This Privacy Policy explains how the SelfPeak mobile application ("SelfPeak", "the App", "we",
"our", or "us") collects, uses, stores, and protects your personal data, and the rights you
have under the EU General Data Protection Regulation (GDPR) and the Croatian Act on the
Implementation of the GDPR.
1. Data Controller
The data controller responsible for your personal data is:
2. Information We Collect
We collect the following categories of personal data:
- Account information β email address and password (stored only as a salted hash) when you create an account.
- Profile data β display name and profile photo you optionally provide.
- Fitness data β workout sessions, duration, exercise types, calorie estimates, goals, and training preferences you log in the App.
- Body metrics β optional height, weight, and related body measurements you enter to personalise your experience.
- Health data (special category) β your self-reported fitness level and any injuries or physical limitations you choose to enter so the AI can adapt your plan. This is special-category data under GDPR Article 9 and is processed only with your explicit consent (see Section 4).
- Apple Health data (optional, iPhone only) β only if you turn on Apple Health in the App: your weight, heart rate, resting heart rate and sleep are read from Apple Health and shown to you on your device. This data is not sent to our servers (see Section 4).
- Progress photos (optional) β photos you add to your progress journal, with the date, an optional weight from Body Metrics and an optional note. They are stored only on your device and never uploaded (see Section 6).
- AI usage data β a count of AI workout/coaching generations, stored on our servers to protect the service from abuse.
- Usage analytics β which screens and features you use in the App (for example, finishing an onboarding step or completing a workout), with a timestamp. See Section 5.
- Purchase data β the current version of SelfPeak has no in-app purchases, so we collect none. If paid subscriptions are added later, subscription status will be handled by RevenueCat. We never see or store your payment card details.
- Diagnostic data β crash reports and technical diagnostics (device type, OS version, and IP address as processed by our crash-reporting provider). We have disabled screen recording / session replay so your app screens are never captured.
3. How We Use Your Information & Legal Bases
We process your data on the following GDPR Article 6 legal bases:
- Performance of a contract β to create and authenticate your account, sync your data across devices, display your statistics, and provide the core service.
- Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) β to send your fitness level and injuries to Google Gemini for AI personalisation, and to send workout-reminder notifications. You can withdraw either consent at any time.
- Legitimate interests (Art. 6(1)(f)) β to keep the App secure, prevent abuse of the AI features, diagnose crashes, and understand how the App is used so we can improve it (usage analytics, Section 5). We balance these against your rights.
- Legal obligation β to comply with applicable law where required.
4. AI Personalisation & Health Data
SelfPeak generates workouts and coaching using the Google Gemini API. When you enable AI
Personalisation, the data needed for a plan β which may include your fitness level and any
injuries you entered β is sent to Google for processing. Because injuries are health data,
we ask for your explicit consent before any AI request is made, and no AI
call happens without it. You can withdraw consent at any time in the App under
Profile β AI Personalization; withdrawing disables AI features while the rest of the
App keeps working.
Apple Health (optional, iPhone only)
SelfPeak can connect to Apple Health. It is off until you turn it on in
Profile β Apple Health, and iOS then asks you which data types to allow.
- What SelfPeak writes to Apple Health: your finished workouts (type, start and end time, estimated active calories) and the weight you log in Body Metrics.
- What SelfPeak reads from Apple Health, and why: your latest weight, to add it to Body Metrics; your heart rate during a workout, to show your average and maximum heart rate in the workout summary and history; and your resting heart rate and last night's sleep, to show them on the Recovery card in Statistics. SelfPeak reads nothing it does not show you.
- Where it stays: data read from Apple Health stays on your iPhone. It is not sent to our servers or synced to your account, and it is never sent to Google Gemini. Heart rate, resting heart rate and sleep are read when you view them and are not stored by SelfPeak; a weight added from Apple Health is kept only in Body Metrics on your device.
- Never for advertising: Apple Health data is never used for advertising, marketing or analytics, never sold, and never shared with third parties.
- How to turn it off: switch off Apple Health in Profile β Apple Health and SelfPeak stops reading and writing immediately. To remove the permission itself, go to Settings β Health β Data Access & Devices β SelfPeak. Workouts and weights already saved to Apple Health stay there until you delete them in the Health app.
5. In-App Usage Analytics
The App records a small set of usage events so we can see which parts of SelfPeak work and
which do not, and fix them.
- What we record β the type of event (for example "onboarding step viewed",
"workout started", "workout completed", "workout rated", "share card shared"), the time it
happened, and a few details about it, such as the workout category and duration, the
effort rating you picked, or which onboarding question was shown. The onboarding summary
records your main goal and a few counts (for example, how many training days you picked).
