PeachFit Privacy Policy

Effective date: July 2, 2026

1. Overview

Ingbo Company ("we," "us," or the "Company") operates the PeachFit mobile application (the "Service"). We respect your privacy. This Privacy Policy explains how we handle personal information in connection with applicable data protection laws, including the Personal Information Protection Act of the Republic of Korea ("PIPA") and relevant laws in the regions where the Service is offered.

In this Policy, "personal information" means information that identifies, relates to, or can reasonably be linked to an individual. Some laws refer to similar information as "personal data."

This Privacy Policy explains what information we collect, how we use it, whom we share it with, how long we keep it, and the rights and choices you have. It applies to your use of the PeachFit app on iOS and Android.

2. Information We Collect

We collect only the information needed to operate the Service. You can use core features of the Service without registering with an email address, Google, or Apple (anonymous use). In that case, Firebase creates a user identifier (UID), and we process the activity and preference information described below without an email address.

2.1 Account and profile information (stored on our servers)

When you create or use an account, we store the following in our database (Google Cloud Firestore):

2.2 Workout records synced to our servers

If you are signed in with a non-anonymous account, your workout records are saved on your device first and then synced to our servers so that your records are backed up and can be restored when you sign in again. Synced workout records include:

Workout records are not synced for anonymous users; for anonymous users these records remain on the device only. Pre-workout condition inputs and survey responses are never synced — see Sections 2.5 and 3.

2.3 Authentication and security information (processed by our service provider)

Sign-in is handled through Firebase Authentication, a Google service. In that process, our service provider processes information such as your email address, password, IP address, device and browser information, and authentication records. If you sign in with Google or Apple, authentication credentials issued by those providers are also processed. Passwords are processed by Firebase Authentication for authentication purposes only; we never store or view your password in plain text.

2.4 Support inquiries

If you contact us by email, we process your email address, the contents of your inquiry, and our response records.

2.5 Information stored only on your device

The following information is stored only in local storage on your device and is not transmitted to our servers. We do not receive it on our servers or have server-side access to it. It is normally removed from your device when you delete the app or clear the app's data on your device:

Your device or platform backup settings may affect copies controlled by your device platform provider; PeachFit does not receive those backups.

3. Health-Related Information

Some information handled by the Service relates to your health and fitness:

We do not use health-related information for advertising, we do not sell it, and we do not share it with third parties except as described in Section 6.

4. How We Use Information

We use the information described above for the following purposes:

  1. Account creation and management: sign-up and sign-in (including email, Google Sign-In, and Sign in with Apple), account identification, and account deletion
  2. Providing the Service: providing workout routines, workout records and statistics, and recommendation results based on the information you enter
  3. Sync and backup: backing up signed-in users' workout records and restoring them across sign-ins and devices
  4. Preferences: displaying the Service in your preferred language and region format
  5. Customer support: receiving inquiries, verifying facts, and responding
  6. Service security: user authentication and prevention of fraudulent use (handled through security features provided by our service provider during authentication)
  7. Purchases and subscriptions: activating, verifying, and managing PeachFit PRO subscriptions and related entitlements

We do not use your information for advertising or marketing profiling, and we do not sell your personal information.

5. Purchases and Subscriptions

The Service offers an optional paid subscription (PeachFit PRO). Purchases are processed by Apple (App Store) or Google (Google Play) under their own terms and privacy policies. We do not receive or store your full payment card details. To activate and manage your subscription, we process purchase and entitlement information such as your subscription product, status (active, trial, expired), transaction or receipt identifiers where applicable, and purchase/expiration timestamps, linked to your account identifier or app user identifier. Deleting your PeachFit account does not automatically cancel an active subscription. Subscription cancellation and refunds are handled through your App Store or Google Play account settings.

6. Sharing and Disclosure

We do not sell your personal information. We disclose personal information only as described in this Policy:

  1. To service providers that process information on our behalf to operate the Service, as described in Section 7
  2. When you have given prior consent
  3. When disclosure is required or permitted by law (for example, in response to a lawful request by a competent authority)

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising or targeted advertising.

7. Service Providers (Processing Outsourcing)

We use the following service providers to process information on our behalf to operate the Service. We supervise our service providers in accordance with applicable law and our contracts with them, and they are expected to process personal information only for the tasks described below or as otherwise permitted by our agreement with them.

