Privacy Policy
This policy explains what the Peak app collects, why, who receives it, how long it is kept, and the choices you have. It covers the Peak iPhone app and these web pages.
Consumer Health Data Privacy Policy
Peak has a separate policy about consumer health data. It lists the health data Peak collects, where it comes from, whether it is shared, and how to use your rights.
The short version
- Your profile, workouts, meals and streak are saved on your phone. Peak does not sync them to our servers or to iCloud in this version. They are part of your device's iCloud Backup if you have it turned on.
- You can use Peak without an account. Signing in with Apple is needed only to subscribe and to scan meals.
- The meal scan uses AI. When you tap scan, and only after you agree, your meal photo goes through Peak's server on Google Firebase to Claude, an AI model made by Anthropic.
- Peak shows no ads, sells no data, and never uses health or fitness data for advertising or marketing.
- You can delete your account in Settings, and you can email us about any of your data.
1. Who is responsible
EdgeMind Apps, based in Cairo, Egypt, makes Peak and decides how your personal data is used. In privacy law, that makes us the controller. In this policy, "we" and "us" mean EdgeMind Apps.
To reach us about privacy, email peak@edgemind.dev.
2. What stays on your phone
Peak saves these in its own storage on your phone:
- Your profile: your name, your goal, and your gender (female or male), which sets the app's colors and photos.
- Your workouts: exercises, sets, reps, weights, dates, and any photo you add to a workout.
- Your meals: the result of each meal scan and a small thumbnail of its photo.
- Your streak and your settings in Peak.
- A note that you finished the welcome screens, and, once you sign in, the ID that Apple gives Peak for your Apple Account.
Peak's server keeps no copy of this data, and Peak does not sync it with iCloud in this version. Peak itself sends only what section 3 describes when you sign in, and what section 4 describes when you use the meal scan. iOS does include it in your device's iCloud Backup when you have iCloud Backup turned on, and Apple handles those backups under its own privacy policy.
This data stays on your phone until you delete the app. Older device backups may still hold a copy until they are replaced or you delete them.
3. Your account
You can use Peak without an account. You need one only to subscribe and to use the meal scan. Peak uses Sign in with Apple, through Google Firebase Authentication.
- The first time you sign in, Apple may share your name and your email address with Peak. If you choose Hide My Email, Apple shares a private relay address instead of your real one.
- Your name stays on your phone. Peak puts it in your profile if your profile has no name yet, and never sends it to Firebase or to our server.
- Firebase Authentication stores your account ID, the link to your Apple Account, and the email address Apple shares, which may be the relay address. Peak shows that email in Settings.
- Firebase Authentication also records your IP address and your device's user agent (a short description of the app and system making the request). It keeps the IP address for a few weeks, and the user agent until your account is deleted.
4. The AI meal scan
The meal scan reads a photo of your meal and suggests what to add so it satisfies you: protein, fiber and healthy fat. It uses AI: Claude, an AI model made by Anthropic, PBC.
Your permission comes first
- The scan is optional. Before your first scan, Peak asks for your permission, and names Anthropic and what is sent.
- Sending health details from your profile is a separate choice, with its own yes.
- You can turn AI features off at any time in Settings. While they are off, Peak sends no photo and no correction.
What is sent
- One smaller copy of your meal photo, saved as a JPEG on your phone. Its location and camera details are removed on your phone before it is sent.
- Peak's instructions for reading the meal.
- Details from your profile, such as your goal, only if you gave the separate yes for health details, and only when the scan needs them.
- If you fix a meal's estimate, the correction you type or dictate, with the meal's current estimate. The photo is not sent again.
- Your account ID goes to Peak's server with each request, so the server can check your sign in and your scan limit. The server may pass Anthropic a coded (hashed) form of that ID, which Anthropic may use to detect abuse. Your name, email address and phone number are never sent to Anthropic.
The photo travels from the app to Peak's server on Google Firebase Cloud Functions, and from there to Anthropic. The app never sends it straight to Anthropic. A correction takes the same path.
If a person appears in your photo: Anthropic's rules do not allow Claude to be used to identify people in images. Even so, keeping people out of meal photos is best.
What comes back
An estimate of the meal: a name for it, marks for protein, fiber and healthy fat, and a calorie range when you have turned calories on. It is saved on your phone with a small thumbnail of the photo.
