Privacy policy
Last updated 11 October 2026
Peekdrift is a visual regression testing service for Storybook. This policy explains what we collect when you use peekdrift.com, app.peekdrift.com and the peekdrift command-line tool, why we collect it, and what you can do about it.
Peekdrift is operated by Erwan Andre Marcel Joly, a sole trader in New Zealand (NZBN 9429050980765), who is responsible for your personal data. Questions go to admin@peekdrift.com.
What we collect
- Account details. Your name, email address and profile picture, from the sign-in provider you choose (email and password, Google or GitHub).
- Organizations and projects. Their names, who belongs to them, project tokens (stored only as hashes) and settings.
- Snapshots. The PNG screenshots your CI uploads, with their story names, themes and viewports, and the git details of each build: commit hash, branch name, ancestor commits and pull request number.
- Storybook builds. If Peekdrift takes your screenshots, the static files of your built Storybook (its HTML, JavaScript, CSS and assets). We use them only to render your stories in an isolated, single-use sandbox.
- Review decisions. Who accepted or rejected which change, and when.
- GitHub connection. If you install the Peekdrift GitHub App: the installation, the repository you connect, and the commit statuses and pull request comments we post.
- Billing. If you subscribe, Stripe handles your card details; we never see or store them. We keep the Stripe customer and subscription identifiers and your plan.
- Technical logs. Request logs (including IP addresses) and error logs, used to run and secure the service.
We do not use advertising or analytics trackers. The only cookie is the session cookie that keeps you signed in to app.peekdrift.com.
Why we use it
To provide the service you signed up for (storing and comparing snapshots, showing reviews, reporting to GitHub), to bill paid plans, to keep the service secure and to answer support requests. We rely on performing our contract with you and on our legitimate interest in running a secure service. We do not sell personal data, and we do not use your snapshots for anything other than providing Peekdrift to you.
Who processes it
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, snapshot storage, logs, email | United States (Oregon) |
| Supabase | Database | United States (Oregon) |
| Auth0 (Okta) | Sign-in | United States |
| Stripe | Payments, for paid plans | United States and elsewhere |
| GitHub | Commit statuses and comments, if you install the app | United States |
Your data may therefore be processed outside your country. Each of these providers is bound by its own data protection terms.
How long we keep it
- Account, organization and project data: while your account exists.
- Snapshots and review history: while the organization exists, or until you ask us to delete them.
- Diff images (the highlighted differences): 90 days.
- Uploaded Storybook files: 90 days after they were last uploaded.
- Unfinished uploads: 1 day.
- Request and error logs: 30 days.
- Billing records: as long as tax law requires.
Security
Snapshots are stored in private, encrypted storage under a separate path for each organization, are never shared between organizations, even when two upload an identical image, and are only reachable through links that expire within the hour. All traffic uses HTTPS. Secrets are kept in an encrypted parameter store, never in code.
Your rights
You can ask for a copy of your personal data, for corrections, or for your account and data to be deleted, by emailing admin@peekdrift.com from your account's address. We answer within 30 days. Depending on where you live, you may also be able to object to processing or complain to your data protection authority; in New Zealand, that is the Office of the Privacy Commissioner.
Changes
If we change this policy in a way that matters, we'll update the date above and tell account owners by email before the change takes effect.