1. The short version
Wakify is an alarm app that gets you out of bed. To do that it holds some personal information about you. Here is the honest summary, and the rest of this policy is the detail behind it.
- Your night stays on your phone. When you track a night of sleep, Wakify listens with the microphone and analyses the sound on your device. Raw audio, and the short night clips you can play back, are never uploaded to us or to anyone else. Only the summary (how long each sleep stage lasted, your sleep score) is saved to your account.
- Your camera never leaves your phone either. Camera missions such as Object Hunt, Sky Photo, Mirror Selfie and the exercise missions are processed live on your device. No image or video frame is stored or transmitted.
- We do not sell your data, we do not run ads, and we do not track you across other apps or websites. Wakify does not use the App Tracking Transparency framework because there is nothing to track you with.
- Product analytics are off unless you turn them on. We ask you once, the answer starts at "no", and you can change it any time in Settings. If you say yes, the events are linked to your account rather than anonymous, and section 5.8 lists exactly what they contain. Separately, a small set of reliability events records whether your alarm actually rang; that is not behavioural profiling and section 5.8 explains it.
- You can delete everything from inside the app. Settings contains a Delete Account button. It signs you out at once and erases your account 30 days later, and signing in again inside those 30 days cancels it.
- The leaderboard is real. If you set a username, other users see your name, your photo and your streak. Nothing about your sleep is ever shown to anyone, and one switch takes you off the board.
- Your account data is stored in the European Union (Frankfurt, Germany).
2. Who we are
Wakify is developed and operated by:
Cazari B.V.
Klaaskampen 40
1251 KP Laren, the Netherlands
Chamber of Commerce (KvK) number: 98486748
Email: hello@cazaristudio.com
In this policy we call ourselves "we", "us" or "Wakify", and we call you "you". For the purposes of the EU General Data Protection Regulation (GDPR) we are the controller of the personal data described here, which means we decide why and how it is processed.
We have assessed whether we must appoint a Data Protection Officer. At our current scale, and because the most sensitive processing happens on your device as described in section 4, we are not required to appoint one. We will revisit this as Wakify grows. All privacy questions go to hello@cazaristudio.com and are handled by us directly.
3. What this policy covers
This policy covers the Wakify iOS app, the backend services that support it, and the pages we publish at wakify.co (section 17). It does not cover:
- Apple. Your App Store purchases, your Apple Account, Apple Health and the iOS alarm system are governed by Apple's own privacy policy. Apple is the seller of every Wakify subscription and we never see your payment details.
- Google. If you choose Sign in with Google, Google's privacy policy applies to that sign-in.
- Other apps and devices. If your Apple Watch, Whoop, Oura or another wearable writes sleep data into Apple Health, the maker of that device decides what it collects. Wakify only reads what Apple Health makes available to it, and only if you allow it.
4. The principle behind the app: on-device by default
Wakify is built so that the most intimate data it touches never reaches a server. This is an architectural choice, not just a promise:
| What the app senses | Where it is processed | What leaves your device |
|---|---|---|
| Microphone during a tracked night | On your device (live sound analysis) | No sound. The night's stage timeline, its score, and for each sound we detect its type, its time and how sure we are |
| Short night audio clips (snoring, talking) | Stored in the app's private storage on your device | Nothing |
| Camera during a mission | On your device (Apple Vision framework) | Nothing. No frame is saved |
| Your voice during the Shout mission | On your device (on-device speech recognition) | Nothing |
| Motion during a mission, and while you track a night | On your device | Nothing. Only whether the mission was completed |
| An NFC tag or dock you scan | On your device | Nothing. Only whether the mission was completed |
| Apple Health sleep and heart data | On your device | Nothing raw. Only the resulting sleep summary |
| Your calendar and reminders on the morning screen | On your device | Nothing |
| Your profile photo | Cropped on your device, then stored on your account | A small copy, which other users see on the leaderboard (section 5.11) |
| Lifestyle tags you add to a night (for example caffeine, alcohol, stress) | On your device | The tags, saved with that night so they survive a reinstall |
5. What we collect, why, and on what legal basis
Everything below is stored in your personal account so that it survives a reinstall, a new phone or a re-login. Every table is protected by row-level security, which means the database itself refuses to return one user's rows to another user.
