Privacy Policy
What Peekly collects, why, who it is shared with, and how to have it deleted.
The short version
- Peekly reads analytics from the creator accounts you connect and shows them back to you. Its access is read-only: it cannot post, edit or delete anything on your accounts.
- There are no ads and no trackers, and we do not sell your data.
- The access tokens each platform gives us are encrypted before they are stored.
- Your history is kept for as long as you have an account. Deletion is by email request today — the steps are on the Delete your data page.
Who we are
Peekly is a creator analytics app for iPhone. This website, getpeekly.app, runs the service behind the app and hosts these pages. Peekly is operated by Jawad Rafiq Haider (“Peekly”, “we”, “us”), the controller of the personal data described in this policy. You can reach us at hello@getpeekly.app.
Peekly is an independent product. It is not part of, endorsed by or affiliated with YouTube, Google, TikTok, Meta, Instagram, Facebook, Threads or Apple.
The Terms of Service set out the rules for using Peekly. This policy covers the data.
What we collect
Data reaches Peekly in three ways: from you when you sign in, from the platforms you choose to connect, and automatically as technical records when the app talks to our servers. Peekly collects numbers about your own accounts and posts. It does not collect the text of comments, or the identity of anyone who follows, watches, likes or comments on your content.
Your Peekly account
- You sign in with Sign in with Apple. The app passes Apple’s identity token to our sign-in provider. It contains Apple’s identifier for you and the email address you chose to share, which may be an Apple private relay address.
- Your email address is held by the sign-in provider and travels to our servers inside your sign-in token. Peekly’s own database identifies you by an internal account ID and does not keep a separate copy of your email.
- The sign-in provider also keeps the records that signing in needs: when your account was created and last used, your sessions with the IP address and the app or browser they came from, the tokens that keep you signed in, and the identity details Apple supplied. It keeps an audit log of sign-in events as well, whose entries can include your email address and IP address.
- The app’s sign-in request asks Apple for your name as well as your email address. Apple gives the name to the app on your device. Peekly does not send your name to its servers or store it.
- One workspace record that groups your data, with a name and creation date.
Your platform connections
- Which platform you connected, that platform’s ID for your account, the permissions you granted, the connection status, when data was last collected, and the most recent error message if a collection failed.
- The access and refresh tokens the platform issues to Peekly. They are encrypted before they are stored.
- Never your platform password. You sign in on the platform’s own page and Peekly only receives the tokens.
YouTube
Peekly uses YouTube API Services to read your channel’s data. When you connect YouTube you grant two read-only permissions through Google: viewing your YouTube account and viewing your YouTube Analytics reports. With them Peekly collects:
- Your channel’s ID, title, custom URL and subscriber count.
- Daily channel figures: views, minutes watched, average view duration, subscribers gained and lost, and counts of likes, comments and shares.
- Your 50 most recent uploads: video ID, title, publish date, duration and link, with each video’s views, likes, comment count and watch time.
- Audience percentages: the share of your viewers by age group and gender, and your top ten countries by share of views. These are totals from YouTube, never individual viewers.
- The same daily channel figures for up to 365 past days, when the app loads your history. YouTube reports only today’s subscriber total, so the totals Peekly shows for earlier days are its own estimate worked backwards from the gains and losses.
TikTok
When you connect TikTok you authorise Peekly through TikTok Login Kit to read your basic profile, profile details, account statistics and video list. Peekly collects:
- TikTok’s identifiers for your account in our app (open ID and union ID), your display name and the web address of your avatar image.
- Your follower, following, total likes and video counts.
- Up to 200 of your videos: video ID, creation time, title, description, duration and share link, with each video’s view, like, comment and share counts.
TikTok does not give Peekly any audience demographics.
Instagram, Facebook and Threads (not yet available)
You cannot connect an Instagram account, a Facebook Page or a Threads account in the app yet, so Peekly collects nothing about you from those platforms today. The connections are built to read the following through Meta’s official APIs:
- Your username and name, and your follower, following and post counts.
- Account-level figures such as reach, views, link taps, likes, replies, reposts and follower changes, depending on the platform.
- Up to 50 recent posts: the caption or text, link, publish time and media type, with each post’s counts for likes, comments, reach, views, saves, shares and clicks and, for reels, watch time.
- Follower percentages by age, gender, country and city. These are totals from Meta, never individual followers.
Peekly collects nothing from a platform you have not connected.
What Peekly works out from your data
- Insights, alerts and a daily report built from your numbers. The report can quote the captions or titles of your strongest and weakest recent posts.
- Hashtag comparisons, for Instagram, Facebook and Threads posts only: the hashtags are read from those captions when the posts are collected. Peekly does not read hashtags from YouTube or TikTok posts.
- Estimates such as growth projections and the subscriber history described above.
Technical records
- A collection log: each time Peekly collects, it records the time, the platform, whether it worked and how many items were read. The entry for a scheduled run across all accounts is not tied to any one account. It lists each connection the run touched by platform, the first six characters of the connection’s internal ID and a status word.
- Standard request logs kept by our hosting and sign-in providers, such as IP address, time, the address requested and the app or browser used. While you are connecting a platform these logs can include the short-lived, single-use codes and the connection reference (described under Who we share it with) that pass through the address bar.
- Error logs. Peekly is designed to keep tokens out of them: it sends tokens to YouTube and TikTok in request headers and bodies rather than in web addresses, and its collection code removes anything that looks like an access-token parameter from a platform’s error text before logging it. This is a safeguard, not a guarantee.
What we do not collect
Peekly does not ask for your contacts, location, camera, microphone or date of birth, does not use advertising identifiers, and does not take payment details.
How we use it
We use your data for these purposes, on these legal grounds:
- To provide Peekly. Creating your account, connecting your platforms, collecting your analytics once a day and when you refresh in the app, keeping your history, and showing you charts, insights, alerts and reports. Legal ground: performing our contract with you (the Terms of Service).
- To read from each platform. This relies on the permission you give on that platform’s own consent screen. You can withdraw it at any time on the platform — see Deleting your data.
- To keep the service secure and working. Request and error logs, diagnosing failures and preventing abuse. Legal ground: our legitimate interest in running a safe and reliable service.
- To meet legal duties, such as answering a rights request. Legal ground: legal obligation.
We do not use your data for advertising, we do not sell it, and we do not use it to build or train AI models. Peekly makes no automated decisions about you that have legal or similarly significant effects. Its insights are calculations about your own content, for you to act on or ignore.
You are not required by law to give us any data. Without an account and at least one connected platform, though, Peekly has nothing to show you.
AI-written summaries
Your daily report is produced by fixed rules from your numbers. Peekly’s software also contains an optional step that asks an AI model from Anthropic to rewrite the report in more natural language. That step is switched off on this service, so nothing is sent to Anthropic or to any other AI provider.
The step is controlled by the operator for the whole service, not per account. This section reflects the setting the service is running with: when the step is on, this section lists exactly what is sent.
Google and YouTube data
Peekly uses YouTube API Services. By using Peekly you agree to be bound by the YouTube Terms of Service (opens in a new tab). Google’s handling of your information is described in the Google Privacy Policy (opens in a new tab).
Peekly’s use of information received from Google APIs will adhere to the Google API Services User Data Policy (opens in a new tab), including the Limited Use requirements. In practice that means your Google and YouTube data is:
- Used only to provide and improve the analytics features you see in Peekly.
- Not sold, and not transferred to advertising platforms, data brokers or information resellers.
- Not used for advertising, retargeting or decisions about credit or lending.
- Not used to develop or train general AI models.
- Not read by a person, unless you have agreed to it (for example when you ask us for help with your account), it is necessary for security purposes such as investigating abuse, or the law requires it.
- Passed to others only as needed to provide those features (the providers listed above), for security, or to comply with the law.
You can remove Peekly’s access to your Google account at any time in your Google security settings (opens in a new tab). That is in addition to asking us to delete what Peekly has stored, described below.
TikTok and Meta data
Data that Peekly receives from TikTok, Instagram, Facebook or Threads is used only to show you your own analytics in Peekly. It is never sold or licensed, and it is shared only with the service providers listed above, when the law requires it, or when you tell us to.
We delete this data when you ask, if we stop operating Peekly, if the platform requires it, or if the law requires it. Nothing else triggers deletion: how long data is kept is set out under How long we keep it.
Nothing in this policy gives Peekly wider rights over a platform’s data than that platform’s own terms allow. Each platform’s handling of your information is described in its own policy: the TikTok Privacy Policy (opens in a new tab) and the Meta Privacy Policy (opens in a new tab).
Cookies and device storage
On this website
- Two security cookies are set while you connect a platform. They hold the security values for the sign-in in progress (a signed state value and a one-time verifier) so the result can be matched to your account. Page scripts cannot read them, they are sent only over HTTPS, and they expire after 10 minutes.
- Your light or dark theme choice is saved in the browser’s local storage if you change it.
- The password-protected dashboard on this site, used by the operator, also notes in session storage that its intro animation has played.
There are no analytics, advertising or tracking cookies, and the site loads no third-party scripts or fonts.
In the iPhone app
- Your sign-in session is kept in the iOS Keychain so you stay signed in.
- Two preferences are kept in the app’s local settings: your automatic-refresh choice, and a note of which connections have finished loading their history. That note is saved under a name that includes your account email. Signing out removes the session; these two preferences stay on the device until you delete the app.
- Connecting a platform opens the system sign-in sheet, which shares cookies with Safari. The platform’s own login cookies are stored there by iOS, not by Peekly.
The app contains no analytics, crash-reporting or advertising software, and does not ask for tracking permission.
How long we keep it
- Your analytics history is kept for as long as you have a Peekly account, because showing your history over time is what Peekly is for. Nothing is deleted on a timer.
- While a connection is active, Peekly collects fresh data every day, and that daily request is also how it learns that an authorisation has been withdrawn. For YouTube it covers your channel details, the latest days of channel figures, your audience percentages and your 50 most recent videos.
