Privacy Policy
Last updated: August 31, 2026
Pelma (“we”, “us”) is an iOS app and a website (pelma.app) operated by Crolab, a French company whose full details are on the Legal Notice page. Crolab is the data controller. This policy explains what we collect, why, where it goes, and what you can ask us to do about it.
The one thing worth knowing up front: what you tell Pelma is health information, and we treat it that way. Your leaks stay between you and the app. Nothing you log is ever sold, shared with advertisers, or used to train anything, and you can wipe all of it from inside the app in two taps.
What we collect
- On the website, before you give us anything: anonymous usage of the assessment (which screen was seen, for how long, the answers you pick) tied to a random session identifier stored in your browser. This is how we improve the questionnaire. It never contains your name or email.
- Your first name: only what you type on the setup screen, so the app can address you. You can put anything you like there.
- Your assessment answers: the questionnaire responses, the resulting score, and whether your leaks are classified as stress, urge or mixed. This is what makes the program yours rather than generic.
- Your email address: when you ask us to send you your program at the end of the assessment. It creates your Pelma account, so the program you paid for on the web is waiting for you in the app. We also use it to send you your results and a short series of emails about the program; every one of them has an unsubscribe link.
- What you log in the app: the leaks and dry days you record, with the severity and trigger you pick, and the date and time. Plus the training sessions you complete.
- Purchase status: whether you have an active subscription. Payments on the website are handled by Stripe through RevenueCat; payments in the app are handled by Apple. We never see or store your card details.
- Crash and usage diagnostics: anonymous technical reports that tell us the app broke, and aggregate counts that tell us which screens are used.
- Advertising measurement: if you arrived from an ad, we may tell the advertising platform (Meta) that a visit, a completed assessment or a purchase happened, so we know which ads work. We send hashed identifiers only, never your answers, your score or anything about your leaks. You can opt out of this measurement in your browser or through the platform's own settings.
What we never do
- We never sell or rent your data.
- We never share what you log with an employer, an insurer, or any other third party beyond the service providers listed below.
- We never use your health data to train models.
- We never post anything anywhere on your behalf. Pelma has no social features by design.
Why we are allowed to hold it (legal basis)
- Performing our contract with you (GDPR Article 6(1)(b)), for your account, your subscription and the delivery of the program.
- Your explicit consent (Article 9(2)(a)), for the health information. Your assessment score and your leak records are special category data, and the law requires your explicit permission before we may process them. You give it by choosing to answer the questionnaire and to log your days, and you can withdraw it at any time by deleting your account.
- Our legitimate interest (Article 6(1)(f)), for anonymous website analytics and advertising measurement, which you can object to at any time.
Who processes data for us
- Supabase: your account, your profile and your logged history.
- Vercel: hosting of this website.
- RevenueCat and Stripe: web payments and subscription status.
- Apple: in-app payments, Sign in with Apple, app distribution.
- PostHog: aggregate product analytics. Sentry: anonymous crash reports.
- Klaviyo: the emails we send you.
- Meta: advertising measurement, as described above.
Some of these are located outside the European Union. Transfers rely on the European Commission's Standard Contractual Clauses.
How long we keep things
- Your account, your profile and your logged history: for as long as your account exists.
- Website assessment analytics: 13 months.
- Diagnostics: a rolling window of up to 90 days.
- Proof of purchase: as long as French accounting law requires.
Deleting your account
You can delete your account and everything attached to it from inside the app, in Settings → Delete account, or by writing to contact@pelma.app. It removes your profile, your assessment, every leak and dry day you logged, and your session history, on our servers and on your phone. It is immediate and it is not reversible.
Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, or restrict how we use it, and you can object to processing. Write to contact@pelma.app and we will answer within 30 days. If you are not satisfied, you can lodge a complaint with the CNIL, the French data protection authority (cnil.fr). If you are in California, you have equivalent rights under the CCPA; we do not sell or share personal information as defined there.
Children
Pelma is made for adults. It is not directed at children and we do not knowingly collect data from anyone under 16.
Not a medical record
What you log in Pelma is a personal training diary, not a medical record, and we are not a healthcare provider. The program does not diagnose anything (see the Legal Notice).
Changes
If we change this policy in a way that matters, we will update the date at the top and tell you by email or in the app.
Questions about any of this: contact@pelma.app.