Service provider Outsourced task Information processed Retention
Google LLC User authentication and account management via Firebase Authentication Email address, UID, password, IP address, device and browser information, authentication records Until account deletion, then per the provider's deletion schedule
Google LLC Storage of account, profile, preference, and synced workout record data via Cloud Firestore UID, email, sign-in method, anonymous flag, nickname, account activity timestamps, onboarding completion, preferred language/region, synced workout records (Section 2.2) Until account deletion
RevenueCat, Inc. In-app subscription entitlement verification and purchase/restore state management App user identifier (UID), subscription product, subscription status, transaction/receipt identifiers, purchase and expiration timestamps Until subscription ends or account deletion, except where retention is required or permitted by laws relating to payment, refunds, disputes, taxes, accounting, or app marketplace transactions

8. International Data Transfers

We are based in the Republic of Korea, and the Service's primary database (Cloud Firestore) is located in the Seoul region (asia-northeast3), Republic of Korea.

In all cases, transfers occur over encrypted connections, and our service provider (Google LLC) is bound by contractual data protection commitments and maintains technical and organizational security measures described in its public security and service documentation. The purposes and retention periods for transferred information are as described in this policy. If you do not wish your information to be transferred as described, you may choose not to create an account or to delete your account; however, account-based features (including sync) will not be available.

For users in Korea: the transfer of authentication information to the United States is based on Article 28-8(1)3 of PIPA (outsourced processing necessary for the performance of a contract), as further described in the Korean version of this policy.

9. Data Retention

Category Retention period
Account, profile, and preference information (Cloud Firestore) Until you delete your account
Synced workout records (Cloud Firestore) Until you delete your account
Purchase and subscription entitlement information Until your subscription ends or your account is deleted, unless a longer retention period is required or permitted by law for payment, refund, dispute, tax, accounting, or app store transaction purposes
Authentication and security information (processed by our service provider) Until deletion following your account deletion; removal from the provider's operational and backup systems may take additional time under the provider's (Firebase's) data deletion schedule
Support inquiry and response records 3 years after the inquiry is resolved
Information stored only on your device (Section 2.5) Not held by us; removed when you delete the app or clear the app's data

Where retention is required by law, we keep the relevant information separated from other personal information, use it only for the required purpose, and destroy it when the retention period ends. When personal information is no longer needed, we delete, de-identify, or otherwise destroy it without undue delay using reasonable methods intended to prevent ordinary recovery or unauthorized reuse. Information remaining in backup systems is deleted when the applicable backup cycle expires and is protected from other use until then.

10. Security

We take the following measures to protect your personal information:

  1. Encryption of data in transit (HTTPS/TLS)
  2. Access control through database security rules provided by our service provider (Firebase Security Rules), designed to help ensure that, through the app, authenticated users can access only their own user data, except for limited administrator or service access needed to operate, secure, or support the Service
  3. Minimization of administrator and service account privileges
  4. Passwords are processed only for authentication and are never stored in plain text

11. Your Rights and Choices

You have the following rights regarding your personal information, subject to applicable law:

If you choose not to provide information needed for a feature, or if you withdraw consent for optional information, the affected feature may be unavailable or limited. Core features remain available when you decline optional health-related survey or condition inputs.

How to exercise your rights: use the in-app options described in this policy, or email us at ingbbocp@gmail.com. You may also act through an authorized agent. To protect your information, we may need to verify your identity (or your agent's authority) before fulfilling a request — for example, by confirming through the email address registered to your account. We respond to requests without undue delay and within the time limits required by applicable law. If a request is limited or denied on grounds permitted by law, we will explain the reason. We will not discriminate against you for exercising your rights.

12. Account Deletion

Deleting the PeachFit app from your device does not by itself delete your PeachFit account or server-synced records. To delete your account and related server-synced information, use one of the methods below.

  1. In the app: go to the Records tab, open Settings (gear icon), and select Delete Account. This deletes your account, profile, preference information, and synced workout records from our servers, and clears locally stored workout records, survey responses, pre-workout condition inputs, and consent status on that device.
  2. If you can no longer use the app: email ingbbocp@gmail.com from, or including, the email address you signed up with, or the relay email shown in your account if you used Sign in with Apple and chose to hide your email. After identity verification, we complete deletion without undue delay, and no later than 10 business days after verification.

If you use PeachFit anonymously and do not have an email address linked to your account, please use the in-app deletion flow when possible; email deletion requests for anonymous accounts may require additional information to verify the account.

