The official Peach app uses SSL and they also do certificate pinning in the requests, that's not a problem. The problem is that Peach's server side authorisation token does not expire when you 'log out' and you can reuse the token.
The issue is mainly got to do with third party apps + this flaw in Peach's API. There is already one[0] which has reversed the Peach API, and the flaw is still present. What happens when another third-party Peach app comes out and does not use SSL, you can still use Peach's API without SSL and it does not default to HTTPS.
This sort of flaw would lead to a similar issue to the Snapsaved leak[1].
[0] http://techcrunch.com/2016/01/14/peach-gets-an-unofficial-we...
[1] http://techcrunch.com/2014/10/13/snapsaved-takes-responsibil...