Version: 1.3 Effective date: 2026-08-11 Last updated: 2026-08-12 Applies to: the Snora mobile application (iOS and Android), our website at snora.app, and any companion web application we may offer there (together, the "Service").
What changed in version 1.3: two things, and this version has not taken effect yet, so both are described here rather than in a separate version. First, local sunrise and weather. If you allow location access, the app sends your approximate coordinates, rounded to about one kilometre, directly from your device to the Norwegian Meteorological Institute (MET Norway), and nothing else: no account identifier and no app data. In app versions 1.0.5 and later, sunrise and sunset are calculated on your device and are not requested from anyone. Your coordinates never reach our servers, we store nothing from it, and the feature is off until you allow location. The new Section 4.5 sets out exactly what is sent, and Sections 5, 8, and 10 add the permission, the recipient, and the overseas-transfer disclosure. This describes behaviour that was already in the app; the Policy simply did not name it before. Second, this Policy now also covers our website at snora.app, which it previously did not describe at all. The website is hosted by Vercel, and it uses Vercel's cookie-free web analytics to count page views and a small number of clicks, such as which app store badge was tapped. No cookies are set, nothing is stored on your browser for this, and none of it is linked to your Snora account or to any app data. The new Section 4.4 sets out exactly what is collected, and Sections 8, 10, and 11 add Vercel as a processor, disclose the transfer to the United States, and state the retention. Nothing about the app itself changed in this version.
What changed in version 1.2: two things. Crash reporting arrived with app version 1.0.4. The encrypted backup arrives with Snora Plus, in a later app version. First, Snora Plus will offer an optional end-to-end encrypted backup: if you turn it on, your sleep history, alarms, and settings are encrypted on your device, with a key that only you hold, and stored on our backend as ciphertext we cannot decrypt (Sections 2, 3, 4, 6, 11, and 12). Restoring an existing backup never requires a paid plan. Second, when the app crashes, it now sends a crash report to Sentry (Functional Software, Inc.), a crash-reporting provider in the United States; a report carries the technical crash details, and the app attaches no account identifier to it (Sections 4.3, 8, and 10). Your sleep, rhythm, Wake Confidence, and condition data still never leave your device in a form we can read, and we still do not sell your data or use advertising trackers.
1. Who we are
Snora is operated by Foo AI Corp., a company established under the laws of the Republic of Korea and the publisher of the Snora app ("Snora," "we," "us," or "our"). We are the controller of the limited personal data described in this Policy. You can contact us, including for any data-protection matter, at contact@snora.app.
For any privacy question or request, contact us at contact@snora.app or through snora.app.
2. Our privacy approach in one paragraph
Snora is designed to keep your most personal information on your device. Your sleep logs, your wake/bedtime rhythm, your Wake Confidence status, and any condition tags you choose to add never leave your device in a form we can read. The only way any of that data ever reaches our servers is the optional end-to-end encrypted backup (Section 4): if you turn it on, your device encrypts the data with a key that only you hold, and what we store is ciphertext we cannot decrypt. Beyond that, what we keep on our backend is a minimal set of account-related data (your account identifier, your consent history, your subscription status) plus non-sensitive product analytics events that tell us which features are used, never what your data says (Section 4.2). If the app crashes, a technical crash report, to which we attach no account identifier, goes to Sentry, a crash-reporting provider in the United States (Section 4.3). Payments run through the App Store and Google Play, so we never receive your card details, and the purchase itself is validated for us by RevenueCat, a subscription-infrastructure provider in the United States, which is where your subscription state is kept (Sections 4.1 and 10). If you allow location access so the home screen can show local sunrise and weather, your approximate coordinates, rounded to about one kilometre, go directly from your device to a national weather service, never to us. In app versions 1.0.5 and later that service is the Norwegian Meteorological Institute (MET Norway) and sunrise and sunset are calculated on your device rather than requested; in 1.0.4 it was Open-Meteo and sunrise and sunset were requested too (Section 4.5). Visiting our website, snora.app, is separate from all of this: it sets no cookies, it knows nothing about your app account, and it counts page views and a few clicks through Vercel's cookie-free analytics (Section 4.4). We do not use advertising trackers, we do not sell your data, and we do not build advertising profiles.
3. What stays only on your device (we can never read this)
The following data is created, processed, and stored locally on your device, in encrypted form, and is never transmitted to Snora's servers in a form we can read. The only way any of it ever reaches our servers is the optional end-to-end encrypted backup described in Section 4: you turn it on yourself, the data is encrypted on your device with a key that only you hold, and what we store is ciphertext we cannot decrypt. This on-device data is:
- Sleep logs and timing data you record or that the app derives locally.
- Rhythm / regularity data (your wake and bedtime patterns over time).
- Wake Confidence computations: the Safe / Caution / Risk status and the inputs used to compute it.
- Condition tags you optionally tap (for example, "stress" or "caffeine").
- Any sound or voice analysis the app may perform in the future: if introduced, it is processed entirely on-device and is not transmitted to us.
Because this data lives only on your device, and any backup of it is ciphertext to us, we cannot access it, read it, or provide a readable copy of it; it is under your control. You can erase all of it by deleting the app data or uninstalling the app (see Section 11); if you turned on backup, the encrypted backup is deleted separately, in the app or together with your account (Section 11).
