Version: 1.6 Effective date: 2026-09-27 Last updated: 27 September 2026 Applies to: the Snora mobile application (iOS and Android), our website at snora.app, and any companion web application we may offer there (together, the "Service").
What changed in version 1.6: one optional feature, off until you turn it on. The app can read the sleep that your watch or other apps saved to Apple Health (iPhone) or Health Connect (Android) and show those nights in your sleep report; it keeps that copy in the app and does not send it to our servers, our encrypted backup, or the AI features in Section 4.6 (Sections 3 and 5). It adds no recipient and nothing new reaches our servers, so it takes effect on the date above, the day it was published.
What changed in version 1.5: three optional features, each off until you turn it on (night sound analysis and the AI sleep coach arrive in later app updates). AI wake-up call: your spoken answer becomes text on your phone; the text goes via our backend in Korea to OpenAI, and the reply to Eleven Labs for the voice. AI sleep coach: with separate consent, a daily summary of recent nights goes to OpenAI. Microphone: for those answers and, if you choose, night sounds analysed on your phone; no audio is saved or sent. Section 4.6 sets out exactly what is sent and what is not, and Sections 4, 5, 8, 10, and 11 add the two companies, the permissions, the two overseas transfers, and the retention. We also corrected our description of on-device storage: the app keeps that data in its private storage on your phone, not in a separately encrypted form. This change takes effect on the date above, and nothing is sent to either company under it before then.
What changed in version 1.4: one thing, and it concerns the website only. Until now, the visit counting on snora.app was done entirely by Vercel, our host. From the effective date above, the website also counts visits itself, on our own backend in Korea, with no analytics provider involved (the request still passes through our host, Vercel, already named in Section 8). It records less than the Vercel analytics already record: no IP address, no coarse location, no device or browser details, and still no cookies. To tell one visit apart from several page views, your browser holds a random value that it erases when you close the tab, which means a returning visitor cannot be recognised and the resulting number counts sessions, not people. Records are deleted after 180 days. Section 4.4 sets out exactly what is stored and what is not, Section 11 states the retention, and Sections 8 and 10 confirm that this adds no new recipient and no transfer outside Korea. Nothing about the app itself changed in this version. This change takes effect on the date above, and we do not collect anything under it before then.
What changed in version 1.3: two things, and both are described here rather than in a separate version. First, local sunrise and weather. If you allow location access, the app sends your approximate coordinates, rounded to about one kilometre, directly from your device to the Norwegian Meteorological Institute (MET Norway), and nothing else: no account identifier and no app data. In app versions 1.0.5 and later, sunrise and sunset are calculated on your device and are not requested from anyone. Your coordinates never reach our servers, we store nothing from it, and the feature is off until you allow location. The new Section 4.5 sets out exactly what is sent, and Sections 5, 8, and 10 add the permission, the recipient, and the overseas-transfer disclosure. This describes behaviour that was already in the app; the Policy simply did not name it before. Second, this Policy now also covers our website at snora.app, which it previously did not describe at all. The website is hosted by Vercel, and it uses Vercel's cookie-free web analytics to count page views and a small number of clicks, such as which app store badge was tapped. No cookies are set, nothing is stored on your browser for this, and none of it is linked to your Snora account or to any app data. The new Section 4.4 sets out exactly what is collected, and Sections 8, 10, and 11 add Vercel as a processor, disclose the transfer to the United States, and state the retention. Nothing about the app itself changed in this version.
What changed in version 1.2: two things. Crash reporting arrived with app version 1.0.4. The encrypted backup arrives with Snora Plus, in a later app version. First, Snora Plus will offer an optional end-to-end encrypted backup: if you turn it on, your sleep history, alarms, and settings are encrypted on your device, with a key that only you hold, and stored on our backend as ciphertext we cannot decrypt (Sections 2, 3, 4, 6, 11, and 12). Restoring an existing backup never requires a paid plan. Second, when the app crashes, it now sends a crash report to Sentry (Functional Software, Inc.), a crash-reporting provider in the United States; a report carries the technical crash details, and the app attaches no account identifier to it (Sections 4.3, 8, and 10). Your sleep, rhythm, Wake Confidence, and condition data still never leave your device in a form we can read, and we still do not sell your data or use advertising trackers.
1. Who we are
Snora is operated by WorkNPLAY Inc., a company established under the laws of the Republic of Korea and the publisher of the Snora app ("Snora," "we," "us," or "our"). We are the controller of the limited personal data described in this Policy. You can contact us, including for any data-protection matter, at contact@snora.app.
For any privacy question or request, contact us at contact@snora.app or through snora.app.
2. Our privacy approach in one paragraph
Snora is designed to keep your most personal information on your device. Your sleep logs, your wake/bedtime rhythm, and any condition tags you choose to add never leave your device in a form we can read, except what you choose to send to the AI features in Section 4.6. Apart from those AI features, which you turn on yourself and which send only the items listed there, the only way any of that data ever reaches our servers is the optional end-to-end encrypted backup (Section 4): if you turn it on, your device encrypts the data with a key that only you hold, and what we store is ciphertext we cannot decrypt. Beyond that, what we keep on our backend is a minimal set of account-related data (your account identifier, your consent history, your subscription status) plus non-sensitive product analytics events that tell us which features are used, never what your data says (Section 4.2). If the app crashes, a technical crash report, to which we attach no account identifier, goes to Sentry, a crash-reporting provider in the United States (Section 4.3). Payments run through the App Store and Google Play, so we never receive your card details, and the purchase itself is validated for us by RevenueCat, a subscription-infrastructure provider in the United States, which is where your subscription state is kept (Sections 4.1 and 10). If you allow location access so the home screen can show local sunrise and weather, your approximate coordinates, rounded to about one kilometre, go directly from your device to a national weather service, never to us. In app versions 1.0.5 and later that service is the Norwegian Meteorological Institute (MET Norway) and sunrise and sunset are calculated on your device rather than requested; in 1.0.4 it was Open-Meteo and sunrise and sunset were requested too (Section 4.5). Visiting our website, snora.app, is separate from all of this: it sets no cookies, it knows nothing about your app account, and it counts page views and a few clicks through Vercel's cookie-free analytics and, from version 1.4 of this Policy, through our own counting on our backend in Korea, which stores less and involves no analytics provider (Section 4.4). We do not use advertising trackers, we do not sell your data, and we do not build advertising profiles.
3. What stays only on your device (we cannot read this, except what you send to the AI features)
The following data is created, processed, and stored locally on your device, and is never transmitted to Snora's servers in a form we can read, unless you turn on an AI feature in Section 4.6, which sends only the items listed there. Apart from that, the only way any of it ever reaches our servers is the optional end-to-end encrypted backup described in Section 4: you turn it on yourself, the data is encrypted on your device with a key that only you hold, and what we store is ciphertext we cannot decrypt. This on-device data is:
- Sleep logs and timing data you record or that the app derives locally.
- Rhythm / regularity data (your wake and bedtime patterns over time). Bedtime and wake time for recent nights are part of the AI sleep coach summary if you turn it on.
- Alarm checks: whether notification, battery, and alarm permissions are set so alarms can ring.
- Condition tags you optionally tap (for example, "stress" or "caffeine").
- Sound analysis during sleep tracking, if you turn it on: the microphone is analysed on your device and no audio is saved or sent. Only the times and counts of sounds such as snoring are kept on your phone; if you also turn on the AI sleep coach, the daily count is part of its summary (Section 4.6).
- Sleep imported from Apple Health or Health Connect, if you turn it on: the app reads sleep records (when you fell asleep, when you woke, and sleep stages) that your watch or other apps saved there, and keeps a copy in the app to show in your sleep report. This copy is not sent to our servers, is not included in Snora's encrypted backup, and is not sent to the AI features in Section 4.6. Turning the setting off deletes the copy. Like other app data, the copy can be included in your phone's own system backup (iCloud on iPhone, Google on Android), which we do not control.
Because this data lives only on your device, any backup of it is ciphertext to us, and what the AI features in Section 4.6 send passes through our backend without being stored, we cannot access it, read it, or provide a readable copy of it; it is under your control. You can erase all of it by deleting the app data or uninstalling the app (see Section 11); if you turned on backup, the encrypted backup is deleted separately, in the app or together with your account (Section 11).
