Privacy Policy — Gailuh
1. Data controller
The controller of your personal data is:
- Controller: Irakai Studio SL
- NIF/CIF: B95935615
- Registered address: Meñaka bidea 4, 48100 Mungia (Bizkaia), Spain
- Privacy / contact email: roberto@irakai.com
- Data Protection Officer (DPO): not appointed — none of the circumstances of art. 37 GDPR that require one apply (we are not a public authority and our activity does not involve regular and systematic large-scale monitoring or large-scale processing of special categories of data). For any privacy matter or to exercise your rights, use the contact email indicated above.
This policy governs the processing of the data of users of the Gailuh application (hereinafter, “the app”).
2. Quick summary (the important part in 30 seconds)
- Your progress photos NEVER leave your iPhone. They are stored only on your device, encrypted. We do not upload them to any server or provider. Only the date and the body zone travel to the server, never the image.
- We collect the minimum data needed for the app to work: your account, the devices and routines you record, your usage records and streaks, and the status of your subscription.
- We do not track you across other companies’ apps or websites. We do not use the advertising identifier (IDFA).
- Analytics and error diagnostics identify you only with a non-reversible code (hash), never with your name or email. You can turn off product analytics whenever you want from Settings → Privacy.
- You can delete your account and your data from within the app itself.
3. What data we collect and for what purpose
Verified against the app’s actual data schema (
specs/tecnico-claude.md§7.1 / §7.3 andspecs/funcional-claude.md§5). We do not collect phone number, precise geolocation, contacts, or data from HealthKit / Apple Health sensors.
3.1. Account and identity data
- Email and, on password-based accounts, an encrypted password (hash). If you sign in with Apple or Google, we receive your provider’s identifier and, depending on your choice, your name and an email (which may be an Apple “Hide My Email” private relay address).
- Display name and avatar (initials or, where applicable, a photo — see §3.4).
- Account preferences (theme/appearance, Face ID protection).
The email is handled in the authentication layer (Supabase Auth), not in your app profile.
3.2. Your activity in the app
- The beauty devices, fitness routines and supplements you add, with their custom name or brand.
- Configuration of each item: weekly frequency/goal, reminders, days, body zones.
- Usage records, pauses and streaks.
3.3. Metadata of your progress photos (NOT the image)
- Only the date the photo was taken and the associated body zone. The image is never transmitted (see §4).
3.4. Profile avatar
- If you use initials, no image is processed.
- If you upload an optional avatar photo for your profile, that image is local-only: it lives in your iPhone’s private storage (just like your body progress photos — see §4) and is neither stored nor synced to our server. It is deleted along with the rest of the local content when you delete your account or uninstall the app.
3.5. Your Pro subscription
- The product purchased, the store (App Store / Google Play) and the dates it is in force. This information is handled by our subscription provider (RevenueCat) based on the store receipt.
3.6. Technical and diagnostic data (without identifying you)
- For stability and product improvement we process usage events and error/performance reports, associated with a non-reversible hashed identifier derived from your internal identifier, never with your email, name or phone number, and never with the content of your photos (see §10).
4. Special treatment of your body progress photos
This is a core privacy decision of Gailuh and we explain it in detail.
Your progress photos (including the first-day one) are stored EXCLUSIVELY on your iPhone, inside the app’s private storage, encrypted at rest by means of the iOS system’s data protection (iOS Data Protection).
- We never upload your photos to our servers or to any external provider. There is no “bucket” or cloud storage for them in our infrastructure.
- Only metadata without the image travels to the server: the date and the body zone. We do not store the image, nor thumbnails, nor EXIF data, nor location, nor dimensions, nor a hash of the content. That metadata only serves to regroup your series if you change device or recover your Pro access.
- Text you will see inside the app (canonical copy): “Your photos live only on your iPhone, never on our servers. Turn on iCloud Photos in the system Settings to have an automatic backup.”
Nature of this data. Because the images are never transmitted to us and are not accessible to us, we do not carry out any processing of them within the meaning of the GDPR: they remain under your exclusive control on your device, like any photo in your camera roll, and the app acts as a purely local tool. We do not perform facial recognition and do not identify anyone from the images (Recital 51 GDPR). The only data related to your photos that we do process is the date and the body zone (§3.3), which do not include the image and do not on their own reveal information about your health.
Backup under your control. By default your photos are only in the app. You can enable “Save a copy to iPhone Photos” (an option disabled by default) to copy them to your photo library, or use iCloud Photos. Both routes are yours and do not pass through our servers. Important: if you enable either of these copies, those images fall outside our technical control and we will not be able to delete them for you (see §7).
Additional protection. You can protect the progress gallery, the comparison view and “My photos” with Face ID (enabled by default).
Menstrual cycle notice. Before a photo of the abdomen zone, the app shows a respectful, non-blocking notice asking whether you would rather take the photo now or repeat it in a few days (because of possible bloating associated with the cycle). We keep this feature because it helps you take comparable photos. The app does not store or transmit any data about your cycle: the notice is triggered solely by the body zone you are about to photograph, so no processing of information about your cycle takes place on our side.
Internal sources:
specs/funcional-claude.md§21, §12.7 and §12.8;specs/tecnico-claude.md§7.1 (photo_metadatatable, with no image/path column), §7.13.
5. Legal basis for each processing operation (art. 6 and art. 9 GDPR)
| Purpose | Data | Legal basis |
|---|---|---|
| Create and maintain your account; provide the tracking service (devices, routines, usage records, streaks, configuration); sync across your devices and the Apple Watch | Account/identity and your activity (§3.1–3.2) | Performance of the contract — art. 6(1)(b) |
| Photo metadata (date + zone) to regroup your series | §3.3 | Performance of the contract — art. 6(1)(b) |
| Your body progress photos | Images (§4) | No processing on our side: the images remain exclusively on your device and we never receive them (§4) |
| Manage your Pro subscription and your access | §3.5 | Performance of the contract — art. 6(1)(b), and legal obligation (accounting/tax) — art. 6(1)(c) |
| Error and performance diagnostics (Sentry) | §3.6 (technical data, hashed identifier) | Legitimate interest — art. 6(1)(f) (service stability and security; legitimate interest assessment documented) |
| Product analytics (PostHog) | §3.6 (pseudonymous usage events, no PII) | Legitimate interest — art. 6(1)(f) (product improvement); you can turn it off at any time from Settings → Privacy within the app (§9) |
Sources: https://gdpr-info.eu/art-6-gdpr/ · https://gdpr-info.eu/art-9-gdpr/ · https://gdpr-info.eu/art-7-gdpr/
The photo features are optional: if you do not use them, the app works normally. Because the images never leave your device, we do not need to ask for your consent to process them — we do not process them. As for product analytics, you can turn it off at any time from Settings → Privacy within the app; as for error diagnostics, you can object through the privacy contact (§9 and §17).
6. Recipients and data processors (subprocessors)
To provide the service we rely on the following providers, which act as data processors on behalf of the controller, bound by the corresponding processing agreement (DPA, art. 28 GDPR). None of them processes your progress photos (they are local-only).
| Processor | Purpose | Categories of data | Region / country | Transfer safeguard | DPA |
|---|---|---|---|---|---|
| Supabase (Supabase, Inc.) | Database, authentication and backend functions | Account, devices, routines, usage records, streaks, configuration, photo metadata | EU (residency in Frankfurt/Ireland); parent company in the USA | Data hosted in the EU; SCCs (Standard Contractual Clauses) as a backstop due to the US parent | https://supabase.com/legal/dpa |
| PowerSync | Data synchronisation between your devices | The same service data as Supabase | EU (EU instance) | Data hosted in the EU; SCCs as a backstop where applicable | https://www.powersync.com/legal/dpa |
| RevenueCat (RevenueCat, Inc.) | Subscription management | Pseudonymous identifier (app_user_id) +
purchase/subscription status |
USA (AWS + ClickHouse in the USA; does not offer EU residency) | International transfer covered by its DPA + EU Standard Contractual Clauses 2021/914 (module 2) | https://www.revenuecat.com/dpa/ |
| Sentry (Functional Software, Inc.) | Error and performance diagnostics | Technical device data, without PII; hashed identifier | EU (organisation with data residency in the EU); parent company in the USA | Data hosted in the EU; SCCs as a backstop due to the US parent | https://sentry.io/legal/dpa/ |
| PostHog (PostHog, Inc.) | Product analytics | Pseudonymous usage events, without PII | EU (PostHog Cloud EU — AWS Frankfurt); parent company in the USA | Data hosted in the EU; SCCs as a backstop due to the US parent | https://posthog.com/dpa |
The list of each provider’s actual sub-subprocessors is set out in the annex to its DPA. We do not reproduce here generic public lists that mix in providers unrelated to the processing of your data.
6.1. Third parties acting as independent controllers
The following are not our processors but independent controllers that process your data in accordance with their own policies:
- Apple — Sign in with Apple, App Store (subscription payment) and push notifications (APNs). Policy: https://www.apple.com/legal/privacy/en-ww/
- Google — Sign in with Google and Google Play (subscription payment), where applicable.
We do not use iCloud/CloudKit for your app data (photos are local-only). Internal sources:
specs/tecnico-claude.md§7, §11, §12; §6.2 (auth).
7. Retention periods
- While your account is active, we keep your data in order to provide you with the service.
- Deletion of server data: when you delete a device
or a routine, we mark it as deleted (soft delete) and physically
purge it after 90 days by means of a daily automated process.
The same applies to the purge following account closure. Internal
source:
specs/tecnico-claude.md§7.6 (cascading soft delete +pg_cronat 90 days). - Local photos: they are deleted from your iPhone immediately when you delete them or uninstall the app (our servers are not involved).
- Billing/tax records: transaction data associated with the subscription may be retained for up to 6 years (commercial record-keeping obligation, art. 30 of the Spanish Commercial Code; the general tax limitation period is 4 years, art. 66 of the Spanish General Tax Law), even if you delete your account.
- Backups: the database provider’s technical backups expire and are overwritten under its standard retention periods; after deletion, your information is not restored to active systems.
8. Deleting your account and the right to erasure (art. 17 GDPR)
You can delete your account from Settings → Delete account inside the app.
When you do:
- We delete your data from our database.
- We anonymise or invalidate your identifier at the subscription (RevenueCat) and analytics/diagnostics (PostHog/Sentry) providers.
- We close your sessions on all your devices. If you signed in with Apple, we also revoke with Apple the Sign in with Apple tokens associated with the app.
- We delete the app’s local content on your device, including the photos stored in the app.
Important — be aware of the following:
- The process may complete in a
staggered/asynchronous manner: your account becomes
inaccessible immediately, but erasure at some external
provider may finish shortly afterwards through automatic reconciliation.
Internal source:
specs/tecnico-claude.md§7.13 (delete-accountsaga, possible “partial” state). - Error diagnostics (Sentry): erasure by expiry. Sentry does not offer per-user individual deletion (events are immutable); what we associate with your account is an irreversible pseudonym (salted, truncated hash) that does not make it possible to identify you or cross-reference you with other sources. When you delete your account we stop emitting that pseudonym immediately and historical events expire automatically after 90 days under the provider’s retention policy. Internal source: decision D4 of the S35 plan (approved by the controller on 2026-07-12).
- If you use Gailuh on more than one iPhone: when you delete your account from one of them, the session on the others is revoked immediately, but the local photos on those other devices (which never left them) remain in their storage encrypted and inaccessible from the app until you uninstall the app on that device. Internal source: decision D10 of the S35 plan (approved 2026-07-12).
- We cannot delete the copies you hold in Photos/iCloud. If you enabled “Save a copy to Photos” or you use iCloud Photos, those images remain in your photo library; you must delete them yourself from the system. We never had those photos on our server.
- Deleting your account does not cancel an active App Store/Google Play subscription. Manage or cancel your subscription from your store account (see Terms).
9. Your rights and how to exercise them
You have the right to request:
- Access (art. 15), rectification (art. 16), erasure (art. 17), restriction (art. 18), portability (art. 20) and objection (art. 21).
- In particular, you can object at any time to product analytics by turning off the “Product analytics” toggle in Settings → Privacy within the app (immediate effect, no questions asked), and to error diagnostics based on legitimate interest through the privacy contact (§17).
How to exercise them:
- Erasure: from within the app itself (see §8).
- Access and portability: write to us at roberto@irakai.com and we will provide you with a structured export (e.g. JSON) of your server data (devices, routines, usage records, streaks, configuration). Your photos are already on your iPhone, so they are not part of the export.
- Other rights: through the same contact channel.
We will respond within one month (extendable by two months in complex cases), free of charge, and we may ask you to prove your identity.
In the MVP, access and portability are handled by support (there is no self-service download on screen). Internal source:
specs/funcional-claude.md§13/§21;specs/tecnico-claude.md§7.4 (export-datafunction).
10. Analytics, diagnostics and absence of tracking
- We do not track you across other companies’ apps or websites and we do not use the advertising identifier (IDFA). We do not show advertising and we do not share data with data brokers.
- Product analytics (PostHog, in the EU) and error diagnostics (Sentry) identify you solely by means of a non-reversible hashed identifier (derived from your internal identifier), never your email, name or phone number.
- In session recordings (if used), all images are masked and, by design, we never record the content, the location or the technical metadata of your photos, nor any health data.
- You can turn off product analytics whenever you want from Settings → Privacy within the app: event collection stops immediately and, with the setting off, the analytics component is not even started on subsequent launches. The preference is stored only on your device. Error diagnostics (Sentry) does not depend on this toggle; to object to it, use the privacy contact (§9 and §17).
Internal source: specs/tecnico-claude.md §12.1–12.6;
specs/funcional-claude.md §13 (analytics toggle).
11. International transfers
We have chosen data residency in the European Union for every processor that allows it: Supabase (Frankfurt/Ireland), PowerSync (EU instance), Sentry (organisation with data residency in the EU) and PostHog (EU Cloud, AWS Frankfurt). Their parent companies are in the USA, so, despite hosting the data in the EU, we also rely on Standard Contractual Clauses and/or applicable adequacy frameworks (e.g. the EU-US Data Privacy Framework) as a safeguard against possible remote access.
- RevenueCat is the only exception: it processes the data in the USA because it does not offer EU residency. It is the only international transfer, covered by its DPA and the European Commission’s Standard Contractual Clauses (Decision 2021/914, module 2).
These safeguards are put in place through each provider’s data processing agreement (DPA), incorporated into their terms of service and linked in the table in section 6. You can request further information about these safeguards through the privacy contact.
Sources: https://gdpr-info.eu/chapter-5/ · https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
12. Security measures (art. 32 GDPR)
- Encryption in transit and at rest.
- Per-user isolation: each person accesses only their
own data, by means of row level security (RLS) policies in the database
tied to your identifier (
owner_uid), and by partitioning the local storage on the device. - Protection of the photos with the iOS system encryption and, optionally, Face ID.
- Observability without PII or photo content (see §10).
Technical note: signing out does not delete your local data; it remains encrypted and inaccessible to another account and reappears when you sign back in with your account. Only “Delete account” erases the local content. Isolation between accounts on the same iPhone is provided by partitioning on
owner_uid. Internal source:specs/tecnico-claude.md§7.1, §13.1.
13. Automated decision-making and profiling
We do not make automated decisions producing legal or similarly significant effects concerning you. The product analytics described in §10 is used only in aggregate to improve the app: it does not build individual profiles with effects on you and is not used for advertising.
14. Minimum age and minors
The app is aimed at adults and is not directed at minors. The minimum age to use Gailuh is 18: by creating your account you declare that you meet this requirement (see Terms, §3). We do not knowingly collect data from minors; if we detect the processing of a minor’s data below the permitted age, we will delete it.
Source: https://www.aepd.es/preguntas-frecuentes/10-menores-y-educacion/FAQ-1001-cual-es-la-edad-para-que-los-menores-puedan-prestar-consentimiento-para-tratar-sus-datos-personales
15. Complaint before the supervisory authority
If you consider that the processing of your data does not comply with the regulations, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD):
- Website: https://www.aepd.es
- Electronic office: https://sedeagpd.gob.es
We would be grateful if you first tried to resolve the matter with us through the privacy contact.
Source: https://gdpr-info.eu/art-77-gdpr/
16. Changes to this policy
We may update this policy to reflect legal or product changes. We will inform you of substantial changes through appropriate means (e.g. within the app). The date of the last update appears at the foot of the document.
17. Contact
For any privacy matter or to exercise your rights:
- Irakai Studio SL (NIF B95935615)
- roberto@irakai.com
- Meñaka bidea 4, 48100 Mungia (Bizkaia), Spain
Last updated: 2026-07-27 · Version 1.0