Privacy Policy
Peak ("Peak", "we", "us") is an independent iOS app for browsing and trading Polymarket prediction markets. Peak is not affiliated with, endorsed by, or operated by Polymarket, Inc. This policy explains what data moves through the app and who else can see it.
1. What Peak collects, and why
TL;DR: only what's needed to sign you in, show your positions, and let you place a trade — no ads, no tracking, no sale of your data.
Peak is built to need as little of your data as it can and still place a trade. Depending on how you use the app:
- Wallet identifiers. When you sign in, Peak receives a wallet address and, if you chose email sign-in, your email — both via Privy, our authentication provider.
- An imported private key or seed phrase, only if you choose to import one. Peak offers two ways to trade. If you sign in with an embedded wallet through Privy, Peak never receives your private key. If you instead import an existing Polymarket wallet by pasting its private key or seed phrase, that secret is sent over HTTPS to Peak's backend, which derives your wallet address and signs your orders on your instruction. It is never written to your device. On Peak's servers it is held encrypted (AES-256-GCM) in memory only, for the life of a trading session — it is never written to disk, and a restart clears it. See Custody for what this means for control of your funds.
- Trading instructions you send. Orders you place (token, side, size, price) pass through Peak's backend so an order can be constructed and signed, then submitted to Polymarket's exchange. Peak's backend does not execute trades on its own initiative — it only acts on an instruction you send from the app.
- Portfolio and activity data. To show your positions and history, Peak reads them from Polymarket's systems using your wallet address. This is requested live and is not built into a separate profile.
- Crash and error diagnostics. In released (non-development) builds, Peak uses Sentry to report crashes and hangs so bugs can be fixed. This is configured to exclude your IP address, device identifiers, and screenshots — see Third parties below.
- Device region signal. Peak checks a coarse region signal to warn you if Polymarket restricts trading where you are. This is used to inform you, not to profile you, and is not stored against your identity.
Peak does not run advertising, does not sell data, and does not use cross-app or cross-site tracking. Peak's iOS privacy declarations to Apple state no tracking.
2. What never leaves your device
Some of what makes Peak feel personal to you stays local, in iOS's standard on-device storage, and is not sent to Peak's servers:
- Your watchlist
- Price alerts you've set
- Category / interest preferences
- Appearance and accent theme choice
- A read-only wallet address, if you added one to view a portfolio without signing in
Deleting the app deletes this data along with it.
3. Third parties Peak relies on
TL;DR: Peak doesn't sell your data, and doesn't share it beyond the providers below that Peak itself runs on.
Peak is a thin client over other people's infrastructure. Each of the following processes some of your data under its own privacy terms:
- Polymarket — the exchange itself. Market data, order execution, and your position history all live on Polymarket's systems. Peak reads and writes there on your instruction.
- Privy — authentication and embedded wallet infrastructure. Handles sign-in and, if you use it, secure key management.
- Reown / WalletConnect — used if you connect your own external wallet instead of an embedded one.
- Sentry — crash and error reporting, released builds
only. Configured with
sendDefaultPiiand screenshot/view attachment both switched off — it does not receive your IP, device identifiers, positions, or balances. - Cloudflare — routes some network requests at the edge so the app can reach Polymarket reliably from more regions.
- Railway — hosts Peak's backend server, including the encrypted store that holds imported signing keys.
4. Custody — please read this one
Your funds always sit in your own wallet. Peak has no account of its own and never takes ownership of your money. But how much control Peak's servers have depends on which sign-in you choose, and the two are genuinely different:
- Embedded wallet via Privy (non-custodial). Key management is handled by Privy. Peak never receives your private key and cannot sign anything without you. This is the path we recommend.
- Imported wallet (Peak's servers hold a signing key). If you paste a private key or seed phrase to trade an existing Polymarket wallet, Peak's backend stores that key in encrypted form and signs with it on your behalf. That key is technically capable of authorizing transactions from that wallet. Peak only ever uses it to carry out instructions you send from the app, and never moves funds on its own initiative — but you are trusting Peak's infrastructure with it, in the same way you would trust any hosted service. If you are not comfortable with that, use the embedded wallet instead, or import a wallet holding only what you intend to trade.
5. Retention and deletion
On-device data is deleted when you delete the app. For data Peak's backend touches in the course of relaying a trade, it is kept only as long as needed to operate the service and meet any applicable recordkeeping obligation, then deleted or anonymized. If you imported a private key or seed phrase, the encrypted signing key lives only in Peak's server memory for the life of that trading session. It is never written to disk, so a restart or deployment clears it and you re-import. You can also remove it yourself at any time from Account, and signing out removes it. To ask about or request deletion of data associated with your account, see Contact.
6. Age
Peak is not directed at children and is not intended for anyone under 18. Do not use Peak if you are under the minimum age for entering into financial transactions where you live, whichever is higher.
7. Your choices and rights
You can sign out, disconnect a wallet, clear on-device data from within Settings, or delete the app at any time.
If you are in the UK or European Economic Area, you have rights under UK and EU data protection law (GDPR), including the right to: request access to and a copy of your personal data; request correction or deletion of it; object to or restrict certain processing; request portability of your data; and withdraw consent at any time where processing is based on consent.
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to: request access to and a copy of the personal information Peak's backend has collected about you; request its deletion; and opt out of the "sale" or "sharing" of personal information as those terms are defined under CCPA — Peak does not sell or share your personal information for cross-context behavioral advertising, so there is nothing to opt out of today, but the right stands regardless.
To exercise any of these rights, contact us — see Contact below. We may need to verify your identity before acting on a request. Peak will not discriminate against you for exercising these rights.
8. Changes to this policy
If this policy changes materially, the "Last updated" date below will change and, where required, we'll tell you in the app.
9. Contact
Email: support@peakapp.site
Last updated: 2026-08-05