Information Plume handles
When you create an account or record, Plume may handle your name, email address or Apple private relay address, selected tracking areas, hair concerns and history, treatments and routines you enter, completion history, symptoms, side effects, notes, consent choices, and account settings.
Plume also creates account and app identifiers needed for authentication, synchronization, request safety, and service operation. Technical records may include request status, timing, error information, and basic network or device information used to secure and troubleshoot the service.
Original progress photos
Original progress photo files stay in protected storage inside the Plume app on your device. Plume does not upload those original photo files to Supabase or OpenAI. Structured photo information, such as date, selected area, angle, completion state, and technical capture quality results, may sync with your account.
Deleting the app removes its local photo files. You can also delete local photos and related records from Plume's Privacy & Data controls. Because original files are not backed up to the cloud by Plume, they cannot be restored on another device or after reinstalling the app.
Account sync and storage
Plume uses Supabase for account authentication, protected structured record synchronization, storage of records tied to your account, and server functions. Synchronized records remain while your account exists unless you delete them or delete your account.
When you request account deletion, Plume blocks access and removes the account and active data tied to it through its deletion process. Limited security, access log, or backup copies may remain temporarily where required for service integrity, fraud prevention, legal obligations, or routine backup expiration.
Ask Plume and OpenAI
Ask Plume is an optional OpenAI assisted educational feature. Before the first remote Ask Plume request, the app asks for explicit permission and explains that your question, recent Ask Plume conversation, and relevant recorded health or tracking facts are sent to OpenAI through Plume's Supabase service. Original progress photos are not included.
You can choose Not Now and continue using features that do not use OpenAI. You can later withdraw Ask Plume permission in Profile → Privacy & Data; pending remote requests are removed when permission is withdrawn. Ask Plume is for education and does not diagnose, prescribe, or determine whether a treatment is appropriate.
Purchases
Apple processes Plume Pro purchases, renewals, refunds, and subscription management through the App Store and StoreKit under Apple's privacy terms. Plume receives verified entitlement status needed to unlock app features, but does not receive your full payment card details.
How Plume uses information
- Authenticate your account and keep each person's record separated
- Synchronize the structured record you choose to create
- Track routines, streaks, symptoms, notes, and dated check ins
- Provide source photo comparison and technical capture guidance
- Answer optional Ask Plume educational requests after permission
- Operate, secure, debug, prevent abuse of, and improve reliability of the service
- Provide export and deletion controls and comply with legal obligations
Service providers and sharing
Plume uses Apple for Sign in with Apple and App Store purchases, Supabase for account and backend services, OpenAI for optional Ask Plume processing after consent, and website or infrastructure providers to deliver and secure the public site. These providers process information for the services they provide under their own terms and applicable agreements.
Plume does not sell your personal or health related information. Plume does not use it for third party advertising, data broker sales, or tracking across apps. Plume does not have a research or model training upload pipeline for your original progress photos.
Your choices and controls
- Choose which routines, symptoms, treatment details, photos, and notes to record
- Decline or withdraw optional Ask Plume data sharing permission
- Export your structured record from the app
- Delete photos, derived records, or all local app data
- Delete your Plume account and its data from Profile → Account
- Manage or cancel Plume Pro through Apple's subscription settings
Security and children
Plume uses platform protections, owner scoped access controls, protected local storage, and encrypted network connections. No storage or transmission system can be guaranteed completely secure.
Plume is not directed to children under 13. If you believe a child has provided personal information, contact us so we can investigate and remove it where appropriate.
This website
The public website does not offer access to your Plume health record. Its hosting and security providers may process basic request information needed to deliver and protect the site, such as IP address, browser type, requested page, and timestamps. The site does not currently use advertising trackers or accept health record submissions.
Changes and contact
Plume may update this policy when its services or legal obligations change. The updated date above identifies the current version. Material changes will be reflected here and, when appropriate, disclosed in the app before new processing begins.
For privacy questions, access or deletion requests, or concerns about this policy, email: