← Back to PrimeFlow

Privacy Policy

PrimeFlow Core / PrimeFlow Pearl

Last updated: February 2026
Version: 1.1

EXECUTIVE SUMMARY

This Privacy Policy describes how PrimeFlow Labs S.L. collects, uses and protects the personal data of users of the PrimeFlow Core and PrimeFlow Pearl applications.

AspectSummary
What data do we collect?Registration data, app usage data and exercise data
What do we use it for?Providing the service, personalising the experience, improving the app
Do we share it?Only with essential service providers and we never sell data
Where is it stored?On secure servers within the EU
How long do we keep it?As long as your account is active, plus legally required periods
What are your rights?Access, rectification, erasure, portability, objection and restriction

1. DATA CONTROLLER INFORMATION

1.1 Identity of the Controller

FieldInformation
ControllerPrimeFlow Labs S.L.
Tax ID (CIF)[Pending registration]
Registered address[Fiscal address], Spain
Privacy emailprivacy@prime-flow-app.com
Websitehttps://prime-flow-app.com

1.2 Privacy Contact

For data protection enquiries, you may contact our privacy team at: privacy@prime-flow-app.com

2. DATA WE COLLECT

2.1 Data You Provide to Us

2.1.1 Registration Data

DataPurposeLegal basis
NamePersonalisation of the experienceContract
EmailIdentification and communicationsContract
PasswordAccess security (stored encrypted)Contract
Date of birthAge verification, personalisationContract
CountryRegional adaptation, legal complianceContract

2.1.2 Onboarding Data

DataPurposeLegal basis
Health goalsPersonalisation of routines and exercisesConsent
Available timeAdaptation of session durationContract
Notification preferencesSending remindersConsent

2.1.3 Exercise Data (Special Category)

IMPORTANT: Data related to pelvic floor exercises may be considered health-related data under Article 9 of the GDPR. We process this data based on your explicit consent, which you provide when you accept this Privacy Policy and begin using the application.

DataPurposeLegal basis
Completed sessionsProgress trackingConsent
Exercise type and durationProgramme personalisationConsent
Level and progressionAutomatic difficulty adjustmentConsent
Streaks and achievementsMotivation and gamificationConsent

2.2 Data We Collect Automatically

DataPurposeLegal basis
Device type and modelTechnical compatibilityLegitimate interest
Operating system and versionTechnical supportLegitimate interest
App usage statisticsService improvementLegitimate interest
Error and crash logsBug fixingLegitimate interest
Subscription statusService managementContract

2.3 Data We Do NOT Collect

We want to be transparent: we never collect:

3. HOW WE USE YOUR DATA

3.1 Primary Purposes

PurposeData usedLegal basis
Providing the serviceRegistration, profile, exercisesPerformance of contract
Personalising routinesGoals, level, progressPerformance of contract
Sending remindersEmail, time preferencesConsent
Showing progressSession dataConsent
Managing subscriptionEmail, billing data (via stores)Performance of contract

3.2 Secondary Purposes

PurposeData usedLegal basis
Improving the applicationAnonymous usage dataLegitimate interest
Statistical analysisAggregated, anonymous dataLegitimate interest
Fraud preventionUsage patternsLegitimate interest
Legal complianceAs requiredLegal obligation

3.3 Communications

TypeLegal basisOpt-out
Training remindersConsentApp settings
Service communicationsPerformance of contractNot applicable
News and updatesLegitimate interestLink in email
Marketing and promotionsConsentSettings or link in email

4. LEGAL BASES FOR PROCESSING

Under the GDPR, we need a legal basis for each processing of data:

4.1 Performance of Contract (Art. 6.1.b GDPR)

We process data necessary to:

4.2 Consent (Art. 6.1.a GDPR)

We request your explicit consent to:

You may withdraw your consent at any time from the application settings or by contacting privacy@prime-flow-app.com

4.3 Legitimate Interest (Art. 6.1.f GDPR)

We rely on our legitimate interest to:

We have carried out balancing assessments demonstrating that these processing activities do not override your rights and freedoms.

