protection of users. We balance those interests against your rights, minimise the data and provide an objection right where applicable.

7. What is required and what is optional

To create and use a cloud account, you must provide an email address or supported sign-in identifier and the data needed to secure the account. Without it, we cannot create or authenticate that account. Crew requires an account because members and safety controls must be identifiable to the service.

A profile photo, product analytics, marketing attribution, push notifications, social participation and a purchase are optional. Product analytics and marketing attribution have separate choices. Refusing or withdrawing either choice does not remove account, challenge, Crew or Premium access. Fitness, hydration or social entries are required only when you choose the corresponding feature. If you do not provide enough information about a support request, we may be unable to locate the issue or verify the account.

On iOS, Peak Streak's marketing-attribution choice and Apple's ATT permission are separate. Opting in inside Peak Streak does not override Apple. If ATT is denied, restricted or not yet determined, the iOS AppsFlyer SDK and RevenueCat attribution bridge remain off. You can deny ATT without losing any account, challenge, Crew or Premium feature.

8. Social visibility and moderation

  • Accepted Crew members see the display name, built-in avatar and daily status needed to run the Crew. Optional photos and broader statistics follow the applicable privacy choice.
  • Crew Feed notes and reactions are available only to accepted members of that Crew, subject to blocks, removals and moderation. Other members may still take screenshots or repeat what they see, so do not post information you would not want the selected group to know.
  • A report is available to authorised moderators and necessary providers. Reporting hides the item from the reporter immediately; moderators may remove it for everyone or act on an account. We do not use private Crew content to train an external generative-AI model.
  • A share card contains only the information you deliberately choose to share and excludes private notes and detailed fitness or wellness entries by default.

The Community Guidelines explain reporting, blocking, prohibited content, moderation and appeals.

9. Service providers and other recipients

We do not sell personal data, disclose private app data to data brokers or use fitness, wellness, Crew, invite or account data for advertising. After a separate website marketing choice, a configured advertising platform may receive limited public-site interaction data for campaign measurement, optimization or audiences as described in the Cookie Policy. We provide only the data needed for the purposes described above:

  • Supabase — Processor for authentication, account storage, challenge data, private social features, private media and server functions. The primary project is hosted in Ireland. ( privacy notice )
  • RevenueCat — Processor for purchase validation, subscription status and Premium entitlements. It receives a Peak Streak account ID for signed-in users and store transaction information, but not full payment-card details. After valid marketing consent, the app gives RevenueCat only AppsFlyer's own installation ID and a sharing filter so RevenueCat can send validated subscription and revenue events once that integration is enabled. Peak Streak does not ask RevenueCat to collect IDFA, IDFV, GAID or IP for this integration. On iOS, the bridge is available only while Apple App Tracking Transparency status is authorised. ( privacy notice )
  • Firebase Cloud Messaging (Google) — Processor for push-notification delivery using an app-instance token. Peak Streak does not use Firebase Analytics. ( privacy notice )
  • PostHog EU — Processor for optional, consent-only product analytics in the EU. Autocapture and session replay are disabled, and the release uses a pseudonymous installation identifier rather than the Peak Streak account ID. ( privacy notice )
  • AppsFlyer — Processor for optional mobile campaign attribution, public deferred campaign links, paywall-view and subscription-revenue measurement and advertising-fraud prevention. It does not receive a Peak Streak account ID, health, fitness, habit, challenge, Crew or Event data. On Android, it may receive the Google Advertising ID only after marketing-attribution opt-in. On iOS, the SDK and RevenueCat bridge start only after both that opt-in and Apple App Tracking Transparency authorisation; only then may the AppsFlyer installation ID and IDFA be used. ( privacy notice )
  • Sentry — Processor for app stability, crash and error diagnostics. Session replay, screenshots, view-hierarchy capture and deliberate account identification are disabled. ( privacy notice )
  • Resend — Processor for service email, support delivery and privacy-safe moderation alerts. Some account, message metadata and logs may be processed in the United States even when email delivery is routed through an EU region. ( privacy notice )
  • Vercel — Processor for hosting, content delivery and security of peakstreak.app. Vercel Web Analytics and Speed Insights are disabled for this release. ( privacy notice )
  • Apple — Independent controller for Apple ID, Sign in with Apple, App Store distribution, App Tracking Transparency permission status, purchases, subscriptions, tax and Apple-controlled transaction records. ( privacy notice )
  • Google — Independent controller for Google Account, Google sign-in, Google Play distribution, purchases, subscriptions, tax and Google-controlled transaction records. Google also processes FCM data for us as described above. ( privacy notice )

When we activate an integration for a paid campaign, the advertising platform that delivered that campaign may receive a limited install, paywall-view or subscription postback through AppsFlyer after your opt-in and, on iOS, ATT authorisation. The exact platform depends on the campaign and its own privacy notice applies to its independent processing. We do not use these postbacks for advertising personalisation or custom-audience building.

We may also disclose data where required by law, to protect a person or our legal rights, or as part of a sale, reorganisation or transfer of the service. A successor may process the data only for compatible purposes and must receive any notice or consent required by law.

10. International transfers

The primary Supabase project and PostHog service are configured in the European Union. Other providers or their subprocessors may process data in the United States or other countries. Where personal data leaves the EEA or UK without an applicable adequacy decision, we use the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or another lawful safeguard, together with a transfer assessment where required.

You may request information about or a copy of the relevant safeguard by emailing support. We may redact confidential commercial information while still explaining the protection.

11. Retention

  • Guest data on a device remains until you clear that workspace, remove the app or the operating system removes it. Device backups are controlled by Apple or Google.
  • Account, profile, challenge, fitness and social data remains while the account is active. On valid deletion, it is removed or de-identified in active systems unless a specific legal exception applies.
  • Crew notes and reactions remain until deleted, the account is deleted or they are removed through moderation. A copy connected to a live safety report may remain until that report and any applicable claim period are resolved.
  • Push data is disabled when you turn the feature off, sign out, delete the account or the token is reported invalid. Limited delivery records are normally removed after 30 days and failed-delivery records after 90 days.
  • Moderation records are restricted to authorised staff. Dismissed reports are normally deleted after 90 days and moderator-action records after 180 days. A live report, legal hold or serious safety investigation may be kept longer only while necessary.
  • Optional analytics stops collecting when consent is withdrawn. Pseudonymous app event history cannot be connected to an account after the app rotates its identifier. Website analytics uses no app account ID or private app-link token. When enabled, each is kept only for the shortest period configured for its measurement purpose and is then deleted or irreversibly aggregated. Provider and cookie periods are listed in the Cookie Policy.
  • Optional marketing attribution stops collecting when you withdraw consent and, on iOS, whenever ATT is no longer authorised: the app instructs AppsFlyer to anonymise future traffic, stops its SDK, sets RevenueCat's AppsFlyer sharing filter to block all partners and clears its AppsFlyer ID. A device-level retry barrier repeats that provider cleanup before another RevenueCat revenue operation if a network or app interruption prevents the first sync. Withdrawal or ATT revocation does not rewrite campaign reports already produced. AppsFlyer states that user-level retention varies by reporting method and advertising-partner requirements, and that End User Data is not normally retained for more than 24 months except where a customer directs otherwise or law permits or requires it; aggregated data may remain for up to 25 months. We configure and review the shortest period needed for campaign measurement. For a signed-in account with a stored AppsFlyer installation identifier, account deletion automatically starts and tracks a processor-erasure request. A guest or older unmapped installation may require support and the technical AppsFlyer identifier so that historical installation-level data can be located.
  • Optional website campaign measurement stops collecting when website marketing consent is withdrawn. Public-site events already processed may remain in provider reports for the configured retention period or as aggregate statistics. The Cookie Policy lists the typical technologies and periods; we configure the shortest period needed for campaign measurement.
  • Diagnostics and website security logs are kept for a short operational period based on troubleshooting and security needs. A restricted copy is kept longer only while needed for a specific incident, legal claim or binding obligation.
  • Support and privacy cases remain while the case is open and afterwards only for the limited period needed to demonstrate the response, resolve a dispute and meet applicable limitation or legal-duty periods. Unnecessary attachments and identity evidence are removed earlier.
  • Waitlist data, if collected, remains until launch access is delivered, you withdraw the request or the waitlist is closed, then is removed within 30 days unless you separately opt into another communication.
  • Purchase, tax and legal records remain for the period required by law or the independent store controller. They do not include detailed challenge content.

Encrypted backups may retain a protected copy until overwritten under the verified provider schedule. Backup data is put beyond ordinary use. If a disaster-recovery restore occurs before expiry, outstanding deletion instructions must be reapplied before restored data returns to ordinary processing. We do not promise one universal backup period until every production provider's longest schedule has been verified.

12. Your choices and rights

Subject to applicable law, you may request access to, correction or erasure of personal data; restriction of processing; and a portable copy of data processed automatically on the basis of consent or contract. You may object to processing based on legitimate interests and may withdraw consent at any time. Requests are normally free of charge.

You can withdraw product-analytics and marketing-attribution consent separately in the app's privacy settings. Withdrawing marketing-attribution consent stops future AppsFlyer transmission from that installation. For a signed-in account with a stored AppsFlyer installation identifier, the in-app account-deletion flow automatically submits and tracks the available AppsFlyer processor-erasure request. Because we never send AppsFlyer a Peak Streak account ID, historical erasure for a guest or older unmapped installation may still require support and the technical AppsFlyer installation identifier, preferably before uninstalling or resetting the app. Refusing or withdrawing consent does not affect prior lawful processing.

Website analytics and marketing choices can be changed at any time through “Cookie settings” in the footer or on the Cookie Policy page. Withdrawal updates the provider consent signals, stops future allowlisted website events and removes first-party provider cookies that peakstreak.app can delete.

On iOS, you can also change ATT permission in system Settings. If Apple reports the permission as denied or restricted, Peak Streak does not start or continue the iOS AppsFlyer SDK or RevenueCat attribution bridge. ATT authorisation by itself does not enable AppsFlyer if the separate Peak Streak marketing-attribution choice is off.

We respond without undue delay and ordinarily within one calendar month after receiving the request and information reasonably necessary to verify identity. For a complex request or multiple requests, we may extend the period by up to two further months and explain the extension within the first month. We do not require you to use the account email if another proportionate verification method is available.

You may complain to the President of the Personal Data Protection Office in Poland at uodo.gov.pl. If UK GDPR applies, you may also complain to the Information Commissioner's Office. Contacting us first does not limit a regulatory or court remedy.

To make a data-protection complaint to us, email support with the subject Data protection complaint. We acknowledge a UK data-protection complaint within 30 days, investigate it without undue delay, keep you appropriately informed and tell you the outcome.

13. Account and data deletion

In the app, open You → Settings → Delete account & data and confirm Delete account and data. You can also use our account deletion instructions or contact support. We erase applicable data from active systems and instruct processors where required. Shared Crew history may retain a pseudonymous membership and Team Day fact labelled Deleted member so another person's outcome remains correct. The account UUID, profile, commitment payload and private Feed content are removed. Because a small Crew may recognise who left from context, we describe this as pseudonymisation rather than anonymity.

Account deletion also applies the on-device marketing-attribution withdrawal state so the AppsFlyer SDK stops future transmission. For a signed-in account with a stored AppsFlyer installation identifier, Peak Streak automatically submits the processor-erasure request, retries and checks it until AppsFlyer confirms completion, subject to a lawful retention exception. A guest or older unmapped installation may still require support and the technical AppsFlyer identifier to locate historical installation-level records.

For a signed-in user who consented, Peak Streak privately registers AppsFlyer's own installation identifier against the account in Supabase solely to submit and track that automatic processor-erasure request. This private mapping is not used for marketing, and we never send the Peak Streak or Supabase account ID to AppsFlyer as a customer user ID or other identifier. The capped registry is not readable by app users, survives Auth deletion only while the durable erasure barrier runs, and is purged with the raw identifier after AppsFlyer confirms completion. We retain the completed deletion barrier and AppsFlyer's request log as the minimal audit evidence.

Deleting a Peak Streak account does not cancel an App Store or Google Play subscription and does not erase transaction records controlled independently by those stores.

14. Website storage and analytics

The website uses storage needed for security and one necessary cookie to remember the version and result of your privacy choice. Optional analytics and advertising tools are off by default, load only after the matching category is accepted and remain disabled on private /i/… app-link routes. Rejecting them does not restrict the site or app.

This release currently has no optional website provider ID configured. The Cookie Policy displays the active build status, purposes, typical technologies, providers and durations. Google Search Console ownership verification is not visitor analytics and does not set a measurement cookie.

The AppsFlyer integration described elsewhere in this policy remains inside the mobile app; peakstreak.app does not load an AppsFlyer browser SDK or pixel.

15. Age requirement

Peak Streak is intended for people aged 16 or older. The app does not ask for a date of birth or age band, request an age declaration, verify age or block a feature through an in-app age check. Users aged 16 or 17 may still receive children's privacy protections under local law. Contact support if you believe a younger person created an account so we can investigate and take the steps required by law.

16. Automated processing

Peak Streak automatically calculates streaks, progress, challenge outcomes, Premium entitlement and safety rate limits from the rules described in the app. These calculations do not produce legal or similarly significant effects. Final account suspension and moderation decisions are not made solely by automated means.

17. Security

We use encryption in transit, access controls, private storage rules, restricted staff access, audit records, data minimisation and contracted providers. No system can be guaranteed completely secure. We investigate incidents and notify affected people and authorities where law requires.

18. Disabled and future integrations

The release does not import data from Health Connect or Apple Health or send data to Google Gemini or another external model for generative-AI coaching. Local deterministic coaching may still appear. Before any such integration is enabled, we will update the privacy assessment, this policy, store disclosures and any required just-in-time consent.

19. Changes to this policy

We may update this policy when the service, provider set or law changes. We will publish the new effective date and give an in-app or email notice before a material change where required. If a new purpose requires consent, we will ask rather than treat continued use as consent.

20. Contact

Email support@peakstreak.app or visit Peak Streak Support. The controller is Marcin Tobała Digital Media, Służba Polsce 4/18, 32-200 Miechów, Poland, VAT/NIP: PL6591489319.