At Peak Social, transparency is paramount. We understand that your fitness and health data is deeply personal. This Privacy Policy exhaustively details exactly what information we collect, how we process it, where it is stored, and who it is shared with. By using Peak Social, you explicitly consent to the data practices described in this document.
1. Comprehensive Data Collection
We collect extensive data to provide our social and tracking services. This includes:
- Identity & Contact Data: Your registered email address, phone number (used for SMS OTP verification), chosen username, encrypted password hashes, and date of birth.
- Biometric & Health Data: Your height, weight, sex, age, and activity level. This data is actively processed to compute your Body Mass Index (BMI) and Basal Metabolic Rate (BMR).
- Nutritional Data: Detailed logs of what you eat, meal times, serving sizes, and the exact breakdowns of carbohydrates, proteins, fats, and total calories consumed. These macros are cross-referenced with public databases like the USDA FoodData Central.
- Workout Data: Information on every exercise you log, including specific movements, set counts, repetition counts, rest timers, weight lifted, and workout duration.
- Geolocation Data: When utilizing the "Outdoor Tracker" feature, we access your device's GPS hardware to record your longitude, latitude, speed, and elevation over time. This data is used solely to map your running or cycling routes. We do not track your location in the background when the tracker is disabled.
- Social & Media Data: All photos and images uploaded as avatars or post attachments. All text published in posts, comments, and direct messages (DMs).
- Device & Telemetry Data: Your device model, Operating System (iOS/Android) version, IP address, timezone, local storage data (via AsyncStorage), and crash analytics.
2. Processing and Usage of Data
Your data is processed directly to facilitate app functionality:
- Algorithms & Calculators: We apply mathematical formulas (e.g., Mifflin-St Jeor) to your biometric data to generate fitness insights and macro targets.
- Social Graphing: Your followings, followers, and engagement metrics are used to construct your personalized feed.
- Communication: We utilize your contact data to send critical transactional emails (like password resets) via our partner Resend, and Push Notifications via Expo Push Services.
3. Data Storage and Third-Party Subprocessors
We do not sell your personal data to data brokers or advertising networks. However, to operate the App globally, we share data with secure third-party infrastructure providers:
- Supabase: Acts as our primary backend database and authentication provider. Your user profiles, posts, messages, and fitness data are securely stored in PostgreSQL databases hosted by Supabase. Images are stored in Supabase Storage buckets.
- Expo: Handles over-the-air updates and device push notifications.
- Resend: Our SMTP provider used for securely delivering OTPs and system emails.
- Nutrition APIs: When you search for foods, your search queries may be routed through third-party food databases (e.g., USDA APIs) to retrieve macro information.
4. Visibility and Privacy Settings
- Public by Default: Unless otherwise configured, your profile, workout logs, posts, and followers are visible to the entire Peak Social community.
- Private Accounts: You may toggle your account to "Private" in the settings. This restricts access to your posts and detailed fitness logs strictly to users whom you have manually approved as followers. Your basic profile (username, bio, avatar) remains searchable.
- Direct Messages: DMs are private between the sender and recipient, though they are stored on our servers to synchronize across your devices. They are not end-to-end encrypted.
5. Data Retention, Export, and Deletion
- Retention: We store your data indefinitely as long as your account remains active, ensuring your fitness history is always accessible.
- Export: You may request a raw data export of your information by contacting our support team.
- Deletion (Right to be Forgotten): You have the absolute right to delete your account. Using the "Delete Account" button in settings triggers a cascading deletion process in our PostgreSQL database. This permanently erases your identity, biometric data, workouts, posts, and social connections from active production servers. Residual data may exist in secure, encrypted backups for up to 30 days before being fully overwritten.
6. Security Measures
Peak Social employs Row Level Security (RLS) policies within our database to ensure users can only modify their own data. All API communications are secured via Transport Layer Security (TLS/HTTPS). Passwords and OTP tokens are cryptographically hashed before storage. Despite these measures, internet transmissions are never entirely secure, and you use the App at your own risk.
7. California Privacy Rights (CCPA) and GDPR
If you are a resident of California or the European Union, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR). This includes the right to access, rectify, or erase your data, and the right to object to processing. You may exercise these rights directly within the App's settings or by emailing our privacy officers.
8. Changes to this Policy
We may modify this Privacy Policy periodically. If we make material changes, we will notify you via email or a prominent notice within the App prior to the changes taking effect. Continued use of the App constitutes acceptance of the revised policy.
For any privacy-related concerns, please contact us at peaksocialsupport@gmail.com.
← Back to Support