PeakList Legal

Consumer Health Data Privacy Policy

Effective Date: July 11, 2026 • Last Updated: July 11, 2026

This Consumer Health Data Privacy Policy describes how PeakList collects, uses, and shares “consumer health data,” including information that identifies or can reasonably be linked to a consumer and identifies past, present, or future physical or mental health status. It supplements the PeakList Privacy Policy. If this notice provides greater protection for consumer health data, this notice controls for that data.

PeakList is operated by Nathan Sobol. In this notice, “PeakList,” “we,” “us,” and “our” refer to Nathan Sobol and the services used to provide PeakList. This notice provides consumer health data disclosures required by the Washington My Health My Data Act where applicable.

1. Consumer Health Data We Collect 2. Sources of Consumer Health Data 3. Why We Collect and Use Consumer Health Data 4. Consumer Health Data We Share 5. Your Consumer Health Data Rights

1. Consumer Health Data We Collect

Depending on the features you choose, PeakList may collect or infer the following categories of consumer health data:

  • Health and workout data: hiking, walking, running, workout type, workout date and time, duration, distance, energy or calorie estimates, elevation gain and loss, pace, speed, heart-rate or other workout information contained in a user-selected Apple Health, Strava, Garmin, AllTrails, GPX, TCX, FIT, KML, or similar import.
  • Fitness and activity data: hike logs, routes, trail and summit activity, completion history, moving and elapsed time, effort summaries, checkpoint or summit matches, personal bests, fitness progress, activity-source metadata, and PeakList Global validation or ranking information.
  • Precise and approximate location data: route tracks, waypoints, timestamps, elevation, trailheads, meeting locations, navigation progress, last known coordinates, breadcrumbs, public route geometry, custom routes, location snapshots, and location-derived activity patterns.
  • Nutrition, hydration, and planning data: selected foods, quantities, weights, calories, macronutrients, sodium, calories per day or ounce, water estimates, hydration calculations, carry or gear choices, trip-readiness inputs, and related planning values.
  • Safety and environmental context: weather, conditions, exposure, altitude, daylight, trail or access reports, device and sensor diagnostics, emergency or urgent plan status, and other context you request in connection with an outdoor activity.
  • Health-related inferences: estimated pace, duration, calorie or water needs, effort eligibility, progress, readiness, route difficulty context, personal targets, activity patterns, or similar conclusions produced from the information above.
  • Identifiers and operational metadata: account and user identifiers, connected-provider identifiers, import identifiers, file hashes, consent and permission state, timestamps, source application, device/app context, quota and anti-abuse records, and support or audit information linked to health-related use.

PeakList does not intentionally collect diagnoses, prescriptions, medical records, genetic data, reproductive or sexual-health data, biometric templates used for identification, or clinical treatment information. Do not enter those categories into free-text fields or support messages unless PeakList expressly requests them for a supported purpose.

2. Sources of Consumer Health Data

We may collect consumer health data from:

  • you, including information you enter, upload, import, save, sync, publish, or submit;
  • your device and Apple frameworks, including HealthKit, Core Location, motion, altitude, heading, camera, photo library, local files, widgets, Live Activities, and app-group storage, only as permitted by your choices and system permissions;
  • connected or user-selected services and files, including Strava, Garmin, AllTrails exports, GPX, TCX, FIT, KML, and similar route or activity files;
  • PeakList features that calculate or infer information from your inputs, such as Navigate, Long Trail navigation, Custom Route, Snap, Plan Builder, Food Library, Water Calculator, PeakList Global, and safety or environmental tools;
  • other users when they invite you to or collaborate with you in a live plan, report content, or submit shared activity information; and
  • service providers that return requested route, elevation, weather, daylight, environmental, map, trail, access, plant, or activity results.

3. Why We Collect and Use Consumer Health Data

We collect and use consumer health data only as reasonably necessary to:

  • provide the feature you request, including recording or importing a hike, displaying progress, calculating or saving a route, preparing a trip, estimating food or water needs, showing weather or environmental context, restoring a navigation session, or validating an eligible PeakList Global effort;
  • sync, back up, export, share, publish, or display information when you direct us to do so;
  • personalize your lists, history, achievements, targets, planning, and app experience;
  • maintain account, entitlement, quota, provider-connection, import, duplicate-prevention, and consent state;
  • provide customer support, investigate errors, and honor privacy or deletion requests;
  • protect accounts and users, detect abuse or manipulated activity, enforce community and competition rules, maintain auditability, and comply with law; and
  • create aggregate or de-identified statistics that are not reasonably linkable to an individual.

We do not use consumer health data for advertising, cross-context behavioral advertising, data brokerage, credit or insurance eligibility, employment decisions, or unrelated profiling. We do not use HealthKit data for marketing or advertising.

Where applicable law requires consent, PeakList requests affirmative consent before collecting consumer health data or before sharing it beyond what is necessary to provide the product or service you requested. A general acknowledgement of the Privacy Policy or acceptance of the Terms is not a substitute for separate consent where the law requires it.

4. Consumer Health Data We Share

The categories of consumer health data PeakList may share are:

  • Health and workout data and fitness and activity data: with Apple or a connected activity provider as needed for the integration you authorize; with Supabase for account-scoped storage, sync, support, security, and deletion; and with people or the public when you direct a hike, route, activity, or standing to be shared.
  • Precise and approximate location data: with Supabase or Cloudflare for a requested sync, route, public link, live-plan, navigation, security, or deletion function; with GraphHopper or another disclosed feature provider for an online route or other location-based request; and with people or the public when you direct location or route information to be shared.
  • Nutrition, hydration, and planning data: with Supabase for account-scoped storage, sync, support, security, and deletion, and with people you invite when you direct the information to be included in a shared plan.
  • Safety and environmental context: with Supabase or a disclosed weather, daylight, elevation, map, trail, access, environmental, or similar provider as needed to return, store, or support the result you request, and with people or the public when you direct a related report or plan to be shared.
  • Health-related inferences: with Supabase for the requested feature, account-scoped storage, sync, support, security, and deletion, and with people or the public when you direct a result, plan, progress record, or PeakList Global standing to be shared.
  • Identifiers and operational metadata linked to health-related use: with Apple, Supabase, Cloudflare, connected activity providers, feature providers, and support or operations providers as needed for authentication, permissions, delivery, integration, security, support, audit, consent, deletion, and the requested feature.

Those categories may be shared with the following categories of recipients and specific providers:

  • At your direction: with people or the public when you publish or share a hike, photo, route, location snapshot, plan, live-plan content, trail report, public profile activity, or PeakList Global standing. Public content can be copied, cached, indexed, downloaded, screenshotted, or retained by others.
  • Apple: HealthKit provides data you authorize; Apple Push Notification service, widgets, Live Activities, Siri, Shortcuts, Spotlight, and other Apple surfaces process the information needed for the feature and may display information according to your device settings.
  • Supabase: authentication, account-scoped databases, sync, Edge Functions, first-party analytics where enabled, provider-connection records, security, moderation, support, and deletion workflows.
  • Cloudflare: PeakList APIs, public links, user-owned object storage, route and asset delivery, security, rate limiting, support verification, and account-deletion object cleanup.
  • Connected activity providers: Strava and Garmin receive authorization and disconnection requests and provide the activity information you authorize. AllTrails data is processed from files you select; PeakList does not connect to an AllTrails account in the current implementation.
  • Feature providers: GraphHopper or another disclosed routing provider for an online route request; weather, daylight, elevation, map, trail, access, environmental, or similar providers for the coordinates and context needed to return the result; and PlantNet when you submit a plant-identification image.
  • Support and operations providers: Resend or similar email services when health-related information is included in a support or operational message, and Firebase/Google for opted-in analytics, crash, or performance processing as described in the general Privacy Policy. PeakList is designed not to send raw route coordinates or HealthKit values in ordinary analytics events.
  • Legal and safety recipients: regulators, courts, law enforcement, professional advisers, transaction counterparties, or others when disclosure is legally required or reasonably necessary to protect rights, security, users, or the service.

These recipients process data for the limited role described above and under their applicable contracts, policies, or legal obligations.

Specific affiliates with whom PeakList shares consumer health data: None as of the Last Updated date.

Categories of consumer health data sold: None. We do not sell consumer health data.

5. Your Consumer Health Data Rights

Subject to applicable law and permitted exceptions, you may request to:

  • confirm whether PeakList is collecting, sharing, or selling your consumer health data;
  • access the consumer health data associated with you, including a list of third parties or affiliates with whom it was shared where required;
  • correct inaccurate consumer health data;
  • delete consumer health data from PeakList systems;
  • withdraw consent to future collection or sharing; and
  • appeal a denial of your request.

Submit a request by emailing [email protected] with the subject “Consumer Health Data Request” and identifying the right you wish to exercise. We may verify your identity using information reasonably related to your account and request. An authorized agent may act for you where permitted, but we may request proof of authority and direct verification with you.

You may withdraw consent prospectively by changing the relevant in-app setting, revoking the iOS permission, disconnecting the provider, stopping the activity, deleting or unpublishing supported content, or submitting a request. Withdrawal does not affect processing already performed lawfully and may make the related feature unavailable.

If you request deletion, PeakList will delete consumer health data from active systems and notify relevant processors and other recipients as required by applicable law. Deletion from archived or backup systems may be delayed for the period allowed by law, which may be up to six months after authentication under Washington law. Copies retained by Apple, connected providers, public recipients, other users, or device backups may need to be deleted through those parties or systems.

PeakList will respond without undue delay and within the period required by applicable law. Under Washington law, that period is generally 45 days after receipt, subject to one reasonably necessary 45-day extension with notice. Requests are generally free up to twice annually, although manifestly unfounded, excessive, or repetitive requests may be denied or subject to a reasonable administrative fee where law permits.

If we deny or limit a request, appeal by emailing [email protected] with the subject “Privacy Appeal” and explain why the decision should be reconsidered. We will provide a written appeal response within the period required by applicable law. If the appeal is denied, you may contact the Washington State Attorney General or another competent privacy regulator where applicable. PeakList will not discriminate against you for exercising a consumer health data right, although we may be unable to provide a feature that requires data you asked us not to process.

View Privacy Policy View Terms Open support Back to PeakList