Privacy Policy

Version 2026-08-25 · Effective 25 August 2026 · Supersedes the version dated March 2026

This Privacy Policy explains how The Peachy Life Company ("we", "us", "our") collects, uses, stores, and protects your personal information when you use The Peachy Life mobile application and website (together, "the Service").

We have written this policy in plain English, but it is legally complete. Please read it carefully. If you have questions, email us at hello@thepeachylifecompany.com.

Important disclaimer: The Peachy Life is a general mental fitness and wellbeing tool. It is not a medical device, clinical service, or crisis intervention service. If you are in crisis or need urgent mental health support, please contact a qualified professional or emergency services in your country.

1. Who We Are

The Peachy Life Company
Sydney, New South Wales, Australia
Email: hello@thepeachylifecompany.com
Website: thepeachylifecompany.com

For users in the United Kingdom, The Peachy Life Company acts as the data controller within the meaning of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

For users in Australia, we are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Although the small business exemption under the Privacy Act may technically apply based on our current revenue, we voluntarily comply with the APPs in full because we handle health information, which is always subject to the Act regardless of business size.

For users in California, USA, please also read the dedicated section at the end of this policy covering your rights under the California Consumer Privacy Act (CCPA) and related California laws.

2. What Data We Collect and Why

We only collect data that is necessary to provide and improve the Service.

2.1 Account and Identity Data

  • What: Email address and display name.
  • Why: To create and authenticate your account, and to identify you within the app.
  • How collected: You provide this directly when you register.
  • Retention: For the duration of your account. Erased 30 days after account deletion.
  • UK GDPR lawful basis: Performance of a contract (Art. 6(1)(b)) — you cannot use the Service without an account.

2.1a Age Verification Data

  • What: Two items, recorded once when you create an account. Year of birth — the year only. We do not ask for, and do not store, the day or month. Verification time — the date and time you completed the age check.
  • Why: To confirm you are old enough to use the Service, and to keep a record that we carried out that check.
  • How collected: You select your year of birth during signup, immediately after you begin creating an account and before we collect any wellbeing information. The list of years is complete, so you can answer honestly whatever your age.
  • If your answer shows you are under 16: We never store the year you selected. Because we ask this question just after you begin creating an account, an account exists for the few seconds in between — we delete it. That deletion removes the account itself, your sign-in credentials and anything attached to them, and we sign you out. What we keep afterwards is a record that a signup was blocked and the time it happened. That record contains nothing that identifies you: no account reference, no email address, no year of birth. We then show you information about support services suitable for your age, and the signup process ends.
  • Retention: For the duration of your account. Both values are erased 30 days after account deletion, at the same time as the rest of your account data.
  • Why we collect it (Australia): Collecting your year of birth is reasonably necessary for our functions and activities under Australian Privacy Principle 3, because we operate an age check, and we tell you about it before we collect it under Australian Privacy Principle 5.

We do not use your year of birth to profile you, to decide what content you see, or to target advertising. We do not run advertising.

2.1b Consent and Agreement Records

  • What: When you tick the box confirming you accept our Terms of Service and this Privacy Policy, we record the date and time you accepted, the version of the Terms of Service you accepted, and the version of this Privacy Policy you accepted. Versions are identified by their version date.
  • Why: So we hold an accurate record of what you agreed to and when. Without it we cannot show that we obtained your agreement, and we cannot tell you which version of these documents applied to you.
  • How collected: Recorded automatically when you complete signup.
  • Retention: For the duration of your account, and for 7 years after you delete it. We keep it because it is the evidence that you consented. It is stored apart from your wellbeing data, contains no health information, and we use it for nothing else.

Acceptances before 25 August 2026. We began recording document versions in August 2026. If you accepted our Terms and Privacy Policy before then, your record holds the date and time of your acceptance and nothing more. It does not identify which version of the documents you saw. We cannot reconstruct the exact text displayed to you at that moment, and we will not claim otherwise. Email us and we will tell you what we do hold, and which published version was current on that date.

2.2 Mood and Wellbeing Data

  • What: Mood scores, emotion words, activity tags, responses to validated wellbeing check-ins like the WHO-5, and associated timestamps you submit.
  • Why: To generate personalised mood insights, trends, and weekly reports for you.
  • How collected: You enter this data directly through the app.
  • Special category status: This data constitutes health or mental health data under UK GDPR Article 9 and Australian law. We treat it accordingly (see Section 3).
  • UK GDPR lawful basis: Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)). You give this consent when you create an account and begin logging. You can withdraw consent at any time by deleting your data or account.

2.3 Journal Entries

  • What: Free-text content you write in the journalling feature.
  • Why: To provide a private, secure space for self-reflection and to connect journal content with your broader wellbeing picture (where you choose to).
  • How collected: You type this directly into the app.
  • Special category status: May contain sensitive mental health information. Treated as special category data.
  • UK GDPR lawful basis: Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)).

2.4 AI Conversation Messages

  • What: Messages you send to, and responses you receive from, the AI chat feature.
  • Why: To provide the AI coaching and support feature.
  • How collected: You type or dictate messages. To generate a reply we send your message, and a rolling summary of the recent conversation, to an external AI provider. Section 5a sets out exactly what we send and what we do not. If you dictate rather than type, Section 2.9 explains where the audio goes.
  • Retention: AI conversation messages are retained for up to 90 days and then deleted. This deletion process is actively being implemented; in the interim, messages may be retained until the automated deletion job is live.
  • Special category status: May contain sensitive mental health information. Treated as special category data.
  • UK GDPR lawful basis: Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)).

2.5 Biometric and Health Metrics

  • What: Health metrics such as step count, heart rate, sleep data, and other biometric data sourced from Apple Health (iOS), Google Health Connect (Android), or Garmin Connect — depending on which integrations you enable.
  • Why: To enrich your wellbeing picture by correlating physical health data with mood patterns.
  • How collected: Only with your explicit, separate in-app permission for each integration. You can revoke access at any time from your device's health app settings or within The Peachy Life app.
  • Special category status: Biometric and health data is special category data. We do not collect this unless you actively grant permission.
  • UK GDPR lawful basis: Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)).

2.6 Usage Analytics and Crash Reporting

  • What: Which features you use, general navigation flows, and technical diagnostic data when the app crashes, such as device model, operating system version and the state of the app at the time.
  • Why: To understand how the app is used, prioritise improvements, and diagnose and fix crashes.
  • How collected: In the app, via Firebase Analytics and Firebase Crashlytics, which run in the background while you use it. On our website, via Cloudflare Web Analytics, which sets no cookies, does not track visitors between sessions or sites, and does not store IP addresses.
  • This data is pseudonymous, not anonymous. It is not linked to your name or email, and we cannot read your journal or chat content from it. It does carry persistent identifiers: crash reports are keyed to a shortened, scrambled version of your account identifier, so reports from the same installation can be grouped together. That means it is still information about you, and we treat it as personal information rather than calling it anonymous.
  • We do not copy your journal, mood or assessment records into our analytics systems.
  • UK GDPR lawful basis: Legitimate interests (Art. 6(1)(f)) — maintaining and improving a reliable service, balanced against the limited privacy impact of technical and pseudonymous usage data.

2.7 Communications Data

  • What: The content of any emails or messages you send us, and your email address.
  • Why: To respond to your enquiries and support requests.
  • UK GDPR lawful basis: Legitimate interests (Art. 6(1)(f)) — responding to communications you initiate.

2.8 Psychometric Assessments

  • What: Your answers to structured wellbeing assessments, the scores calculated from them, and the written reports we generate to help you interpret your results.
  • Why: To give you a structured view of specific areas of wellbeing over time, and to explain what your results mean in plain language.
  • How collected: You complete an assessment in the app. Taking one is your choice, and the Service works without them.
  • Special category status: Health data under UK GDPR Article 9 and health information under the Privacy Act 1988.
  • What we send to the AI provider: When we generate a written report we send a descriptive band rather than your result, for example "a developing area". We do not send your numeric score, and we do not send your answers to individual questions.
  • Retention: For the duration of your account. Erased 30 days after account deletion.