4. What we collect on our backend (only as needed for the Service)
We rely on six processors: Supabase for our database and authentication (it also stores the optional encrypted backup described below), RevenueCat for purchases and subscription state (Section 4.1), Sentry for crash reports (Section 4.3), Vercel for hosting our website and its cookie-free analytics (Section 4.4), OpenAI for the replies and notes of the AI features, and Eleven Labs for the wake-up call's voice (Section 4.6). We collect and store the following limited data only when you sign in, when you use a feature that requires it, for crash reports when the app crashes, or, for the website, when you visit snora.app:
| Data | What it is | Why we collect it |
|---|---|---|
| Account identifier | An anonymous user ID by default. You may optionally upgrade your account by adding an email address or signing in with a third-party OAuth provider. | To create and identify your account so settings/entitlements can sync across your devices. |
| Consent records | An append-only ledger recording which optional data permissions you granted and when (timestamps). | To keep an accurate, auditable record of your choices and to honor them. |
| Subscription / entitlement status | Your entitlement (free or Plus), the purchase it comes from (product, store, purchase and expiry dates, renewal state, trial state, price and currency the store charged, country and store metadata), and your account identifier. This record is held for us by RevenueCat, in the United States (Sections 4.1, 8, and 10). Your device also keeps a copy of the last confirmed answer (free or Plus) so that Plus keeps working when you are offline. | To validate the purchase with Apple or Google, to grant and maintain access to paid features, and to end that access when a subscription expires, is refunded, or is revoked (Section 4.1). |
| Product analytics events | Non-sensitive product signals: an event name from a fixed list, plus properties limited to counts, fixed options, and true/false values. Never free text. | To understand which features are used and whether people want a paid plan, and to fix problems (Section 4.2). |
| Encrypted backup (optional, Snora Plus) | If you turn on Backup, the app uploads an end-to-end encrypted copy of your on-device data (your sleep history, alarms, and settings). It is encrypted on your device, before upload, with a key that only you hold; what we store is the resulting ciphertext plus technical metadata (size, timestamps, app version). We cannot decrypt, read, or recover its contents, and we cannot reset or recover your recovery code. | To let you restore your data when you get a new device or reinstall the app. Restoring an existing backup never requires a paid plan. Kept until you delete the backup or your account (Section 11). |
| Crash and diagnostic reports | If the app crashes or hits an unexpected error, a technical report goes to our processor Sentry in the United States: the stack trace, basic device and system information (device model, operating system and version, app version and build), the time, and a stripped trail of recent technical steps. We attach no account identifier, and it carries no message text and nothing you entered (Section 4.3). | To find and fix crashes and errors so that alarms and the app stay reliable. Reports are deleted after 90 days. |
| Website analytics (snora.app) | When you visit our website, our processor Vercel records the page you viewed, the referring site, and coarse device and country information, plus a small number of named clicks such as which app store badge you tapped. Separately, and from version 1.4 of this Policy, we count visits ourselves on our own backend in Korea, storing less than the above: which page you viewed (one entry from a fixed list of the site's pages, never the address you typed), the time on our server, a random token your browser erases when you close the tab, your browser's language, the host name that linked you here, and, for a badge click, which of the two stores it was. No cookies are used, no account identifier is involved, no IP address is stored, and none of it is linked to the app or to anything above (Section 4.4). | To see which pages of the website people read and whether the download links work, so we can improve the site. |
| AI feature usage records (Snora Plus) | When you use the AI wake-up call or the AI sleep coach, our backend records the time, which feature, how many turns or notes were used, and the result of the Snora Plus check, tied to your account identifier. It records nothing you said, no reply, and no sleep data. | To enforce the usage limits and the one-time preview, so the features stay reliable and affordable. Deleted on the schedule in Section 11. |
We do not collect or store, on our servers, in any form we can read: your sleep logs, rhythm data, condition tags, health data, precise location, contacts, browsing history, advertising identifiers, your card or payment-method details, or the labels and times of your alarms. If you turn on the optional encrypted backup, your sleep history, alarms, and settings are inside it, but only as ciphertext we cannot decrypt. The daily sleep summary you choose to send to the AI sleep coach, and the text of your answers in an AI wake-up call, pass through our backend to OpenAI and are not stored by us (Section 4.6).
4.1 Payments and subscriptions (including RevenueCat)
Snora Plus is sold as an in-app purchase through the App Store and Google Play. Those stores take the payment, not us. Checking that a purchase is genuine, and keeping track of whether a subscription is still active, is done for us by RevenueCat.
Apple and Google (payment).
- We never receive, see, or store your card number, bank details, or payment method. Apple and Google handle payment data as independent controllers under their own privacy policies.
- We do not receive your name, billing address, or store account email from the stores.
- Your invoices, order history, and refunds live in your Apple or Google account, not in Snora. See our Terms of Service, Section 7.
RevenueCat (receipt validation and subscription state).
We use RevenueCat, Inc., a company based in the United States, as our processor for in-app purchases. It is the service that checks your purchase with Apple or Google and tells our app whether your Plus access is active. We do not run our own receipt-validation server.
- What RevenueCat receives from the app: the store's receipt or purchase token and the associated transaction and product identifiers; your Snora account identifier (the same anonymous or signed-in account id described above, used as your customer id at RevenueCat); the entitlement, plan, price, currency, purchase and expiry dates, trial and renewal state reported by the store; and technical metadata that comes with the request, namely the platform, operating system and app version, the store, the country the purchase or request is associated with, and the IP address the request is made from, which RevenueCat uses to determine your country and to operate the service. It does not receive your card details (nor do we), and it does not receive your sleep, rhythm, or condition data, in any form; the optional encrypted backup (Section 4) never goes to RevenueCat.
- When it happens: when you buy or restore a purchase, when the store tells RevenueCat that your subscription renewed, expired, or was refunded, and when the app starts and asks whether your Plus access is currently valid. That last check runs for every user of a version that offers Plus, including users who never buy anything, because the app has to know which state it is in and what the plans cost in your currency.
- Why: to validate the purchase against Apple or Google, and to hold the resulting subscription state, so that paid features open only for people who actually paid and close again when a subscription ends. Your Plus access is granted only on the strength of that server-verified answer.
- Where: on RevenueCat's infrastructure in the United States. See Section 10 for the international-transfer disclosure.
- How long: RevenueCat keeps the customer record and its purchase history while your Snora account exists. When you delete your Snora account, we ask RevenueCat to delete the customer record it holds for you (Section 11). Apple and Google keep their own record of the transaction under their own policies and as commerce and tax law requires, and neither we nor RevenueCat can delete that.
- RevenueCat processes this data on our behalf and on our instructions, under a data processing agreement. We do not permit it to use your data for its own advertising, and no advertising or tracking identifier is sent to it by Snora.
4.2 Product analytics events
The app sends a small number of product analytics events to our backend, tied to your account identifier. They are designed so that they cannot carry anything sensitive:
- What an event contains: an event name from a fixed, predefined list (for example, opening the app, creating an alarm, confirming a wake, viewing the paywall), the time it happened, and properties that may only be counts, fixed options from a predefined list, or true/false values.
- Paywall signals. Where Snora Plus is offered, events include a paywall view (which part of the app you opened it from, chosen from a fixed list, and whether you are already on Plus) and a plan interest signal (which plan you tapped: monthly, annual, or lifetime). These tell us whether a paid plan is wanted. They are not a purchase and do not charge you.
- What an event never contains: free text of any kind, your alarm labels or alarm times, your sleep, rhythm, or condition data, the content of your consents, prices, or any contact detail.
- These events are write-only: the app can add them but cannot read them back, and they are readable only by us, for product and reliability analysis.
- We do not use these events for advertising, for cross-app tracking, or to build a profile about you, and we do not share them with advertisers or data brokers.
4.3 Crash and diagnostic reports (Sentry)
Versions of the app that include crash reporting (1.0.4 and later) use Sentry, a crash-reporting service operated by Functional Software, Inc., a company based in the United States, as our processor for crash diagnostics. When the app crashes, or hits an unexpected error it cannot recover from on its own, a technical report is sent to Sentry so that we can find and fix the problem.
- What a report contains: the technical stack trace (which part of the app's code failed), basic device and system information (device model, operating system and version, app version and build), the time of the crash, and a short trail (at most 30 entries) of recent technical steps, each stripped down to its kind, category, severity level, and time.
