Last updated: July 29, 2026
We take the protection of your personal data seriously. This privacy policy explains how the Gallus application collects, uses, shares, and protects information when you use it. It applies to all Gallus users, regardless of where you reside.
In short: Gallus works with no user account and no advertising tracking whatsoever. The things that are most personal to you never leave your device: the content of your engagement phrases, your voice, your voice transcripts, your motivation photo, and your favorite quote (see sections 2.2 and 3). That said, Gallus does have servers (Supabase, hosted in the European Union) where we record technical data tied to an anonymous identifier: your alarm settings, usage and diagnostic events, and subscription state (see section 2.5). Two pieces of personal data may be added to it, both optional: a phone number you may provide during onboarding so we can gather your feedback (section 2.1), and the free-text comment you may write if you cancel your subscription (section 2.6). Finally, one exception about photos: if you enable "Stronger wake-up" mode, its photo proof mission takes a wake-up photo of you that is sent to an AI service (OpenAI) just long enough to check that you are standing up, then kept nowhere (section 2.7). It is distinct from your motivation photo, which never leaves your device.
The data controller is Gallus, based in France. Contact: contact@gallus-app.com
Gallus provides no user account system: no sign-up, no password. We do not ask for your name, email, or any identity data.
On first launch, the app automatically opens an anonymous session on our server. It generates a random technical identifier (a UUID) that contains no information about you and is not linked to any identity. That identifier, and nothing else, is what ties together the data described in section 2.5. This data is pseudonymous: it cannot identify you by name, but it does constitute personal data under the GDPR, and you have all your rights over it (section 9).
During onboarding, we also ask, on a strictly optional basis, for your phone number. You can skip this step and keep using the app normally. If you choose to provide it, we use it for a single purpose: to contact you (typically via WhatsApp) to gather feedback and help us improve Gallus during this early phase. It is then stored in two places: on our server (section 2.5) and as a contact property in our analytics tool (section 2.4). We never sell it, never use it for advertising, and you can ask us to delete it or to stop contacting you at any time (see sections 9 and 15).
Providing your phone number is the only act that lifts the pseudonymity: without it, we have no way of knowing who you are.
The following is stored only on your device, in the application's private sandbox. It is never sent to our servers, nor to any third party:
| Data | Purpose |
|---|---|
| The content of your engagement phrases (both the catalog ones and the ones you write) | Voice challenge to dismiss the alarm |
| Motivation photo (if you add one) | Personalized display during the challenge |
| Favorite quote (if you set one) | Personalized display during the challenge |
| Display preferences (theme, vibration) | App personalization |
Two nuances, to be exact: your device's language is part of the technical profile sent to our servers (section 2.5), and your subscription state is cached locally but also exists server-side (sections 2.5 and 4). Neither says anything about your identity.
This data is removed when you uninstall the application.
Not to be confused with photo proof: the motivation photo above stays on your device and is never sent. It is different from the wake-up proof photo in "Stronger wake-up" mode, which is transmitted for analysis at wake-up time without being stored (see section 2.7).
One exception to be aware of: the name you give an alarm (its label, e.g. "Work wake-up") is free text, and it is sent to our servers along with the rest of the alarm's settings (section 2.5).
In total, the app has only three free-text fields whose content leaves your device: the alarm label, the "Other" answer to the "how did you hear about Gallus?" onboarding question, and the optional comment in the cancellation survey (section 2.6). Avoid entering sensitive information in them. Your engagement phrases are in none of these cases: they stay on the device.
| Permission | Purpose | Required? |
|---|---|---|
| Microphone | Voice recognition for the challenge (speak the phrase to dismiss) | Yes (otherwise keyboard fallback) |
| Speech recognition | Verify that you correctly pronounce the phrase | Yes (otherwise keyboard fallback) |
| Notifications | Trigger alarms and chained reminders | Yes |
| Alarms (AlarmKit, iOS 26+) | Allow alarms to ring even in silent mode or Do Not Disturb | Yes (iOS only) |
| Photo library | Pick a motivation photo | No, optional |
| Camera | Take the "Stronger wake-up" mode proof photo (photo proof mission) | No, only if you enable that mission (section 2.7) |
Gallus uses PostHog (hosted in Europe, eu.i.posthog.com) to understand how the app is used and improve it. PostHog receives anonymous events tied to a random identifier generated locally on your device. By default this identifier is not linked to any identity information.
