Privacy Policy
Last updated: June 9, 2026
1. Introduction
This Privacy Policy describes how Peako ("we", "us", "our") collects, uses, and protects your personal information when you use our interactive system design lesson platform at peako.dev and app.peako.dev (collectively, the "Service").
We are committed to protecting your privacy. We collect only the data necessary to provide and improve the Service.
2. Information We Collect
Account Information
When you sign up via Google OAuth or email authentication, we collect:
- Email address
- Display name
- Profile photo URL (if provided by your OAuth provider)
Usage Data
When you use the Service, we collect:
- Lesson progress and choice history
- Architecture diagram state during lessons
- Lesson completion status
Analytics Data
We collect analytics to understand how the Service is used and to improve it. Before you sign in, this data is generally anonymous. After you sign in, we may associate your usage with your account using a pseudonymous identifier. This may include:
- Pages visited and features used
- Browser type and device information
- Referring URLs
- Approximate geographic location (country/region level)
Cookies
We use the following types of cookies:
| Type | Purpose |
|---|---|
| Essential | Authentication session management. Required for the Service to function. |
| Analytics | Usage metrics to improve the Service. Anonymous before sign-in; pseudonymous after sign-in. |
3. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your account
- Store your lesson progress and track your learning
- Analyze usage patterns to improve the user experience
- Send transactional communications related to your account
- Detect and prevent abuse or unauthorized access
We do not sell your personal information. We do not use your data for advertising or marketing profiling.
4. Data Storage and Security
Your data is stored securely using Supabase (hosted on cloud infrastructure). We implement industry-standard security measures including:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest for stored data
- Row-level security policies restricting access to your own data
- Regular security updates and monitoring
5. Third-Party Services
We use the following third-party services that may process your data:
- Supabase: authentication and database hosting
- Google: OAuth authentication provider
- Vercel: application hosting and edge delivery
- PostHog: product analytics and session replay (EU-hosted). See PostHog's privacy policy.
Each third-party service operates under its own privacy policy. We encourage you to review their policies.
6. Data Retention
We retain your account data and submissions for as long as your account is active. If you delete your account, we will delete your personal data within 30 days. Anonymized, aggregated data (e.g., overall usage statistics) may be retained indefinitely.
7. Your Rights
You have the right to:
- Access: request a copy of the personal data we hold about you
- Correction: request correction of inaccurate data
- Deletion: request deletion of your account and associated data
- Export: request an export of your data in a portable format
- Objection: object to processing of your data for analytics purposes
To exercise any of these rights, contact us at privacy@peako.dev. We will respond within 30 days.
8. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly. If you believe a child under 13 has provided us with personal information, please contact us at privacy@peako.dev.
9. International Data Transfers
Your data may be processed in countries other than your own. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws. We ensure appropriate safeguards are in place for such transfers.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact
For questions or concerns about this Privacy Policy or our data practices, contact us at privacy@peako.dev.