4. What we collect on our backend (only as needed for the Service)
We rely on four processors: Supabase for our database and authentication (it also stores the optional encrypted backup described below), RevenueCat for purchases and subscription state (Section 4.1), Sentry for crash reports (Section 4.3), and Vercel for hosting our website and its cookie-free analytics (Section 4.4). We collect and store the following limited data only when you sign in, when you use a feature that requires it, for crash reports when the app crashes, or, for the website, when you visit snora.app:
| Data | What it is | Why we collect it |
|---|---|---|
| Account identifier | An anonymous user ID by default. You may optionally upgrade your account by adding an email address or signing in with a third-party OAuth provider. | To create and identify your account so settings/entitlements can sync across your devices. |
| Consent records | An append-only ledger recording which optional data permissions you granted and when (timestamps). | To keep an accurate, auditable record of your choices and to honor them. |
| Subscription / entitlement status | Your entitlement (free or Plus), the purchase it comes from (product, store, purchase and expiry dates, renewal state, trial state, price and currency the store charged, country and store metadata), and your account identifier. This record is held for us by RevenueCat, in the United States (Sections 4.1, 8, and 10). Your device also keeps a copy of the last confirmed answer (free or Plus) so that Plus keeps working when you are offline. | To validate the purchase with Apple or Google, to grant and maintain access to paid features, and to end that access when a subscription expires, is refunded, or is revoked (Section 4.1). |
| Product analytics events | Non-sensitive product signals: an event name from a fixed list, plus properties limited to counts, fixed options, and true/false values. Never free text. | To understand which features are used and whether people want a paid plan, and to fix problems (Section 4.2). |
| Encrypted backup (optional, Snora Plus) | If you turn on Backup, the app uploads an end-to-end encrypted copy of your on-device data (your sleep history, alarms, and settings). It is encrypted on your device, before upload, with a key that only you hold; what we store is the resulting ciphertext plus technical metadata (size, timestamps, app version). We cannot decrypt, read, or recover its contents, and we cannot reset or recover your recovery code. | To let you restore your data when you get a new device or reinstall the app. Restoring an existing backup never requires a paid plan. Kept until you delete the backup or your account (Section 11). |
| Crash and diagnostic reports | If the app crashes or hits an unexpected error, a technical report goes to our processor Sentry in the United States: the stack trace, basic device and system information (device model, operating system and version, app version and build), the time, and a stripped trail of recent technical steps. We attach no account identifier, and it carries no message text and nothing you entered (Section 4.3). | To find and fix crashes and errors so that alarms and the app stay reliable. Reports are deleted after 90 days. |
| Website analytics (snora.app) | When you visit our website, our processor Vercel records the page you viewed, the referring site, and coarse device and country information, plus a small number of named clicks such as which app store badge you tapped. No cookies are used, no account identifier is involved, and it is not linked to the app or to anything above (Section 4.4). | To see which pages of the website people read and whether the download links work, so we can improve the site. |
We do not collect or store, on our servers, in any form we can read: your sleep logs, rhythm data, Wake Confidence data, condition tags, health data, precise location, contacts, browsing history, advertising identifiers, your card or payment-method details, or the labels and times of your alarms. If you turn on the optional encrypted backup, your sleep history, alarms, and settings are inside it, but only as ciphertext we cannot decrypt.
4.1 Payments and subscriptions (including RevenueCat)
Snora Plus is sold as an in-app purchase through the App Store and Google Play. Those stores take the payment, not us. Checking that a purchase is genuine, and keeping track of whether a subscription is still active, is done for us by RevenueCat.
Apple and Google (payment).
- We never receive, see, or store your card number, bank details, or payment method. Apple and Google handle payment data as independent controllers under their own privacy policies.
- We do not receive your name, billing address, or store account email from the stores.
- Your invoices, order history, and refunds live in your Apple or Google account, not in Snora. See our Terms of Service, Section 7.
RevenueCat (receipt validation and subscription state).
We use RevenueCat, Inc., a company based in the United States, as our processor for in-app purchases. It is the service that checks your purchase with Apple or Google and tells our app whether your Plus access is active. We do not run our own receipt-validation server.
- What RevenueCat receives from the app: the store's receipt or purchase token and the associated transaction and product identifiers; your Snora account identifier (the same anonymous or signed-in account id described above, used as your customer id at RevenueCat); the entitlement, plan, price, currency, purchase and expiry dates, trial and renewal state reported by the store; and technical metadata that comes with the request, namely the platform, operating system and app version, the store, the country the purchase or request is associated with, and the IP address the request is made from, which RevenueCat uses to determine your country and to operate the service. It does not receive your card details (nor do we), and it does not receive your sleep, rhythm, Wake Confidence, or condition data, in any form; the optional encrypted backup (Section 4) never goes to RevenueCat.
- When it happens: when you buy or restore a purchase, when the store tells RevenueCat that your subscription renewed, expired, or was refunded, and when the app starts and asks whether your Plus access is currently valid. That last check runs for every user of a version that offers Plus, including users who never buy anything, because the app has to know which state it is in and what the plans cost in your currency.
- Why: to validate the purchase against Apple or Google, and to hold the resulting subscription state, so that paid features open only for people who actually paid and close again when a subscription ends. Your Plus access is granted only on the strength of that server-verified answer.
- Where: on RevenueCat's infrastructure in the United States. See Section 10 for the international-transfer disclosure.
- How long: RevenueCat keeps the customer record and its purchase history while your Snora account exists. When you delete your Snora account, we ask RevenueCat to delete the customer record it holds for you (Section 11). Apple and Google keep their own record of the transaction under their own policies and as commerce and tax law requires, and neither we nor RevenueCat can delete that.
- RevenueCat processes this data on our behalf and on our instructions, under a data processing agreement. We do not permit it to use your data for its own advertising, and no advertising or tracking identifier is sent to it by Snora.
4.2 Product analytics events
The app sends a small number of product analytics events to our backend, tied to your account identifier. They are designed so that they cannot carry anything sensitive:
- What an event contains: an event name from a fixed, predefined list (for example, opening the app, creating an alarm, confirming a wake, viewing the paywall), the time it happened, and properties that may only be counts, fixed options from a predefined list, or true/false values.
- Paywall signals. Where Snora Plus is offered, events include a paywall view (which part of the app you opened it from, chosen from a fixed list, and whether you are already on Plus) and a plan interest signal (which plan you tapped: monthly, annual, or lifetime). These tell us whether a paid plan is wanted. They are not a purchase and do not charge you.
- What an event never contains: free text of any kind, your alarm labels or alarm times, your sleep, rhythm, Wake Confidence, or condition data, the content of your consents, prices, or any contact detail.
- These events are write-only: the app can add them but cannot read them back, and they are readable only by us, for product and reliability analysis.
- We do not use these events for advertising, for cross-app tracking, or to build a profile about you, and we do not share them with advertisers or data brokers.
4.3 Crash and diagnostic reports (Sentry)
Versions of the app that include crash reporting (1.0.4 and later) use Sentry, a crash-reporting service operated by Functional Software, Inc., a company based in the United States, as our processor for crash diagnostics. When the app crashes, or hits an unexpected error it cannot recover from on its own, a technical report is sent to Sentry so that we can find and fix the problem.
- What a report contains: the technical stack trace (which part of the app's code failed), basic device and system information (device model, operating system and version, app version and build), the time of the crash, and a short trail (at most 30 entries) of recent technical steps, each stripped down to its kind, category, severity level, and time.
- How we keep it to that list: the crash-reporting library collects far more device detail by default, including screen size, memory, free storage, battery and charging state, orientation, locale and time zone, and a device identifier. Before a report leaves the app we discard all of it and keep only the three items named above: the device model, the operating system and its version, and the app version and build. We do this with a fixed list of what may be kept, so anything the library adds in a future version is dropped unless we review it and update this Policy.
- What a report never contains: your account identifier (not even the anonymous one), your name or email, request headers, cookies, or request bodies (we remove them), console output (we drop it entirely, because it could carry text), any message text or attached data in the step trail (we strip those fields), and, as always, your sleep, rhythm, Wake Confidence, or condition data, your alarm labels or times, and free text of any kind. The app never tells the crash reporter who you are: it sets no account identifier on it at any point, and reports sent by the app also have the user field removed before sending. We configure the reporting library not to attach your IP address or other default identifiers to the report.
- Crashes handled by the operating system. If the app is terminated by a low-level crash, by an "application not responding" timeout, or by the system watchdog, the report is written by the platform's own crash handler and sent the next time you open the app, without passing through the filtering step described above. Those reports still carry no account identifier and no request data, and no sleep, alarm, or console content, because the app never places any of it in the crash reporter. They do carry the device and system details the platform collects and a trail of technical steps recorded by the platform itself, which can include app lifecycle, screen changes, and network requests to our backend. A network entry of that kind can contain the address of a request, and such an address can include your account identifier. We cannot filter these entries from inside the app, so we disclose the possibility here rather than claim otherwise. They are subject to the same 90-day deletion.
- What we deliberately leave off: performance tracing is turned off entirely (its sample rate is zero), and we do not use session replay, so no screen recording or interaction capture takes place.
- When: only when a crash or unexpected error occurs. There is no background or periodic reporting.
- Where and how long: on Sentry's infrastructure in the United States (Section 10). Crash reports are retained for 90 days and then deleted automatically. Because reports are not filed under your account identifier, we cannot reliably find "your" crash reports in order to show or delete them; they age out on their own.
- Sentry processes this data on our behalf and on our instructions, under a data processing agreement. We do not permit it to use this data for its own purposes, and no advertising or tracking identifier is sent to it by Snora.
Your right to object to crash reporting. We process crash reports on the basis of our legitimate interest in keeping Snora and its alarms reliable (Article 6(1)(f) GDPR, Section 7). You have the right to object to this processing at any time on grounds relating to your particular situation. To object, email contact@snora.app. This notice is given separately from the rest of this Policy, as Article 21(4) GDPR requires.
4.4 Our website at snora.app
This Section is about the website, not the app. Visiting snora.app does not involve your Snora account, and nothing described here is linked to the app data in the rest of this Policy.
Hosting. The website is hosted by Vercel Inc., a company based in the United States, acting as our processor. As with any web host, its servers necessarily receive the technical details every browser sends in order to be served a page: your IP address, the page requested, your user agent (browser and operating system), and the referring page. Vercel keeps short-lived operational logs of these requests for security and to keep the site running.
Cookie-free analytics. The site uses Vercel Web Analytics. We chose it because it works without cookies: it does not set a cookie, it does not write an identifier into your browser's storage, and there is therefore no cookie banner and nothing to consent to on the grounds of terminal-equipment access.
- What an event contains: the page path you viewed, the referring source, the approximate location derived from the request (country and region level, not an address), the device type, the operating system, the browser, and the time. Where a link carries campaign parameters (
utm_*), those are recorded too. - Named clicks. In addition to page views, the site records a small, fixed set of named events. At present there is one:
store_badge_click, recorded when you tap the App Store or Google Play badge, with a single property saying which of the two it was. It contains no free text and nothing about you. - What it never contains: your name, your email, your Snora account identifier (the website has no way to know it), your sleep, rhythm, Wake Confidence, or condition data, or any free text.
- Your IP address. Vercel uses the incoming request to derive the country and a visitor hash that is rotated regularly, so that repeat views can be counted without identifying you. Vercel states that it does not store the IP address with the analytics event. The IP address does still reach the server as part of the request itself, as described under Hosting above.
- Where: on Vercel's infrastructure, in the United States (Section 10).
- Advertising. These events are not used for advertising, for cross-site tracking, or to build a profile about you, and they are not shared with advertisers or data brokers. Vercel processes them on our behalf and on our instructions, under a data processing agreement.
Legal basis (GDPR). We rely on our legitimate interest (Article 6(1)(f)) in understanding which pages of our website are read and whether the download links work. Because the analytics are cookie-free and carry no identifier we can tie to a person, this interest does not override your rights.
Your right to object to website analytics. You have the right to object to this processing at any time on grounds relating to your particular situation. To object, email contact@snora.app. You can also block the analytics script with any content blocker, and the website works normally without it. This notice is given separately from the rest of this Policy, as Article 21(4) GDPR requires.
4.5 Local sunrise and weather (optional)
The home screen can show your local sunrise, sunset, and current weather. This is off unless you allow location access, and the app works normally without it.
This section describes app versions 1.0.5 and later. Version 1.0.4 behaved differently in two ways, and that version is still installed on many devices: the request went to Open-Meteo (OpenMeteo GmbH, Switzerland) instead of MET Norway, and it also asked for sunrise and sunset rather than calculating them on the device. Everything else was the same: approximate coordinates rounded to about one kilometre, no identifier attached, nothing stored on our servers. The overseas-transfer disclosure for that version is Transfer 5 in Section 10.
- Sunrise and sunset never leave your device. They are calculated on your device from your coordinates and the date. No request is made for them.
