Privacy Policy
Effective date: October 6, 2026 · Last updated: October 6, 2026
Thank you for choosing PeakState (“PeakState,” “the App,” “we,” “us,” or “our”). We understand how important your personal information is to you, and your trust matters deeply to us. We comply with applicable laws and regulations and implement appropriate security measures to keep your personal information safe and under your control.
Important Notice: The energy management suggestions provided by PeakState are for informational purposes only and do not constitute medical advice. If you have any health concerns, please consult a qualified healthcare professional. PeakState accepts no liability for any health issues arising from your use of the App.
1. Information We Collect and How We Use It
1.1 Account Information
You can create a PeakState account with an email address and password, with Sign in with Apple, or with Google. Depending on how you sign up, we collect:
- Email address: used for sign-in, account recovery, and important service notices. If you use Sign in with Apple and choose Hide My Email, we receive a private relay address from Apple instead of your personal email address
- Name or nickname (optional): used to address you in a personalized way. With Sign in with Apple, Apple shares the name you choose only the first time you sign in; with Google, we receive the name on your Google Account. You can change it in the App at any time
- Apple or Google account identifier: a unique identifier that Apple or Google issues for your account, used to recognize you when you sign in again. We never receive your Apple or Google password
- Sign in with Apple token: if you use Sign in with Apple, we store a token issued by Apple so that we can revoke PeakState’s access to your Apple Account when you delete your PeakState account
- Avatar (optional): used for account identification
When you sign in with Google, we request only your basic profile and email address. We do not access your contacts, Gmail, Google Drive, or any other data in your Google Account. If the verified email address from Apple or Google matches a PeakState account you previously created with Apple or Google, we sign you in to that same account.
1.2 Health Data (via HealthKit)
To provide personalized energy management insights, the App reads the HealthKit data you authorize. The health data you authorize is uploaded to our servers in Singapore and associated with your account. We use it to generate your energy analysis, morning and evening briefings, proactive care messages, and anomaly alerts.
We read the following categories of health data:
- Sleep data: total sleep duration, deep sleep duration, REM sleep duration, bedtime, and wake-up time, used to assess sleep quality and recovery status
- Heart rate data: resting heart rate and exercise heart rate, used to assess physical load and stress levels
- Heart rate variability (HRV): used to assess autonomic nervous system function and recovery status
- Step count: used to assess daily activity levels
- Workout records: workout type, duration, and calories burned, used to assess physical exertion
- Respiratory rate: used to assess stress and relaxation states
- Body temperature: used to assess recovery and physical strain
- Stand time: used to assess sedentary behavior and daily activity
- Mindfulness minutes: used to assess mental wellness activities
- Active energy and exercise minutes: used to assess daily activity and physical exertion
- Blood oxygen: used to assess recovery status
- Environmental sound levels: used to assess how your environment affects your energy
- Blood glucose, insulin delivery, and dietary carbohydrates: read only if you authorize them, used for metabolic energy insights
- Menstrual cycle data (menstrual flow, cervical mucus quality, ovulation test results, intermenstrual bleeding): requested only if you enable the cycle card; this data is used and stored only on your device and is not uploaded
Data Storage Note: The App reads health data through Apple’s HealthKit framework and uploads the data you authorize to our servers over an encrypted (HTTPS/TLS) connection. Heart rate, respiratory rate, body temperature, and stand time samples are uploaded approximately every 10 minutes; sleep data (duration, bedtime and wake-up time, deep and REM sleep, HRV) and activity data are also synced. Health data is never sold or used for advertising. If you agree to AI Data Sharing, summaries of this data are sent to our AI providers (Anthropic or DeepSeek) as described in Section 4.3. You can revoke the App’s access at any time in Settings > Health > Data Access & Devices; this stops further uploads, and data already uploaded is kept until you delete your account.
1.3 Calendar Data
To analyze your workload density and identify recovery windows, the App reads your calendar data:
- Meeting times and durations: used to assess workload and identify open time blocks
- Number of meetings: used to analyze schedule density
Privacy Protection: We do not collect or upload sensitive content such as meeting titles, attendees, locations, or notes. We upload only time-slot information for your events (date, start and end time, duration, and event type) and daily workload statistics (such as meeting count, total meeting time, and free time blocks) to our servers, where they are used for workload analysis, pre-meeting reminders, and proactive care.
1.4 Screen Time Data
To help you manage your digital wellbeing, the App accesses your Screen Time data:
- Per-app usage time: usage duration statistics for individual apps
- Device pickups: used to assess attention fragmentation
- Total screen time: your daily total screen usage
Data Storage Note: Detailed Screen Time data stays on your device. We upload only aggregated statistics (such as total screen time, time by category, and pickup counts) to our servers; we never upload lists of specific app names.
1.5 Location Information
To provide weather data and analyze how weather affects your energy, the App requests access to your location:
- Approximate location: used to retrieve current weather, temperature, air quality, pollen, and other environmental data
Privacy Protection: We use only your approximate location (at roughly kilometer-level precision); we do not track or store your precise location (such as a street address). To retrieve environmental data, the App sends these approximate coordinates to Apple WeatherKit and Open-Meteo (see Section 4.2). You may grant the “While Using the App” location permission, and we never track your location continuously in the background.
1.6 Voice Data
When you use the voice input feature:
- Voice recordings: used solely for speech-to-text conversion; PeakState never stores raw audio or sends it to our servers
- Transcribed text: used for the AI conversation feature
Speech recognition is performed by Apple’s speech recognition service, which may process audio on your device or on Apple’s servers under Apple’s privacy policy. PeakState does not receive or store your audio.
1.7 Camera and Photo Library
When you use the nutrition tracking feature:
- Meal photos: photos you choose to take or select are used by AI to identify foods and estimate nutritional content. This feature is available only if you have agreed to AI Data Sharing (see Section 4.3).
Privacy Protection: Photos are sent over an encrypted connection to our servers and relayed in real time to one of our AI providers (Anthropic or DeepSeek) for recognition. Our servers do not store your meal photos. The recognized foods and nutrition estimates are saved in your meal log. Each AI provider’s handling of the photos it receives is governed by its own terms, as described in Section 4.3.
1.8 AI Conversation Data
When you chat with the AI assistant, we collect and process:
- Conversation content: used to generate personalized recommendations and maintain conversational context
- Conversation history: stored on our cloud servers to support multi-device sync
- Conversation summaries and long-term memory: generated from your conversations, together with the name you’d like the assistant to call you, and stored on our servers so the assistant can remember context over time
- Mood signals: mood signals identified from conversation summaries, which are stored on our servers and appear in your mood history
AI features that process this data are available only if you have agreed to AI Data Sharing (see Section 4.3).
1.9 Records You Create in the App
When you use the App’s tracking features, we store the following on our servers:
- Energy and mood check-ins: used for your energy analysis, briefings, and trends
- Meal logs: the foods and nutrition estimates you save
- 7-day energy experiments: your experiment plans, daily check-ins, and reports
- Caffeine and alcohol records: the caffeine and alcohol intake you log in Coffee & Drinks
- Values and goals: your values assessment results, how you describe the values that matter to you, and your goals, sub-tasks, progress, and goal reviews
- Journal and reflection entries: what you write in tools such as the Gratitude Journal, Morning Ritual, and Evening Review
- People in your life: if you use features that let you record people in your life, the names, relationships, and notes you enter. Please record only information you have the right to share
1.10 Setup Questions and Your Energy Profile
When you first set up the App, it asks a few short questions: what affects your energy most, when in the day you usually feel low, your usual bedtime and wake-up time, and what you would most like to improve.
- Your answers are stored on your device and sent to our servers together with your messages to the AI assistant, where they are saved alongside your conversation records and used to personalize replies. Because the AI assistant is available only if you agree to AI Data Sharing, your answers reach our AI providers only in that case (see Section 4.3). Your answers are removed from your device when you sign out, and from our servers when you delete your account
- Your energy profile (the profile type and findings shown at the end of setup) is calculated on your device from your answers and, if you connect Apple Health, from your sleep, resting heart rate, HRV, and step data for the past 30 days. The resulting profile type, and your energy assessment results if you take the assessment, are synced to our servers and used to personalize replies. If you agree to AI Data Sharing, your energy profile is also sent to our AI providers with your AI requests (see Section 4.3)
1.11 “About You” and “Goals” Details
The App offers optional “About You” and “Goals” pages that help the AI assistant get to know you. We collect these details only if you choose to fill them in, and every item is optional:
- About you: occupation, gender, year of birth (age), height, weight, activity level, and health conditions you describe (for example, blood pressure, blood sugar, or heart issues), together with any notes you add
- Goals: the goals you want to achieve
Health conditions, height, and weight are health information. These details are stored on our servers and used to personalize the AI assistant’s advice. If you agree to AI Data Sharing, they are also sent to our AI providers with your AI requests (see Section 4.3).
2. Website Waitlist
If you join the waitlist on our website (https://mypeakstate.ai), we collect:
- Email address: used to send you one email when PeakState launches on the App Store (the “launch email”). The launch email includes an optional link to keep receiving occasional product updates; we send product updates only if you choose to receive them
- Site language preference (locale): used to send the launch email in your preferred language
We apply the following limitations to waitlist data:
- Single opt-in: joining the waitlist does not require email confirmation, and we do not email you before the launch email
- No IP addresses are stored in our waitlist records
- Waitlist data is stored on our servers located in Singapore
- Resend sends the launch email, and product updates if you opt in, on our behalf; we share only your email address and the message content with Resend for this purpose (see Section 4.2)
- If you do not opt in to product updates, we delete your waitlist data 30 days after we send you the launch email. If you opt in, we keep your email address until you unsubscribe or ask us to delete it
- Every email we send includes an unsubscribe link. You may also request deletion of your waitlist data at any time by emailing kobwhatsup@gmail.com
3. How We Store Your Personal Information
3.1 Where Your Data Is Stored
- Cloud servers (Singapore): account information (including Apple or Google sign-in identifiers); your setup answers, energy profile type, and energy assessment results; the optional “About You” details and goals you enter; the health data you authorize; energy and mood records, caffeine and alcohol records, and mood signals; your values and goals; journal and reflection entries; the people you record; calendar time slots and workload statistics; aggregated Screen Time statistics; meal logs; and AI conversation records, summaries, and long-term memories are stored on our Alibaba Cloud servers located in Singapore
- On your device: data in Apple Health, your full calendar, and detailed Screen Time data remain on your iPhone. Genetic profile information you choose to enter, menstrual cycle data (whether read from Apple Health or entered manually), and the body information you enter for the Nutrition Assistant are processed and stored only on your device and are not uploaded to our servers. The App uploads only the data described in Section 1
- Anthropic (United States): if you agree to AI Data Sharing, the data described in Section 4.3 may be transferred to Anthropic for processing; see Section 4.3.1 for how Anthropic retains it
- DeepSeek (China): if you agree to AI Data Sharing, the data described in Section 4.3 may be transferred to DeepSeek and processed and stored in China; see Section 4.3.2 for how DeepSeek retains it
3.2 How Long We Retain Your Data
- Account data (including Apple or Google sign-in identifiers and the Sign in with Apple token): retained until you delete your account
- Conversation records, summaries, and long-term memories: retained until you delete the relevant conversation or delete your account; they are not automatically deleted after a fixed period. Deleting a conversation also deletes the summaries and memories derived from it; deleting a single message removes that message but may not remove summaries or memories already derived from it. Our automatic memory maintenance may also merge or remove individual memories earlier
- Health, energy, mood, calendar, Screen Time, and meal data, setup answers, and the other records and details described in Sections 1.9 to 1.11 on our servers: retained until you delete your account
- Website waitlist data: deleted 30 days after we send you the launch email, unless you opt in to product updates (see Section 2)
- Meal photos: not stored on our servers
- When you delete your account: all of your personal data is deleted from our systems; residual copies in our database backups are deleted as the backups rotate, within 8 days
- Crash and error reports (which may include a screenshot, see Section 4.2): kept by Sentry for its retention period and not deleted immediately when you delete your account
- Data in Apple Health on your device: managed by your iPhone and not affected by deleting your PeakState account
3.3 Security Measures
We protect your data with the following measures:
- Encryption in transit: all data transmissions are encrypted with HTTPS/TLS
- Access controls: strict server access permission management
- Regular backups: databases are backed up automatically every day to prevent data loss
3.4 International Data Transfers
PeakState is operated from mainland China, and our servers are located in Singapore. Our personnel, who are located in mainland China, may access data remotely for operation, maintenance, and support. If you agree to AI Data Sharing, the data described in Section 4.3 is also transferred to Anthropic, PBC in the United States or to DeepSeek in China. Our other service providers listed in Section 4.2 may process data in the countries where they operate. Where the law of your country requires safeguards for such transfers, we rely on appropriate mechanisms: for transfers to Anthropic, Anthropic’s Data Processing Addendum incorporates the European Commission’s Standard Contractual Clauses; for transfers to DeepSeek, China is not covered by an EU adequacy decision and DeepSeek does not offer Standard Contractual Clauses or a data processing agreement, so we rely on the explicit consent you give on the AI Data Sharing screen (where applicable, under Article 49(1)(a) of the GDPR). This means data transferred to China may not receive the same level of protection as in your region; for example, local authorities may require access to the data under Chinese law. You can withdraw your consent at any time, with effect for subsequent requests.
4. How We Share, Transfer, and Publicly Disclose Your Personal Information
4.1 Sharing
We do not sell your personal information, and we do not share it with third parties for their own marketing or advertising purposes. We share personal information only in the following cases:
- Service providers acting on our behalf: providers that host our servers, deliver push notifications and emails, and report app crashes (see Section 4.2). They process data only as needed to operate the App on our behalf
- Sign-in providers: if you choose Sign in with Apple or Google, we exchange sign-in tokens with Apple or Google to verify your identity; if you signed in with Apple, we also contact Apple when you delete your account to revoke PeakState’s access
- Weather and environmental data providers: to retrieve weather and pollen data, the App sends your approximate location to Apple WeatherKit and Open-Meteo (see Section 4.2)
- AI processing with your consent: if you agree to AI Data Sharing, the data described in Section 4.3 is sent to Anthropic or DeepSeek
- With your explicit consent in other cases
- Where required by law: pursuant to applicable laws and regulations, legal proceedings, or requests from competent government authorities
4.2 Third-Party Services
The App uses the following third-party services:
- Anthropic, PBC — Claude API (United States): powers the App’s AI features. Data is sent only if you agree to AI Data Sharing; see Section 4.3 for what is sent, your choices, and how Anthropic handles the data
- DeepSeek — DeepSeek API (China): powers the App’s AI features. Data is sent only if you agree to AI Data Sharing; see Section 4.3 for what is sent, your choices, and how DeepSeek handles the data
- Sign in with Apple (Apple Inc.): optional sign-in method. Apple verifies your identity and shares with us the identifier, email address (or relay address), and name described in Section 1.1, under Apple’s Privacy Policy
- Google Sign-In (Google LLC, United States): optional sign-in method. Google verifies your identity in a secure browser window and shares with us your Google account identifier, email address, and name, under Google’s Privacy Policy
- Apple HealthKit: reads the health data you authorize on your device; the App uploads the data described in Section 1.2 to our servers
- Apple WeatherKit: weather data retrieval based on your approximate location
- Open-Meteo: retrieves pollen data; the App sends your approximate location coordinates to Open-Meteo
- Alibaba Cloud ECS (Singapore): cloud server hosting
- Apple Push Notification service (APNs): delivers reminders and care notifications; we send your device token and the notification content to Apple
- Resend: sends transactional emails (such as verification codes and support replies) and our website waitlist emails (the one-time launch email and, only if you opt in, product updates; see Section 2); we send your email address and the message content to Resend
- Sentry (Functional Software, Inc., United States): crash, app-hang, error, and performance reporting to help us find and fix bugs. Reports include device and app details and a hashed form of your account ID; reports of crashes and other errors can also include a screenshot of the screen and a description of its layout (view hierarchy) at that moment, which may show information you were viewing
4.3 AI Data Sharing with Anthropic and DeepSeek
PeakState’s AI features are powered by two AI providers, and data is relayed to them through our servers:
- Anthropic, PBC (United States), which provides the Claude API — 548 Market St, PMB 90375, San Francisco, CA 94104, United States (privacy contact: privacy@anthropic.com)
- Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd. (DeepSeek, China), which provides the DeepSeek API (privacy contact: privacy@deepseek.com)
Each AI request is sent to only one of them. Which one handles a request depends on our service configuration and on each provider’s availability (for example, if one fails or is busy, the request is automatically handled by the other). We send your data to either provider only after you agree to AI Data Sharing, which the App asks you about when you first use it and again whenever our AI providers change.
