Peaf

Your life isn’t the product

Privacy Policy

Peaf is built for deeply personal information, so privacy isn’t an add-on.

Last updated September 1, 2026

The short version

Peaf is a private journal and a private way to stay close to the people who matter to you. That only works if your data stays yours, so the app is built that way and this policy describes exactly what that means.

  • We never sell your data, and we never share it with advertisers or data brokers.
  • We do not use advertising trackers, and we never sell or share your personal information for targeted advertising. The app measures how much it is used only if you say yes, and never what you write, name or photograph.
  • Everything you create is private by default. A moment is visible only to you until you deliberately choose an audience for it, or create a share link for it.
  • Your phone’s address book is never uploaded. Peaf uses it on your device to help you find people, and only hashes leave your phone.
  • Your content is never used to train shared AI models. Most of Peaf’s AI runs on your phone; content goes to an external AI service only with your explicit consent, for a feature you turned on that cannot work otherwise.
  • The sensitive features are opt-in and off by default — health syncing, automatic health sharing, AI meal estimation, suggestions based on your photo library, and helping us improve the assistant. You can turn each one off, and delete what it collected.
  • You can take everything with you — one tap in Settings builds a ZIP of your whole account, original photos and videos included.
  • You can delete your account from inside the app, and we actually delete it: your content, your account, and your contributions to other people’s shared moments. When you leave, your data leaves with you.

The rest of this page is the detail behind those promises. It is written to be read, not to be skimmed past — if anything here is unclear, email us and we will explain it.

Who we are

Peaf is an independent app built and operated by a solo developer based in the United States (“Peaf”, “we”, “us”). We are the party responsible for the personal information described here — in privacy law terms, the controller (GDPR) or business (California).

This policy covers the Peaf iOS app, the Peaf website at peaf.app, and the Peaf backend service that syncs your data between your devices and the people you share with.

You can reach us about anything on this page at help@peaf.app.

What we collect

We collect what the app needs to work, and we try not to collect anything else. Here is the whole list.

Information you give us directly

DataWhy we have it
Account detailsYour email address, username, and optionally your first and last name and a profile photo. Needed to create your account, sign you in, and let the people you connect with recognize you.
Sign-in credentialsIf you use a password, we store only a scrambled (hashed) version — never the password itself. If you sign in with Apple or Google, we store the account identifier they give us. If you use a passkey or two-factor authentication, we store the credential needed to verify it.
Your contentThe moments you create and everything in them: captions, notes, dates, photos and videos, voice notes, locations and saved places, comments, reactions, the people you tag, your groups and collections, and your private notes about a contact.
What you logThe books, films, TV shows and games you track; your reading and watching progress; meals and meal plans; and any other journal entries you choose to keep.
Support messagesIf you email us, we keep the message and our reply so we can help you.
Bug reports and ideasIf you send feedback from inside the app, we keep what you wrote, plus — because a bug report without them is usually unfixable — technical diagnostics such as your app and iOS version, and any screenshot you chose to attach. You decide whether to include a contact email for a reply.
Share links you createWhich moments a link covers, the name you addressed it to, when it expires, and — if you set one — a scrambled (hashed) version of its passphrase. See Share links for the whole picture.

Information collected automatically

DataWhy we have it
Device and connection dataYour IP address, device model and iOS version, app version, and time zone. Used to deliver the service, keep dates correct across time zones, and detect abuse.
How much the service is usedOur own server logs record which features were called and that an account was active, against a one-way pseudonym — not your account identifier. We use it to count how many people use Peaf and which parts they use. It cannot tell us who you are, where you were, or which of your moments, places or people were involved: the address of every request is stripped of identifiers before it is logged, and we deliberately removed the country and language fields that would have made it possible to work backwards.
Share link opensWhen somebody opens a link you sent them: a one-way fingerprint of their browser, a short device description such as “iPhone · Safari”, an approximate city, and the time. Used to keep the link bound to one device and to show you whether it reached the right person. Their full browser identifier and network address are not stored.
App usage measurementOnly if you say yes. Firebase Analytics is switched off in the app we ship and stays off until you turn on “Help improve Peaf” — we ask once, and the switch is in You → Data & Privacy. Once on, Google’s Firebase Analytics records that the app was opened, for how long, on what device model, iOS version, app version and approximate country, and which features you open. It is collected against a random code created when you install the app — not your account, not your name, and never joined to either. It records no screen views: automatic screen reporting is switched off in the app we ship. Google deletes all of it after two months. Turning the switch off stops collection and discards the code.
Push notification tokenAn anonymous identifier issued by Apple and Firebase so we can deliver notifications to your device. It is not an advertising identifier and cannot be used to track you across other apps.
Crash diagnosticsIf the app crashes, Firebase Crashlytics sends us a technical report of what went wrong — device model, iOS version, app version and where in the code it failed. It no longer carries your user ID or username: the report is tagged with a one-way pseudonymous identifier, which lets us see that the same anonymous installation crashed twice without telling us who you are. It does not include the content of your moments.
Security and rate-limit recordsSign-in attempts, session tokens, and counts of certain requests, kept to protect accounts from takeover and abuse.