2.9 Dictated Audio

  • What: Audio of anything you dictate instead of typing, including journal entries, mood notes and chat messages.
  • Why: To convert your speech into text.
  • How collected: When you tap the microphone, your device's built-in speech recognition captures the audio.
  • Where it goes: Dictation is not processed on your device. Our app uses the speech recogniser built into iOS or Android, configured for server-side recognition, so the audio is sent to Apple or Google in the United States to be transcribed. Whatever you say reaches them, which can include distress or health disclosures.
  • If you would rather it did not: Type instead of dictating. Nothing is sent for transcription unless you use the microphone.
  • What we keep: We store the resulting text as part of the entry you were writing. We do not store the audio.

2.10 Food and Nutrition Logging

  • What: Food and drink you log, the nutrition information attached to it, and any photograph you take of a meal.
  • Why: To let you keep a food diary and see it alongside your mood and wellbeing data.
  • Photographs are not analysed on your device. If you log food by taking a photo, the photograph is sent to OpenAI in the United States to identify what is in it. There is no setting that keeps this on your device or routes it elsewhere. If you would rather your photographs did not leave the device, log food by searching or typing instead.
  • Food searches are not private to us. When you search our food database, the search term is sent from our servers to USDA FoodData Central, a United States federal government agency, to look up nutrition data.
  • Retention: For the duration of your account. Erased 30 days after account deletion.

2.11 Goal Sharing and Accountability Partners

If you choose to share a goal with someone, two things happen that involve another person's information as well as your own.

We collect their email address. You give us the email address of the person you nominate. That is personal information about someone who is not our user and has not read this policy. We use it only to send them the updates you asked us to send, we do not add them to any mailing list, and we do not use it for anything else. If you nominate someone, please make sure they are happy to hear from us first.

We disclose your goal data to them. The person you nominate receives your goal and your progress against it. Once we have sent it to them, we cannot retrieve it or control what they do with it. Only share with someone you trust.

You can stop sharing at any time in the app. That stops future updates and does not undo updates already sent. If you have been nominated by someone and want your email address removed, email hello@thepeachylifecompany.com and we will remove it.

3. Special Category Data — Mental Health Information

Mood scores, journal content, wellbeing self-assessments, AI conversation messages, and biometric data are all treated as health or mental health data. Under UK GDPR, this is "special category" data that attracts heightened protections under Article 9. Under Australian law, it is "sensitive information" and "health information" under the Privacy Act 1988.

We process this data exclusively on the basis of your explicit, freely given, informed consent. This means:

  • We explain clearly what data we collect and how we use it before you provide it.
  • You can withdraw consent at any time without penalty by exporting and deleting your data through the app's Settings, or by contacting us.
  • We never use your mental health data for advertising, profiling, or sale to third parties.
  • Access to this data is limited. Within our own systems only you and our authorised engineers can read it, engineers are bound by confidentiality obligations, and their access is audit-logged. Some of it also goes to the external companies listed in Section 5 so that the features you use can work: the AI companion, and speech-to-text if you dictate. Sections 5a and 2.9 set out exactly what goes where.

We also apply data minimisation: we only ask you for data that is directly useful to you. Beyond the crash and usage telemetry described in Section 2.6, we do not collect information about you in the background.

4. Data We Do Not Collect

  • Payment information: All payments are processed directly by Apple (App Store) or Google (Play Store). We receive no raw payment card data, bank details, or full billing addresses. We may receive a transaction confirmation and subscription status from the platform.
  • Advertising identifiers: We do not use advertising SDKs, tracking pixels, or ad identifiers such as IDFA or GAID.
  • Device identifiers beyond what Firebase requires: Firebase Authentication may generate an anonymous installation ID for technical operation. We do not use this for advertising.
  • Location data: We do not collect precise or coarse location data.
  • Contact lists or social graph: We do not access your contacts, social accounts, or friends lists.

5. Third-Party Data Processors

We use the following third-party services to operate The Peachy Life. Each is a data processor acting on our instruction — they may not use your data for their own purposes.