It does not record your fitness level or anything about injuries, and never the text you
typed.
- What we do not record β no advertising identifier, no device identifier,
no location, and no free text you entered.
- Why β to improve the App. Nothing in the App reads these events back, and
they are not used for advertising.
- Legal basis β our legitimate interest in improving the App
(GDPR Art. 6(1)(f)). You can object at any time by contacting us.
- Link to your account β events are stored with your account ID. Events from
before you sign in (the first-run onboarding) are stored without any account ID and are not
linked to you.
- Where β in our own Supabase database in the EU (Frankfurt). They are not
shared with any third party.
- How long β for as long as your account exists. When you delete your account,
the events linked to it are deleted with it.
6. Data Storage and Security
Your account and synced data (workout history, plans, and profile) are stored on Supabase
servers located in the European Union (Frankfurt, Germany). A copy is also kept locally on
your device for offline use. Authentication tokens are stored
in the device's hardware-backed secure storage (iOS Keychain / Android Keystore). All traffic
is encrypted in transit over HTTPS.
Progress photos stay on your device. Photos you add to your progress journal
are saved only inside SelfPeak on your phone. They are not uploaded to our servers, not synced
to your account, not sent to Apple Health or to Google Gemini, and never used for analytics or
advertising. Only the capture date is read from a photo you choose from your library; other photo
metadata, including location, is not kept. You can delete a photo at any time in the journal,
and all progress photos are deleted from the device when you sign out or delete your account.
Like other app data, they may be included in your own device backup (for example iCloud Backup)
if you have that turned on in iOS; SelfPeak has no access to that backup.
We do not sell, trade, or rent your personal information to third parties.
7. Third-Party Services
SelfPeak relies on the following processors, each with its own privacy policy:
- Supabase β authentication, database, and data sync (supabase.com/privacy).
- Google Gemini API β AI workout and coaching generation (policies.google.com/privacy).
- RevenueCat β in-app subscription management, used only if paid subscriptions are added; not active in the current version (revenuecat.com/privacy).
- Sentry β crash reporting and diagnostics; processes device/OS information and IP address for error triage (sentry.io/privacy).
- Expo / EAS β app build, delivery, and push-notification infrastructure (expo.dev/privacy).
SelfPeak for Garmin watches. The watch app reads your heart rate to show it during a workout and to record it in the activity it saves to your own Garmin Connect account. Heart rate is not sent to SelfPeak. When the watch is linked to the SelfPeak iPhone app, it sends the sets you log (repetitions and weight), your button presses and your post-workout rating (effort, how you felt, and where anything hurt) to the app over Bluetooth, and the app sends the watch your planned workout. The watch app does not use location or the internet. Garmin is not responsible for data you give the SelfPeak app.
8. International Data Transfers
Some of our processors β including Google (Gemini), Sentry, and RevenueCat β may process data
on servers located in the United States or other countries outside the European Economic Area.
Where data is transferred outside the EEA, it is protected by appropriate safeguards such as
the European Commission's Standard Contractual Clauses. By enabling AI Personalisation you
also consent to your fitness level and injuries being processed by Google in the US for the
purpose of generating your plan.
9. Notifications
If you enable workout reminders, we use Expo Notifications to send push notifications to your
device. You can disable notifications at any time through your device's system settings or in
the App under Profile β Reminders.
10. Children's Privacy
SelfPeak is not directed to children under the age of 16. We do not knowingly collect personal
data from children under 16. If you believe a child has provided us with personal data, please
contact us and we will delete it.
11. Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure ("right to be forgotten") β you can delete your account and all associated data directly in Profile β Delete Account.
- Restrict or object to certain processing.
- Data portability β request a copy of your data in a machine-readable format.
- Withdraw consent (for AI Personalisation or notifications) at any time, without affecting prior lawful processing.
- Lodge a complaint with your supervisory authority β in Croatia, the Personal Data Protection Agency (AZOP, azop.hr).
To exercise any of these rights, contact us at the email below.
12. Data Retention
We retain your account and synced data for as long as your account is active. When you delete
your account, your server-side data (authentication record, synced state, AI usage record, and
the usage analytics linked to your account) is deleted, and local data on your device is cleared.
Usage events recorded before sign-in carry no account ID, so they cannot be matched to you or
deleted with your account. Crash diagnostics are retained only for
as long as needed to investigate and fix issues.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes
by updating the date at the top of this page. Your continued use of SelfPeak after changes are
posted constitutes your acceptance of the updated policy.