- If a connection stops working or you remove Peekly’s access on the platform, Peekly can no longer read that account. It keeps trying each time it collects, and starts collecting again if the connection recovers. YouTube is the exception: when Google confirms that your authorisation was withdrawn, Peekly marks the connection as revoked and stops trying. With TikTok, Peekly cannot tell a withdrawn authorisation from an expired one, so a TikTok connection is retried each time Peekly collects until it is deleted. Data already collected is not removed automatically. It stays until you ask us to delete it.
- When you ask us to delete, we delete within 30 days, and within 7 calendar days for data that came from YouTube. Insights, alerts and reports are built from all your platforms together, so for an account that has YouTube data they are deleted within the same 7 calendar days.
- Short-lived records: the two connection cookies expire after 10 minutes, and the single-use codes used to hand a connection from the app to the browser expire after 60 seconds.
- Provider logs are kept by our hosting and sign-in providers for the limited period their service sets.
We will also delete platform data if we stop operating Peekly, if a platform requires us to (for example if our access to its API ends), or if the law requires it.
Deleting your data
You can ask us to delete your account and everything Peekly holds about you, or just the data from one platform. Every Peekly user has this right, wherever they live. There is no delete button in the app yet, so the request is made by email. The steps, what is removed and how long it takes are on the Delete your data page.
You can also remove Peekly’s access on the platform itself:
- Google and YouTube: Google security settings (opens in a new tab).
- TikTok: in the TikTok app, open Settings and privacy, then Security & permissions, then Apps and services permissions.
- Facebook: Facebook Apps and Websites settings (opens in a new tab). Instagram: Instagram Apps and websites settings (opens in a new tab). Threads: Threads account settings (opens in a new tab), under Website permissions.
Removing access on a platform means Peekly can no longer read that account. It does not delete what Peekly already stored. For that, send us a deletion request.
Security
- Platform tokens are encrypted with AES-256-GCM before they are stored, using a key that is kept outside the database. They are decrypted only for the moment Peekly collects your data, and they are never sent back to the app.
- All traffic between the app, this site and the platforms uses HTTPS.
- Every request from the app carries a signed sign-in token that our servers verify, and each request can reach only the data of the account that made it. Accounts share one database and are kept logically separate.
- The operator has administrative access to the servers and the database, which running the service requires. Google and YouTube data is looked at by a person only in the cases listed under Google and YouTube data.
No system is perfectly secure. If you think something is wrong, tell us at hello@getpeekly.app.
International transfers
Peekly’s application servers run in Tokyo, Japan. Before a request from the app reaches them it is checked on our hosting provider’s network at a location close to you. That check reads your sign-in token, which contains your email address, to confirm who you are.
Our providers are companies based in the United States and may process data there and in other countries, so your data may be handled outside the country you live in.
Write to us at hello@getpeekly.app if you would like to know more about where your data is handled and how it is protected there.
Your rights
Whoever you are and wherever you live, you can ask us what we hold about you, ask us to correct it, and ask us to delete it.
If you are in the EU, the EEA or the UK
You have the right to access your data, have it corrected, have it erased, restrict or object to its use, and receive it in a portable form. Where we rely on your permission, you can withdraw it at any time. We answer within one month.
You can also complain to your data-protection authority: the Information Commissioner’s Office (opens in a new tab) in the UK, or your national authority (opens in a new tab) in the EU. We would appreciate the chance to put things right first.
If you are in California
You have the right to know what personal information we collect, to have it deleted or corrected, and not to be treated differently for using these rights. In the last 12 months Peekly collected the following categories:
- Identifiers: your email address, your Peekly account ID, and the IDs and names of the accounts you connected.
- Internet or network activity: the request logs and sign-in records described above.
- Analytics about your own creator accounts and posts, received from the platforms you connected.
The sources are you, the platforms you connect and your device. The purposes are those listed under How we use it. We disclosed this information only to the service providers listed under Who we share it with, for those purposes. We have not sold personal information or shared it for cross-context behavioural advertising, so there is nothing to opt out of.
How to use your rights
Write to hello@getpeekly.app. Tell us the email address shown in the app under Settings so we can find your account. If you signed in with Apple’s Hide My Email, that is a private relay address you cannot send mail from, so write from any address you can read. We reply to the address you wrote from, and to protect your account we may ask you to confirm that you control it before we act. The app has no download button yet, so we prepare copies of your data by hand when you ask.
Children
Peekly is for people aged 18 and over, and we do not knowingly collect data from anyone younger. Peekly does not ask for your date of birth, so if you believe someone under 18 has an account, tell us and we will delete it.
The age-group percentages Peekly shows describe your audience as a whole. They come from the platform as totals and say nothing about any individual.
Changes to this policy
We will update this page when what Peekly does with your data changes, and review it at least once every 12 months. The date at the top shows when the current version took effect. If a change significantly affects how your data is used, we will draw attention to it here before it applies.
Contact
Questions, requests and complaints about privacy go to Jawad Rafiq Haider at hello@getpeekly.app.