Privacy policy

Last updated: September 10, 2026

Plumm is a menstrual cycle and pregnancy tracking app published by NEW GAME (SAS). Your cycle data is among the most intimate there is: we handle it with the utmost care and in strict compliance with the General Data Protection Regulation (GDPR). This policy explains what we process, why, on what legal basis, for how long, and what your rights are.

Data controller

The controller responsible for processing your data is:

NEW GAME, a simplified joint-stock company (SAS) with share capital of €2, registered with the Paris Trade and Companies Register under number 105 490 080, with its registered office at 66 avenue des Champs-Élysées, 75008 Paris, France.

For any question about your personal data, write to us at hello@plumm-app.com.

Our philosophy: local-first

Plumm is designed to work entirely on your phone. Your cycle data (period dates, cycle length, symptoms, cervical mucus, pain, mood, contraception, pregnancy) is stored only in the app's private space, on your device — isolated from other apps by iOS and Android, and protected by your phone's storage encryption.

By default, this data does not leave your phone and we have no access to it. One strictly optional choice can make it transit, and only if YOU enable it: cloud backup (encrypted in transit and at rest, hosted by our processor so we can restore it for you). As long as you don't enable it, no cycle data leaves your device.

What data we process

1. Cycle data — stored locally by default (sent only if you enable cloud backup): • Period dates, cycle length, period length • Symptoms: mood, energy, pain, cervical mucus, spotting, ovulation pain, intimacy • Contraception type and related settings (pill time, insertion date, etc.) • Pregnancy (start date, estimated due date) • First name (optional) and app preferences

2. Pseudonymized technical data (error detection): • Application error logs — no cycle data whatsoever • OS version and device model • No IP address retained in these logs, no cookies, no advertising identifiers

3. Data from the “Let's talk” messaging (only if you use it): • The content of the messages you send our team • An anonymous identifier for your device (random UUID, unrelated to your identity) • A notification token (push token) so we can send you a reply

Messaging is optional: as long as you don't use it, none of this data is created or transmitted. No account, no email, no first name is requested — you stay anonymous.

4. Idea board data (only if you post an idea, vote or comment): • The content of your ideas and comments — they are public, visible to all users • Your first name (or 'Anonymous') shown next to your ideas and comments • An anonymous device identifier and a notification token (to alert you when the team replies)

The idea board is optional and public: only share what you're comfortable making visible to the community.

5. Cloud backup data (only if you enable it): • A copy of your cycle data (see point 1), encrypted in transit and at rest, stored on our servers (Supabase) and tied to your account • Your email address (the backup account identifier)

Cloud backup is optional and opt-in: it only exists if you enable it, so you don't lose your history if you change or lose your phone. Unlike the rest, this copy is technically readable by the server (it is not end-to-end encrypted) — that's the deliberate trade-off so we can restore it for you. You can delete it in one tap at any time. And if you'd rather have nothing on a server, simply leave it off: everything then stays on your phone.

6. Android waitlist (only if you ask to be notified on the website): • Your email address, language, signup date and source, consent version and Resend synchronization status

This information is stored in Supabase. Your email and language are shared with Resend to send only the Android launch announcement, in your language. No advertising use or resale. You can request deletion at hello@plumm-app.com and unsubscribe using the link in the email.

7. Website contact form (only if you write to us from plumm-app.com): • Your first name (optional), your email address and the text of your message, delivered by Resend to our hello@plumm-app.com inbox • To prevent repeated submissions: a fingerprint of your address and your message (irreversible without our key — never the values themselves), kept for 2 hours at most

We retain no IP address. Our host (Vercel) technically logs requests to the site, as it does for any other page — that is what lets us limit automated submissions without creating any data on our side. Only write in this form what you're happy to entrust to us by email.

Legal basis and health data

Your cycle data is health data within the meaning of Article 9 of the GDPR (special category of data). Its processing is based on your explicit consent (Article 9.2.a of the GDPR): by voluntarily entering this information in the app, you expressly consent to its processing for tracking your cycle. You can withdraw this consent at any time by deleting your data or uninstalling the app.

If you are under 15, this processing also requires the consent of the holder(s) of parental authority (Article 45 of the French Data Protection Act).

Messaging is processed on the basis of your consent (you choose to write to us) and our legitimate interest in providing support. Error detection is based on our legitimate interest in ensuring the app works properly.

The website contact form relies on your consent (you choose to write to us, and to decide what you entrust to us) and on our legitimate interest (Article 6.1.f GDPR) in replying to you and in protecting the service against automated bulk submissions — hence the short-lived fingerprint described above.

Third parties and processors

We keep third parties to a strict minimum. No ads, no analytics trackers (Google Analytics, Facebook Pixel…), no data resale, no commercial profiling.

  • Sentry (Functional Software, Inc., EU hosting) — technical error detection. Receives only pseudonymized error traces, never cycle data.
  • Supabase (Supabase, Inc., United States) — hosts the “Let's talk” messaging, the idea board, and the cloud backup if you enable it. Receives: message content, ideas/votes/comments (public), your display first name, your anonymous device identifier, and — for cloud backup only — an encrypted copy of your cycle data plus your account email. It also holds a short-lived fingerprint of your address and your message, to limit repeated submissions from the website contact form.
  • Expo (650 Industries, Inc., United States) — push notification delivery service (messaging replies, reminders). Receives only an anonymous notification token.
  • Resend (Resend, Inc., United States) — sends the sign-in emails for cloud backup (your email address and the 6-digit code sent to you — never any cycle data) and delivers messages sent from the website contact form (your first name, your email address and the text you write).
  • Vercel (Vercel, Inc., United States) — hosts the plumm-app.com website, including the pre-launch waitlist form and the contact form, and processes the technical logs of requests to the site.

These processors act on our instructions and are bound by contractual commitments compliant with the GDPR.

As Supabase, Expo, Resend and Vercel are based in the United States, the data they handle on our behalf (messaging, idea board, cloud backup, sign-in emails, contact form messages and their anti-abuse fingerprints, website request logs) is transferred there. These transfers are governed by appropriate safeguards: the European Commission's Standard Contractual Clauses and, where applicable, the EU—US Data Privacy Framework. You can request a copy of these safeguards at hello@plumm-app.com.

The Android waitlist is also stored in Supabase (email, language and signup information). Resend receives the email and language for the launch announcement and manages unsubscribes.

Retention periods

  • Cycle data: kept on your device as long as you use the app. It is permanently deleted as soon as you reset or uninstall the app.
  • Messages: kept for as long as needed to handle your request, then archived for a maximum of 3 years from the last exchange.
  • Device identifier and notification token: kept while your conversation is active, and deleted at the latest when the message thread is archived (3 years maximum).
  • Error logs: kept for a maximum of 90 days, then automatically deleted.
  • Cloud backup (if enabled): kept as long as your account exists, overwritten on each new backup, and deleted immediately when you delete it from the app.
  • Backup account and its email address (if you create one): kept for as long as the account exists. It is deleted, along with the backup it holds, as soon as you delete your account from the app (Account > Privacy & data > Cloud backup > “Manage my account and my backup” > “Delete my account”), or on request at hello@plumm-app.com.
  • Website contact form messages: kept for as long as needed to handle your request, then archived for a maximum of 3 years from the last exchange.
  • Contact form anti-abuse fingerprints: kept for 2 hours at most, then deleted automatically.

Your rights (GDPR)

Under the GDPR, you have the following rights: • Access: export your cycle history as a JSON file from Account > Privacy & data > Export my data. This export contains your app settings, your period and cycle history, your symptom journal, your pill log and your prediction metrics. It does not contain your support messages, the messages you sent from the website contact form, your ideas, votes and comments, your backup account email address, the authors you have hidden, or your security settings — for those, write to us and we will send them to you. • Rectification: edit or correct your data directly in the app • Erasure: Account > Reset app deletes all your local data in 1 tap (irreversible action). The cloud backup is deleted directly in the app (Account > Privacy & data > Cloud backup > Delete my backup). To also delete the backup account itself, email address included, go to Account > Privacy & data > Cloud backup > “Manage my account and my backup” > “Delete my account”. To erase the other data stored on our servers (messaging, ideas, votes and comments, device identifier, notification token), write to us at hello@plumm-app.com: we delete it within 30 days. • Portability: the JSON export is readable and reusable • Objection and withdrawal of consent: you can stop using the app or messaging at any time

To exercise these rights or for any question, write to us at hello@plumm-app.com. You also have the right to lodge a complaint with the CNIL (the French data protection authority — www.cnil.fr).

Changes to this policy

We may update this policy to reflect legal or technical developments. Any substantial change will be notified within the app. The last update date is shown at the top of this document.