- How we keep it to that list: the crash-reporting library collects far more device detail by default, including screen size, memory, free storage, battery and charging state, orientation, locale and time zone, and a device identifier. Before a report leaves the app we discard all of it and keep only the three items named above: the device model, the operating system and its version, and the app version and build. We do this with a fixed list of what may be kept, so anything the library adds in a future version is dropped unless we review it and update this Policy.
- What a report never contains: your account identifier (not even the anonymous one), your name or email, request headers, cookies, or request bodies (we remove them), console output (we drop it entirely, because it could carry text), any message text or attached data in the step trail (we strip those fields), and, as always, your sleep, rhythm, or condition data, your alarm labels or times, and free text of any kind. The app never tells the crash reporter who you are: it sets no account identifier on it at any point, and reports sent by the app also have the user field removed before sending. We configure the reporting library not to attach your IP address or other default identifiers to the report.
- Crashes handled by the operating system. If the app is terminated by a low-level crash, by an "application not responding" timeout, or by the system watchdog, the report is written by the platform's own crash handler and sent the next time you open the app, without passing through the filtering step described above. Those reports still carry no account identifier and no request data, and no sleep, alarm, or console content, because the app never places any of it in the crash reporter. They do carry the device and system details the platform collects and a trail of technical steps recorded by the platform itself, which can include app lifecycle, screen changes, and network requests to our backend. A network entry of that kind can contain the address of a request, and such an address can include your account identifier. We cannot filter these entries from inside the app, so we disclose the possibility here rather than claim otherwise. They are subject to the same 90-day deletion.
- What we deliberately leave off: performance tracing is turned off entirely (its sample rate is zero), and we do not use session replay, so no screen recording or interaction capture takes place.
- When: only when a crash or unexpected error occurs. There is no background or periodic reporting.
- Where and how long: on Sentry's infrastructure in the United States (Section 10). Crash reports are retained for 90 days and then deleted automatically. Because reports are not filed under your account identifier, we cannot reliably find "your" crash reports in order to show or delete them; they age out on their own.
- Sentry processes this data on our behalf and on our instructions, under a data processing agreement. We do not permit it to use this data for its own purposes, and no advertising or tracking identifier is sent to it by Snora.
Your right to object to crash reporting. We process crash reports on the basis of our legitimate interest in keeping Snora and its alarms reliable (Article 6(1)(f) GDPR, Section 7). You have the right to object to this processing at any time on grounds relating to your particular situation. To object, email contact@snora.app. This notice is given separately from the rest of this Policy, as Article 21(4) GDPR requires.
4.4 Our website at snora.app
This Section is about the website, not the app. Visiting snora.app does not involve your Snora account, and nothing described here is linked to the app data in the rest of this Policy.
Hosting. The website is hosted by Vercel Inc., a company based in the United States, acting as our processor. As with any web host, its servers necessarily receive the technical details every browser sends in order to be served a page: your IP address, the page requested, your user agent (browser and operating system), and the referring page. Vercel keeps short-lived operational logs of these requests for security and to keep the site running.
Cookie-free analytics. The site uses Vercel Web Analytics. We chose it because it works without cookies: it does not set a cookie, it does not write an identifier into your browser's storage, and there is therefore no cookie banner and nothing to consent to on the grounds of terminal-equipment access.
- What an event contains: the page path you viewed, the referring source, the approximate location derived from the request (country and region level, not an address), the device type, the operating system, the browser, and the time. Where a link carries campaign parameters (
utm_*), those are recorded too. - Named clicks. In addition to page views, the site records with Vercel a small, fixed set of named events. At present there is one:
store_badge_click, recorded when you tap the App Store or Google Play badge, with a single property saying which of the two it was. It contains no free text and nothing about you. - What it never contains: your name, your email, your Snora account identifier (the website has no way to know it), your sleep, rhythm, or condition data, or any free text.
- Your IP address. Vercel uses the incoming request to derive the country and a visitor hash that is rotated regularly, so that repeat views can be counted without identifying you. Vercel states that it does not store the IP address with the analytics event. The IP address does still reach the server as part of the request itself, as described under Hosting above.
- Where: on Vercel's infrastructure, in the United States (Section 10).
- Advertising. These events are not used for advertising, for cross-site tracking, or to build a profile about you, and they are not shared with advertisers or data brokers. Vercel processes them on our behalf and on our instructions, under a data processing agreement.
Our own measurement. From version 1.4 of this Policy, the website also counts visits itself, with no analytics provider involved (the request still passes through our host, Vercel, already named in Section 8). We added this because the Vercel analytics above can be read only by opening a dashboard by hand, which is not something we can rely on. What we record here is less than what Vercel already records, it is stored on our own backend in Korea, and it is shared with no one beyond our host and our database provider, both already named in Section 8.
- What we store: which page you viewed, recorded as one entry from a fixed list of the site's pages, never as the address you typed. Blog posts are recorded as the blog-post page itself rather than the individual article, and any address that is not on that list (including one that does not exist) is recorded as a single
unknownentry, so a made-up address never becomes stored text. Also: the time, taken from our server rather than from your device; a one-way hash of a tab-session token described below; the first part of your browser's language setting (for exampleko, neverko-KR); the host name of the page that linked you here (for examplewww.google.com, never the full address); if you arrived through a link shared from the Snora app, the name of that sharing channel; and, when you tap a download badge, which of the two store badges it was. The named events are a fixed pair:page_viewandstore_badge_click. - The tab-session token. So that twenty page views are not counted as twenty visitors, your browser generates a random value that means nothing and keeps it in
sessionStorage, which the browser erases when you close the tab. It is not a cookie and nothing is written to permanent storage. Our server does not store that value itself: it stores a one-way hash of it, so whatever a browser puts in that field cannot be read back out of our database. Because a returning visitor gets a new value, we cannot recognise you on a later visit, and the number this produces is a count of sessions, not people. We describe it that way everywhere we use it. - What we never store: your IP address; any cookie or permanent identifier; the query string of the address you arrived at or came from; the full referring address; your name; your email; your Snora account identifier; your sleep, rhythm, or condition data; and any free text. The database rejects anything outside the fixed lists above, so free text cannot be stored even by mistake.
- Where: on our own backend, hosted by our processor Supabase on Amazon Web Services in Seoul, Republic of Korea (Sections 8 and 10). This adds no new recipient and no transfer outside Korea.
- Retention: 180 days, after which each record is deleted automatically by a scheduled job (Section 11).
- Advertising. As above, none of this is used for advertising, for cross-site tracking, or to build a profile about you, and none of it is shared with advertisers or data brokers.
- Obvious crawlers are recognised from the information browsers send about themselves, and are not recorded. This filter is partial: an automated visitor that describes itself as an ordinary browser cannot be told apart from one, so these counts still include some automated traffic. We would rather say so than imply a precision we do not have.
Legal basis (GDPR). For both the Vercel analytics and our own measurement, we rely on our legitimate interest (Article 6(1)(f)) in understanding which pages of our website are read and whether the download links work. Because both are cookie-free and carry no identifier we can tie to a person, and because the tab-session token is erased when you close the tab, this interest does not override your rights.
Your right to object to website analytics. You have the right to object to this processing at any time on grounds relating to your particular situation. To object, email contact@snora.app. You can block the Vercel analytics script with any content blocker, and you can stop our own measurement by blocking the address it posts to or by turning off JavaScript for this site. The website works normally in every case. This notice is given separately from the rest of this Policy, as Article 21(4) GDPR requires.
4.5 Local sunrise and weather (optional)
The home screen can show your local sunrise, sunset, and current weather. This is off unless you allow location access, and the app works normally without it.
This section describes app versions 1.0.5 and later. Version 1.0.4 behaved differently in two ways, and that version is still installed on many devices: the request went to Open-Meteo (OpenMeteo GmbH, Switzerland) instead of MET Norway, and it also asked for sunrise and sunset rather than calculating them on the device. Everything else was the same: approximate coordinates rounded to about one kilometre, no identifier attached, nothing stored on our servers. The overseas-transfer disclosure for that version is Transfer 5 in Section 10.
- Sunrise and sunset never leave your device. They are calculated on your device from your coordinates and the date. No request is made for them.
- What leaves your device, and only for the weather: your approximate coordinates, rounded to about one kilometre, and nothing else. No account identifier, no device identifier, no name, and no app data are attached. The app asks the operating system for low-accuracy location and uses your last known position when one is available.
