MVPeak Privacy Policy
Last updated: June 2026
Overview
MVPeak is an AI-powered fitness and movement analysis platform operated by MVPeak (ABN 92 424 605
570), a business governed under the laws of Victoria, Australia. This Privacy Policy explains how we collect,
use, store, and protect your personal information in accordance with the Privacy Act 1988 (Cth) and the
Australian Privacy Principles (APPs).
By using MVPeak — including our web app, iOS app, Android app, or marketing site — you agree to the
practices described in this policy. If you do not agree, please discontinue use of the platform.
1. Information We Collect
1.1 Information you provide directly
● Name and email address when creating an account
● Date of birth, biological sex, height, weight, and fitness goals entered during onboarding
● Health and fitness data you submit — including exercise logs, meal logs, and form analysis media
(images and videos)
● Equipment images captured via the live equipment scanning feature — photos or video frames of gym
equipment captured through your device camera to generate program suggestions. Because this feature
is used in gym and fitness facility environments, captured images or footage may incidentally include
other people, facility signage, or surroundings present in frame. We do not use this footage to identify
other individuals, and it is processed for the sole purpose of equipment recognition.
● Payment information processed securely via Stripe — MVPeak does not store card details
● Communications you send to our support team
1.2 Information collected automatically
● Device identifiers, operating system, and app version
● IP address and approximate location (country/region level only)
● Usage data — features accessed, session duration, interaction patterns
● Crash reports and performance diagnostics
1.3 AI-generated and inferred data
MVPeak uses Google Gemini Vision to analyse exercise form from images and videos you submit. The
platform may infer fitness levels, movement patterns, and health trends from your usage data to personalise your
coaching experience. This inferred data is treated as personal information under this policy.
2. How We Use Your Information
● To provide, personalise, and improve the MVPeak platform and your AI coaching experience
● To generate personalised workout plans, meal plans, and exercise demonstrations
● To analyse your exercise form and provide movement feedback via AI
● To process payments and manage your subscription via Stripe
● To communicate with you about your account, updates, and support requests
● To send transactional emails (e.g. trial reminders, payment receipts, cancellation confirmations)
● To comply with our legal obligations under Australian law
● To detect fraud, security incidents, and protect the integrity of the platform
We do not use your personal information to train third-party AI models or sell your data to advertisers.
MVPeak products are ad-free.
3. Health and Sensitive Information
MVPeak collects and processes health-related information including fitness metrics, body measurements,
movement data, and media submitted for form analysis. Under the Privacy Act 1988, health information is
classified as sensitive information and is afforded a higher level of protection.
We collect this information only with your express consent, provided during onboarding. You may withdraw
consent at any time by deleting your account. Health information is used solely to power your personal coaching
experience and is not disclosed to third parties except as described in Section 5.
MVPeak is not a medical service. The platform provides general fitness and movement guidance only and
does not constitute medical advice, diagnosis, or treatment. Always consult a qualified health professional
before starting a new exercise programme, particularly if you have a pre-existing medical condition.
4. Data Storage and Security
Your data is stored on infrastructure located in Australia and the United States, including:
● Database: Neon PostgreSQL (encrypted at rest and in transit)
● File storage: Cloudflare R2 (images, videos, and AI-generated media)
● Authentication: Clerk (account credentials and session management)
● API infrastructure: Fly.io (Sydney region)
We implement industry-standard security measures including TLS encryption for all data in transit, access
controls, and regular security reviews. In the event of a data breach affecting your rights, we will notify you as
required by the Notifiable Data Breaches scheme under the Privacy Act 1988.
5. Disclosure of Your Information
We may share your information with the following third parties:
● Stripe — payment processing
● Google (Gemini API) — AI form analysis and content generation
● ElevenLabs — AI voice generation for coaching audio (text prompts only; no personal data
transmitted)
● Clerk — authentication and account management
● Cloudflare — file storage and CDN delivery
● Email service providers — transactional email delivery (e.g. Resend or equivalent)
We do not sell, rent, or trade your personal information to any third party. We may disclose information if
required by law, court order, or regulatory authority, or to protect the rights and safety of MVPeak, our users, or
the public.
Where you subscribe via the Apple App Store or Google Play, Apple or Google process your payment
information as an independent controller under their own privacy policies; MVPeak does not receive or
store your card details in these cases.
6. Your Rights Under Australian Privacy Law
Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to:
● Access your personal information held by MVPeak
● Correct inaccurate or out-of-date personal information
● Request deletion of your personal information (subject to legal retention obligations)
● Withdraw consent to the collection and use of sensitive health information
● Complain to the Office of the Australian Information Commissioner (OAIC) if you believe your
privacy rights have been breached
To exercise any of these rights, contact us at legal@mvpeak.app. We will respond within 30 days of receiving
your request.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. If
you delete your account, we will delete or anonymise your personal information within 90 days, except where
required by law (e.g. financial transaction records retained for 7 years under Australian taxation law).
Media submitted for AI form analysis (images and videos) is retained for the duration of your account and
deleted upon account closure unless you request earlier deletion.
8. Cookies and Tracking Technologies
Our web app and marketing site use cookies and similar technologies for authentication, session management,
and analytics. We do not use tracking cookies for advertising purposes. You can control cookie settings through
your browser. Disabling cookies may limit certain functionality of the platform.