Your phone’s address book — the part people ask about most

If you allow it, Peaf reads your address book on your device to find which of the people in it already use Peaf. Your address book is not uploaded. Each phone number is converted on your phone into a fixed-length code (a SHA-256 hash), and only those codes are sent for matching. Your address book never reaches us: not the names, not the emails, not the numbers themselves. Codes that match nothing are not stored against your account or anyone else’s — but we do remember, for 24 hours, which codes have been looked up, so that we can cap how many any one account may test. That cap is the thing below that makes large-scale probing impractical, and it cannot work without the memory. After 24 hours the record is gone. We had said we kept none of them, which was not right.

We would rather be precise than reassuring about what this does and does not protect. Phone numbers are drawn from a small and predictable range, so this kind of code is not the same as being unreadable: someone who obtained a list of them could work out which numbers produced them by trying candidates until they matched. What the technique reliably does is keep your address book off the wire and out of our hands. What it does not do is make a leaked code permanently meaningless. We limit how many lookups an account can perform to make large-scale probing impractical, and we are actively looking at stronger contact discovery methods.

Being findable this way is your choice: you can turn phone discoverability on or off at any time in Settings, and turning it off removes your stored code from our servers. Names, emails and other address-book details never leave your phone.

The contacts you create inside Peaf are a different thing. A person you add to Peaf — their name, their birthday, what you keep about them — is your own content, and it syncs to our servers like your moments do, so it survives a lost phone. Your phone’s address book is what stays on your phone; the contacts you deliberately keep in Peaf are not the same list.

What we never do

  • We do not sell your personal information, and we have never sold it. We do not share it for cross-context behavioral advertising.
  • We do not use advertising trackers, the app contains no advertising SDK, and nothing in it follows you across other companies’ apps or websites.
  • We measure how much the app is used, and never what is in it. Two things do the measuring, and both are deliberately blunt. Google’s Firebase Analytics records that the app was opened, for how long, and on what device and version — against a random per-install code, never your account. Our own server logs count which features were called, against a one-way pseudonym. Neither one ever receives the words you wrote, the names you gave anyone, the places you kept, or anything from your photos or your health data. Both are described in What we collect, with how long each is kept.
  • We do not measure you without asking. Firebase Analytics is switched off in the app we ship and cannot start on its own — Peaf asks once, in the same sheet as the other choices it will not make for you, and the switch stays in You → Data & Privacy. Say no and nothing is ever sent; turn it off later and the random code is discarded along with it. The server-side count is different, and we do not pretend otherwise: it is a by-product of running the service at all, so it is described in What we collect rather than offered as a choice.
  • We do not record screen views. Firebase’s automatic screen reporting is switched off in the app we ship, and we send no screen or tap events of our own. No funnels built from what you looked at, and no session replay.
  • We correct this page when we find it wrong. Until 30 August 2026 this section said the app measured nothing, and that was not true: the setting meant to switch Firebase Analytics off was written under a key name the SDK does not read, so collection ran from first launch. We have chosen to keep the measurement described above for the beta rather than restore the claim, and to say so here.
  • We do still collect crash reports automatically, because an app that crashes silently never gets fixed. Those reports are technical and pseudonymous — see What we collect.
  • We do not access your private content for advertising, profiling, or any purpose unrelated to running the app. Automated systems process it only as far as is necessary to provide the features you use.
  • Your private content is never used to train shared AI models — ours or anyone else’s. Peaf sends private content to an AI provider only when doing so is necessary to perform an AI feature you have chosen to use, and only the content that feature needs.
  • We do not make your content public. Peaf has no public feed and no discovery of strangers’ content. The one way a moment can leave the app is a share link you create yourself and address to one person. It is not indexed, not discoverable, and stops working when you revoke it.

Access by a person. Human access to private content is restricted and subject to controls. It happens only where necessary — to investigate a security incident, to resolve a support request you have raised, or to comply with a valid legal obligation — and never out of curiosity, and never for commercial purposes. Where we can help you without looking at your content, we do.

AI and your content

Peaf has AI features, and we think you should know exactly what they do with what you write and photograph. Three rules govern all of them.

Your private content is never used to train shared AI models. Not ours, not a provider’s, not a future one. Your moments, photos, captions, notes and health data are yours; they do not become training material for a model that anyone else benefits from, and we do not grant anyone the right to use them that way.

We send private content to an AI provider only when it is necessary to perform an AI feature you chose to use — and only the specific content that feature needs, for as long as the request takes.

And we ask you first. Nothing goes to an external AI service without your explicit consent for that specific feature, and we would not use your content to train a model without asking you separately and getting a clear yes. Consent to one thing is never consent to another: allowing meal photo estimation permits that and nothing else. You can withdraw any of it at any time in Settings, and the rest of Peaf keeps working exactly as before. If we ever want to do something new with your content, we will explain it and ask — and saying no will always be a real option, not one that costs you the app.

In practice, most of Peaf’s AI runs on your device and sends nothing anywhere. The assistant that turns “dinner with Marie last night” into a moment, the parser that reads a pasted meal plan, and the ingredient and calorie estimates for text you type all use Apple’s on-device model. Your words never leave your phone for those features, even when you are offline.

Dictation is the honest exception. When you speak to Peaf instead of typing, the audio is turned into text by Apple’s speech recognition. On devices that support on-device recognition that happens entirely on your phone; where the device or the language does not support it, iOS sends the audio to Apple’s speech service to transcribe. That is Apple’s system, not ours — we receive only the resulting text — but it means we cannot promise the audio always stays on the device, so we do not. The permission prompt in the app says the same thing before you agree to it.

As of the date at the top of this page, one feature sends content off your device to an AI provider: meal photo calorie estimation. It is off by default. When you turn it on, the photo of that meal is sent to Anthropic’s Claude API to identify what is on the plate, and Anthropic does not use it to train their models. When the setting is off, the server refuses the request outright, so the photo cannot be sent even by mistake. As of that date, no other photo in Peaf is sent to an external AI service.

We expect to add other AI features over time, and we would rather tell you the rule than a number that goes out of date. Every new capability that sends content to an external AI service gets its own switch, off until you turn it on, enforced on our servers rather than in the app. A new capability never inherits permission from one you already allowed, so nothing starts sending because we shipped an update. When we add one, we will update this page and tell you it changed.

The one other AI-related thing we collect — data to check whether the assistant is getting things right — is optional, and is scrambled on your device before it is sent, as described in Optional features you turn on. It is used to measure and improve how Peaf’s assistant works, never to train a model for anyone else.

How we use it

We use the information above only to:

  • run the app — store your moments, sync them between your devices, and deliver them to the specific people you share with;
  • authenticate you and keep your account secure, including detecting and blocking abuse;
  • send you notifications you asked for, such as a reaction on a shared moment, a connection request, or a reminder you set;
  • send necessary service emails — verifying your address, resetting your password, or telling you about a change that affects you;
  • fix crashes and bugs; and
  • comply with the law, and enforce our terms if someone abuses the service.

We do not use your data for automated decision-making that produces legal or similarly significant effects about you, and we do not profile you for advertising.

Optional features you turn on

These features are off by default. Each one is described here so you can decide before enabling it, and each can be switched off later.

Health and activity syncing

Covered in its own section below — Health and activity data.

AI calorie estimation for meal photos

If you turn this on, a photo of a meal you log — and only that photo — is sent to Anthropic’s Claude API to estimate what the meal contains and roughly how many calories it holds. Anthropic processes it to return that estimate and does not use it to train their models. If the setting is off, the server refuses the request outright, so no meal photo is sent to any AI service. As of the date of this policy, no other photo in Peaf is sent to an external AI service.

Helping us improve the assistant

Peaf’s assistant lets you create moments by typing naturally. Using the assistant and helping us improve it are two entirely separate decisions. The assistant simply works on devices that can run it, and using it sends us nothing about what you asked. Contributing your interactions is a second, separate question, asked on its own screen, and it lives as its own switch in Settings. Saying yes to the assistant has never been a way of saying yes to this — and if you were asked the two together in an earlier version of the app, they are now split apart.

If you do opt in to help improve it, we collect what you asked for and whether the assistant got it right — after your phone has scrambled it. A two-pass process on your device replaces every name, place, phone number and email with a placeholder such as [PERSON_1] or [LOCATION_1] before anything is sent. Where you file something about another person — that a friend is allergic to penicillin, say — we keep only that you recorded it, never what it said. That fact is theirs, and they were never asked.

The same setting also collects moments you write yourself, with no assistant involved, scrambled the same way. That sample is what teaches the assistant what a real moment looks like. We had described this setting only as “what you ask”, which was narrower than what it collects, so we are correcting it here.

This data is stored against a random token rather than your user ID, and it carries no name, no email and no account reference. Rotating that token — which happens whenever you turn the setting off — cuts the link to everything recorded before it. We can still re-establish that link with access to our own database, and that is deliberate: it is what lets us find your assistant data when you ask to see or delete it. A design where nobody could make the connection would also be one where nobody could erase it on your behalf. We had said this data “cannot be joined back to your account”, which claimed more than we can honestly promise. You can see exactly what was collected and exactly what left your phone in Settings → Privacy → View collected data, and delete all of it from both your device and our servers with one tap. Turning the setting off stops future collection.

Suggestions for things to log

Peaf can suggest moments worth keeping — noticing that you took a burst of photos somewhere yesterday, or that you are near a place you have saved. Working that out means looking at your photo library and looking up where you were, which is a lot to do to someone without asking. So we ask first.

Nothing is scanned until you have seen the explanation screen and said yes. Before that, Peaf does not read your photo library for suggestions, does not look up locations for them, and builds no profile of your habits. All of it runs on your phone; suggestions are not sent to us. Your answer is stored on your account rather than only on the device, so signing in on a new phone does not quietly reset it to yes, and declining stays declined. You can change your mind either way in Settings.

Health and activity data

Health data is the most sensitive thing Peaf can hold, so it gets its own rules. Whatever the source, health and activity data is created private to you. Sharing any of it takes a deliberate action by you in the app; no sync, import, assistant action or scheduled job can widen who sees it. Because sharing works per moment, sharing a daily moment shares everything in it — which is why the app warns you before you do.

Peaf can also share health data automatically, through a rule you set up — your sleep score going to your partner each morning, say. Because a rule keeps working after you have forgotten you made it, the first time you set one up the app stops and asks for your explicit consent, on a screen that spells out what will be shared, with whom, and that it will keep happening. You cannot arrive at an automatic health share by accident. That consent is recorded on your account with the version of the wording you agreed to and the date you agreed to it, so both of us can see exactly what was asked. Declining creates nothing, and you can stop or delete any rule at any time afterwards.

We never use health data for advertising or marketing, never sell it, and never share it with third parties beyond the providers listed in this policy that are needed to deliver the feature.

WHOOP

If you connect a WHOOP account, Peaf retrieves your sleep, recovery, workout and daily cycle data, plus your WHOOP profile, and turns them into private daily moments. The connection uses WHOOP’s own authorization screen, so we never see your WHOOP password, and the access tokens we receive are encrypted before being stored.

You can disconnect at any time in Settings, which stops the sync and deletes the stored connection. Moments already created from that data stay in your journal until you delete them, like anything else you have logged.

Apple Health (HealthKit)

Peaf reads Apple Health only if you turn it on, from Body → Apple Health. Nothing is read until you tap it and iOS asks you; installing or updating the app switches nothing on.

When it is on, Peaf reads your workouts and sleep, and the figures attached to them: heart rate, resting heart rate, heart rate variability, active energy, and walking or running, cycling and swimming distance. It reads the summary of each workout and each night, not the underlying stream of samples.

Peaf never writes to Apple Health. Everything above is read-only, and Peaf writes nothing back.

Maps of your runs

A route is a map of where you live and run, so it is the one thing Peaf treats as a separate question. It is a separate permission, asked separately, off unless you turn it on in Body → Apple Health, and refusable on its own — declining it changes nothing about the rest.

The first and last 200 metres are removed on your iPhone, before anything is sent. Peaf never receives the point a run started from, rather than receiving it and promising not to look — and because it never had those points, it cannot be made to produce them later. The map you see is shorter than the run you did, on purpose. You can change that distance, or turn the trimming off, and both are your decision to make.

What is kept is a simplified line: the shape of the route, at about a metre of precision, with the points that do not change its shape dropped. Peaf does not ask for or receive your live location — these coordinates come from a workout Apple Health already recorded, which is why the app requests no location permission at all.

A route is yours, so it is yours to send. If you share a workout with someone, its map goes with it. An automatic sharing rule is different: a rule keeps working long after you set it up, so it carries a route only if you told that rule to include one.

If a workout in Apple Health was written by an app Peaf already syncs with directly, such as WHOOP, it is the same session arriving twice. Peaf keeps only the fact that it saw the copy — which app wrote it, when, and whether the figures agreed with the ones it already had — and never a second set of figures. That is what stops one run appearing twice in your day.

With your permission iOS may wake Peaf in the background when new health data is available, at most once an hour, so a workout reaches your journal without you opening the app.

You can change what Peaf may read, or revoke all of it, in iOS Settings → Health → Data Access & Devices. Because Apple deliberately hides read denials from apps, Peaf cannot tell what you refused — it only knows what arrives, which is why the app reports whether data is being sent rather than claiming to be “connected”. Data already sent stays in your journal until you delete it, like anything else you have logged.

Apple’s HealthKit rules bind us, and we treat them as commitments: we read only the data types you approve, use them solely to provide the feature you enabled, never use them for advertising, marketing or any similar purpose, never sell them or share them with data brokers, and never disclose them to a third party without your explicit consent.

Permissions the app asks for

iOS asks your permission before Peaf can use any of these. You can say no to any of them and change your mind later in iOS Settings; declining one only disables the feature that needs it.

PermissionWhat Peaf does with it
PhotosAttach photos and videos to your moments, and save media back to your library when you ask.
CameraTake a photo or video from inside the app.
HealthRead the workouts and sleep already on your iPhone, so they appear in your day. Read-only — Peaf writes nothing back. Only asked when you turn Apple Health on from the Body page. Route maps are a separate permission, asked separately, and trimmed on the phone before anything is sent.
MicrophoneRecord voice notes and video sound.
Speech recognitionTurn what you say into text. Transcription is Apple’s: on your device where the device supports it, and otherwise by sending the audio to Apple’s speech service. The permission prompt says so before you decide.
LocationTag a moment with where it happened, and suggest nearby places. Location is used when you are using the app, and is only stored on moments you attach it to.
ContactsFind which of your contacts are on Peaf, using the scrambled-number matching described above.
CalendarAdd an event to your calendar when you ask the app to.
Local networkFind a nearby friend to connect with directly when you are in the same room.
Face IDUnlock the app and re-authenticate you locally. Your biometric data stays on your device and is never available to us.
NotificationsDeliver the alerts you have turned on.

Who else sees your data

People you choose. The only people who see your content are the people you share a moment with, the members of a group you post to, and anyone you send a share link to. Everything starts private, and tagging someone privately never notifies them or reveals the moment to them.

Service providers. We use a small number of companies to run the service. They process data on our instructions only, and may not use it for their own purposes:

ProviderWhat they handle
Heroku (Salesforce)Hosting for the Peaf backend.
Cockroach LabsThe database holding your account and moments.
Amazon Web ServicesStorage of your photos and videos, in S3, in the United States. Video is also streamed to your device straight from S3, because video playback needs a kind of request our delivery layer does not yet forward.
CloudflareDelivery of your photos at media.peaf.app, and the signature check that refuses any request the file was not issued for. Cloudflare also keeps request metadata — the address requested, the IP address it came from, the browser identifier — in its Workers logs, which we use to debug delivery problems and investigate abuse. We had not previously disclosed that, so we are disclosing it now.
VercelHosting for the peaf.app website, including the pages your share links open. Like any web host, it sees the IP address and request details of anyone who visits.
RedisShort-lived caching for performance.
PusherReal-time updates so shared moments appear instantly.
MailjetSending service emails such as address verification and account-deletion confirmation codes.
Apple and Firebase Cloud MessagingDelivering push notifications. A notification has to carry its own words to be readable on a lock screen, so when someone comments on your moment, the comment's text and the moment's title pass through Google's servers on the way to your phone. Nothing else does: photos and videos never travel this way, and the links to them are stripped out before sending. We had not previously said so, so we are saying it now.
Firebase CrashlyticsCrash reports.
Firebase AnalyticsMeasuring how much the app is used — opens, session length, device and app version — and only if you turned it on. Never the contents of your account.
AnthropicMeal photo calorie estimation — only if you turned that feature on.
WHOOPRetrieving your health data — only if you connected an account.
The Movie Database (TMDB)Film and TV search results and cover art. They receive what you typed into the search box, nothing about you.
Open LibraryBook search results and covers. They receive your search terms only.
IGDB (Twitch / Amazon)Video game search results and cover art. They receive your search terms only.
KlipyGIF search. They receive what you typed to find a GIF, nothing about you.

About the catalog services in that list. When you look up a film, show, book, game or GIF to log, the words you typed go to that service so it can send back titles and cover art. Your account identity, your library and what you finally chose to save are not sent, and the lookup is not linked to you.

Legal reasons. We may disclose information if we are legally required to, or where we believe it is necessary to protect someone’s safety or to defend our rights. We will tell you about such a request unless we are legally prohibited from doing so.

If Peaf changes hands. If the app is ever transferred to another owner, your data may transfer with it. We will tell you before that happens, and this policy will continue to apply until you are given notice of a new one.

Where your data lives

Most of your data lives on your phone — Peaf stores your moments locally so the app works offline — and is synced to our servers in the United States so it survives a lost phone and reaches the people you share with.

Your photos and videos are stored in Amazon S3 in the United States. Photos are delivered through Cloudflare, whose network has machines all over the world, so a file you open may be handed to you by a machine near you and that request logged there. The website is hosted by Vercel, which works the same way. Neither of them holds your library — the files live in the United States. What happens elsewhere is the last hop of the delivery, plus the request metadata described in the provider table above.

If you use Peaf from outside the United States, your information is transferred to and processed in the US. For transfers from the European Economic Area, the United Kingdom or Switzerland, we rely on the safeguards our providers offer for that transfer — either the European Commission’s Standard Contractual Clauses or certification under the EU–US Data Privacy Framework. You can ask us which mechanism applies to a particular provider.

How we protect it

  • All traffic between the app and our servers is encrypted in transit with TLS.
  • Passwords are stored only as slow, salted scrypt hashes — we cannot read them, and neither could anyone who obtained the database.
  • Third-party access tokens, such as your WHOOP connection, are encrypted before being stored.
  • Sessions use short-lived access tokens with rotating, revocable refresh tokens, so signing out or losing a device can be handled cleanly. You can add two-factor authentication or a passkey, and lock the app behind Face ID.
  • Our servers enforce who can see each moment; the app does not rely on hiding things locally.

No service can promise perfect security. If a breach ever affects your personal information, we will notify you and the relevant authorities as the law requires.

How long we keep it

Every table in our database now has to declare how long it keeps things and why — it is a list in the code, checked automatically, and a scheduled job actually enforces it. That was as much for our benefit as yours: it is the only way to answer this question honestly.

  • Your content and account — kept until you delete them. When you delete something in the app it disappears immediately and is erased for good 30 days later, which is the window in which we can still get it back for you if you ask.
  • Backups — deleted content is removed from our live systems straight away. Copies can survive briefly in our providers’ automatic database backups, which roll over on their own cycle; within 90 days at the outside, nothing remains there either.
  • Share links — until they expire or you revoke them, and permanently deleted 90 days after that, taking the record of who opened them with them. Revoking a link starts that clock early rather than waiting for the original expiry date.
  • Assistant improvement data — 90 days, and you can delete it sooner from Settings whenever you like.
  • Feedback and bug reports — deleted a year after you send them. If you delete your account first, the report text stays so we can still fix the bug, but everything identifying you goes immediately: your account reference, the contact email you gave, the diagnostics, and any screenshots you attached, which are deleted from storage. One caveat we would rather admit than hide: reports that carry a screenshot are currently held past the one-year mark, because the automatic purge cannot yet delete their images at the same time. Finishing that is on the list.
  • Waitlist entries — if an address on the waitlist never becomes an account, it is deleted after a year.
  • Sessions — expired sign-in sessions and refresh tokens are purged automatically as soon as they lapse.
  • Data exports — the ZIP you asked for is deleted from storage after seven days; the record that you made the request lasts a month.
  • Crash reports — retained by Crashlytics for up to 90 days.
  • App usage measurement — two months, both the events and the random per-install code they are grouped under. Nothing on our side joins to that code, so there was no reason to keep it longer. Our own server logs follow the log store’s retention, and carry only the one-way pseudonym.
  • Notifications — 30 days.
  • Security and abuse records — kept only as long as needed for that purpose.
  • Records we must keep by law — kept for the period the law requires, and nothing longer.

