Privacy Policy
Pluh Inc. · Last updated September 24, 2026
This policy explains what Pluh Inc. (“Pluh,” “we,” “us”) collects when you use Pandu, what we do with it, and the choices you have. Pandu is the iOS app and the websites at panducare.com and start.panducare.com (the skin quiz and web checkout). Together we call them the “Service.”
1. Who we are
Pluh Inc. is a Delaware corporation. We are the data controller for the personal information described here. You can reach us at hey@thepandu.app.
2. What we collect
On start.panducare.com (the quiz and checkout)
- Email address.Entered on the quiz. We use it to create your Pandu account (see §3), attach your purchase to it, and send the emails described in §7.
- Quiz answers. Your skin type, concerns, and lifestyle answers, used to build your plan and pre-fill your profile in the app.
- First name. Optional, if you choose to give one.
- Approximate location. One quiz screen shows local UV, humidity, and air-quality readings. To do that, we derive a city-level location from your IP address using Cloudflare. It is used only to show that screen and is not stored.
- Selfie. The selfie step captures a photo on your deviceto preview your face map. It is never uploaded from the website. It is not the same as the face scan in the app (see §4).
- IP address and browser user agent. Stored with your quiz record for fraud prevention and advertising attribution.
- Advertising and campaign identifiers. Click identifiers from the link that brought you to us (
fbclid,ttclid,gclid), the Meta browser cookies (_fbp,_fbc), UTM parameters, the page you landed on, and the referring site. - Purchase details.Which plan you bought, when, the Stripe customer and subscription identifiers, and the status of your subscription. Your card number never reaches our servers; Stripe handles it (see §8).
In the app: things you give us
- Account info: your email address, and a name or nickname if you choose to share one.
- Skin profile:answers you give during onboarding — skin type, sensitivities, goals, age range, and optional details like pregnancy or breastfeeding status. You decide what to share.
- Your routine: the steps you build, the products you save to your shelf, and the daily check-ins you tap off.
- Face scans:photos you take of your skin so Pandu can show your progress over time. See §4.
- Product scans: photos of product labels or barcodes when you ask Pandu to check a product.
- Messages to your AI panda: anything you type into the in-app chat.
In the app: things we collect automatically
- Device and app info: device model, OS version, app version, language, timezone.
- Usage events: screens viewed, actions taken (open, scan, complete a step), session length. Used to understand how Pandu is working.
- Crash reports: stack traces and surrounding state when the app crashes.
- A random per-install identifierfor analytics, and — only if you allow it when iOS asks — the advertising identifier (IDFA) for ad measurement. See §6.
Things we do not collect
We do not collect precise location, your contacts, microphone audio, or your camera roll beyond the specific photos you choose to share with the app. We never see your full card number.
3. How we use what we collect
We use the information above to:
- Create your account when you enter your email on the quiz, and sign you into the app after purchase with a one-time claim link or a 6-digit email code.
- Run the Service: save your routine, sync between devices, keep your plan active.
- Show you your progress over time and rate products against your skin profile.
- Power the AI panda. When you chat, we send your message, your recent routine context, and your skin profile to our AI provider so the reply is relevant. See §10.
- Process payments and manage your subscription, with Stripe or Apple.
- Send the emails and push notifications described in §7.
- Measure whether our advertising works, so we can spend on ads that reach people who actually want Pandu. See §5 and §6.
- Diagnose crashes and improve the app and the quiz.
- Detect and prevent abuse, fraud, and security incidents.
- Comply with our legal obligations, including tax and accounting rules.
We do not sell your personal information.We do not run third-party ads inside Pandu. We do not give your skin profile, quiz answers, face scans, routine, or chat messages to advertisers or data brokers. We do share limited conversion data (a hashed email address, IP address, browser details, click identifiers, and the fact that a purchase or sign-up happened) with Meta and TikTok so they can measure our ads, as described in §5 and §6.
Legal bases (UK / EEA users). Where GDPR applies, we rely on: your consent (face scans, optional profile fields, push notifications, advertising cookies and pixels where consent is required); performance of our contract with you (account, routine, shelf, checkout, billing, transactional email); legitimate interest (security, fraud prevention, debugging, basic product analytics, measuring our own advertising); and legal obligation (tax records, responding to lawful requests).
