GailuhVersión en español

Privacy Policy — Gailuh


1. Data controller

The controller of your personal data is:

This policy governs the processing of the data of users of the Gailuh application (hereinafter, “the app”).


2. Quick summary (the important part in 30 seconds)


3. What data we collect and for what purpose

Verified against the app’s actual data schema (specs/tecnico-claude.md §7.1 / §7.3 and specs/funcional-claude.md §5). We do not collect phone number, precise geolocation, contacts, or data from HealthKit / Apple Health sensors.

3.1. Account and identity data

The email is handled in the authentication layer (Supabase Auth), not in your app profile.

3.2. Your activity in the app

3.3. Metadata of your progress photos (NOT the image)

3.4. Profile avatar

3.5. Your Pro subscription

3.6. Technical and diagnostic data (without identifying you)


4. Special treatment of your body progress photos

This is a core privacy decision of Gailuh and we explain it in detail.

Your progress photos (including the first-day one) are stored EXCLUSIVELY on your iPhone, inside the app’s private storage, encrypted at rest by means of the iOS system’s data protection (iOS Data Protection).

Nature of this data. Because the images are never transmitted to us and are not accessible to us, we do not carry out any processing of them within the meaning of the GDPR: they remain under your exclusive control on your device, like any photo in your camera roll, and the app acts as a purely local tool. We do not perform facial recognition and do not identify anyone from the images (Recital 51 GDPR). The only data related to your photos that we do process is the date and the body zone (§3.3), which do not include the image and do not on their own reveal information about your health.

Backup under your control. By default your photos are only in the app. You can enable “Save a copy to iPhone Photos” (an option disabled by default) to copy them to your photo library, or use iCloud Photos. Both routes are yours and do not pass through our servers. Important: if you enable either of these copies, those images fall outside our technical control and we will not be able to delete them for you (see §7).

Additional protection. You can protect the progress gallery, the comparison view and “My photos” with Face ID (enabled by default).

Menstrual cycle notice. Before a photo of the abdomen zone, the app shows a respectful, non-blocking notice asking whether you would rather take the photo now or repeat it in a few days (because of possible bloating associated with the cycle). We keep this feature because it helps you take comparable photos. The app does not store or transmit any data about your cycle: the notice is triggered solely by the body zone you are about to photograph, so no processing of information about your cycle takes place on our side.

Internal sources: specs/funcional-claude.md §21, §12.7 and §12.8; specs/tecnico-claude.md §7.1 (photo_metadata table, with no image/path column), §7.13.


Purpose Data Legal basis
Create and maintain your account; provide the tracking service (devices, routines, usage records, streaks, configuration); sync across your devices and the Apple Watch Account/identity and your activity (§3.1–3.2) Performance of the contract — art. 6(1)(b)
Photo metadata (date + zone) to regroup your series §3.3 Performance of the contract — art. 6(1)(b)
Your body progress photos Images (§4) No processing on our side: the images remain exclusively on your device and we never receive them (§4)
Manage your Pro subscription and your access §3.5 Performance of the contract — art. 6(1)(b), and legal obligation (accounting/tax) — art. 6(1)(c)
Error and performance diagnostics (Sentry) §3.6 (technical data, hashed identifier) Legitimate interest — art. 6(1)(f) (service stability and security; legitimate interest assessment documented)
Product analytics (PostHog) §3.6 (pseudonymous usage events, no PII) Legitimate interest — art. 6(1)(f) (product improvement); you can turn it off at any time from Settings → Privacy within the app (§9)

Sources: https://gdpr-info.eu/art-6-gdpr/ · https://gdpr-info.eu/art-9-gdpr/ · https://gdpr-info.eu/art-7-gdpr/

The photo features are optional: if you do not use them, the app works normally. Because the images never leave your device, we do not need to ask for your consent to process them — we do not process them. As for product analytics, you can turn it off at any time from Settings → Privacy within the app; as for error diagnostics, you can object through the privacy contact (§9 and §17).


6. Recipients and data processors (subprocessors)

To provide the service we rely on the following providers, which act as data processors on behalf of the controller, bound by the corresponding processing agreement (DPA, art. 28 GDPR). None of them processes your progress photos (they are local-only).

Processor Purpose Categories of data Region / country Transfer safeguard DPA
Supabase (Supabase, Inc.) Database, authentication and backend functions Account, devices, routines, usage records, streaks, configuration, photo metadata EU (residency in Frankfurt/Ireland); parent company in the USA Data hosted in the EU; SCCs (Standard Contractual Clauses) as a backstop due to the US parent https://supabase.com/legal/dpa
PowerSync Data synchronisation between your devices The same service data as Supabase EU (EU instance) Data hosted in the EU; SCCs as a backstop where applicable https://www.powersync.com/legal/dpa
RevenueCat (RevenueCat, Inc.) Subscription management Pseudonymous identifier (app_user_id) + purchase/subscription status USA (AWS + ClickHouse in the USA; does not offer EU residency) International transfer covered by its DPA + EU Standard Contractual Clauses 2021/914 (module 2) https://www.revenuecat.com/dpa/
Sentry (Functional Software, Inc.) Error and performance diagnostics Technical device data, without PII; hashed identifier EU (organisation with data residency in the EU); parent company in the USA Data hosted in the EU; SCCs as a backstop due to the US parent https://sentry.io/legal/dpa/
PostHog (PostHog, Inc.) Product analytics Pseudonymous usage events, without PII EU (PostHog Cloud EU — AWS Frankfurt); parent company in the USA Data hosted in the EU; SCCs as a backstop due to the US parent https://posthog.com/dpa

The list of each provider’s actual sub-subprocessors is set out in the annex to its DPA. We do not reproduce here generic public lists that mix in providers unrelated to the processing of your data.

6.1. Third parties acting as independent controllers

The following are not our processors but independent controllers that process your data in accordance with their own policies:

We do not use iCloud/CloudKit for your app data (photos are local-only). Internal sources: specs/tecnico-claude.md §7, §11, §12; §6.2 (auth).


7. Retention periods


8. Deleting your account and the right to erasure (art. 17 GDPR)

You can delete your account from Settings → Delete account inside the app.

When you do:

  1. We delete your data from our database.
  2. We anonymise or invalidate your identifier at the subscription (RevenueCat) and analytics/diagnostics (PostHog/Sentry) providers.
  3. We close your sessions on all your devices. If you signed in with Apple, we also revoke with Apple the Sign in with Apple tokens associated with the app.
  4. We delete the app’s local content on your device, including the photos stored in the app.

Important — be aware of the following:


9. Your rights and how to exercise them

You have the right to request:

How to exercise them:

We will respond within one month (extendable by two months in complex cases), free of charge, and we may ask you to prove your identity.

In the MVP, access and portability are handled by support (there is no self-service download on screen). Internal source: specs/funcional-claude.md §13/§21; specs/tecnico-claude.md §7.4 (export-data function).


10. Analytics, diagnostics and absence of tracking

Internal source: specs/tecnico-claude.md §12.1–12.6; specs/funcional-claude.md §13 (analytics toggle).


11. International transfers

We have chosen data residency in the European Union for every processor that allows it: Supabase (Frankfurt/Ireland), PowerSync (EU instance), Sentry (organisation with data residency in the EU) and PostHog (EU Cloud, AWS Frankfurt). Their parent companies are in the USA, so, despite hosting the data in the EU, we also rely on Standard Contractual Clauses and/or applicable adequacy frameworks (e.g. the EU-US Data Privacy Framework) as a safeguard against possible remote access.

These safeguards are put in place through each provider’s data processing agreement (DPA), incorporated into their terms of service and linked in the table in section 6. You can request further information about these safeguards through the privacy contact.

Sources: https://gdpr-info.eu/chapter-5/ · https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj


12. Security measures (art. 32 GDPR)

Technical note: signing out does not delete your local data; it remains encrypted and inaccessible to another account and reappears when you sign back in with your account. Only “Delete account” erases the local content. Isolation between accounts on the same iPhone is provided by partitioning on owner_uid. Internal source: specs/tecnico-claude.md §7.1, §13.1.


13. Automated decision-making and profiling

We do not make automated decisions producing legal or similarly significant effects concerning you. The product analytics described in §10 is used only in aggregate to improve the app: it does not build individual profiles with effects on you and is not used for advertising.


14. Minimum age and minors

The app is aimed at adults and is not directed at minors. The minimum age to use Gailuh is 18: by creating your account you declare that you meet this requirement (see Terms, §3). We do not knowingly collect data from minors; if we detect the processing of a minor’s data below the permitted age, we will delete it.

Source: https://www.aepd.es/preguntas-frecuentes/10-menores-y-educacion/FAQ-1001-cual-es-la-edad-para-que-los-menores-puedan-prestar-consentimiento-para-tratar-sus-datos-personales


15. Complaint before the supervisory authority

If you consider that the processing of your data does not comply with the regulations, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD):

We would be grateful if you first tried to resolve the matter with us through the privacy contact.

Source: https://gdpr-info.eu/art-77-gdpr/


16. Changes to this policy

We may update this policy to reflect legal or product changes. We will inform you of substantial changes through appropriate means (e.g. within the app). The date of the last update appears at the foot of the document.


17. Contact

For any privacy matter or to exercise your rights:


Last updated: 2026-07-27 · Version 1.0