Version française

Privacy

Last updated: July 29, 2026

We take the protection of your personal data seriously. This privacy policy explains how the Gallus application collects, uses, shares, and protects information when you use it. It applies to all Gallus users, regardless of where you reside.

In short: Gallus works with no user account and no advertising tracking whatsoever. The things that are most personal to you never leave your device: the content of your engagement phrases, your voice, your voice transcripts, your motivation photo, and your favorite quote (see sections 2.2 and 3). That said, Gallus does have servers (Supabase, hosted in the European Union) where we record technical data tied to an anonymous identifier: your alarm settings, usage and diagnostic events, and subscription state (see section 2.5). Two pieces of personal data may be added to it, both optional: a phone number you may provide during onboarding so we can gather your feedback (section 2.1), and the free-text comment you may write if you cancel your subscription (section 2.6). Finally, one exception about photos: if you enable "Stronger wake-up" mode, its photo proof mission takes a wake-up photo of you that is sent to an AI service (OpenAI) just long enough to check that you are standing up, then kept nowhere (section 2.7). It is distinct from your motivation photo, which never leaves your device.

1. Data Controller

The data controller is Gallus, based in France. Contact: contact@gallus-app.com

2. Data Collected

2.1 No user account, but an anonymous identifier

Gallus provides no user account system: no sign-up, no password. We do not ask for your name, email, or any identity data.

On first launch, the app automatically opens an anonymous session on our server. It generates a random technical identifier (a UUID) that contains no information about you and is not linked to any identity. That identifier, and nothing else, is what ties together the data described in section 2.5. This data is pseudonymous: it cannot identify you by name, but it does constitute personal data under the GDPR, and you have all your rights over it (section 9).

During onboarding, we also ask, on a strictly optional basis, for your phone number. You can skip this step and keep using the app normally. If you choose to provide it, we use it for a single purpose: to contact you (typically via WhatsApp) to gather feedback and help us improve Gallus during this early phase. It is then stored in two places: on our server (section 2.5) and as a contact property in our analytics tool (section 2.4). We never sell it, never use it for advertising, and you can ask us to delete it or to stop contacting you at any time (see sections 9 and 15).

Providing your phone number is the only act that lifts the pseudonymity: without it, we have no way of knowing who you are.

2.2 Data that never leaves your device

The following is stored only on your device, in the application's private sandbox. It is never sent to our servers, nor to any third party:

Data Purpose
The content of your engagement phrases (both the catalog ones and the ones you write) Voice challenge to dismiss the alarm
Motivation photo (if you add one) Personalized display during the challenge
Favorite quote (if you set one) Personalized display during the challenge
Display preferences (theme, vibration) App personalization

Two nuances, to be exact: your device's language is part of the technical profile sent to our servers (section 2.5), and your subscription state is cached locally but also exists server-side (sections 2.5 and 4). Neither says anything about your identity.

This data is removed when you uninstall the application.

Not to be confused with photo proof: the motivation photo above stays on your device and is never sent. It is different from the wake-up proof photo in "Stronger wake-up" mode, which is transmitted for analysis at wake-up time without being stored (see section 2.7).

One exception to be aware of: the name you give an alarm (its label, e.g. "Work wake-up") is free text, and it is sent to our servers along with the rest of the alarm's settings (section 2.5).

In total, the app has only three free-text fields whose content leaves your device: the alarm label, the "Other" answer to the "how did you hear about Gallus?" onboarding question, and the optional comment in the cancellation survey (section 2.6). Avoid entering sensitive information in them. Your engagement phrases are in none of these cases: they stay on the device.

2.3 Required system permissions

Permission Purpose Required?
Microphone Voice recognition for the challenge (speak the phrase to dismiss) Yes (otherwise keyboard fallback)
Speech recognition Verify that you correctly pronounce the phrase Yes (otherwise keyboard fallback)
Notifications Trigger alarms and chained reminders Yes
Alarms (AlarmKit, iOS 26+) Allow alarms to ring even in silent mode or Do Not Disturb Yes (iOS only)
Photo library Pick a motivation photo No, optional
Camera Take the "Stronger wake-up" mode proof photo (photo proof mission) No, only if you enable that mission (section 2.7)

2.4 Anonymous product analytics (PostHog)

Gallus uses PostHog (hosted in Europe, eu.i.posthog.com) to understand how the app is used and improve it. PostHog receives anonymous events tied to a random identifier generated locally on your device. By default this identifier is not linked to any identity information.

If you choose to provide your phone number (section 2.1), it is attached to your PostHog profile as a contact property so we can reach out for feedback. In that case, your analytics profile is no longer anonymous. If you skip that step, your profile stays anonymous.

Data sent to PostHog Data never sent
  • App opens (lifecycle)
  • Phone number — only if you choose to provide it (section 2.1), stored as a contact property
  • Onboarding screens visited (steps, drop-offs)
  • How you heard about Gallus, including the text you type if you answer "Other"
  • Paywall view and plan selection (monthly/yearly)
  • Purchase attempts (succeeded, cancelled, failed) — no payment details
  • Phrase creation and deletion (counts only, never their content)
  • Cancellation survey opened and reason selected (section 2.6). The free-text comment is not sent to PostHog
  • Device type, iOS version, device language
  • Installed app version
  • Name, email, profile picture — you don't enter any of these in the app
  • Geo-precise IP address (PostHog truncates the IP)
  • IDFA / advertising identifier
  • The content of your engagement phrases
  • Your alarm labels (they do go to our servers, section 2.5, but not to PostHog)
  • Recorded audio or voice challenge transcripts
  • Motivation photo
  • Payment information

This data is used solely for product analytics (e.g., identifying friction points in onboarding). It is never used for advertising or shared with third parties for commercial purposes. The app's privacy manifest (PrivacyInfo.xcprivacy) formally declares these analytics collections to Apple as Product Interaction, Other Usage Data, Purchase History, and User ID — all marked Linked to User = false and Used for Tracking = false. The optional phone number (section 2.1), when you provide it, is declared separately as Phone Number (Contact Info), Linked to User = true, used only to contact you and never for tracking.

PostHog's policy: posthog.com/privacy

2.5 Data sent to our servers (Supabase)

Gallus relies on a database hosted with Supabase, in the European Union. All the data below is tied to the anonymous identifier described in section 2.1, not to your identity. It serves three purposes: running the subscription, diagnosing alarms that fail to ring (the most serious risk for an alarm app), and improving the product.

Data Content Why
Technical profile Device model, OS version, app version, language, time zone, permission states (notifications, AlarmKit), push notification token, and your phone number if you provided one (section 2.1) Know which devices and versions alarms fail on
Your alarm settings Time, days, on/off state, sound, volume, phrase mode, the identifiers of the associated phrases (never their text), and the alarm label (free text) Reproduce and understand trigger failures
Usage and diagnostic events App opens, screens visited, alarm lifecycle, voice challenge flow (number of attempts, match rate, and the length of the transcript, never its text), technical errors and crash traces Detect bugs and friction points
Diagnostic snapshots A comparison between the alarms stored in the app and those actually scheduled by the iOS system (AlarmKit), to spot discrepancies Fix alarms that don't ring
Subscription state Plan (monthly/yearly), status (trial, active, expired), period end date. Sent by RevenueCat, with no payment data whatsoever Verify your access to features
Cancellation survey See section 2.6 Understand why people leave
"Stronger wake-up" mode (photo proof) Judgment result (standing yes/no, sufficient brightness, pass), the AI model used, response time, image size in bytes, anti-abuse counters, and the IP address the call came from. Never the image itself. See section 2.7 Track the feature's reliability and cost, and prevent abuse
Wake-up streaks Number of consecutive days you completed your wake-up Show your progress (streak)

This data is protected by per-row access rules (Row Level Security): from the app, your identifier can only read and write its own data, never another user's.

Never sent to our servers: the content of your engagement phrases, your voice, voice challenge transcripts, your motivation photo (as distinct from the "Stronger wake-up" mode proof photo, which passes through for analysis without being stored, section 2.7), your favorite quote, and your payment information.

Supabase's policy: supabase.com/privacy

2.6 Cancellation survey

If you ask to cancel your subscription from the app's Settings, we show you a short survey before redirecting you to Apple's cancellation page. It asks for the reason you are leaving (from a list of choices) and lets you add a free-text comment if you wish.

Answering is optional and has no bearing on your cancellation: cancellation happens entirely at Apple, and nothing you answer here can block, delay, or alter it.

If you do answer, we store on our servers: the reason selected, your free-text comment exactly as you wrote it (up to 500 characters), and your subscription plan plus whether you were in a trial period. All of it is tied to your anonymous identifier. Because this comment is free text, do not write sensitive information in it. It is never sent to PostHog or any third party; it is used solely to understand why people cancel.

2.7 "Stronger wake-up" mode and photo proof

"Stronger wake-up" mode is optional and enabled per alarm. It adds one or more small missions to your wake-up (memory, language exercises, etc.). Almost all of these missions run entirely on your device and send no new data. Only one is an exception: the photo proof mission.

If you enable the photo proof mission, at wake-up time the app asks you to take a live photo of yourself (via the camera) to confirm you are standing and out of bed. This photo is sent to our server (Supabase) and then forwarded to OpenAI, whose image analysis ("vision") service determines whether you are standing and whether the image is bright enough.

What happens to the photo: it is processed in flight and is kept nowhere: not on your device (beyond the immediate display after it passes), not on our servers, and not in our analytics. OpenAI acts here as a technical sub-processor: it receives the image only for as long as it takes to analyze it and, under its API terms, does not use it to train its models. We keep only the result of the judgment and technical metadata (see section 2.5), never the image.

