SleepAnchor — Privacy Policy

Version: 1.0.0 Effective: 2026-10-02 Applies to: All versions of the SleepAnchor Android app, including closed testing tracks on Google Play.

This policy is provided to satisfy the transparency obligations of Articles 12–13 of the GDPR.1 Plain-language text first; every statutory or regulatory reference is collected in the footnotes and the Legal basis & references annex at the end.

Data Controller

Durdeu Vlad-Ioan (dwurdy), Romania2 Contact: support@dwurdy.com

Overview

SleepAnchor is built local-first: your sleep schedule, session history, and app-usage monitoring live on your device. Cloud services are used only for anonymous analytics, crash reporting, and optional accountability/community sharing that you explicitly enable. This architecture is our implementation of the GDPR principles of data minimisation and data protection by design and by default.3

Data We Process

Stored only on your device (never transmitted)

Local data is stored in an encrypted database (SQLCipher) and is excluded from Android cloud backups (allowBackup=false).5

Sleep and health-related entries can fall within the "special categories" of personal data protected by GDPR Article 9.6 Because this data never leaves your device, the only potentially health-related transmissions are: (a) the optional shared check-in described below — which happens only with your explicit consent — and (b) a coarse functional outcome flag in Analytics that records what the app did (e.g., whether a recovery plan was suggested), not how you felt or any measurement.

Sent to Firebase (Google)

Data Service Purpose Legal basis (GDPR)7
Anonymous app events (feature usage, onboarding completion, bucketed outcomes — never exact sleep times, exact timestamps, or other apps' names)11 Firebase Analytics Understand whether core features work Legitimate interest — Art. 6(1)(f)8
Crash reports (device model, OS version, stack trace) Firebase Crashlytics Fix bugs and stability issues Legitimate interest — Art. 6(1)(f)8
Anonymous user ID + profile (invite code, partner link, sharing preferences) Firebase Auth + Cloud Firestore Accountability/community features Consent — Art. 6(1)(a); the anonymous account is created only if you enable these features12
Shared check-ins (feeling + approximate sleep duration) Cloud Firestore Visible only to your linked accountability partner, only if you enable sharing Explicit consent — Art. 6(1)(a) and Art. 9(2)(a); toggleable in Accountability settings126
Community stats snapshot — a one-time upload taken when you opt in, covering the previous 7 days: total minutes of monitored-app usage, number of monitored apps, and names of your top-3 most-used monitored apps Cloud Firestore anonymous_stats → weekly Cloud Function aggregates into community_trends Power the anonymous community trends snapshot Consent — Art. 6(1)(a); written once when you opt in on the Community screen10

The Firebase SDKs store and read pseudonymous app-instance identifiers (Firebase Installation IDs / Analytics instance IDs) on your device to provide these services. Storing information on, or accessing information stored in, a user's terminal equipment is regulated by Article 5(3) of the ePrivacy Directive, implemented in Romania by Law no. 506/2004.13 For identifiers written at first run we rely on the exemption for storage/access strictly necessary to provide the service you requested; the anonymous telemetry attached to those identifiers is processed under GDPR Art. 6(1)(f) legitimate interest, and you may object to it at any time under Art. 21 (see Your Rights). We keep such identifiers limited to what is needed for service functionality, stability, and anonymous measurement; analytics telemetry is disabled entirely in development builds.14

Read locally, never transmitted

Never collected

Data Sharing

We do not sell, rent, or trade your data. Data is processed by:

Retention

Retention follows the GDPR storage-limitation principle:19

Your Rights (GDPR)

If you are in the EU/EEA you may exercise the following rights under Articles 12–22 GDPR:23

Security

Security measures are applied under GDPR Article 32:25

Age Restriction

SleepAnchor is intended for adults (18+). We do not knowingly collect data from children, and the App does not offer services directly to children within the meaning of GDPR Article 8.26

Changes

We may update this policy; material changes are announced in-app or via the testing channel. The current version is always at the hosted URL linked in the app and the Play Store listing.27

Contact

support@dwurdy.com


Statutes and regulations are cited to their Official Journal or official consolidated texts; platform policies are contractual documents cited to the publisher's help pages.

EU law

Romanian law

Supervisory authority

Google Play policies (contractual)

Processor documentation

Footnotes


  1. Regulation (EU) 2016/679, Arts. 12–13. Full text: https://eur-lex.europa.eu/eli/reg/2016/679/oj ↩

  2. GDPR Art. 4(7) defines the controller; Art. 13(1)(a) requires disclosure of the controller's identity and contact details. ↩

  3. GDPR Art. 5(1)(c) (data minimisation) and Art. 25 (data protection by design and by default). ↩

  4. Sleep records are read via the android.permission.health.READ_SLEEP Health Connect permission. Health Connect data is "personal and sensitive user data" under Google Play's User Data policy (https://support.google.com/googleplay/android-developer/answer/10144311) and Health Content and Services policy (https://support.google.com/googleplay/android-developer/answer/16679511). Reads are on-device only. ↩

  5. Implementation: Drift database encrypted via sqlcipher_flutter_libs with the key held in flutter_secure_storage; android:allowBackup="false" in android/app/src/main/AndroidManifest.xml. ↩

  6. GDPR Art. 9 prohibits processing of health-related special-category data unless an exception applies; the only transmission of such data is the consent-gated shared check-in under Art. 9(2)(a) explicit consent. ↩↩

  7. GDPR Art. 6(1) requires a lawful basis for each processing operation. ↩

  8. GDPR Art. 6(1)(f) — processing necessary for legitimate interests (measuring whether core features work; fixing crashes), which are not overridden by your interests given the anonymised, bucketed design. You may object under Art. 21 (see Your Rights). ↩↩

  9. Check-in Analytics events: recovery_checkin_submit_started is dropped entirely (its only params are deny-listed, so nothing is sent); recovery_checkin_submitted lands carrying only a coarse outcome flag (early_exit / recovery_suggested / no_recovery_needed) — a functional state, not a wellbeing value. The deny-list sanitiser strips feeling, has_health_data, sleep_minutes_estimate and related keys before transmission (lib/core/services/firebase_service.dart). ↩

  10. Implementation: anonymous_stats/{uid} is written once when you opt in (CommunityService.submitWeeklyStats, lib/features/community/logic/community_service.dart), covering the previous 7 days (weekStart, totalMinutes, uniqueApps, topPackages). A scheduled Cloud Function (publishWeeklyCommunityTrends, firebase/functions/index.js) aggregates opted-in documents into community_trends/current (participant count, average minutes, top-5 apps across participants). Firestore rules (firebase/firestore.rules): anonymous_stats is write-only by its owner and unreadable by other users; community_trends is publicly readable (allow read: if true) and contains aggregates only; community_profiles is owner-only. Opting out deletes your anonymous_stats document immediately. ↩↩↩↩

  11. Enforcement in code: all Analytics events pass a deny-list sanitiser that drops timestamps, sleep values, wellbeing parameters (check-in feelings, sleep-minute estimates, plan/recovery IDs, anchor_end_hour), monitored-app package names (top_packages/topPackages), user identifiers and other sensitive keys, truncates strings, and caps events per session (lib/core/services/firebase_service.dart). Time values are bucketed (e.g., hour_bucket) rather than sent as exact timestamps. ↩

  12. GDPR Art. 6(1)(a) and Art. 7 (conditions for consent, including withdrawal per Art. 7(3)). In code, AuthConsentRequiredException is raised before FirebaseAuth.signInAnonymously() unless the user has consented (lib/features/accountability/logic/accountability_service.dart, lib/features/community/logic/community_service.dart). ↩↩

  13. Directive 2002/58/EC, Art. 5(3) (https://eur-lex.europa.eu/eli/dir/2002/58/oj) as implemented in Romania by Law no. 506/2004 (consolidated text: https://legislatie.just.ro/Public/DetaliiDocumentAfis/288598). Firebase Installation IDs are retained by Google until the customer requests deletion — see "Privacy and Security in Firebase": https://firebase.google.com/support/privacy. ↩

  14. firebase_analytics_collection_enabled / firebase_crashlytics_collection_enabled are set false for the dev build flavour and true for staging/prod (android/app/build.gradle, AndroidManifest.xml); logEventSafe also refuses to send when collection is disabled. ↩

  15. android.permission.PACKAGE_USAGE_STATS declared in the manifest; usage stats are sensitive data under Google Play's User Data policy (https://support.google.com/googleplay/android-developer/answer/10144311). Processing is on-device except for the consent-gated community weekly upload described in the table above. ↩

  16. Google Play, "Use of the AccessibilityService API": https://support.google.com/googleplay/android-developer/answer/10964491. SleepAnchor does not declare isAccessibilityTool (see android/app/src/main/res/xml/accessibility_service_config.xml); the in-app permissions screen explains the service's purpose before you enable it in Android settings. ↩

  17. GDPR Art. 28; Firebase Data Processing and Security Terms: https://firebase.google.com/terms/data-processing-terms; overview of per-product data handling: https://firebase.google.com/support/privacy. ↩

  18. GDPR Arts. 44–46; Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj ↩

  19. GDPR Art. 5(1)(e) — personal data kept no longer than necessary for the purposes. ↩

  20. Google Analytics Help, "Data retention" — standard GA4 properties offer 2- or 14-month user/event-level retention (longer tiers exist only for Analytics 360): https://support.google.com/analytics/answer/7667196 ↩

  21. "Firebase Crashlytics keeps crash stack traces, extracted minidump files and associated identifiers … for 90 days" — Privacy and Security in Firebase: https://firebase.google.com/support/privacy ↩

  22. Google Play, "Understanding Google Play's app account deletion requirements" — where account creation is offered, the policy requires both an in-app deletion path and a web link resource where users can request deletion: https://support.google.com/googleplay/android-developer/answer/13327111. Erasure is the GDPR Art. 17 right. ↩

  23. GDPR Arts. 12–22 (transparent exercise of rights; access, rectification, erasure, restriction, portability, objection). ↩

  24. GDPR Art. 77 (right to lodge a complaint with a supervisory authority). ANSPDCP: https://www.dataprotection.ro/ ↩

  25. GDPR Art. 32 (security of processing — encryption at rest and in transit, confidentiality of services). ↩

  26. GDPR Art. 8 governs consent of children for information-society services; the App is contractually restricted to adults (see Terms of Service §2). ↩

  27. Google Play requires a publicly accessible, non-geofenced privacy policy URL for apps handling personal/sensitive data — Health Content and Services policy: https://support.google.com/googleplay/android-developer/answer/16679511; User Data policy: https://support.google.com/googleplay/android-developer/answer/10144311. ↩