5.1 Account data
| Data | Why |
|---|---|
| Email address | To create your account, sign you in and contact you about the service |
| Password (stored only as a cryptographic hash) or your Apple / Google sign-in identifier | To authenticate you |
| A random account identifier (UUID) | To link your data to you without using your email everywhere |
| Account creation and last sign-in timestamps | Security, abuse prevention and support |
Legal basis: performance of our contract with you (GDPR Article 6(1)(b)).
If you use Sign in with Apple you may choose Apple's private relay address. Wakify works perfectly with a relay address, and we never attempt to unmask it.
5.2 Profile and onboarding answers
During onboarding we ask a small set of questions so the app can be set up for you.
| Data | Why |
|---|---|
| Your name, as a first and last name | To address you in the app, and to show you on the leaderboard if you appear on it (section 5.11) |
| A username you choose | It is unique, so we check it against other usernames. It is what makes you eligible for the leaderboard. Other users never see it |
| Sex (female / male / other or prefer not to say) | Optional context for sleep norms |
| Year of birth | For age-appropriate sleep norms and guidance |
| Usual bedtime and wake time | To pre-fill your first alarm and to judge your sleep rhythm |
| How often you snooze, and whether you used an alarm app before | To understand who Wakify is for and how to improve the product. We do not use these answers to configure your alarms |
| What you struggle with (for example "I struggle to fall asleep") | To personalise the app |
| Your goals (for example "Sleep better") | To personalise the app |
| Where you heard about Wakify | To understand how people find us |
| Whether you opted in to marketing email | To send you product email if, and only if, you asked for it |
Legal basis: performance of our contract (Article 6(1)(b)) for the settings that drive the app. For the answers that say something about your sleep health, we rely on your explicit consent (Articles 6(1)(a) and 9(2)(a)). You give it by answering those questions and confirming on the account screen, where this policy is linked, and you withdraw it by deleting your account. For marketing email we rely on your consent (Article 6(1)(a)), which you can withdraw at any time; every marketing email we send contains an unsubscribe link, and using it stops marketing email immediately without changing anything else about your account. For the question about where you heard about Wakify we rely on our legitimate interest in understanding how people find the app (Article 6(1)(f)), and you can object to it at any time.
Most of these questions have to be answered to finish setting up the app. Where a neutral answer exists you can pick it, for example "Other or prefer not to say" for sex, and deleting your account removes everything you answered.
5.3 Alarms and app settings
| Data | Why |
|---|---|
| Your alarms: label, time, repeat days, chosen sound, chosen mission and its settings, any extra missions chained after it, whether snooze is allowed, whether the wake-up check is on, whether app blocking is on, whether Hardcore mode is on, and whether the alarm is on | So your alarms survive a reinstall and restore on a new phone |
| Your preferences: bedtime reminder and its time, Apple Health sync on/off, wearable sleep stages on/off, alarm vibration, interface sounds, night clip recording, analytics consent | So your setup survives a reinstall, and so we can honour your privacy choices across devices |
Legal basis: performance of our contract (Article 6(1)(b)).
Note that the name of a custom alarm sound is stored, but the sound file itself stays on your device.
5.4 Sleep and wake-up data
| Data | Why |
|---|---|
| Sleep session: start time, end time, sleep score, the stage timeline, the tags you added, where the stages came from (this phone, an Apple Watch, or an import), and for each detected sound its type, when it happened and how confident we are | To show you your sleep history and trends across devices |
| Wake-up log: when the alarm went off, which alarm, which mission, how long you took to complete it, whether you snoozed, and whether you used the emergency dismiss | To calculate your streak, your badges and your wake-up statistics |
| Missed alarm: which alarm rang, when it rang, when we noticed it was never completed, which mission it used, and how many times it was silenced | So we can measure how often the alarm fails to get someone up, which is the one number this product lives on |
| Streak: current streak, longest streak, freezes left, total wake-up days, last active day | To keep your streak when you reinstall |
The number of sound events is stored, never the sound. The stage breakdown is a duration per stage, never a recording.
Legal basis: your explicit consent (Articles 6(1)(a) and 9(2)(a)), because sleep sessions are data concerning your health. We ask for that consent on a separate consent screen the first time you start sleep tracking or import sleep from Apple Health. You can withdraw it at any time: turning tracking off stops new collection, and deleting the stored nights or your account removes what was collected. The wake-up log and your streak are not health data; for those we rely on performance of our contract (Article 6(1)(b)).
5.5 Health data from Apple Health
If you allow it, Wakify reads the following types from Apple Health:
- Sleep analysis (in bed, asleep, and the sleep stages your wearable recorded)
- Heart rate and heart rate variability during the night, used only to estimate sleep stages for wearables that do not write stages themselves
If you allow it, Wakify writes back:
- Sleep analysis for the nights that Wakify itself tracked, so all your sleep lives in one place
Heart data is read into memory, used on your device to estimate your sleep stages, and then discarded. We never send heart rate, heart rate variability or raw Apple Health samples to our servers. Only the resulting sleep summary described in 5.4 is synced.
Legal basis: your explicit consent (Articles 6(1)(a) and 9(2)(a)), given twice over: once in Apple's own Health permission sheet and once through the Health toggles in Wakify's Settings. You can withdraw it in either place at any time.
In line with Apple's rules, health and fitness data is never used for advertising, marketing or use-based data mining, and we never store it in iCloud. We never disclose it to any third party for that party's own purposes. The only copy that leaves your device is the sleep summary described in 5.4, which our EU hosting provider stores for us under the safeguards in section 7.
5.6 Badges and referrals
| Data | Why |
|---|---|
| Badges you earned and when | To restore your achievements |
| Your referral code, how many people used it, which code you redeemed, how many reward days you earned | To run the referral programme and to detect abuse |
Legal basis: performance of our contract (Article 6(1)(b)) and our legitimate interest in preventing fraud in the referral programme (Article 6(1)(f)).
5.7 Subscription and purchase data
Wakify+ is sold by Apple, not by us. Apple processes the payment and we never receive your card details, billing address or full payment record.
To know whether your subscription is active we use RevenueCat, which receives your random Wakify account identifier and the purchase receipt from Apple, and returns whether you have an active entitlement. We store on your profile:
- subscription status, plan, store, start date, expiry date, whether it will renew, and the timestamp of the last subscription event.
We also keep an append-only log of the subscription events our provider sends us: the event type, store, product, environment, trial or normal period, purchase and expiry times, and the event as it was sent, which can include the price, the currency and the country of the store account. Only our server can read it. We use it to support you, to reconstruct billing disputes and for our accounting records.
Legal basis: performance of our contract (Article 6(1)(b)). Apple, as the seller, holds the financial record of your purchase. The records we keep for tax and accounting law are Apple's aggregated payout reports, which do not identify you. If such a record ever contains personal data, we keep only what the law requires, for as long as it requires (Article 6(1)(c)).
5.8 Product analytics and reliability events
The app records two separate kinds of event, on two different legal bases. Nothing here is sold, shared with advertisers, or used to track you across other apps.
Tier 1, reliability. A short list of events that record whether the alarm service did its job: alarm_fired, ring_presented, alarm_ring_missed, alarm_schedule_failed, emergency_dismiss, mission_asset_missing, mission_fallback_used, sync_push_failed. These exist because an alarm app that silently fails to ring is worthless, and we cannot find such failures without knowing they happened. They carry no behavioural profile, only what happened and when.
Legal basis: our legitimate interest in delivering and debugging the service you signed up for (Article 6(1)(f)), balanced against your privacy: the set is deliberately tiny, describes the app's own behaviour rather than yours, and is kept only as long as section 9 allows. You can object to it under section 11.
