Privacy

What PeerFlow holds about you, who else can see it, and how to get rid of it.

Last updated 5 September 2026

The short version

PeerFlow holds the account you made, the profile you filled in, and the record of the sessions you booked. There is no advertising on this site. The public pages count page views so we can see where people arrive from, and that count cannot tell one visitor from another. It keeps nothing in your browser unless you ask not to be counted, which is the one thing it stores. Nothing about you is sold or handed to anyone whose job is not running PeerFlow. If you want all of it gone, Settings has a button that does it, and it does not wait for anyone's approval.

What we hold

Your account. An email address, and either a password — stored as a hash, so nobody here can read it back — or the fact that you signed in with Google. If you use Google, what we receive is your email address and the name on that account, and nothing else.

Your profile. Your name, the path and topic you are learning, the stage you are at, what you are learning for, your timezone, and the hours you marked free. All of that is visible to other members, which is the point of it: it is how somebody decides whether to ask you to be their partner.

Your picture, if you signed in with Google. We keep the address of the photo on your Google account and show it next to your name wherever it appears to another member — the list of people, your profile, a conversation, a partner card. Other members see it, for the same reason they see the rest of your profile. No image is stored here — your browser fetches it from Google, the same way it already does for the picture in your own account menu. If you signed up with an email address there is no photo and your initial is shown instead, and removing the picture from your Google account removes it here the next time you sign in. Added 8 September 2026; before that date the site held no picture of you at all.

Your sessions. Who you paired with, the times you booked, the topic and goal written on each one, and whether you turned up. Attendance is recorded by the video server rather than by either of you claiming it.

Your messages. Chat with a partner is stored so that it is still there next time. It is not end-to-end encrypted and we will not imply otherwise: it sits in a database we can read.

Your notifications. The list behind the bell, and whether an email went out for each one.

If you left your email on the home page before making an account, that is stored as well, along with whatever you typed about what you wanted to learn.

What we don't do

No advertising. No third-party analytics — no Google Analytics, no tracking pixel, no service that would see you here and recognise you somewhere else. No tracking cookies, and no tracking without them either: the only thing PeerFlow keeps in your browser is the token that holds you signed in, and clearing it signs you out. Nothing about you is sold, rented, or passed to a data broker, and there is no arrangement under which that could change without this page changing first.

Until 4 September 2026 this page said there was no analytics of any kind, including a self-hosted one, and that nobody here knew which pages you looked at. That stopped being true on that date and the section below says what replaced it. It is recorded here rather than quietly edited out, because a promise that changes without saying so is worse than one that was never made.

Counting visits

The public pages — the home page, the eight learning paths, the guides and these legal pages — record that a page was viewed. There is no script on the signed-in pages, so nothing records which parts of the app you use.

What a view records: which page, the hostname of the site you arrived from if you followed a link, any campaign tag in the address, a device class (mobile, tablet or desktop), a browser family from a fixed list, and the timezone your browser reports. That last one is the closest thing to a location and it is a region shared by millions of people, not an address.

What it does not record, and could not: any identifier, cookie or fingerprint, your IP address, your full user-agent string, or the full address of the page you came from. There is nothing in the table that could join two page views together, which means we cannot count how many people visited, or follow anyone from one page to the next, and cannot connect any of it to an account. Those are not settings that could be turned on later; the data to do it is not collected.

One thing can be written to your browser, and only if you ask for it. Adding ?pf_count=off to any address here stores a single value meaning do not count me, and while it is there no view of yours is recorded at all; ?pf_count=on removes it. It is the same value for everyone who sets it, so it identifies nobody, and it is never sent anywhere — what it does is stop the request being made. It lives in that browser only, so it has to be set again on another device, and clearing your browsing data removes it.

Until 5 September 2026 this section said nothing was written to your browser at all, which was true until that option existed. The sentence is corrected rather than removed for the same reason as the dated line further up.

It is ours, on our own servers, and no third party is involved. If your browser sends Do Not Track or Global Privacy Control, nothing is recorded at all. Rows are deleted after ninety days.

Your calls

Video and audio run through LiveKit, which passes the streams between the two of you. Calls are not recorded — not by us and not by LiveKit. There is no recording feature in PeerFlow and nothing from a call is written to disk. What comes back from the video server is the bare fact of attendance: that your account joined a room at one moment and left at another. That is what a streak is counted from.

What your partner does at their end is between the two of you. Somebody can point a phone at their own screen and neither we nor you would ever know.

Who else sees it

Running the site means a few companies handle your data on our behalf. Each is used for one job:

  • Supabase — the database and the sign-in system. Everything listed above lives there.
  • Vercel — serves the pages, and therefore sees the requests for them, including your IP address.
  • LiveKit Cloud — carries the video and audio while a call is happening.
  • Resend — sends the email, so it handles your address and the text of the message.
  • Google — if you chose to sign in with Google. Google also serves the typeface the site is set in, which means your browser fetches a file from Google on every page and Google sees your IP address in the process.
  • jsDelivr — a content network that serves two JavaScript libraries the site depends on. Same point about IP addresses.

Beyond those: other members see your profile, and your partner sees what you write to them.

And the person who runs PeerFlow can see the account records themselves — your name, which path you chose, when you signed up, when you last signed in, and how many sessions you have proposed, booked and turned up to. That is one screen listing everyone with an account, and it exists to answer whether people are coming back. Nothing new is collected for it: those are the records you made by signing up and by booking, and the sign-in dates are kept by Supabase for every account on every service built on it.

It does not include your messages, and it is not connected to the page views described above — there is still nothing in that table that could be tied to an account, so it cannot say which pages any particular member read.

The paragraph above is new on 5 September 2026. This section used to end "Nobody else sees anything", which was written about other members and read as though it covered the operator too. The screen it describes is new; the records on it are not.

Email

We email you when a session needs an answer — a time proposed, accepted, turned down or called off — and for nothing else. There is no newsletter and there are no product announcements. You can switch it off in Settings, and the bell inside the app carries on working either way.

How long it is kept

Until you delete it. Your profile, your sessions and your messages stay for as long as the account does.

Getting rid of it

Settings has Delete your account. It removes the account itself, your profile, your sessions, your messages and your notifications, immediately, with nothing to approve and nobody to email first.

Two things outlive it, and both are about somebody else's record rather than yours. A former partner's own session rows keep the times the two of you booked, with your name taken off them — otherwise their history would quietly rewrite itself. And if somebody reported you, the report stays, because the whole use of a report is that a pattern is still visible later.

Backups are a separate matter. Supabase keeps encrypted backups on a short rotation, so a deleted row can survive there for up to thirty days before it ages out. Nobody opens a backup except to restore one.

Age

PeerFlow puts two people who have not met on a video call together. You need to be 16 or older to hold an account.

Changes

If this changes in a way that matters — a new company handling your data, or a new thing collected — the date at the top changes and every account gets an email about it. Fixing a clumsy sentence will not get an email.

Asking about any of this

Write to hello@peerflow.dev. If you want to know what is held about you, ask from the address you signed up with and you will be sent it.