1. Who is responsible for your data
I am the data controller, which means I am the person responsible for your personal data:
Marko BaturZagreb, Croatia
support@selfpeak.fit
2. What I collect
Your account
If you sign up with email, I get your email address and your password. The password is stored only as a salted hash, by the authentication provider. If you use Sign in with Apple, Apple shares your email address (or a private relay address) and, the first time, your name, which becomes your display name if you have not set one. If you use Sign in with Google, Google shares your email address, name and profile picture link with the authentication provider.
The display name you choose is synced with your account. A profile photo you pick stays on your phone. Only a reference to the file on your phone is synced, never the photo itself.
Your training
Your workouts (exercises, sets, repetitions, weights, duration and calorie estimates), saved plans, goals and training preferences, such as training days, session length, focus areas, where you train and the equipment you have.
After a workout you can rate how hard it was, how you felt, your energy and sleep, and how each exercise felt. These ratings are stored with the workout.
Your age, if you give it
Entering your age is optional. The age you enter during onboarding or in your profile (16 to 90) is stored on your device and synced with your training preferences. You can also choose "prefer not to say".
From your age SelfPeak works out an age group: under 30, 30 to 49, 50 to 64, or 65+. From 50 the age group makes your plans gentler, with no jumps, a longer warm-up and longer rests. Only the age group is used anywhere else (sections 4 and 5). Your exact age is never sent to Google Gemini or recorded in usage analytics. If you choose "prefer not to say", the number is removed from your phone. To have it removed from your synced account as well, delete your account or write to me.
Health data
This covers your fitness level, the injuries or exercises you want to avoid that you enter, and any pain you report after a workout (the body regions: neck, shoulder, wrist, lower back, groin, hamstring, knee or ankle). Injuries and pain are health data, a special category of personal data under GDPR Article 9.
Entering them is optional, and SelfPeak works without them. The first time you enter an injury or report pain, the app asks for your explicit consent to keep and use them (section 3). If you agree, they are synced with your account, and they are sent to Google Gemini only if you also turn on AI personalisation (section 4). Without that consent they stay only on your phone: they are not synced to the SelfPeak servers and not sent to Google Gemini.
You can change or remove injuries in Profile → Your training plan → Injuries, and pain you reported is removed when you delete that workout.
Only on your devices
Body metrics, meaning the height, weight and body measurements you choose to enter, stay on your device and are not synced to the SelfPeak servers.
Progress photos you add to your progress journal, with their date, an optional weight from Body Metrics and an optional note, are stored only on your device and never uploaded (section 6).
Apple Health data is read only if you turn on Apple Health in the app, and on Apple Watch while you train with the SelfPeak watch app. Section 4 explains what is read and where it stays.
Technical data
To protect the AI features from abuse, the SelfPeak servers keep a count of AI workout and coaching generations per account, and a one-way hash of your sign-in identity (section 13).
The app records which screens and features you use (for example, finishing an onboarding step or completing a workout), with a timestamp. Section 5 has the details.
The app also sends crash reports and technical diagnostics: device type, OS version, app version, a random installation identifier that is not linked to your account, and a short log of what the app was doing before the problem. Your email, username and IP address are not attached to crash reports. Screen recording (session replay) is turned off, so your app screens are never captured.
The current version of SelfPeak has no in-app purchases, so I collect no purchase data. If paid subscriptions are added later, subscription status will be handled by RevenueCat. I never see or store your payment card details.
The website
If you join the waitlist on selfpeak.fit, I store what is listed in section 9.
3. Why I use it, and the legal basis
To run the service
I use your data to create your account and sign you in, sync your data across devices, build and adapt your workouts, show your statistics, and provide the core service. The legal basis is performance of a contract (Art. 6(1)(b)).
Injuries and pain, with your explicit consent
With your explicit consent (Art. 9(2)(a)), I store and sync the injuries and pain you enter, and use them to plan around them: to leave out exercises that load that area and to keep load off a joint you reported. The app asks for this consent the first time you enter an injury or report pain, and keeps a record of your answer, and when you gave it, on your phone. With it, injuries and pain are stored with the rest of your training data on servers in the EU (section 6).
Without it, they stay only on your phone. There, injuries still narrow which exercises the app picks for you, but recent pain no longer shapes your AI plans, and neither is synced to the SelfPeak servers or sent to Google Gemini.
You can withdraw it at any time in Profile → Account → Health data. When you withdraw it, or answer no, the app deletes the copies on the SelfPeak servers: your injuries are cleared from your account, and your workouts with pain are replaced by versions without it. Your phone keeps its own copy. A phone that has not shown you the question yet (for example a new phone signed in to an account you agreed on with another phone) deletes nothing from the SelfPeak servers; deletion starts only after an explicit no or a withdrawal.
This consent is separate from the AI personalisation consent below. Injuries and pain reach Google Gemini only if you have given both.
AI personalisation, with your explicit consent
With your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)), I send the data listed in section 4, including health data, to Google Gemini for AI personalisation. You can withdraw it at any time.
The waitlist, with your consent
With your consent (Art. 6(1)(a)), I add you to the waitlist and send you launch emails (section 9).
Legitimate interests
On the basis of legitimate interests (Art. 6(1)(f)), I use data to keep the app secure, prevent abuse of the AI features and the waitlist, diagnose crashes, and understand how the app is used so I can improve it (usage analytics, section 5).
Legal obligations
Where the law requires it, I process data to comply with applicable law.
4. AI personalisation, health data and Apple Health
SelfPeak generates workouts and coaching with the Google Gemini API. Nothing is sent to Google until you agree in the app, and no AI request is made without that consent. When AI personalisation is on, a request can include:
- the workout you ask for: type, length, intensity, focus areas, goal, warm-up and cool-down length;
- where you train (gym, home, outdoor, park or hotel), the equipment you have, and names of equipment or exercises you typed yourself;
- your fitness level, the injuries and exercises to avoid that you entered, and pain you reported after recent workouts (injuries and pain only if you have also given the health data consent, section 3);
- your age group, only if it is 50 to 64 or 65+ (never your exact age);
- your recent workouts (up to the last 8): date, type, duration, exercises, the weights and repetitions you logged, your best weights, and your ratings (effort, how you felt, energy, sleep, and how each exercise felt).
It never includes your name, email address, body metrics, Apple Health data or photos. Google processes this data in the United States (section 8). You can withdraw consent at any time in Profile → Account → AI personalization. That turns off the AI features, and the rest of the app keeps working.
Apple Health on iPhone (optional)
SelfPeak can connect to Apple Health. It is off until you turn it on in Profile → Reminders and devices → Apple Health, and iOS then asks you which data types to allow.
SelfPeak writes your finished workouts (type, start and end time, estimated active calories) and the weight you log in Body Metrics to Apple Health.
It reads your latest weight, to add it to Body Metrics; your heart rate during a workout, to show your average and maximum heart rate in the workout summary and history; and your resting heart rate and last night's sleep, to show them on the Recovery card in Statistics. SelfPeak reads nothing it does not show you.
Data read from Apple Health stays on your iPhone. It is not sent to the SelfPeak servers or synced to your account, and it is never sent to Google Gemini. Heart rate, resting heart rate and sleep are read when you view them and are not stored by SelfPeak. A weight added from Apple Health is kept only in Body Metrics on your device.
Apple Health data is never used for advertising, marketing or analytics, never sold, and never shared with third parties.
To turn it off, switch off Apple Health in Profile → Reminders and devices → Apple Health and SelfPeak stops reading and writing immediately. To remove the permission itself, go to Settings → Health → Data Access & Devices → SelfPeak. Workouts and weights already saved to Apple Health stay there until you delete them in the Health app.
SelfPeak for Apple Watch
When you start a workout on the SelfPeak watch app, watchOS asks for Apple Health access so the watch can show your heart rate while you train. This is separate from the iPhone setting above. Heart rate stays on the watch: it is not sent to the iPhone app, to the SelfPeak servers or to Google Gemini. The workout session the watch runs is not saved to Apple Health.
The watch sends the iPhone app only what you tap: sets you log (repetitions, weight or time), skipping rest, moving to the next exercise and finishing. The iPhone app sends the watch your current workout.
SelfPeak for Garmin watches
The Garmin watch app reads your heart rate to show it during a workout and to record it in the activity it saves to your own Garmin Connect account, if you choose to save it. Heart rate is not sent to SelfPeak.
When the watch is linked to the SelfPeak iPhone app, it sends the app the sets you log (repetitions and weight, or time), your button presses and, for workouts started from the phone, your post-workout rating (effort, how you felt, and where anything hurt). This goes over Bluetooth through Garmin Connect Mobile. The app sends the watch your planned workout, its live progress and your saved plans. The watch app does not use location or the internet. Garmin is not responsible for data you give the SelfPeak app.
5. Usage analytics in the app
The app records a small set of usage events so I can see which parts of SelfPeak work and which do not, and fix them.
Each event has a type (for example "onboarding step viewed", "workout started", "workout completed", "workout rated", "share card shared"), the time it happened, and a few details about it, such as the workout category and duration, the effort and feeling ratings you picked, or which onboarding question was shown. The onboarding summary records your main goal, your age group (never your exact age) and a few counts (for example, how many training days you picked). It does not record your fitness level, anything about injuries or pain, or the text you typed.
There is no advertising identifier, no device identifier, no location, and no free text you entered.
I use these events to improve the app. Nothing in the app reads them back, and they are not used for advertising. The legal basis is my legitimate interest in improving the app (GDPR Art. 6(1)(f)). You can object at any time by writing to me.
Events are stored with your account ID. Events from before you sign in (the first-run onboarding) wait on your phone and are stored without your account ID.
They are kept in SelfPeak's own Supabase database in the EU (Frankfurt) and are not shared with any third party. They are kept for as long as your account exists. When you delete your account, the events linked to it are deleted with it.
6. Where your data is stored
Your account and synced data (workout history and ratings, plans, goals, training preferences including age, injuries and pain if you gave the health data consent in section 3, and your display name) are stored on Supabase servers located in the European Union (Frankfurt, Germany). A copy is also kept on your device for offline use. Authentication tokens are stored in the device's hardware-backed secure storage (iOS Keychain or Android Keystore). All traffic is encrypted in transit over HTTPS.
Progress photos stay on your device
Photos you add to your progress journal are saved only inside SelfPeak on your phone. They are not uploaded to the SelfPeak servers, not synced to your account, not sent to Apple Health or to Google Gemini, and never used for analytics or advertising. Only the capture date is read from a photo you choose from your library; other photo metadata, including location, is not kept.
You can delete a photo at any time in the journal, and all progress photos are deleted from the device when you sign out or delete your account. Like other app data, they may be included in your own device backup (for example iCloud Backup) if you have that turned on in iOS. SelfPeak has no access to that backup.
No ads, no selling
There are no ads in SelfPeak. I do not sell, trade or rent your personal information to third parties.
7. Services I use
SelfPeak relies on these processors, each with its own privacy policy:
- Supabase runs sign-in, the database, data sync and the waitlist, hosted in the EU (Frankfurt). supabase.com/privacy
- The Google Gemini API generates AI workouts and coaching, only with your consent. policies.google.com/privacy
- Apple and Google confirm who you are if you choose Sign in with Apple or Sign in with Google, and share the data listed in section 2. apple.com/legal/privacy, policies.google.com/privacy
- Sentry handles crash reporting and diagnostics, stored in Sentry's EU data centre (Germany). sentry.io/privacy
- Brevo sends the waitlist emails and account emails such as sign-up confirmation and password reset. brevo.com/legal/privacypolicy
- RevenueCat manages in-app subscriptions, and is used only if paid subscriptions are added. It is not active in the current version. revenuecat.com/privacy
8. Data sent outside the EU
Google processes the data sent for AI personalisation (section 4) on servers in the United States. Where data is transferred outside the European Economic Area, it is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses. By turning on AI personalisation you also consent to that data, including your fitness level, injuries and the pain you reported, being processed by Google in the US for the purpose of generating your plan.
My other processors may be companies based outside the EEA, but the data listed for Supabase and Sentry in section 7 is stored in the EU.
9. Waitlist and emails
If you join the waitlist on selfpeak.fit, I store your email address, when you joined and confirmed it, your invite code, the invite code of whoever sent you (if any), where you came from (for example Instagram or TikTok, from the link you followed) and your browser language.
To limit repeated sign-ups I keep counters keyed by your IP address and by your email address. They are deleted in a regular cleanup once they are two days old.
You get a confirmation email, and after that only emails about the SelfPeak launch. Brevo delivers them.
I keep your waitlist entry for 12 months after the launch of SelfPeak, until 10 October 2027, and then delete it. If you leave the list earlier, I remove you then. If you create a SelfPeak account, your account is covered by the rest of this policy (section 13); it does not depend on the waitlist.
How to leave: write to support@selfpeak.fit and I remove you.
10. Notifications
If you turn on workout reminders, the app schedules them on your device. They are local notifications: no push service is used, and no notification token is sent to me or to anyone else. You can turn them off at any time in Profile → Reminders and devices → Workout reminders or in your device's system settings.
11. Children
SelfPeak is not directed at children under 16, and I do not knowingly collect personal data from children under 16. If you believe a child has given me personal data, write to me and I will delete it.
12. Your rights
Under the GDPR you have the right to:
- access the personal data I hold about you;
- ask me to correct inaccurate data;
- ask me to erase your data (the "right to be forgotten"). You can delete your account and its data yourself in Profile → Account → Account settings → Delete account, or without the app at selfpeak.fit/delete-account;
- restrict or object to certain processing;
- data portability: ask for a copy of your data in a machine-readable format;
- withdraw consent (for health data, AI personalisation or the waitlist) at any time, without affecting processing that was lawful before you withdrew it;
- lodge a complaint with your supervisory authority. In Croatia this is the Personal Data Protection Agency (AZOP, azop.hr).
To use any of these rights, write to me at support@selfpeak.fit.
13. How long I keep your data
I keep your account and synced data for as long as your account is active. When you delete your account, your server-side data (authentication record, synced state, AI usage count, and the usage analytics linked to your account) is deleted, and local data on your device is cleared. A few things are kept after that:
- Usage events recorded before sign-in are stored without your account ID, so they are not deleted with your account.
- A one-way hash of your sign-in identity (not your email or name) and that day's AI usage count are kept, so that deleting and re-creating an account does not reset the daily AI limit. After 48 hours they are no longer used and are removed in a routine cleanup. The legal basis is legitimate interest in preventing abuse.
- Crash reports carry no account ID, email or IP address and are kept for up to 90 days to fix bugs.
- Data SelfPeak wrote to Apple Health stays in the Health app until you delete it there.
- Waitlist data is separate from your account and is kept as described in section 9.
14. Changes to this policy
I may update this policy. When I make a significant change, I will tell you by updating the date at the top of this page. If you keep using SelfPeak after a change is posted, the updated policy applies to you.