4.4 Legal Obligation (Art. 6.1.c GDPR)

We comply with legal obligations such as:

5. WHO WE SHARE YOUR DATA WITH

5.1 Service Providers (Data Processors)

We share data with providers who help us operate the service:

ProviderServiceDataLocation
Google FirebaseDatabase and authenticationRegistration, usageEU (Belgium)
RevenueCatSubscription managementUser ID, subscription statusUSA*
Google AnalyticsUsage analyticsAnonymous dataUSA*
OneSignalPush notificationsToken, preferencesUSA*

*These providers are certified under the EU-US Data Privacy Framework or have Standard Contractual Clauses (SCCs) ensuring an adequate level of protection.

5.2 App Stores

Subscription payments are processed directly by:

We do not have access to your complete payment data (card number, bank account).

5.3 Third Parties We Do NOT Share Data With

We never sell, rent or share your personal data with:

5.4 Other Disclosure Scenarios

We may disclose data to third parties when:

6. INTERNATIONAL TRANSFERS

6.1 General Principle

Your data is primarily stored on servers located within the European Union.

6.2 Transfers to the USA

Some of our providers are based in the United States. For these transfers, we use the following safeguards:

SafeguardDescription
EU-US Data Privacy FrameworkProviders certified under this framework
Standard Contractual Clauses (SCCs)Contracts approved by the European Commission
Supplementary measuresEncryption, pseudonymisation, access controls

6.3 Risk Assessment

We have assessed the risk of each international transfer and concluded that the safeguards in place provide a level of protection essentially equivalent to that of the GDPR.

You may request further information about specific safeguards by contacting privacy@prime-flow-app.com

7. DATA RETENTION

7.1 Retention Periods

Data typeRetention periodReason
Account dataWhile the account is activeService provision
Exercise dataWhile the account is activeProgress tracking
Billing data5 years after the last transactionTax obligations
Consent records5 yearsLegal proof
Anonymous usage data2 yearsStatistical analysis
Error logs90 daysTechnical debugging

7.2 After Deletion

When you delete your account or the retention periods expire:

8. DATA SECURITY

8.1 Technical Measures

8.2 Organisational Measures

8.3 Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms:

9. YOUR RIGHTS

Under the GDPR, you have the following rights:

RightDescriptionTimeframe
AccessKnow what data we process about you1 month
RectificationCorrect inaccurate data1 month
ErasureDelete your data ("right to be forgotten")1 month
PortabilityReceive your data in a structured format1 month
ObjectionObject to certain processing activities1 month
RestrictionLimit the processing in certain cases1 month
Withdraw consentWithdraw previously given consentImmediate

How to Exercise Your Rights

We will respond within one month. In complex cases, this may be extended by an additional two months with prior notice.

Right to Lodge a Complaint

If you believe your data protection rights have been infringed, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es, or with your local supervisory authority.

10. CHILDREN

The application is intended for people aged 18 and over. We do not knowingly collect data from children. If we become aware that we have collected data from a person under 18, we will immediately delete such data.

11. ACCOUNT AND DATA DELETION

11.1 How to Delete Your Account

You may request the deletion of your account and all associated data:

11.2 What Happens When You Delete Your Account

12. COOKIES AND SIMILAR TECHNOLOGIES

12.1 In the App

The mobile application does not use traditional cookies. It uses local storage (AsyncStorage) to save preferences and session data on the device.

12.2 On the Website

Our website may use:

TypePurposeConsent
Essential cookiesBasic website functionalityNot required
Analytics cookiesUnderstanding how visitors use the siteRequired
Preference cookiesRemembering user settingsRequired

13. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. In the event of significant changes:

14. CONTACT

For any privacy-related enquiries:

15. ADDITIONAL INFORMATION

This Privacy Policy has been drawn up in accordance with:

16. VERSION HISTORY

© 2026 PrimeFlow Labs S.L. All rights reserved.