Plyko

Privacy Policy

Last updated: 15 May 2026

Data controller: Plyko, an application published from France and operating under EU and French law.
Contact: privacy@plyko.app

This policy explains what data Plyko (“we”, “us”) collects when you use the Plyko mobile app and the supporting Plyko backend, why, with whom we share it, and the rights you have over it. We follow the EU General Data Protection Regulation (GDPR) and the French Loi Informatique et Libertés. The competent supervisory authority is the CNIL.

1. Summary in plain language

2. Data we collect

CategoryExamplesPurposeLegal basis
AccountEmail, password hash, user IDSign in, identify you across devicesContract (Art. 6.1.b GDPR)
ProfileHandle, avatar, gender, height, body weight, body-fat %, goals, dietary preferencesAdapt the app and macro targets to youContract
Workout activitySessions, sets, exercises, custom exercises, personal records, workout templatesCore feature — your training logContract
Nutrition activityMeal logs, food items, saved recipes, scanned barcodes, nutrition goalsCore feature — your nutrition logContract
Body metricsWeight, body-fat, water intake, step count historyBody composition + activity trackingContract
Apple Health / Health ConnectStep count and active calories read from the OS health storeDisplay daily activityConsent (you opt in via the OS prompt)
Photos for AIPictures of plates / fridges / nutrition labels you takeOne-shot AI analysis, then discardedConsent (you take the action)
SubscriptionStatus and transaction ID via RevenueCat — never card or bank dataManage your Pro accessContract
DiagnosticsAnonymous crash logs via Sentry; AI feature usage countersFix bugs, enforce quotasLegitimate interest (Art. 6.1.f)
SocialFriend list, leaderboard handle, profile photoSocial features you opt intoConsent (you connect friends)

We never collect: precise GPS location, contacts list, microphone recordings, browsing history, payment card numbers (Apple/Google handle billing).

3. Where the data goes

Plyko relies on the following processors. Each runs under a Data Processing Agreement.

ProcessorWhat they receiveWhereWhy
Supabase Inc. (USA, EU-hosted instance)All data above except photos and diagnosticsFrankfurt, Germany (eu-central-1)Database, authentication, edge functions
Anthropic, PBC (USA)Photos and prompts for AI featuresUSAClaude API inference
RevenueCat, Inc. (USA)App user ID + Apple/Google transaction IDsUSASubscription orchestration
Apple Inc.IAP transactions, push tokens, Apple Health (stays on device)Apple serversStoreKit + APNs
Sentry (USA / Germany)Crash stack traces, anonymous device + app versionFrankfurt EU regionError reporting
USDA / Open Food FactsFood search queries (no user identifiers)USA / FranceFood nutrition data lookup

Transfers to the United States rely on the Standard Contractual Clauses (SCC) issued by the European Commission and, for enrolled vendors, the EU-US Data Privacy Framework.

4. How long we keep it

5. Your rights

Under the GDPR you have the right to:

To exercise any of these rights, email privacy@plyko.app. We respond within 30 days.

You may also lodge a complaint with the CNIL: www.cnil.fr / 3 Place de Fontenoy, 75007 Paris.

6. Security

No system is unbreakable. If a breach affects your data, we notify you and the CNIL within 72h as required by Art. 33–34 GDPR.

7. Children

Plyko is rated 12+ and not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has signed up, email privacy@plyko.app and we will delete the account.

8. Cookies and similar tech

The Plyko mobile app does not use cookies. The Plyko website uses no analytics cookies and no third-party tags.

9. Changes to this policy

We update this policy when our practices change or when laws require. The “Last updated” date reflects the latest revision. Material changes will be announced inside the app at least 30 days before they take effect.

10. Contact

Plyko — published from France. Email: privacy@plyko.app. For full legal entity details, write to contact@plyko.app or see our Legal Notice.