Privacy Policy
Last updated: August 2026
This Privacy Policy explains how Awakefit ("we," "us," "the app") collects, uses, stores, and protects your information when you use our iOS application. Awakefit is operated from the European Union ("the Operator"). If you have any questions about this policy, you can reach us at jar.appstudio@gmail.com.
We designed Awakefit to work with as little personal data as possible. This policy tells you exactly what we collect, why, and how you can control or delete it.
1. Data We Collect
1.1 Account data (synced to our cloud database, Supabase)
If you sign in with your Apple ID, the following is stored in our EU-hosted Supabase database, protected by row-level security so only you can access your own record:
- A unique account identifier and your Apple user ID (used only to link your account; we never see your real Apple ID email unless you choose to share it, and Apple may substitute a private relay address)
- Your display name (as entered during onboarding)
- Onboarding responses: self-reported age range (not date of birth), how many alarms you currently use, your typical wake-up struggles and goals, your chosen wake-up exercise and morning workout preferences, how you heard about us, and your selected subscription plan
- Your alarms: wake time, repeat days, assigned wake-up exercise, and alarm sound
- Your streak and workout data: current streak, longest streak, which calendar days you completed your wake-up mission, and optional morning workout completions (day and minutes, not video)
- Your overnight app-blocking schedule (start/end times relative to your alarm, and whether blocking is enabled), not which specific apps (see 1.2)
- Subscription/transaction metadata from Apple (transaction ID, product purchased, status, expiry). We never see or store your payment card details.
1.2 Data stored locally on your device only
- A local copy of your alarms, exercise history, and streak progress (using Apple's SwiftData framework)
- Which specific apps and app categories you've chosen to block overnight. This is stored only on your device using Apple's Family Controls framework as encrypted, opaque tokens. We do not know, and cannot see, the names of the apps you block.
- Your Screen Time authorization status and current lock/unlock state
1.3 Data processed on-device and never sent to us
- Wake-up workout camera check: when you complete a wake-up mission (e.g. squats, push-ups, burpees, or deadbugs — one of the app's built-in exercises), your camera feed is analyzed locally using Apple's on-device Vision framework (body pose detection) to check that you're moving and count your reps. Camera frames are not recorded, saved, or uploaded to our servers.
1.4 Data we do not collect
We do not collect: precise location, contacts, photos or camera roll, browsing history, your exact date of birth, video or image recordings of you, or the names of any apps you've chosen to block. We do not offer Facebook or Google login. Only Sign in with Apple.
2. Why We Process This Data (Legal Basis under GDPR)
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing your account and syncing alarms/streaks across devices | Account data (1.1) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Enabling overnight app blocking | Local + on-device data (1.2) | Consent, via Family Controls / Screen Time authorization (Art. 6(1)(a)) |
| Checking your wake-up workout via camera | On-device processing (1.3) | Consent, via camera permission (Art. 6(1)(a)) |
| Sending alarm and reminder notifications | Notification permission | Consent (Art. 6(1)(a)) |
| Processing your subscription | Transaction metadata | Performance of a contract (Art. 6(1)(b)) |
| Improving the app and diagnosing issues | Aggregated, non-identifying product analytics (PostHog, EU-hosted) and paywall analytics (Superwall, if active) | Legitimate interest (Art. 6(1)(f)) |
You can withdraw consent at any time (e.g., by revoking camera, notification, or Screen Time permissions in iOS Settings), though this may limit app functionality.
3. Third Parties We Share Data With
We work with a small number of service providers ("subprocessors") who process data on our behalf:
- Apple: Sign in with Apple, in-app purchases, Screen Time / Family Controls, on-device Vision-based pose detection, and push notifications. See Apple's Privacy Policy.
- Supabase: our database and authentication provider, hosting your account, alarm, and streak data in an EU region. See Supabase's Privacy Policy.
- Superwall (if enabled): used to display and test subscription paywalls. May receive device and app usage analytics, and paywall interaction events. See Superwall's Privacy Policy.
- PostHog (EU-hosted): product analytics to help us understand app usage and improve the experience. See PostHog's Privacy Policy.
We do not sell your personal data to anyone.
4. International Data Transfers
Your account data is stored in an EU region via Supabase, and product analytics are processed on PostHog's EU servers. Some subprocessors (Superwall, Apple) may process data in the United States. Where this occurs, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards as recognized under GDPR Chapter V.
5. Your Rights
Under GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict or object to certain processing
- Port your data to another service
- Withdraw consent at any time
To exercise these rights: Use the Delete Account option in the app's Settings screen, which permanently removes your cloud data (subscription, alarm, and streak records) and wipes all local data from your device. You can also email us at jar.appstudio@gmail.com for any of these requests, including data access or correction requests that aren't covered by the in-app deletion flow.
Note: Apple may independently retain in-app purchase transaction records for its own accounting and legal obligations, separate from our deletion of your account.
6. Data Retention
We retain your account data for as long as your account is active. If you delete your account, your profile, alarm, and subscription records are permanently deleted from our database immediately. Local data on your device is wiped at the same time.
7. Children's Privacy
Awakefit is not directed at children under 16. Because several features rely on your own consent as the legal basis for processing (e.g., camera access, notifications, Screen Time authorization), and German law requires a user to be at least 16 to give this consent themselves (Art. 8 GDPR), we do not knowingly collect personal data from, or offer accounts to, users under 16. Our onboarding only requests a self-reported age range, not a birthdate, but users who indicate they are under our minimum age requirement will not be able to create an account.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via an in-app notice or update to this page, with the "Last updated" date revised accordingly.
9. Contact Us
For any privacy questions, data requests, or concerns, contact:
Julius Rucha Am Steinbruch 24, 90542 Eckental, Germany jar.appstudio@gmail.com