Data Policy

Effective Date: July 2026

This Data Policy explains how you can request an export of your personal information, how account deletion operates inside Alumea, and what technical procedures occur on our systems when you initiate a data request or account termination.

At Alumea (“we,” “our,” or “us”), we believe you should have complete clarity and control over your personal data. This policy outlines your data rights, our retention schedules, and our technical security safeguards.

For assistance with data requests, account deletion, or privacy inquiries, contact our privacy team at support@alumea.app.


1. Overview of Your Data Rights

You hold comprehensive rights regarding the personal information you share with Alumea:

  • Access & Ownership: You have the right to request a complete copy of all personal, wellness, and account data associated with your user profile.
  • Correction: You can update or amend your profile details at any time inside the app or by reaching out to support.
  • Account Erasure: You can permanently delete your account and associated personal data directly within the application settings.
  • Data Portability: Upon request, we will provide your account data in a structured, machine-readable format.

2. How to Request an Export of Your Data

While we work on introducing self-service CSV export features directly inside the application, you can request a complete export of all data linked to your account at any time.

How to Request a Data Export:

  1. Send an email from your registered Alumea account address to support@alumea.app with the subject line "Data Export Request".
  2. Our privacy team will verify your account identity to protect your confidential information.
  3. Within 30 days (and often much sooner), we will compile and securely transmit a comprehensive data package containing:
    • Account Information: Registered name, email address, account preferences, and creation timestamps.
    • Wellness & Reflection Data: Logged symptoms, check-ins, mood entries, cognitive restructuring responses (Reality Checks), and journal entries.
    • Subscription & Billing Records: Transaction history, subscription tier status, and payment renewal metadata (excluding sensitive credit card credentials).

3. How to Delete Your Account

You do not need to email support to delete your account. Alumea provides a direct, self-service account deletion control within the app.

Step-by-Step Deletion Process:

  1. Open the Alumea app on your mobile device.
  2. Tap the Settings icon in the main navigation.
  3. Navigate to either Account Details or My Subscription.
  4. Scroll to the bottom of the screen and tap Delete Account.
  5. Follow the on-screen confirmation prompts to finalize the deletion.

4. Important Considerations Before Deleting Your Account

Before confirming account deletion, please keep the following operational policies in mind:

  • Permanent Removal: Account deletion is irreversible. Once confirmed, your personal data, cognitive exercise history, check-in records, and journal entries are permanently purged from active systems and cannot be restored. If you wish to preserve your entries, request a data export before deleting your account.
  • Mobile Store Subscriptions: Deleting your Alumea account does not automatically cancel recurring active subscriptions billed through the Apple App Store or Google Play Store. Because Apple and Google manage mobile billing directly on their platforms, you must cancel your subscription through your device settings:
    • iOS: Go to Settings > Apple ID > Subscriptions.
    • Android: Open Google Play Store > Profile Icon > Payments & Subscriptions > Subscriptions.
  • Active System Purge: Upon account deletion confirmation, your profile records and personal data are deleted from active databases within 30 days.

5. System Backup Lifecycle & Disaster Recovery

To protect against infrastructure failures, technical corruption, and security incidents, Alumea maintains encrypted system backups on Google Cloud Platform (GCP).

  • Backup Retention: When you delete your account, your data is removed immediately from active production databases. Residual copies may persist in encrypted system backups until those backups expire and are overwritten according to our automated rotation cycle.
  • Strict Purpose Limitation: Backup repositories are isolated and encrypted. Backup data is used strictly for disaster recovery, system restoration, and emergency infrastructure continuity. We never extract deleted data from backups for product operations, analytics, research, or marketing.

6. What Data We Collect & How We Use It

For a complete explanation of our data collection practices, please review our full Privacy Policy.

Summary of Collected Categories:

  • Account Data: Name, email address, password hash, date of birth, and account preferences.
  • Wellness & Health Data: Symptoms, mood check-ins, journal entries, and cognitive restructuring exercise responses (processed as Special Category Data under explicit consent).
  • Technical & Device Data: IP address, operating system, unique device identifiers, app version, and crash diagnostic logs.
  • Billing Metadata: Payment status, subscription renewal dates, and transaction tokens (processed via RevenueCat and Stripe).

Summary of Usage Purposes:

We process data strictly to deliver guided anxiety management features, personalize wellness insights, manage subscriptions, communicate critical service updates, maintain infrastructure security, and fulfill legal obligations.

We do not sell your personal information, and we do not share identifiable user content with third parties or external artificial intelligence providers for model training.

7. Anonymized Data for Research and Product Efficacy

We may transform usage data, exercise interactions, and aggregated check-in patterns into anonymized or de-identified datasets.

  • Effective Anonymization: Anonymization removes or transforms all personal identifiers so that the data can no longer reasonably identify or be linked to any individual.
  • Product Improvement: Non-identifiable anonymized datasets help us evaluate feature effectiveness, analyze common friction points in health anxiety exercises, conduct product safety research, and improve Alumea for all users.
  • Retention Post-Deletion: Because genuinely anonymized and aggregated data contains no personal identifiers, we may retain non-identifiable aggregated metrics after an account is deleted to maintain product benchmarks and research continuity.

8. Data Security & Encryption Standards

Alumea implements multi-layered security measures to safeguard your information:

  • Data in Transit: Secured using Transport Layer Security (TLS 1.2+ / SSL).
  • Data at Rest: Encrypted using AES-256 bit encryption across all databases, cloud storage buckets, and server backups on Google Cloud Platform (GCP) infrastructure in Europe (EEA).
  • Access Control: System access is restricted to authorized personnel operating under least-privilege permissions, multi-factor authentication, and strict confidentiality agreements.

9. Data Retention Timeline

Data Lifecycle PhaseTimeline & Handling
Active AccountsData is retained while your account remains active to provide the Services.
Account DeletionPersonal data is purged from active production databases within 30 days.
Encrypted BackupsPurged automatically as backup rotation cycles expire and overwrite legacy snapshots.
Anonymized MetricsNon-identifiable aggregated research metrics are retained for system analysis.
Legal Compliance RecordsLimited financial transaction metadata is retained where required by statutory tax/legal laws.

10. Contact Us & Additional Resources

If you have questions about your data, need help with a data export, or require privacy assistance, please contact us:

Core Legal Documents:

  • Privacy Policy — Comprehensive details on our privacy practices and data rights.
  • Terms of Service — Terms and conditions governing the use of Alumea.