In short
- Peltify stores your account, what it read from the services you connected, your library, your posts and messages, and the taste profile it built.
- It never stores a password you type into another service, and it never sees your card details.
- A small number of providers process your data: hosting in the United States, a database in Canada, email, AI models, and Stripe for payments.
- Nothing is sold, nothing is used for advertising, and there are no trackers or analytics.
- You can export everything as one file and delete everything from Settings. Deletion has a thirty-day undo window.
- Questions: contact@peltify.com.
Contents
- 1. Who this covers
- 2. What we collect
- 3. What we do not collect
- 4. What we use it for
- 5. AI processing
- 6. Who sees it
- 7. Where it is stored
- 8. How long we keep it
- 9. How we protect it
- 10. Your rights and controls
- 11. Cookies and browser storage
- 12. The Chrome extension
- 13. Children
- 14. Changes to this policy
- 15. Contact and complaints
1. Who this covers
- Peltify is operated by its founder as an unincorporated business in British Columbia, Canada. The Terms of Service say who “Peltify” is.
- For privacy law, Peltify is the organisation responsible for your personal information, and the founder is the person accountable for it.
- British Columbia’s Personal Information Protection Act (PIPA) applies. Canada’s PIPEDA applies to information that crosses borders. If you use Peltify from the EEA or the UK, the GDPR or UK GDPR may give you further rights, and this policy honours them where they apply.
- This policy replaces the version dated August 26, 2026.
2. What we collect
Account
- Username, email address, and a password if you set one. The password is stored only as a salted scrypt hash.
- The email address is verified by a six-digit code sent to it. An account does not exist until the code comes back.
- If you sign in with Google, Google gives us your email address and name. We never see your Google password.
- Display name, profile text, avatar, and the profile sections you choose to show.
- When the account was created, how you signed in, and which plan you are on.
Homepage and posts
- The posts you write: text, the works you mention, ratings, reviews, lists, and each post’s visibility setting.
- Comments, replies and likes, yours and the ones on your posts.
- Edits and archived posts.
Search
- The words you search are sent to the server to find people and works. They are not kept as a history on the server.
- The people you opened from search are remembered in your own browser only (“Recent”).
Discover (the suggestions chat)
- The messages you type, the works and people you mention, the cards you were shown, and your answers (kept, not for me, already seen).
- The thread is stored so it comes back when you return. Starting a new chat replaces it.
- The number of asks and scans you have used today, so the daily allowance can be counted.
Library
- Every item in your library, where it came from, your ratings, verdicts, lists, pins, and any name corrections you make.
- Items are matched to a catalogue record (a “work”) by an external id from the provider that knows it, never by name alone.
Scans and connected services
- When you connect a service (a “Source”) and run a scan, Peltify reads and stores what your account on that Source can see: music listened to and saved, films and shows watched, books rated, posts saved, communities joined.
- Each read records which Source it came from and when.
- For Sources read through an official API or a public username (Reddit, Last.fm, ListenBrainz, Discogs), Peltify stores the username or OAuth token you authorised.
- For Sources read by a browser Peltify runs (Goodreads, Netflix), Peltify stores the session cookies that Source issued after you signed in, encrypted at rest. The password itself is used once and discarded.
- For Sources read by the Chrome extension, nothing about the Source is stored except what the scan read.
- A history of scans, the steps each one took, and the agent’s notes on how each Source behaves for your account.
Profile
- The taste profile Peltify builds from your reads and library: genres, clusters, a headline. You can edit the genres.
People, messages and pelts
- Who you follow, who follows you, and message requests.
- Direct messages: text, replies, reactions, attached posts and cards, when a thread was opened (seen receipts).
- Pelts, the recommendation cards you send a friend: the work, why it fits, the two people’s taste overlap, and a copy of the cover image.
- Share cards you create.
Plan and payments
- Your plan (Free or Plus), billing interval, subscription status, and your Stripe customer id.
- Stripe holds your card and billing details. Peltify never receives the card number.
Without an account
- You can read the public feed and public profiles, search, and run one taste round.
- What you add stays in your browser’s storage. The server keeps only a per-browser counter for the free round.
Technical
- The hosting provider processes IP address, browser type, the pages requested and when, to deliver and secure the site.
