PeakBod PEAKBOD

Privacy Policy

Last updated July 21, 2026

PeakBod looks at photos of your body and estimates how developed each muscle group is, then builds a training plan from the result. This page says exactly what we collect, where it goes, how long we keep it, and how you delete it. Plain language, no lawyer-speak.

Who we are

PeakBod is published by an independent developer based in France.

Questions about this policy, or about your data: sten.irlpro@gmail.com.

Your photos

PeakBod asks for two photos of your body — front and back — and, optionally, a reference photo of the physique you are aiming for. You frame the shot yourself.

PeakBod never analyzes your face. The analysis is about the development of your muscle groups, nothing else. There is no facial scan, no facial measurement, and no facial data of any kind anywhere in this app.

Before anything leaves your phone, each photo is resized on your device to a maximum of 1024 pixels and re-encoded as a JPEG. The resized copy is sent over HTTPS to our server, which passes it straight to OpenAI for analysis.

We do not store your photos. Not in a database, not in file storage, not in our logs. They exist in our server’s memory for the few seconds the analysis takes, and then they are gone. The only thing kept from a scan is the resulting numbers.

The original photos never leave your phone except for that one transfer. They stay in your photo library and in the app’s local storage.

PeakBod uses OpenAI’s API to perform the image analysis. Under OpenAI’s policies, data sent through the API is not used to train or improve their models, and API inputs are retained by OpenAI for up to 30 days for abuse monitoring, then deleted (unless a longer period is legally required). OpenAI processes this data on U.S. infrastructure. See openai.com/enterprise-privacy and openai.com/policies.

What we save on our servers

Each scan writes a single row to our database. That row contains: the estimated development level of each of your 14 muscle groups, the raw estimate the model returned before our corrections, which muscle group came out lowest, the name of the model used, an anonymous device identifier, and the date.

That is the entire record. No photo, no name, no email, no phone number.

The device identifier is a random string generated by the app on your phone the first time you scan. It is not your Apple ID, not your phone number, not your advertising identifier (IDFA), and not your vendor identifier (IDFV). Its only job is to let your scans be grouped together over time.

Scan rows carry only that identifier. This table holds no name and no email.

We keep scan rows for 90 days. After that they are deleted automatically by a scheduled job that runs every day — this is not a promise to act on request, it is a mechanism that runs on its own.

These rows are stored on infrastructure hosted in the European Union (Ireland), operated by Supabase.

What we send along with a scan

The analysis request also carries the goal you selected, your declared training level, and your body weight. These give the model context and keep estimates consistent from one scan to the next.

They are used for the analysis only. They are not written to the scan record.

No account

This version of PeakBod has no accounts and no sign-in. You use every feature without creating one — there is no username, no password, and no login of any kind.

Your progress

Your onboarding answers (age, height, weight, goal, training level, gym access, equipment, weekly frequency), your muscle levels, your completed workouts, your streak, your progress photos and your scan history live on your device and nowhere else. Deleting the app deletes them permanently, and reinstalling starts you from zero.

Your progress photos — the ones you add yourself to follow your change over time — stay on your phone and are never uploaded. They are not your scan photos; those are never stored at all, by anyone, as described above.

What we do not collect

No password, no account, no login of any kind.

No email address and no name.

No location. No contacts. No advertising identifier. No device fingerprinting.

No analytics, no crash reporting, no attribution, no marketing SDK. There is no third-party software development kit of any kind in this app.

No tracking across other apps or websites. We do not track you, full stop.

No push notification token. Notifications are scheduled entirely on your phone by the app itself; nothing is sent from a server, so no server can know when you open PeakBod or whether you train.

No payment information. PeakBod Pro is sold through Apple’s In-App Purchase — your payment details go to Apple, never to us. We only learn, from Apple, whether your subscription is active.

Who processes your data

Supabase hosts our database and the server functions that handle a scan or a deletion.

OpenAI performs the image analysis.

Apple processes your subscription purchase through In-App Purchase; your payment details go to Apple, never to us.

That is the complete list. We do not sell your data, and we do not share it for advertising. There is nobody else in the chain.

Deleting your data

Open Settings in the app and tap “Delete my data”. It erases every scan row tied to your device from our servers, and everything the app holds on your phone: your levels, your history, your streak, your progress photos and your answers. Your device identifier is replaced with a new one, so nothing you do afterwards can be linked to what was deleted.

It takes effect immediately and it cannot be undone. There is nothing to wait for and nobody to ask.

If you would rather ask us, or if you want to know what is held against your device identifier, write to sten.irlpro@gmail.com.

Deleting the app removes everything stored on your phone. It does not remove anything from our servers — use “Delete my data” first if you want both gone.

Children

PeakBod is for people aged 13 and over.

We do not knowingly collect personal information from children under 13. If we learn that we have, we delete it. If you believe a child under 13 has used PeakBod and given us data, write to sten.irlpro@gmail.com and we will remove it.

Your California privacy rights

If you live in California, the CCPA and CPRA give you rights over your personal information. Because of how PeakBod is built, there is very little of it: an anonymous device identifier and the numbers from your scans, kept for 90 days.

You have the right to know what we collect and why — this page is that disclosure, and it is complete.

You have the right to delete your personal information. The “Delete my data” button in Settings does exactly that, immediately, without asking us.

You have the right to correct inaccurate personal information. Since what we hold is a machine estimate rather than a fact you supplied, correction in practice means deleting it and scanning again.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by California law. We never have, and there is no mechanism in the app that could.

We will not discriminate against you for exercising any of these rights. There is no worse version of PeakBod for people who ask us to delete their data.

If you are in the EU, EEA or UK

You have the right to ask what personal data we hold about you, to have it corrected, and to have it deleted. The “Delete my data” button covers deletion immediately; for anything else, write to sten.irlpro@gmail.com.

Scan rows are hosted in the European Union (Ireland). Photos are sent to OpenAI for analysis on infrastructure in the United States, and are not stored by us.

PeakBod’s publisher is based in France, so the GDPR applies. Our lawful basis for the little data we process is your consent and the performance of the service you asked for; the data controller is the publisher, reachable at the contact email above. You may also lodge a complaint with your local data-protection authority.

Security

Everything the app sends travels over HTTPS.

The scan table is locked down. The app cannot read it or write to it at all — only our server function can, using a key that never leaves the server. That key is not in the app, and it is not in our source code.

The same is true of our OpenAI key: the app never holds it and never talks to OpenAI directly.

Changes to this policy

If this policy changes, the date at the top of this page changes with it. Significant changes will be surfaced in the app.

Questions: sten.irlpro@gmail.com.