Cookie & Data Retention Policy
Last updated: March 2026
1. Overview
The Peachy Life Company ("we", "our", "us") believes your privacy is a right, not a feature. This page explains honestly and completely what cookies and similar technologies this website uses, how we track (or don't track) visitors, and how long we retain data in The Peachy Life mobile application.
The short version: this website sets no analytics cookies, no advertising cookies, and no third-party tracking cookies. Our analytics provider, Plausible, is cookieless by design. The only browser storage we use is strictly necessary for authentication when you are logged in to any account-management area.
2. What Is a Cookie?
A cookie is a small text file placed on your device by a website. Cookies can store preferences, keep you logged in, or track your behaviour across sites. Similar technologies include localStorage, sessionStorage, and IndexedDB — these serve the same purpose but store data in your browser rather than as a file.
Cookies and similar technologies are broadly classified as:
- Strictly necessary — essential for a service you have requested (e.g. keeping you logged in). These do not require consent.
- Analytics / performance — help us understand how visitors use the site. Require consent under UK PECR unless the data collected is genuinely anonymous.
- Marketing / advertising — used to build profiles for targeted advertising. Always require consent.
3. Cookies & Browser Storage This Website Uses
The table below is a complete and accurate list of every cookie and browser storage item set by thepeachylifecompany.com.
| Name / Key | Technology | Category | Purpose | Expiry | Set by |
|---|---|---|---|---|---|
firebase:authUser:… | IndexedDB / localStorage | Strictly necessary | Persists Firebase Authentication state so you remain logged in to any account-management pages without re-entering credentials on every page load. | Until sign-out or session expiry | Firebase Auth (Google) |
| Session storage keys | sessionStorage | Strictly necessary | Transient UI state (e.g. scroll position, open/closed accordions). Never persisted beyond the current browser tab session. | Cleared when tab closes | First party |
| No analytics cookies, advertising cookies, or third-party tracking cookies are set. | |||||
Firebase Authentication is a Google service. When Firebase Auth stores your authentication token in IndexedDB/localStorage it does so solely to keep you signed in. This data never leaves your device except as part of secure API calls to verify your identity. Google's use of this data is governed by the Firebase Privacy & Security documentation.
If you are only browsing the marketing website and not signed in to any account area, no cookies or persistent browser storage are set at all.
4. Analytics — Plausible (No Cookies, No Consent Banner Required)
This website uses Plausible Analytics, an open-source, privacy-first analytics platform based in the EU.
Plausible works without cookies. Specifically:
- Plausible does not set any cookies or use any persistent identifiers.
- It does not track you across websites — it has no capability to do so.
- Your IP address is anonymised immediately upon receipt and is never stored.
- No personal data is collected or transmitted. Page view counts and referral sources are aggregated only.
- Plausible is fully compliant with GDPR, CCPA, and PECR out of the box. Because it collects no personal data and uses no cookies, it falls outside the scope of PECR consent requirements.
This means we can honestly tell you: no consent banner is needed for our analytics, and none is shown. You can review Plausible's data policy at plausible.io/data-policy.
We deliberately chose Plausible over Google Analytics and similar products precisely because it respects your privacy without requiring us to ask for consent to count page views.
5. What We Do Not Use
For complete transparency, the following tracking technologies are not present on this website:
- Google Analytics or Google Tag Manager
- Facebook Pixel or Meta tracking
- Advertising or retargeting pixels of any kind
- Hotjar, Clarity, FullStory, or session-recording tools
- Affiliate tracking cookies
- Cross-site tracking of any description
6. App Data Retention Schedule
The Peachy Life mobile application stores personal data on Google Firebase infrastructure. The table below describes every category of personal data we hold, how long we keep it, and the legal basis under which we retain it. These periods apply from the moment the data is created unless otherwise stated.
We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) — in particular APP 11 (security and retention) and APP 13 (destruction or de-identification when no longer needed). Where UK users are concerned, these periods are consistent with the UK GDPR data minimisation principle (Article 5(1)(e)).