Recipient Purpose What it receives Country Privacy information
Anthropic, PBC Default AI provider: chat replies, wellbeing insights, psychometric report text Your chat messages, which may contain health disclosures; rolling summaries of recent conversation; journal text you submit for analysis; descriptive result bands from assessments and WHO-5 band labels, never numeric scores; summaries derived from your wearable data such as sleep, heart-rate variability, activity and engagement; habit, exercise and food context United States anthropic.com/legal/privacy
OpenAI, L.L.C. Photo food recognition, and standby AI provider for the categories in the row above The photograph you take when you log food by photo. Also, when it is acting as the standby provider, the same text categories listed above United States openai.com/policies/privacy-policy
Google Firebase — Cloud Firestore Primary database for your app data Mood entries, journal entries, AI messages, assessment results, food logs, settings, wearable records Australia (australia-southeast1) firebase.google.com/support/privacy
Google Firebase — Authentication Account authentication Email address, display name, sign-in metadata United States firebase.google.com/support/privacy
Google Firebase — Analytics and Crashlytics Usage analytics and crash reporting Usage events, crash diagnostics, device and installation identifiers, and a shortened scrambled form of your account identifier. No journal, mood or assessment content United States firebase.google.com/support/privacy
Apple (iOS) Speech-to-text; app distribution; in-app purchases; optional Apple Health integration; push notification delivery Audio you dictate. Payments handled entirely by Apple. Health data only with your permission. United States apple.com/legal/privacy
Google (Android) Speech-to-text; app distribution; in-app purchases; optional Health Connect integration; push notification delivery Audio you dictate. Payments handled entirely by Google. Health data only with your permission. United States policies.google.com/privacy
USDA FoodData Central Nutrition database lookups The food search terms you enter United States (federal government agency) fdc.nal.usda.gov
Garmin Optional integration syncing fitness and biometric data from Garmin devices Fitness and biometric metrics you choose to sync, only if you connect a Garmin account United States garmin.com privacy policy
Cloudflare, Inc. Cookieless website analytics No personal data. Aggregated website statistics only. United States / global edge network cloudflare.com/privacypolicy
Web3Forms Delivers messages sent through the website contact form and beta signup form Your email address, the content of your message, and — if you sign up for the beta — whether you told us you use an iPhone or an Android phone United States web3forms.com/privacy
Buttondown Beta signup and newsletter mailing list Your email address, and for beta signups whether you use an iPhone or an Android phone United States buttondown.com/legal/privacy

We do not authorise any of our processors to use your data for their own purposes, to sell your data, or to transfer it to further parties beyond what is required to provide their service to us.

5a. What We Send to AI Providers, and What We Do Not

The AI features work by sending some of your information to an external AI company, which generates a response and sends it back to us. Our default provider is Anthropic, in the United States. OpenAI, also in the United States, is our standby provider for these features and takes over when Anthropic is unavailable. OpenAI also handles one feature outright: photo food recognition, described in Section 2.10.

What we send:

  • The text of your chat messages, and rolling summaries of your recent conversation for context.
  • Journal text, when you use a feature that analyses a journal entry.
  • Descriptive bands from assessments, such as "a developing area", and WHO-5 band labels.
  • Summaries derived from your wearable data, such as sleep, heart-rate variability, activity and engagement patterns. See the note on the setting below.
  • Context about your habits, exercise and food logs.
  • The photograph, when you log food by taking a photo.

What we do not send:

  • Your account identifier. The AI provider receives nothing that links a request back to your account.
  • Your email address or display name.
  • Your numeric assessment scores, or your answers to individual assessment questions.

Your wearable data and the AI: this setting is on by default. The setting that lets the AI use summaries of your wearable data is switched on when you connect a wearable. You do not have to turn it on, and it will be on until you turn it off. You can switch it off at any time in Settings, and once you do, we stop sending those summaries. We are telling you this plainly because it is the opposite of how an opt-in setting works, and you should know which one this is.

We remove contact details we can spot, and here is what that is worth. Before your text goes to an AI provider, our server scans it for email addresses and phone numbers and strips out any it detects. This reduces the contact details in the text as a side effect. It is not anonymisation and it is not de-identification. It is pattern matching, it misses things, and it cannot remove names, places, or anything else you have written about yourself or another person. Assume that anything you write in a message or journal entry sent for analysis reaches the AI provider substantially as you wrote it. We do not treat this step as a safeguard for your health information and neither should you.

What we can and cannot tell you about how these companies handle your data. We send this data under the providers' standard commercial API terms for business customers. We do not yet hold written confirmation from Anthropic about whether data sent through its API is retained or used to train its models. Until we hold that in writing, we will make no claim about it. We will update this section when the position changes.