4. Face scans
In the app, face scans use Apple’s ARKit and, on TrueDepth-equipped devices, the TrueDepth API to align a single front-facing photo to your face region. We collect a standard RGB photograph from your front-facing camera and a face-surface mesh that is used only in memory to crop and align that photograph. The mesh is not retained, transmitted to any server, or used to build any biometric template. Only the cropped photograph and the resulting written analysis are saved to your account.
- Face scans are encrypted in transit and at rest, and tied only to your account.
- We use them to draw your visual timeline, generate per-scan analyses (texture, tone, breakouts), and — only with your explicit opt-in — improve the model that produces those analyses.
- We do not sell or share face scans with advertisers.
- We do not use face scans for biometric identification or to recognise you across other services.
- The cropped photograph is processed by our AI provider (Anthropic) under zero-retention enterprise terms — it is not used to train their models and is not retained beyond the request needed to generate your analysis.
- You can delete any individual scan in Scan History. Deleting your account removes all scans within 30 days, except where they have already been written to a rolling backup (also deleted within 30 days).
The selfie on start.panducare.com is different: it stays in your browser and is never uploaded.
5. Advertising and analytics on start.panducare.com
Most people find Pandu through an ad. To know which ads work, the quiz and checkout use the following technologies. None of them receive your quiz answers, face scan, or routine.
- Meta Pixel (Meta Platforms, Inc.). A script that tells Meta which pages you viewed and whether you signed up or bought, together with the
_fbpand_fbccookies and your browser details. Meta uses this to attribute the result to an ad you saw on Facebook or Instagram and, under its own policies, to improve its ad delivery. - TikTok Pixel (TikTok Inc.). The same idea for ads you saw on TikTok, using the
ttclidclick identifier and TikTok’s cookies. - Meta Conversions API and TikTok Events API (server-side). When you sign up or complete a purchase, our servers also send that event directly to Meta and TikTok with a hashed (SHA-256) version of your email address, your IP address, browser user agent, and the click identifiers above. Server-side events are more reliable than the browser pixel and let the platforms count a purchase even if the pixel was blocked. Each event carries an identifier so the browser and server copies are de-duplicated.
- PostHog. Product analytics and error tracking for the quiz (which steps people reach, where they drop off, what breaks). Uses cookies and browser storage. The payment step happens on Stripe’s page, which PostHog does not see.
- Cloudflare Turnstile. A bot check that runs when you submit your email. It may set cookies and looks at browser signals to tell people from scripts.
- Stripe. Hosts the checkout page and processes payment. Stripe may set cookies for fraud prevention. Your card details never touch our servers. Stripe’s own privacy policy governs what it does with them.
Your choices.
- Block or clear cookies in your browser; the quiz and checkout still work without the advertising cookies.
- Control how Meta uses data from sites like ours at facebook.com/adpreferences.
- Control how TikTok uses off-platform data in the TikTok app under Settings and privacy → Ads.
- Turn on Global Privacy Control in your browser. Where the law requires it, we treat a GPC signal as a request to opt out of the sharing described here.
- Email hey@thepandu.app and we will stop sending your data to advertising platforms.
6. Advertising measurement in the iOS app
The app may ask for permission to track you using Apple’s App Tracking Transparency prompt. If you allow it, the app shares your device’s advertising identifier (IDFA) with TikTok and Meta so they can match your install and subscription to an ad. If you decline, we do not access the IDFA, and attribution happens only through Apple’s privacy-preserving SKAdNetwork, which gives advertisers aggregate counts without identifying you. Separately, when you start a trial or subscribe, our servers send that event to Meta and TikTok with a hashed email and an anonymous account identifier so the platforms can measure results. You can change your choice at any time in iOS Settings → Privacy & Security → Tracking.
7. Emails and notifications
If you use the web quiz or checkout, we may email you:
- Transactional messages you cannot unsubscribe from while your account exists: your purchase confirmation with the claim link that signs you into the app, 6-digit sign-in codes you request, receipts and billing notices from Stripe, and important notices about your account or these policies.
- At most one reminder if you started checkout but did not finish it.