To prevent abuse of this feature (each analysis has a cost), our server logs the IP address the request came from, along with a daily usage counter, tied to your anonymous identifier. An IP address is personal data; it is used solely to rate-limit abusive usage and is never used for advertising.

The Camera permission (section 2.3) is only requested if you use this mission. If the camera is not authorized or the analysis fails, the mission does not leave you locked at wake-up.

OpenAI's policy: openai.com/policies/privacy-policy

3. Speech recognition

The voice challenge relies on the operating system's speech recognition:

Gallus does not record your voice, does not store transcriptions, and does not send any audio to its servers. Only the text result returned by the system is locally compared to your engagement phrase, then immediately removed from memory. The only information reported from a voice challenge is technical measurements: number of attempts, match percentage, and the length of the recognized text. Never the text itself.

Apple's policy: apple.com/legal/privacy/ · Google's policy: policies.google.com/privacy

4. Subscription and in-app purchases

Access to Gallus is gated by a paid subscription (monthly or yearly with a free trial). Payments are handled by the app stores, not by Gallus:

RevenueCat's policy: revenuecat.com/privacy

5. Tracking and advertising

Gallus shows no ads and performs no cross-app tracking. The app's PrivacyInfo.xcprivacy file formally declares to Apple: NSPrivacyTracking = false. The data types collected by PostHog and RevenueCat (see sections 2.4 and 4) are declared with NSPrivacyCollectedDataTypeTracking = false and NSPrivacyCollectedDataTypeLinked = false.

The advertising identifier (IDFA on iOS, AAID on Android) is never read or used. No App Tracking Transparency (ATT) prompt is shown, because no cross-app tracking is performed.

6. Sharing data with third parties

We share no personal data with third parties for commercial or advertising purposes. The only technical third parties involved are:

We never sell your data, and we never share it with advertisers or data brokers.

7. Retention

On your device: your local data (section 2.2) is retained as long as the application is installed. To erase it all, uninstall Gallus: iOS and Android automatically wipe the app's private storage.

On our servers: the data described in sections 2.5 and 2.6, along with your phone number if you provided one, is retained until you ask us to delete it. We do not yet run an automatic purge after a fixed period. Importantly, uninstalling the app does not delete it, because it is not stored on your phone. To have it erased, email us at contact@gallus-app.com: we delete all data associated with your identifier, within 30 days at most.

Purchase history is kept by Apple or Google according to their respective policies, independently of Gallus.

8. Security

9. Your rights

You have the rights guaranteed by the GDPR over all data tied to your anonymous identifier. Some are exercised directly in the app, others on simple request by email:

Right How to exercise
Access Your local data is visible inside the application itself. To receive a copy of the data held on our servers (sections 2.5 and 2.6), request it at contact@gallus-app.com.
Rectification Edit alarms, phrases, and preferences directly in the app. To correct server-side data, email us.
Erasure Uninstall the app: the OS wipes all local data. Uninstalling does not erase server-side data. To have all data tied to your identifier deleted (profile, alarms, events, diagnostics, cancellation survey, and your phone number if you provided one, both on our servers and at PostHog), contact us at contact@gallus-app.com.
Portability On request at contact@gallus-app.com, we will send you the data we hold about you on our servers in a machine-readable format.
Objection / consent withdrawal Revoke permissions (microphone, notifications) in system Settings. To opt out of analytics and diagnostics collection, or to stop us from contacting you on the number you provided, contact us at contact@gallus-app.com.

For any further question, contact contact@gallus-app.com. Response time: 30 days.

10. Push notifications

Notifications are essential to Gallus: they trigger alarms and maintain the chained-alarm mechanism (which keeps reminding you until you complete the challenge). Disabling notifications means alarms cannot be reliably triggered.

11. Protection of minors

Gallus is intended for users aged 13 or older, in line with app store terms. We do not knowingly collect data from minors. If you believe a minor has provided information, contact us at contact@gallus-app.com.

12. International transfers

Our two main hosting services are located in the European Union: our database (Supabase, see 2.5) and our product analytics (PostHog, eu.i.posthog.com, see 2.4). However, if you use the photo proof mission (section 2.7), the photo is transmitted to OpenAI, located in the United States: this processing involves a transfer outside the EU. Any transfers performed by OpenAI, Apple, Google, RevenueCat, or Expo as part of their own services are governed by their respective policies and safeguards (EU Standard Contractual Clauses, EU-US Data Privacy Framework).

13. Changes to this policy

If we update this policy:

14. Complaint to a supervisory authority

If you believe your rights are not being respected, you may file a complaint with:

15. Contact

For any question regarding this policy: contact@gallus-app.com

← Back to home