- What leaves your device, and only for the weather: your approximate coordinates, rounded to about one kilometre, and nothing else. No account identifier, no device identifier, no name, and no app data are attached. The app asks the operating system for low-accuracy location and uses your last known position when one is available.
- Who receives it: the Norwegian Meteorological Institute (MET Norway), a Norwegian government institute, through its public weather service. The app calls it directly from your device. It answers with the temperature, humidity, and precipitation for that area. It is not our processor and we hold no account with it. As its terms require, the app identifies itself in the request with its name, version, and our contact address, so that MET Norway can reach us if there is a problem.
- The city name shown next to the weather comes from your operating system's own geocoder (Apple or Google), not from us and not from MET Norway.
- What we store: nothing. The answer is cached on your device so the screen does not re-request it, and your coordinates are never sent to our servers, never stored on them, and never linked to your account.
- What MET Norway stores: its terms state that "the user's IP address will be stored in our logs, along with any possible geocoordinates used in requests", and that "All api.met.no access logs are stored in our own data center in Oslo, Norway." It does not publish a retention period for those logs. We tell you this because it is a different fact from the one above: we keep nothing, but the request still leaves a trace with them.
- Why the app calls it directly: MET Norway suggests routing calls through a proxy so that user IP addresses reach the proxy instead of MET. We do not do that, because it would send the same coordinates and IP to our servers instead, which is exactly what this feature is designed to avoid. The trade is deliberate: the request stays between your device and a national meteorological institute, and we never see it.
- Turning it off: revoke location access in your system settings. The card then stops requesting anything, and the app stops using even the cached answer.
Legal basis (GDPR). Your consent (Article 6(1)(a)), given through the operating system's location permission, which you can withdraw at any time in system settings.
Anonymous accounts
If you never add an email or use OAuth, your account identifier is an anonymous ID that does not, by itself, identify you as a natural person. If you later add an email or use OAuth, that identifier becomes linked to you, and this Policy's rights and protections apply to it.
5. Permissions the app requests
Snora requests only the permissions it needs to function. All are optional except notifications:
- Notifications: required to ring alarms. Without this, the core alarm function cannot work.
- Exact alarm scheduling (Android) and battery-optimization exemption (Android): requested so that alarms fire at the scheduled time and are not delayed or suppressed by the operating system's power-saving behavior.
- Health-data consent (optional): requested only if you choose to use optional condition tags. Any health-related input you provide is treated as on-device data (Section 3) and is not sent to our servers in a form we can read; it reaches them only inside the optional encrypted backup, as ciphertext (Section 4). You can decline this and still use the app's core features.
- Approximate location, while using the app (optional): requested only if you choose to see local sunrise, sunset, and weather on the home screen. The app asks for low-accuracy location, rounds the coordinates to about one kilometre, and sends only those rounded coordinates to the weather service described in Section 4.5. Sunrise and sunset are calculated on your device and are not requested from anyone. Your coordinates never reach our servers. Decline it, or revoke it later, and the rest of the app is unaffected.
We do not request precise location, background or always-on location, contacts, microphone for surveillance, or any advertising permission.
6. How we use data
We use the limited backend data in Section 4 only to:
- create, authenticate, and operate your account;
- sync your settings and entitlements across your devices;
- store, only if you turn it on, an end-to-end encrypted backup of your on-device data so that you can restore it on a new device. It is encrypted with a key that only you hold, so we cannot read it (Section 4), and restoring an existing backup does not require a paid plan;
- record and honor your consent choices;
- have our processor RevenueCat verify a purchase with Apple or Google, and grant, maintain, or end your subscription entitlement and access control (Section 4.1);
- understand, through the product analytics events in Section 4.2, which features are used and whether people want a paid plan, so we can decide what to build and what to charge for;
- find and fix crashes and errors, through the crash reports in Section 4.3, to which we attach no account identifier, so that the app and its alarms stay reliable;
- understand which pages of our website are read and whether its download links work, through the cookie-free analytics in Section 4.4, which are not linked to your account;
- detect, prevent, and address security issues, fraud, abuse, or technical problems, including payment fraud and attempts to obtain paid features without paying;
- comply with legal obligations.
We do not use any data for advertising, behavioral tracking, cross-app profiling, or to make automated decisions producing legal or similarly significant effects about you. We never sell your personal information.
7. Legal bases for processing (GDPR / EEA, UK)
Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): to create and operate your account, sync your settings/entitlements, have the purchase verified with the store through our processor RevenueCat, and provide the subscription access you bought.
- Consent (Art. 6(1)(a)): for optional permissions and optional data (e.g., health-data consent for condition tags, and the optional encrypted backup, which runs only after you turn it on and your choice is recorded in your consent ledger). You may withdraw consent at any time (Section 9); withdrawal does not affect processing already carried out.
- Legitimate interests (Art. 6(1)(f)): to keep the Service secure, prevent abuse and payment fraud, maintain an accurate consent ledger, understand how features are used through the minimal, non-sensitive product analytics events in Section 4.2, and diagnose and fix crashes through the crash reports in Section 4.3, to which we attach no account identifier, so that we can improve the Service and decide what to offer. We keep those events limited to counts, fixed options, and true/false values precisely so that this interest does not override your rights. The same basis covers the cookie-free website analytics in Section 4.4, which carry no identifier we can tie to a person. You may object to this processing (Section 9), and Sections 4.3 and 4.4 set out your right to object to crash reporting and to website analytics separately.
- Legal obligation (Art. 6(1)(c)): where we must retain or disclose data to comply with law.
Optional health-related inputs, if any, are processed on your device under your explicit consent. If you turn on the encrypted backup, they can be included in it, but they reach our servers only as ciphertext we cannot decrypt, on the basis of your explicit consent (Art. 9(2)(a)); we never process special-category data on our servers in readable form.
8. Sharing and processors
We do not sell, rent, or trade your personal data, and we do not share it with advertisers or data brokers. We use the following service providers, who process data on our behalf and under contract, only to provide the Service:
- Supabase: our backend infrastructure (database/auth) provider, acting as our processor. It hosts the limited account, consent, and analytics data described in Section 4, and, if you turn it on, the encrypted backup, which neither it nor we can read, on servers in Korea (Section 10). It is contractually bound to process this data only on our instructions.
- RevenueCat, Inc. (United States): our processor for in-app purchases. It receives the store receipt or purchase token, your account identifier, and the purchase, entitlement, and device/store metadata listed in Section 4.1, and it validates the purchase with Apple or Google and holds your subscription state. It acts only on our instructions, under a data processing agreement, and RevenueCat's own sub-processors (its cloud infrastructure providers) are engaged under that agreement. It is not an advertising company, and we send it no advertising identifier.
- Sentry (Functional Software, Inc., United States): our processor for crash reporting. When the app crashes, it receives the technical report described in Section 4.3: the stack trace, basic device and system information, and a stripped trail of recent technical steps, with no account identifier attached by us, no IP address stored with the report, and no free text (Section 4.3 explains the one case the app cannot filter, where the operating system's own crash handler writes the report). It acts only on our instructions, under a data processing agreement, retains reports for 90 days, and we send it no advertising identifier.
- Vercel Inc. (United States): our processor for hosting snora.app and for its cookie-free web analytics. Its servers receive the technical details of each request to the website (IP address, page, user agent, referrer), and its analytics record the page view, referring source, coarse location, device, operating system, browser, and a small fixed set of named clicks, as described in Section 4.4. It receives no account identifier, no app data, and no free text, it sets no cookies, it acts only on our instructions under a data processing agreement, and we send it no advertising identifier.
- Norwegian Meteorological Institute (MET Norway), Norway: the public weather service the app calls directly from your device when you turn on local sunrise and weather. It receives your approximate coordinates, rounded to about one kilometre, and nothing else: no account identifier, no device identifier, and no app data. As its terms require, the app identifies itself with its name, version, and our contact address. It is not our processor, we hold no account with it, and nothing from that request reaches or is stored on our servers. Its own terms state that it stores the request's IP address and coordinates in access logs held in Oslo (Section 10, Transfer 4). Norway is part of the European Economic Area, so this involves no transfer outside the EEA (Section 10). Section 4.5 sets out exactly what is sent and what is kept.
- OpenMeteo GmbH (Open-Meteo), Switzerland: the weather service used by app version 1.0.4, which is still installed on many devices. It received the same approximate coordinates, rounded to about one kilometre, and nothing else, and it also answered the sunrise and sunset times that later versions calculate on the device. It is not our processor and nothing from that request reached our servers. Switzerland has an adequacy decision from the European Commission (Section 10, Transfer 5). App versions 1.0.5 and later do not contact it.
- Apple (App Store) and Google (Google Play): in-app purchases of Snora Plus are processed by the stores' billing systems. We never receive your card or payment-method details. Apple and Google process your payment data as independent controllers under their own privacy policies, and they hold your order history, invoices, and refunds. They also provide the receipt or purchase token that RevenueCat validates on our behalf (Section 4.1).
We may also disclose data if required by law, legal process, or a lawful government request, or to protect the rights, safety, or property of users, the public, or Snora.
9. Your rights
Subject to applicable law, you have the right to:
- Access the backend data we hold about your account;
- Correct inaccurate account data;
- Delete your backend account data ("right to erasure");
- Withdraw consent for any optional permission at any time;
- Object to or restrict certain processing;
- Data portability: receive your backend account data in a portable format, where applicable;
- Lodge a complaint with your data protection authority (in Korea, the Personal Information Protection Commission (PIPC); in the EEA/UK, your local supervisory authority).
On-device data (Section 3) is under your direct control: you exercise your "delete" right over it by clearing app data or uninstalling, since we cannot access it. If you use the optional encrypted backup, you can delete it in the app at any time, and it is deleted together with your account (Section 11).
California residents (CCPA/CPRA)
We do not sell or "share" (as defined under the CPRA) personal information, and we do not use it for cross-context behavioral advertising. California residents have the right to know, delete, correct, and to non-discrimination for exercising these rights. Because we do not sell or share, no "Do Not Sell or Share" action is required, but you may still contact us to exercise your rights.
To exercise any right, email contact@snora.app. We will verify your request reasonably (for anonymous accounts, this may require information that links you to the account) and respond within the period required by applicable law.
10. International data transfers
Snora is operated from the Republic of Korea. The account, consent, and analytics data described in Section 4, and the optional encrypted backup, are hosted by our processor Supabase on Amazon Web Services infrastructure located in Seoul, Republic of Korea (the AWS ap-northeast-2 region). The purchase and subscription data described in Section 4.1 is processed by RevenueCat in the United States, the crash reports described in Section 4.3 are processed by Sentry in the United States, and our website and its cookie-free analytics, described in Section 4.4, are hosted by Vercel in the United States. If you turn on local sunrise and weather, your approximate coordinates go directly from your device to a national weather service and never to our servers: MET Norway in Norway in app versions 1.0.5 and later, and Open-Meteo in Switzerland in version 1.0.4 (Section 4.5). Your on-device data leaves your device only if you turn on the encrypted backup, and then only as ciphertext we cannot decrypt, stored in Korea alongside the rest of our backend data.
Transfer of personal data abroad (PIPA Article 28-8)
Under the Korean Personal Information Protection Act, we must tell you, in this Policy, about any transfer of your personal data outside Korea. There are five: the purchase and subscription data processed by RevenueCat (Section 4.1), the crash reports processed by Sentry (Section 4.3), the website request and analytics data processed by Vercel (Section 4.4), and, only if you allow location access, the approximate coordinates sent for local weather, which go to MET Norway in app versions 1.0.5 and later (Transfer 4) and went to Open-Meteo in version 1.0.4 (Transfer 5) (Section 4.5). The encrypted backup is not transferred abroad; it stays in Korea.
Legal basis for these transfers. Each transfer below is made under PIPA Article 28-8(1)3: the transfer is necessary to perform the contract with you and to respond to your requests, and each recipient acts as our processor under a written agreement that binds it to our instructions and to the protections this policy describes. We do not sell personal data and we do not transfer it abroad for any purpose beyond the ones stated in each table.
Transfer 1: RevenueCat (purchases and subscriptions)
| Item | Detail |
|---|---|
| Recipient | RevenueCat, Inc., United States. Privacy contact: as published at revenuecat.com/privacy |
| Country | United States (RevenueCat's cloud infrastructure) |
| When and how | Continuously while you use a version of the app that offers Snora Plus: when you buy or restore a purchase, when the store reports a renewal, expiry, or refund, and when the app checks your subscription state at start-up. Transmitted from the app over an encrypted (TLS) connection |
| Data transferred | Store receipt or purchase token and the transaction/product identifiers; your Snora account identifier; entitlement, plan, price, currency, purchase and expiry dates, trial and renewal state; platform, OS and app version, store, country, and the IP address of the request (Section 4.1). No card data. No sleep, rhythm, Wake Confidence, or condition data |
| Purpose | Validating the purchase with Apple or Google, and maintaining your subscription state so that paid features open and close correctly |
| Retention | While your Snora account exists. Deleted when you delete your account (Section 11), subject to the records Apple and Google keep independently |
| How to refuse, and what happens | You can refuse this transfer by not using a version of Snora that offers Snora Plus, or by uninstalling the app. Because the check is how the app knows whether you have paid, we cannot offer Snora Plus without it. The free tier of Snora works whether or not you ever buy anything, and your sleep data never becomes readable to us either way (Sections 2 and 3) |
Transfer 2: Sentry (crash reports)
| Item | Detail |
|---|---|
| Recipient | Functional Software, Inc. (Sentry), United States. Privacy contact: as published at sentry.io/privacy |
| Country | United States (Sentry's cloud infrastructure) |
| When and how | Only when the app crashes or hits an unexpected error, in versions of the app that include crash reporting (1.0.4 and later). Transmitted from the app over an encrypted (TLS) connection |
| Data transferred | The technical stack trace; basic device and system information, limited to device model, operating system and version, and app version and build; the time of the crash; and a stripped trail of recent technical steps (kind, category, severity level, and time only) (Section 4.3). No account identifier. No IP address stored with the report. No sleep, rhythm, Wake Confidence, or condition data. No alarm labels or times. No free text. For crashes handled by the operating system's own crash handler, the report is assembled outside the app and additionally carries the device and system details the platform collects and the platform's own trail of technical steps, which can include a network request address containing your account identifier (Section 4.3) |
| Purpose | Diagnosing and fixing crashes and errors so that the app and its alarms stay reliable |
| Retention | 90 days from the report, after which it is deleted automatically |
| How to refuse, and what happens | Crash reports are sent only when the app crashes, and we attach no account identifier to them; this version of the app does not offer a separate switch for them. You can refuse this transfer by not using a version of the app that includes crash reporting, or by uninstalling the app. You can also object to this processing at any time by emailing contact@snora.app (Section 4.3). Refusing does not affect your account or your data |
Transfer 3: Vercel (website hosting and cookie-free analytics)
| Item | Detail |
|---|---|
| Recipient | Vercel Inc., United States. Privacy contact: as published at vercel.com/legal/privacy-policy |
| Country | United States (Vercel's cloud infrastructure) |
| When and how | Each time you open a page on snora.app. Transmitted from your browser over an encrypted (TLS) connection |
| Data transferred | The technical details every browser sends with a request: IP address, the page requested, user agent, and referrer; and, for analytics, the page path, referring source, coarse location (country and region), device type, operating system, browser, campaign parameters if the link carried any, and a small fixed set of named clicks such as which app store badge was tapped (Section 4.4). No cookies. No account identifier. No app data. No free text. Vercel states that the IP address is not stored with the analytics event |
| Purpose | Serving the website, keeping it secure, and understanding which pages are read and whether the download links work |
| Retention | Operational request logs for a short period, as required to run and secure the site; analytics for the limited period provided under our plan with Vercel, after which they are deleted. Neither is linked to your Snora account (Section 11) |
| How to refuse, and what happens | The hosting transfer is inseparable from visiting the website, so you refuse it by not visiting snora.app; the app works without it. You can refuse the analytics separately by blocking the analytics script with any content blocker, and the website works normally without it. You can also object at any time by emailing contact@snora.app (Section 4.4). Refusing does not affect your account, your app data, or your Snora Plus access |
Transfer 4: MET Norway (local weather, app versions 1.0.5 and later, only if you allow location)
| Item | Detail |
|---|---|
| Recipient | Norwegian Meteorological Institute (Meteorologisk institutt, MET Norway), Norway. Privacy contact: as published at met.no |
| Country | Norway (European Economic Area) |
| When and how | Only while local sunrise and weather is turned on, that is, only after you allow location access. The app requests a forecast at most a few times a day and caches the answer on your device. Transmitted from the app over an encrypted (TLS) connection |
| Data transferred | Your approximate coordinates, rounded to about one kilometre; the IP address the request is made from, which every network request carries; and an identifying string containing the app name, version, and our contact address, which MET Norway's terms require. No account identifier. No device identifier. No name. No sleep, rhythm, Wake Confidence, or condition data. No alarm labels or times. No free text. Sunrise and sunset are calculated on your device and are not requested (Section 4.5) |
| Purpose | Obtaining the temperature, humidity, and precipitation forecast for your area, so the home screen can show them |
| Retention | At the recipient: MET Norway's terms state that the IP address and any coordinates used in a request are stored in its access logs, held in its own data centre in Oslo. It does not publish a retention period for those logs. At Snora: nothing. The answer is cached on your device only, and nothing from this request reaches our servers |
| How to refuse, and what happens | Decline the location permission, or revoke it later in your system settings. The card then stops requesting anything, and every other part of the app, including alarms, sleep tracking, and Snora Plus, is unaffected |
Transfer 5: Open-Meteo (local sunrise and weather, app version 1.0.4 only, only if you allow location)
| Item | Detail |
|---|---|
| Recipient | OpenMeteo GmbH, Switzerland. Privacy contact: as published at open-meteo.com |
| Country | Switzerland (European Commission adequacy decision) |
| When and how | Only in app version 1.0.4, and only while local sunrise and weather is turned on. The app requested a forecast at most a few times a day and cached the answer on the device. Transmitted from the app over an encrypted (TLS) connection. App versions 1.0.5 and later do not contact this service |
| Data transferred | Your approximate coordinates, rounded to about one kilometre, and the IP address the request is made from. No account identifier. No device identifier. No name. No sleep, rhythm, Wake Confidence, or condition data. No alarm labels or times. No free text. Unlike later versions, this request also asked for the sunrise and sunset times (Section 4.5) |
| Purpose | Obtaining the sunrise, sunset, temperature, humidity, and precipitation forecast for your area, so the home screen could show them |
| Retention | At the recipient: Open-Meteo states that it does not store personal data from API requests and does not publish a retention period. At Snora: nothing. The answer was cached on the device only, and nothing from this request reached our servers |
| How to refuse, and what happens | Decline the location permission, or revoke it later in your system settings; or update to app version 1.0.5 or later, which contacts MET Norway instead. Every other part of the app, including alarms, sleep tracking, and Snora Plus, is unaffected |
EEA and UK users
For users in the EEA or UK, storing data in Korea is a transfer to a third country. The Republic of Korea benefits from the European Commission's adequacy decision for Korea, and, for UK users, from the UK's corresponding adequacy arrangements where applicable. Norway, where MET Norway is based, is part of the European Economic Area, so the request described in Section 4.5 is not a transfer to a third country at all. Switzerland, where Open-Meteo is based, benefits from an adequacy decision, so the version 1.0.4 request needed no additional safeguard either. The transfers to RevenueCat, to Sentry, and to Vercel, all in the United States, are made under the Standard Contractual Clauses (or another lawful transfer mechanism provided for in each processor's data processing agreement, such as certification under an approved framework). In all cases we limit transferred data to the minimal account, consent, entitlement, and purchase data described in Section 4, the crash reports described in Section 4.3, and the website request and analytics data described in Section 4.4; we do not transfer your sleep, rhythm, Wake Confidence, or condition data in readable form. If you turn on the optional encrypted backup, it is hosted in Korea, under the same adequacy basis, as ciphertext we cannot decrypt.
11. Data retention
- On-device data: retained on your device until you delete it. You can remove it by clearing app data or uninstalling the app; uninstalling deletes the locally stored, on-device data.
- Backend account data (account identifier, consent records, entitlement status): retained while your account is active and as needed to provide the Service. When you request deletion, or after a reasonable period of inactivity, we delete or de-identify it, except where we must retain certain records to comply with legal obligations or to resolve disputes. Consent records may be retained as a legal record of your prior choices for the minimum period required.
- Subscription / entitlement record (held by RevenueCat, Section 4.1): kept while your Snora account exists, so that your Plus access works across your devices and so that a lifetime purchase can be restored. When you delete your account, we ask RevenueCat to delete the customer record it holds for you (see below).
- The transaction itself (amount, payment method, invoice, refund) is held by Apple or Google, the merchants of the sale, not by us. They keep it under their own policies and under the tax and commerce law that applies to them. Neither we nor RevenueCat can delete those records, and deleting your Snora account does not remove them.
- Product analytics events (Section 4.2): retained while your account is active and deleted together with your account, automatically, when you delete it. We keep them no longer than we need them for the purposes in Section 4.2.
- Encrypted backup (optional, Section 4): kept while you keep backup turned on; each new backup replaces the previous one. It is deleted immediately when you delete the backup in the app, and it is deleted together with your account when you delete your account. Because it is end-to-end encrypted with a key that only you hold, a backup whose recovery code is lost is permanently unreadable, by you and by us, and we cannot reset or recover that code.
- Crash reports (Section 4.3): retained by Sentry for 90 days, then deleted automatically. Because they are not filed under your account identifier, they are not linked to your account and are not part of account deletion.
- Website data (Section 4.4): the operational request logs Vercel keeps in order to serve and secure snora.app are short-lived, and the cookie-free analytics are retained for the limited period provided under our plan with Vercel and then deleted. Because neither carries an account identifier, they are not linked to your Snora account and are not part of account deletion.
What deletion actually deletes. Deleting your account removes your account record, your consent records, any entitlement record on our own backend, your analytics events, and your encrypted backup if you have one, and it sends RevenueCat a request to delete the customer record and purchase history it holds for your account. If that request cannot be completed at the time (for example, RevenueCat is temporarily unreachable), your Snora account is still deleted, and you can write to contact@snora.app to have the RevenueCat record removed. The purchase records held by Apple and Google are not affected, as described above.
Note that deleting your Snora account does not cancel a subscription with Apple or Google: cancel that in your store account settings first (see the Terms of Service).
12. Security
We use reasonable technical and organizational measures appropriate to the limited data we hold, including:
- On-device encryption of locally stored sleep/rhythm/Wake Confidence/condition data;
- End-to-end encryption of the optional backup: it is encrypted on your device before upload, with a key that exists only on your device and in your recovery code, so our servers hold only ciphertext;
- Row-Level Security (RLS) on our backend so that account, consent, entitlement, and backup records are accessible only to the corresponding account;
- access controls and transport encryption (TLS) for data in transit to our backend;
- data minimization: we deliberately keep sensitive data off our servers.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Data protection officer / privacy contact (Korea, PIPA §31)
In accordance with the Personal Information Protection Act (PIPA) §31, we have designated a person responsible for personal-information protection and for handling your privacy inquiries and complaints:
- Privacy Officer: JEEHO SONG, Representative Director, Foo AI Corp.
- Department: Privacy, Foo AI Corp.
- Contact: contact@snora.app (please mark your message "Privacy")
You may direct any question, request, or complaint about your personal data to this contact, and you may also lodge a complaint with the Personal Information Protection Commission (PIPC) (Section 9).
Security-incident notification (PIPA §34)
If we become aware of a breach affecting personal data we hold on our backend, we will notify affected users and report to the competent authorities (in Korea, the Personal Information Protection Commission and the Korea Internet & Security Agency (KISA)) within the time and in the manner required by applicable law. Your sleep, rhythm, Wake Confidence, and condition data are never sent to us in readable form, so a breach of our backend cannot expose their contents: the only copy we may hold is the optional encrypted backup, which is ciphertext that cannot be read without your recovery code.
