Privacy & Security
This page explains exactly what data Peek collects, why we collect it, who processes it, and how you stay in control. We believe you should be able to read a privacy policy in a few minutes and actually understand it.
Most data stays local
Lists, meal plans, budgets, and preferences live only on your phone — never uploaded.
Account is optional
Sign in only to publish recipes. Your profile and published content are stored in Supabase.
Analytics disclosed
PostHog product analytics runs in the app. Every event type is listed in full below.
1. Data stored on your device only
Most of what you do in Peek is stored only in local storage on your device. This data is never synced, uploaded, or sent to our servers, and we cannot see it:
- Your basket and its contents
- Shopping lists and the items on them
- Meal plans
- Weekly budget settings
- Store and recipe preferences, filters, and onboarding state
- Lifetime savings tracker
- Recently viewed recipes and products
- Session tokens, stored in the iOS Keychain via expo-secure-store
What this means: if you use Peek as a guest, virtually everything you do stays on your phone. Deleting the app removes all of this data permanently — there is no backup and no way to restore it.
2. Account data
You can use Peek without an account. If you choose to sign in, authentication is handled via Google or Apple using standard OAuth and native ID-token flows. Peek never sees or stores your password.
When you sign in, we receive and store the following in Supabase:
- Your email address
- Your display name
- Your auth provider ID (from the OAuth token)
We also create a profile record with these fields:
- Name, bio (optional), avatar image URL (optional)
- Whether you have completed onboarding
- Account creation date
Apple sign-in note: if you use Apple's "Hide My Email" feature, Peek receives only Apple's private relay address — we never see your real email. Apple also provides your name only on the very first authorization; after that, Peek uses the name already stored in your profile.
A guest mode lets you use the app without creating an account at all. All traffic between the app and our backend is encrypted over HTTPS.
3. User-generated content
If you have an account, the following content is stored on our servers in Supabase, tied to your account:
- Recipes you create — including the recipe name, description, ingredients, steps, metadata (difficulty, budget, calories), and any uploaded images (stored in Supabase storage)
- Likes you give to other users' recipes
- Ratings you leave on recipes
- Comments you post on recipes
- Dietary and category preferences used to personalise your feed
What is visible to other users
The following are public and visible to anyone using Peek:
- Recipes you choose to publish (those you mark as public)
- Comments you post on recipes
- Your display name and avatar when shown as a recipe author
Likes, ratings, and dietary preferences are not publicly visible.
4. Analytics
Peek uses PostHog for product analytics. PostHog is a third-party service hosted in the United States (us.i.posthog.com). We use it to understand how the app is used, identify bugs, and improve the product.
Important: analytics data leaves your device and is stored on PostHog's servers in the United States. This section discloses everything we send.
Identity data sent to PostHog
When you are signed in, Peek sends PostHog the following, keyed to your Supabase user ID:
- Your email address
- Your display name
- Your authentication provider (Google or Apple)
Events tracked (34 event types)
Peek sends analytics events when you interact with core features. The full list:
- Recipes viewed
- Products viewed
- Stores viewed
- Basket item added
- Basket item removed
- Basket item checked
- Shopping list created
- Shopping list updated
- Shopping list deleted
- Meal plan created
- Meal plan updated
- Meal plan deleted
- Budget set
- Budget updated
- Recipe created
- Recipe published
- Recipe liked
- Recipe unliked
- Recipe rated
- Recipe commented on
- Recipe shared
- Recipe saved
- Recipe unsaved
- Product searched
- Recipe searched
- Onboarding step completed
- Onboarding finished
- Category preference set
- Store preference set
- Sign-in completed
- Sign-out completed
- Profile updated
- App error captured
- Screen / route viewed
Search queries
When you search for recipes or products, the raw search query string you type is sent to PostHog as part of the search event.
Screen views
Every time you navigate to a new screen in the app, a screen-view event is recorded with the route name.
Device data collected automatically
The PostHog SDK automatically collects the following from your device:
- Device model and manufacturer
- Operating system and version
- App version
- Locale and timezone
- A persistent pseudonymous device ID (not your advertising ID)
5. Device permissions
Peek requests access to your photo library only when you add a photo to a recipe or update your profile picture. Images are uploaded to Supabase storage. No camera access is requested.
This permission is optional — you can decline it and still use the rest of the app, and you can revoke it at any time in your device settings.
Peek does not access your location, contacts, calendar, microphone, or messages.
6. Third-party price data
Store and product prices displayed in Peek come from our scraping backend, which collects publicly available pricing information from grocery retailers. This data is informational only and is not guaranteed to be accurate or up to date. No personal data is involved in price lookups.
7. How and why we use your data
| Data category | Purpose |
|---|---|
| Account data | Authentication, service delivery, and account management |
| User-generated content | Service delivery and community features (publishing, rating, commenting) |
| Analytics | Product improvement, bug detection, and understanding usage patterns |
| Device-only data | App functionality (local features work without a network connection) |
| Photos | Displaying recipe images and profile pictures you choose to upload |
We do not use your data for advertising and we do not sell or share personal data with third parties for advertising purposes.
8. Legal bases (EEA / UK)
If you are located in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR:
- Contract (Art. 6(1)(b)) — for account data and service delivery. Creating an account and using Peek's features requires us to process your profile and content data.
- Legitimate interest (Art. 6(1)(f)) — for product analytics. We have a legitimate interest in understanding how the app is used so we can fix bugs and improve the product. You can object to analytics processing by contacting us.
- Consent — for optional features such as uploading photos. You can withdraw consent at any time by revoking device permissions.
9. Sub-processors and data sharing
We use the following third-party services to operate Peek. No other parties receive your personal data.
| Service | Role | Data received | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Account data, user content, uploaded images | United States |
| PostHog | Product analytics | Events, identity data, device data (see section 4) | United States |
| OAuth authentication provider | OAuth token exchange (email, name, provider ID) | United States | |
| Apple | OAuth authentication provider | OAuth token exchange (email or relay address, name on first auth) | United States |
Peek does not sell, rent, or share your personal data with any third party for advertising or marketing purposes.
10. Data retention
- Account data and user content — retained for as long as your account is active. After you delete your account, we remove your data from Supabase within 30 days.
- Analytics data (PostHog) — retained for up to 7 years under PostHog's default retention policy.
- Device-only data — exists only on your device and is deleted when you uninstall the app or use "Clear all app data" in settings.
11. Your rights and data deletion
Deleting your account
You can delete your account directly in the app:
- Go to Profile
- Tap Privacy & Security
- Tap Delete my account
This permanently removes from our servers: your profile, all recipes you created, your likes, ratings, comments, dietary preferences, and uploaded images. Local data on your device is also cleared.
You can also email peek.eat@outlook.com to request account deletion or to exercise any of the rights listed below.
Your rights
Depending on your location, you may have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your personal data
- Restriction — ask us to limit how we process your data
- Portability — receive your data in a portable format
- Objection — object to processing based on legitimate interest (including analytics)
We respond to all privacy requests within 30 days.
Heads up: data stored only on your device (section 1) cannot be recovered after you clear it or uninstall the app — we have no copy on our servers.
12. Children's privacy
Peek is intended for users aged 13 and older. We do not knowingly collect personal data from children under 13. If we learn that we have collected data from a child under 13, we will delete that data promptly. If you believe a child under 13 has provided us with personal data, please contact us at peek.eat@outlook.com.
13. Changes to this policy
If we change how Peek handles data, we will update this page and its effective date. Material changes will also be communicated through an in-app notice before they take effect.
14. Contact
Peek is operated by Peek. If you have questions about privacy, security, or your data, or want to exercise any of your rights, get in touch:
- Email: peek.eat@outlook.com
We aim to respond to all enquiries within 30 days.