- Who receives it: the Norwegian Meteorological Institute (MET Norway), a Norwegian government institute, through its public weather service. The app calls it directly from your device. It answers with the temperature, humidity, and precipitation for that area. It is not our processor and we hold no account with it. As its terms require, the app identifies itself in the request with its name, version, and our contact address, so that MET Norway can reach us if there is a problem.
- The city name shown next to the weather comes from your operating system's own geocoder (Apple or Google), not from us and not from MET Norway.
- What we store: nothing. The answer is cached on your device so the screen does not re-request it, and your coordinates are never sent to our servers, never stored on them, and never linked to your account.
- What MET Norway stores: its terms state that "the user's IP address will be stored in our logs, along with any possible geocoordinates used in requests", and that "All api.met.no access logs are stored in our own data center in Oslo, Norway." It does not publish a retention period for those logs. We tell you this because it is a different fact from the one above: we keep nothing, but the request still leaves a trace with them.
- Why the app calls it directly: MET Norway suggests routing calls through a proxy so that user IP addresses reach the proxy instead of MET. We do not do that, because it would send the same coordinates and IP to our servers instead, which is exactly what this feature is designed to avoid. The trade is deliberate: the request stays between your device and a national meteorological institute, and we never see it.
- Turning it off: revoke location access in your system settings. The card then stops requesting anything, and the app stops using even the cached answer.
Legal basis (GDPR). Your consent (Article 6(1)(a)), given through the operating system's location permission, which you can withdraw at any time in system settings.
4.6 AI wake-up call and AI sleep coach (optional)
Two optional features use AI companies. Each is off until you choose it, and the app asks for your agreement before anything is sent for the first time. The sound analysis described in Section 3 is not one of them: it runs only on your phone and sends nothing.
AI wake-up call (Snora Plus, with a one-time free preview). When an alarm you set as an AI wake-up call rings, a voice talks with you, and you choose how the call ends. Your phone turns your spoken answer into text on the device, and only that text is sent.
- What is sent: the text of your answer, the time, the name you asked to be called, a weather word such as "rain", and the voice persona you chose. It goes through our backend in Korea to our processor OpenAI, L.L.C. in the United States, which writes the reply. The reply text and the id of the chosen voice then go to our processor Eleven Labs Inc. in the United States, which turns it into speech.
- What is never sent: your voice recording, minute-by-minute data, sound timings, alarm labels, and your account identifier. No audio is saved.
- If something fails: the alarm still rings with its built-in sound, and you can always end the call.
AI sleep coach (Snora Plus, off until you agree). When a note is written or you ask a question, your phone sends a daily summary of your recent nights (bedtime, wake time, total sleep, estimated stage shares, a good, fair or poor rating for the night, regularity, count of sounds such as snoring, naps and alarm outcomes), your sleep goal and whether you set your schedule as irregular, your app language and time format, and your question, through our backend, to our AI processor OpenAI, L.L.C. in the United States. Recordings, minute-by-minute data, sound timings, alarm labels and your account identifier never leave your phone. We keep no copy. Notes are saved only on your phone. Turn it off in Settings: saved notes are deleted and nothing more is sent.
- What we keep: no copy of what you said, of the reply, or of your summary. Our backend keeps only the usage records in Section 4, for the periods in Section 11.
- What the two companies keep: OpenAI and Eleven Labs keep data under their own policies, published at openai.com/policies/privacy-policy and elevenlabs.io/privacy-policy.
- Turning it off: set your alarms back to a normal sound, and turn off the AI sleep coach in Settings.
Legal basis (GDPR). Your consent (Article 6(1)(a)) for the AI wake-up call, and your explicit consent (Article 9(2)(a)) for the AI sleep coach summary, which concerns your sleep. You can withdraw either at any time in the app; withdrawal does not affect processing already carried out.
Anonymous accounts
If you never add an email or use OAuth, your account identifier is an anonymous ID that does not, by itself, identify you as a natural person. If you later add an email or use OAuth, that identifier becomes linked to you, and this Policy's rights and protections apply to it.
5. Permissions the app requests
Snora requests only the permissions it needs to function. All are optional except notifications:
- Notifications: required to ring alarms. Without this, the core alarm function cannot work.
- Exact alarm scheduling (Android) and battery-optimization exemption (Android): requested so that alarms fire at the scheduled time and are not delayed or suppressed by the operating system's power-saving behavior.
- Health-data consent (optional): requested only if you choose to use optional condition tags. Any health-related input you provide is treated as on-device data (Section 3) and is not sent to our servers in a form we can read; it reaches them only inside the optional encrypted backup, as ciphertext (Section 4). You can decline this and still use the app's core features.
- Approximate location, while using the app (optional): requested only if you choose to see local sunrise, sunset, and weather on the home screen. The app asks for low-accuracy location, rounds the coordinates to about one kilometre, and sends only those rounded coordinates to the weather service described in Section 4.5. Sunrise and sunset are calculated on your device and are not requested from anyone. Your coordinates never reach our servers. Decline it, or revoke it later, and the rest of the app is unaffected.
- Microphone (optional): requested the first time you choose an AI wake-up call or turn on sleep sound analysis. Audio is processed on your phone and is not saved or sent (Sections 3 and 4.6).
- Speech recognition (iPhone, optional): turns your spoken answer into text on the device during an AI wake-up call.
- AI sleep coach consent (optional, Snora Plus): requested only if you turn on the AI sleep coach (Section 4.6). You can decline it and still use every other feature.
- Apple Health (iPhone) or Health Connect (Android), read-only (optional): requested only if you turn on sleep import. Snora reads sleep data only, does not write to them, and reads only while the app is open. You can turn it off in the app's settings, which deletes the imported copy, and remove the permission in the Health app or Health Connect at any time.
We do not request precise location, background or always-on location, contacts, or any advertising permission.
6. How we use data
We use the limited backend data in Section 4 only to:
- create, authenticate, and operate your account;
- sync your settings and entitlements across your devices;
- store, only if you turn it on, an end-to-end encrypted backup of your on-device data so that you can restore it on a new device. It is encrypted with a key that only you hold, so we cannot read it (Section 4), and restoring an existing backup does not require a paid plan;
- record and honor your consent choices;
- have our processor RevenueCat verify a purchase with Apple or Google, and grant, maintain, or end your subscription entitlement and access control (Section 4.1);
- understand, through the product analytics events in Section 4.2, which features are used and whether people want a paid plan, so we can decide what to build and what to charge for;
- find and fix crashes and errors, through the crash reports in Section 4.3, to which we attach no account identifier, so that the app and its alarms stay reliable;
- understand which pages of our website are read and whether its download links work, through the cookie-free analytics in Section 4.4, which are not linked to your account;
- provide, only if you choose them, the AI wake-up call and the AI sleep coach, and keep their use within the limits of your plan (Section 4.6);
- detect, prevent, and address security issues, fraud, abuse, or technical problems, including payment fraud and attempts to obtain paid features without paying;
- comply with legal obligations.
We do not use any data for advertising, behavioral tracking, cross-app profiling, or to make automated decisions producing legal or similarly significant effects about you. We never sell your personal information.
7. Legal bases for processing (GDPR / EEA, UK)
Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): to create and operate your account, sync your settings/entitlements, have the purchase verified with the store through our processor RevenueCat, and provide the subscription access you bought.
- Consent (Art. 6(1)(a)): for optional permissions and optional data (e.g., health-data consent for condition tags, the optional encrypted backup, which runs only after you turn it on and your choice is recorded in your consent ledger, and the AI wake-up call and AI sleep coach in Section 4.6). You may withdraw consent at any time (Section 9); withdrawal does not affect processing already carried out.
- Legitimate interests (Art. 6(1)(f)): to keep the Service secure, prevent abuse and payment fraud, maintain an accurate consent ledger, understand how features are used through the minimal, non-sensitive product analytics events in Section 4.2, and diagnose and fix crashes through the crash reports in Section 4.3, to which we attach no account identifier, so that we can improve the Service and decide what to offer. We keep those events limited to counts, fixed options, and true/false values precisely so that this interest does not override your rights. The same basis covers the cookie-free website analytics in Section 4.4, which carry no identifier we can tie to a person. You may object to this processing (Section 9), and Sections 4.3 and 4.4 set out your right to object to crash reporting and to website analytics separately.
- Legal obligation (Art. 6(1)(c)): where we must retain or disclose data to comply with law.
Optional health-related inputs, if any, are processed on your device under your explicit consent. If you turn on the encrypted backup, they can be included in it, but they reach our servers only as ciphertext we cannot decrypt, on the basis of your explicit consent (Art. 9(2)(a)); we never process special-category data on our servers in readable form, except the AI sleep coach summary, which passes through unstored on your explicit consent (Art. 9(2)(a)).
8. Sharing and processors
We do not sell, rent, or trade your personal data, and we do not share it with advertisers or data brokers. We use the following service providers, who process data on our behalf and under contract, only to provide the Service:
- Supabase: our backend infrastructure (database/auth) provider, acting as our processor. It hosts the limited account, consent, and analytics data described in Section 4, the website measurement described in Section 4.4, and, if you turn it on, the encrypted backup, which neither it nor we can read, on servers in Korea (Section 10). It is contractually bound to process this data only on our instructions.
- RevenueCat, Inc. (United States): our processor for in-app purchases. It receives the store receipt or purchase token, your account identifier, and the purchase, entitlement, and device/store metadata listed in Section 4.1, and it validates the purchase with Apple or Google and holds your subscription state. It acts only on our instructions, under a data processing agreement, and RevenueCat's own sub-processors (its cloud infrastructure providers) are engaged under that agreement. It is not an advertising company, and we send it no advertising identifier.
- Sentry (Functional Software, Inc., United States): our processor for crash reporting. When the app crashes, it receives the technical report described in Section 4.3: the stack trace, basic device and system information, and a stripped trail of recent technical steps, with no account identifier attached by us, no IP address stored with the report, and no free text (Section 4.3 explains the one case the app cannot filter, where the operating system's own crash handler writes the report). It acts only on our instructions, under a data processing agreement, retains reports for 90 days, and we send it no advertising identifier.
- Vercel Inc. (United States): our processor for hosting snora.app and for its cookie-free web analytics. Its servers receive the technical details of each request to the website (IP address, page, user agent, referrer), and its analytics record the page view, referring source, coarse location, device, operating system, browser, and a small fixed set of named clicks, as described in Section 4.4. It receives no account identifier, no app data, and no free text, it sets no cookies, it acts only on our instructions under a data processing agreement, and we send it no advertising identifier.
- OpenAI, L.L.C. (United States): our processor for the AI features. It receives the text of your spoken answer and the other call items, and, if you turn on the AI sleep coach, the daily summary and your question, as listed in Section 4.6, and it returns the reply or note. It receives no audio, no account identifier, and no alarm labels, it acts only on our instructions under a data processing agreement, and we send it no advertising identifier.
- Eleven Labs Inc. (United States): our processor for the voice of the AI wake-up call. It receives the reply text and the id of the voice you chose, and it returns audio. It receives nothing you said, no sleep data, and no account identifier, it acts only on our instructions under a data processing agreement, and we send it no advertising identifier.
- Norwegian Meteorological Institute (MET Norway), Norway: the public weather service the app calls directly from your device when you turn on local sunrise and weather. It receives your approximate coordinates, rounded to about one kilometre, and nothing else: no account identifier, no device identifier, and no app data. As its terms require, the app identifies itself with its name, version, and our contact address. It is not our processor, we hold no account with it, and nothing from that request reaches or is stored on our servers. Its own terms state that it stores the request's IP address and coordinates in access logs held in Oslo (Section 10, Transfer 4). Norway is part of the European Economic Area, so this involves no transfer outside the EEA (Section 10). Section 4.5 sets out exactly what is sent and what is kept.
- OpenMeteo GmbH (Open-Meteo), Switzerland: the weather service used by app version 1.0.4, which is still installed on many devices. It received the same approximate coordinates, rounded to about one kilometre, and nothing else, and it also answered the sunrise and sunset times that later versions calculate on the device. It is not our processor and nothing from that request reached our servers. Switzerland has an adequacy decision from the European Commission (Section 10, Transfer 5). App versions 1.0.5 and later do not contact it.
- Apple (App Store) and Google (Google Play): in-app purchases of Snora Plus are processed by the stores' billing systems. We never receive your card or payment-method details. Apple and Google process your payment data as independent controllers under their own privacy policies, and they hold your order history, invoices, and refunds. They also provide the receipt or purchase token that RevenueCat validates on our behalf (Section 4.1).
We may also disclose data if required by law, legal process, or a lawful government request, or to protect the rights, safety, or property of users, the public, or Snora.
9. Your rights
Subject to applicable law, you have the right to:
- Access the backend data we hold about your account;
- Correct inaccurate account data;
- Delete your backend account data ("right to erasure");
- Withdraw consent for any optional permission at any time;
- Object to or restrict certain processing;
- Data portability: receive your backend account data in a portable format, where applicable;
- Lodge a complaint with your data protection authority (in Korea, the Personal Information Protection Commission (PIPC); in the EEA/UK, your local supervisory authority).
On-device data (Section 3) is under your direct control: you exercise your "delete" right over it by clearing app data or uninstalling, since we cannot access it. If you use the optional encrypted backup, you can delete it in the app at any time, and it is deleted together with your account (Section 11).
California residents (CCPA/CPRA)
We do not sell or "share" (as defined under the CPRA) personal information, and we do not use it for cross-context behavioral advertising. California residents have the right to know, delete, correct, and to non-discrimination for exercising these rights. Because we do not sell or share, no "Do Not Sell or Share" action is required, but you may still contact us to exercise your rights.
To exercise any right, email contact@snora.app. We will verify your request reasonably (for anonymous accounts, this may require information that links you to the account) and respond within the period required by applicable law.
10. International data transfers
Snora is operated from the Republic of Korea. The account, consent, and analytics data described in Section 4, the website measurement described in Section 4.4, and the optional encrypted backup, are hosted by our processor Supabase on Amazon Web Services infrastructure located in Seoul, Republic of Korea (the AWS ap-northeast-2 region). The purchase and subscription data described in Section 4.1 is processed by RevenueCat in the United States, the crash reports described in Section 4.3 are processed by Sentry in the United States, and our website and its cookie-free analytics, described in Section 4.4, are hosted by Vercel in the United States. If you turn on local sunrise and weather, your approximate coordinates go directly from your device to a national weather service and never to our servers: MET Norway in Norway in app versions 1.0.5 and later, and Open-Meteo in Switzerland in version 1.0.4 (Section 4.5). If you use the AI features, the text described in Section 4.6 goes through our backend in Korea to OpenAI and Eleven Labs in the United States. Apart from those AI features, your on-device data leaves your device only if you turn on the encrypted backup, and then only as ciphertext we cannot decrypt, stored in Korea alongside the rest of our backend data.
Transfer of personal data abroad (PIPA Article 28-8)
Under the Korean Personal Information Protection Act, we must tell you, in this Policy, about any transfer of your personal data outside Korea. There are seven: the purchase and subscription data processed by RevenueCat (Section 4.1), the crash reports processed by Sentry (Section 4.3), the website request and analytics data processed by Vercel (Section 4.4); only if you allow location access, the approximate coordinates sent for local weather, which go to MET Norway in app versions 1.0.5 and later (Transfer 4) and went to Open-Meteo in version 1.0.4 (Transfer 5) (Section 4.5); and, only if you use the AI features, the text sent to OpenAI (Transfer 6) and to Eleven Labs (Transfer 7) (Section 4.6). The encrypted backup and the website measurement we do ourselves (Section 4.4) are not transferred abroad; they stay in Korea.
Legal basis for these transfers. Each transfer below is made under PIPA Article 28-8(1)3: the transfer is necessary to perform the contract with you and to respond to your requests, and each recipient acts as our processor under a written agreement that binds it to our instructions and to the protections this policy describes. We do not sell personal data and we do not transfer it abroad for any purpose beyond the ones stated in each table.