What we send (only if you agree):
- Your messages to the AI assistant
- Health and status summaries attached to personalize replies — aggregated values such as sleep, heart rate and HRV, steps, energy and mood, caffeine and alcohol intake, schedule density, weather, and Screen Time — together with your setup answers and energy profile (Section 1.10)
- Your preferred name, the optional “About You” details and goals you entered (occupation, age, gender, height and weight, activity level, health conditions; Section 1.11), and your values and goals with their progress
- Meal photos you choose to take or select, for food recognition and nutrition estimates
- What you write in the Evening Review and your feedback after using a tool, to generate insights
- Relevant data and conversation summaries sent in the background to generate morning and evening briefings, proactive care messages, conversation summaries and long-term memory, and 7-day energy experiment reports
If you do not agree: we do not send any of your data to Anthropic or DeepSeek. The AI assistant and meal photo recognition are unavailable; morning and evening briefings and reminders use standard template text generated on our servers; all other features work as usual.
Changing your choice: you can turn AI Data Sharing on or off at any time under Profile > Account Settings > Data Authorization. Turning it off applies to subsequent requests; data that has already been sent to Anthropic or DeepSeek cannot be recalled. Turning it off does not delete your records in PeakState.
4.3.1 How Anthropic handles the data
Anthropic’s processing of data we send through its API is governed by Anthropic’s Commercial Terms of Service and the Data Processing Addendum incorporated into them, under which Anthropic processes the data as our processor. According to Anthropic’s Commercial Terms of Service, Anthropic may not train models on content that customers such as PeakState submit through its API. According to information Anthropic publishes for API customers (as of July 1, 2026), Anthropic automatically deletes API inputs and outputs within 30 days, except where it needs to keep them longer to comply with the law or to enforce its Usage Policy. These terms are set by Anthropic, may change, and are outside our control. For Anthropic’s general privacy practices, see the Anthropic Privacy Policy.
4.3.2 How DeepSeek handles the data
DeepSeek’s processing of data we send through its API is governed by DeepSeek’s Open Platform Terms of Service and Privacy Policy, under the laws of mainland China. According to DeepSeek’s Privacy Policy (version of February 10, 2026), please note in particular:
- Processed and stored in China: DeepSeek collects, processes, and stores the personal data it receives in the People’s Republic of China.
- May be used for model training: DeepSeek’s Privacy Policy applies to its API and states that it may use inputs and the corresponding outputs received through its services to train and improve DeepSeek’s models. DeepSeek has not given us a commitment not to train on API content, and does not offer a data processing agreement.
- Retention: DeepSeek states that it keeps personal data only for as long as necessary to provide its services, and does not publish a specific retention period for API data.
These terms are set by DeepSeek, may change, and are outside our control. If you do not want your data to be processed by DeepSeek, please do not agree to AI Data Sharing; if you have agreed, you can turn it off at any time.
