Data controller
Wellmum SAS, registered in France, is responsible for processing your personal data. Our head office is located in Paris, France.
Last updated : May 2026
Wellmum is committed to protecting your personal data. This policy explains what information we collect, why, and how we protect it.
Wellmum SAS, registered in France, is responsible for processing your personal data. Our head office is located in Paris, France.
We collect the following categories of personal data:
Your data is used for the following purposes:
We process your data on the basis of your explicit consent (given at sign-up), the performance of our contract with you (provision of the Wellmum service), and our legitimate interest in improving the application.
Health data is processed under Article 9(2)(a) of the GDPR with your explicit consent. You may withdraw this consent at any time.
We never sell your personal data. We may share it with:
On compatible Android devices, you can choose to connect Wellmum to Health Connect. This integration is entirely optional and requires your explicit authorization, data type by data type, through Health Connect. Here is exactly what data Wellmum accesses and why:
Retention: data from Health Connect is encrypted and kept for as long as your Wellmum account is active, under the same rules as your other data (see Retention period). Deletion: you can revoke access at any time, data type by data type, from Health Connect in your Android device settings; you can also delete all of your data by deleting your Wellmum account from the app — it is then anonymized after a 30-day grace period (see Your rights).
On iPhone, you can choose to connect Wellmum to Apple Health (HealthKit) so Wellmum can read some of your wellness measurements and save your workouts there. This integration is optional and requires your explicit authorization, per data category, through Apple Health:
Your personal data is kept for as long as your account is active. When you request account deletion, your data is anonymized after a 30-day grace period.
Anonymized usage statistics may be retained indefinitely for service improvement purposes.
We implement security measures in line with industry standards to protect your data:
Your data is hosted on Amazon Web Services (AWS) cloud infrastructure, in data centres located in France (Paris region). It never leaves the European Union.
We chose infrastructure eligible for health-data hosting (HDS) and GDPR-compliant, to protect the sensitive information you entrust to us. Like any cloud host, AWS may be subject to legal data-access obligations; encrypting your data provides an additional technical safeguard.
Under the GDPR, you have the following rights regarding your personal data:
For any question regarding this privacy policy or to exercise your rights, contact us at: