Last updated: May 20, 2026
Privacy Policy
Peak Health is a cloud-synced fitness companion. This policy explains what information we collect, why we collect it, which third-party services help us run Peak Health, and the choices you have about your data.
Information we collect
Training data: workouts, exercise notes, onboarding answers and health metrics that you enter in the app. This data syncs securely to your account in the Peak Health Supabase project so you can use the same information across devices. An offline cache keeps your active workout working without a connection; it syncs back when you reconnect.
Account information: when you register we collect the details required to create an account, such as email address or authentication identifiers. Authentication is handled by Supabase Auth.
Product analytics: when you are signed in we send a small set of authenticated, identified product events (for example, workout started, workout logged, onboarding completed) to PostHog Cloud EU. Event properties are deliberately coarse and never include direct PII, free-form notes, or sensitive health detail. Public website pages capture a separate consent-gated funnel; the authenticated Soft-Launch Product Analytics described here is processed under legitimate interest and is subject to the opt-out below.
Connected devices and services: if you choose to connect a device or service such as Garmin, we process the data you authorize in order to bring that information into your account.
Waitlist: if you sign up for the pre-launch waitlist we collect the email address you provide and use our email provider, Resend, to send you the related messages.
How we store and retain information
Offline cache: your account data is stored in the Peak Health Supabase project, and a copy of your active workout is cached on your device so it keeps working offline. You can clear the cache from the settings page or by using your browser’s storage controls.
Peak Health Supabase: account holders have an encrypted copy of their training data in our Supabase project hosted with Supabase in the European Union. We retain this data while your account remains active. If you delete your account we remove the synchronized copy within 30 days.
Third-party services: authentication, database and storage are handled by Supabase. PostHog Cloud EU stores authenticated product analytics events for 12 months. When your Peak Health account is deleted we request the corresponding PostHog person to be deleted on a best-effort basis (it does not block the rest of the account-deletion flow).
- Clearing the offline cache removes the locally cached copy immediately
- Account deletion removes the synchronized copy from the Peak Health Supabase project
Third-party services we rely on
Supabase (authentication and managed data platform) handles sign-in and hosts our synchronized database and storage.
Vercel (application hosting) operates the infrastructure that serves Peak Health.
Resend (email) delivers the waitlist messages described above.
Garmin (optional device integration) provides the activity and health data you authorize when you connect a device or service.
PostHog (product analytics) processes authenticated product events for Peak Health on PostHog Cloud EU (Frankfurt, AWS eu-central-1) under a signed Data Processing Agreement. PostHog uses a small set of operational subprocessors covered by EU Standard Contractual Clauses; the current list is available at https://posthog.com/subprocessors. Public website analytics for unauthenticated visitors is gated by your cookie / analytics consent banner; identified product events for signed-in users rely on legitimate interest (Article 6(1)(f) GDPR) and can be objected to from Settings → Privacy.
- Each provider processes data in accordance with its own privacy policy
- We share the minimum data necessary to operate the service
- We require providers to follow industry-standard security controls
Your choices and rights
Clear the offline cache on your device at any time from the in-app settings or by clearing your browser’s storage; this removes the locally cached copy of your active workout without affecting the synced data in your account.
Exercise your right to object (Article 21 GDPR) to authenticated product analytics from Settings → Privacy. The opt-out suppresses both client-side and server-side PostHog capture for your account; you do not need to grant or revoke a cookie banner to exercise this right.
Request deletion of your Peak Health account by emailing privacy@peakhealth.es. We will remove the synchronized copy of your data from our Supabase project within 30 days, confirm when the process is complete, and issue a best-effort person-delete request to PostHog so your analytics history is erased as well.
You can export or delete the data stored in your Peak Health account by contacting us. The offline cache on your device can be cleared at any time through your browser.
