Privacy Policy
Effective 19 August 2026 · pum.me
Pum is local-first. Your health data lives on your device, not on Pum's servers. This policy describes, plainly, what Pum does with information, and what it does not.
Pum is an iOS app for tracking endometriosis and adenomyosis symptoms, built and operated by Lewis Thompson, an independent developer in Australia. There are no Pum accounts. Pum does not sell data, run advertising, embed third-party analytics, or use behavioural tracking SDKs.
What information Pum handles
When you use Pum, you create health information: bleeding, pain, GI symptoms, medications, mood, fatigue, sleep, sexual activity, clinical events, and similar entries. With your permission, Pum also reads data from Apple Health — sleep, heart rate, heart rate variability, exercise, wrist temperature, basal body temperature, and cycle history.
All of this is stored locally on your device. Pum does not collect your name, email address, phone number, postal address, government identifier, or any other contact details. There is no sign-up, no profile, no login. Under the Australian Privacy Act 1988, Pum collects no information that identifies you — no name, email, account, or device identifier — and the limited anonymous data Pum does receive (install attribution, the first-launch ping, feedback you choose to send, and crash diagnostics, described below) is not reasonably linkable to you. Under the EU General Data Protection Regulation, your health information is processed locally on your device and is not transmitted to Pum.
What leaves the device, and where it goes
There are only a few paths by which information ever leaves your device, and you control each of them.
- iCloud sync (optional). If you turn on iCloud sync, Pum stores your data in a private CloudKit container in your own iCloud account. Apple encrypts this data in transit and at rest. Pum's servers are not involved in this sync and Pum has no access to the data while it is in iCloud. Apple's handling of the data while it is in iCloud — including its retention, backup, and access controls — is governed by Apple's Privacy Policy and iCloud Terms. You can turn iCloud sync off at any time, which stops new data from syncing; data already in iCloud can be deleted via the Settings path described below.
- Apple Health (read-only, with permission). When you grant Pum access to specific Apple Health data types, Pum reads from Apple Health on your device. Pum does not write to Apple Health and does not transmit Apple Health data anywhere.
- AI Export (manual, user-initiated). When you tap export, Pum prepares a paste-ready summary of the data you selected and places it on your device's clipboard. You then paste it into the AI tool of your choice — Claude, ChatGPT, Gemini, or any other. Pum is not a middleman. Once the data is on your clipboard and you paste it into a third-party app, the third party's privacy policy governs what happens next.
- Install attribution (one-time, anonymous, skippable). During onboarding, Pum asks how you found it. If you answer, Pum sends only the option you selected — plus the free text you enter if you choose "other" — to a Pum-operated server. The submission carries a single-use random tag whose only purpose is to stop a network retry from double-counting your answer; it is not a device or user identifier, and the server does not retain the network address the request arrives from. Pum attaches no name, email, device identifier, or health data, and retains no network address, so Pum has no way to link your answer back to you. If you type identifying details into the free-text box, only that text is stored. Pum keeps these anonymous answers, without any identifier, only to understand how people discover Pum. You can skip the question.
- First-launch ping (one-time, anonymous). The first time you open Pum after installing it from the App Store, Pum sends a single "the app was opened" signal to a Pum-operated server. It carries no health data, no answer, no text — only the same kind of single-use random retry tag as the attribution answer above, plus the app version. Pum keeps only the count, to know how many installed apps were actually opened.
- Feedback (manual, user-initiated). If you send feedback from Settings, Pum sends your message, the app version, and — only if you type one — a reply-to email address. Left blank, the message is anonymous and Pum has no way to reply or to link it to you.
- Crash diagnostics (opt-out, anonymous). Described in the next section.
Pum makes no other network requests that carry your data. Pum does not send your symptom data, notes, or logs anywhere. Where the paths above involve another company — Apple for iCloud sync, or whichever AI tool you paste an export into — your data may be stored or processed in another country under that company's own terms; Pum itself transfers nothing about you across borders.
Diagnostics
Pum sends anonymous diagnostic information to a Pum-operated server (crashes.pum.me) to help diagnose crashes and serious bugs. This is on by default. You can turn it off at any time in Settings → Privacy → Send anonymous diagnostics.
Diagnostics are only sent following a crash. The payload contains:
- The device class reported by iOS (for example,
iPhone) — not a device name or unique identifier. - The iOS version.
- The Pum app version and build number.
- The timestamp of the crash.