Transfer 1: RevenueCat (purchases and subscriptions)
| Item | Detail |
|---|---|
| Recipient | RevenueCat, Inc., United States. Privacy contact: as published at revenuecat.com/privacy |
| Country | United States (RevenueCat's cloud infrastructure) |
| When and how | Continuously while you use a version of the app that offers Snora Plus: when you buy or restore a purchase, when the store reports a renewal, expiry, or refund, and when the app checks your subscription state at start-up. Transmitted from the app over an encrypted (TLS) connection and, when you use an AI feature, from our backend, which asks RevenueCat whether your account has Snora Plus |
| Data transferred | Store receipt or purchase token and the transaction/product identifiers; your Snora account identifier; entitlement, plan, price, currency, purchase and expiry dates, trial and renewal state; platform, OS and app version, store, country, and the IP address of the request (Section 4.1). No card data. No sleep, rhythm, or condition data |
| Purpose | Validating the purchase with Apple or Google, and maintaining your subscription state so that paid features open and close correctly |
| Retention | While your Snora account exists. Deleted when you delete your account (Section 11), subject to the records Apple and Google keep independently |
| How to refuse, and what happens | You can refuse this transfer by not using a version of Snora that offers Snora Plus, or by uninstalling the app. Because the check is how the app knows whether you have paid, we cannot offer Snora Plus without it. The free tier of Snora works whether or not you ever buy anything, and your sleep data never becomes readable to us either way, except the AI coach summary you turn on (Transfer 6) (Sections 2 and 3) |
Transfer 2: Sentry (crash reports)
| Item | Detail |
|---|---|
| Recipient | Functional Software, Inc. (Sentry), United States. Privacy contact: as published at sentry.io/privacy |
| Country | United States (Sentry's cloud infrastructure) |
| When and how | Only when the app crashes or hits an unexpected error, in versions of the app that include crash reporting (1.0.4 and later). Transmitted from the app over an encrypted (TLS) connection |
| Data transferred | The technical stack trace; basic device and system information, limited to device model, operating system and version, and app version and build; the time of the crash; and a stripped trail of recent technical steps (kind, category, severity level, and time only) (Section 4.3). No account identifier. No IP address stored with the report. No sleep, rhythm, or condition data. No alarm labels or times. No free text. For crashes handled by the operating system's own crash handler, the report is assembled outside the app and additionally carries the device and system details the platform collects and the platform's own trail of technical steps, which can include a network request address containing your account identifier (Section 4.3) |
| Purpose | Diagnosing and fixing crashes and errors so that the app and its alarms stay reliable |
| Retention | 90 days from the report, after which it is deleted automatically |
| How to refuse, and what happens | Crash reports are sent only when the app crashes, and we attach no account identifier to them; this version of the app does not offer a separate switch for them. You can refuse this transfer by not using a version of the app that includes crash reporting, or by uninstalling the app. You can also object to this processing at any time by emailing contact@snora.app (Section 4.3). Refusing does not affect your account or your data |
Transfer 3: Vercel (website hosting and cookie-free analytics)
| Item | Detail |
|---|---|
| Recipient | Vercel Inc., United States. Privacy contact: as published at vercel.com/legal/privacy-policy |
| Country | United States (Vercel's cloud infrastructure) |
| When and how | Each time you open a page on snora.app. Transmitted from your browser over an encrypted (TLS) connection |
| Data transferred | The technical details every browser sends with a request: IP address, the page requested, user agent, and referrer; and, for analytics, the page path, referring source, coarse location (country and region), device type, operating system, browser, campaign parameters if the link carried any, and a small fixed set of named clicks such as which app store badge was tapped (Section 4.4). No cookies. No account identifier. No app data. No free text. Vercel states that the IP address is not stored with the analytics event |
| Purpose | Serving the website, keeping it secure, and understanding which pages are read and whether the download links work |
| Retention | Operational request logs for a short period, as required to run and secure the site; analytics for the limited period provided under our plan with Vercel, after which they are deleted. Neither is linked to your Snora account (Section 11) |
| How to refuse, and what happens | The hosting transfer is inseparable from visiting the website, so you refuse it by not visiting snora.app; the app works without it. You can refuse the analytics separately by blocking the analytics script with any content blocker, and the website works normally without it. You can also object at any time by emailing contact@snora.app (Section 4.4). Refusing does not affect your account, your app data, or your Snora Plus access |
Transfer 4: MET Norway (local weather, app versions 1.0.5 and later, only if you allow location)
| Item | Detail |
|---|---|
| Recipient | Norwegian Meteorological Institute (Meteorologisk institutt, MET Norway), Norway. Privacy contact: as published at met.no |
| Country | Norway (European Economic Area) |
| When and how | Only while local sunrise and weather is turned on, that is, only after you allow location access. The app requests a forecast at most a few times a day and caches the answer on your device. Transmitted from the app over an encrypted (TLS) connection |
| Data transferred | Your approximate coordinates, rounded to about one kilometre; the IP address the request is made from, which every network request carries; and an identifying string containing the app name, version, and our contact address, which MET Norway's terms require. No account identifier. No device identifier. No name. No sleep, rhythm, or condition data. No alarm labels or times. No free text. Sunrise and sunset are calculated on your device and are not requested (Section 4.5) |
| Purpose | Obtaining the temperature, humidity, and precipitation forecast for your area, so the home screen can show them |
| Retention | At the recipient: MET Norway's terms state that the IP address and any coordinates used in a request are stored in its access logs, held in its own data centre in Oslo. It does not publish a retention period for those logs. At Snora: nothing. The answer is cached on your device only, and nothing from this request reaches our servers |
| How to refuse, and what happens | Decline the location permission, or revoke it later in your system settings. The card then stops requesting anything, and every other part of the app, including alarms, sleep tracking, and Snora Plus, is unaffected |
Transfer 5: Open-Meteo (local sunrise and weather, app version 1.0.4 only, only if you allow location)
| Item | Detail |
|---|---|
| Recipient | OpenMeteo GmbH, Switzerland. Privacy contact: as published at open-meteo.com |
| Country | Switzerland (European Commission adequacy decision) |
| When and how | Only in app version 1.0.4, and only while local sunrise and weather is turned on. The app requested a forecast at most a few times a day and cached the answer on the device. Transmitted from the app over an encrypted (TLS) connection. App versions 1.0.5 and later do not contact this service |
| Data transferred | Your approximate coordinates, rounded to about one kilometre, and the IP address the request is made from. No account identifier. No device identifier. No name. No sleep, rhythm, or condition data. No alarm labels or times. No free text. Unlike later versions, this request also asked for the sunrise and sunset times (Section 4.5) |
| Purpose | Obtaining the sunrise, sunset, temperature, humidity, and precipitation forecast for your area, so the home screen could show them |
| Retention | At the recipient: Open-Meteo states that it does not store personal data from API requests and does not publish a retention period. At Snora: nothing. The answer was cached on the device only, and nothing from this request reached our servers |
| How to refuse, and what happens | Decline the location permission, or revoke it later in your system settings; or update to app version 1.0.5 or later, which contacts MET Norway instead. Every other part of the app, including alarms, sleep tracking, and Snora Plus, is unaffected |
Transfer 6: OpenAI (AI wake-up call and AI sleep coach, only if you use the AI features)
| Item | Detail |
|---|---|
| Recipient | OpenAI, L.L.C., United States. Privacy contact: as published at openai.com/policies/privacy-policy |
| Country | United States (OpenAI's cloud infrastructure) |
| When and how | Only while you use an AI feature: during an AI wake-up call, including the one-time preview, and, if you turn on the AI sleep coach, when a note is written or you ask a question. Sent from our backend in Korea over an encrypted (TLS) connection |
| Data transferred | For the wake-up call: the text of your spoken answer, the time, the name you asked to be called, a weather word, and the voice persona you chose. For the sleep coach: the daily summary of recent nights listed in Section 4.6 and your question. No audio. No account identifier. No minute-by-minute data, sound timings, or alarm labels. No IP address of yours, because the request comes from our backend |
| Purpose | Writing the replies in the AI wake-up call and the notes and answers of the AI sleep coach |
| Retention | Under the recipient's policy (openai.com/policies/privacy-policy). At Snora: nothing |
| How to refuse, and what happens | Do not choose an AI wake-up call and do not turn on the AI sleep coach, or turn them off in the app. Your alarms then ring with their normal sound, and every other part of the app is unaffected |
Transfer 7: Eleven Labs (voice of the AI wake-up call, only if you use it)
| Item | Detail |
|---|---|
| Recipient | Eleven Labs Inc., United States. Privacy contact: as published at elevenlabs.io/privacy-policy |
| Country | United States (Eleven Labs' cloud infrastructure) |
| When and how | Only during an AI wake-up call, including the one-time preview, each time a reply is spoken. Sent from our backend in Korea over an encrypted (TLS) connection |
| Data transferred | The reply text written for you, which can include the name you asked to be called, and the id of the voice you chose. Nothing you said. No sleep data. No account identifier. No audio from your phone |
| Purpose | Turning the reply into speech |
| Retention | Under the recipient's policy (elevenlabs.io/privacy-policy). At Snora: nothing |
| How to refuse, and what happens | Do not choose an AI wake-up call. Your alarms then ring with their normal sound, and every other part of the app is unaffected |
EEA and UK users
For users in the EEA or UK, storing data in Korea is a transfer to a third country. The Republic of Korea benefits from the European Commission's adequacy decision for Korea, and, for UK users, from the UK's corresponding adequacy arrangements where applicable. Norway, where MET Norway is based, is part of the European Economic Area, so the request described in Section 4.5 is not a transfer to a third country at all. Switzerland, where Open-Meteo is based, benefits from an adequacy decision, so the version 1.0.4 request needed no additional safeguard either. The transfers to RevenueCat, Sentry, Vercel, OpenAI, and Eleven Labs, all in the United States, are made under the Standard Contractual Clauses (or another lawful transfer mechanism provided for in each processor's data processing agreement, such as certification under an approved framework). In all cases we limit transferred data to the minimal account, consent, entitlement, and purchase data described in Section 4, the crash reports described in Section 4.3, the website request and analytics data described in Section 4.4, and the AI feature data described in Section 4.6; we do not transfer your sleep, rhythm, or condition data in readable form, except the AI sleep coach summary you choose to send (Transfer 6). If you turn on the optional encrypted backup, it is hosted in Korea, under the same adequacy basis, as ciphertext we cannot decrypt.