Tier 2, product analytics, only with your consent. Everything else:
app_opened, onboarding_started, onboarding_step_viewed, onboarding_completed, onboarding_skipped, signup_completed, paywall_shown, paywall_dismissed, purchase_started, purchase_completed, purchase_cancelled, purchase_restored, mission_completed, mission_attempt_failed, mission_abandoned, mission_previewed, mission_gate_hit, sound_gate_hit, snooze_pressed, alarm_created, alarm_updated, alarm_deleted, alarm_toggled, sleep_tracking_started, sleep_tracking_ended, sleep_sound_played, sleep_tags_added, bedtime_reminder_scheduled, weekly_recap_viewed, feature_toggled, leaderboard_viewed, referral_shared, referral_redeemed, nfc_tag_paired, nfc_scan_succeeded, nfc_scan_failed, blocking_enabled, blocking_disabled.
Each event carries at most a few short properties, for example which mission type was used, how many seconds a mission took, which subscription plan was shown, or a sleep score, plus the app version, build and platform so we can tell a bug in one release from a bug in another. When we add or change an event we update this list first, and section 15 applies.
These events are linked to your account. They are not anonymous: each one is stored with your user id, which is what lets us delete them when you delete your account.
Before you have an account. The onboarding funnel happens before you sign up, so those events are recorded against a random identifier for your installation, not against you. If you then create an account within the same session, that identifier is attached to it so your own funnel becomes part of your history. If you never create an account, the identifier is never connected to a person.
This list is the full catalogue we maintain. The App emits a subset of it today, and we keep the catalogue complete so that switching an event on is never a surprise.
Legal basis: your consent (Article 6(1)(a)). The switch starts off, we ask you once, and Settings lets you withdraw as easily as you agreed. Withdrawing stops new events immediately. We keep a record of when you agreed or withdrew, and to which version of this policy, because Article 7(1) requires us to be able to demonstrate it. Analytics are never a condition for any feature or for your subscription.
5.9 Technical and device data
Written once each time you open the app:
| Data | Why |
|---|---|
| Time zone | To schedule your alarms in the right local time |
| Language and region setting | To show the app in the right format |
| App version and build | To diagnose bugs and to know which version a problem belongs to |
| Platform (always "ios") | Same |
| Last active timestamp | Support, and to detect abandoned accounts |
Legal basis: performance of our contract (Article 6(1)(b)) for your time zone, language and region, which the app needs to ring your alarms at the right local time and display itself correctly. Our legitimate interest in operating, securing and debugging the service (Article 6(1)(f)) for the app version, build, platform and last active timestamp, balanced against your privacy. This set is deliberately minimal: your Wakify profile holds no device identifier, no advertising identifier and no IP-based profiling. A bug report you choose to send carries your iPhone model and iOS version, as section 5.12 describes. Our subscription provider does use an identifier that is specific to Wakify, as described in section 7.
Our hosting provider records standard server logs, including IP addresses, for security and abuse prevention, and deletes them on a short rolling schedule.
5.10 If you email us
If you contact support we keep your message, your email address and our reply so we can help you and so we can prove what was agreed.
Legal basis: our legitimate interest in handling your request (Article 6(1)(f)).
5.11 Your public profile and the leaderboard
The App has a leaderboard that ranks users by their current streak. It is real. When you are on it, other Wakify users can see:
| What they see | Where it comes from |
|---|---|
| Your name | The first and last name on your profile. If you signed in with Apple or Google, that is the name they gave us, unless you changed it |
| Your profile photo | The small copy stored on your account. If you set none, other users see your initials |
| Your current streak, in days | Counted from your own wake-ups |
| Whether you have Wakify+ | Shown as a small badge next to your name |
They see nothing else. No email address, no username, no account identifier, no sleep data, no sleep score, no wake times, no alarms, no badges, no location and no age. The database itself refuses everything else and never returns more than a hundred rows.
