Privacy Policy
Updated September 14, 2026
Peach is operated by Melvin Zaid, an individual based in California, United States ("Peach," "we," or "us"). This notice explains how we handle personal information in the Peach app, our websites, and communications with us. It also covers information about other people that users submit.
Eligibility and AI processing
Peach is for ages 16 and up. Remi is an AI companion, not a person. Companion chatbots may not be suitable for some minors. We do not ask your age or date of birth, and we do not verify identity. If you tell Remi your own current age in conversation, we record a safety marker and its date so the protections below can apply.
Before your first message or screenshot can reach Remi, Peach asks you to explicitly allow AI processing: a confirmation names OpenAI and Vercel and offers Allow AI processing or Not now. Choosing Not now keeps that processing off, sends nothing, and does not create or affect an account. An existing account whose accepted policy version has lapsed sees a fuller confirmation screen with the same choice. Once allowed, submitting a message or a screenshot is what sends that content to our AI providers, together with relevant saved context needed to respond. You choose what to submit and you can stop submitting at any time. To stop further processing, stop submitting content and contact us or request account deletion; the app’s memory and deletion controls remain available to you. Stopping does not automatically erase earlier processing or records retained for a permitted purpose.
Information we collect
- Account and choices: temporary or permanent account identifiers; contact and authentication information from your selected sign-in method; display name, onboarding answers, writing preferences, and the terms and policy version you accepted with the date you accepted it. We do not ask your age. Accounts created under earlier versions may still hold the adult-eligibility declaration and birth year those versions asked for; we keep those existing records, and we no longer ask for either. If you tell Remi your own age in conversation, we record only a safeguard marker and its date so the age-related protections in our Terms can apply; the message itself stays in your conversation history like any other message. Apple sign-in may supply a private relay email. When available, we retain an encrypted Apple authorization token so we can revoke Peach’s sign-in authorization when you delete your account.
- Conversations and saved information: submitted messages, screenshots and context; extracted text, generated replies and interpretations; people and situation labels, goals, Files, conversation history, remembered details, writing samples, your corrections and updates about outcomes.
- Safety information: automated assessments used to route a request to appropriate support, and a situation-level indicator that can pause companion reminders. These assessments can be wrong and are not diagnoses.
- Reports and support: the report category, related feature or response identifiers, comments and any example you explicitly choose to share; messages and contact details you send to support. Privacy requests include a tracking record, a hashed receipt, and any correction details needed to address your request. Prepared data copies and exceptional correction details are encrypted in our database.
- Purchases and usage: subscription status, purchase and transaction identifiers, usage balances, product events, timestamps, app version, platform, session identifiers and installation identifiers or their hashes.
- Optional reminders: notification permission and preferences, push token, time zone, requested schedule, related situation identifier and delivery-status information.
- Website and promotions: campaign links, page views, App Store taps, technical request information, and any contact details or entry you submit to a promotion. Some public routes use an IP-address hash for abuse prevention.
Conversation content can reveal sensitive information about you or someone else, including health or intimate relationship details. Submit only information needed for your request and remove unnecessary names and sensitive details. Account IDs and hashes may still be personal information.
Screenshots are transmitted for processing. Our current companion flow saves extracted text and generated results, rather than keeping a separate original-screenshot archive. This does not mean that no temporary or provider-held copy can exist. Some conversation history, session information and preferences also remain on your device.
How we use information
We use information to provide and personalize replies, maintain conversations and memory, authenticate accounts, administer subscriptions and allowances, deliver reminders you choose, respond to reports and support, understand feature use and reliability, apply safety protections, prevent abuse, and meet legal obligations.
Remi can save useful details automatically. You can review, correct or delete saved memories using the app’s memory controls. Correcting or forgetting a memory changes what is available for future context; it does not necessarily erase the original message from visible conversation history. Delete that message or conversation separately when you want it removed too.
We do not routinely review all private chats to evaluate response quality. Reports are optional, and sharing an example requires a separate choice. Automated quality summaries use report categories and counts without copying private example text into those summaries. Operating the service and applying real-time safety checks are separate from this reported-example process. Necessary support, security or legal work may involve authorized access; Peach is not a service where nobody can ever access content.
Service providers
- OpenAI: processes content and relevant context to generate responses and perform automated safety checks.
- Vercel: hosts our backend and can route AI requests through its AI Gateway.
- Supabase: provides authentication, database storage and first-party event storage.
- Apple and RevenueCat: support purchases, subscription status and transaction administration. Peach does not send your conversation content through its billing integration.
- Expo and platform push services, including Apple: process push tokens, notification payloads and delivery metadata when you enable remote reminders. Notification text is discreet by default.
- Sentry, when operational reporting is enabled: receives limited technical error metadata. Our configured reporting pathway excludes conversation text, screenshots, request headers and attachments.
Our current companion requests turn off optional storage of completions for our provider dashboard. This is not a promise of zero provider retention. Providers may retain information for security, legal compliance or other applicable service requirements; previously stored content may also require separate cleanup. OpenAI’s commercial API data controls describe its default training and retention practices. Consumer ChatGPT settings do not determine Peach’s API settings.
Information may be processed in the United States and other countries where these providers operate. Applicable protections can differ by location. Contact us for information about the processing and safeguards relevant to your request.