9. Children's Privacy
MVPeak is intended for users aged 16 and over. We do not knowingly collect personal information from anyone
under the age of 16. Users aged 16–17 must have obtained prior consent from a parent or legal guardian before
creating an account. By registering on behalf of a 16–17 year old, the parent or guardian confirms they have
read and accepted these Terms, consent to the collection and use of the minor's personal information as
described in this Privacy Policy, and accept responsibility for the minor's activity on the platform.
If you are a parent or guardian and believe your child under 16 has provided us with personal information
without your consent, please contact us immediately at legal@mvpeak.app and we will take prompt steps to
delete it.
10. International Data Transfers
Some of our third-party service providers are based outside Australia. Where personal information is transferred
overseas, we take reasonable steps to ensure it receives comparable protection to that required under the
Australian Privacy Principles, including through contractual data processing agreements with our service
providers.
11. Singapore Users — Personal Data Protection Act (PDPA)
If you are located in Singapore, the following provisions apply in addition to the rest of this Privacy Policy, to
the extent required by the Personal Data Protection Act 2012 (Singapore) (“PDPA”):
● Consent. We collect, use, and disclose your personal data based on your consent, given during
onboarding and at other points where new categories of data are collected. Where the PDPA permits us
to rely on an exception to consent (for example, for fraud prevention or business improvement
purposes), we do so only within the scope permitted by law.
● Purpose limitation. We only collect, use, and disclose your personal data for the purposes described in
this Privacy Policy, or other purposes you have been notified of and have not objected to.
● Data Protection Officer. MVPeak has designated a Data Protection Officer responsible for our
compliance with the PDPA. You can contact our Data Protection Officer at legal@mvpeak.app.
● Access and correction. In addition to the rights described in Section 6, Singapore users may request
access to, or correction of, their personal data held by MVPeak. We aim to respond to such requests
within 30 days.
● Overseas transfer. Your personal data may be transferred to, and stored in, Australia and the United
States as described in Section 4. Before doing so, we take steps to ensure the recipient is bound by
legally enforceable obligations to protect your personal data to a standard comparable to the protection
under the PDPA, including through contractual data processing terms with our service providers.
● Data breach notification. Where a data breach involving your personal data is assessed to be
notifiable under the PDPA (broadly, where it is likely to result in significant harm to affected
individuals, or affects 500 or more individuals), we will notify the Personal Data Protection
Commission (PDPC) and affected individuals as required by law.
● Retention. Personal data is retained in accordance with Section 7 of this Policy, and we cease retaining
it once it is reasonable to assume the purpose for which it was collected is no longer being served and
retention is no longer necessary for legal or business purposes.
● Complaints. If you believe MVPeak has not complied with the PDPA, you may lodge a complaint
with the Personal Data Protection Commission of Singapore (pdpc.gov.sg).
12. New Zealand Users — Privacy Act 2020
If you are located in New Zealand, the following provisions apply in addition to the rest of this Privacy Policy,
to the extent required by the Privacy Act 2020 (NZ):
● Information Privacy Principles. We collect, use, hold, and disclose your personal information in
accordance with the 13 Information Privacy Principles (IPPs) set out in the Privacy Act 2020, covering
matters such as the manner of collection, storage and security, access and correction, and limits on use
and disclosure.
● Health Information Privacy Code. Because MVPeak collects health and fitness-related information
(see Section 3), we also have regard to the Health Information Privacy Code 2020, which applies
additional rules to the collection, storage, and disclosure of health information about identifiable
individuals in New Zealand.
● Overseas disclosure. Your personal information may be transferred to, and stored in, Australia and the
United States as described in Section 4. Before doing so, we take reasonable steps to ensure the
overseas recipient is subject to privacy safeguards comparable to those in the Privacy Act 2020 —
including through contractual data processing terms with our service providers — or we otherwise rely
on an applicable exception under IPP 12, such as your express authorisation.
● Access and correction. In addition to the rights described in Section 6, New Zealand users have the
right under IPPs 6 and 7 to request access to, and correction of, personal information we hold about
them. We aim to respond to such requests within 20 working days, in line with the timeframe set out in
the Act.
● Notifiable privacy breaches. Where a privacy breach involving your personal information has caused,
or is likely to cause, serious harm, we will notify the Privacy Commissioner and affected individuals as
soon as practicable, in accordance with the notifiable privacy breach requirements of the Privacy Act
2020.
● Retention. Personal information is retained in accordance with Section 7 of this Policy. We do not
keep personal information for longer than is required for the purpose it was collected, consistent with
IPP 9.
● Complaints. If you believe MVPeak has not complied with the Privacy Act 2020, you may contact us
in the first instance at legal@mvpeak.app, or lodge a complaint with the Office of the Privacy
Commissioner (privacy.org.nz).
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via
email or an in-app notification at least 14 days before the changes take effect. Continued use of MVPeak after
the effective date constitutes acceptance of the updated policy.
14. Contact Us
Business MVPeak
ABN 92 424 605 570
Governing law Victoria, Australia
Email legal@mvpeak.app
Response time Within 30 days for privacy requests
Complaints (Australia) Office of the Australian Information Commissioner
(OAIC) — oaic.gov.au
Complaints (New Zealand) Office of the Privacy Commissioner —
privacy.org.nz
Complaints (Singapore) Personal Data Protection Commission —
pdpc.gov.sg