Deactivating or deleting your account

There are two ways to stop, and they are deliberately different things. Deactivating is a pause you can undo. Deleting destroys everything, permanently, on purpose. We would rather you had the reversible option than discovered too late that you only had the other one.

Deactivating — the reversible break

Deactivating signs you out on every device and makes you invisible: you stop appearing in search and in phone-number discovery, you cannot be sent connection requests, and notifications, emails, scheduled jobs and connected integrations all stop. Nothing is deleted. Your moments, photos and connections sit exactly where you left them.

There is no time limit and no countdown. A deactivated account is not on its way to being deleted, and we will not delete it for you because it has been quiet. Sign back in and everything comes back on.

One honest limit: deactivating hides you, not things you already shared. A photo you put in a friend’s moment last year stays visible to the people who could already see it. If you want that gone, delete the content, or delete the account.

Deleting — and what actually happens

Deletion lives in the app’s Settings, under Privacy. Because it cannot be undone once it runs, we email a confirmation code to the address on your account and ask you to type it in — so an unlocked phone in the wrong hands is not enough to erase your life.

The moment you confirm, the account is frozen: signed out everywhere, every session and refresh token revoked, push devices removed, and you disappear from search, discovery, connection requests and notifications. Then a seven-day grace period starts. During those seven days nothing has been destroyed and signing back in restores everything — the same account, the same content, the same connections. We built the grace period for the version of you who does this at 2 a.m. (During the grace period your existing shared content is still visible to the people it was always visible to; the freeze hides you, and the erasure is what removes the content.)

If you have already decided, you can skip the wait: immediate deletion is offered as an explicit, clearly-labelled choice behind the same email code and typed confirmation. Choose it and the erasure begins the moment you confirm — there is nothing to restore and no way back, not for us either. And if your account is deactivated, you can delete it without switching it back on: signing in offers deletion alongside restoring.

After seven days an automated pipeline takes over and does the real thing. It runs in checkpointed stages so it can survive a restart and pick up where it left off: it first revokes the connections you gave us — your WHOOP authorisation, your Google sign-in token — then removes your contributions from shared content, deletes the content you own, deletes the pseudonymous records tied to you, and finally deletes the account row itself.

Media deletion is verified, not hopeful. Deleting files from storage is the step most services fire and forget. We queue every prefix, delete it, then go back and look — re-listing storage to confirm nothing survived. If anything is still there, the job retries with backoff and the deletion is not marked finished. Your deletion is only complete when storage has confirmed it is empty.

What we keep afterwards is a receipt, not a copy. We retain one record per deletion: how many rows of each kind were removed and when each stage finished. It is the evidence that the erasure happened and is the only way we could ever prove it to you or to a regulator. The account identifier is scrubbed — set to nothing when the deletion completes — so what remains is a dated tally that points at nobody.

When you leave, your data leaves with you

Plenty of apps tell you that things you sent to other people are gone from your account but stay on theirs. We decided that was the wrong answer for something as personal as this. Deleting your account removes your photos, your comments and your other contributions from shared moments — for everyone, not just from your own view. Your name is spliced out of participant lists rather than left as a “deleted user” ghost. One deliberate exception: if somebody replied to a comment of yours, your comment becomes an empty “comment deleted” stub — nothing of yours survives in it, but their reply keeps its place instead of being destroyed by your departure. Their words are theirs. It is a feature, and it is the behaviour we would want.

The one nuance worth stating plainly, because it cuts both ways: a moment you own is yours, so deleting your account deletes it in full — including for the people who were in it, and including their comments on it. And a moment somebody else made is theirs: it stays with them after you go, minus whatever you put into it. The same logic applies to a shared goal you created — it goes, and so do the entries it generated. If content in a moment of yours matters to someone else, tell them to save it before you go.

One physics note, stated honestly: removal reaches other people’s phones when those phones next talk to us — usually within moments if they are online, at next launch if not. An app that is never opened again keeps whatever it had already downloaded; that is true of every app that works offline, and no honest policy can promise otherwise.

Other people’s address books are theirs too. If a friend saved you as a contact, their contact card stays — it simply stops being linked to a Peaf account.

Groups you were in

Deleting your account removes you from every group, including your admin role in the ones you ran. A group with other members keeps existing without you; we do not delete other people’s shared space because you left. A group left with no members at all is deleted.

