Your data, explained

Privacy policy

How PlungeLab handles your information, what stays on your devices, and the choices you control.

Effective date: September 8, 2026

PlungeLab is provided by EGGYOLK YAZILIM TİCARET LİMİTED ŞİRKETİ (“Eggyolk,” “we,” “us,” or “our”). This Privacy Policy explains how personal data is handled when you use the PlungeLab iPhone app, Apple Watch app, widgets, complications, and the PlungeLab website, support, or legal pages (together, “PlungeLab”).

The short version

  • Your PlungeLab session history, Apple Health data, notes, heart-rate data, temperatures, and personal insights are stored and analyzed on your devices. Eggyolk does not receive them through the ordinary operation of the app.
  • PlungeLab does not require an account and has no first-party app backend.
  • PlungeLab contains no advertising, cross-app tracking, general app-usage analytics SDK, or third-party crash-reporting SDK.
  • If you use PlungeLab Pro, RevenueCat receives limited purchase, entitlement, and technical information. It does not receive your PlungeLab sessions, Apple Health data, notes, temperatures, heart-rate data, moods, or insights.
  • We may add privacy-conscious analytics, crash diagnostics, performance monitoring, feature delivery, or similar operational tools in a future version. Before they begin collecting data, we will update this Policy, identify the relevant data and purposes, update the App Store privacy disclosures, and provide any consent or control required by law.
  • You can control Apple Health permissions, notifications, exports, and local deletion from Apple settings and PlungeLab settings.

1. Scope

This Policy applies only to PlungeLab. Other Eggyolk products and services may have separate privacy notices.

Apple, RevenueCat, Cloudflare, Vercel, and any app or person you choose through an Apple share sheet handle information under their own terms and privacy notices. We describe their role in PlungeLab below.

2. Data processed only on your devices

PlungeLab processes the following data locally to provide the features you choose to use:

  • Session data: activity type, start and end times, duration, water temperature, capture source, notes, breathwork choice, perceived intensity, mood entries, and related timestamps.
  • Watch and sensor data: live and summary heart rate, post-exit heart-rate recovery, water-submersion events, and water temperature when supported by your Apple Watch. PlungeLab does not collect precise location or workout routes. Depth information is not used in the current version.
  • Apple Health data: depending on the permissions you grant, heart rate, heart-rate variability (SDNN), resting heart rate, respiratory rate, sleep analysis, Apple Watch wrist temperature, water temperature, workouts, and State of Mind entries.
  • Derived information: dose progress, streaks, daily summaries, correlations, insight reports, personal response maps, routine comparisons, and data-quality or confidence indicators.
  • Preferences and app state: unit and protocol choices, reminder settings, Watch capture settings, safety acknowledgment, entitlement cache, widget snapshots, and recovery drafts used to avoid losing a session.

This data may be stored in PlungeLab’s protected app and app-group containers on your iPhone and Apple Watch. PlungeLab may synchronize it between your paired devices through Apple’s WatchConnectivity framework and may display limited dose and streak summaries in widgets and complications. These operations do not send the data to an Eggyolk server.

With your permission, PlungeLab may read from or write to Apple Health. PlungeLab writes only the data associated with features you use, such as a workout, supported water-temperature samples, or a State of Mind entry when you enable that optional setting. Apple Health permissions are granular and can be changed at any time.

3. Limited data used for purchases, support, and website delivery

PlungeLab does not send the session, Apple Health, sensor, note, mood, temperature, heart-rate, or insight data described in Section 2 to Eggyolk, RevenueCat, Cloudflare, Vercel, or an Eggyolk server during ordinary app use. The limited non-health information below is processed only when needed for purchases, support, Apple diagnostics you have enabled, or delivery of the PlungeLab website.

Purchases and entitlements

Apple processes App Store purchases. We use RevenueCat, Inc. to validate purchases, restore purchases, and determine whether PlungeLab Pro features should be available.

RevenueCat may process:

  • an automatically generated anonymous App User ID;
  • device type, operating system, app version, and similar limited technical information;
  • last-seen time;
  • Apple receipt and transaction information;
  • product, trial, subscription, purchase, refund, and entitlement status.

PlungeLab does not provide RevenueCat with your name, email address, advertising identifier, PlungeLab session history, Apple Health data, notes, temperatures, heart-rate data, moods, or insights. We do not enable RevenueCat advertising integrations or use its data for cross-app tracking.

Support communications

If you contact support, we receive the information you choose to provide, such as your email address, message, attachments, and limited diagnostics you choose to share. The in-app support summary is designed to exclude health values, but you may voluntarily include sensitive information in a message, screenshot, or exported file. Please send only what is necessary for your request.

PlungeLab website pages

The PlungeLab website at plungelab.app uses Cloudflare for hosting and delivery. Legacy PlungeLab pages on eggyolk.io use Vercel. When you visit these pages, the relevant hosting provider may process ordinary web-request information such as IP address, browser and device information, requested page, timestamps, approximate location derived from IP address, and security or performance logs. PlungeLab does not use these pages for behavioral advertising or cross-site tracking. If analytics or nonessential cookies are added later, this Policy and any required consent controls will be updated before they are enabled.

For more information about Cloudflare’s handling of end-user request data, see Cloudflare’s Privacy Policy.

Apple diagnostics

Apple may process App Store, device, and diagnostic information under Apple’s privacy terms. If you have chosen to share analytics or diagnostics with app developers, Apple may make aggregated or opted-in diagnostic information available to us. PlungeLab does not embed a separate analytics or crash-reporting SDK.

Future development and operational tools

At the effective date of this Policy, PlungeLab does not use a third-party general app-usage analytics SDK, third-party crash-reporting SDK, remote feature-configuration service, advertising SDK, or marketing-attribution SDK. We may introduce limited tools in a future version to understand whether features work, diagnose failures, improve performance, deliver features safely, protect the service, or communicate with users. Depending on the tool and configuration, this could include:

  • Product analytics and experiments: app launches, screens or features used, button interactions, onboarding and purchase-funnel events, experiment or feature-flag assignments, event timestamps, app version, operating-system version, device class, language or region, and a random app-install or analytics identifier.
  • Crash and performance diagnostics: crash logs, stack traces, hangs, launch time, responsiveness, memory or energy use, network failures, app version, operating-system version, device model, and limited technical context needed to reproduce a problem.
  • Feature delivery and remote configuration: a random installation identifier, app version, device compatibility information, configuration requests, and the feature or experiment variant delivered.
  • Notifications and communications: an Apple push token, notification preferences, delivery status, and interaction events needed to deliver or evaluate notifications. We will not place Apple Health values or private session notes in a push payload.
  • Security and abuse prevention: IP address, request timestamps, device or app information, and events reasonably needed to detect fraud, secure purchases, protect infrastructure, or investigate misuse.
  • Website measurement: page views, referral information, device and browser information, approximate region derived from IP address, cookie or similar identifiers, and performance events if website analytics are enabled.

Any provider actually enabled will be identified in this Policy or an incorporated, publicly accessible provider list before collection begins. We will describe the data it receives, why it is used, whether it is linked to you, applicable retention or deletion controls, and material international transfers. Where required, we will request consent or provide an in-app or website control.

Development and operational tools will be configured to avoid sending Apple Health values, session history, heart-rate or temperature readings, moods, notes, insight results, CSV exports, or other health-related content. We will not use Apple Health data for advertising, marketing attribution, cross-app tracking, or sale. If a future feature would require health or session data to leave your devices—for example, optional cloud backup or server-generated analysis—we will explain that feature separately and obtain any permission required before transmission.

Where applicable law requires a legal basis, we rely on the following:

  • Provide PlungeLab at your request and perform our contract: local session processing, device synchronization, widgets, exports, purchase validation, entitlement delivery, and support.
  • Your explicit consent or permission: processing health-related data after you grant Apple Health permissions, optional State of Mind writes, notifications, and any sensitive information you deliberately send to support. You may withdraw a permission at any time.
  • Legitimate interests: protecting PlungeLab and its legal pages, preventing fraud, troubleshooting, responding to support requests, and improving reliability in ways that do not override your rights.
  • Legal obligations and legal claims: tax, accounting, consumer-protection, lawful requests, dispute resolution, and compliance with applicable law.

