Privacy Policy
Last updated: August 12, 2026
Pelma ("we", "us") is an iOS app operated by Crolab, a French company whose full details are on the Legal Notice page. Crolab is the data controller. This policy explains what the app collects, why, where it goes, and what you can ask us to do about it.
The one thing worth knowing up front: what you tell Pelma is health information, and we treat it that way. Your leaks stay between you and the app. Nothing you log is ever sold, shared with advertisers, or used to train anything — and you can wipe all of it from inside the app in two taps.
What we collect
- Nothing, to start with. You can complete the assessment and use the programme without creating an account. The app opens an anonymous session so your progress is saved on your device.
- Your first name — only what you type on the setup screen, so the app can address you. You can put anything you like there.
- Your assessment answers — the questionnaire responses, the resulting score, and whether your leaks are classified as stress, urge or mixed. This is what makes the programme yours rather than generic.
- What you log — the leaks and dry days you record, with the severity and trigger you pick, and the date and time. Plus the training sessions you complete.
- Your email address — only if you choose to create an account, either directly or through Sign in with Apple. If you use Apple's private relay, we only ever see the relay address.
- Purchase status — whether you have an active subscription. Payments are handled entirely by Apple and managed through RevenueCat. We never see or store your card details.
- Crash and usage diagnostics — anonymous technical reports that tell us the app broke, and aggregate counts that tell us which screens are used. These never contain your score, your severities or your triggers.
What we never do
- We never sell or rent your data. There is no ad network in this app and nobody to sell it to.
- We never share what you log with an employer, an insurer, or any other third party beyond the service providers listed below.
- We never use your health data to train models.
- We never post anything anywhere on your behalf. Pelma has no social features by design.
Why we are allowed to hold it (legal basis)
Two grounds, under the GDPR:
- Performing our contract with you (Article 6(1)(b)) — for your account, your subscription and the delivery of the programme.
- Your explicit consent (Article 9(2)(a)) — for the health information. Your assessment score, your leak records and their severity are special category data, and the law requires your explicit permission before we may process them. You give it by choosing to answer the questionnaire and to log your days, and you can withdraw it at any time by deleting your account.
Withdrawing consent does not undo processing that already took place, and it does not affect our legal obligation to keep proof of purchase.
Permissions the app asks for
Pelma asks for very little, and iOS will always ask you first:
- Notifications — only to remind you of your daily session, at the time you pick. These reminders are scheduled on your phone: no reminder ever travels through a server, and their wording never mentions leaks or anything intimate.
That is the whole list. Pelma does not use your camera, your microphone, your photo library, your contacts or your location. It is not connected to Apple Health.
Who processes data for us
- Supabase — your account, your profile and your logged history, so they survive a phone change.
- Apple — payments, Sign in with Apple, app distribution.
- RevenueCat — subscription status management.
- Sentry — anonymous crash reports.
- PostHog — aggregate product analytics.
Some of these are located outside the European Union. Transfers rely on the European Commission's Standard Contractual Clauses.
How long we keep things
- Your account, your profile and your logged history — for as long as your account exists, because the whole point is to show you change over months.
- Diagnostics — a rolling window of up to 90 days.
- Proof of purchase — as long as French accounting law requires.
Security
Traffic between the app and our servers is encrypted in transit (HTTPS). Your session token is held in the iOS Keychain, not in plain storage. On the server, row-level security means a signed-in account can only ever read and write its own rows — your history is not reachable from another account.
Deleting your account
You can delete your account and everything attached to it from inside the app, in Settings → Delete account. It removes your profile, your assessment, every leak and dry day you logged, and your session history — on our servers and on your phone. It is immediate and it is not reversible.
Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, or restrict how we use it, and you can object to processing. Write to contact@pelma.app and we will answer within 30 days. If you are not satisfied, you can lodge a complaint with the CNIL, the French data protection authority (cnil.fr).
Children
Pelma is made for adults. It is not directed at children, we do not knowingly collect data from anyone under 16, and the App Store rating reflects that. If you believe a child has given us information, write to us and we will remove it.
Not a medical record
What you log in Pelma is a personal training diary, not a medical record, and we are not a healthcare provider. The app does not diagnose anything — see the Legal Notice. If you want to show your history to a doctor, that is entirely your choice and your copy.
Changes
If we change this policy in a way that matters, we will update the date at the top and tell you in the app.
Contact
Questions about any of this: contact@pelma.app.