If you choose to provide your phone number (section 2.1), it is attached to your PostHog profile as a contact property so we can reach out for feedback. In that case, your analytics profile is no longer anonymous. If you skip that step, your profile stays anonymous.
| Data sent to PostHog | Data never sent |
|---|---|
|
|
This data is used solely for product analytics (e.g., identifying friction points in onboarding). It is never used for advertising or shared with third parties for commercial purposes. The app's privacy manifest (PrivacyInfo.xcprivacy) formally declares these analytics collections to Apple as Product Interaction, Other Usage Data, Purchase History, and User ID — all marked Linked to User = false and Used for Tracking = false. The optional phone number (section 2.1), when you provide it, is declared separately as Phone Number (Contact Info), Linked to User = true, used only to contact you and never for tracking.
PostHog's policy: posthog.com/privacy
Gallus relies on a database hosted with Supabase, in the European Union. All the data below is tied to the anonymous identifier described in section 2.1, not to your identity. It serves three purposes: running the subscription, diagnosing alarms that fail to ring (the most serious risk for an alarm app), and improving the product.
| Data | Content | Why |
|---|---|---|
| Technical profile | Device model, OS version, app version, language, time zone, permission states (notifications, AlarmKit), push notification token, and your phone number if you provided one (section 2.1) | Know which devices and versions alarms fail on |
| Your alarm settings | Time, days, on/off state, sound, volume, phrase mode, the identifiers of the associated phrases (never their text), and the alarm label (free text) | Reproduce and understand trigger failures |
| Usage and diagnostic events | App opens, screens visited, alarm lifecycle, voice challenge flow (number of attempts, match rate, and the length of the transcript, never its text), technical errors and crash traces | Detect bugs and friction points |
| Diagnostic snapshots | A comparison between the alarms stored in the app and those actually scheduled by the iOS system (AlarmKit), to spot discrepancies | Fix alarms that don't ring |
| Subscription state | Plan (monthly/yearly), status (trial, active, expired), period end date. Sent by RevenueCat, with no payment data whatsoever | Verify your access to features |
| Cancellation survey | See section 2.6 | Understand why people leave |
| "Stronger wake-up" mode (photo proof) | Judgment result (standing yes/no, sufficient brightness, pass), the AI model used, response time, image size in bytes, anti-abuse counters, and the IP address the call came from. Never the image itself. See section 2.7 | Track the feature's reliability and cost, and prevent abuse |
| Wake-up streaks | Number of consecutive days you completed your wake-up | Show your progress (streak) |
This data is protected by per-row access rules (Row Level Security): from the app, your identifier can only read and write its own data, never another user's.
Never sent to our servers: the content of your engagement phrases, your voice, voice challenge transcripts, your motivation photo (as distinct from the "Stronger wake-up" mode proof photo, which passes through for analysis without being stored, section 2.7), your favorite quote, and your payment information.
Supabase's policy: supabase.com/privacy
If you ask to cancel your subscription from the app's Settings, we show you a short survey before redirecting you to Apple's cancellation page. It asks for the reason you are leaving (from a list of choices) and lets you add a free-text comment if you wish.
Answering is optional and has no bearing on your cancellation: cancellation happens entirely at Apple, and nothing you answer here can block, delay, or alter it.
If you do answer, we store on our servers: the reason selected, your free-text comment exactly as you wrote it (up to 500 characters), and your subscription plan plus whether you were in a trial period. All of it is tied to your anonymous identifier. Because this comment is free text, do not write sensitive information in it. It is never sent to PostHog or any third party; it is used solely to understand why people cancel.
"Stronger wake-up" mode is optional and enabled per alarm. It adds one or more small missions to your wake-up (memory, language exercises, etc.). Almost all of these missions run entirely on your device and send no new data. Only one is an exception: the photo proof mission.
If you enable the photo proof mission, at wake-up time the app asks you to take a live photo of yourself (via the camera) to confirm you are standing and out of bed. This photo is sent to our server (Supabase) and then forwarded to OpenAI, whose image analysis ("vision") service determines whether you are standing and whether the image is bright enough.
What happens to the photo: it is processed in flight and is kept nowhere: not on your device (beyond the immediate display after it passes), not on our servers, and not in our analytics. OpenAI acts here as a technical sub-processor: it receives the image only for as long as it takes to analyze it and, under its API terms, does not use it to train its models. We keep only the result of the judgment and technical metadata (see section 2.5), never the image.
To prevent abuse of this feature (each analysis has a cost), our server logs the IP address the request came from, along with a daily usage counter, tied to your anonymous identifier. An IP address is personal data; it is used solely to rate-limit abusive usage and is never used for advertising.
The Camera permission (section 2.3) is only requested if you use this mission. If the camera is not authorized or the analysis fails, the mission does not leave you locked at wake-up.
OpenAI's policy: openai.com/policies/privacy-policy
The voice challenge relies on the operating system's speech recognition:
requiresOnDeviceRecognition = true). No audio or transcription is sent to Apple's servers. If the requested language is not available on-device, the challenge falls back to keyboard input.Gallus does not record your voice, does not store transcriptions, and does not send any audio to its servers. Only the text result returned by the system is locally compared to your engagement phrase, then immediately removed from memory. The only information reported from a voice challenge is technical measurements: number of attempts, match percentage, and the length of the recognized text. Never the text itself.
Apple's policy: apple.com/legal/privacy/ · Google's policy: policies.google.com/privacy
Access to Gallus is gated by a paid subscription (monthly or yearly with a free trial). Payments are handled by the app stores, not by Gallus:
RevenueCat's policy: revenuecat.com/privacy
Gallus shows no ads and performs no cross-app tracking. The app's PrivacyInfo.xcprivacy file formally declares to Apple: NSPrivacyTracking = false. The data types collected by PostHog and RevenueCat (see sections 2.4 and 4) are declared with NSPrivacyCollectedDataTypeTracking = false and NSPrivacyCollectedDataTypeLinked = false.
The advertising identifier (IDFA on iOS, AAID on Android) is never read or used. No App Tracking Transparency (ATT) prompt is shown, because no cross-app tracking is performed.
We share no personal data with third parties for commercial or advertising purposes. The only technical third parties involved are:
We never sell your data, and we never share it with advertisers or data brokers.
On your device: your local data (section 2.2) is retained as long as the application is installed. To erase it all, uninstall Gallus: iOS and Android automatically wipe the app's private storage.
On our servers: the data described in sections 2.5 and 2.6, along with your phone number if you provided one, is retained until you ask us to delete it. We do not yet run an automatic purge after a fixed period. Importantly, uninstalling the app does not delete it, because it is not stored on your phone. To have it erased, email us at contact@gallus-app.com: we delete all data associated with your identifier, within 30 days at most.
Purchase history is kept by Apple or Google according to their respective policies, independently of Gallus.
You have the rights guaranteed by the GDPR over all data tied to your anonymous identifier. Some are exercised directly in the app, others on simple request by email:
| Right | How to exercise |
|---|---|
| Access | Your local data is visible inside the application itself. To receive a copy of the data held on our servers (sections 2.5 and 2.6), request it at contact@gallus-app.com. |
| Rectification | Edit alarms, phrases, and preferences directly in the app. To correct server-side data, email us. |
| Erasure | Uninstall the app: the OS wipes all local data. Uninstalling does not erase server-side data. To have all data tied to your identifier deleted (profile, alarms, events, diagnostics, cancellation survey, and your phone number if you provided one, both on our servers and at PostHog), contact us at contact@gallus-app.com. |
| Portability | On request at contact@gallus-app.com, we will send you the data we hold about you on our servers in a machine-readable format. |
| Objection / consent withdrawal | Revoke permissions (microphone, notifications) in system Settings. To opt out of analytics and diagnostics collection, or to stop us from contacting you on the number you provided, contact us at contact@gallus-app.com. |
For any further question, contact contact@gallus-app.com. Response time: 30 days.
Notifications are essential to Gallus: they trigger alarms and maintain the chained-alarm mechanism (which keeps reminding you until you complete the challenge). Disabling notifications means alarms cannot be reliably triggered.
Gallus is intended for users aged 13 or older, in line with app store terms. We do not knowingly collect data from minors. If you believe a minor has provided information, contact us at contact@gallus-app.com.
Our two main hosting services are located in the European Union: our database (Supabase, see 2.5) and our product analytics (PostHog, eu.i.posthog.com, see 2.4). However, if you use the photo proof mission (section 2.7), the photo is transmitted to OpenAI, located in the United States: this processing involves a transfer outside the EU. Any transfers performed by OpenAI, Apple, Google, RevenueCat, or Expo as part of their own services are governed by their respective policies and safeguards (EU Standard Contractual Clauses, EU-US Data Privacy Framework).
If we update this policy:
If you believe your rights are not being respected, you may file a complaint with:
For any question regarding this policy: contact@gallus-app.com
← Back to home