← Home

Legal information

This page is maintained by the PeakMe team to answer common questions about the service's security and privacy. It describes our current practices; it is not an independent certification.

1. Shared responsibility model

PeakMe relies on established providers (hosting, database, payment, AI). We configure these building blocks and write the application; providers manage the security of their infrastructure; you manage the confidentiality of your password and the device you use.

2. Authentication & access

  • Login via email/password or Google.
  • Passwords stored in hashed form by our authentication provider — never in plain text.
  • Encrypted sessions, revocable from your account.
  • Each user can only access their own analyses, plans and tasks (database-level isolation).

3. Data & encryption

  • All traffic between your device and PeakMe goes over HTTPS (TLS).
  • Data is stored with our sub-processors, which encrypt data at rest.
  • Your original photo is automatically deleted after 30 days (see Privacy).

4. Payments

Payments are processed by Stripe. PeakMe never sees your full card number and does not store it on its servers. The transaction appears on your bank statement under the descriptor "NOVEXA STUDIO" (or a shortened form such as "NOVEXA").

5. Main sub-processors

  • Edge hosting: Cloudflare.
  • Database & authentication: Supabase.
  • AI analysis: OpenAI and Google Vertex.
  • Payment: Stripe.

Details and legal bases in the Privacy page.

6. Retention & deletion

You can request the deletion of your account and your photo at any time via the contact form. Detailed retention periods are set out in the Privacy page.

7. Cookies & advertising

PeakMe uses only strictly necessary technical cookies for the operation of the service (session, security). No advertising pixel, no analytics cookie, no third-party tracker is placed. Our occasional advertising campaigns are delivered without behavioral targeting based on your browsing and without site-side conversion tracking — that is why no consent banner is required.

8. Reporting a security issue

If you think you have found a vulnerability, contact us via the contact form with a description and, if possible, steps to reproduce. Please do not disclose publicly before we have had a chance to fix it.

9. AI transparency

PeakMe is a deployer of third-party general-purpose AI models: the OpenAI GPT family for text analysis and plan generation, and the Google Gemini / Vertex family for image generation and editing. Providers and model versions may change to improve quality, cost or availability.

  • You are always told, before use, that you are interacting with an AI system (Art. 50 AI Act).
  • The "after" photo is a synthetic simulation, labelled as AI-generated — not a photograph and not a prediction of your real future appearance.
  • Your photo is never used to train any model, ours or a provider's; our AI providers operate on no-training terms for API data.
  • No facial recognition, no biometric identification or template, no emotion recognition, no biometric categorisation, no social scoring — none of the practices prohibited by Art. 5 of the AI Act.
  • No AI output has legal or similarly significant effects on you (Art. 22 GDPR). You can request human review of any result via the contact form.
  • Outputs are probabilistic and may contain errors, biases or artifacts; they are never medical or professional advice.

10. Your data rights and incident handling

For users in the EU/EEA, PeakMe applies the GDPR: access, rectification, erasure, restriction, portability, objection and withdrawal of consent, exercisable via the contact form with a reply within one month, plus the right to lodge a complaint with your national supervisory authority (e.g. the CNIL in France). Outside the EU, the equivalent rights of the UAE PDPL apply. International transfers are covered by the European Commission's Standard Contractual Clauses. In the event of a personal data breach likely to create a risk, we notify the competent authority within 72 hours and inform affected users where the risk is high. Full detail in the Privacy Policy.

11. Compliance

PeakMe is published by NOVEXA STUDIO - FZCO (trade license No. 90184, issued by the Dubai Integrated Economic Zones Authority), registered office at DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai (United Arab Emirates), operating internationally. The service is governed by the law of the United Arab Emirates (Federal Law No. 15 of 2020 on consumer protection, PDPL No. 45 of 2021, Decree-Law No. 14 of 2023 on e-commerce) and, for users in the European Union, additionally applies the GDPR, the AI Act transparency obligations, the consumer-rights and digital-content directives, and the mandatory consumer protections of the user's country of residence (Rome I, Art. 6(2)). Payments are processed by Stripe as Merchant of Record: Stripe collects, invoices, handles local taxes and refunds in each jurisdiction. We do not claim SOC 2, ISO 27001, HIPAA or PCI certifications; our sub-processors' certifications belong to them.

12. Updates

This page is editable and may evolve with the product. For any question, use the contact form.