- A short trail of recent in-app events ("breadcrumbs"). Each breadcrumb has a timestamp, a subsystem name (
app,engine,today, ortrigger), an event name, and a small set of structural fields — counts (for example,hk=63 pum=100), state flags (for example,hasShift=true), reasons (for example,stale_data,new_bleeding), and categories of events that occurred (for example,type=pain,type=medication,type=bowelMovement).
A representative breadcrumb looks like this:
[engine] recalculate.skip reason=predictionFresh
The diagnostic payload does not include the values you logged, your notes, your symptom details, your cycle dates, your vendor identifier, your device name, or any user identifier. Pum's diagnostics record that a logging action of a given type occurred, not what was logged.
Two things to be candid about. First, breadcrumb timestamps mean the times at which you used the app are visible in the diagnostic payload. Second, any HTTPS request — diagnostics included — arrives with a source IP address at the network layer; this is unavoidable for web traffic. Pum does not log or store these source IPs: they are not recorded in Pum's server access logs and never enter the diagnostics database. The diagnostic record carries no network identifier.
Crash diagnostic reports are retained for 90 days, then deleted.
The Pum website
This policy is published on Pum's website, pum.me, which collects a little information the app does not. If you join the waitlist, Pum stores the email address you give and uses it only to tell you about Pum; sign-up is double opt-in (you confirm by email). If you use the contact form, Pum stores your message and email address so it can reply. This information is held separately and is not linked to your on-device health data or to the anonymous install-attribution answer. To have it removed, email support@pum.me.
Your data, your control
You can delete your data at any time:
- Local app data. Uninstall Pum. This removes the local database.
- iCloud data. Go to Settings → Apple Account → iCloud → Manage Storage → Pum and delete Pum's data from iCloud.
- Crash diagnostic records. You can stop sending them at any time at Settings → Privacy → Send anonymous diagnostics. Because the records contain no identifier, Pum cannot single out yours automatically; email support@pum.me and Pum will work with you to identify and remove diagnostic records from around the time you used the app.
Because Pum has no accounts and no central store of user-identifiable health data, there is no Pum-side profile to delete.
Your rights
If you are in the European Union, the United Kingdom, or another jurisdiction with comparable privacy laws, you have rights to access, correct, delete, and port your personal information, and to object to or restrict its processing. Because Pum holds no personal information about you on Pum's servers, most of these rights are exercised directly on your device or in your own iCloud account, using the controls described above. For specific requests, contact support@pum.me. Where Pum does process limited anonymous data, the legal basis is Pum's legitimate interest in diagnosing crashes (for diagnostics) and your consent (for the optional install-attribution answer); diagnostic records are kept for 90 days. You also have the right to lodge a complaint with your local supervisory authority — in the United Kingdom, the Information Commissioner's Office.
Under the Australian Privacy Act 1988, you have the right to ask what personal information Pum holds about you. In Pum's assessment the anonymous data it receives is not personal information as defined by the Act, because it is not reasonably linkable to you. You can contact support@pum.me with concerns, and you may also raise concerns with the Office of the Australian Information Commissioner.
In the United States, Pum is not a HIPAA-covered entity, and the information you log is not regulated by HIPAA — that law governs healthcare providers, health plans, and clearinghouses, not an app you keep for yourself. Several states regulate consumer health data held by apps like Pum, notably Washington's My Health My Data Act and comparable laws in Nevada and Connecticut, which govern the collection, sharing, and sale of consumer health data. Pum holds no consumer health data that is linked or reasonably linkable to you: your health entries never leave your device except into your own iCloud account, and the crash-diagnostic flow described above records only de-identified categories of action — that a pain entry was made, for example — never the values, dates, or notes you logged, and carries no identifier. Pum does not sell or share consumer health data. Because there is no central, identifiable store to draw from, the access, deletion, and opt-out rights these laws provide are exercised on your device using the controls above; for anything else, contact support@pum.me. For California residents, the local-only handling described here means Pum collects no personal information to sell or to use for cross-context behavioural advertising.
Children
Pum is intended for adults and is not directed at children under 13. Pum does not knowingly collect information from children under 13. If you believe a child has used Pum and you would like to ensure no diagnostic records associated with their use are retained, contact support@pum.me.
Changes to this policy
If this policy changes in a way that affects what data leaves your device or how it is handled, the change will be described on this page and the effective date at the top of this document will be updated. Minor wording changes that do not affect substance may be made without notice.
Contact
For privacy questions, requests, or concerns, email support@pum.me.
Effective 19 August 2026 · pum.me