13. Children
Snora is not directed to children. During onboarding, the app presents a self-attested age gate (14 or older). We do not knowingly collect personal data from anyone under the applicable minimum age (14 in Korea; 13 under COPPA in the United States; 16 or the lower age set by a member state under the GDPR). If you believe a child under the applicable age has provided us data, contact contact@snora.app and we will delete it.
14. Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will provide notice through the app or at snora.app at least 7 days before it takes effect, and where the change is unfavorable to you or where required by law, at least 30 days in advance. The "Last updated" date reflects the latest version. Continued use after the effective date constitutes acceptance, to the extent permitted by law.
15. Contact
Foo AI Corp. (operator and data controller of Snora) Email: contact@snora.app Web: snora.app
Given Snora's current scale and the minimal, non-sensitive nature of the backend data we process (Section 4), we have determined that we are not required to designate an EU/UK representative under Article 27 of the GDPR at this time. If our processing changes such that a representative becomes required, we will designate one and identify them here.
Change history
- v1.3a (last updated 2026-08-12): presentation only. The Korean labels that ran alongside the English ones in the international-transfer tables and the privacy-officer block were removed, so every label now reads in English. No value, recipient, purpose, retention period, or right changed, and no notice period applies to a change that alters nothing about how data is handled.
- v1.3 (last updated 2026-08-04, effective 2026-08-11): two additions, both made before this version took effect. First, local sunrise and weather: the app has always sent approximate coordinates, rounded to about one kilometre, directly from the device to a public weather service when you allow location access, and none of it was disclosed here. In app versions 1.0.5 and later that service is the Norwegian Meteorological Institute (MET Norway) and sunrise and sunset are calculated on your device rather than requested; in version 1.0.4 it was Open-Meteo (Switzerland) and sunrise and sunset were requested too. Both are disclosed, as Transfers 4 and 5 in Section 10. The new Section 4.5 states what is sent, that no identifier accompanies it, that nothing from it reaches or is stored on our servers, and how to turn it off; Section 2 summarises it; Section 5 adds the location permission; Section 8 adds MET Norway as a recipient that is not our processor; Section 10 adds the Korean international-transfer disclosures (PIPA §28-8) as Transfer 4 (MET Norway, versions 1.0.5 and later) and Transfer 5 (Open-Meteo, version 1.0.4). The effective date moved from 2026-08-10 to 2026-08-11 so that the full seven days' notice under Section 14 runs from this addition. Second, this version brought our website at snora.app into the scope of this Policy, which previously described only the app. The website was already hosted by Vercel Inc. (United States) and already used Vercel's cookie-free web analytics, including one named click event recording which app store badge was tapped; none of that was disclosed here. The new Section 4.4 states what the hosting and the analytics receive, that no cookies are set and no account identifier is involved, that Vercel states it does not store the IP address with an analytics event, the legal basis (legitimate interest), and, separately as Article 21(4) GDPR requires, the right to object. Section 2 notes that visiting the website is separate from the app; Section 4 adds the website row and counts four processors instead of three; Section 6 adds the purpose; Section 7 extends the legitimate-interest basis to it; Section 8 adds Vercel as a processor; Section 10 adds the Korean international-transfer disclosure (PIPA §28-8) as Transfer 3 and adds Vercel to the EEA/UK transfer basis; Section 11 states the retention. No change was made to the app or to what it collects.
- v1.2 (last updated 2026-07-27, effective 2026-08-03): two changes. Crash reporting shipped with app version 1.0.4; the encrypted backup ships with Snora Plus, in a later app version. Added the optional end-to-end encrypted backup for Snora Plus: Sections 2 and 3 condition the former absolute statement that sleep, rhythm, Wake Confidence, and condition data "never leave your device" on this single, opt-in exception, in which the data is encrypted on your device with a key that only you hold and reaches us only as ciphertext we cannot decrypt; Section 4 adds the backup to the data table; Section 6 adds the purpose; Section 7 states the legal bases, including explicit consent for any health-related content inside the ciphertext; Sections 10, 11, and 12 state where it is stored (Korea), how long it is kept, that it is deleted with the backup toggle or with your account, and that a lost recovery code cannot be reset or recovered by anyone, including us. Restoring an existing backup never requires a paid plan. Added crash reporting through Sentry (Functional Software, Inc., United States) as a processor: the new Section 4.3 describes exactly what a crash report contains (stack trace, device model, operating system and version, app version and build, and a stripped trail of recent technical steps), how the app holds it to that list by keeping only a fixed set of fields and discarding the wider device detail the reporting library collects by default, what it never contains (no account identifier attached by us, no IP address stored with the report, no request headers, cookies, or bodies, no console output, no free text, no sleep or alarm data, no performance tracing, no session replay), and, separately, that reports written by the operating system's own crash handler are assembled outside the app and can carry a platform-recorded trail we cannot filter; Section 4.3 also states, separately as Article 21(4) GDPR requires, the right to object to crash reporting; Section 8 adds Sentry as a processor; Section 10 adds the Korean international-transfer disclosure (PIPA §28-8) for the transfer to Sentry and the EEA/UK transfer basis; Section 11 adds the 90-day retention.
- v1.1 (last updated July 17, 2026, effective July 24, 2026): added Section 4.1 (payments and subscriptions: Apple and Google take the payment and we never receive card details; RevenueCat, Inc., in the United States, is our processor for receipt validation and subscription state, and Section 4.1 lists exactly what it receives, when, why, and for how long) and Section 4.2 (product analytics events, including the paywall and plan-interest signals, limited to counts, fixed options, and true/false values, never free text). Section 8 adds RevenueCat as a processor. Section 10 adds the Korean international-transfer disclosure (PIPA §28-8) for the transfer to the United States, and the EEA/UK transfer basis. Section 11 states what account deletion does and does not reach. The earlier statement that we validate receipts on our own server has been corrected: we do not. The scope and sync wording no longer assume a companion web application is in operation.
- v1.0 (July 1, 2026): Initial publication.