| Data Type | What It Includes | Retention Period | Legal Basis | Action at End of Period |
|---|---|---|---|---|
| Account data | Email address, display name, account creation date, subscription status | Duration of active account, plus 30 days after account deletion request is submitted | Contract (performance of the service you signed up for) | Permanent deletion from all Firebase collections and backups within 30 days |
| Mood entries | Mood scores, emotion tags, activity labels, timestamps | Duration of active account | Contract; Legitimate interest (enabling historical trend analysis) | Deleted with account |
| Journal entries | Free-text journal content | Duration of active account | Contract | Deleted with account |
| AI conversation messages | Messages sent to and received from the AI companion feature | Up to 90 days from each message, then automatically deleted on a rolling basis | Legitimate interest (short-term conversational context); data minimisation | Auto-purged on a rolling 90-day cycle regardless of account status |
| Biometric / health data | Health metrics synced from Apple Health, Google Health Connect, or Garmin (e.g. sleep, steps, heart rate) | Duration of active account | Explicit consent (required before any health sync is enabled; revocable at any time in Settings) | Deleted with account; also deleted immediately if you revoke health-sync permission |
| Usage analytics | Anonymous, aggregated app usage patterns | Retained indefinitely in aggregated, anonymous form only | Not applicable — no personal data is retained | No deletion required; data is not personal |
| Account deletion requests | Record that a deletion was requested, timestamp | 30 days from request (recovery window) | Legal — to honour your right to recover an accidentally deleted account before purge completes | Deletion process executes and purge record is removed |
| Billing records | Transaction IDs, subscription purchase records (not full payment card details, which are held by Apple / Google) | 7 years from transaction date | Legal obligation — Australian tax law (Income Tax Assessment Act 1997; GST Act 1999) | Secure deletion after 7-year statutory period |
| Support correspondence | Emails and in-app support messages sent to hello@thepeachylifecompany.com | 3 years from last contact in the thread | Legitimate interest (reference for ongoing support; evidence in case of dispute) | Deleted after 3 years of inactivity in the thread |
A note on backups
Firebase automated backups may contain copies of your data for a short period after a deletion request is processed. These backups are overwritten on a rolling cycle (typically within 30 days) and are encrypted at rest. We do not restore deleted user data from backups except in the case of a serious infrastructure incident affecting multiple users, and only within the 30-day account recovery window described above.
7. How to Control Cookies & Browser Storage
Browser-level controls
All major browsers let you view, block, or delete cookies and localStorage entries. Because this site sets no third-party or analytics cookies, using these controls will primarily affect the Firebase Auth token — which will simply sign you out of any account area.
App data controls
Within The Peachy Life app you can:
- Export all your data — Settings → Account → Export Data.
- Delete your account and all data — Settings → Account → Delete Account. This initiates the 30-day recovery window described in the retention schedule above.
- Revoke health-data sync — Settings → Integrations. All synced biometric data is deleted immediately.
- Opt out of in-app analytics — Settings → Privacy → Usage Analytics.
If you require assistance deleting your data or have a specific deletion request that the in-app flow does not cover, email us at hello@thepeachylifecompany.com with the subject line "Data Deletion Request".
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of access — request a copy of the data we hold about you.
- Right to rectification — request correction of inaccurate data.
- Right to erasure ("right to be forgotten") — request deletion of your data, subject to legal retention obligations (e.g. billing records).
- Right to data portability — receive your data in a machine-readable format (available via in-app export).
- Right to object — object to processing based on legitimate interest.
- CCPA / California rights — the right to know what data we collect, the right to delete, and the right to opt out of sale. We do not sell personal data to third parties.
- Australian Privacy Act rights — the right to access and correct personal information we hold about you.
Full details of your rights, how to exercise them, and our response timescales are set out in our Privacy Policy. We aim to respond to all rights requests within 30 days.
9. We Do Not Sell Your Data
The Peachy Life Company does not sell, rent, trade, or otherwise transfer personal information to third parties for their commercial purposes. This applies to all users regardless of location, including California residents under the CCPA. Our business model is subscription-based; your data is never a revenue source.
10. Changes to This Policy
We may update this Cookie & Data Retention Policy from time to time. Where changes are material — for example, if we were to introduce a new category of cookie — we will provide prominent notice on this page and, where applicable, notify you via the app. The "Last updated" date at the top of this page reflects when the most recent changes were made.
Archived versions of this policy are available on request by emailing hello@thepeachylifecompany.com.
11. Contact
For any questions about cookies, data retention, or your privacy rights, please contact us:
- Email: hello@thepeachylifecompany.com
- Subject line for data requests: "Privacy Request" or "Data Deletion Request"
- Company: The Peachy Life Company, Sydney, Australia
If you are in the UK and your concern is not resolved to your satisfaction, you have the right to lodge a complaint with the Information Commissioner's Office (ICO). If you are in Australia, you may contact the Office of the Australian Information Commissioner (OAIC).