Last updated 26 August 2026
This site collects one thing: an email address, and only if you type one into the waitlist form. No cookies, no analytics, no tracking. The rest of this page is the detail.
Your email address, if you submit the waitlist form. That is the only thing you are ever asked for, and the only personal data we deliberately store.
Ordinary server logs. Like any website, ours records requests as they arrive — including your IP address, the page requested, and your browser’s user-agent string. We do not read these routinely; they exist so the site can be kept running and abuse can be investigated.
Your IP address, very briefly. To stop automated abuse of the signup form, we count recent requests per IP address in memory for sixty seconds. Nothing is written to disk and nothing is kept afterwards.
Nothing else. This site sets no cookies, so there is no cookie banner to dismiss. There is no analytics, no advertising pixel, and no third-party script of any kind. Even the fonts are served from our own domain, so no font provider sees that you visited.
Your email address — consent. You gave it to us so we could tell you when the app is ready. That is the only thing we will use it for. We will not send you unrelated marketing, and we will not sell or rent the list to anyone. You can withdraw consent at any time and we will delete the address.
Logs and rate limiting — legitimate interests. Specifically, keeping the site available and preventing abuse of the signup form. This is a narrow interest and we have kept the data collected to the minimum that serves it.
Loops stores the waitlist and is what we will send the launch announcement from. Your email address is passed to them along with a note that it came from this site. Nothing else about you is sent — not your IP address, not your browser, not the page you were on.
Vercel hosts the site and processes the server logs described above as part of delivering it.
Both are based in the United States, so your email address is stored outside the UK. Both are bound by contract to process it only on our instructions. Nobody else receives it. We do not share it for advertising, and there is no advertising on this site to share it for.
Your email address until you ask us to remove it, or until the waitlist has served its purpose and we delete it — whichever comes first. It is not kept indefinitely just in case.
Server logs for the short retention period our host applies, then they are discarded.
Rate-limiting counts for sixty seconds, in memory only.
Under UK data protection law you can ask us to give you a copy of what we hold about you, correct it, delete it, restrict what we do with it, object to it, or hand it to another provider. You can withdraw your consent whenever you like. None of these cost anything and we will not ask you why.
The fastest route is to email hello@sendpeek.io. Say “delete me” and that is enough — you do not need to explain or use any particular wording. Every email we send will also have an unsubscribe link.
If you think we have handled your data badly, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you told us first, but you are not obliged to.
Peek is in testing. What follows describes the app; everything above describes this website.
The photo. It is encrypted on the sending device before it leaves. What arrives here is ciphertext we have no key for, and it is all we ever hold. We cannot open it, cannot preview it, and cannot produce it in readable form for anyone who asks — including a court.
The key. It is put into the link after the #, on the sender’s device. Browsers and messengers do not transmit that part of a URL to the server, so it never reaches us. Anyone holding the link can open the photo; anyone holding only the id cannot.
The policy you set. How long it lives, how many times it can be opened, how big the file is, how many times it has been opened, and whether a screenshot was reported. This is what lets the server enforce expiry rather than merely promise it. It describes the photo, never the person who opened it — no name, no account, no location, no IP address kept against it.
A notification token, if you allow notifications. So we can tell you your photo was opened. Your device keeps a secret and sends us only its hash, and a photo record points at an internal identifier rather than at anything your device would recognise as its own. Turning notifications off deletes the token rather than flagging it. Notifications say that something happened, never what.
Reports. If someone reports a photo they were sent, the report reaches us with whatever they wrote, and — if they chose to attach it — a copy of the photo sent from their device. We cannot decrypt anything ourselves, so this is the only way a person here can see what was reported. Reporting also stops the photo opening immediately. Reports and anything attached to them are kept separately and outlive the photo, because that is what makes them reviewable. We aim to look within 24 hours.
No accounts. The app asks for no email address, no phone number, and no name. Recipients install nothing to be identified and are never asked who they are.
How long any of it lasts. When a photo expires, is revoked, or runs out of views, both the record and the encrypted file are deleted — expiry means the bytes are gone, not that a flag was set. Notification tokens that nothing points at any more are deleted after 90 days.
What we cannot protect you from. A recipient can photograph the screen with another camera. No app can prevent that, and we do not claim to. What Peek does is deter it, tell you when a screenshot is taken on the device itself, and mark what is shown with an identifier tied to the recipient.
Peek is run by Lucas Oliveri, who is the data controller for the purposes of UK data protection law. You can reach us at hello@sendpeek.io.
If this policy changes, the date at the top changes with it. If the change is significant and we hold your email address, we will tell you rather than quietly editing the page.