Privacy Policy

Last Updated: May 1, 2026

1. Introduction

Welcome to MyPeak. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application («App») and our website mypeakapp.com («Website»), including any purchases made through our online store.

The data controller is MyPeak (hereinafter, "we", "our" or "MyPeak"). For privacy-related inquiries, you can contact us at [email protected].

We recommend that you read this policy in its entirety. By using our App or our Website, you agree to the practices described in this document.

2. Scope of Application

This policy applies to:

  • The MyPeak mobile application (iOS and Android).
  • The website mypeakapp.com, managed using WordPress.
  • The online store integrated into the Website, managed using WooCommerce.
  • All services, functions, and interactions associated with the above.

3. Information We Collect

3.1 Data collected through the App

Account Details: When you register, we collect your username, email address, and a "hashed" (encrypted) version of your password.

Training Data: We collect the data you voluntarily provide, including training routines, exercise names, sets, reps, weights, and body measurement history.

AI Interaction Data: Your training history is processed by Google's Gemini API to generate performance insights. We do not share your personal identifiers, such as your email address, with the AI model.

App Analytics Data: We collect anonymous data about your device (such as model and operating system version) and how you interact with our app (such as screens visited and features used) through Google Firebase Analytics. This data helps us improve our services and is not linked to your personal identity.

3.2 Data collected through the Website

Navigation Data: When you visit our Website, we automatically collect technical information such as your IP address, browser type, operating system, pages visited, time spent on the site, and referring URL, through Google Analytics.

Contact Information: If you send us a contact form or subscribe to our mailing list, we collect your name and email address.

Web Registration Details: If you create an account on the Website through WooCommerce, we collect your first name, last name, email address, and encrypted password.

Cookies and Web Tracking Technologies: Our website uses cookies and similar technologies. See Section 9 for more information.

3.3 Data collected in purchase transactions (WooCommerce and Stripe)

When you make a purchase on our Website, we collect:

  • Billing information: full name, billing address, email address and phone number (if applicable).
  • Shipping information: If the order includes physical products, we collect your delivery address.
  • Order history: Details of the products or subscriptions purchased and purchase dates.
  • Payment details: Your credit or debit card details are NOT stored on our servers. Payment processing is handled entirely by Stripe, Inc., a PCI-DSS certified payment processor. We only receive a transaction confirmation and, if applicable, an anonymized payment identifier.

4. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, operate and maintain the App and the Website.
  • Process and manage your orders, subscriptions, and payments made through WooCommerce and Stripe.
  • Generate custom AI-powered performance charts and progress summaries.
  • Communicating with you, including account management, technical support, and sending order confirmations.
  • To understand and analyze how you use our App and Website, in order to improve functionality and user experience.
  • To comply with our legal obligations, including tax and accounting obligations arising from business transactions.
  • Preventing fraud and ensuring the security of our services.
  • With your consent, send you marketing communications related to MyPeak.

5. Legal Basis for Processing (EU Users — GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, the processing of your personal data is based on the following legal grounds, in accordance with the General Data Protection Regulation (GDPR):

Performance of a contract (Art. 6.1.b GDPR): We process your account and purchase data to fulfill our service or sales contract with you. This includes processing payments through Stripe and managing your subscription through WooCommerce.

Legitimate interest (Art. 6.1.f GDPR): We process anonymous analytical data (Firebase Analytics, Google Analytics) to improve our services and detect technical errors. This interest does not override your fundamental rights.

Consent (Art. 6.1.a GDPR): For the use of non-essential cookies (such as Google Analytics for statistical purposes) and for sending marketing communications, we rely on your explicit consent, which you can withdraw at any time.

Legal obligation (Art. 6.1.c GDPR): We retain certain transaction data to comply with our tax and accounting obligations under applicable law.

6. Perspectives on AI and Data Processing

The AI-powered insights feature sends your anonymized training history (exercise names, sets, reps, weights, and timestamps) to Google servers to be processed by the Gemini language model. Your personal account information (such as email or username) is NOT sent to the AI model.

Please note that the insights generated are for informational purposes only and are not a substitute for professional medical or fitness advice. Do not rely on AI insights for medical diagnosis or treatment. Always consult a qualified healthcare professional.

7. Exchange and Disclosure of Data

We do not sell your personal information. We may share your information with third parties only in the following situations:

Using Google (Gemini API): To provide the AI Coach function, as described in Section 6.

With Google (Firebase Analytics): Anonymous app usage data is shared for behavioral analysis.

With Google (Google Analytics): Anonymous or pseudonymized browsing data from the Website is shared for statistical analysis.

With Stripe, Inc.: To securely process payments made on our website, Stripe operates as an independent payment processor and is subject to its own privacy policy (stripe.com/es/privacy). Credit card data is processed directly by Stripe and does not pass through our servers.

With Automattic, Inc. (WordPress / WooCommerce): Our website is hosted on the WordPress platform and uses WooCommerce for e-commerce management. These services may process technical data necessary for the website's operation.

With Hosting and Cloud Service Providers: We may share data with the infrastructure providers that host our App and our Website, subject to appropriate data processing agreements.

For Legal Reasons: We may disclose your information if required by law or in response to valid requests from public authorities (for example, a court or government authority).

In the event of a business reorganization: If MyPeak is involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction. We will notify you in advance by email and through a prominent notice on our website.