When you appear. You appear once all of these are true: you have set a username, you have a name on your profile, your current streak is above zero, and you have woken up recently enough for that streak to still count. If you stop using the App your streak stops counting and you drop off the board. If you never set a username you never appear, although you can still look at the board.
Private profile. Settings has a Private profile switch. Turning it on writes a flag to your account, and the server leaves you out of every board it builds for anyone else. It takes effect the next time anybody loads the board. The switch starts off, which means an account that has set a username is visible by default. Scheduling your account for deletion also takes you off the board straight away.
Legal basis: our legitimate interest in running a social feature that motivates people to get up (Article 6(1)(f)), balanced against your privacy by keeping the shared set to the four things above, by never sharing anything about your sleep, and by giving you a switch that removes you completely. You can object at any time under section 11, and the Private profile switch is the fastest way to do it.
5.12 Bug reports
The App can send us a bug report. You reach it under Settings, then Support, and while Wakify is in testing through TestFlight you can also open it by shaking your phone. Sending is always your choice: opening the form sends nothing, and nothing leaves your phone until you write a description and tap Send.
When you send a report, we receive:
| Data | Why |
|---|---|
| What you wrote | It is the report. Please do not put anything in it you would not want us to keep |
| The name of the screen you were on | To know where to look |
| A screenshot of that screen, unless you remove it | A picture of the bug is clearer than a description of it. The image is shown to you in the form before you send, and a Remove button takes it out |
| Your app version and build, your iPhone model, your iOS version, and your language and region | Many bugs happen on one model, one release or one language only |
| Whether your subscription is active | Some bugs affect only free accounts, or only paid ones |
| A snapshot of what the app was doing | How many alarms you have and how many are on, whether the alarm permission was granted, whether a night was being recorded and when it started, whether an alarm was ringing and which mission it was running, and whether a wake-up was still owed |
| The last ten minutes of the app's own log, up to 300 lines | The same reason. This is Wakify's own diagnostic log only. It can never contain anything logged by iOS or by another app |
| Your account identifier | So we can come back to you, and so we can group your reports about the same bug |
A screenshot shows whatever was on your screen. If you report from the sleep statistics screen, the image contains your sleep data. If you report from the morning screen it can contain your agenda. That is why we always show it to you first and why you can remove it.
You must be signed in to send a report, and only we can read it. The database refuses to return a bug report to any app, including yours, and screenshots are held in private storage that no link reaches.
Legal basis: our legitimate interest in finding and fixing faults (Article 6(1)(f)), balanced against your privacy: you decide whether to send anything, you see the screenshot first, and we ask for no more context than a bug needs. You can object at any time under section 11, and not sending reports has the same effect. If you choose to write something about your health in a report, you are giving us that yourself and we rely on your explicit consent for it (Article 9(2)(a)).
How long we keep it. A bug report is our engineering record of a fault, so unlike the rest of section 5 it is not erased with your account. When you delete your account we remove your account identifier from the report. Section 9 says how long we keep it.
6. Permissions the app asks for, and what happens if you say no
Wakify asks for permission at the moment a feature needs it, never in a wall of requests up front. Every permission is optional except the alarm permission, and refusing one only disables the feature that depends on it.
| Permission | Used for | If you refuse |
|---|---|---|
| Alarms (AlarmKit) | Ringing through Silent mode and Focus | Wakify cannot save an alarm. We block saving rather than store an alarm that cannot ring |
| Microphone | Recording custom alarm sounds, the Shout mission, and sleep sound analysis during a tracked night | Those features are unavailable. Everything else works |
| Camera | Object Hunt, Sky Photo, Mirror Selfie, and the exercise missions | Those missions are unavailable. Pick another mission |
| Speech recognition | Checking that you said the wake-up phrase | The Shout mission falls back to another mission |
| Motion | Counting steps and repetitions, and sensing when you fall asleep | Wakify reads motion straight from the sensors, so iOS shows no separate prompt for this |
| Apple Health | Reading your sleep and heart data, writing your tracked nights back | Wakify uses only its own on-device measurements |
| NFC | Scanning your tag or dock to turn off the alarm | iOS asks no separate NFC permission. If your iPhone cannot read a tag, the alarm falls back to the Math mission so you are never stuck |
| Notifications | The bedtime reminder | No bedtime reminder |
| Calendar and Reminders | Showing today's agenda on the morning screen | No agenda. Nothing else changes |
| Location (only while using the app) | Looking up the weather for the morning screen, and finding a city when you set your place by hand | No weather on the morning screen. Nothing else changes |
| Screen Time (Family Controls) | Only for the optional "Can't be deleted" setting, which stops apps being deleted while an alarm is unfinished | The setting stays off and nothing on your phone is restricted |
Calendar and reminder content is read on your device, shown to you, and never transmitted or stored by us. Your location is used at the moment the morning screen loads the weather: your approximate position, or the city name you type, goes to Apple to fetch the forecast. It never reaches us and we never store it. The Screen Time permission gives Wakify one thing only, the ability to switch app deletion off and on again while an alarm is unfinished. It gives us no list of your apps, no usage figures and no data of any kind.
7. Who we share your data with
We do not sell personal data, we do not share it for advertising, and we do not disclose it for anyone else's purposes. We use a small number of service providers ("processors") who handle data only on our documented instructions and under a data processing agreement that requires the same level of protection this policy promises.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Supabase Inc. | Database, authentication, hosting and file storage | The account, settings and summary data described in section 5, including profile photos and any bug report with its screenshot. Never raw audio, night clips, camera frames, voice recordings or raw Apple Health samples | Servers in Frankfurt, Germany (EU). Sub-processors include AWS and Cloudflare |
| RevenueCat, Inc. | Subscription status and entitlement | Your random Wakify account identifier, or an anonymous one it generates before you sign in, plus the Apple purchase receipt and standard technical details its software sends (app version, iOS version, store country and an identifier specific to Wakify). It is contacted when the app starts, even if you never buy anything | United States |
| Apple Inc. | App Store, payments, alarms, Apple Health | Your purchase, as the seller of the subscription, and your sign-in if you use Sign in with Apple. Apple never receives your Wakify sleep data from us | Global |
| Google LLC | Sign in with Google, only if you choose it | Your sign-in request and the identity token | United States |
| Microsoft Corporation | Hosts our hello@cazaristudio.com mailbox (Microsoft 365) | The emails you send us and our replies | United States and the European Union, under the safeguards in section 8 |
| Vercel Inc. | Hosting for wakify.co, including these legal pages | Standard web server logs, including your IP address and the page you requested. No account or app data | United States |
Other Wakify users are also recipients, but only of the four things listed in section 5.11 and only while you are on the leaderboard.
We will also disclose data where we are legally obliged to, for example to comply with a valid court order, or where it is necessary to establish, exercise or defend a legal claim. If Wakify is ever sold or merged, your data may transfer to the acquirer, who will be bound by this policy until they lawfully replace it. You will be told before your data is transferred, and you can delete your account before the transfer takes effect so that your data does not move.
8. Where your data is stored, and international transfers
Your account data is stored in the European Union, on servers in Frankfurt, Germany.
Four of our providers are established in the United States: RevenueCat, Google, Microsoft and Vercel, and Supabase Inc. may access EU-hosted data from the United States for support and maintenance. For those transfers we rely on:
- the European Commission's Standard Contractual Clauses, combined with technical measures such as encryption in transit and at rest and strict access control, and where applicable
- the provider's certification under the EU-US Data Privacy Framework.
You can ask us for a copy of the relevant safeguards at hello@cazaristudio.com.
9. How long we keep your data
| Data | Retention |
|---|---|
| Account, profile, alarms, settings, sleep summaries, wake-ups, missed alarms, streaks, badges, referrals | Until you delete your account. Asking us to delete it schedules the deletion 30 days ahead and signs you out; signing in again inside those 30 days cancels it. After 30 days the data is erased across every table, apart from the two exceptions in the rows below |
| Subscription event log | Kept after you delete your account, with your account identifier removed, because we need it for accounting and billing disputes. Deleted after seven years |
| Encrypted backups | Residual copies expire automatically from our hosting provider's encrypted backup rotation, within 30 days of deletion at the latest. If we ever restore a backup after a system failure, we re-apply your deletion afterwards |
| Product analytics events | Deleted when you delete your account, and in any case no later than 24 months after they were recorded |
| Subscription records | Until you delete your account. The records we keep for tax and accounting law are Apple's aggregated payout reports, which do not identify you |
| Bug reports | Kept after you delete your account, with your account identifier removed, because the report is our record of a fault in the App |
| Support email | Deleted no later than 24 months after the conversation ends |
| Inactive accounts | Deleted after 24 months without opening the App, after a warning at least 30 days in advance (see the Terms of Use) |
| Night audio clips (on your device) | The most recent 30 nights, capped at 250 MB. Older clips are deleted automatically, and clips are removed when you delete the night. They are excluded from your iCloud and iTunes backups |
| Everything else on your device | Until you delete the app, delete the data in the app, or sign out of a switched account |
10. How we protect your data
- Transport encryption. All traffic between the app and our backend uses TLS.
- Encryption at rest. The database and its backups are encrypted at rest.
- Row-level security. Every table is scoped to its owner at the database level, so a request authenticated as one user cannot return another user's rows even if the app had a bug. There is one deliberate exception: the leaderboard, which is built by a single audited database function that returns only the four things listed in section 5.11 and nothing else.
- Server-only fields. Your premium status can only be written by our server, never by the app, so the app cannot alter it.
- On-device processing. The most sensitive signals, audio, camera, voice and heart data, are processed on your phone and never transmitted.
- Credential handling. Your session token is stored in the iOS Keychain. We never see your Apple or Google password, and account passwords are stored only as salted hashes.
No system is perfectly secure. If a personal data breach is likely to result in a risk to you, we will notify the Dutch Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware of it. If the breach is likely to result in a high risk to you, we will also inform you directly without undue delay.
11. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectify data that is wrong or incomplete. You can change your display name and profile photo in the app, and your alarms and settings sync automatically. For anything else you told us during onboarding, email hello@cazaristudio.com and we will correct it.
- Erase your data ("right to be forgotten").
- Restrict processing while a dispute about accuracy or legitimacy is resolved.
- Object to processing based on legitimate interest, on grounds relating to your situation.
- Data portability: receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible.
- Withdraw consent at any time, without affecting processing that already happened. The Health toggles in Settings are consent withdrawals, and so is revoking a permission in iOS Settings.
- Complain to a supervisory authority.
How to use them. The fastest routes are built into the app:
- Delete everything: Settings, then Delete Account. We sign you out at once, take you off the leaderboard, and schedule your data for erasure 30 days later. Signing in again within those 30 days cancels the deletion. After that it erases your account and every row attached to it, apart from the two records described in section 9 that we keep with your account identifier removed: the subscription event log, and any bug report you sent us.
- Get a copy of your data: Settings, then Export my data. This produces a single JSON file containing your profile, settings, alarms, sleep summaries, wake-ups, streak, badges, referral state and consent history, the Article 20 format, straight from the server.
- Stop analytics: Settings, then the analytics toggle. That withdraws your consent for the tier-2 events in section 5.8 and takes effect immediately. To object to the tier-1 reliability events, email us.
- Stop health processing: Settings, then the Apple Health toggles, or revoke access in the iOS Health app.
For anything else, email hello@cazaristudio.com. We answer within one month, and will tell you if we need up to two further months for a complex request. We may ask you to confirm the email address on your account before we act, so we do not hand your data to someone else. Using your rights is free, unless a request is manifestly unfounded or excessive.
Complaints. You can lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag, the Netherlands
autoriteitpersoonsgegevens.nl
If you live elsewhere in the EEA you may complain to your own national authority instead. We would appreciate the chance to fix it first.
12. Children
Wakify is a general-audience app. It is not directed at children, and we do not knowingly collect personal data from anyone below the minimum age below. During setup we ask for your date of birth to tailor sleep guidance. We do not verify it and we cannot check that it is true, so please answer honestly.
- In the European Economic Area, the United Kingdom and Switzerland you must be at least 16 to use Wakify.
- Elsewhere you must be at least 13.
- If you are under 18, you need permission from a parent or guardian before you buy a subscription.
One thing to know if you are a parent: if the account has a username, the person's name, photo and streak are shown to other users on the leaderboard (section 5.11). The Private profile switch in Settings takes them off it, and not setting a username keeps them off it from the start.
If you believe a child below these ages has given us personal data, email hello@cazaristudio.com and we will delete the account.
13. No tracking, no advertising, no automated decisions about you
- Wakify contains no advertising SDK and shows no ads.
- Wakify does not track you across other companies' apps or websites, and therefore does not ask for App Tracking Transparency permission.
- We do not sell or share personal data as those terms are defined under United States state privacy laws, including the California Consumer Privacy Act.
- The leaderboard shows real users, and when you are on it other users see your name, your photo, your streak and whether you have Wakify+. Section 5.11 explains it in full, including how to stay off it. Nothing about your sleep is ever shown to anyone.
- We use no automated decision-making that produces legal or similarly significant effects on you. Your sleep score and streak are calculated automatically. Your score is only ever shown
back to you; your streak is also the number the leaderboard ranks you on if you appear there.
14. Region-specific information
European Economic Area, United Kingdom, Switzerland. This whole policy is written to GDPR standards. The controller is named in section 2, and complaint routes are in section 11.
California. If you are a California resident you have the right to know what personal information is collected, disclosed or sold, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information, and we do not use it for cross-context behavioural advertising. The categories we collect are set out in section 5, and you can exercise your rights through the routes in section 11.
Other United States states. Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah and Texas) have comparable rights of access, correction, deletion and portability. Use the same routes in section 11.
United States consumer health data. Your sleep data is health data and we treat it that way in every US state: we collect and process it only with your consent, we never sell it, we never share it for advertising, and you can delete it at any time through the routes in section 11.
Everywhere else. Wherever you live, we honour the rights described in section 11: access, correction, deletion, portability, objection and withdrawal of consent. If the privacy law of your country gives you more, for example the LGPD in Brazil or PIPEDA in Canada, we honour requests under it through the same routes. We never sell personal data, wherever you live.
15. Changes to this policy
We will update this policy when the App, our website or our service providers change what happens to your data. When a change matters to you, we will tell you before it takes effect, in the App or by an email to the address on your account, and where the law requires it we will ask for your consent again. The version number and date at the top of this document always show which version is current. Previous versions are available on request.
16. Contact
Cazari B.V.
Klaaskampen 40, 1251 KP Laren, the Netherlands
Email: hello@cazaristudio.com
Chamber of Commerce (KvK): 98486748
We aim to answer every privacy question within five working days, and always within the statutory deadlines described in section 11.
17. Our website
The pages at wakify.co, including this policy, are hosted for us by Vercel Inc. Vercel keeps standard web server logs, including your IP address, to keep the site running and secure, and deletes them on a short rolling schedule.
- The site sets no cookies and asks for no consent, because it needs none.
- It runs no advertising, analytics or tracking scripts, and loads no third-party scripts at all. Fonts are served from our own domain.
- The only thing it stores in your browser is your light or dark theme choice, and only after you press the theme button.
- We do advertise Wakify on social platforms, including Meta. Those campaigns are targeted by the platform using the platform's own data. We place no measurement code on this site and we give those platforms no data from your Wakify account.
If we ever add a tracking or measurement script to this site, we will ask for your consent before it loads and we will update this policy first.