Turning it off. The AI chat, insights and generated reports are optional. Mood tracking, journalling and assessments work without them. Photo food logging is optional too, and you can log food by searching or typing instead.

6. Where Your Data Goes

Your journal entries, mood check-ins, chat history, assessments and wearable summaries are stored in Australia, in Google Cloud's Sydney region. We moved our primary database there on 2 August 2026. Your health and wellbeing records are held onshore in Australia under the Australian Privacy Act.

Storing your records in Australia is not the same as everything happening in Australia. Some of our processing still runs on servers in the United States, including for people using older versions of the app, which continue to call our previous United States servers until they update. Several features send data overseas by design. Where a feature sends data overseas we say so, and you can turn that feature off.

The overseas transfers that involve your personal information are:

  • AI processing (United States). Chat messages, journal text submitted for analysis, assessment band descriptors, wearable-derived summaries, and food and habit context go to Anthropic and, as standby, to OpenAI. Photographs of food go to OpenAI. This includes health information. Section 5a sets out exactly what is sent.
  • Speech-to-text (United States). Audio you dictate goes to Apple or Google. See Section 2.9.
  • Usage and crash telemetry (United States). Via Firebase Analytics and Crashlytics. Pseudonymous, and it contains none of your journal, mood or assessment content.
  • Nutrition lookups (United States). Food search terms go to USDA FoodData Central.
  • Wearable data (United States). If you connect a Garmin account.
  • App distribution, payments and notification delivery. Via Apple and Google.
  • Website contact forms, mailing list and website analytics. As listed in Section 5.

For Australian users

Under Australian Privacy Principle 8, before disclosing personal information to an overseas recipient we must take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles. For Google services we rely on Google's Data Processing Addendum and its standard contractual clauses. For our AI providers we currently rely on their standard commercial API terms. We are working to put specific data processing agreements in place and will update this section when we do.

For UK users

Transfers of your personal data from the United Kingdom to the United States are governed by appropriate safeguards. For transfers to Google we rely on the UK International Data Transfer Agreement (UK IDTA) or equivalent standard contractual clauses approved by the UK Information Commissioner's Office (ICO). For our AI providers, the transfer mechanism is under review as part of putting formal data processing agreements in place, and we will state it here once settled. You may ask us at any time which mechanism applies to a given transfer by emailing hello@thepeachylifecompany.com.

7. How Long We Keep Your Data

Data type Retention period
Account data (email, display name) For the duration of your account. Deleted within 30 days of account deletion.
Mood entries For the duration of your account. Deleted within 30 days of account deletion.
Journal entries For the duration of your account. Deleted within 30 days of account deletion.
AI conversation messages Up to 90 days from the date of each message, then automatically deleted. (Automated deletion job actively being implemented.)
Biometric/health data For the duration of your account, or until you revoke integration permission. Deleted within 30 days of account deletion.
Website analytics (Cloudflare Web Analytics) Aggregated website statistics only. No personal data retained.
App usage and crash telemetry (Firebase Analytics, Crashlytics) Pseudonymous. Retained by Firebase under Google's standard retention periods for analytics and crash data.
Age verification data (year of birth, verification timestamp) For the duration of your account. Erased 30 days after account deletion.
Consent records (acceptance time, document versions) For the duration of your account, and 7 years after deletion. See Section 2.1b.
Assessment results and generated reports For the duration of your account. Erased 30 days after account deletion.
Food logs and food photographs For the duration of your account. Erased 30 days after account deletion.
Crisis-safety records 90 days after account deletion, then permanently purged. See below.
Compliance audit trail Kept indefinitely. See below.
Support correspondence Up to 3 years, for the purpose of resolving any ongoing or future queries.

When you delete your account in Settings, there is a 30-day recovery window. During those 30 days your account is deactivated and we stop using your data, but your records still exist, so that you can get your account back if you change your mind or deleted it by mistake. At the end of the 30 days we erase your records permanently, including files held in storage. Residual copies may persist in encrypted backup snapshots for a short period afterwards, consistent with our backup and disaster-recovery practices, before being overwritten.

Three things outlive that erasure, and we would rather you knew before you pressed the button than after.

Crisis-safety records, kept for 90 days. If the Service detected content suggesting a risk to your safety and responded, for example by showing you crisis support resources, we keep a record of that for 90 days after you delete your account and then purge it permanently. This covers the safety event itself, any follow-up we scheduled, and mood readings taken around it. It is not your journal and it is not your conversation history. We keep it for that short window because it may be needed to protect someone's life or safety.

Consent records, kept for 7 years. The record of your acceptance of these documents, as described in Section 2.1b.

A compliance audit trail, kept indefinitely. When you ask us for a copy of your data, or ask us to delete your account, we keep a record that you asked, when you asked, and what kind of request it was. It never contains the content of your data. We keep it because it is our evidence that we honoured your request, and deleting it would destroy the proof that the deletion happened.

Apart from these three, erasure is complete once the 30-day window closes.

8. How We Protect Your Data

  • Encryption in transit: All data is transmitted over HTTPS/TLS.
  • Encryption at rest: Data stored in Google Cloud Firestore is encrypted at rest by Google's infrastructure.
  • Credentials for connected services: When you connect a service such as Garmin, we hold an access credential for it. We encrypt these credentials with a key managed in Google Cloud Key Management Service in Australia, on top of the encryption Google's infrastructure already applies.
  • Access controls: Access to production data is restricted to authorised personnel only, on a need-to-know basis, and is audit-logged.
  • Firebase Security Rules: Firestore rules are configured so that users can only read and write their own data. No cross-user data access is possible at the database level.
  • Authentication: Firebase Authentication handles credential storage and management. We never store raw passwords.

No method of transmission over the internet or electronic storage is 100% secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant authorities as required by law.

9. Your Rights

You have the following rights in relation to your personal data, regardless of where you are located. Additional jurisdiction-specific rights are set out in Sections 10 and 11.

  • Get a copy of your data: You can view your data within the app. You can request a copy of the records you created — your mood check-ins, journal entries, chat history, assessments and wearable summaries — as a machine-readable JSON file, from Settings. We send you a download link that expires after 24 hours. Some internally generated records are not included in that file: our system's own inferences about you, the credentials for services you have connected, and safety audit logs. You can ask us about those separately at hello@thepeachylifecompany.com.
  • Delete your data: You can delete your account from Settings at any time. There is a 30-day recovery window, after which your records are erased permanently, including files held in storage. Three narrow exceptions apply, all described in Section 7.
  • Correct your data: You can update your display name and account details within the app. For other corrections, contact us.
  • Withdraw consent: Where we process your data on the basis of consent (including all special category data), you can withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing that occurred before withdrawal. Withdrawing consent for core data processing will require deleting your account.
  • Disable health integrations: You can revoke Apple Health, Google Health Connect, or Garmin permission at any time from your device settings or within the app.

To exercise any right, or for any privacy-related request, contact us at hello@thepeachylifecompany.com. We will respond within 30 days.

10. For UK Users — UK GDPR Rights

If you are located in the United Kingdom, you have the following rights under the UK GDPR and Data Protection Act 2018, in addition to the general rights above:

  • Right of access (Art. 15): You have the right to receive a copy of your personal data and information about how it is processed.
  • Right to rectification (Art. 16): You have the right to have inaccurate personal data corrected and incomplete data completed.
  • Right to erasure (Art. 17): You have the right to request deletion of your personal data ("right to be forgotten") in certain circumstances — for example, where you withdraw consent and there is no other lawful basis for processing.
  • Right to restriction of processing (Art. 18): You have the right to request that we restrict processing of your data in certain circumstances — for example, while the accuracy of data is contested.
  • Right to data portability (Art. 20): Where processing is based on consent or contract and carried out by automated means, you have the right to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller. You can export your data at any time from the app's Settings.
  • Right to object (Art. 21): You have the right to object to processing based on our legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
  • Rights related to automated decision-making (Art. 22): The Peachy Life does not make automated decisions that produce legal or similarly significant effects on you. AI-generated coaching suggestions are informational only and do not constitute automated decision-making in the Art. 22 sense.