The honest consequence: a group you administered can end up with no admin, because nothing promotes someone automatically. If you cared about that group, hand it over first — ownership transfer is offered in the deletion flow and is always available in the group’s settings. A group without an admin is not stuck forever: any remaining member can claim the role with one explicit tap, and the other members are told who took over.

Address-book people you added to groups follow their cards: someone you added who was never on Peaf disappears from those groups with your account, while a person your card pointed at who is on Peaf keeps their own seat. A group left with nobody who can actually open Peaf is removed entirely.

Your rights and choices

Wherever you live, you can:

  • See your data — most of it is visible directly in the app, and we will provide a copy of the rest on request;
  • Correct it — edit your profile and your content in the app at any time;
  • Delete it — delete individual moments in the app, wipe assistant data from Settings, or delete your whole account from inside the app. You can also ask us to do it for you;
  • Export it — take a full copy of your account with you, in one tap, described just below;
  • Pause deactivate your account without deleting anything, for as long as you want;
  • Withdraw consent — turn off health syncing, AI meal estimation, assistant improvement, phone discoverability, or notifications, at any time, without losing the rest of the app;
  • Complain — to us first, we hope, and to your data protection authority if we have not resolved it.

Taking a copy with you

Exporting is not a support ticket any more — it is a button. Settings → Privacy → Export my data builds you a single ZIP containing a JSON file per category of what we hold — your profile, moments, contributions to other people’s moments, comments, reactions, collections, contacts, saved places, groups, friends, goals, share links, notifications, devices, passkeys, health-sharing rules, WHOOP data, meal catalog, feedback you sent, assistant interactions — plus a readable index page so you can see what is in it without opening a single JSON file, and all your original photos and videos at full quality, with a manifest listing them.

It is built in the background, so you can close the app; we send you a notification when it is ready. The archive stays available for seven days and then is deleted from storage. You can build one export at a time, with a short cooldown between exports — that is only there because packaging an entire photo library is expensive, not to discourage you. Requesting an export is free, does nothing to your account, and you never have to explain why you want it.

To exercise any of these, email help@peaf.app from the address on your account, or contact us from within the app. We respond within 30 days (45 days in California, where we may extend once if we tell you why). We will never charge you for this, and we will never give you a worse service for asking.

US state privacy rights

If you live in California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, you have the rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to appeal a decision we make about such a request. The section above explains how to exercise them.

In the twelve months before this policy’s date, we collected the categories of personal information described in What we collect — identifiers, account information, your own content including photos and audio, approximate and precise location if you attach it, health information if you connect WHOOP or turn on Apple Health, and device and internet activity information — for the purposes listed in How we use it, from the sources described there.

We do not sell personal information and we do not share it for cross-context behavioral advertising, including that of anyone under 16. Because we do not sell or share, there is no opt-out to offer. We do not use sensitive personal information for purposes other than providing the features you asked for. We do not offer financial incentives in exchange for personal information.

You may use an authorized agent to make a request; we will ask for proof that you authorized them. If we deny a request, you can appeal by replying to our decision, and we will respond in writing.

If you are in the EEA or UK

We process your personal data on these legal bases: to perform our contract with you — running your account, syncing and sharing your content, and sending service emails; on your consent — health syncing, automatic health sharing, AI meal estimation, assistant improvement data, suggestions drawn from your photo library, contacts access, location, and push notifications; and on our legitimate interests — keeping the service secure, preventing abuse, and fixing crashes, weighed against your rights. Where we rely on consent you can withdraw it at any time, which does not affect processing already carried out.

You also have the right to object to processing based on legitimate interests, the right to restrict processing, and the right to data portability. You may lodge a complaint with your national data protection authority — in France, the CNIL; in the UK, the ICO.

Children

Peaf is not intended for children. You must be at least 13 years old to use it, and at least 16 if you are in the European Economic Area or the United Kingdom. We do not knowingly collect personal information from children below those ages. If you believe a child has created an account, email us and we will delete it and their data.

Changes to this policy

If we change this policy, we will update the date at the top of this page. For any change that materially affects how we handle your personal information, we will tell you in the app or by email before it takes effect, so you have a chance to review it — and where the law requires your consent, we will ask for it rather than assume it.

Contact us

Questions, requests, or something on this page that does not match what you see in the app — write to us at help@peaf.app. A person reads it.