Privacy Policy
PeachClimb ("we", "us") is a fitness app for glute training. This policy explains what data the app handles and the choices you have. The short version: our server doesn't keep your scan photos, we don't sell data, and we don't display third-party ads in the app. We use advertising attribution to understand whether our ads lead to installs and subscriptions.
Data we collect
- Account. The app creates an anonymous account so your progress can sync. If you choose "Continue with Apple", we receive the name and email you approve through Sign in with Apple.
- Your answers. The first name you enter and your onboarding choices (goals, focus zones, equipment, schedule), used to build and personalize your workout plan.
- Body scan photos. If you choose the optional AI booty scan, your photo is sent over an encrypted connection to our server, which passes it to our AI provider (Anthropic's Claude) solely to produce your zone scores. The photo is processed in memory for that single analysis and immediately discarded by our server. Anthropic does not use commercial API inputs to train its models by default, but under its standard API policy it may retain inputs and outputs for up to 30 days (and longer where required for safety or legal reasons). Only the numeric scores are kept by PeachClimb. A baseline copy may be kept on your device only for your progress view. The scan is optional — you can answer questions instead.
- Progress data. Completed workouts, streaks, measurements you enter, and scan scores.
- Purchases. Subscriptions are processed by Apple. We receive purchase status (not your payment details) via Apple and our billing partner RevenueCat to unlock your subscription.
- Usage events. Basic product-interaction events (e.g. an onboarding step or offer was shown) may be tied to your account id and processed by PostHog to help us understand and improve the app. PeachClimb does not record screen or session-replay video. You can turn this off any time under Profile → Analytics & ad attribution.
- Advertising attribution. Device identifiers and app events may be processed by AppsFlyer and advertising partners Meta and TikTok to measure which campaigns lead to installs and subscriptions. Apple's advertising identifier (IDFA) is only used if you allow it through Apple's App Tracking Transparency prompt, which we request after you tap Start during setup; if it is unavailable or denied, we rely on IDFA-less, privacy-preserving, or aggregated attribution. Purchase amount and currency may be shared for campaign measurement, but never your payment details. You can turn attribution off any time under Profile → Analytics & ad attribution.
What we don't do
- No third-party ads displayed in the app, and no selling or renting of your data.
- No access to Apple's advertising identifier or cross-app tracking unless you grant permission through Apple's App Tracking Transparency prompt.
- No use of scan photos, progress photos, or fitness answers for ad targeting.
- No storage of scan photos or form-check video on our servers.
Progress photos
Progress photos you take in the app stay on your device. They are not uploaded.
Notifications
Workout reminders and occasional offer notifications are only sent if you allow notifications in iOS, and you can turn them off any time in Settings.
Where data lives & security
Account and progress data are stored with our backend providers (Supabase and Railway) and protected in transit with HTTPS/TLS. Access is restricted by row-level security so your data is only readable by your account. Subscription and analytics data may also be processed by RevenueCat, PostHog, AppsFlyer, Meta, and TikTok for the purposes described above. We require providers that receive user data to protect it consistently with this policy and applicable privacy requirements.
Retention & deleting your data
Your PeachClimb account and synced data are kept while your account exists. You can permanently delete them any time in the app: Profile → Delete account. This removes your profile, plan answers, scan scores, workout history, measurements, streaks, progress, and events from PeachClimb-controlled servers. It also erases that account's device-only scan baseline and progress-photo files on the iPhone where you delete the account. Because those photo files never sync, PeachClimb cannot remotely erase copies left in another app installation or device.
Account deletion stops future account-linked analytics and attribution from that installation, but it does not cancel an Apple subscription or automatically erase records independently held by Apple, RevenueCat, PostHog, AppsFlyer, Meta, or TikTok. Those providers may retain transaction, fraud-prevention, security, legal-compliance, or previously collected analytics/attribution records under their own retention rules. Cancel subscriptions in App Store settings. To request deletion of provider-linked records where applicable, contact cuilabsltd@gmail.com.
You can turn Analytics & ad attribution off any time under Profile → Analytics & ad attribution. Apple's tracking permission can be changed separately in iOS Settings.
Children
PeachClimb is not directed at children under 13, and we do not knowingly collect data from them.
Changes
If we change this policy, we'll update this page and the effective date above.
Contact
Questions or requests: cuilabsltd@gmail.com