8. International Data Transfers

Some of our third-party providers (including Google and Stripe) may be located or process data outside the European Economic Area (EEA), specifically in the United States. In these cases, we ensure that such transfers are carried out with the appropriate safeguards required by the GDPR, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • The EU-US Data Privacy Framework, where applicable.
  • Compliance with equivalent transfer mechanisms recognized by current legislation.

You can request more information about applicable safeguards by contacting us at [email protected].

9. Cookies and Tracking Technologies

9.1 In the App

We use Google Firebase Analytics to collect anonymous data about your device and how you interact with our app. This helps us understand usage patterns, fix bugs, and improve functionality. This data is essential for operating the service and is not used for marketing or cross-site tracking.

9.2 On the Website

Our website, powered by WordPress, uses the following types of cookies:

Strictly necessary cookies: They are essential for the basic operation of the Website and the WooCommerce store (for example, to keep your session active, manage the shopping cart, and process payments). They do not require your consent.

Analytical cookies (Google Analytics): We use Google Analytics to collect information about how visitors use our website (pages visited, time spent, traffic source). The data is collected anonymously or pseudonymized. These cookies are only activated if you give your consent via our cookie banner.

Functional cookies: They allow the Website to remember your preferences (such as language or currency). They are only activated with your consent.

Cookie Management: When you access our website for the first time, you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies. You can modify your preferences at any time via the "Cookie Settings" link available in the website footer. You can also configure your browser to block or delete cookies; however, this may affect the proper functioning of some parts of the website.

10. Data Retention

We retain your personal data for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law:

  • App account details: While your account is active. If you delete your account, your data will be deleted within 30 days, unless we are legally required to retain it.
  • Transaction and billing data (WooCommerce / Stripe): Purchase data is kept for the period required by applicable tax and commercial legislation (generally 5 to 7 years depending on the jurisdiction).
  • Anonymous analytical data (Firebase / Google Analytics): Depending on the service retention setting, generally between 14 and 26 months.
  • Contact form data: They are kept for the time necessary to respond to your inquiry and up to an additional 2 years for follow-up purposes.

11. Data Security

We use administrative, technical, and physical security measures to help protect your personal information. These measures include encrypting data in transit using TLS/HTTPS, storing passwords in hashed format, and delegating payment processing to Stripe, which is PCI-DSS Level 1 certified.

While we have taken reasonable steps to protect the personal information you provide to us, please be aware that no security measure is perfect or impenetrable, and we cannot guarantee the absolute security of your information.

In the event of a data breach that may pose a risk to your rights and freedoms, we will notify the relevant authorities and, where legally required, the affected users, within the time limits set by applicable regulations.

12. Your Rights

12.1 Users' rights in the European Union (GDPR)

If you are in the EEA or the United Kingdom, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right of rectification: Request the correction of inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): Request the deletion of your personal data, unless there is a legal obligation to retain it.
  • Right to restriction of processing: Request that we restrict the processing of your data in certain circumstances.
  • Right to portability: Receive your data in a structured, commonly used, and machine-readable format.
  • Right to object: To object to the processing of your data based on our legitimate interest or for direct marketing purposes.
  • Right to withdraw consent: When the processing is based on your consent, you have the right to withdraw it at any time without affecting the lawfulness of the previous processing.
  • Right to file a complaint: If you believe that the processing of your data violates applicable regulations, you have the right to file a complaint with the competent supervisory authority in your country (in Spain, the Spanish Data Protection Agency — www.aepd.es).

To exercise any of these rights, you can contact us at [email protected]. We will respond to your request within 30 days.

You can manage your App account information and delete your account directly from the App's Profile section.

12.2 User Rights in California, USA (CCPA / CPRA)

If you are a resident of the state of California, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know: Request information about the categories and specific personal data we have collected about you, the purposes of its use, and with whom we share it.
  • Right to elimination: Request the deletion of your personal data, subject to certain exceptions.
  • Right to correction: Request the correction of inaccurate personal data.
  • Right to non-discrimination: You will not receive discriminatory treatment for exercising your privacy rights under the CCPA/CPRA.
  • Right to opt out of selling or sharing your data: MyPeak does not sell your personal data to third parties or share it for cross-site behavioral advertising purposes.

To exercise your rights under the CCPA/CPRA, contact us at [email protected].

12.3 Rights of other users in the USA.

Other U.S. states have enacted similar privacy laws (such as Virginia, Colorado, Connecticut, and Utah, among others). To the extent such laws are applicable, we recognize and will respect the privacy rights they grant you. Contact us at [email protected] to exercise any applicable privacy rights in your jurisdiction.

13. Children's Privacy

Our services are not directed to individuals under the age of 16 in the European Union (or the applicable minimum age of consent in your country) or under the age of 13 in the United States. We do not knowingly collect personal data from minors. If we discover that we have collected data from a minor without verifiable parental consent, we will take steps to delete that information immediately. If you believe that a minor has provided us with personal data, please contact us at [email protected].

14. Links to Third-Party Websites

Our website may contain links to third-party websites. This Privacy Policy does not apply to those sites. We encourage you to read the privacy policy of any third-party website you visit. We have no control over the content or privacy practices of those sites and assume no responsibility for them.

15. Changes to this Privacy Policy

We may update our Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable law. We will notify you of any relevant changes by posting the new Privacy Policy on this page and indicating the date of the last update at the top of the document.

If the changes are significant, we will provide you with more prominent notice, which may include an email notification for registered users.

16. Contact us

If you have any questions about this Privacy Policy, wish to exercise your rights, or would like more information about how we process your personal data, you can contact us at:

Email: [email protected]
Website: mypeakapp.com