Back to home
Legal

Privacy Policy

We collect only what we need to give you accurate coaching, store your data in the European Union, and never sell it or use it for advertising.

Last updated: 2 September 2026

1. Who we are

Peakfy (the “app”, the “service”, “Peakfy”) is an AI cycling-coaching app. Peakfy is operated by MIBEVA LTD, the data controller responsible for your personal data.

  • Company: MIBEVA LTD (company number 17404533)
  • Registered address: 124-128 City Road, London EC1V 2NX, England
  • Contact: support@peakfy.app

This Privacy Policy explains what personal data we collect, why, how we use and protect it, who we share it with, and the rights you have over it. We are committed to data minimisation: we collect only what we need to give you accurate coaching, we store your data in the European Union, and we never sell your data or use it for advertising.

2. Scope

This policy covers the Peakfy mobile app and the Peakfy website. It applies to everyone who creates a Peakfy account or connects a third-party service to Peakfy.

3. The data we collect

a) Account and profile data

  • Email address and authentication data (managed by our authentication provider; passwords are stored only as salted hashes — we never see your password).
  • Optional profile details you provide: name or display name, sex, date of birth or age, height, weight, training goal and event(s), experience level, preferred units and language, and manually entered performance values such as FTP.

b) Health and fitness data (special category — see legal basis in Section 5)

Depending on what you record or connect, this can include:

  • Activity data: power, heart rate, cadence, speed, distance, duration, elevation, calories, temperature, and GPS route / location data for your rides and other activities.
  • Recovery and wellness data: heart-rate variability (HRV), resting heart rate, sleep, VO2max, body weight, and your subjective effort ratings (RPE).
  • Values we compute from the above (for example training load, readiness/recovery, personal bests, estimated FTP and training zones). These are computed by our software from your real data.

c) Data from services you connect

If you choose to connect a third-party service, we access data through that service's official API, only after you authorise it, and only to the extent needed to provide Peakfy's features. The lists below describe every connection that exists today.

Services Peakfy reads data from

  • Apple Health (HealthKit) — sleep, HRV, resting heart rate, VO2max, weight, and your rides and other workouts including heart rate, power, cadence and running dynamics (read on your device with your permission). See the HealthKit statement in Section 8.
  • WHOOP — recovery data only: sleep (duration and sleep stages), heart-rate variability (RMSSD), resting heart rate, respiratory rate, blood oxygen (SpO2) and skin temperature. Peakfy does not read rides, workouts or power data from WHOOP. See the WHOOP statement in Section 8.
  • Polar (Polar AccessLink) — recovery data only: sleep, and Nightly Recharge (heart-rate variability, night-time heart rate, breathing rate). Peakfy does not read rides or workouts from Polar. See the Polar statement in Section 8.
  • Intervals.icu — heart-rate variability, resting heart rate, sleep duration, body weight, and your rides.
  • FIT file upload — the ride contained in a file you upload yourself.

Service Peakfy writes data to

  • Strava — if you connect Strava, Peakfy can write your completed training to it. This connection is write-only: Peakfy does not read your activities or any other data from Strava. See the Strava statement in Section 8.

Connections that are built but not yet available

Peakfy has built connections to Wahoo, COROS and Suunto. They are not available to you yet, because each still requires that provider's approval. Until it is granted, no data flows to or from these services. Section 8 sets out the commitments that apply from the moment one of them goes live.

Services Peakfy is not connected to

Peakfy has no connection to Garmin and receives no data from it. Beyond the services named above, Peakfy is not connected to any other platform.

You can disconnect any service at any time (Section 10).

d) Technical data

Minimal technical information needed to run and secure the service (for example app version and basic diagnostic/error information). On your own device, the app stores your signed-in session locally so that you stay logged in between visits; you end it by signing out or deleting the app. Peakfy does not use third-party advertising or cross-app tracking SDKs, and does not build advertising profiles.

e) The Peakfy website (getpeakfy.com)

Our marketing website is a purely informational site. It uses no cookies and no analytics, tracking or advertising tools, and its fonts are served locally from our own server (no connection to third-party font servers). The only thing the site stores in your browser is a small local entry recording that you have dismissed the “this page is also available in your language” notice; it contains no personal data and is never transmitted to us. When you visit, our hosting provider automatically processes standard server log data — including your IP address, the date and time, the page requested, and your browser type — to deliver and secure the site (legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a secure, reliable website).