AI results are estimates. They may be wrong, incomplete, misleading or out of date, so check them before you rely on them.
How Anthropic handles it
- Anthropic works as our service provider (a processor) under its Commercial Terms and Data Processing Addendum. It may not train its models on your photos or results, it does not sell or share them, and it does not combine them with other data except where the law allows.
- Anthropic keeps what Peak sends and what Claude returns for up to 30 days, then deletes it automatically.
- If Anthropic's automated safety systems flag a request under its Usage Policy, Anthropic may keep that request and its result for up to 2 years, and the safety scores for up to 7 years. Anthropic may also keep data longer where the law requires it.
- We cannot ask Anthropic to delete a scan early. Deleting your Peak account deletes our copies, and Anthropic's copies follow its automatic schedule.
- Anthropic stores this data in the United States. The scan itself may run on Anthropic's servers in the United States, Europe, Asia or Australia. Anthropic may also process it for safety review, support or incident response in other countries where Anthropic or its affiliates operate.
- Anthropic's own consumer privacy policy does not govern your scans. This policy and Anthropic's agreement with us do. You can read how Anthropic handles data sent to its API in the Anthropic Privacy Center.
5. Your subscription
- You need to be signed in to subscribe, so your subscription is tied to your Peak account.
- Apple takes payment through the App Store. Neither we nor RevenueCat ever see your card or payment details. Apple gives us receipts with no personal details, and reports that show a subscriber ID and your country or region.
- RevenueCat manages subscription status for us. It receives your Peak account ID, your purchase history and subscription status, your device type and system version, the identifier Apple gives Peak for your device (the IDFV), and your App Store country. RevenueCat stores this with Amazon Web Services in the United States and uses the subprocessors it lists.
6. Analytics, crash reports and notifications
- In this version, Peak collects no analytics and no crash reports. The Google Firebase tools for them, Google Analytics for Firebase and Crashlytics, are built into the app but switched off, so they send nothing.
- Peak sends no notifications in this version, and creates no notification token.
- If a later version turns any of these on, we will update this policy first, and ask for your consent where the law requires it.
7. Keeping Peak's server safe
- Firebase App Check confirms that requests to Peak's server come from the real Peak app on a real device. It uses Apple's App Attest, or Apple's DeviceCheck where App Attest is not available. App Check does not keep the attestation material. Its tokens last at most 7 days, and tokens used on protected requests are stored for at most 30 days.
- Google Cloud Functions records basic details of each request to our server, such as which function was called and your IP address, and keeps IP addresses only briefly.
8. What Peak's server keeps
For each account, Google Cloud Firestore holds a small record with only:
- your account ID
- dates and usage counters, such as how many scans you have used, so limits and spending caps work
- the time you gave your AI consent
- the app language, so any future messages from Peak can use your language
It holds no photos, meal results, workouts, profile answers, name or email address. Our server logs, kept by Google Cloud Logging for 30 days, never contain your photo, a meal result or your email address.
9. Who receives your data
We share data only with these companies, each only for its task. Anthropic, RevenueCat and Google's Firebase and Google Cloud services work as our processors, under contracts that protect your data at least as well as this policy. Gmail, Apple and Cloudflare handle their part under their own terms and privacy policies.
- Google (Firebase, Google Cloud and Gmail)
- Sign in (Firebase Authentication), Peak's server (Cloud Functions, Cloud Firestore and Cloud Logging) and app security (App Check). For Firebase services, Google is our processor under the Firebase Data Processing and Security Terms. See Privacy and Security in Firebase. Our mailbox is on Gmail, so Google also stores the emails you send us and our replies.
- Anthropic
- The AI meal scan, as our processor. See section 4.
- RevenueCat
- Subscriptions, as our processor. See RevenueCat's privacy policy.
- Apple
- Sign in with Apple, App Store payments, App Attest and DeviceCheck, and your own iCloud Backup. If you chose Hide My Email, Apple's Private Email Relay forwards the emails we send to your relay address on to your own inbox. Apple's privacy policy covers what Apple collects.
- Cloudflare
- Hosts these web pages, and forwards emails sent to peak@edgemind.dev to our mailbox without storing their content. Cloudflare receives no data from the app.
Cloudflare forwards the emails you send us to our Gmail mailbox, provided by Google, where they are kept.