Other disclosures and business transfers
We do not sell personal information to advertisers or data brokers, use private conversations for advertising, or share personal information for cross-context behavioral advertising. We measure our own feature use and campaign links. Peach does not read your clipboard for invite attribution.
If Peach considers or participates in a merger, acquisition, financing, sale of some or all business assets, restructuring, insolvency proceeding, or transfer to a new service operator, personal information may be disclosed to prospective counterparties and their professional advisers to evaluate and carry out the transaction. We limit disclosures to what is reasonably needed and use appropriate confidentiality safeguards. Information may transfer to the acquiring or successor organization, subject to applicable law and the privacy commitments applicable to it. We will provide notice and obtain consent where required.
We may also disclose information where reasonably necessary and permitted by law to comply with a valid legal requirement, investigate misuse, establish or defend legal claims, or protect people’s rights and safety.
Retention and deletion
There is no single automatic expiry period for every type of Peach information. We retain saved account content while it supports your account and chosen features, unless you delete it or it is no longer needed. We assess retention using the purpose, sensitivity, your requests, and specific legal, security or dispute-resolution needs.
- Saved conversations, Files, memories and preferences remain available until the relevant deletion action or account deletion, subject to the scope of the control you use.
- In-app report text and examples are scheduled for removal after 30 days; report categories and related metadata after 90 days. Account-linked reports are also included in account deletion. Separate support emails and promotion records are retained as needed to handle the issue and relevant legal or security needs; a request may need to identify those records separately.
- A prepared data copy is available for 24 hours. Its stored copy is cleared by expiry cleanup or an explicit completion request. Downloaded copies that you save or share are outside Peach’s control. Changing or forgetting source context invalidates an earlier prepared copy.
- Unaccepted first-result drafts are scheduled to be refunded and cleared after 30 minutes. Failed or cancelled request-result caches are scheduled for clearing after one day. Request identifiers and status can remain to prevent an old retry from generating a duplicate.
- Our technical event and AI-usage records, inactive notification tokens and finished notification records are scheduled for removal after 30 days. These limits do not delete saved conversation history or establish the retention period of a provider’s separate logs.
- Transaction records may remain for accounting, subscription disputes and applicable legal obligations. Records containing transaction or account identifiers are not necessarily anonymous.
- Limited deletion-job and provider-object references remain while cleanup or verification is pending and for necessary request administration. A protected account-ID hash can remain while a backup could restore deleted information, so we can reapply deletion restrictions. These hashes are not treated as anonymous. Aggregate safety counts contain no account, request or device identifiers.
- Technical logs and backup copies can have separate provider retention periods. Active-system deletion does not establish immediate removal from every backup or provider system.
To request account deletion, open You in Peach and choose Delete account. The request starts a tracked process; it is not a confirmation that every copy has already been erased. New companion activity is restricted once deletion begins. Active account data and provider cleanup may finish at different times. Failed or unverified provider steps remain pending or require attention, including historical AI-stored records and sign-in-provider cleanup where applicable. Keep the request receipt provided by the app and contact us if you need help checking progress.
If you used Apple sign-in and we need a fresh authorization to revoke its access, the app can offer an Apple confirmation before deletion. You may continue with Peach-data deletion if that confirmation is unavailable or you decline; any unfinished Apple step remains visible. Revoking Apple sign-in authorization is separate from cancelling an Apple subscription.
We do not promise a universal deletion deadline across all providers and backups. We handle requests within applicable legal time limits and explain material delays or justified exceptions. You can contact us if you cannot access the app or wish to exercise a privacy right.
Deleting the app alone does not delete your account. Deleting your account does not cancel an Apple subscription. Manage billing separately in Apple Subscriptions. Disabling or deleting a reminder cannot recall a notification already handed to a delivery provider.
Your choices and privacy requests
Open You → Your data and privacy requests to request a prepared copy and check a request’s status. The app protects the receipt on your device; do not share it publicly. You can correct or forget saved memories under Memory and check-ins. Simple corrections can be applied automatically, while disputed identity, information supplied by another user, and other exceptional requests may need individual handling. A status saying attention is needed does not mean the request has been fulfilled.
Depending on applicable law, you may also have rights to object to or restrict processing, withdraw consent, or complain to a privacy regulator. Contact melzoogle@gmail.com if you cannot use the app or another user submitted information about you. We may ask for proportionate information to verify identity and locate the records without disclosing someone else’s private information. Exercising a privacy right does not require a paid subscription.
Reminders are optional and limited to at most one companion check-in per day. You can change reminder preferences or disable them; delivery depends on device settings and notification services. Our websites do not change their behavior in response to browser Do Not Track signals. We do not conduct cross-site behavioral advertising tracking. Contact us about a specific privacy signal or choice.
Security, age and changes
We use access controls and technical safeguards designed to protect information. No system guarantees absolute security. If you believe someone under 16 is using Peach, contact us so we can address access and associated information. Our minimum-age policy does not mean our safeguards can always identify a user’s age.
We update this notice when practices change and provide appropriate notice of material changes, such as an in-app notice or email where available. Where a change requires permission, we ask before applying that processing. The update date alone does not replace required notice or consent.
Read our Terms of Service for AI limitations and our Safety page for how companion safety checks work.