4. How we use your data

We use your data only to provide and improve the coaching service you asked for:

  • to calculate your training metrics, zones, load, readiness and personal bests accurately;
  • to let the AI coach plan sessions, explain them, and analyse your activities;
  • to write planned workouts to your calendar and connected device/app at your request;
  • to operate, secure, debug and support the app;
  • to communicate with you about your account and service (e.g. verification and security emails).

5. Legal bases (UK GDPR and EU GDPR)

  • Health and fitness data is special-category data (Article 9). We process it only on the basis of your explicit consent, which you give when you enter or connect this data. You can withdraw consent at any time (Section 10), which stops future processing.
  • Contract (Article 6(1)(b)): account and profile data needed to provide the service you signed up for.
  • Legitimate interests (Article 6(1)(f)): keeping the service secure and working (balanced against your rights).
  • Legal obligation (Article 6(1)(c)): where the law requires us to retain certain records.

6. How the AI coach uses your data

Peakfy's coach is an AI chat. The numbers are always computed by our software, not by the AI — the AI explains and plans, it does not invent values. To generate its replies, relevant training context is sent to our AI processing provider (currently Anthropic). Before data is sent to the AI provider we remove direct identifiers such as your name and email address. The AI provider processes the request only to return a response and does not use your data to train its models for this purpose. We never send your data to an AI provider for advertising or profiling.

What the AI coach never receives. We do not use your data — from any source — to train general-purpose AI models. In addition, no data from Strava ever reaches the AI coach: Strava's API terms prohibit the use of Strava data in connection with any AI application, and Peakfy keeps to that. Peakfy's Strava connection is write-only in any case, so there is no Strava data on our side to pass on (Sections 3(c) and 8).

Automated processing (Art. 22 GDPR). Peakfy generates your training recommendations automatically, including with the help of AI. These are training guidance only — they do not produce legal effects concerning you or similarly significantly affect you, so they are not the kind of solely automated decision covered by Article 22 GDPR. The underlying numbers are computed by our software (the AI explains and plans, it does not make decisions about you), and you can always reach a person at support@peakfy.app with questions about how a recommendation was reached.

7. Who we share data with (processors / sub-processors)

We do not sell your data and we do not share it for anyone else's marketing. We use a small number of vetted providers (“processors”) strictly to run Peakfy, under data-processing agreements:

  • Supabase — database, authentication and storage, hosted in the European Union.
  • Anthropic — to generate the coach's replies (see Section 6).
  • Resend — to send account and security emails.
  • Netlify — hosting for the Peakfy marketing website (getpeakfy.com); processes standard server log data as described in Section 3(e).
  • A subscription/billing provider — when paid subscriptions are introduced.
  • The third-party platforms you connect (Apple Health, WHOOP, Polar, Intervals.icu, and Strava as a write-only destination) — data flows to or from them only to sync your training, at your request. These platforms are independent third parties, not our processors; the exact list, and what each one receives or provides, is in Section 3(c).

A current list of our sub-processors is published at Sub-processors, and is also available on request at support@peakfy.app. We may also disclose data if required by law, or to protect the rights, safety and security of our users and service.

8. Connected platforms — specific commitments

When you connect a third-party platform, our use of the information we receive complies with that platform's API terms, and:

  • we access it only with your authorisation and only to provide Peakfy's features;
  • we do not sell it, use it for advertising, or share it with third parties for their own purposes;
  • you can disconnect at any time; we then stop syncing and delete the data we pulled from that platform, except where we must keep records to meet a legal obligation.

Apple HealthKit statement. Data read through Apple Health / HealthKit is used solely to provide Peakfy's training and recovery features that you have enabled. In line with Apple's requirements, we never use HealthKit data for advertising or marketing, never sell it, and never disclose it to third parties for their own purposes or for data-mining. HealthKit data is used on your device and, where you enable syncing, stored in your account in the EU under your consent, and is deleted when you delete your account or disconnect Apple Health.

WHOOP statement. If you connect WHOOP, Peakfy reads only the recovery data listed in Section 3(c) — sleep duration and sleep stages, heart-rate variability (RMSSD), resting heart rate, respiratory rate, blood oxygen (SpO2) and skin temperature. We use it for one purpose only: to calculate your recovery and readiness and to let the coach explain them to you. Peakfy does not read rides, workouts or power data from WHOOP. Where WHOOP data is shown in Peakfy, it is identified as coming from WHOOP (“DATA BY WHOOP”), and WHOOP's own metrics keep their WHOOP names — we do not rename them. We never use WHOOP data for advertising, never sell or otherwise transfer it, and never use it to train general-purpose AI models. Data obtained from WHOOP is deleted on request, and automatically when you disconnect WHOOP or delete your Peakfy account.

