Pellica keeps your shooting log in your own account. Everything you log is saved on your phone first, then backed up to our servers in the EU so you can pick it up on another phone. We don't sell your data, don't share it for advertising, and don't run analytics on what you photograph. The app does measure how it is used and reports crashes, so we can see what to fix. This page lists every piece of data and every service involved.
Who we are.
Pellica is an independent app built and published from France. The developer is the data controller for everything described here.
Email: contact@pellica.app
What we collect.
We try to collect as little as possible. Here is the exhaustive list:
- Your account: your email, or your Apple or Google sign-in, to sign you in, sync your log and manage a subscription. Never used for marketing unless you explicitly opt in.
- Your log: rolls, frames, notes, gear, projects, lab visits, the location and weather stamped on each frame, and the home area you set for the lab map. Stored in your account and synced between your phones.
- Usage analytics: which screens you open and which features you use, with your device model and app version, so we can see what helps and what gets in the way. Not your notes, not your photos.
- Crash reports: when Pellica crashes, a stack trace with your device model and OS version.
- Push token (if you allow notifications): so we can send the reminders you turn on.
- Payment records (Pro subscribers): handled by Apple (iOS) or Google (Android) and managed through our subscription provider. We see the transaction, never your card.
On your phone.
Everything you log is saved on your phone first, in encrypted storage, so Pellica works with no signal: in the field, on a plane, in the darkroom. It syncs with your account when you are back online. Voice notes are transcribed by your phone's own speech recognition (Apple's on iPhone, Google's on Android), which may process the audio on their servers; Pellica keeps only the text.
Your account and sync.
When you are signed in, Pellica backs up your log to our servers in the European Union and syncs it between your phones. Sync is included with every account, free or Pro. Your data travels encrypted, and no other account can read yours. The Pellica team can access it to run the service and to help you when you ask. It is not end-to-end encrypted.
Third-party services.
We rely on a small number of providers, each receiving only what its job needs:
- Hosting and sync: our database provider, with servers in the EU, stores your account and your synced log.
- Apple and Google: app distribution, payments, sign-in, and the speech recognition that transcribes voice notes.
- Subscription management: purchase and subscription status for Pro.
- Usage analytics and notifications: which features are used, and delivering the reminders you turn on.
- Crash reporting: the crash reports described above.
- Weather and maps: a frame's coordinates to fetch its weather, and the map area you are looking at to draw the map and name places. Never your identity.
- Email delivery: the emails we send you.
There is no advertising SDK in the app, no ads, and nothing is sold or shared for advertising. For the name of a specific provider, email contact@pellica.app.
On this website.
The marketing site you are reading right now is a separate surface with its own, narrower set of tools. Nothing that stores data in your browser runs until you click Accept in the cookie banner.
- Without your consent: our analytics tool (PostHog, hosted in the EU) still counts visits: pages viewed, scroll depth, clicks on our buttons, your approximate country and city. It does so without cookies and without storing anything in your browser. To count unique visitors, PostHog derives an anonymous identifier from your connection on its own servers, and that identifier changes every day. Your IP address is not stored, and nothing is recorded.
- With your consent, an analytics cookie: the same tool sets a first-party cookie, so we can tell a returning visitor from a new one and, on Android, link your visit to the app install it led to.
- With your consent, session recordings: about one visit in ten is recorded (pages, scrolling, clicks) so we can see where the site gets in the way. Recordings are kept 30 days.
- With your consent, Google Ads (AW-18064228375): measures which of our ad campaigns brought you here. Ad personalization stays off.
- With your consent, the Meta Pixel: measures which of our Instagram and Facebook ads brought you here.
Your choice is kept for six months, then the banner asks again. You can change it at any time with "Cookie settings" in the site footer. Nothing on the website is used for re-targeting you elsewhere on the web.
Your rights under GDPR & CCPA.
You have the right to access, export, correct, and delete any data we hold about you. In the app: Settings → Account → Export data / Delete account. Or email contact@pellica.app. We respond within 30 days (usually within 48 hours).
How long we keep things.
- Account data: for as long as your account exists. Delete the account, we delete it all within 30 days.
- Crash reports: 90 days, then automatically purged.
- Payment records: 10 years, because French tax law requires it. Sorry.
Minors.
Pellica is not intended for children under 13. We don't knowingly collect data from anyone under 13. If you believe a child has created an account, email us and we'll delete it.
Changes to this policy.
If we ever change this policy in a way that expands what we collect, we will email you, post a notice in the app, and give at least 30 days to review before it takes effect. Cosmetic and clarifying changes get a changelog entry at the bottom of this page.
How to reach us.
Email contact@pellica.app. We answer personally, usually within a day.
Changelog.
- 9 October 2026 (version 5): the website now does what the "On this website" section said. Until this date the analytics cookie was set and the Google Ads tag loaded on every visit, whatever you chose in the cookie banner, and about one visit in ten was recorded; only the Meta Pixel waited for your consent. Now nothing is stored in your browser and nothing is recorded before you accept, and without consent visits are only counted anonymously, without cookies. Your choice is kept six months, and "Cookie settings" in the footer changes it.
- 28 September 2026 (version 4): corrected how this page described storage and sync: your log is saved on your phone first and backed up to your account on servers in the EU, encrypted in transit but not end-to-end encrypted as the previous version said. Also described the usage analytics and crash reporting the app uses, which the previous version described as absent or opt-in.