Withdrawing consent does not affect processing that was lawful before withdrawal. Some features cannot work without the data or permission they require, but the local session log remains usable without Apple Health access.

5. When data is disclosed

We disclose personal data only as described in this Policy:

  • Apple: for App Store distribution and billing, Apple Health features you authorize, Apple Watch connectivity, notifications, and system share sheets.
  • RevenueCat, Inc.: for purchase validation, subscription management, entitlement delivery, fraud prevention, and purchase analytics.
  • Cloudflare, Inc.: to deliver and secure the PlungeLab website at plungelab.app.
  • Vercel, Inc.: to deliver and secure legacy PlungeLab web pages on eggyolk.io.
  • Professional advisers and authorities: when reasonably necessary to obtain legal, accounting, or security advice; comply with law or a valid legal process; or protect users, Eggyolk, or others.
  • A successor organization: in a merger, financing, reorganization, or sale, subject to applicable law and protections consistent with this Policy.

We do not sell personal data. We do not share personal data for cross-context behavioral advertising. We do not use Apple Health data for advertising, marketing, eligibility decisions, or data brokerage, and we do not disclose Apple Health data to RevenueCat, Cloudflare, or Vercel.

When you export a CSV, create a share card, or use a system share sheet, the recipient you select receives the information you choose to share. Their handling of that information is outside our control.

6. International transfers

Eggyolk is established in Türkiye. RevenueCat, Cloudflare, and Vercel are based in the United States and may use infrastructure or subprocessors in other countries. Purchase, support, and web-request information may therefore be processed outside your country.

We permit international transfers only where allowed by applicable law and, where required, use contractual or other approved safeguards. Health data and PlungeLab session data processed locally by the app are not transferred to RevenueCat, Cloudflare, Vercel, or an Eggyolk server.

7. Retention and deletion

  • On-device PlungeLab data remains until you delete it, delete the app, or your operating system removes it. On iPhone, Delete iPhone data removes the iPhone’s local sessions, derived insight cache, settings, snapshots, recovery drafts, comparisons, notification decision, review history, and safety acknowledgment. Data stored separately by the Apple Watch app may remain until it is removed on the Watch or the Watch app and its data are deleted. Deleting one device’s copy does not necessarily delete a copy already synchronized to another device. If offered, you may also ask PlungeLab to delete workouts that PlungeLab wrote to Apple Health. Imported or third-party workouts are not deleted by PlungeLab. Deleting local data does not cancel an Apple subscription or delete RevenueCat’s purchase records.
  • Apple Health records and permissions are managed separately by Apple. Deleting PlungeLab does not necessarily delete records already written to Apple Health. You can review permissions and delete records in Apple’s Health and Settings apps.
  • Purchase and entitlement information is retained for as long as needed to provide or restore purchases, prevent fraud, satisfy tax or accounting requirements, resolve disputes, and comply with law. RevenueCat may retain some information under its own legal obligations and retention policy.
  • Support communications are retained while we handle your request and for a reasonable period afterward for follow-up, security, dispute resolution, and legal compliance, then deleted or anonymized when no longer needed.
  • Web security and request logs are retained according to the hosting and security configuration and only for as long as reasonably needed to deliver, protect, and troubleshoot the pages or comply with law.

Temporary CSV export files are created only when you request an export and are removed after the share flow when the system permits. Files you save or send are controlled by the destination you selected.

8. Your controls

  • Apple Health: On iPhone, open Settings > Privacy & Security > Health > PlungeLab, or use the Health app’s sharing controls.
  • Notifications: Change PlungeLab’s notification settings in the app or in system Settings.
  • Local data: On iPhone, use Settings > Your Data > Delete iPhone data. To remove app containers from both devices, remove PlungeLab and the PlungeLab Watch app from each device. Review Apple Health separately.
  • Apple Health workouts: Use PlungeLab’s optional deletion flow for eligible PlungeLab-authored workouts or delete records in Apple Health.
  • Subscriptions: Manage or cancel an auto-renewing subscription in your Apple Account subscription settings. Deleting the app does not cancel a subscription.
  • Exports and sharing: You choose whether to create an export or share card and which recipient receives it.

9. Your privacy rights

Depending on where you live, you may have rights to request access to, information about, correction of, deletion of, restriction of, or portability of personal data; object to certain processing; withdraw consent; and complain to a data-protection authority. You will not be discriminated against for exercising a privacy right.

PlungeLab does not make decisions that produce legal or similarly significant effects based solely on automated processing. Its insights describe correlations in your own data and are not medical decisions.

Because Eggyolk does not receive your on-device health and session data, the most direct way to exercise control over that data is through PlungeLab, Apple Health, and system Settings. We cannot access, export, correct, or delete data that never leaves your devices. For information held by RevenueCat, Cloudflare, Vercel, or in support records, contact us using the details below. Because there is no PlungeLab account and RevenueCat uses an anonymous identifier, we may need information from your device or Apple purchase record to locate a purchase record, and in some cases we may be unable to link an email address to an anonymous record.

Türkiye (KVKK)

Under Article 11 of Türkiye’s Law No. 6698 on the Protection of Personal Data (KVKK), you may ask whether your personal data is processed; request information about processing; learn its purpose and whether it is used accordingly; learn the domestic or foreign recipients; request correction, deletion, or destruction where the legal conditions are met; request notice of correction or deletion to recipients; object to an adverse result produced exclusively by automated analysis; and claim compensation for damage caused by unlawful processing.

Submit a request to the contact address below. KVKK requests will be handled as soon as possible and no later than 30 days, subject to identity verification and the procedures permitted by law. You may also lodge a complaint with the Turkish Personal Data Protection Authority.

EEA, United Kingdom, and other regions

Where the GDPR, UK GDPR, or similar law applies, you may also have the right to lodge a complaint with the supervisory authority where you live or work. California residents may have rights to know, delete, and correct covered information and to non-discrimination. PlungeLab does not sell or share personal information as those terms are defined by the California Consumer Privacy Act.

10. Security

PlungeLab minimizes data leaving your devices and relies on Apple platform protections for app containers, Apple Health, and device-to-device communication. We limit service providers to the information needed for their role and use reasonable administrative, contractual, and technical measures for information we receive. No storage or transmission method is completely secure, so we cannot guarantee absolute security. Protect your devices with a passcode and keep their operating systems current.

11. Children

PlungeLab is not directed to children under 13. We do not knowingly collect personal data from a child under 13 through PlungeLab. If you believe a child under 13 has sent us personal data, contact us so we can review and delete it where appropriate.

If you are between 13 and the age of legal majority where you live, a parent or legal guardian should review PlungeLab’s Terms with you and supervise any cold- or heat-exposure activity. This age statement is a safety and contractual rule; it does not mean that PlungeLab sends a minor’s health or session data off the device.

12. Changes to this Policy

We may update this Policy when PlungeLab, our providers, or applicable law changes. We will post the revised Policy on the PlungeLab privacy page and change the effective date. If a change materially affects how data is handled, we will provide additional notice where required.

We will not rely only on a general policy-change clause to begin materially different processing such as transmitting health or session data off-device, advertising or cross-app tracking, or selling personal data. Before such processing begins, we will provide a specific explanation and obtain consent where required by law or Apple platform rules.

13. Contact and data controller

  • Data controller: EGGYOLK YAZILIM TİCARET LİMİTED ŞİRKETİ
  • Address: Alacaatlı Mahallesi, 5088. Cadde, 67A/12, Çankaya, 06810 Ankara, Türkiye
  • Email: gungor@eggyolk.io
  • Telephone: +90 532 464 67 07

Use the subject line PlungeLab Privacy Request for privacy requests.

Back to top ↑