Privacy Policy
Effective September 17, 2026
Peekr is made by JTTTsolutions, Inc., a Delaware corporation (“we”, “us”). This policy explains what we collect when you use the Peekr apps, the web app at peekr.dev, the API and the MCP server (together, the “Service”), why we collect it, and the choices you have. We wrote it to be read, not skimmed; if anything is unclear, write to privacy@peekr.dev.
The short version
- The desktop apps work entirely on your machine until you sign in. Nothing leaves your computer before that.
- When you sign in, the captures you file and everything attached to them sync to our servers so your workspace — and the agents you connect — can see them.
- We don't sell data, we don't run advertising, and we don't use your content to train models — ours or anyone else's.
- Delete a capture, a workspace or your account and the data is removed, not just hidden.
What we collect
Account information
Your name, email address and, if you sign in with Google, the profile picture Google shares. Passwords are stored as salted hashes. Magic-link and verification tokens are short-lived and single-use.
Content you create
Screenshots, the markup you draw on them, notes, titles, tags, comments, assignments and status changes. When you capture, the app also records context so the capture is useful later: the name of the application, the window title and — for browsers — the page URL. You can see and edit all of it before it's saved, and delete it afterwards.
Devices and sessions
For each signed-in device: a name you can change, its platform, the app version, and when it last synced. For each session: an IP address and user agent, so you can recognise and revoke it from your account page.
Agents and integrations
When an MCP client, API token, bot or webhook acts on your workspace we record what it did and on whose behalf, because that attribution is the point. We keep webhook delivery logs (status codes, timestamps, error text) for 30 days.
Operational logs
Request logs (timestamps, routes, status codes, IP addresses) and error reports, kept for up to 30 days to run and secure the Service. We do not use third-party analytics or advertising trackers on any part of the Service.
How we use it
- To provide the Service: store and sync your content, show it to the people and agents you've allowed, send the notifications you've chosen.
- To keep it secure: detect abuse, enforce quotas, investigate incidents.
- To talk to you: transactional email (verification, magic links, invites, notifications) and, rarely, notices about material changes to the Service or these terms. No marketing email without your explicit opt-in.
- To improve Peekr, using aggregate, de-identified usage counts (how many captures a day, which features are used) — never the content of captures.
Who can see your content
Visibility is a rule enforced by the database, not a preference: a capture is visible to its author, to admins of the workspace, and — once it's filed into a group — to the people in that group (or the whole workspace, for workspace-visible groups). Guests see only the private groups they've been added to. Agents connected by a person see exactly what that person sees; bots see what their role and group memberships allow. We publish the full rules in the documentation.
Our staff do not look at your content except when you ask us to for support, or when required to investigate abuse or a security incident, and access is logged.
Where it lives, and who we rely on
The Service runs in the United States. We use a small number of subprocessors, each bound by their own data-processing terms:
| Provider | Purpose |
|---|---|
| Railway | Application servers and the Postgres database |
| Cloudflare | Screenshot storage (R2), DNS and network security |
| Resend | Sending transactional email |
| Sign-in with Google, only if you choose it |
We'll update this list here before adding a provider that handles your content.
Retention and deletion
- Content stays as long as your workspace keeps it. Workspace admins can set a retention policy that deletes screenshots a chosen number of days after a capture is resolved (the note and discussion stay).
- Deleting a capture removes it for everyone; its screenshots are removed from storage within 24 hours. Deleting a workspace removes everything in it. Deleting your account removes your profile and your personal captures; content you contributed to a shared workspace stays with that workspace, attributed to a “former member”.
- Encrypted database backups are kept for 30 days and then destroyed; deleted data can persist in backups for that window.
- Desktop apps keep a local copy of what you can see. Signing out removes the synced copy from that device; a local-only library (captures you never synced) stays on your machine, because it's yours.
Security
Everything travels over TLS. Screenshots are stored under content-addressed names in a private bucket and served through short-lived signed links. Row-level security in the database enforces visibility on every query. Passwords are hashed with a modern algorithm; API tokens and bot tokens are stored only as hashes and shown once. If we ever learn of a breach affecting your data, we'll tell you without undue delay.
Your rights and choices
Wherever you live, you can access, correct, export and delete your data from within the Service, and you can email us to do any of it for you. If you're in the EEA, the UK, Switzerland or a US state with a privacy law, you also have the right to object to or restrict certain processing and to complain to your local authority; we'll cooperate fully. Our legal basis for processing is performance of our contract with you, and our legitimate interest in running a secure service. We don't make automated decisions with legal effect about you.
Children
Peekr is for people 16 and older. If you believe a younger person has created an account, tell us and we'll remove it.
Changes
If we change this policy in a way that matters, we'll email account holders and post the new version here with a new effective date at least 14 days before it applies.
Contact
JTTTsolutions, Inc.
Delaware, United States
privacy@peekr.dev