MVPeak Privacy Policy

Last updated: June 2026

Overview

MVPeak is an AI-powered fitness and movement analysis platform operated by MVPeak (ABN 92 424 605

570), a business governed under the laws of Victoria, Australia. This Privacy Policy explains how we collect,

use, store, and protect your personal information in accordance with the Privacy Act 1988 (Cth) and the

Australian Privacy Principles (APPs).

By using MVPeak — including our web app, iOS app, Android app, or marketing site — you agree to the

practices described in this policy. If you do not agree, please discontinue use of the platform.

1. Information We Collect

1.1 Information you provide directly

● Name and email address when creating an account

● Date of birth, biological sex, height, weight, and fitness goals entered during onboarding

● Health and fitness data you submit — including exercise logs, meal logs, and form analysis media

(images and videos)

● Equipment images captured via the live equipment scanning feature — photos or video frames of gym

equipment captured through your device camera to generate program suggestions. Because this feature

is used in gym and fitness facility environments, captured images or footage may incidentally include

other people, facility signage, or surroundings present in frame. We do not use this footage to identify

other individuals, and it is processed for the sole purpose of equipment recognition.

● Payment information processed securely via Stripe — MVPeak does not store card details

● Communications you send to our support team

1.2 Information collected automatically

● Device identifiers, operating system, and app version

● IP address and approximate location (country/region level only)

● Usage data — features accessed, session duration, interaction patterns

● Crash reports and performance diagnostics

1.3 AI-generated and inferred data

MVPeak uses Google Gemini Vision to analyse exercise form from images and videos you submit. The

platform may infer fitness levels, movement patterns, and health trends from your usage data to personalise your

coaching experience. This inferred data is treated as personal information under this policy.

2. How We Use Your Information

● To provide, personalise, and improve the MVPeak platform and your AI coaching experience

● To generate personalised workout plans, meal plans, and exercise demonstrations

● To analyse your exercise form and provide movement feedback via AI

● To process payments and manage your subscription via Stripe

● To communicate with you about your account, updates, and support requests

● To send transactional emails (e.g. trial reminders, payment receipts, cancellation confirmations)

● To comply with our legal obligations under Australian law

● To detect fraud, security incidents, and protect the integrity of the platform

We do not use your personal information to train third-party AI models or sell your data to advertisers.

MVPeak products are ad-free.

3. Health and Sensitive Information

MVPeak collects and processes health-related information including fitness metrics, body measurements,

movement data, and media submitted for form analysis. Under the Privacy Act 1988, health information is

classified as sensitive information and is afforded a higher level of protection.

We collect this information only with your express consent, provided during onboarding. You may withdraw

consent at any time by deleting your account. Health information is used solely to power your personal coaching

experience and is not disclosed to third parties except as described in Section 5.

MVPeak is not a medical service. The platform provides general fitness and movement guidance only and

does not constitute medical advice, diagnosis, or treatment. Always consult a qualified health professional

before starting a new exercise programme, particularly if you have a pre-existing medical condition.

4. Data Storage and Security

Your data is stored on infrastructure located in Australia and the United States, including:

● Database: Neon PostgreSQL (encrypted at rest and in transit)

● File storage: Cloudflare R2 (images, videos, and AI-generated media)

● Authentication: Clerk (account credentials and session management)

● API infrastructure: Fly.io (Sydney region)

We implement industry-standard security measures including TLS encryption for all data in transit, access

controls, and regular security reviews. In the event of a data breach affecting your rights, we will notify you as

required by the Notifiable Data Breaches scheme under the Privacy Act 1988.

5. Disclosure of Your Information

We may share your information with the following third parties:

● Stripe — payment processing

● Google (Gemini API) — AI form analysis and content generation

● ElevenLabs — AI voice generation for coaching audio (text prompts only; no personal data

transmitted)

● Clerk — authentication and account management

● Cloudflare — file storage and CDN delivery

● Email service providers — transactional email delivery (e.g. Resend or equivalent)

We do not sell, rent, or trade your personal information to any third party. We may disclose information if

required by law, court order, or regulatory authority, or to protect the rights and safety of MVPeak, our users, or

the public.

Where you subscribe via the Apple App Store or Google Play, Apple or Google process your payment

information as an independent controller under their own privacy policies; MVPeak does not receive or

store your card details in these cases.

6. Your Rights Under Australian Privacy Law

Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to:

● Access your personal information held by MVPeak

● Correct inaccurate or out-of-date personal information

● Request deletion of your personal information (subject to legal retention obligations)

● Withdraw consent to the collection and use of sensitive health information

● Complain to the Office of the Australian Information Commissioner (OAIC) if you believe your

privacy rights have been breached

To exercise any of these rights, contact us at legal@mvpeak.app. We will respond within 30 days of receiving

your request.

7. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. If

you delete your account, we will delete or anonymise your personal information within 90 days, except where

required by law (e.g. financial transaction records retained for 7 years under Australian taxation law).

Media submitted for AI form analysis (images and videos) is retained for the duration of your account and

deleted upon account closure unless you request earlier deletion.

8. Cookies and Tracking Technologies

Our web app and marketing site use cookies and similar technologies for authentication, session management,

and analytics. We do not use tracking cookies for advertising purposes. You can control cookie settings through

your browser. Disabling cookies may limit certain functionality of the platform.

