Controller
MyPeakYears is a Dutch sole proprietorship registered with the Netherlands Chamber of Commerce (KvK) under number 75473097 and is responsible for processing within the website and iOS app. Send privacy questions and requests to support@mypeakyears.com.
Data we process
We process account data, profile data, goals, check-ins, sleep, steps, cardio, strength, protein target, mood, notes, biomarkers, Academy progress, behaviour plans, barriers and reflections you enter. If you separately enable Cycle context, we additionally process minimal cycle events and the related consent record. After your separate iOS permission, the iPhone app may process permitted Apple Health data. We also process limited technical data needed for security, error investigation and reliable operation.
Health and behaviour data
Data about your health and health patterns can be special-category personal data. We request separate explicit consent during onboarding to process these data for personalised coaching. Cycle context has an additional opt-in that is off by default. You can withdraw consent; features that rely on the data may then stop working or become less personalised.
Purposes and legal bases
We process account management, service access and subscriptions to perform the contract. We rely on your explicit consent for health data used for personalised coaching, including optional cycle context. Security, fraud prevention and limited technical diagnostics may rely on our legitimate interests. We process statutory administration where a legal obligation applies.
Coaching emails and commercial information
Weekly coaching and restart emails are off by default. You can enable them yourself and disable them later. A weekly email for a free account may also include information about Premium, so we do not use pre-ticked consent. Every coaching email includes a direct unsubscribe option.
Apple Health
Apple Health is used only after separate permission in iOS. Permitted steps, sleep and recorded workouts can automatically add to your check-in when synchronisation is enabled; resting heart rate, HRV and VO₂max provide additional context. If Cycle context is separately enabled, menstrual flow only can be read after a separate HealthKit permission for minimal cycle context. Missing values remain unknown and manual corrections are protected. You can withdraw access per data type in iOS.
Website analytics and cookies
On public website pages, we use Google Analytics only after you have given permission. The Google tag is not loaded before consent. We do not measure signed-in coaching or health routes and do not send account data, health data or user IDs to Google Analytics. With consent, Google may process technical and usage data such as public pages visited, device and browser information, campaign parameters and analytics cookies. You can change your choice at any time through ‘Cookie settings’ in the footer.
Providers and recipients
MyPeakYears uses providers including Vercel, Supabase, Stripe, Resend and — only after consent — Google Analytics for hosting, authentication, database storage, payments, email delivery and website analytics. They process data only for their agreed service and under applicable processor or data-protection terms. Apple processes App Store purchases and Apple Health access under Apple's terms.
Transfers outside the EEA
Some providers may process data outside the European Economic Area. Where this occurs, we use applicable safeguards such as an adequacy decision or standard contractual clauses where required by the GDPR.
No sale or health advertising
We do not sell personal, health or behaviour data. Health and behaviour data is not used to target third-party advertising.
Retention
Account and coaching data is generally retained while your account is active. Cycle events are additionally deleted when you disable Cycle context. After account deletion, product data is removed except for limited legal, security or dispute purposes. Consent records and relevant delivery history may be kept longer to demonstrate lawful processing or communication. Payment and invoice records may be retained as long as tax or other legal rules require.
Your rights
To the extent the GDPR grants them in your situation, you have rights to information, access, rectification, erasure, restriction, data portability and objection. Where processing is based on consent, you may withdraw that consent at any time without affecting earlier lawful processing. Send requests to support@mypeakyears.com.
Complaint to a regulator
If you believe your personal data is not handled properly, you may complain to the Dutch Data Protection Authority or the competent data-protection authority where you live or work. This does not require you to give up other legal rights.
Scores and automated processing
MyPeakYears uses calculations to show coaching scores, trends and recommendations. Cycle context does not change the Healthspan Score. These outputs are not solely automated decisions producing legal or similarly significant effects, and are not medical diagnosis or treatment.
Age
MyPeakYears is intended for adults aged 18 and over. The service is not designed to collect children's health data.
Security
We use access control, encrypted connections, row-level security, restricted server privileges and separation between user data and server-only data. Optional cycle data is stored in separate owner-isolated tables. No system is risk-free; security incidents are handled under applicable legal obligations.
Changes
If this Privacy Policy changes materially, we update the date and notify users where reasonably required. For new purposes requiring consent, we request appropriate consent again.
Apple Health
After your separate iOS permission, MyPeakYears can read steps, sleep data, recorded workouts, resting heart rate, heart-rate variability (HRV) and VO₂max. If you separately enable Cycle context and grant Health access for it, the iPhone app can additionally read menstrual flow only. Other reproductive HealthKit types are not requested for Cycle context. Steps, sleep duration and recognised cardio or strength workouts can automatically add to your daily check-in. Missing HealthKit data is not entered as zero or ‘no’. Resting heart rate, HRV and VO₂max provide context on the Apple Health screen and are not silently added as extra Healthspan Score components. The app does not write data back to Apple Health.
If you enable automatic synchronisation, the app reads permitted data again when you open or return to the app. HealthKit may also deliver changes in the background; iOS decides when such background work actually runs. A manually adjusted check-in value is not automatically overwritten while it differs from the last value imported from HealthKit.
HealthKit data is not sold or used for advertising, marketing or use-based data mining. You manage access per data type through the iOS privacy settings.
Optional cycle context
Cycle context is off by default and is only offered for a profile where female is selected. Enabling it requires separate explicit consent. MyPeakYears stores only the consent and minimal cycle events, such as a period start or end and whether the source was manual or Apple Health. The data is used as context for recovery and daily behaviour coaching, not for fertility, contraception or medical predictions and not as part of the Healthspan Score.
You can disable Cycle context at any time. Stored cycle events are then removed from MyPeakYears; data already held in Apple Health remains under your control in Apple Health.