Pumply – Privacy Policy

Last updated: 18 August 2026

Pumply is operated by Maeve Sikorski, a UK sole trader trading as Hearth & Pine (“we”, “us” or “our”).
This Privacy Policy explains how we collect, use and share information when you use the Android or iOS version of Pumply (the “App”). Some processing applies only to the Android version, as indicated.

For privacy questions or requests, contact us at app@hearthandpine.co.uk.

1. Information we handle

Information stored on your device

The App lets you record pumping and milk-storage information, including pumping dates and times, duration, milk volume, notes, stash and storage details, reminders and preferences.

This information is primarily stored in the App on your device. We do not operate an account system or receive a copy of the contents of your pumping log or stash through our own servers.

Your device may include locally stored App information in a backup associated with your Google account on Android or your Apple/iCloud account on iOS. Backups are controlled by Google or Apple and your device settings. Information you export, such as a CSV backup, remains wherever you choose to save or share it.

Analytics and app activity

Android only: We use Firebase Analytics to understand how the Android App is used and improve it. It may collect app interactions, screen views, feature use, country and language, app and device information, and pseudonymous identifiers.

Some events associated with pumping and storage features may include a pumping-duration value, whether an entry contains a note, whether milk was added to the stash, storage type and a local record identifier. We do not intentionally send the text of notes, exact milk volume, or the date and time of an entry to Firebase Analytics.

The iOS App does not use Firebase Analytics or another in-app analytics service.

Diagnostics and performance

Android only: Firebase Crashlytics and Firebase Performance Monitoring may collect crash reports, error information, performance measurements, IP address, device model, operating-system and App versions, country, installation identifiers and information about the screen or feature being used when a problem occurs.

The iOS App does not include Firebase Crashlytics, Firebase Performance Monitoring or another third-party diagnostics SDK. Apple may independently process App Store and device diagnostic information under its own privacy terms and the choices you make in your Apple device settings.

Purchases

Android only: If you make or restore an in-app purchase, Google Play and Qonversion process information such as product purchased, purchase status, transaction and device identifiers, subscription or entitlement status, and related events. We do not receive or store your full payment-card details.

The iOS App does not offer or process in-app purchases.

Advertising and consent choices

Android only: The free version of the Android App displays advertisements using Google AdMob. Google and participating ad-technology providers may process information such as your IP address, approximate location, advertising or device identifiers, App and advertisement interactions, diagnostic information and privacy choices. Depending on your choices and applicable law, this information may be used to provide, personalise and measure advertisements, prevent fraud and maintain security.

Where required, the App presents a privacy message that lets you review the purposes and providers involved and make or withdraw your choices. The applicable providers are identified within that message under the vendor or ad-partner preferences. You can also review Google’s information about ad-technology providers and how Google uses information from apps that use its services.

The iOS App does not display third-party advertising and does not use Google AdMob or another advertising SDK.

Files, notifications and support

If you import or export information, the App accesses only the files you select or create for that purpose. Reminder information and notification preferences are stored on your device. If you contact us, we receive the information contained in your message and your contact details.

2. How and why we use information

We use information to:

  • provide the App and its features;
  • store and restore preferences and, on Android, purchases;
  • provide advertising in the free Android version of the App;
  • understand Android App use and improve its features;
  • diagnose Android crashes, errors and performance problems;
  • prevent fraud and maintain security; and
  • respond to support and privacy requests and comply with legal obligations.

Under UK data-protection law, we rely on:

  • performance of our contract with you, or steps taken at your request, to provide App features and purchases;
  • our legitimate interests in operating, securing, troubleshooting and improving the App, provided those interests are not overridden by your rights;
  • your consent for personalised advertising, device storage or access, and other processing where consent is required; and
  • compliance with legal obligations, including tax, accounting and lawful requests.

You may withdraw advertising consent or review your choices through the privacy-options control in the App where available. Withdrawing consent does not affect processing that occurred before withdrawal.

3. When information is shared

We do not sell your personal information.

For the Android App, information may be processed by the following services for the purposes described above:

  • Google Firebase Analytics, Crashlytics, Performance Monitoring and Remote Config;
  • Google AdMob, Google User Messaging Platform and the ad-technology providers shown in the App’s consent interface;
  • Qonversion;
  • Google Play Billing and Google Payments; and
  • service providers that help us respond to support, comply with the law or protect our rights.

The iOS App does not use the Firebase, AdMob, Qonversion or payment services listed above. Apple processes information necessary to distribute the iOS App and may process device or App Store information under Apple’s Privacy Policy.

We may also disclose information when required by law, to investigate fraud or security incidents, to protect legal rights or safety, or as part of a sale or transfer of the business. If the business is transferred, information will remain subject to this Policy or notice of any material change will be provided.

4. How long information is kept

We keep personal information only for as long as reasonably necessary for the purposes described in this Policy or as required by law.

  • Local App information on Android or iOS remains on your device until you reset the App where that option is available, clear its storage or uninstall it. Device backups and exported files may remain until you delete them separately.
  • For Android, Firebase Analytics user-level and event-level data is retained for up to 2 months. Its retention period is not reset when a user becomes active again. Standard aggregated reports may remain available for longer because the Analytics retention control does not apply to those reports.
  • For Android, Firebase Crashlytics generally retains crash reports and associated identifiers for 90 days before deletion begins.
  • For Android, Firebase Performance Monitoring generally retains IP-associated events for 30 days and installation-associated or de-identified performance information for 60 days before deletion begins.
  • For Android, AdMob User Activity reporting data is available for up to 90 days. Ads Activity, Cohort, and Privacy & Messaging reporting data may be available for up to 2,555 days. Google and participating advertising providers may retain underlying information for different periods under their own policies, including for security, fraud prevention, billing and legal compliance.
  • For Android, Qonversion retains subscriber and purchase-event information for as long as necessary to provide its subscription-management services or comply with legal obligations.
  • We normally retain support correspondence and privacy requests for up to 24 months after the matter is resolved, unless it is reasonably necessary to keep it longer for legal, security or dispute-resolution purposes.
  • Purchase, tax and accounting records may be kept for the period required by applicable law.

5. International processing

Some providers process information outside the United Kingdom. Where UK data-protection law applies, we use providers that rely on recognised adequacy regulations or appropriate safeguards, such as approved contractual protections. You may contact us for further information about the safeguards relevant to your information.

6. Your choices and rights

You can:

  • reset locally stored App information or uninstall the App;
  • control notification and backup settings through your device;
  • decide whether to import or export files or make a purchase; and
  • on Android, review or withdraw applicable advertising choices using the privacy-options control in the App.

Depending on the circumstances, UK data-protection law may give you rights to request access to, correction of, deletion of, restriction of, or transfer of your personal information, and to object to certain processing. You can also withdraw consent where processing is based on consent.

Because the App has no account system, we normally cannot identify you from pseudonymous information held by Android service providers. To locate a particular record, we may need an applicable identifier generated for your installation, such as a Firebase App Instance ID or Qonversion User ID. If neither you nor we can obtain an identifier that reliably relates the information to you, we may be unable to locate, verify or delete an individual record. We will explain this if it applies to your request. Information that cannot be linked to an individual request remains subject to the retention periods described above.

To exercise a right, email app@hearthandpine.co.uk. You also have the right to complain to the UK Information Commissioner’s Office.

7. Data deletion

Use the App’s reset option, clear the App’s storage or uninstall it to remove locally stored information. You must separately delete exported files and manage any device backups.

You may contact app@hearthandpine.co.uk to ask us to assess whether information held through our service providers can be located and deleted. Because the App does not use accounts and we do not know which pseudonymous identifiers belong to you, we may be unable to identify an individual record unless an applicable installation or provider identifier is available. Some information also cannot be removed from previously aggregated reports, and information may be retained where necessary for legal obligations, security, fraud prevention, accounting or the establishment, exercise or defence of legal claims.

8. Children’s privacy

The App is intended for adults and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information through the App or directly to us, contact app@hearthandpine.co.uk.

9. Security

We use reasonable technical and organisational measures designed to protect information. Information transmitted to the service providers described above is encrypted in transit. No method of electronic storage or transmission is completely secure.

10. Changes to this Policy

We may update this Policy when the App, our providers or legal requirements change. We will update the date at the top and provide additional notice where appropriate. If a change requires consent, we will ask for it.

11. Contact us

Maeve Sikorski, trading as Hearth & Pine
United Kingdom
app@hearthandpine.co.uk