- Peltify’s own server keeps short-lived operational logs and an accounting log of AI spend per account (counts and costs, not content).
- No analytics product, no advertising pixel, no third-party tracker on any Peltify surface.
Correspondence
- If you email contact@peltify.com: your address, your message and anything you attach.
3. What we do not collect
- Third-party passwords. A password typed into a Source sign-in inside Peltify is used once to perform that sign-in and is not written to the database, to logs, or to disk. The same is true of two-factor codes.
- Card details. Payment happens on Stripe’s pages. Peltify sees the plan, the status and a customer id, not the card.
- Location, contacts, device identifiers. Not requested. The trusted-device cookie is a signed cookie, not a fingerprint.
- Accounts you did not connect. Peltify reads only Sources you connected, only when you start a scan.
- Browsing history. The extension runs only on the Source domains in its manifest and only during a scan you started.
- Advertising or tracking data. None.
4. What we use it for
Only for the purposes below, which PIPA calls purposes a reasonable person would consider appropriate. Where another law asks for a legal basis, it is in brackets.
- Homepage — show you the posts of people you follow and the public feed. [our agreement with you]
- Search — find people and works for the words you typed. [our agreement]
- Discover — build suggestions from your library, your profile and what you asked, and remember your answers so the next round is better. [our agreement; your consent when you connect each Source]
- Library — hold what you have listened to, watched, read and played, and let you rate and sort it. [our agreement]
- Scan — read the Sources you connected, on your instruction. [your consent, given per Source]
- Profile — build a taste profile and show the parts of it you chose to make visible. [our agreement]
- Messages and pelts — deliver what you send to the person you sent it to. [our agreement]
- Plan — count your daily allowance, take payment through Stripe, and show your invoices. [our agreement]
- Sign-in and account mail — sign-in codes, deletion confirmations, notices of material changes, replies to you. No marketing email. [our agreement; legal obligation]
- Security — detect abuse, keep each account isolated, enforce quotas, investigate incidents. [legitimate interests; legal obligation]
- Fixing the product — understand why a scan or a search failed, from operational logs and your reports. [legitimate interests]
- Law — answer lawful requests. [legal obligation]
Peltify does not sell personal information, does not share it for advertising, and does not use your data to train a machine-learning model of its own. A new purpose means asking you first.
5. AI processing
- Suggestions, the reasons behind them, the taste-check questions and the profile’s wording are produced by large language models run by third parties, reached through OpenRouter.
- What is sent: the words you typed in Discover, the works and people you mentioned, the rows of your library and profile the ask needs, and your earlier answers in the thread. Never your credentials, never your messages to other people.
- OpenRouter’s published policy is that it does not train on what passes through it. The model provider it forwards to has its own retention policy, which Peltify does not control.
- Every suggestion is retrieved from real catalogue records first; the model chooses among them. The output is still an inference, is labelled as one, and can be wrong.
- No decision with a legal or similarly significant effect on you is made automatically. The only thing a profile affects is what Peltify suggests.
7. Where it is stored
- Your stored data and the hosted browser live in Canada (Azure, Canada Central).
- The application server, email, AI processing and payments run in the United States, so your data is processed there while in use and may be subject to lawful access there.
- Peltify shares only what each provider needs and chooses providers with strong contractual protections, but cannot promise that foreign law matches Canadian law.
- By using the Service you consent to this. If you would rather your data not leave Canada, Peltify cannot offer you the Service at this stage.
8. How long we keep it
- Your account and everything under it — for as long as the account exists.
- After you delete your account — a thirty-day undo window, during which nothing is removed and signing back in cancels the deletion. Then the account and everything under it is purged from the live database: reads, library, profile, posts, comments, likes, messages you sent, pelts, share cards, and the chat.
- After you reset your data — reads, profile, suggestions, verdicts, memories and stored Source sessions are removed at once. The account stays.
- After you forget a Source — its stored session, token or username is deleted at once.
- Posts, comments, messages — until you delete, archive or unsend them, or delete the account.
- The Discover thread — until you start a new chat or delete the account.
- Plan records — Stripe keeps its own records of payments for as long as its policy and tax law require. Peltify keeps the plan and customer id while the account exists.