9. Children's Privacy

MVPeak is intended for users aged 16 and over. We do not knowingly collect personal information from anyone

under the age of 16. Users aged 16–17 must have obtained prior consent from a parent or legal guardian before

creating an account. By registering on behalf of a 16–17 year old, the parent or guardian confirms they have

read and accepted these Terms, consent to the collection and use of the minor's personal information as

described in this Privacy Policy, and accept responsibility for the minor's activity on the platform.

If you are a parent or guardian and believe your child under 16 has provided us with personal information

without your consent, please contact us immediately at legal@mvpeak.app and we will take prompt steps to

delete it.

10. International Data Transfers

Some of our third-party service providers are based outside Australia. Where personal information is transferred

overseas, we take reasonable steps to ensure it receives comparable protection to that required under the

Australian Privacy Principles, including through contractual data processing agreements with our service

providers.

11. Singapore Users — Personal Data Protection Act (PDPA)

If you are located in Singapore, the following provisions apply in addition to the rest of this Privacy Policy, to

the extent required by the Personal Data Protection Act 2012 (Singapore) (“PDPA”):

● Consent. We collect, use, and disclose your personal data based on your consent, given during

onboarding and at other points where new categories of data are collected. Where the PDPA permits us

to rely on an exception to consent (for example, for fraud prevention or business improvement

purposes), we do so only within the scope permitted by law.

● Purpose limitation. We only collect, use, and disclose your personal data for the purposes described in

this Privacy Policy, or other purposes you have been notified of and have not objected to.

● Data Protection Officer. MVPeak has designated a Data Protection Officer responsible for our

compliance with the PDPA. You can contact our Data Protection Officer at legal@mvpeak.app.

● Access and correction. In addition to the rights described in Section 6, Singapore users may request

access to, or correction of, their personal data held by MVPeak. We aim to respond to such requests

within 30 days.

● Overseas transfer. Your personal data may be transferred to, and stored in, Australia and the United

States as described in Section 4. Before doing so, we take steps to ensure the recipient is bound by

legally enforceable obligations to protect your personal data to a standard comparable to the protection

under the PDPA, including through contractual data processing terms with our service providers.

● Data breach notification. Where a data breach involving your personal data is assessed to be

notifiable under the PDPA (broadly, where it is likely to result in significant harm to affected

individuals, or affects 500 or more individuals), we will notify the Personal Data Protection

Commission (PDPC) and affected individuals as required by law.

● Retention. Personal data is retained in accordance with Section 7 of this Policy, and we cease retaining

it once it is reasonable to assume the purpose for which it was collected is no longer being served and

retention is no longer necessary for legal or business purposes.

● Complaints. If you believe MVPeak has not complied with the PDPA, you may lodge a complaint

with the Personal Data Protection Commission of Singapore (pdpc.gov.sg).

12. New Zealand Users — Privacy Act 2020

If you are located in New Zealand, the following provisions apply in addition to the rest of this Privacy Policy,

to the extent required by the Privacy Act 2020 (NZ):

● Information Privacy Principles. We collect, use, hold, and disclose your personal information in

accordance with the 13 Information Privacy Principles (IPPs) set out in the Privacy Act 2020, covering

matters such as the manner of collection, storage and security, access and correction, and limits on use

and disclosure.

● Health Information Privacy Code. Because MVPeak collects health and fitness-related information

(see Section 3), we also have regard to the Health Information Privacy Code 2020, which applies

additional rules to the collection, storage, and disclosure of health information about identifiable

individuals in New Zealand.

● Overseas disclosure. Your personal information may be transferred to, and stored in, Australia and the

United States as described in Section 4. Before doing so, we take reasonable steps to ensure the

overseas recipient is subject to privacy safeguards comparable to those in the Privacy Act 2020 —

including through contractual data processing terms with our service providers — or we otherwise rely

on an applicable exception under IPP 12, such as your express authorisation.

● Access and correction. In addition to the rights described in Section 6, New Zealand users have the

right under IPPs 6 and 7 to request access to, and correction of, personal information we hold about

them. We aim to respond to such requests within 20 working days, in line with the timeframe set out in

the Act.

● Notifiable privacy breaches. Where a privacy breach involving your personal information has caused,

or is likely to cause, serious harm, we will notify the Privacy Commissioner and affected individuals as

soon as practicable, in accordance with the notifiable privacy breach requirements of the Privacy Act

2020.

● Retention. Personal information is retained in accordance with Section 7 of this Policy. We do not

keep personal information for longer than is required for the purpose it was collected, consistent with

IPP 9.

● Complaints. If you believe MVPeak has not complied with the Privacy Act 2020, you may contact us

in the first instance at legal@mvpeak.app, or lodge a complaint with the Office of the Privacy

Commissioner (privacy.org.nz).

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via

email or an in-app notification at least 14 days before the changes take effect. Continued use of MVPeak after

the effective date constitutes acceptance of the updated policy.

14. Contact Us

Business MVPeak

ABN 92 424 605 570

Governing law Victoria, Australia

Email legal@mvpeak.app

Response time Within 30 days for privacy requests

Complaints (Australia) Office of the Australian Information Commissioner

(OAIC) — oaic.gov.au

Complaints (New Zealand) Office of the Privacy Commissioner —

privacy.org.nz

Complaints (Singapore) Personal Data Protection Commission —

pdpc.gov.sg