Back to home
Legal

Security

Our written information security policy, published in plain language — where your data lives, who can reach it, and what we do when something goes wrong.

Last updated: 2 September 2026

1. What this page is

This page is MIBEVA LTD's written information security programme for the Peakfy app, the Peakfy website and the systems that hold your data. We publish it rather than file it away, so that what we commit to can be read and held against us.

  • Version 1.0, in force from 2 September 2026.
  • Last reviewed: 2 September 2026.
  • Review cycle: at least once a year, and whenever we make a significant change to how Peakfy is built or hosted.
  • Accountable: the Director of MIBEVA LTD.

Peakfy is built by a very small team. We would rather tell you plainly what we do than imply a certification we do not hold: Peakfy is not ISO 27001 or SOC 2 certified.

2. Where your data lives

  • Your account and health data are stored in the European Union, on managed infrastructure provided by Supabase (region eu-central-1).
  • The data controller is MIBEVA LTD, 124-128 City Road, London EC1V 2NX, England.
  • The full list of providers that process data on our behalf is published at Sub-processors.
  • Where our team or a provider accesses data from outside the EU or the UK, we rely on the safeguards set out in the Privacy Policy, Section 9.

3. Encryption and hosting

  • All traffic between the app, the website and our systems is encrypted in transit (HTTPS/TLS). The website is served over HTTPS only, with HSTS.
  • Your data is held in managed PostgreSQL 17 in the European Union (eu-central-1, Frankfurt). Every connection to it is TLS-encrypted.
  • Passwords are never seen or stored by us in readable form. Authentication is handled by our authentication provider and passwords are held only as salted hashes.
  • The website sets no cookies and loads no third-party resources; it is served with a strict Content-Security-Policy and the usual hardening headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy).

4. Access control

  • Access to production systems and to user data is limited to the people who need it to run the service, on a least-privilege basis.
  • Access is removed when it is no longer needed.
  • Health data is never written to logs or error reports, so it does not reach diagnostic tooling.

5. How the AI coach is contained

  • Every number Peakfy shows you — training load, recovery, readiness, personal bests — is computed by our own software. The AI explains those finished numbers; it does not calculate them.
  • Direct identifiers such as your name and email address are removed before anything is sent to our AI provider.
  • We do not use your data to train general-purpose AI models, and we do not send your data to an AI provider for advertising or profiling.
  • Data from Strava is never used in connection with the AI coach; Peakfy's Strava connection is write-only and reads nothing (see the Privacy Policy, Section 8).

6. Connected platforms

  • We connect to a third-party platform only through its official API, only after you authorise it, and only for the data we actually need. The exact list is in the Privacy Policy, Section 3(c).
  • Disconnecting a platform stops the sync and deletes the data we pulled from it.
  • Where a partner sets a deletion deadline, we meet it: data obtained from COROS is deleted within 24 hours of withdrawal or request; data obtained from Wahoo within 48 hours of a request. Data obtained from WHOOP is deleted on request.
  • We never sell data received from a connected platform, never use it for advertising, and never pass it to a third party for that third party's own purposes.

7. Deletion

When you delete your Peakfy account, your personal and health data are genuinely erased from our systems — not merely flagged as deleted. The steps are on the account deletion page.

8. If something goes wrong

  • If a personal-data breach occurs, we assess it, act to contain it, and notify the competent supervisory authority within 72 hours where the law requires it, and affected users without undue delay where the breach is likely to pose a high risk to them.
  • We keep a record of such incidents and of what we changed afterwards.

9. Reporting a vulnerability

If you believe you have found a security vulnerability or a privacy problem, write to support@peakfy.app with the subject line “Security”. Tell us what you found and how to reproduce it, and please give us a reasonable chance to fix it before you make it public. We will confirm receipt and keep you posted. We do not take legal action against people who report a problem to us in good faith and do not access, change or delete other people's data.

10. Contact

MIBEVA LTD, 124-128 City Road, London EC1V 2NX, England.
Security and privacy enquiries: support@peakfy.app.


← Back to home  ·  Privacy Policy  ·  Sub-processors  ·  Delete your account  ·  Terms of Service  ·  Legal Notice