- Database backups — encrypted, kept 35 days, then expired. Purged data may persist in a backup until then. Backups are used only to recover from a failure, never to restore one account.
- Operational logs — short-lived and rotated by the hosting provider. The AI spend log is purged with the account.
- Correspondence — as long as needed to deal with the matter and keep a record of it.
- Without an account — data stays in your browser. Clearing site data removes it.
Where a law requires a record to be kept longer, for example that a deletion request was received, we keep the minimum needed for that purpose.
9. How we protect it
- Every connection uses TLS.
- Passwords are hashed with scrypt and a per-user salt. Peltify cannot read them.
- The first sign-in from a browser needs the emailed code, even with the right password. A browser that has proved the address keeps a signed device cookie for 180 days, minted for that one account.
- Source sessions and tokens are encrypted at rest with AES-256-GCM, with a key held in the deployment environment and not in the database.
- Sign-in cookies are signed with a server secret, HttpOnly, SameSite, and Secure on the hosted deployment.
- Every record is namespaced to the account that owns it, and the Service is tested so a forged identity reaches nothing.
- Stripe events are verified by signature before they change a plan.
- Cover images are fetched only from the catalogue providers’ own hosts.
- Database access uses a least-privilege application role. Administrative access is limited to the founder.
No system is perfectly secure, and Peltify is a small validation-stage service without a security team. If Peltify learns of a breach involving your personal information that creates a real risk of significant harm, it will notify you and the relevant privacy regulator as PIPEDA and PIPA require, as soon as feasible. If you find a vulnerability, please email contact@peltify.com before disclosing it.
10. Your rights and controls
Most of these you can do yourself, in the app, without asking:
- Export — Settings gives you one JSON file with everything Peltify holds about you.
- Correct — your username, name, profile text, avatar and library records are editable in the app.
- Delete — Settings: Delete account (Section 8), or Reset data to keep the account and remove the reads and profile.
- Forget a Source — in Library › Scan, at any time. You can also revoke Peltify at the Source.
- Visibility — the profile sections other people see, and each post’s audience, are set in the app.
- Messages — whether strangers may message you is a setting. You can unsend a pelt you sent.
- Plan — cancel or change it from the Plan page, which opens Stripe’s customer portal.
- Email — Peltify sends only the messages the Service needs. The “Product updates” switch is off unless you turn it on, and nothing is mailed for it yet.
For anything else, an access request under PIPA or PIPEDA, a question about how a suggestion was made, or a GDPR right such as restriction or objection, email contact@peltify.com. We answer within 30 days or say why we need longer, may need to verify that you are the account holder, and charge nothing for a reasonable request. If we refuse, we say why and how to challenge it.
12. The Chrome extension
- The extension reads Sources in your own Chrome, on the sessions you are already signed into, so no third-party sign-in happens anywhere else.
- It runs only on the Source domains listed in its manifest and on Peltify’s own domains, and only while a scan you started is running.
- What it reads is sent to Peltify under your account and stored as in Section 2. Nothing goes anywhere else.
- It stores, locally in the browser, its link to your Peltify account and its own working state. It does not store your reads.
- It does not collect browsing history and does not run on other sites. Its use of data obtained through Chrome permissions is limited to the feature you enabled, consistent with the Chrome Web Store User Data Policy, including the Limited Use requirements.
- Removing the extension stops it entirely. It does not delete data already in your account; Settings does that.
13. Children
Peltify is not for anyone under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has an account, tell us at contact@peltify.com and we will delete it.
14. Changes to this policy
When the product changes what is collected, who processes it or how long it is kept, this policy changes in the same release, with a new effective date at the top. For a material change, if you have an account with a verified email, we will make reasonable efforts to tell you before it takes effect. Earlier versions are kept in Peltify’s source repository and can be produced on request.
15. Contact and complaints
Privacy questions, requests and complaints: contact@peltify.com. The founder is accountable for Peltify’s compliance with privacy law and answers personally.
If you are not satisfied with our response, you may complain to the Office of the Information and Privacy Commissioner for British Columbia, or, for matters under PIPEDA, to the Office of the Privacy Commissioner of Canada. If you are in the EEA or the UK, you may also complain to your local data protection authority.
Effective September 15, 2026. Previous versions: August 26, 2026; August 12, 2026.