LEGAL

Privacy Policy

Last updated: September 25, 2026

This Privacy Policy explains how the SelfPeak mobile application ("SelfPeak", "the App", "we", "our", or "us") collects, uses, stores, and protects your personal data, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Croatian Act on the Implementation of the GDPR.

1. Data Controller

The data controller responsible for your personal data is:

2. Information We Collect

We collect the following categories of personal data:

3. How We Use Your Information & Legal Bases

We process your data on the following GDPR Article 6 legal bases:

4. AI Personalisation & Health Data

SelfPeak generates workouts and coaching using the Google Gemini API. When you enable AI Personalisation, the data needed for a plan β€” which may include your fitness level and any injuries you entered β€” is sent to Google for processing. Because injuries are health data, we ask for your explicit consent before any AI request is made, and no AI call happens without it. You can withdraw consent at any time in the App under Profile β†’ AI Personalization; withdrawing disables AI features while the rest of the App keeps working.

Apple Health (optional, iPhone only)

SelfPeak can connect to Apple Health. It is off until you turn it on in Profile β†’ Apple Health, and iOS then asks you which data types to allow.

5. In-App Usage Analytics

The App records a small set of usage events so we can see which parts of SelfPeak work and which do not, and fix them.

6. Data Storage and Security

Your account and synced data (workout history, plans, and profile) are stored on Supabase servers located in the European Union (Frankfurt, Germany). A copy is also kept locally on your device for offline use. Authentication tokens are stored in the device's hardware-backed secure storage (iOS Keychain / Android Keystore). All traffic is encrypted in transit over HTTPS.

Progress photos stay on your device. Photos you add to your progress journal are saved only inside SelfPeak on your phone. They are not uploaded to our servers, not synced to your account, not sent to Apple Health or to Google Gemini, and never used for analytics or advertising. Only the capture date is read from a photo you choose from your library; other photo metadata, including location, is not kept. You can delete a photo at any time in the journal, and all progress photos are deleted from the device when you sign out or delete your account. Like other app data, they may be included in your own device backup (for example iCloud Backup) if you have that turned on in iOS; SelfPeak has no access to that backup.

We do not sell, trade, or rent your personal information to third parties.

7. Third-Party Services

SelfPeak relies on the following processors, each with its own privacy policy:

SelfPeak for Garmin watches. The watch app reads your heart rate to show it during a workout and to record it in the activity it saves to your own Garmin Connect account. Heart rate is not sent to SelfPeak. When the watch is linked to the SelfPeak iPhone app, it sends the sets you log (repetitions and weight), your button presses and your post-workout rating (effort, how you felt, and where anything hurt) to the app over Bluetooth, and the app sends the watch your planned workout. The watch app does not use location or the internet. Garmin is not responsible for data you give the SelfPeak app.

8. International Data Transfers

Some of our processors β€” including Google (Gemini), Sentry, and RevenueCat β€” may process data on servers located in the United States or other countries outside the European Economic Area. Where data is transferred outside the EEA, it is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses. By enabling AI Personalisation you also consent to your fitness level and injuries being processed by Google in the US for the purpose of generating your plan.

9. Notifications

If you enable workout reminders, we use Expo Notifications to send push notifications to your device. You can disable notifications at any time through your device's system settings or in the App under Profile β†’ Reminders.

10. Children's Privacy

SelfPeak is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Your Rights

Under the GDPR you have the right to:

To exercise any of these rights, contact us at the email below.

12. Data Retention

We retain your account and synced data for as long as your account is active. When you delete your account, your server-side data (authentication record, synced state, AI usage record, and the usage analytics linked to your account) is deleted, and local data on your device is cleared. Usage events recorded before sign-in carry no account ID, so they cannot be matched to you or deleted with your account. Crash diagnostics are retained only for as long as needed to investigate and fix issues.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the date at the top of this page. Your continued use of SelfPeak after changes are posted constitutes your acceptance of the updated policy.

Contact Us

If you have any questions about this Privacy Policy or your data, please contact us at:
support@selfpeak.fit