Effective: 2026-06-03 · Last updated: 2026-06-03
The 30-second summary
We don't have a server. Your photos, lifestyle logs, and Apple Health data live on your device. We can't see your face. We can't see your sleep. We can't see your cycle.
The only things we receive are anonymous app crash reports (so we can fix bugs) and anonymous usage events (so we know which screens to improve). Neither is linked to your identity.
If you'd rather opt out of even that, you can — see §5.
1. Who we are
puffphew is operated by TODALABS PTE LTD, a private limited company incorporated in Singapore ("we", "us", "puffphew"), reachable at michele@todalabs.io. This policy explains what we do and don't do with your data when you use the puffphew iOS app.
2. What stays on your device (we never receive it)
Per Apple's definition of "data collection" (data that leaves your device and reaches us), the following items are NOT collected by puffphew:
- Face capture photos. Saved to puffphew's app sandbox on your device. Kept on your device until you delete them (tap "Delete all data" in Settings, or delete the app). Never uploaded.
- Face landmark measurements. Computed on-device using Apple's Vision framework. The numbers stay local.
- Lifestyle logs (sleep, alcohol, sodium, hydration, workouts, cycle phase). Stored in MMKV on your device.
- Apple Health data we read (sleep, hydration, workouts, menstrual cycle). HealthKit gives us read-only access; the data is processed locally and never transmitted.
- Your profile (goal, sex, cycle length, wake time, preferences). Local only.
- Correlation insights, baselines, and forecasts. Computed on-device from your local data.
If you tap "Delete all data" in Settings, all of the above are erased from your device, including photo files.
3. What we do receive (Apple's "Data Linked / Not Linked to You")
| What | Linked to your identity? | Why |
|---|---|---|
| App Store subscription receipt (handled by RevenueCat on our behalf) | Yes, via your Apple ID | To confirm your trial / subscription status |
| Anonymous crash reports (handled by Sentry) | No | To debug app crashes |
| Anonymous usage events (handled by PostHog) | No | To understand which screens / features work |
We do not collect: your name, email, phone, address, contacts, social graph, precise location, microphone audio, or browsing history. We do not share or sell any data, and we do not use any of it for advertising.
4. Apple Health (HealthKit) data — specific clauses
Per Apple's HealthKit requirements:
- We read the following data types only, and only after you grant permission: sleep analysis, water intake, workout sessions, menstrual flow.
- We do not write any data back to Apple Health.
- HealthKit data is used solely to provide app functionality (correlating these factors with your daily face measurements).
- HealthKit data is never used for advertising or marketing, and is never shared with third parties, including data brokers.
- HealthKit data is never stored on any server.
- You can revoke our HealthKit access at any time via iOS Settings → Privacy & Security → Health → puffphew. The in-app "Disconnect Apple Health" button opens this page for you.
5. Subprocessors
We use these vendors to run puffphew. None of them receive your photos, lifestyle logs, or health data.
| Vendor | What they do | What they receive |
|---|---|---|
| Apple (App Store, HealthKit, Vision, Notifications) | iOS platform + payments | Subscription receipt; HealthKit read permission grant; nothing more |
| RevenueCat | Subscription receipt validation, restore, trial tracking | Anonymous subscription identifier tied to your Apple ID receipt |
| Sentry | Anonymous crash diagnostics | Stack trace + device model. No PII. Opt-out: contact us. |
| PostHog | Anonymous product analytics | Screen views, button taps, anonymized device ID. No PII. Opt-out: contact us. |
These vendors process data on our behalf under their respective Data Processing Agreements and are bound by privacy commitments comparable to ours.
6. Children's privacy
puffphew is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has used puffphew, contact us at michele@todalabs.io and we'll delete any associated subscription record.
7. Your rights
Because most of your data never leaves your device, the simplest way to exercise your privacy rights is in the app itself:
- Access: open Settings → your captures, logs, and profile are all viewable in the app.
- Delete: Settings → "Delete all data" wipes everything (MMKV records + photos).
- Disconnect Apple Health: Settings → "Disconnect Apple Health" opens iOS Settings → Health to revoke our read access.
- Cancel subscription: Settings → "Manage subscription" opens Apple's subscription management.
For the anonymous data Sentry and PostHog receive (crash reports, screen events), email michele@todalabs.io with the subject "Opt out" and we'll disable both for your install.
If you are in the European Economic Area or United Kingdom, you have additional rights under GDPR: access, rectification, erasure, restriction, portability, and objection. Because we hold so little data linked to you, these reduce to "delete in app" or "email us to opt out of crash/usage data." If you have a complaint, you may also contact your national data-protection authority.
If you are in California, you have rights under the CCPA / CPRA: to know, delete, correct, and opt out of sale (we don't sell). Submit a request to michele@todalabs.io.
If you are in Singapore, you have rights under the Personal Data Protection Act 2012 (PDPA): to access, correct, and withdraw consent for the processing of personal data we hold about you. Since we are a Singapore company (TODALABS PTE LTD), the PDPA applies to our processing regardless of where you are located. Requests: michele@todalabs.io. If you believe we have not handled your request properly, you may contact the Personal Data Protection Commission of Singapore (PDPC) at www.pdpc.gov.sg.
8. International data transfers
puffphew is operated from Singapore. Our subprocessors (Apple, RevenueCat, Sentry, PostHog) primarily process data in the United States and the European Union. Where personal data crosses borders, we rely on the relevant transfer mechanisms — for EU/UK users, the European Commission's Standard Contractual Clauses; for Singapore data subjects, the PDPA's overseas-transfer requirements; for users in other jurisdictions, equivalent legal mechanisms.
9. Security
Data on your device is protected by iOS's built-in encryption when your device is locked. Subscription receipts in transit between Apple, RevenueCat, and our app use TLS 1.2 or higher. Because we don't operate a server, there is no central database for an attacker to breach.
10. Changes to this policy
If we make material changes (e.g., adding a new subprocessor or beginning to collect new data), we will update the "Last updated" date at the top and notify you in the app on next launch. Continued use after the change indicates acceptance.
11. Contact
Questions, requests, or privacy concerns:
TODALABS PTE LTD (Singapore) michele@todalabs.io
For Apple-specific issues (subscription billing, refunds, App Store purchase history), please contact Apple directly via reportaproblem.apple.com — we cannot reverse App Store charges.