4.4 Transfer
We will not transfer your personal information to any company, organization, or individual, except:
- In the event of a merger, acquisition, or bankruptcy liquidation involving the transfer of personal information, we will require the new entity holding your personal information to remain bound by this Privacy Policy; otherwise, we will require that entity to seek your authorization and consent again
4.5 Public Disclosure
We will publicly disclose your personal information only:
- With your explicit consent
- Where mandated by applicable laws, legal processes, litigation, or competent government authorities
5. Your Rights
5.1 Accessing and Managing Your Information
You can view and manage your personal information within the App:
- Account information: view and edit under Profile > Account Settings
- Conversation records: view your chat history on the Chat page
- Permission settings: manage authorizations under Settings > Privacy & Security
5.2 Deleting Your Information
You can delete your information in the following ways:
- Delete messages: long-press a message on the Chat page and choose Delete
- Delete a conversation: in the conversation history, delete a conversation to remove it together with the summaries and memories derived from it
- Delete your account: go to Profile > Account Settings > Personal Info > Delete Account to permanently delete your account and all of your data on our servers. If you signed in with Apple, deleting your account also revokes PeakState’s access to your Apple Account
Note: After account deletion, your account information, conversation records, summaries and memories, and the health and other data stored on our servers are permanently deleted and cannot be recovered. Residual copies in database backups are deleted within 8 days, as described in Section 3.2. Data in Apple Health on your device is managed by HealthKit and is not affected. Data already sent to Anthropic or DeepSeek under AI Data Sharing is handled as described in Section 4.3.
5.3 Revoking Permissions
You can revoke authorizations at any time:
- HealthKit: revoke under Settings > Health > Data Access & Devices > PeakState
- Calendar: turn off under Settings > Privacy & Security > Calendars > PeakState
- Location: turn off under Settings > Privacy & Security > Location Services > PeakState
- Screen Time: manage under Settings > Screen Time > Content & Privacy Restrictions
- AI Data Sharing: turn off under Profile > Account Settings > Data Authorization
- Sign in with Apple: stop using it for PeakState under Settings > [your name] > Sign in with Apple. This does not delete your PeakState account; to delete your data, delete your account in the App
- Google: remove PeakState’s access at myaccount.google.com/connections. This does not delete your PeakState account
5.4 Additional Rights for EU, UK, and California Residents
If you are in the European Economic Area or the United Kingdom, you have the right to:
- Access: request a copy of your personal data
- Rectification: have inaccurate personal data corrected
- Erasure: have your personal data deleted
- Restriction: ask us to limit how we use your personal data
- Data portability: receive your personal data in a structured, machine-readable format
- Objection: object to processing based on our legitimate interests
- Withdrawal of consent: withdraw your consent at any time, without affecting processing carried out before the withdrawal
- Complaint: lodge a complaint with the data protection authority where you live or work
If you are a California resident, the personal information described in Section 1 falls into the following categories under the CCPA: identifiers (email address and account identifiers), health and medical information, activity data, usage data, profile information, characteristics of protected classifications (age and gender, if you provide them), professional information (occupation, if you provide it), and user content (chat messages, journal entries, and photos). You have the right to:
- Know: request details of the personal information we collect, use, and disclose
- Delete: request deletion of your personal information
- Correct: request correction of inaccurate personal information
- Opt out of sale or sharing: we do not sell your personal information or share it for cross-context behavioral advertising
- Non-discrimination: we will not treat you differently for exercising any of these rights
To exercise any of these rights, email us at kobwhatsup@gmail.com. We will respond within 30 days. You can also delete your account and all of your data yourself at any time in the App (see Section 5.2).
6. Children’s Privacy
The App is intended only for users aged 18 and over. If you are under 18, please do not use the App or provide us with any personal information.
We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from someone under 18, we will delete the relevant data as soon as possible.
7. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date of this policy. When material changes are made, we will notify you before the changes take effect by:
- An in-app pop-up notice
- An email sent to your registered email address
Where a change requires your consent, such as sharing new types of data with our AI providers, we will ask for your explicit consent first. If the data we share with our AI providers, or the providers themselves, change, the App will ask for your AI Data Sharing consent again before sending data under the new terms.
Material changes to this Privacy Policy include, without limitation:
- Significant changes to our service model
- Changes to the principal parties with whom personal information is shared, to whom it is transferred, or to whom it is publicly disclosed
- Significant changes to your rights regarding the processing of your personal information or the means of exercising those rights
8. Contact Us
If you have any questions, comments, or suggestions about this Privacy Policy, or wish to exercise your rights, please contact us:
- Privacy inquiries: kobwhatsup@gmail.com
- Support: kobwhatsup@gmail.com
We will respond to your request within 30 days.
9. Language
This Privacy Policy is prepared in English. Where translations are provided for convenience, the English version prevails in the event of any inconsistency.