How to exercise your UK GDPR rights

Email us at hello@thepeachylifecompany.com with the subject line "UK GDPR Data Rights Request". We will acknowledge within 5 working days and respond in full within one calendar month (extendable by a further two months for complex or numerous requests, with notice).

Right to complain to the ICO

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:

We would appreciate the opportunity to address your concern directly before you approach the ICO, so please contact us first.

11. For Australian Users — Privacy Act 1988

If you are located in Australia, we comply with all 13 Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Key rights and obligations include:

  • APP 5 — Notice at collection: We notify you of our data collection practices at the point of collection — through this policy and in-app notices.
  • APP 6 — Use and disclosure: We only use and disclose your personal information for the primary purpose for which it was collected, or with your consent, or as required by law.
  • APP 1 — Openness: This policy is our openness statement. It describes the kinds of personal information we collect and hold, how we collect it, why we hold it, how you can get at it and correct it, how to complain, and which countries your information may go to.
  • APP 8 — Cross-border disclosure: Your journal, mood, assessment and wearable records are stored in Australia. Several features send information overseas, mostly to the United States. Section 6 describes them and Section 5 names the companies involved and the countries they operate in.
  • APP 11 — Security: We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure (see Section 8).
  • APP 12 — Access: You have the right to access your personal information. Make a request by emailing hello@thepeachylifecompany.com. We will respond within 30 days. We may charge a reasonable fee to cover the cost of providing access (we will notify you in advance).
  • APP 13 — Correction: You have the right to request correction of inaccurate, out-of-date, incomplete, irrelevant, or misleading personal information. You can update most data directly within the app.

Notifiable Data Breaches

If we suffered a data breach likely to cause you serious harm, Part IIIC of the Privacy Act 1988 requires us to notify you and the Office of the Australian Information Commissioner as soon as practicable after we conclude that has happened. We would tell you what happened, which of your information was involved, and what we recommend you do. We would publish a notice on our website if we could not contact you directly.

Complaints — Australian users

If you believe we have breached the APPs, please contact us first at hello@thepeachylifecompany.com. We will investigate and respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

12. For California Users — CCPA / CalOPPA

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the California Online Privacy Protection Act (CalOPPA).

Categories of personal information we collect

In the preceding 12 months, we have collected the following categories of personal information from California residents:

  • Identifiers: Email address, display name.
  • Personal records: Content of mood entries, journal entries, and AI chat messages.
  • Health and medical information: Mood data, wellbeing assessments, and biometric data (where explicitly permitted).
  • Internet or network activity: Pseudonymous app usage and crash data via Firebase Analytics and Crashlytics, and aggregated website statistics via Cloudflare Web Analytics.
  • Age information: Year of birth, collected to check eligibility to use the Service.
  • Audio: Speech you dictate, transcribed by Apple or Google.
  • Visual information: Photographs you take to log food.

Business or commercial purpose for collection

We collect this information to provide the core features of The Peachy Life: mood tracking, journalling, AI coaching, and personalised wellbeing insights.

We do not sell or share your personal information

The Peachy Life Company does not sell, rent, trade, or share your personal information with third parties for their own commercial or advertising purposes. This applies to all users, including California residents. There is no "opt-out of sale" mechanism because we do not engage in the sale of personal information.

Your CCPA rights

  • Right to know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources from which it was collected, the business purpose for collection, and the categories of third parties with whom we have shared it.
  • Right to delete: You have the right to request deletion of personal information we have collected from you, subject to certain exceptions. You can delete your account directly from the app's Settings. Section 7 explains the 30-day recovery window and the three exceptions that outlive erasure.
  • Right to correct: You have the right to request correction of inaccurate personal information.
  • Right to opt out of sale/sharing: We do not sell or share personal information. No opt-out is needed, but you may contact us to confirm.
  • Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights. Exercising these rights will not result in denial of service, different pricing, or a different quality of service.

Shine the Light (California Civil Code Section 1798.83)

California residents may request information once per calendar year about personal information shared with third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes, so no such disclosure is required. To confirm, contact us at hello@thepeachylifecompany.com.

How to exercise your California rights

Email hello@thepeachylifecompany.com with the subject "California Privacy Rights Request". We will acknowledge within 10 business days and respond in full within 45 calendar days (extendable by a further 45 days with notice). We may need to verify your identity before processing your request.