11. Data retention
- On-device data: retained on your device until you delete it. You can remove it by clearing app data or uninstalling the app; uninstalling deletes the locally stored, on-device data.
- Backend account data (account identifier, consent records, entitlement status): retained while your account is active and as needed to provide the Service. When you request deletion, or after a reasonable period of inactivity, we delete or de-identify it, except where we must retain certain records to comply with legal obligations or to resolve disputes. Consent records may be retained as a legal record of your prior choices for the minimum period required.
- Subscription / entitlement record (held by RevenueCat, Section 4.1): kept while your Snora account exists, so that your Plus access works across your devices and so that a lifetime purchase can be restored. When you delete your account, we ask RevenueCat to delete the customer record it holds for you (see below).
- The transaction itself (amount, payment method, invoice, refund) is held by Apple or Google, the merchants of the sale, not by us. They keep it under their own policies and under the tax and commerce law that applies to them. Neither we nor RevenueCat can delete those records, and deleting your Snora account does not remove them.
- Product analytics events (Section 4.2): retained while your account is active and deleted together with your account, automatically, when you delete it. We keep them no longer than we need them for the purposes in Section 4.2.
- Encrypted backup (optional, Section 4): kept while you keep backup turned on; each new backup replaces the previous one. It is deleted immediately when you delete the backup in the app, and it is deleted together with your account when you delete your account. Because it is end-to-end encrypted with a key that only you hold, a backup whose recovery code is lost is permanently unreadable, by you and by us, and we cannot reset or recover that code.
- Crash reports (Section 4.3): retained by Sentry for 90 days, then deleted automatically. Because they are not filed under your account identifier, they are not linked to your account and are not part of account deletion.
- Website data (Section 4.4): the operational request logs Vercel keeps in order to serve and secure snora.app are short-lived, and the cookie-free analytics are retained for the limited period provided under our plan with Vercel and then deleted. The measurement we keep ourselves is deleted 180 days after it is recorded, by a job that runs every day without anyone starting it. Because none of it carries an account identifier, none of it is linked to your Snora account, and none of it is part of account deletion.
- AI feature usage records (Section 4.6): usage records for the AI wake-up call are deleted after 35 days and for the AI sleep coach after 35 days, short-lived abuse-limit counters are deleted within 2 days, and the one-time preview marker and the result of the Snora Plus check are kept while your account exists. All of them are deleted with your account. We keep no copy of what you said, of any reply, or of your summary.
What deletion actually deletes. Deleting your account removes your account record, your consent records, any entitlement record on our own backend, your analytics events, your AI feature usage records, and your encrypted backup if you have one, and it sends RevenueCat a request to delete the customer record and purchase history it holds for your account. If that request cannot be completed at the time (for example, RevenueCat is temporarily unreachable), your Snora account is still deleted, and you can write to contact@snora.app to have the RevenueCat record removed. The purchase records held by Apple and Google are not affected, as described above.
Note that deleting your Snora account does not cancel a subscription with Apple or Google: cancel that in your store account settings first (see the Terms of Service).
12. Security
We use reasonable technical and organizational measures appropriate to the limited data we hold, including:
- Local-only storage of sleep, rhythm, and condition data in the app's private storage on your device;
- End-to-end encryption of the optional backup: it is encrypted on your device before upload, with a key that exists only on your device and in your recovery code, so our servers hold only ciphertext;
- Row-Level Security (RLS) on our backend so that account, consent, entitlement, and backup records are accessible only to the corresponding account;
- access controls and transport encryption (TLS) for data in transit to our backend;
- data minimization: we deliberately keep sensitive data off our servers.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Data protection officer / privacy contact (Korea, PIPA §31)
In accordance with the Personal Information Protection Act (PIPA) §31, we have designated a person responsible for personal-information protection and for handling your privacy inquiries and complaints:
- Privacy Officer: JEEHO SONG, Representative Director, WorkNPLAY Inc.
- Department: Privacy, WorkNPLAY Inc.
- Contact: contact@snora.app (please mark your message "Privacy")
You may direct any question, request, or complaint about your personal data to this contact, and you may also lodge a complaint with the Personal Information Protection Commission (PIPC) (Section 9).
Security-incident notification (PIPA §34)
If we become aware of a breach affecting personal data we hold on our backend, we will notify affected users and report to the competent authorities (in Korea, the Personal Information Protection Commission and the Korea Internet & Security Agency (KISA)) within the time and in the manner required by applicable law. Your sleep, rhythm, and condition data are never stored by us; the only readable data passing through is what you send to the AI features, which we do not keep, so a breach of our backend cannot expose their contents: the only copy we may hold is the optional encrypted backup, which is ciphertext that cannot be read without your recovery code.
13. Children
Snora is not directed to children. During onboarding, the app presents a self-attested age gate (14 or older). We do not knowingly collect personal data from anyone under the applicable minimum age (14 in Korea; 13 under COPPA in the United States; 16 or the lower age set by a member state under the GDPR). If you believe a child under the applicable age has provided us data, contact contact@snora.app and we will delete it.
14. Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will provide notice through the app or at snora.app at least 3 days before it takes effect, and where the change is unfavorable to you or where required by law, at least 30 days in advance. The "Last updated" date reflects the latest version. Continued use after the effective date constitutes acceptance, to the extent permitted by law.
15. Contact
WorkNPLAY Inc. (operator and data controller of Snora) Email: contact@snora.app Web: snora.app
Given Snora's current scale and the minimal, non-sensitive nature of the backend data we process (Section 4), we have determined that we are not required to designate an EU/UK representative under Article 27 of the GDPR at this time. If our processing changes such that a representative becomes required, we will designate one and identify them here.
Change history
- v1.6 (last updated 2026-09-27, effective 2026-09-27): one optional feature, off until you turn it on. Sleep import from Apple Health (iPhone) or Health Connect (Android), arriving in an app update: the app reads sleep records (when you fell asleep, when you woke, and sleep stages) that your watch or other apps saved there, only while the app is open, and keeps a copy in the app to show those nights in your sleep report. It writes nothing to Apple Health or Health Connect. Section 3 adds the imported copy to the list of data kept in the app and states that it is not sent to our servers, is not included in Snora's encrypted backup, and is not sent to the AI features in Section 4.6, and that the phone's own system backup can include it; Section 5 adds the read-only Apple Health or Health Connect permission, how to turn it off, and that turning it off deletes the copy. No processor, recipient, or overseas transfer is added and nothing new reaches our servers, so this is not a material change under Section 14 and it takes effect on the day it was published.
