Privacy Policy
This Privacy Policy explains how Simple Scale FZ-LLC ("DontSnooze", "we", "us") collects, uses, and shares personal data when you use the DontSnooze mobile application and the website at dontsnooze.io (together, the "Service"). DontSnooze is a social accountability alarm clock for iOS that uses photos as a personal stake to help you complete your morning challenges. When you complete your challenge on time, nothing is shared. If you miss a challenge, one photo automatically sampled from your iPhone library is shared with the followers you have accepted on the Service.
We are the data controller for personal data we process about you. If you have any question about this policy or your data, contact us at contact@simplescale.tech.
1. Data we collect
We collect only the data we need to operate the Service. Categories:
- Account & profile data: phone number (primary sign-in) or email address (fallback sign-in), display name, username, optional bio and avatar.
- Photos and videos from your iPhone library: when you grant Photo Library access, the app automatically selects random photos from your library and uploads them to a private server-side "punishment pool". You cannot preview, edit, or delete individual photos in the pool. The only way to avoid having a pool photo shared with your followers is to complete your challenges on time. You may stop new photos from being added at any time by revoking Photo Library access in iOS Settings → Privacy & Security → Photos → DontSnooze; existing pool photos remain until they are consumed by a failed challenge or until you delete your account. Photos in the pool stay private until a failed challenge triggers exposure to your accepted followers. We also store proof videos that you record and any thumbnails generated.
- User content: alarms and challenges you create, schedules, sub-tasks, streak counts, follow relationships, story reactions, witness records.
- Identifiers: account ID assigned by our backend, device push token, anonymous analytics ID.
- Device & diagnostic data: device model, OS version, app version, language, time zone, crash reports, and performance metrics.
- Product interaction: in-app events (screen opens, actions taken) associated with an anonymous analytics ID, used to improve the Service.
- Contacts (only if you grant permission): when you import contacts to find friends already on DontSnooze, we transmit hashed phone numbers and email addresses for matching. We do not store the underlying address book.
- Coarse location (only if you grant permission and only at the moment you record proof): captured to display where the proof was taken on a map. We do not track location in the background.
2. Why we use your data
- To create and operate your account, log you in, and authenticate requests.
- To provide core features: scheduling alarms, recording proof, exposing punishment-pool photos to your accepted followers when a challenge fails, sending push notifications related to your activity.
- To match you with friends already on DontSnooze (only if you grant Contacts permission).
- To send transactional messages (one-time codes, security alerts).
- To analyze aggregate usage of the Service, debug crashes, and improve the product.
- To enforce our Terms of Service, prevent abuse, respond to reports of objectionable content, and comply with legal obligations.
3. Legal bases for processing (GDPR)
- Performance of a contract: to deliver the features you signed up for.
- Legitimate interests: to keep the Service secure, prevent abuse, understand product usage, and improve features.
- Consent: for permissions you grant (camera, photo library, contacts, notifications, location). You can revoke consent at any time in iOS Settings.
- Compliance with legal obligation: to respond to lawful requests and protect users.
4. Who we share data with
We do not sell your personal data. We share limited data with the service providers that power DontSnooze, strictly to operate the Service:
- Convex Inc. — application backend and database. Stores account, user content, follow graph, and metadata. Privacy
- Cloudflare, Inc. — object storage for photos and videos (R2) and content delivery. Privacy
- PostHog Inc. — product analytics, feature flags, and crash diagnostics. We do not enable cross-app tracking; we use anonymous identifiers for analytics. Privacy
- Resend, Inc. — sending one-time codes by email. Privacy
- Amazon Web Services, Inc. — sending one-time codes by SMS via Amazon SNS. Privacy
- Mapbox, Inc. — map tiles for displaying proof locations. Privacy
- Tenor (Google LLC) — public GIF previews shown next to challenge templates. We do not share user data with Tenor; we cache public GIFs. Privacy
- Apple Inc. — Apple Push Notification service, App Store distribution. Privacy
We may also disclose data when required by law, to enforce our Terms, to protect rights, property, or safety, or as part of a merger, acquisition, or asset sale (with continued protection of your data).
5. International data transfers
DontSnooze is operated from the United Arab Emirates by Simple Scale FZ-LLC. Our providers process data in the United States, the European Union, and other regions. We rely on appropriate safeguards (such as the EU Standard Contractual Clauses and provider equivalents) for international transfers.
6. Retention
- Account & user content: kept while your account is active.
- Punishment-pool photos: auto-uploaded after you grant Photo Library access; kept until they are consumed by a failed challenge or until you delete your account. You cannot delete individual pool photos directly; revoking Photo Library access in iOS Settings stops new photos from being added.
- Exposed photos history: kept while your account is active so your followers can see your timeline.
- Push tokens, OTP codes: kept for as long as needed to deliver notifications and authenticate sign-in. OTP codes expire after 10 minutes.
- Diagnostic data: typically retained for 30–90 days.
- Backups: residual copies may persist in routine backups for up to 30 days after deletion.
When you delete your account (see Section 8), we permanently remove personal data within 30 days, except where law requires longer retention.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to processing or withdraw consent. For users in the European Economic Area, the United Kingdom, or Switzerland, rights derive from the GDPR / UK GDPR. For California residents, rights derive from the CCPA / CPRA. We do not "sell" or "share" personal data for cross-context behavioural advertising as those terms are defined under the CCPA.
To exercise any of these rights, email contact@simplescale.tech. You can also delete your account directly inside the app (Settings → Account → Delete Account) or via the web at dontsnooze.io/delete-account.
You may lodge a complaint with your local data protection authority. For the UAE, the relevant authority depends on the free zone; we will assist with any inquiry.
8. Account deletion
You can delete your DontSnooze account at any time from inside the app (Settings → Account → Delete Account) or via dontsnooze.io/delete-account. Deletion removes your profile, alarms and challenges, punishment-pool photos and proof videos in storage, follow relationships, stories, push tokens, and analytics person record. Residual data may persist in routine backups for up to 30 days, and we may retain a minimal record to comply with legal obligations or to resolve disputes.
You can also revoke Photo Library access at any time in iOS Settings → Privacy & Security → Photos → DontSnooze. After revocation no further photos will be added to your punishment pool. Photos already in the pool remain there until they are consumed by a failed challenge or until you delete your account.
9. Children
DontSnooze is not intended for children. The minimum age to use the Service is 17. If you are under 17, do not use DontSnooze. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact contact@simplescale.tech and we will delete it.
10. Security
We use industry-standard safeguards including TLS in transit, encryption at rest by our providers, capability-based signed URLs for private media, and least-privilege access for our team. No system is perfectly secure; if a breach affects you, we will notify you as required by law.
11. Tracking and analytics
DontSnooze does not engage in cross-app or cross-website tracking as defined by Apple's App Tracking Transparency framework. We do not request your IDFA. We use PostHog with anonymous identifiers to understand product usage in aggregate. You can disable analytics events in iOS Settings (Restrict Analytics) or by emailing contact@simplescale.tech.
12. Changes
We may update this Privacy Policy from time to time. Material changes will be announced in the app or by email. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the Service after a change becomes effective means you accept the revised policy.
13. Contact
Simple Scale FZ-LLC
Attn: DontSnooze Privacy
United Arab Emirates
contact@simplescale.tech