Privacy Policy

Last updated: August 9, 2026

1. Who is responsible for your data

The data controller is Hamza Ben Allal, sole proprietor, registered under SIREN number 979 496 585, based at 3 allée Philippe Polderman, 31400 Toulouse, France.

For any question about your data, write to hello@peekly.app.

This page is an English translation provided for convenience. In the event of any discrepancy, the French version governs.

2. Data we collect

Account data. Your email address and, if you sign in with Google, the name associated with your Google account. If you create an account by email, your password is encrypted by our authentication provider and is never accessible to us in plain text.

Service usage data. The apps you track, your favorites and folders, your notification preferences, and your subscription plan. This data exists solely to provide you the service.

Payment data. Payments are processed by Stripe. We never receive or store your card number. We only keep a Stripe customer identifier, your subscription status, and your billing history.

Technical data. Our hosting providers log connection data (IP address, browser type, requested pages) for security and troubleshooting purposes.

3. Audience measurement

To understand our traffic and improve the product, we use an anonymous, cookieless audience measurement tool (Vercel Analytics): it counts page views and visit sources without setting a tracking cookie or personally identifying visitors. Being anonymous and cookieless, it doesn't require a consent banner.

We also use Microsoft Clarity to record, in anonymized form, how you navigate our pages (movements, clicks) to improve usability. Clarity masks text and input fields by default: your passwords, your email, and what you type are not recorded. This tool sets cookies for this purpose, which our banner informs you about.

We use the Meta and X pixels and their server-side conversion APIs to measure advertising campaign results and attribute visits and conversions. Depending on the enabled settings, Meta may receive hashed identifiers such as an email address, name, or country to improve matching with its users. These tools may set cookies or use browser identifiers.

We do not sell your data, we do not rent it, and we do not pass it on to any data broker or ad network.

4. Why we process this data

To perform our contract with you: creating and securing your account, giving you access to the service, managing your subscription and invoices.

To comply with our legal obligations: retaining accounting records and invoices.

For our legitimate interest: preventing fraud and abuse, maintaining the security and availability of the service.

5. Who has access to your data

We use technical service providers who act solely on our instructions:

Supabase (database and authentication, hosted in the European Union, Ireland region) · Vercel (site hosting and anonymous audience measurement) · Microsoft Clarity (anonymized session recording) · Meta and X (advertising measurement and attribution) · Cloudflare R2 (image storage) · Cloudflare Turnstile (anti-bot protection for the login and signup forms) · Google (sign-in via Google account, if you choose that option) · Stripe (payment and billing).

Anti-bot protection (Cloudflare Turnstile). Our login and signup forms are protected by Cloudflare Turnstile, which analyzes a minimal set of technical signals (browser behavior, IP address) to distinguish a human visitor from a bot, without tracking you or showing ads. How it works is described in the Turnstile Privacy Addendum and Cloudflare's Privacy Policy.

Some of these providers are based outside the European Union. These transfers are governed by the European Commission's standard contractual clauses or a recognized adequacy mechanism.

6. How long we keep it

Account and usage data: for as long as your account is active, then deleted within 30 days of closing it.

Invoices and accounting records: 10 years, a duration required by French commercial law.

Technical logs: 12 months maximum.

7. Your rights

Under the General Data Protection Regulation, you have the right to access, correct, erase, restrict, object to, and port your data. You can exercise these rights at any time by writing to hello@peekly.app. We respond within one month at most.

If our response doesn't satisfy you, you can file a complaint with the French data protection authority, the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, 75007 Paris, France.

8. California residents

If you live in California, the law gives you the right to know which categories of personal data are collected and for what purposes, to request their deletion, and not to face discriminatory treatment for exercising these rights.

We do not sell or share your personal data within the meaning of the California Consumer Privacy Act. To exercise your rights, use the same contact address as above.

9. Data about the apps we analyze

Peekly analyzes mobile apps using public sources: app store rankings, product pages published by their developers, and public ad libraries. The download and revenue figures shown are estimates calculated by our models, not data reported by the developers concerned.

This information concerns apps and companies, not individuals. If you're a developer and want to report an error, write to us.

10. Security

Exchanges with Peekly are encrypted (HTTPS). Access to data is segmented per account and passwords are stored in an irreversibly encrypted form. No system being infallible, we would inform you without delay in the event of a data breach likely to create a risk to your rights.

11. Changes

This policy may evolve along with the service. The last update date appears at the top of this page. In the event of a substantial change, we will notify you by email.