We may also disclose data when the law requires it, such as under a valid court order, or to protect the safety of people or of Peak. If Peak moves to a company we set up or to a new owner, your data moves with it under this policy, and we will tell you before that happens.
10. Why we use your data
Where laws such as the GDPR ask for a legal reason, these are ours:
- Your account and your subscription
- To provide the service you ask for (contract).
- The AI meal scan
- Your explicit consent. Sending health details needs a separate explicit consent. You can withdraw either at any time in Settings, as easily as you gave it. Withdrawing does not affect scans already made.
- Usage counters, scan limits and spending caps
- To provide the service (contract), and our legitimate interest in preventing abuse and keeping costs under control.
- App Check, server request logs and security
- Our legitimate interest in protecting Peak, its users and its server from abuse and fraud.
- The app language on our server
- Our legitimate interest in writing to you in your language.
- Answering your emails and requests
- Our legal obligations, and our legitimate interest in handling requests properly and keeping a record of them.
What you must give: the meal scan needs a photo and an account, and a subscription needs an account. Everything else in Peak works without an account and without the scan.
Automated decisions: the AI makes estimates only. It makes no decision about you with legal or similarly significant effects.
11. No selling, no ads, no tracking
- Peak shows no ads and has no Google Ads account linked to it.
- We do not sell your personal data, and we do not share it for targeted advertising.
- We never use or disclose health or fitness data for advertising, marketing or data mining.
- Peak does not track you as Apple defines tracking. We do not link your data with other companies' data for ads, and we do not share it with data brokers. Peak never asks for App Tracking Transparency permission.
- Peak does not collect data about your activity over time and across other companies' apps or websites, and does not let other companies do so through Peak. For that reason, Peak and these pages do not change anything in response to a browser's Do Not Track signal.
- We do not use your personal data to train AI models, including large language models, and Anthropic may not train its models on it.
12. How long we keep data
- On your phone
- Until you delete the app, and in your device backups until those are replaced or deleted.
- Your Firebase account
- Until you delete your account. Google then removes it from its backups within 180 days. IP addresses recorded at sign in: a few weeks.
- Your Firestore record
- Until you delete your account.
- Meal scans at Anthropic
- Up to 30 days. Flagged requests: up to 2 years, and their safety scores up to 7 years. Longer where the law requires it.
- Server logs
- 30 days in Google Cloud Logging.
- App Check tokens
- At most 7 days, or 30 days for tokens used on protected requests.
- RevenueCat
- Until you delete your account, when our server asks RevenueCat to delete your customer record. Apple keeps its own purchase records under its privacy policy.
- Emails you send us
- As long as we need them to answer you and to keep a record of your request and our answer.
We may keep data longer when the law requires it.
13. Deleting your account
If you are signed in, you can delete your account in Peak, in Settings. Peak asks you to sign in with Apple again to confirm, and then:
- deletes your record on Peak's server
- asks RevenueCat to delete your customer record
- revokes Peak's access to your Sign in with Apple
- deletes your Firebase account, including your email address
Data kept only on your phone, such as your workouts, streak and profile, stays there so you can keep using Peak without an account. Delete the app to remove it.
Deleting your account does not cancel a subscription. Apple manages billing, so cancel it in your Apple Account's subscription settings.
Anthropic's copies of past scans follow its automatic schedule in section 4.
You can also ask us to delete your data by email, without signing in. We may ask you to confirm the request comes from you. If you never created an account, our server holds no account data about you.
14. Your rights and choices
Wherever you live, you can:
- see and change your profile in Peak at any time
- turn AI features off in Settings, which withdraws your consent for future scans
- delete your account in Settings
- email peak@edgemind.dev to ask what data we hold about you, get a copy, correct it, delete it, or ask any question
Requests are free. We may ask you to confirm your identity, for example by replying from the email address linked to your account. You never need to create an account to make a request. If someone asks for you as your authorized agent, we may ask for proof of that permission.
United States
Depending on your state, such as California, Connecticut, Nevada or Washington, you may have the right to know about, access, correct, delete and get a copy of your personal data, to opt out of its sale, of targeted advertising and of profiling, and to limit the use of sensitive data. Peak does not sell data, does no targeted advertising, does no profiling with legal or similarly significant effects, and uses sensitive data only to provide the features you ask for. We will not treat you differently for using your rights. If we decline a request, you can appeal by replying to our answer, and we will respond in writing.
For consumer health data, including the answer times and appeal process Washington law sets, see the Consumer Health Data Privacy Policy.
Nevada: we do not sell covered information as Nevada law defines it. For consumer health data, see the Consumer Health Data Privacy Policy. This policy's effective date is at the top of the page, section 21 explains how we tell you about material changes, and section 11 explains that no other company collects data about your activity across other apps or websites through Peak.
European Union, European Economic Area, United Kingdom and Switzerland
You have the right to access, correct and erase your personal data, to restrict or object to its use, to receive it in a portable format, and to withdraw consent at any time, as easily as you gave it and without affecting what was done before. We answer within one month. The law lets us extend that by 2 more months for complex requests, and we will tell you if we need to.
You can complain to the data protection authority where you live or work. See the list of EU and EEA authorities. In the United Kingdom, that is the Information Commissioner's Office. In the United Kingdom you can also complain to us first by email. We acknowledge your complaint within 30 days and tell you the outcome without undue delay.
Egypt
Under Egypt's Personal Data Protection Law, you have the right to know about and access your personal data, withdraw your consent, correct or erase your data, restrict its processing, be told of any breach that affects it, and object to its processing. You can also complain to the Personal Data Protection Center.
15. International transfers
We are based in Cairo, Egypt. The services Peak uses store and process data mainly in the United States, and some process it in other countries too. When data from the EU, the UK or Switzerland goes to them, it is protected by:
- Google (Firebase): the Data Privacy Framework between the EU and the United States, its UK Extension, and the Swiss and United States framework, with Standard Contractual Clauses as the fallback.
- Anthropic: the EU Standard Contractual Clauses of 2021, with the UK Addendum and a Swiss addendum, under Anthropic's Data Processing Addendum.
- RevenueCat: the EU Standard Contractual Clauses, with the UK Addendum and a Swiss version, under RevenueCat's Data Processing Addendum.
Firebase Authentication processes data only in the United States. Cloud Functions, Firestore and Cloud Logging run in the Google Cloud location we chose for Peak, and other Firebase services run on Google's global infrastructure. Where Anthropic processes scans is explained in section 4.
16. Children
Peak is meant for adults aged 18 and over, and it is not directed to children. We do not knowingly collect personal data from children: anyone under 18 in Egypt, under 16 in the EU unless their country sets a lower age, and under 13 in the United States and the UK. If we learn that a child has given us personal data, we will delete it. If you think a child has, please email us.
17. Security
- Data travels between the app, Peak's server and our service providers over encrypted connections.
- Firebase App Check blocks requests that do not come from the real Peak app.
- Peak's AI key and scan instructions live only on our server, never in the app.
- Only Peak's server functions can read or write your record on our server. The app cannot.
- Photos lose their location and camera details on your phone before they leave it.
- Data on your phone is protected by iOS.
No system is perfectly secure, so we cannot promise absolute security.
18. If there is a data breach
If a breach affects your personal data, we will:
- report it to the authorities the law requires, within 72 hours where the law sets that limit, including Egypt's Personal Data Protection Center and the authorities in the EU and the UK
- tell you without undue delay: within 3 working days of our report to the authorities, and never later than 60 days after we discover the breach
- write to you at the email address linked to your account and, where we can, show a notice in the app
The notice will say what happened and when, what data was involved, what we are doing about it, what you can do to protect yourself, and how to reach us.
19. Wellness, not medical advice
Peak gives general wellness and nutrition information. It is not medical advice, diagnosis or treatment, and it does not replace a doctor or dietitian. Its meal estimates may be wrong. If you have a health condition, a food allergy or questions about your diet, talk to a doctor.
20. These web pages
These pages are hosted on Cloudflare Pages. When you open them, Cloudflare processes your IP address and basic request details to deliver the page and protect the site, under Cloudflare's privacy policy. The pages contain no scripts, load nothing from other sites and set no cookies of our own, and we have not turned on website analytics.
21. Changes to this policy
When we update this policy, we change the effective date at the top. If a change is material, such as a new kind of data or a new use of it, we will tell you in the app or by email before it takes effect, and ask for your consent again where the law requires it. Earlier versions are available on request.
22. Contact us
EdgeMind Apps, Cairo, Egypt
Email: peak@edgemind.dev
Cloudflare forwards messages sent to this address to our mailbox, so our replies may come from a different address.