Privacy Policy

Last updated: March 29, 2026

1. Who operates Somnia

Somnia is currently an independent project operated by an individual developer, not by a registered company.In this policy, "Somnia", "I", "me", and "my" refer to the individual developer operating the Somnia mobile application (the App) and thesomnia.fm website (the Site).

This policy explains what data may be collected, why it is collected, how long it is kept, who it may be shared with, and what rights you have.

2. Scope

This policy applies to:

  • the somnia.fm website,
  • the Somnia mobile app,
  • support requests sent to privacy@somnia.fm.

It does not apply to third-party services such as Google, Apple, Google Play, the App Store, RevenueCat, Sentry, or Supabase, which maintain their own privacy policies.

3. Data Somnia may collect

3.1 Account and authentication data

If you create an account, Somnia may process:

  • Email address — to create your account, sign you in, and help you recover access
  • Display name or first name (optional)
  • Language and time zone
  • Authentication credentials handled by Supabase (for example password hashes if you use email/password login)
  • Google-provided identifiers if you choose Google sign-in

3.2 Personalization and usage data

  • Onboarding preferences — civilizations, values, goals, current mood, daily time, attribution
  • Ritual preferences — notification hour, language, and app experience settings
  • Favorites and saved content
  • Streak, progress, and feature usage
  • Playback position or listening resume state
  • User-created affirmations, if you use that feature

3.3 Subscription and purchase data

  • Anonymous app user ID and subscription status through RevenueCat
  • Transaction metadata provided by the App Store or Google Play (offer, premium entitlement, subscription period)
  • Somnia does not receive your full credit card number when purchases are processed by Apple or Google

3.4 Technical data

  • Device and app data — app version, operating system, device model, language, time zone, technical identifiers
  • Crash and diagnostic data — through Sentry, to investigate errors and fix bugs
  • Connection and log data — for example approximate IP address, technical events, and security logs
  • Push notification token if you enable notifications

3.5 Website data

  • Visit data — viewed pages, browser, device, approximate country, referrer, timestamp
  • Website audience measurement through privacy-friendly tools such as Cloudflare Web Analytics, when enabled
  • Support emails and the information you include in them

3.6 Guest mode

You can use some parts of the App without creating an account. In guest mode, locally stored data (for example certain preferences or favorites) generally remains on your device unless you use a feature that requires server-side synchronization.

3.7 Sensitive data

Somnia is a storytelling and wellness content app, not a medical service. Unless you voluntarily send it in a support email, Somnia is not intended to request or process medical records and does not aim to infer health diagnoses.

4. Why this data is used

  • Create and manage your account
  • Provide, personalize, and sync the Somnia experience across devices
  • Display your favorites, streak, preferences, and progress
  • Manage subscriptions, in-app purchases, and premium access
  • Send notifications if you have enabled them
  • Protect the service, prevent abuse, and fix bugs
  • Measure website usage and improve the product
  • Reply to your messages and support requests
  • Comply with applicable legal, accounting, and tax obligations

Somnia does not sell your personal data, does not rent it to advertisers, and does not use it for cross-context behavioral advertising.

As of the date of this policy, Somnia does not use third-party advertising SDKs in the app. Wellness-related personalization inputs (for example mood, goals, or ritual preferences) are used to operate and personalize the experience, not for third-party ad targeting.

5. Legal bases (GDPR)

Where the GDPR applies, processing usually relies on one or more of the following legal bases:

  • Performance of a contract — to provide the App, your account, purchases, and sync features
  • Consent — for example for push notifications or optional settings
  • Legitimate interests — to secure the service, prevent fraud, analyze usage, and improve Somnia
  • Legal obligation — where certain data must be retained for tax, accounting, or regulatory reasons

6. Third-party services used

ServiceRoleRelevant data
SupabaseAuthentication, database, synchronizationEmail, profile, preferences, favorites, streak, progress
RevenueCatSubscription managementAnonymous app ID, premium status, subscription metadata
Google Sign-InGoogle authenticationGoogle identifier, email, and profile information you authorize
SentryError monitoring and diagnosticsTechnical data, crash reports, device/app information
CloudflareWebsite hosting, security, audience measurementWebsite technical logs, visit data, aggregated metrics
Apple / GoogleApp distribution and in-app paymentsPurchase metadata, transaction status, platform account identifiers depending on your use

7. Data sharing and international transfers

Your data may be shared only in the following situations:

  • with technical processors needed to operate Somnia;
  • if required by law or in response to a valid legal request;
  • to protect rights, security, the integrity of the service, or prevent fraud;
  • with your explicit consent, where needed.

The main application database may be hosted in the European Union, but some third-party providers may process data outside your country or the EEA, including in the United States. Where relevant, Somnia relies on appropriate legal safeguards made available by those providers, such as standard contractual clauses or equivalent measures.

8. Retention

  • Account and profile data — kept while your account exists, then deleted or anonymized within a reasonable period after deletion unless law requires otherwise
  • Guest mode data — kept locally on your device until you uninstall the app or clear local storage
  • Subscription and billing data — kept as long as necessary to manage premium access and comply with accounting/tax obligations
  • Logs, diagnostics, and security data — kept for the period needed for debugging, security, and abuse prevention
  • Support emails — kept for as long as needed to handle the request and maintain relevant support history

9. Security

  • Communications use TLS/HTTPS encryption
  • Access to data is limited to technical needs of the service
  • Application and database security controls are used where appropriate
  • Passwords are not stored in plain text by Somnia

No system is perfectly secure, but reasonable measures are taken to reduce the risk of unauthorized access, loss, or alteration.

10. Account deletion and data deletion

If you created a Somnia account, you can request deletion of your account and associated data by emailingprivacy@somnia.fmfrom the email address linked to your account, or by providing enough information to verify the request.

  • Web deletion resource: this page and the email address above are the public web resource for deletion requests
  • Target timeline: verified requests are handled within a reasonable time, usually within 30 days
  • Exceptions: some data may be kept longer if required by law or needed for fraud prevention, security, or dispute resolution
  • Deleting the app does not automatically delete a server-side account if you created a Somnia account; a deletion request is still required
  • Subscriptions: deleting your account does not automatically cancel a subscription managed by Apple or Google; those subscriptions must be managed from your App Store or Google Play account
  • Guest mode: to erase locally stored data from a no-account experience, uninstall the app or clear its local storage on your device

11. Your rights

Depending on where you live, you may have rights such as:

  • Access to your personal data
  • Correction of inaccurate data
  • Deletion of your account or specific data
  • Portability where applicable
  • Objection to certain processing or restriction of processing
  • Withdrawal of consent where processing is based on consent
  • Complaint to a competent data protection authority

To exercise these rights, emailprivacy@somnia.fm.

12. Children

Somnia is designed primarily for teens and adults and is not intended for children under 13.Somnia does not knowingly seek to collect personal data from children under 13.

If a parent, guardian, or legal representative believes that a child or minor has provided personal data without appropriate authorization, they may contact privacy@somnia.fm to request deletion.

13. Changes

This policy may be updated to reflect product changes, changes in service providers, or changes in legal obligations. The date at the top of the page will be updated accordingly.

14. Contact

For privacy questions or to exercise your rights: