Skip to main content
Peltify
DocsPostsContact
Open Peltify

Privacy Policy

What Peltify holds about you, and how to take it back.

Effective September 15, 2026. This policy covers peltify.com (and its staging copy at peltify.vercel.app), the Peltify app and the Peltify Chrome extension. It is part of the Terms of Service. It describes the product as it is actually built.

In short

  • Peltify stores your account, what it read from the services you connected, your library, your posts and messages, and the taste profile it built.
  • It never stores a password you type into another service, and it never sees your card details.
  • A small number of providers process your data: hosting in the United States, a database in Canada, email, AI models, and Stripe for payments.
  • Nothing is sold, nothing is used for advertising, and there are no trackers or analytics.
  • You can export everything as one file and delete everything from Settings. Deletion has a thirty-day undo window.
  • Questions: contact@peltify.com.

Contents

  1. 1. Who this covers
  2. 2. What we collect
  3. 3. What we do not collect
  4. 4. What we use it for
  5. 5. AI processing
  6. 6. Who sees it
  7. 7. Where it is stored
  8. 8. How long we keep it
  9. 9. How we protect it
  10. 10. Your rights and controls
  11. 11. Cookies and browser storage
  12. 12. The Chrome extension
  13. 13. Children
  14. 14. Changes to this policy
  15. 15. Contact and complaints

1. Who this covers

  • Peltify is operated by its founder as an unincorporated business in British Columbia, Canada. The Terms of Service say who “Peltify” is.
  • For privacy law, Peltify is the organisation responsible for your personal information, and the founder is the person accountable for it.
  • British Columbia’s Personal Information Protection Act (PIPA) applies. Canada’s PIPEDA applies to information that crosses borders. If you use Peltify from the EEA or the UK, the GDPR or UK GDPR may give you further rights, and this policy honours them where they apply.
  • This policy replaces the version dated August 26, 2026.

2. What we collect

Account

  • Username, email address, and a password if you set one. The password is stored only as a salted scrypt hash.
  • The email address is verified by a six-digit code sent to it. An account does not exist until the code comes back.
  • If you sign in with Google, Google gives us your email address and name. We never see your Google password.
  • Display name, profile text, avatar, and the profile sections you choose to show.
  • When the account was created, how you signed in, and which plan you are on.

Homepage and posts

  • The posts you write: text, the works you mention, ratings, reviews, lists, and each post’s visibility setting.
  • Comments, replies and likes, yours and the ones on your posts.
  • Edits and archived posts.

Search

  • The words you search are sent to the server to find people and works. They are not kept as a history on the server.
  • The people you opened from search are remembered in your own browser only (“Recent”).

Discover (the suggestions chat)

  • The messages you type, the works and people you mention, the cards you were shown, and your answers (kept, not for me, already seen).
  • The thread is stored so it comes back when you return. Starting a new chat replaces it.
  • The number of asks and scans you have used today, so the daily allowance can be counted.

Library

  • Every item in your library, where it came from, your ratings, verdicts, lists, pins, and any name corrections you make.
  • Items are matched to a catalogue record (a “work”) by an external id from the provider that knows it, never by name alone.

Scans and connected services

  • When you connect a service (a “Source”) and run a scan, Peltify reads and stores what your account on that Source can see: music listened to and saved, films and shows watched, books rated, posts saved, communities joined.
  • Each read records which Source it came from and when.
  • For Sources read through an official API or a public username (Reddit, Last.fm, ListenBrainz, Discogs), Peltify stores the username or OAuth token you authorised.
  • For Sources read by a browser Peltify runs (Goodreads, Netflix), Peltify stores the session cookies that Source issued after you signed in, encrypted at rest. The password itself is used once and discarded.
  • For Sources read by the Chrome extension, nothing about the Source is stored except what the scan read.
  • A history of scans, the steps each one took, and the agent’s notes on how each Source behaves for your account.

Profile

  • The taste profile Peltify builds from your reads and library: genres, clusters, a headline. You can edit the genres.

People, messages and pelts

  • Who you follow, who follows you, and message requests.
  • Direct messages: text, replies, reactions, attached posts and cards, when a thread was opened (seen receipts).
  • Pelts, the recommendation cards you send a friend: the work, why it fits, the two people’s taste overlap, and a copy of the cover image.
  • Share cards you create.

Plan and payments

  • Your plan (Free or Plus), billing interval, subscription status, and your Stripe customer id.
  • Stripe holds your card and billing details. Peltify never receives the card number.

Without an account

  • You can read the public feed and public profiles, search, and run one taste round.
  • What you add stays in your browser’s storage. The server keeps only a per-browser counter for the free round.

Technical

  • The hosting provider processes IP address, browser type, the pages requested and when, to deliver and secure the site.
  • Peltify’s own server keeps short-lived operational logs and an accounting log of AI spend per account (counts and costs, not content).
  • No analytics product, no advertising pixel, no third-party tracker on any Peltify surface.

Correspondence

  • If you email contact@peltify.com: your address, your message and anything you attach.

3. What we do not collect

  • Third-party passwords. A password typed into a Source sign-in inside Peltify is used once to perform that sign-in and is not written to the database, to logs, or to disk. The same is true of two-factor codes.
  • Card details. Payment happens on Stripe’s pages. Peltify sees the plan, the status and a customer id, not the card.
  • Location, contacts, device identifiers. Not requested. The trusted-device cookie is a signed cookie, not a fingerprint.
  • Accounts you did not connect. Peltify reads only Sources you connected, only when you start a scan.
  • Browsing history. The extension runs only on the Source domains in its manifest and only during a scan you started.
  • Advertising or tracking data. None.

4. What we use it for

Only for the purposes below, which PIPA calls purposes a reasonable person would consider appropriate. Where another law asks for a legal basis, it is in brackets.

  • Homepage — show you the posts of people you follow and the public feed. [our agreement with you]
  • Search — find people and works for the words you typed. [our agreement]
  • Discover — build suggestions from your library, your profile and what you asked, and remember your answers so the next round is better. [our agreement; your consent when you connect each Source]
  • Library — hold what you have listened to, watched, read and played, and let you rate and sort it. [our agreement]
  • Scan — read the Sources you connected, on your instruction. [your consent, given per Source]
  • Profile — build a taste profile and show the parts of it you chose to make visible. [our agreement]
  • Messages and pelts — deliver what you send to the person you sent it to. [our agreement]
  • Plan — count your daily allowance, take payment through Stripe, and show your invoices. [our agreement]
  • Sign-in and account mail — sign-in codes, deletion confirmations, notices of material changes, replies to you. No marketing email. [our agreement; legal obligation]
  • Security — detect abuse, keep each account isolated, enforce quotas, investigate incidents. [legitimate interests; legal obligation]
  • Fixing the product — understand why a scan or a search failed, from operational logs and your reports. [legitimate interests]
  • Law — answer lawful requests. [legal obligation]

Peltify does not sell personal information, does not share it for advertising, and does not use your data to train a machine-learning model of its own. A new purpose means asking you first.

5. AI processing

  • Suggestions, the reasons behind them, the taste-check questions and the profile’s wording are produced by large language models run by third parties, reached through OpenRouter.
  • What is sent: the words you typed in Discover, the works and people you mentioned, the rows of your library and profile the ask needs, and your earlier answers in the thread. Never your credentials, never your messages to other people.
  • OpenRouter’s published policy is that it does not train on what passes through it. The model provider it forwards to has its own retention policy, which Peltify does not control.
  • Every suggestion is retrieved from real catalogue records first; the model chooses among them. The output is still an inference, is labelled as one, and can be wrong.
  • No decision with a legal or similarly significant effect on you is made automatically. The only thing a profile affects is what Peltify suggests.

6. Who sees it

Providers that run Peltify

  • Vercel, Inc. (United States) — hosts the website and the application server. Everything that passes through the app passes through it.
  • Microsoft Azure (Canada Central) — the Postgres database holding your account, reads, library, posts, messages and derived data, with its backups. Also runs the hosted browser that reads Goodreads and Netflix for you.
  • Resend, Inc. (United States) — delivers sign-in codes and account emails. Receives your email address and the message.
  • OpenRouter, Inc. (United States) and the model providers it routes to — the AI processing in Section 5.
  • Stripe, Inc. (United States) — payment for the Plus plan. Receives your email address, your Peltify account key, the plan chosen, and your card details, which it keeps and Peltify never sees.
  • Google LLC — only if you sign in with Google: Google learns that you signed in to Peltify and gives Peltify your email address and name.

The catalogue

  • To identify works and fetch covers, samples and descriptions, Peltify’s server queries Deezer, iTunes, MusicBrainz and the Cover Art Archive, ListenBrainz, Last.fm, TMDB, TVmaze, Open Library, Google Books, Wikipedia and Wikidata. They receive the search words and the server’s address, not your identity.
  • A 30-second music sample plays from Apple’s servers, and a film or series trailer plays in a YouTube embed. When you press play, your browser fetches from Apple or YouTube directly, and they see that request as they would any visit.
  • The Inter typeface is loaded from Google Fonts, so Google sees the font request from your browser.

The Sources you connect

  • Reddit, Last.fm, ListenBrainz and Discogs receive API calls under your authorisation or public username, and Peltify receives what they return.
  • A Source read by a browser, yours or Peltify’s, sees a sign-in and page requests under your account, as it would if you visited yourself. Peltify sends the Source nothing else.

Other people on Peltify

  • Your public profile, your public posts, reviews, comments and likes are visible to anyone, signed in or not. A post set to followers is visible to your followers.
  • A message or a pelt is visible to the person you sent it to. A share card is visible to anyone with its link.
  • A media page shows counts of what Peltify holds about a work, never who holds it.

When the law requires, or Peltify changes hands

  • In response to a valid legal demand, or to protect the rights, safety or property of Peltify, its users or the public. We will tell you unless the law forbids it.
  • If Peltify incorporates or is acquired, your information transfers to the successor under this policy, and you will be told.

No provider is given permission to use your data for its own purposes.

7. Where it is stored

  • Your stored data and the hosted browser live in Canada (Azure, Canada Central).
  • The application server, email, AI processing and payments run in the United States, so your data is processed there while in use and may be subject to lawful access there.
  • Peltify shares only what each provider needs and chooses providers with strong contractual protections, but cannot promise that foreign law matches Canadian law.
  • By using the Service you consent to this. If you would rather your data not leave Canada, Peltify cannot offer you the Service at this stage.

8. How long we keep it

  • Your account and everything under it — for as long as the account exists.
  • After you delete your account — a thirty-day undo window, during which nothing is removed and signing back in cancels the deletion. Then the account and everything under it is purged from the live database: reads, library, profile, posts, comments, likes, messages you sent, pelts, share cards, and the chat.
  • After you reset your data — reads, profile, suggestions, verdicts, memories and stored Source sessions are removed at once. The account stays.
  • After you forget a Source — its stored session, token or username is deleted at once.
  • Posts, comments, messages — until you delete, archive or unsend them, or delete the account.
  • The Discover thread — until you start a new chat or delete the account.
  • Plan records — Stripe keeps its own records of payments for as long as its policy and tax law require. Peltify keeps the plan and customer id while the account exists.
  • Database backups — encrypted, kept 35 days, then expired. Purged data may persist in a backup until then. Backups are used only to recover from a failure, never to restore one account.
  • Operational logs — short-lived and rotated by the hosting provider. The AI spend log is purged with the account.
  • Correspondence — as long as needed to deal with the matter and keep a record of it.
  • Without an account — data stays in your browser. Clearing site data removes it.

Where a law requires a record to be kept longer, for example that a deletion request was received, we keep the minimum needed for that purpose.

9. How we protect it

  • Every connection uses TLS.
  • Passwords are hashed with scrypt and a per-user salt. Peltify cannot read them.
  • The first sign-in from a browser needs the emailed code, even with the right password. A browser that has proved the address keeps a signed device cookie for 180 days, minted for that one account.
  • Source sessions and tokens are encrypted at rest with AES-256-GCM, with a key held in the deployment environment and not in the database.
  • Sign-in cookies are signed with a server secret, HttpOnly, SameSite, and Secure on the hosted deployment.
  • Every record is namespaced to the account that owns it, and the Service is tested so a forged identity reaches nothing.
  • Stripe events are verified by signature before they change a plan.
  • Cover images are fetched only from the catalogue providers’ own hosts.
  • Database access uses a least-privilege application role. Administrative access is limited to the founder.

No system is perfectly secure, and Peltify is a small validation-stage service without a security team. If Peltify learns of a breach involving your personal information that creates a real risk of significant harm, it will notify you and the relevant privacy regulator as PIPEDA and PIPA require, as soon as feasible. If you find a vulnerability, please email contact@peltify.com before disclosing it.

10. Your rights and controls

Most of these you can do yourself, in the app, without asking:

  • Export — Settings gives you one JSON file with everything Peltify holds about you.
  • Correct — your username, name, profile text, avatar and library records are editable in the app.
  • Delete — Settings: Delete account (Section 8), or Reset data to keep the account and remove the reads and profile.
  • Forget a Source — in Library › Scan, at any time. You can also revoke Peltify at the Source.
  • Visibility — the profile sections other people see, and each post’s audience, are set in the app.
  • Messages — whether strangers may message you is a setting. You can unsend a pelt you sent.
  • Plan — cancel or change it from the Plan page, which opens Stripe’s customer portal.
  • Email — Peltify sends only the messages the Service needs. The “Product updates” switch is off unless you turn it on, and nothing is mailed for it yet.

For anything else, an access request under PIPA or PIPEDA, a question about how a suggestion was made, or a GDPR right such as restriction or objection, email contact@peltify.com. We answer within 30 days or say why we need longer, may need to verify that you are the account holder, and charge nothing for a reasonable request. If we refuse, we say why and how to challenge it.

11. Cookies and browser storage

Peltify sets two cookies, both strictly necessary, both signed, neither used for tracking:

  • pel_sess — keeps you signed in. 30 days.
  • peltify_device — remembers that this browser proved your email address, so the code is not asked again. 180 days.

Third parties set their own cookies only on their own surfaces: Stripe on its checkout and portal pages, and YouTube when you play a trailer. There are no advertising cookies and no analytics cookies.

Local storage in your browser holds the interface state, your recent searches, and, without an account, the items you add. Clearing site data removes them.

12. The Chrome extension

  • The extension reads Sources in your own Chrome, on the sessions you are already signed into, so no third-party sign-in happens anywhere else.
  • It runs only on the Source domains listed in its manifest and on Peltify’s own domains, and only while a scan you started is running.
  • What it reads is sent to Peltify under your account and stored as in Section 2. Nothing goes anywhere else.
  • It stores, locally in the browser, its link to your Peltify account and its own working state. It does not store your reads.
  • It does not collect browsing history and does not run on other sites. Its use of data obtained through Chrome permissions is limited to the feature you enabled, consistent with the Chrome Web Store User Data Policy, including the Limited Use requirements.
  • Removing the extension stops it entirely. It does not delete data already in your account; Settings does that.

13. Children

Peltify is not for anyone under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has an account, tell us at contact@peltify.com and we will delete it.

14. Changes to this policy

When the product changes what is collected, who processes it or how long it is kept, this policy changes in the same release, with a new effective date at the top. For a material change, if you have an account with a verified email, we will make reasonable efforts to tell you before it takes effect. Earlier versions are kept in Peltify’s source repository and can be produced on request.

15. Contact and complaints

Privacy questions, requests and complaints: contact@peltify.com. The founder is accountable for Peltify’s compliance with privacy law and answers personally.

If you are not satisfied with our response, you may complain to the Office of the Information and Privacy Commissioner for British Columbia, or, for matters under PIPEDA, to the Office of the Privacy Commissioner of Canada. If you are in the EEA or the UK, you may also complain to your local data protection authority.

Effective September 15, 2026. Previous versions: August 26, 2026; August 12, 2026.

© 2026 Peltify
Open PeltifyDocsPostsContactPrivacyTerms