story science privacy circle roadmap support
get pum
story science privacy circle roadmap support questions
get pum on the App Store

← the plain-language version

Privacy Policy

Effective 28 September 2026 · pum.me

Pum is local-first. Your health data lives on your device, not on Pum's servers. This policy describes, plainly, what Pum does with information, and what it does not.

Pum is an iOS app for tracking endometriosis and adenomyosis symptoms, built and operated by Lewis Thompson, an independent developer in Australia. There are no Pum accounts. Pum does not sell data, run advertising, embed third-party analytics, or use behavioural tracking SDKs.

What information Pum handles

When you use Pum, you create health information: bleeding, pain, GI symptoms, medications, mood, fatigue, sleep, sexual activity, clinical events, and similar entries. With your permission, Pum also reads data from Apple Health — sleep, heart rate, heart rate variability, exercise, wrist temperature, basal body temperature, and cycle history.

All of this is stored locally on your device. Pum does not collect your name, email address, phone number, postal address, government identifier, or any other contact details, with two exceptions: if you choose to sign a message to Pum with a name, that name is sent with that message, and if you choose to give an email address for updates, that address is sent to Pum (see Email updates below). There is no sign-up, no profile, no login. Under the Australian Privacy Act 1988, Pum collects no information that identifies you — no account, no device identifier, and no name or email unless you choose to give one — and the limited anonymous data Pum does receive (install attribution, the first-launch ping, daily usage counts under a random tag, messages you choose to send, discovery usefulness answers, and crash diagnostics, described below) is not reasonably linkable to you. Under the EU General Data Protection Regulation, your health information is processed locally on your device and is not transmitted to Pum.

What leaves the device, and where it goes

There are only a few paths by which information ever leaves your device, and you control each of them.

  • iCloud sync (optional). If you turn on iCloud sync, Pum stores your data in a private CloudKit container in your own iCloud account. Apple encrypts this data in transit and at rest. Pum's servers are not involved in this sync and Pum has no access to the data while it is in iCloud. Apple's handling of the data while it is in iCloud — including its retention, backup, and access controls — is governed by Apple's Privacy Policy and iCloud Terms. You can turn iCloud sync off at any time, which stops new data from syncing; data already in iCloud can be deleted via the Settings path described below.
  • Apple Health (read-only, with permission). When you grant Pum access to specific Apple Health data types, Pum reads from Apple Health on your device. Pum does not write to Apple Health and does not transmit Apple Health data anywhere.
  • AI Export (manual, user-initiated). When you tap export, Pum prepares a paste-ready summary of the data you selected and places it on your device's clipboard. You then paste it into the AI tool of your choice — Claude, ChatGPT, Gemini, or any other. Pum is not a middleman. Once the data is on your clipboard and you paste it into a third-party app, the third party's privacy policy governs what happens next.
  • Install attribution (one-time, anonymous). During onboarding, Pum asks how you found it. If you answer, Pum sends only the option you selected — plus the free text you enter if you choose "other" — to a Pum-operated server. The submission carries a single-use random tag whose only purpose is to stop a network retry from double-counting your answer; it is not a device or user identifier, and the server does not retain the network address the request arrives from. Pum attaches no name, email, device identifier, or health data, and retains no network address, so Pum has no way to link your answer back to you. If you type identifying details into the free-text box, only that text is stored. Pum keeps these anonymous answers, without any identifier, only to understand how people discover Pum. "Other" with your own words is always an available answer.
  • Email updates (optional, skippable). At the end of onboarding, Pum asks whether you want occasional emails on endometriosis research and Pum feature updates. If you type an address and continue, Pum sends that address to a Pum-operated server, which emails you a confirmation link; you are on the list only after you tap it. Pum keeps the address on your device so you can see and change it in your profile. It is sent with a random tag, created on your device and kept there with the address, whose only purpose is to let a later change or removal reach the same entry on the list and nothing else. Nothing else is sent with it: no name, no device identifier, no health data, and none of the anonymous answers above. Changing the address in your profile sends a confirmation link to the new address and ends the old one. The address is used only to send those emails and is never sold or shared. Removing it from your profile deletes it from Pum's server, along with any earlier address you gave in the app. The unsubscribe link in every email takes it off the list; to have an address you unsubscribed that way erased entirely, email support@pum.me. If you skip the question, nothing is sent.
  • First-launch ping (one-time, anonymous). The first time you open Pum after installing it from the App Store, Pum sends a single "the app was opened" signal to a Pum-operated server. It carries no health data, no answer, no text — only the same kind of single-use random retry tag as the attribution answer above, plus the app version. Pum keeps only the count, to know how many installed apps were actually opened.
  • Usage counts (daily, anonymous, opt-out). From version 3.4, Pum sends a Pum-operated server one small record for each day the app was opened: the app version, how many times it was opened, roughly how long it was in the foreground (as a range, such as 5 to 15 minutes), which screens were visited (for example the calendar or the insights page), how many entries were made that day (as a range, such as 1 to 2), and a few on/off states (whether Apple Health is connected, whether an Apple Watch is paired, whether iCloud sync is on, whether any reminders are set, and the cycle situation Pum is working in). Once a week it also sends the list of entry types used that week (for example “pain, bleeding”), with no counts. These records carry a random tag created on your device when the app is first opened, so that the days from one installed copy can be counted together and Pum can tell how many people keep using it. The tag is not derived from your device or from anything about you, it is not linked to any other tag Pum uses, and Pum does not retain the network address the records arrive from. The records never contain what you logged: no pain scores, no dates of symptoms, no notes, no medication names. Deleting the app ends the tag; reinstalling creates a new one. You can turn this off at any time at Settings → Privacy → Send anonymous usage counts; turning it off also deletes the tag and any unsent days from your device.
  • Messages (manual, user-initiated). You can write to the person who builds Pum from the You tab (“message the developer”), or from a discovery Pum has shown you, and read replies inside the app. When you first send a message, Pum creates a random conversation tag on your device and sends it with every message and every check for replies. The tag exists so that a reply can find its way back to your app; it is generated on your device, is not derived from your device or from anything about you, and links nothing but the messages in that one conversation. Each message carries your text, the app version, one screenshot if you attach one, and, only if you turn it on, the name you gave Pum at setup. Messages are anonymous by default and the conversation works fully without a name. Replies are stored on the same Pum-operated server until your app collects them. A screenshot of Pum can show your own health entries; attach one only if you are comfortable with the person who builds Pum reading it. You can clear the conversation from inside the app at any time, which deletes every message, screenshot and the tag from your device and from the server. A conversation with no new message or reply for 90 days is deleted from the server. In Pum versions before 3.3, the feedback form instead sends your message, the app version and, only if you type one, a reply-to email address.
  • Discovery usefulness (one tap, anonymous, skippable). When Pum shows you a discovery about your own patterns, it may ask once whether that discovery was useful. If you answer, Pum sends only which kind of discovery it was (a short code for the type of pattern, such as "pain by cycle phase"), your yes or no, and the app version, to a Pum-operated server. It carries no reading, no value, no date, no text, and no identifier of any kind — not even a retry tag — and the server does not retain the network address. Pum keeps only the counts, to learn which kinds of discovery are worth showing. You can ignore the question.
  • Crash diagnostics (opt-out, anonymous). Described in the next section.

Pum makes no other network requests that carry your data. Pum does not send your symptom data, notes, or logs anywhere. Where the paths above involve another company — Apple for iCloud sync, or whichever AI tool you paste an export into — your data may be stored or processed in another country under that company's own terms; Pum itself transfers nothing about you across borders.

Diagnostics

Pum sends anonymous diagnostic information to a Pum-operated server (crashes.pum.me) to help diagnose crashes and serious bugs. This is on by default. You can turn it off at any time in Settings → Privacy → Send anonymous diagnostics.

Diagnostics are only sent following a crash. The payload contains:

  • The device class reported by iOS (for example, iPhone) — not a device name or unique identifier.
  • The iOS version.
  • The Pum app version and build number.
  • The timestamp of the crash.
  • A short trail of recent in-app events ("breadcrumbs"). Each breadcrumb has a timestamp, a subsystem name (app, engine, today, or trigger), an event name, and a small set of structural fields — counts (for example, hk=63 pum=100), state flags (for example, hasShift=true), reasons (for example, stale_data, new_bleeding), and categories of events that occurred (for example, type=pain, type=medication, type=bowelMovement).

A representative breadcrumb looks like this:

[engine] recalculate.skip reason=predictionFresh

The diagnostic payload does not include the values you logged, your notes, your symptom details, your cycle dates, your vendor identifier, your device name, or any user identifier. Pum's diagnostics record that a logging action of a given type occurred, not what was logged.

Two things to be candid about. First, breadcrumb timestamps mean the times at which you used the app are visible in the diagnostic payload. Second, any HTTPS request — diagnostics included — arrives with a source IP address at the network layer; this is unavoidable for web traffic. Pum does not log or store these source IPs: they are not recorded in Pum's server access logs and never enter the diagnostics database. The diagnostic record carries no network identifier.

Crash diagnostic reports are retained for 90 days, then deleted.

The Pum website

This policy is published on Pum's website, pum.me, which collects a little information the app does not. If you sign up for email updates on the website, Pum stores the email address you give and uses it only for those emails; sign-up is double opt-in (you confirm by email). The list is the same one the in-app question above feeds, and every email on it carries an unsubscribe link that takes you off the list. If you use the contact form, Pum stores your message and email address so it can reply. This information is held separately and is not linked to your on-device health data or to the anonymous install-attribution answer. To have it removed, email support@pum.me.

Your data, your control

You can delete your data at any time:

  • Local app data. Uninstall Pum. This removes the local database.
  • iCloud data. Go to Settings → Apple Account → iCloud → Manage Storage → Pum and delete Pum's data from iCloud.
  • Usage counts. You can stop sending them at any time at Settings → Privacy → Send anonymous usage counts; the tag and any unsent days are deleted from your device when you do. Records already received carry no identifier Pum could match to you, so they cannot be selectively deleted, and are kept only as counts.
  • Crash diagnostic records. You can stop sending them at any time at Settings → Privacy → Send anonymous diagnostics. Because the records contain no identifier, Pum cannot single out yours automatically; email support@pum.me and Pum will work with you to identify and remove diagnostic records from around the time you used the app.
  • Messages. Open “message the developer” on the You tab, tap the name at the top, and choose “clear messages”. This deletes the conversation, its screenshots and its tag on your device and on the server. Conversations idle for 90 days are deleted from the server without you doing anything.

Because Pum has no accounts and no central store of user-identifiable health data, there is no Pum-side profile to delete.

Your rights

If you are in the European Union, the United Kingdom, or another jurisdiction with comparable privacy laws, you have rights to access, correct, delete, and port your personal information, and to object to or restrict its processing. Because Pum holds no personal information about you on Pum's servers, most of these rights are exercised directly on your device or in your own iCloud account, using the controls described above. For specific requests, contact support@pum.me. Where Pum does process limited anonymous data, the legal basis is Pum's legitimate interest in diagnosing crashes (for diagnostics) and your consent (for the optional install-attribution answer and for any message you send); diagnostic records and idle message conversations are kept for 90 days. You also have the right to lodge a complaint with your local supervisory authority — in the United Kingdom, the Information Commissioner's Office.

Under the Australian Privacy Act 1988, you have the right to ask what personal information Pum holds about you. In Pum's assessment the anonymous data it receives is not personal information as defined by the Act, because it is not reasonably linkable to you. You can contact support@pum.me with concerns, and you may also raise concerns with the Office of the Australian Information Commissioner.

In the United States, Pum is not a HIPAA-covered entity, and the information you log is not regulated by HIPAA — that law governs healthcare providers, health plans, and clearinghouses, not an app you keep for yourself. Several states regulate consumer health data held by apps like Pum, notably Washington's My Health My Data Act and comparable laws in Nevada and Connecticut, which govern the collection, sharing, and sale of consumer health data. Pum holds no consumer health data that is linked or reasonably linkable to you: your health entries never leave your device except into your own iCloud account, and the crash-diagnostic flow described above records only de-identified categories of action — that a pain entry was made, for example — never the values, dates, or notes you logged, and carries no identifier. Pum does not sell or share consumer health data. Because there is no central, identifiable store to draw from, the access, deletion, and opt-out rights these laws provide are exercised on your device using the controls above; for anything else, contact support@pum.me. For California residents, the local-only handling described here means Pum collects no personal information to sell or to use for cross-context behavioural advertising.

Children

Pum is intended for adults and is not directed at children under 13. Pum does not knowingly collect information from children under 13. If you believe a child has used Pum and you would like to ensure no diagnostic records associated with their use are retained, contact support@pum.me.

Changes to this policy

If this policy changes in a way that affects what data leaves your device or how it is handled, the change will be described on this page and the effective date at the top of this document will be updated. Minor wording changes that do not affect substance may be made without notice.

Contact

For privacy questions, requests, or concerns, email support@pum.me.

Effective 28 September 2026 · pum.me

storyscienceprivacycircleroadmapcomparepelvic painsupport
© 2026 pumpum is not a medical device and does not provide medical advice.updated 28 september 2026