CalOPPA — Policy effective date and updates

This policy carries the version date shown at the top of the page. We will post any changes to this page and update that date. For material changes, we will provide notice through the app.

13. Children's Privacy

The Peachy Life is for people aged 16 and over. When you create an account we ask for your year of birth, and we offer you every year to choose from so that you can answer honestly rather than being nudged into a year that lets you through.

If your answer shows you are under 16, we do not keep it. We delete the account you had just begun creating, together with your sign-in credentials and anything attached to them, and we sign you out. Section 2.1a sets out exactly what survives that deletion, which is a record that a signup was blocked and when, carrying nothing that identifies you.

This is enforced by our servers, not only by the app. Our database refuses to store a year of birth that would make you younger than 16, so the check cannot be got around by tampering with the app on a device.

We do not knowingly collect personal information from anyone under 16. If you are a parent or guardian and believe your child has given us personal information, email hello@thepeachylifecompany.com and we will delete it promptly.

For everyone who does meet the minimum age, we keep the year of birth you gave and when you gave it, so that we can show we carried out this check. Section 2.1a explains what we do with it. We do not use it to profile you, to decide what content you see, or to target advertising, and we do not run advertising.

If you are 16 or 17

You are old enough to use the Service, and data protection law still treats you as a child until you turn 18. That means some things you are entitled to expect from us, and which we do. We do not show you advertising. We do not sell information about you. We do not build a profile of you to decide what you see. What you write in the app is private to you, apart from the material we send to an AI provider to generate a reply, which Section 5a describes in full.

You can export your records, or delete your account, from Settings at any time, without asking us. If anything in this policy is unclear, email hello@thepeachylifecompany.com and we will explain it in plain terms.

A note on crisis content. The Service is not a crisis service and is not a substitute for professional help. Section 15 lists free confidential helplines. If the app detects content suggesting a risk to your safety, it shows you those resources and records that it did so. Section 7 explains how long that record is kept.

14. Cookies and Tracking Technologies

Our website (thepeachylifecompany.com) uses Cloudflare Web Analytics for analytics, which is cookieless and does not track individual users. We do not use advertising cookies, tracking pixels, or any cross-site tracking technologies on our website. No cookie consent banner is required.

The mobile app does not use advertising cookies. Firebase Authentication and Firestore use technical tokens stored on your device to maintain your login session. These are strictly necessary for the app to function.

15. Mental Health Disclaimer

The Peachy Life is a general-purpose mental fitness and wellbeing tool designed to support self-reflection and healthy habits. It is not:

  • A medical device or clinical diagnostic tool.
  • A substitute for professional psychological, psychiatric, or medical advice, diagnosis, or treatment.
  • A crisis service or emergency intervention resource.

If you are experiencing a mental health crisis, thoughts of self-harm, or need urgent support, please reach out to a qualified health professional or contact emergency services. Crisis support resources in key regions:

  • Australia: Lifeline — 13 11 14 | Beyond Blue — 1300 22 4636
  • UK: Samaritans — 116 123 | Crisis Text Line — Text SHOUT to 85258
  • USA: 988 Suicide & Crisis Lifeline — call or text 988

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes:

  • We will update the "Last updated" date at the top of this page.
  • For material changes (changes that significantly affect how we use your data or your rights), we will provide notice through the app and, where required by law, seek your renewed consent before the changes take effect.
  • For minor or administrative changes, updating this page is sufficient notice.

Continued use of the Service after a policy update constitutes acceptance of the updated policy, to the extent permitted by applicable law.

Each version of this policy carries a version date at the top of the page. When you accept this policy in the app we record which version you accepted, so we can tell you later exactly which document you agreed to. Section 2.1b explains the limits of the records we hold for acceptances before 25 August 2026.

We keep previous versions of this policy and will provide any of them on request. Email hello@thepeachylifecompany.com with the version date you want.

17. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:

The Peachy Life Company
Sydney, New South Wales, Australia
Email: hello@thepeachylifecompany.com

We aim to respond to all privacy-related enquiries within 30 days. If you are not satisfied with our response, you have the right to escalate to the relevant supervisory authority for your jurisdiction (see Sections 10 and 11 for contact details).