Wonderwake — Privacy Policy

Wonderwake — Privacy Policy

Effective date: August 5 2025

Last revised: August 5 2025

Wonderwake Inc. (“Wonderwake,” “we,” “us” or “our”) respects your privacy and is committed to protecting it. This Privacy Policy explains what data we collect, why we collect it, where it is processed, and the choices you have. Except where we rely on external analytics (see § 6), nearly all personal data stays on your device and never leaves your control.

If you have any questions, email dev@somnify.org.


1. Key Principles

  • Data minimisation – We request or store only the information needed for the feature you choose to use.
  • Local processing first – Health, motion, and location data remain on-device and are encrypted by your operating system.
  • No selling or profiling – We don’t sell, rent, or share your data for advertising or marketing.
  • Transparency – You can review or revoke permissions at any time in your system settings.
  • Security by design – We use strong encryption in transit and at rest, follow industry-standard security practices, and limit access to authorised personnel with a strict need-to-know.

2. Definitions

Services. The Wonderwake mobile app, our websites, and any related software, content, or features that we operate.

Personal Data. Information that directly identifies you or could reasonably be used to identify you (for example, sleep metrics pulled from Apple Health).

Anonymous Data. Information that has been irreversibly de-identified so it can no longer be linked to you.

Service Providers. Contracted third-party companies that help us host, maintain, or analyse the Services. They must follow our security requirements, act only on our instructions, and are forbidden to use your data for their own purposes.

User (or “you”). Any individual with full legal capacity who accesses or uses the Services.


3. What We Collect & Why

Apple Health data (optional). With your permission, we read sleep duration and timing, heart-rate trends, step counts, and basic demographics such as age and sex. These details stay on your device and let us calculate sleep debt, track consistency, and suggest personalised bedtimes. If you decline, the app still works but offers fewer tailored insights.

Device-motion data (optional). When enabled, the phone’s accelerometer and gyroscope help us detect when you fall asleep and wake up, refining the accuracy of our analysis. Motion data is processed and stored locally.

Location and weather data (optional). If you switch on weather-based advice, the app briefly uses your coarse location to pull real-time temperature, humidity, and daylight information. We do not store your coordinates.

Device information (automatic). We automatically collect your phone model and operating-system version to diagnose crashes and ensure compatibility across devices.

Usage analytics (automatic, pseudonymised). Aggregated statistics—such as how often features are used, which buttons you tap, and crash logs—are sent to Google Firebase. We rely on these metrics solely to improve performance and plan new features. Firebase never receives Health, motion, or location data.



4. How We Collect

  • Consent-based permissions – HealthKit, motion, and location are collected only after you grant permission in system dialogs.
  • Automatic telemetry – Device model/OS and crash logs are captured automatically when you use the app.

5. How We Store & Protect

  • On-device data – Apple Health, motion, and location data never leave your phone. They are encrypted by your operating system and readable only by Wonderwake.
  • Server-side data – Crash logs and pseudonymised usage analytics are stored on Google Cloud servers in the United States and EU. Google is certified under ISO 27001, SOC 2, and complies with GDPR and CCPA contractual safeguards.
  • Security measures – TLS 1.2+ for data-in-transit; encryption-at-rest; regular penetration testing; least-privilege access controls; routine security audits.

6. Third-Party Analytics (Google Firebase)

We use Google Firebase solely for aggregated, pseudonymised metrics—for example, crash traces, feature popularity, and session length. Firebase never receives:

  • Apple Health or motion data
  • Location coordinates
  • Names, emails, or other directly identifying details

Firebase’s processing is limited to Wonderwake’s internal product-improvement needs. We do not enable cross-app tracking, remarketing, or ad identifiers. Firebase complies with GDPR, CCPA, and allows HIPAA-compatible configurations (which we use).


7. Your Rights & Choices

7.1 Universal Controls

  • Revoke permissions – Use your device’s privacy settings to disable Health, motion, or location access at any time.
  • Delete the app – Removing Wonderwake deletes all on-device data. Server logs (crash/usage) are retained only as long as necessary for security or legal obligations, then permanently erased.

7.2 Region-Specific Rights

European Economic Area and United Kingdom (GDPR). If you live in the EEA or UK, you may request to access the personal data we hold about you, correct inaccurate information, erase your data, restrict or object to our processing, or obtain a machine-readable copy for transfer to another service. Simply email dev@somnify.org to exercise any of these rights.

California Residents (CCPA). Californians can ask us to disclose the categories of personal data we collect and how we use it, request deletion of their data, and opt out of any “sale” of personal data (Wonderwake does not sell data in the first place). Send your request to dev@somnify.org. Exercising these rights will not result in discriminatory treatment.



8. When We Share Data

We disclose data only:

  1. Service Providers under written contract who must process data solely for us, follow our security standards, and keep it confidential.
  2. Legal or safety reasons – to comply with lawful subpoenas or protect the rights, safety, or property of Wonderwake, our users, or others.
  3. Corporate events – if Wonderwake is sold, merged, or restructured, data will transfer subject to this Policy (or one that offers equal or stronger protections).

We never sell Personal Data or share it for behavioural ads.


9. Data Retention

  • On-device data persists until you delete it or uninstall the app.
  • Crash/usage logs are typically retained no longer than 24 months, unless required for security, fraud-prevention, or legal obligations.

10. Children

The Services are not directed to children under 16. If we learn that we have collected Personal Data from a child under 16, we will delete it promptly.


11. International Transfers

If you reside outside the United States, your pseudonymised usage data may be processed in the U.S. or other countries with adequate safeguards (e.g., Standard Contractual Clauses). By using the Services, you consent to such transfers.


12. Changes to This Policy

We may update this Policy to reflect new features or legal requirements. We will give at least 30 days’ notice of material changes via in-app alert or email. Continued use after the effective date means you accept the new Policy.


13. Contact Us

Questions, concerns, or requests?

Email: dev@somnify.org

We aim to respond within 30 days.


Thank you for trusting Wonderwake with your sleep journey — and your privacy.



Report Page