Polar statement. Peakfy's Polar connection uses the Polar AccessLink API of the Polar Ecosystem and reads only sleep and Nightly Recharge data (heart-rate variability, night-time heart rate, breathing rate). Peakfy does not read rides or workouts from Polar. Wherever Peakfy displays a Polar measurement, the Polar Ecosystem is named as the source. Values that Peakfy computes from several sources at once — your recovery score, for example, which may combine heart-rate variability from one device, sleep from another and your own rating — carry no single provider's name, because naming one would misdescribe where the number came from. Peakfy collects this data and stores it in your Peakfy account in the European Union, as described in this policy. If you disconnect Polar, syncing stops and the data pulled from Polar is deleted.

Strava statement. Peakfy's Strava connection is write-only: Peakfy can write your completed training to Strava, and reads nothing from it. Strava's API terms prohibit the use of Strava data in connection with any AI application. Peakfy's coach is an AI application, so no Strava data is ever used with it — and because Peakfy reads no Strava data at all, there is none on our side that could be.

COROS statement (connection built, not yet available). When COROS approves the integration and you connect it, Peakfy will read only the data you authorise, and only to provide the features you have enabled. Wherever Peakfy displays COROS data, it will be shown with “Powered by COROS” together with the COROS device model the data came from (for example “COROS PACE 4”). Personal data obtained from COROS is deleted within 24 hours of you withdrawing your authorisation or asking us to delete it. MIBEVA LTD's written information security programme is published in full at Security.

Wahoo statement (connection built, not yet available). When Wahoo approves the integration and you connect it, Peakfy will read only the data you authorise, and only to provide the features you have enabled. Personal data obtained from Wahoo is deleted within 48 hours of a request to delete it.

Suunto statement (connection built, not yet available). When Suunto approves the integration and you connect it, Peakfy will read only the data you authorise through the Suunto Cloud API, and only to provide the features you have enabled, under the same commitments as above.

9. Where your data is stored and international transfers

Your account and health data are stored in the European Union. MIBEVA LTD is registered in the United Kingdom, which the European Commission recognises as providing an adequate level of data protection.

Access from outside the EU and the UK. Peakfy is run by a very small team that works remotely, and our staff may access data from countries outside the European Economic Area and the United Kingdom — including Türkiye — for the limited purposes of operating, securing and supporting the service. Some processors (for example our AI provider) may likewise process limited, identifier-stripped data outside the UK/EU. Where personal data is accessed or processed from a country without an EU adequacy decision, we rely on appropriate safeguards, in particular the Standard Contractual Clauses (and, for UK data, the UK International Data Transfer Agreement/Addendum), together with technical and organisational measures such as encryption in transit, access controls and least-privilege access.

You may request a copy of the relevant safeguards at support@peakfy.app.

10. Retention, disconnecting and deletion

  • We keep your data for as long as your account is active, plus any period the law requires.
  • Disconnecting a service stops future syncing and deletes the data we pulled from that service (subject to legal retention).
  • Deleting your account permanently deletes your personal and health data from our systems — it is genuinely erased, not merely flagged as deleted. You can delete your account in the app or by contacting support@peakfy.app. Step-by-step instructions are on our account deletion page.

11. Your rights

Under the UK GDPR and the EU GDPR you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and withdraw your consent at any time. You also have the right to lodge a complaint with a data protection supervisory authority — in the UK, the Information Commissioner's Office (ICO, ico.org.uk); in the EU, your local authority. To exercise any right, contact support@peakfy.app; we respond within the legal time limits.

12. Security

We use industry-standard measures to protect your data, including encryption in transit, access controls, and EU-based managed infrastructure. Health data is never written to logs or error reports. Our written information security programme is published in full at Security. No system is perfectly secure, but we work continuously to protect your information.

13. Children

Peakfy is not intended for children. You must be at least 16 years old (or the minimum age of digital consent in your country) to use Peakfy. We do not knowingly collect data from children below that age.

14. Not a medical device

Peakfy provides training and recovery guidance for healthy athletes. It is not a medical device and does not provide medical advice, diagnosis or treatment. Always consult a qualified professional for medical questions or before starting a new training programme.

15. Changes to this policy

We may update this policy from time to time. We will post the new version here with an updated “Last updated” date and, for material changes, notify you in the app or by email.

16. Contact

Questions or requests about your data:
MIBEVA LTD, 124-128 City Road, London EC1V 2NX, England.
Enquiries are handled by email: support@peakfy.app.


← Back to home  ·  Support  ·  Legal Notice  ·  Terms of Service  ·  Security  ·  Sub-processors  ·  Delete your account