Every non-transactional email has an unsubscribe link. You can also opt out by emailing hey@thepandu.app. In the app, push notifications (routine reminders, streak nudges) are sent only if you opt in, and can be turned off in iOS Settings.
8. Payments
Web purchases are processed by Stripe, Inc. When you pay, Stripe collects your card details, billing information, and device signals for fraud prevention under its own privacy policy. We receive confirmation of the payment, the plan, the last four digits and brand of your card, and identifiers we use to manage your subscription and open the billing portal for you. App Store purchases are processed by Apple; we receive the subscription status and an anonymised transaction identifier, not your payment details.
9. Children
Pandu is not for children under 13 (or under 16 in the EU and UK). We do not knowingly collect personal information from people in those age groups. If you think a child has given us information, email hey@thepandu.app and we will delete it.
10. Who we share information with
We share information with vendors that help us run Pandu, each limited by contract to processing data on our behalf, and with the advertising platforms described in §5 and §6.
- Supabase— database, authentication (including claim links and sign-in codes), file storage (face scans, product photos).
- Cloudflare— API and website hosting, edge delivery, DDoS protection, IP-based approximate location, Turnstile bot check.
- Stripe— web payments, subscription billing, billing portal, receipts.
- Apple— App Store subscriptions, Sign in with Apple, push notifications, SKAdNetwork attribution.
- Anthropic— powers the AI panda and face-scan analyses. Receives your message and limited routine context for each reply, under zero-retention terms.
- PostHog— product analytics and error tracking (web and app).
- Sentry— crash reporting.
- Superwall— displays in-app subscription offers and reports subscription events.
- Meta and TikTok— advertising measurement as described in §5 and §6. These platforms act as independent controllers of the data they receive.
We may also share information when required by law, in response to lawful requests from public authorities, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
If Pluh goes through a merger, acquisition, or sale of part of the business, your information may be transferred as part of that deal. We will notify you before your information becomes subject to a different privacy policy.
11. International transfers
Pluh is based in the United States. Some vendors process data in other countries. Where required, we rely on Standard Contractual Clauses or equivalent mechanisms to protect information transferred outside the EEA or UK.
12. How long we keep things
- Account data, routine, shelf: while your account is active.
- Face scans and scan analyses: while your account is active.
- Quiz records that never lead to a purchase: deleted or anonymised within 12 months.
- Purchase and payment records: as long as needed for tax and accounting, which is 7 years for payment records.
- Analytics events and crash reports: up to 12 months in identifiable form.
- AI panda conversations: up to 90 days.
- Rolling backups: up to 30 days after deletion.
You can delete your account inside the app (Settings → Account → Delete account) or by emailing us. We will permanently delete your data within 30 days, except where we are legally required to keep it (for example, billing records for tax purposes).
13. Your rights
Depending on where you live, you may have the right to:
- Access the information we hold about you
- Correct inaccurate information
- Delete your information
- Receive your information in a portable format
- Restrict or object to certain processing
- Withdraw consent you previously gave
- Opt out of the sharing of your information for advertising
- Lodge a complaint with your local data protection authority
To use any of these rights, email hey@thepandu.app from the address tied to your account. We will respond within 30 days. We will not treat you any differently for asking.
California and other U.S. states.We do not sell personal information. Sending conversion events to Meta and TikTok (§5, §6) may count as “sharing” for cross-context behavioral advertising under the CCPA and similar state laws. You can opt out using the choices in §5, by turning on Global Privacy Control, or by emailing us. We do not knowingly share the personal information of anyone under 16.
14. Security
We use standard safeguards: TLS in transit, encryption at rest, scoped access tokens, audit logs, and row-level security on our database so each account only sees its own data. Claim links are single-use and expire. No system is perfectly secure; if we discover a breach affecting you, we will notify you as required by law.
15. Cookies and tracking
panducare.com uses essential cookies and first-party product analytics only. start.panducare.com additionally uses the advertising and analytics technologies listed in §5. The app does not use cookies. You can clear cookies in your browser settings at any time.
16. Changes to this policy
We will update this policy when our practices change. If a change is material, we will let you know inside the app or by email before it takes effect. The “Last updated” date at the top tells you when the current version was published.
17. Contact
Pluh Inc., Attn: Privacy
Email: hey@thepandu.app