Full English policy
# PeakPact Elite — Privacy Policy **Effective date:** 15 September 2026 **Controller:** PeakPact (“Company”, “we”, “us”) **Contact:** privacy@peakpactelite.app · support@peakpactelite.app **Governing establishment:** Romania (EU), with worldwide service delivery This Privacy Policy explains how PeakPact Elite collects, uses, stores, shares, and deletes personal data when you use the PeakPact Elite mobile application, web dashboard (`peakpactelite.app`), and related APIs (`api.peakpactelite.app`). ## 1. Scope This policy covers: - Account and authentication data - Trial, quest, verification, ladder, and squad activity data - Automation and AI coaching messages - Device, usage, and diagnostics data - Payment entitlement signals (via RevenueCat / App Store / Google Play; we do not store full card numbers) ## 2. Categories of personal data | Category | Examples | Source | |---|---|---| | Identity | Email, display name / codename, user ID | You; Clerk | | Auth metadata | Session tokens, MFA status, device sessions | Clerk | | Product activity | Check-ins, streaks, strikes, PP, quest status, ladder rank | You; our Worker API | | Verification media | Proof images/files and verification status | You; Cloudflare R2 | | Automation preferences | Reminder intensity, locale, notification toggles | You | | AI interaction content | Prompt context (streak, intensity, locale) and generated coach text | Our systems; OpenAI | | Technical | IP, user agent, approximate region, device identifiers used for API context | Device; Cloudflare Workers | | Diagnostics & analytics | Crash stacks, non-fatal diagnostics, limited app-activity analytics events | Device; Firebase Crashlytics; Firebase Analytics (Google) | | Commercial | Entitlement / trial / subscription status | RevenueCat / Google Play / App Store | We do **not** intentionally collect special-category data (health diagnoses, biometrics for identification, precise continuous location tracking) as a product requirement. Camera/photo access is used only for proof submission you initiate. ## 3. Purposes and legal bases (GDPR Art. 6) | Purpose | Legal basis | |---|---| | Provide Elite Trial, squads, ladders, verification | Contract (Art. 6(1)(b)) | | Authenticate and secure accounts | Contract; legitimate interests (security) | | Send in-product automation / coach messages you enable | Consent and/or contract (depending on region) | | Improve reliability, prevent abuse, debug | Legitimate interests (Art. 6(1)(f)) | | Comply with law, respond to lawful requests | Legal obligation (Art. 6(1)(c)) | | Analytics cookies / non-essential cookies on web | Consent (where required) | ## 4. Processors and subprocessors (data flow) Primary processing stack: 1. **Clerk** — identity, authentication, session JWTs (`aud` = `peakpactelite`) 2. **Cloudflare Workers** — API and automation orchestration at `api.peakpactelite.app` 3. **Neon (Postgres)** — durable product state (profiles, trials, squads, ladders, quests, verification metadata) 4. **Cloudflare R2** — verification media object storage 5. **OpenAI** — composition of automation/coach messages (Elite Mode: gpt-4o; locale-aware; no medical advice; safety filters). Missing key or provider failure returns an error — we do not silently substitute fabricated coach success responses. 6. **Firebase Crashlytics** — crash and stability diagnostics (Google) 7. **Firebase Analytics** — limited product analytics events (Google); PeakPact Elite does **not** serve ads and does not use the advertising ID for advertising 8. **Expo / mobile OS vendors** — push and device capabilities 9. **RevenueCat / Apple / Google Play** — purchase entitlement signals Public overview of this flow: https://peakpactelite.app/legal/data-flow/ ## 5. International transfers Data may be processed in the EU/EEA, United States, and other regions where our processors operate. Where required, we rely on appropriate safeguards (e.g., Standard Contractual Clauses, processor DPAs, and transfer assessments). ## 6. Retention See https://peakpactelite.app/legal/retention/ . In summary: - Account data: for the life of the account + limited post-closure retention for security/legal claims - Verification media: retained while needed for dispute/audit windows, then deleted or anonymized - AI compose logs: minimized; prompts exclude unnecessary personal identifiers - Backups: rolled per infrastructure retention schedules ## 7. Your rights Depending on your region, you may have rights to access, correct, delete, restrict, port, object, withdraw consent, and lodge a complaint with a supervisory authority (EU/EEA/UK) or exercise CCPA/CPRA rights (California). Contact `privacy@peakpactelite.app`. We will verify requests reasonably and respond within applicable timelines. ## 8. Children (COPPA / age gates) PeakPact Elite is directed to adults. Google Play target audience is **18 and over**. We do not knowingly collect personal information from children under 13 (or under 16 in regions that require a higher digital consent age). See https://peakpactelite.app/legal/coppa/ . ## 9. AI processing notice AI features may generate motivational/coaching text. Outputs are assistive, not professional advice. See https://peakpactelite.app/legal/ai-disclosure/ and https://peakpactelite.app/legal/responsible-ai/ . ## 10. Security See https://peakpactelite.app/legal/security/ . No method of transmission or storage is perfectly secure; we apply industry-standard controls appropriate to our risk profile. ## 11. Changes We will update the effective date when this policy changes and, where required, provide additional notice. ## 12. Contact - Privacy / data rights: privacy@peakpactelite.app - General support: support@peakpactelite.app - Legal Center: https://peakpactelite.app/legal/privacy/ - Account deletion: https://peakpactelite.app/legal/account-deletion/