- v1.5 (last updated 2026-09-17, effective 2026-09-21): three optional features, each off until you turn it on. The AI wake-up call (app 1.1.0) sends the text of your spoken answer and a few call details through our backend in Korea to OpenAI, L.L.C. (United States) for the reply, and the reply to Eleven Labs Inc. (United States) for the voice. The AI sleep coach (a later app update, Snora Plus, separate consent) sends a daily summary of recent nights and your question to OpenAI. Night sound analysis (a later app update) runs on your phone and sends nothing. The new Section 4.6 sets out what is sent and what is not; Sections 2 and 3 limit the on-device statements accordingly; Section 4 counts six processors and adds the usage-records row; Section 5 adds the microphone, speech-recognition, and coach permissions and removes the microphone from the list of permissions we do not request; Sections 6 and 7 add the purpose and legal bases; Section 8 adds both companies; Section 10 counts seven transfers and adds Transfers 6 and 7; Section 11 adds the retention of the usage records; Sections 3 and 12 no longer say the on-device data is kept in encrypted form, which was not true of the app's local database. References to Wake Confidence, a status the app is retiring, were removed. Under Section 14 the notice period runs from the last-updated date above, and nothing is sent to either company before the effective date. Corrected before this version took effect (2026-09-18): Section 4.6 now also names the sleep goal, the irregular-schedule setting, the good, fair or poor rating for a night, and the app language and time format, which the daily summary has always carried. The list in 4.6 reads as a closed one, so leaving them out made it narrower than what the app actually sends. Nothing new is sent, and a test now checks that list against the fields in the code.
- Provider change (13 September 2026): the provider of Snora changed from Foo AI Corp. to WorkNPLAY Inc. following a transfer of app ownership. The company name, business registration number, address and mail-order sales registration number below are now those of the new company. What we collect, why, and your rights did not change.
- v1.4 (last updated 2026-08-17, effective 2026-08-25): one addition, concerning the website only, and made before this version takes effect. Until now, all visit counting on snora.app was done by Vercel; the only way to read it is to open a dashboard by hand, which is not a channel we can rely on. From the effective date the website also counts visits itself, on our own backend at Supabase in Seoul, with no analytics provider involved (the request still passes through our host, Vercel, already named in Section 8). Section 4.4 gains a block stating exactly what is stored (page path, server time, a tab-session token, the first part of the browser language, the referring host name, the app sharing channel if the link carried one, and which of the two stores a badge click was for, under the two fixed event names
page_viewandstore_badge_click), what is never stored (IP address, cookies or permanent identifiers, query strings, full referring addresses, account identifiers, app data, free text), that every field is constrained to a fixed shape and the named events to a fixed pair, so free text has nowhere to go, that the tab-session token is erased when you close the tab so the resulting figure counts sessions rather than people, that obvious crawlers are excluded by a filter that is only partial, and the 180-day retention. Section 2 summarises it; Section 4 extends the website row; Section 8 notes that Supabase hosts it; Section 10 confirms it is not transferred abroad and leaves the five existing transfer disclosures unchanged; Section 11 states the 180-day deletion. No new processor and no new overseas transfer, and no change to the app or to what it collects. Under Section 14 the notice period runs from the last-updated date above, and nothing is collected under this change before the effective date. Corrected before this version took effect (2026-08-18): the page path is now recorded as one entry from a fixed list of the site's pages rather than the address as typed, with anything unlisted recorded as a singleunknownentry. This stores strictly less than described above and makes the sentence about the database rejecting anything outside the fixed lists true of the path as well; it was not before, because the path was checked for shape rather than membership. - v1.3a (last updated 2026-08-12): presentation only. The Korean labels that ran alongside the English ones in the international-transfer tables and the privacy-officer block were removed, so every label now reads in English. No value, recipient, purpose, retention period, or right changed, and no notice period applies to a change that alters nothing about how data is handled.
- v1.3 (last updated 2026-08-04, effective 2026-08-11): two additions, both made before this version took effect. First, local sunrise and weather: the app has always sent approximate coordinates, rounded to about one kilometre, directly from the device to a public weather service when you allow location access, and none of it was disclosed here. In app versions 1.0.5 and later that service is the Norwegian Meteorological Institute (MET Norway) and sunrise and sunset are calculated on your device rather than requested; in version 1.0.4 it was Open-Meteo (Switzerland) and sunrise and sunset were requested too. Both are disclosed, as Transfers 4 and 5 in Section 10. The new Section 4.5 states what is sent, that no identifier accompanies it, that nothing from it reaches or is stored on our servers, and how to turn it off; Section 2 summarises it; Section 5 adds the location permission; Section 8 adds MET Norway as a recipient that is not our processor; Section 10 adds the Korean international-transfer disclosures (PIPA §28-8) as Transfer 4 (MET Norway, versions 1.0.5 and later) and Transfer 5 (Open-Meteo, version 1.0.4). The effective date moved from 2026-08-10 to 2026-08-11 so that the full seven days' notice under Section 14 runs from this addition. Second, this version brought our website at snora.app into the scope of this Policy, which previously described only the app. The website was already hosted by Vercel Inc. (United States) and already used Vercel's cookie-free web analytics, including one named click event recording which app store badge was tapped; none of that was disclosed here. The new Section 4.4 states what the hosting and the analytics receive, that no cookies are set and no account identifier is involved, that Vercel states it does not store the IP address with an analytics event, the legal basis (legitimate interest), and, separately as Article 21(4) GDPR requires, the right to object. Section 2 notes that visiting the website is separate from the app; Section 4 adds the website row and counts four processors instead of three; Section 6 adds the purpose; Section 7 extends the legitimate-interest basis to it; Section 8 adds Vercel as a processor; Section 10 adds the Korean international-transfer disclosure (PIPA §28-8) as Transfer 3 and adds Vercel to the EEA/UK transfer basis; Section 11 states the retention. No change was made to the app or to what it collects.
- v1.2 (last updated 2026-07-27, effective 2026-08-03): two changes. Crash reporting shipped with app version 1.0.4; the encrypted backup ships with Snora Plus, in a later app version. Added the optional end-to-end encrypted backup for Snora Plus: Sections 2 and 3 condition the former absolute statement that sleep, rhythm, Wake Confidence, and condition data "never leave your device" on this single, opt-in exception, in which the data is encrypted on your device with a key that only you hold and reaches us only as ciphertext we cannot decrypt; Section 4 adds the backup to the data table; Section 6 adds the purpose; Section 7 states the legal bases, including explicit consent for any health-related content inside the ciphertext; Sections 10, 11, and 12 state where it is stored (Korea), how long it is kept, that it is deleted with the backup toggle or with your account, and that a lost recovery code cannot be reset or recovered by anyone, including us. Restoring an existing backup never requires a paid plan. Added crash reporting through Sentry (Functional Software, Inc., United States) as a processor: the new Section 4.3 describes exactly what a crash report contains (stack trace, device model, operating system and version, app version and build, and a stripped trail of recent technical steps), how the app holds it to that list by keeping only a fixed set of fields and discarding the wider device detail the reporting library collects by default, what it never contains (no account identifier attached by us, no IP address stored with the report, no request headers, cookies, or bodies, no console output, no free text, no sleep or alarm data, no performance tracing, no session replay), and, separately, that reports written by the operating system's own crash handler are assembled outside the app and can carry a platform-recorded trail we cannot filter; Section 4.3 also states, separately as Article 21(4) GDPR requires, the right to object to crash reporting; Section 8 adds Sentry as a processor; Section 10 adds the Korean international-transfer disclosure (PIPA §28-8) for the transfer to Sentry and the EEA/UK transfer basis; Section 11 adds the 90-day retention.
- v1.1 (last updated July 17, 2026, effective July 24, 2026): added Section 4.1 (payments and subscriptions: Apple and Google take the payment and we never receive card details; RevenueCat, Inc., in the United States, is our processor for receipt validation and subscription state, and Section 4.1 lists exactly what it receives, when, why, and for how long) and Section 4.2 (product analytics events, including the paywall and plan-interest signals, limited to counts, fixed options, and true/false values, never free text). Section 8 adds RevenueCat as a processor. Section 10 adds the Korean international-transfer disclosure (PIPA §28-8) for the transfer to the United States, and the EEA/UK transfer basis. Section 11 states what account deletion does and does not reach. The earlier statement that we validate receipts on our own server has been corrected: we do not. The scope and sync wording no longer assume a companion web application is in operation.
- v1.0 (July 1, 2026): Initial publication.