The short version
- Peak does not sell health or personal data.
- Peak does not use HealthKit data for advertising or marketing.
- Core records are stored on your device and may sync through your private iCloud account when you enable iCloud sync.
- Permissions for Health, location, camera, photos, notifications, and biometrics are requested for specific features and can be declined.
- OpenAI features are optional. Selected text or meal images are sent only when you choose an AI action and have configured an API key.
Who operates Peak
Peak is an app in development by NexCode, an independent software studio founded by Daniel Schulte. In this policy, “Peak,” “NexCode,” “we,” and “our” refer to the app and its operator. The fastest way to reach us about privacy is through Peak Support.
Information Peak uses
Account and profile
Depending on the sign-in method you choose, Peak may use an Apple user identifier, Google account identifier, email address, display name, and profile image. Local email credentials are stored in the device Keychain in the current development build. Sign-in tokens and the user-supplied OpenAI API key are also stored in Keychain and marked as accessible only while the device is unlocked.
Health and wellness
With your permission, Peak can read selected Apple Health data such as sleep, heart rate, resting heart rate, respiratory rate, blood pressure, blood oxygen, body temperature, height, weight, activity, workouts, and optional cycle information. Peak can write hydration and mindfulness entries when you ask it to. You choose Health permissions by data type and can change them in iOS Settings or the Health app.
Entries you create
This may include meals and nutrition estimates, water, workouts, mood, habits, notes, goals, wellness status, cycle logs, symptoms, profile details, journal content, and app-layout preferences.
Location, camera, and photos
Location is used only after permission for local Apple Weather conditions and location-aware outdoor workouts. Camera and photo access is used when you scan a food barcode, select a profile or journal image, or deliberately choose a meal photo for AI analysis.
Purchases and diagnostics
Apple processes App Store purchases. Peak receives product and entitlement status from StoreKit but does not receive your payment card details. The current build does not include third-party advertising or behavioral analytics SDKs. Standard platform and service providers may still process technical request information needed to deliver their services.
Storage, security, and sync
Peak is designed around an on-device SwiftData store. If you enable iCloud sync and iCloud is available, eligible Peak records sync through Peak’s private CloudKit database in your Apple account. If CloudKit is unavailable, Peak can use a local persistent store instead.
Apple’s data-protection capability is enabled for the app, and sensitive credentials are placed in Keychain. No security method can guarantee absolute protection, but Peak minimizes server infrastructure and requests only the platform permissions used by its features.
Services Peak can connect to
HealthKit, iCloud/CloudKit, Sign in with Apple, StoreKit, WeatherKit, notifications, Keychain, camera, photos, location, and biometrics. Apple processes these services under its own terms and privacy policies.
If you choose Google sign-in, Google authenticates your account and returns identity information needed to establish the Peak session.
If you explicitly enable the OpenAI Coach or request AI meal analysis, Peak sends the relevant prompt, limited recent coach history, or selected meal image to the OpenAI API using your API key. Requests set store: false and include a one-way hashed safety identifier. AI output may be inaccurate.
Barcode searches can request community-provided product and nutrition information. That information may be incomplete or incorrect, so Peak requires review before saving.
Peak does not send HealthKit data to a third party for advertising, data brokerage, or unrelated profiling. Where a user deliberately invokes an AI health-and-fitness feature, only the information needed for that requested feature should be sent.
Your controls
- Grant or deny each Apple Health category.
- Use Peak without location, camera, photo, notification, or biometric access where the related feature is not needed.
- Keep records on-device or opt into private iCloud synchronization.
- Use the on-device Coach instead of OpenAI, remove the OpenAI key, or disable OpenAI access.
- Edit or delete individual logs and export available app data in CSV or PDF form.
- Change or cancel Apple-managed subscriptions through your Apple Account.
Retention and deletion
Peak keeps app records until you delete them, delete your account, or remove the app’s storage. Individual logs can be removed from their relevant screens. In Peak, open your profile, find the account controls, and choose Delete Account to delete Peak models from the active store, clear Peak credentials from Keychain, sign out, and reset onboarding.
If iCloud sync is active, deletions are expected to synchronize through CloudKit. Copies may remain temporarily in system backups or provider-controlled retention systems. Health records originally held by Apple Health must be managed in the Health app. Deleting Peak does not automatically delete records owned by Apple Health, Google, OpenAI, Open Food Facts, or Apple purchase history.
Children, medical limits, and international use
Peak is not directed to children under 13 and is not intended to collect children’s personal information. Peak is a general wellness tool, not a medical device. It does not diagnose, treat, or prevent a condition. Do not use Peak, its AI features, recovery scores, cycle estimates, or weather information for emergency or life-saving decisions.
Policy changes
We may update this policy as Peak changes. The effective date at the top will change when material revisions are published. Before a public App Store release, the policy and the App Store privacy disclosures will be reviewed against the final production build.
Contact
For a privacy question, correction, access request, or deletion issue, use Peak Support and choose “Peak app support.” Include the sign-in method you used, but never send a password, Apple token, Google token, OpenAI key, medical record, or full health export through the form.