For step-by-step instructions, see our Account Deletion Guide: https://getpeachfit.github.io/account-deletion/en.html

13. Children's Privacy

The Service is intended for users aged 14 and older. We do not knowingly collect personal information from children under 14. If we learn that a child under 14 has created an account, we will delete the associated personal information without undue delay. If you believe a child under 14 has provided us personal information, please contact us at ingbbocp@gmail.com.

14. Cookies, Tracking, and Analytics

We do not use cookies, advertising identifiers (ADID/IDFA), advertising SDKs, behavioral analytics tools, or other tracking technologies for advertising or behavioral analysis. Device and connection information may be processed for security purposes during authentication (Section 2.3), but it is not used for advertising or behavioral analysis. Because we do not sell personal information, share it for cross-context behavioral advertising, or engage in targeted advertising, we do not offer a separate advertising-tracking opt-out. Browser or platform opt-out signals, such as Global Privacy Control, do not change our advertising practices because we do not use your information for those purposes.

15. Privacy Officer (Data Protection Officer)

We have designated the following person as our privacy officer and contact point for privacy matters, including as our data protection officer/contact for Singapore and privacy officer for New Zealand:

You can contact the privacy officer with any questions, concerns, or complaints about this policy or our handling of your personal information.

16. Region-Specific Disclosures

Republic of Korea

This policy is provided in Korean for users in Korea, structured according to PIPA. You have the rights described in Section 11 under PIPA (access, correction, deletion, suspension of processing, and withdrawal of consent). For dispute resolution or to report a privacy violation, you may contact: Personal Information Dispute Mediation Committee (1833-6972 / www.kopico.go.kr), KISA Personal Information Infringement Report Center (118 / privacy.kisa.or.kr), Supreme Prosecutors' Office Cyber Investigation Division (1301 / www.spo.go.kr), or the National Police Agency Cyber Bureau (182 / ecrm.police.go.kr).

United States

We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. Depending on your state, you may have rights to know/access, delete, and correct personal information, and the right not to receive discriminatory treatment for exercising your rights; you can exercise these rights as described in Section 11. Some health-related information described in Section 3 may be considered consumer health data under certain U.S. state laws, including the Washington My Health My Data Act. As described in Sections 2.5 and 3, health-related survey responses and pre-workout condition inputs are stored only on your device with your consent. We do not sell health-related information or share it for advertising.

Canada

We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA). You may request access to or correction of your personal information and may challenge our compliance by contacting our Privacy Officer (Section 15). If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.

Australia

We handle personal information consistently with the Australian Privacy Principles under the Privacy Act 1988. You may request access to or correction of your personal information via Section 11. If you have a complaint, please contact us first (Section 15); if you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).

New Zealand

We handle personal information in accordance with the Privacy Act 2020. Our designated Privacy Officer is listed in Section 15. You may request access to or correction of your personal information via Section 11, and you may complain to the Office of the Privacy Commissioner (privacy.org.nz) if you are not satisfied with our response.

Singapore

We handle personal data in accordance with the Personal Data Protection Act 2012 (PDPA). Our Data Protection Officer's contact details are provided in Section 15. You may withdraw consent, and request access to or correction of your personal data, as described in Section 11. If you withdraw consent, we will inform you of the likely consequences, such as the affected features becoming unavailable or limited.

Taiwan

We handle personal data in accordance with the Personal Data Protection Act (個人資料保護法). The categories of personal data we collect, the purposes of use, the period, area, and manner of use, and your rights are as described in this policy. Providing personal data is voluntary; if you choose not to provide certain data, the related features may be unavailable or limited (Section 11). You may exercise the rights of access and copies, supplementation or correction, cessation of collection, processing, or use, and deletion, as described in Section 11.

Hong Kong

We handle personal data in accordance with the Personal Data (Privacy) Ordinance (PDPO). Personal data is used only for the purposes stated in this policy or directly related purposes. You may request access to and correction of your personal data as described in Section 11, and you may contact the Office of the Privacy Commissioner for Personal Data (PCPD) with concerns.

Japan

We handle personal information in accordance with the Act on the Protection of Personal Information (APPI). The purposes of use are stated in Section 4. Your personal information is stored in the Republic of Korea and, for authentication, processed in the United States, as described in Section 8; Korea maintains a comprehensive personal information protection law (PIPA), and we take reasonable steps through contractual commitments and the safeguards described in Section 10 to protect personal information handled by our service provider. You may request disclosure, correction, cessation of use, and deletion of your personal information as described in Section 11.

17. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will announce them through the app or our website before they take effect, and we will make previous versions or a change history available where required or reasonably practicable. The current version is always accessible in the app and on our website.

18. Contact Us