Privacy Policy for the HolySleep App
Our Privacy Promise
HolySleep was developed around one clear principle:
Your sleep data belongs to you – and you alone.
That is why privacy at HolySleep is not merely a setting, but part of the technical architecture.
As a general principle:
- Your sleep data stays on your device.
- Sleep sounds and analyses are processed directly on your device.
- HolySleep does not require a user account.
- As a general rule, we do not know who you are as a user of the app.
- We do not automatically transfer your sleep recordings to us or to the cloud.
- We do not use tracking or advertising platforms.
- We do not create user profiles for advertising or marketing.
- We do not sell personal data.
- Voluntary data donations to help improve HolySleep are completely separate from your normal use of the app.
Our privacy principles apply regardless of the country in which you use HolySleep.
Where local data protection laws provide additional rights or requirements, these apply in addition to the principles described in this Privacy Policy.
Our technical approach remains the same:
Your regular sleep data is generally processed locally on your device.
1. Controller
The controller responsible for data processing, insofar as processing is carried out by us, is:
Martin Bach (sole proprietorship)
Aggensteinweg 7
87452 Altusried
Germany
Email: info@holysleep.eu
You may also use this contact address for questions, complaints or requests concerning your data protection rights.
HolySleep handles privacy requests and complaints in accordance with the applicable legal requirements.
2. Basic Principle of the HolySleep App
HolySleep is designed so that, wherever possible, your personal sleep data does not reach us in the first place.
For normal use, you do not need:
- a HolySleep account,
- registration using your name or email address,
- a connection to a HolySleep cloud account.
The data used for your sleep analysis is generally processed on your own device.
During normal operation, we do not have access to your sleep recordings or personal sleep analyses.
The typical data flow therefore looks like this:
- You start a function on your device.
- The required data is collected on your device.
- The analysis takes place on your device.
- The results are stored on your device.
- Only you can access the stored results within the app.
- Data is transferred to HolySleep only if you initiate a separate process yourself, such as contacting support or making a voluntary data donation.
We therefore distinguish between:
- local use of the app,
- voluntary contact with support,
- voluntary data donation.
These areas are not linked with one another.
3. What Data Does HolySleep Process on Your Device?
Depending on the functions you use, HolySleep may process the following data on your device in particular:
- microphone recordings during a sleep session started by you,
- detected sleep sounds,
- information about breathing and other body-related sounds,
- volume and audio signals,
- technical audio features calculated from them,
- detected events and timelines,
- analyses, overviews and information generated from them,
- app settings,
- alarm and wake-up settings,
- where applicable, data from external devices or health platforms that you have explicitly enabled.
Because sleep analysis may generate information that could be regarded as health data or other special categories of personal data, HolySleep takes a precautionary approach and treats this data with the high level of protection intended for such information.
We generally treat sleep-related, body-related and health-related information as particularly sensitive data, regardless of whether the applicable national law in a particular case expressly refers to it as health data, sensitive personal data or special personal information.
4. Why Does HolySleep Process This Data?
The processing serves the intended purpose of the app:
to capture and analyse your sleep sounds and, where applicable, other sleep-related information selected by you, and to present this information exclusively for you.
This may include in particular:
- detecting sleep sounds,
- presenting your night,
- placing detected events on a timeline,
- playing back stored recordings,
- comparing different parts of a session,
- creating personal overviews and information,
- where applicable, using additional data sources enabled by you.
The data is not used for advertising or user profiling.
We use personal data only for the purposes for which it was collected or provided by you, or for other purposes permitted by law and compatible with those purposes.
We do not collect additional personal data merely because it is technically available.
5. Legal Bases
For Users in the European Economic Area
Where processing is necessary to provide the HolySleep functions you request, it is carried out on the basis of:
Art. 6(1)(b) GDPR
– processing necessary for the performance of the user relationship or to provide the functions requested by you.
As a precaution, HolySleep assumes that sleep analysis may also involve the processing of health data or other special categories of personal data. We therefore additionally obtain explicit consent pursuant to
Art. 9(2)(a) GDPR
.
Processing of special categories of personal data begins only after you have explicitly consented.
Merely installing or using the app does not replace this explicit consent.
Outside the European Economic Area, the legal basis for processing is determined by the applicable data protection law.
Where the applicable law requires explicit consent for sensitive or health-related data, we obtain such consent accordingly.
6. Your Explicit Consent
Before the relevant processing takes place for the first time, HolySleep informs you what data will be processed and why it is needed.
You then explicitly decide whether you wish to allow this processing.
Your consent applies exclusively to the functions of the app that have been described.
In particular, it does not constitute consent to transfer your sleep data to HolySleep for training, advertising or marketing purposes.
A voluntary data donation for the further development of the HolySleep model is an entirely separate process and requires a separate decision by you.
For sensitive data, we place particular importance on ensuring that you can understand the nature, purpose and possible consequences of the processing.
Optional processing activities are presented separately from processing necessary for the app’s core functionality.
7. Withdrawal of Your Consent
You may withdraw your consent to the processing of special categories of personal data at any time with effect for the future.
Withdrawal does not affect the lawfulness of processing carried out before your consent was withdrawn.
After withdrawal, HolySleep will not start any new processing activities for which your explicit consent is required.
In particular, no new sleep session will be started unless the required consent is in place.
If you later wish to start another sleep session, HolySleep will first present the relevant consent process again.
New processing will begin only after you have given new explicit consent.
8. Your Existing Data Remains Your Data
Withdrawing your consent does not mean that we will prevent you from accessing data already stored on your device.
Existing:
- sessions,
- analyses,
- overviews,
- charts,
- recordings and
- other stored results
generally remain accessible to you.
The reason is simple:
It is your data on your device.
We do not want to use your existing data as leverage to persuade you to give consent again.
However, after consent has been withdrawn, new analyses or new health-related inferences will only be performed once any required explicit consent has been given again.
9. Microphone Access
HolySleep requires access to your device’s microphone to record sleep sounds.
Microphone access is used only for the functions intended for this purpose and in accordance with the permissions provided by your operating system.
A sleep recording begins only when you start the relevant function yourself.
HolySleep does not use microphone access for advertising, tracking or other unrelated purposes.
10. Storage of Your Sleep Data
Your personal HolySleep data is generally stored locally on your device.
Personal data stored locally is technically protected by HolySleep and, where provided for the relevant type of data, stored in encrypted form.
HolySleep does not operate a central cloud to which your regular sleep recordings or sleep analyses are automatically uploaded.
You largely determine how long your data is stored locally through your use and management of the app.
If you delete sessions or other local data within the app, they are removed in accordance with the intended deletion process.
If you completely delete the app together with its local data through the operating system, data stored locally by the app is removed in accordance with the mechanisms of the respective operating system.
Any device backups or operating-system backups are subject to the settings and privacy terms of the relevant platform provider.
Our principle is:
We do not retain personal data for longer than it is needed for the relevant purpose.
The lifecycle of personal data therefore comprises:
Collection → processing → use → retention where applicable → deletion or effective anonymisation.
For data stored exclusively locally on your device, you largely determine this lifecycle yourself.
Separate documented retention and deletion rules apply to data that HolySleep exceptionally receives, for example in connection with support.
11. External Devices and Health Data
In the future, or depending on available functionality, HolySleep may use data from external devices or health platforms.
This may include, for example, sleep-related or body-related information.
Such a connection is not activated automatically.
You decide whether you wish to enable the relevant data source.
HolySleep uses only the data required for the function you have selected and for which you have granted the necessary permissions.
If you revoke the relevant permission, no new data will be retrieved from that source.
12. No Tracking and No Advertising
HolySleep does not use tracking technologies within the app to track your behaviour for advertising purposes.
In particular, we do not use your sleep data for:
- personalised advertising,
- advertising profiles,
- cross-app tracking,
- selling user data,
- data trading,
- profiling for marketing purposes.
HolySleep does not contain any function that automatically shares your personal sleep data with third parties for advertising purposes.
We make only privacy and security commitments that correspond to our actual technical implementation.
When we state that certain sleep data remains local or is not shared for advertising purposes, this forms part of our binding privacy concept.
13. No User Accounts
No user account is required for normal use of HolySleep.
We therefore generally do not maintain a central database linking your identity to your sleep data.
Purchases and subscriptions are also handled through the relevant App Store.
Payments are processed by the relevant platform provider.
HolySleep does not receive your complete credit card or bank details.
The app may receive technical information about an existing purchase or subscription status where this is necessary to unlock purchased features.
Apple’s or Google’s own privacy policies additionally apply to processing carried out by those providers.
14. Support
If you voluntarily contact us, for example by email, this creates a separate processing activity from your normal use of the app.
The following data in particular may be processed:
- your email address,
- your name, if you provide it,
- the content of your message,
- technical information or files that you voluntarily provide.
We use this data solely to handle your enquiry.
Depending on the nature of your enquiry, the legal basis is in particular:
Art. 6(1)(b) GDPR
or
Art. 6(1)(f) GDPR
– our legitimate interest in handling support requests securely and efficiently.
Support data is not used to identify your normal HolySleep use or voluntary training-data donations.
Support and ML data donations are technically and organisationally separated from one another.
Support data is retained only for as long as necessary to handle your enquiry and, where applicable, to comply with statutory documentation or retention obligations.
It is then deleted or, where appropriate, anonymised.
15. Voluntary Data Donation to Improve HolySleep
HolySleep may offer you the option of voluntarily providing suitable sleep sounds to help improve the recognition model.
Participation is entirely voluntary.
Choosing not to participate has no effect on your normal use of the app or your subscription.
Before making a data donation, you will be separately informed about:
- what data will be provided,
- the purpose for which it will be used,
- how the data will be protected,
- the fact that the data-donation process is separate from your normal use of the app,
- the fact that HolySleep does not require a user identifier for the data donation,
- and the consequences of transmitting the data anonymously or in a form that can no longer be linked to you.
Only then do you actively decide whether you wish to provide the data.
16. Privacy Protection for Training Exports
The training-data process is designed so that HolySleep generally does not require the user’s identity for a data donation.
In particular, the export intended for this purpose is designed not to contain deliberately added:
- names,
- email addresses,
- user IDs,
- account IDs,
- device IDs,
- store purchaser identifiers or
- support identifiers.
The technical verification of such an export serves only to establish that it is a valid HolySleep export.
It is not used to identify the user.
The export is technically protected and encrypted before transmission.
17. Anonymisation of Training Data
Training data is processed in a way designed to avoid linking it to individual users and to remove any existing personal references as early as possible.
This may include in particular:
- excluding speech as training content,
- isolating the required sleep sounds,
- removing unnecessary metadata,
- removing session and source references,
- breaking the original temporal relationships,
- mixing suitable training examples from different sources,
- deleting intermediate and source data that is no longer required.
Before a dataset is permanently treated as anonymous, we assess whether a person could still be identified, singled out or linked to other data using means reasonably likely to be used.
18. Withdrawal of a Data Donation
As long as a data donation can still technically be linked to a particular person, applicable data protection rights will be respected.
However, the data-donation process is deliberately designed not to create a permanent link to the user’s identity.
Once effective anonymisation has taken place, individual training contributions can no longer be linked to a particular person.
It is then no longer possible to retrieve a specific anonymous contribution at a later date.
We do not store or generate additional identifying data solely for the purpose of subsequently linking already anonymised contributions back to an individual.
We inform you of this before you make a data donation.
19. Retention and Deletion of Training Data
Incoming data and intermediate datasets that are still personal data, or are treated as personal data as a precaution, are stored only for as long as necessary for the relevant processing step.
Our aim is to remove links to individuals as early as possible.
A maximum processing and deletion period is defined for intermediate datasets that still constitute personal data.
Under the deletion concept currently envisaged, such personal intermediate datasets are to be deleted or effectively anonymised within no more than 30 days.
The 30-day period is a maximum period.
Data is deleted earlier as soon as it is no longer required.
Permanently anonymised training data may subsequently be used to improve the HolySleep model.
When deleting data, we take into account not only active files but, where technically relevant, also temporary files, caches, logs, backup copies and cryptographic keys.
Storage media and systems containing sensitive data are handled in a way that prevents unauthorised access even after the end of their regular use.
20. The Trained ML Model
The HolySleep model is a specialised classification model for sleep sounds.
It is not designed to:
- identify individuals,
- recognise speakers,
- reproduce spoken content or
- reproduce original audio recordings.
Nevertheless, a trained model is not automatically treated as anonymous solely because of its technical structure.
HolySleep therefore also assesses the resulting model to determine whether there remains any realistic possibility of linking or reconstructing personal information from the training data.
21. Data Security
HolySleep uses technical and organisational measures to provide appropriate protection for data.
Depending on the processing involved, these measures include in particular:
- local processing,
- encryption,
- access restrictions,
- data minimisation,
- separate processing paths,
- secure key management,
- short retention periods for personal intermediate training data,
- deletion procedures and
- data protection by design.
Our basic technical principle is:
Data we do not need is data we do not want to possess.
Our security measures are based on the nature, sensitivity and risk associated with the respective data.
These may include in particular:
- encryption of stored data,
- encrypted data transmission,
- separation of identity, support and training data,
- restriction of internal access rights according to the need-to-know principle,
- secure management of cryptographic keys,
- protection against unauthorised access, loss, alteration or disclosure,
- documented deletion and retention processes,
- security updates and technical maintenance,
- regular review of the protective measures in place,
- procedures for handling privacy and security incidents.
Particularly sensitive data receives a correspondingly higher level of protection.
22. Security Incidents
Despite high security standards, security incidents can never be completely ruled out.
We therefore maintain procedures to:
- detect,
- investigate,
- contain,
- document and
- where necessary, report potential privacy or security breaches to affected individuals or competent authorities.
The applicable notification obligations depend on the relevant law.
Where a statutory notification obligation applies, we notify affected individuals and competent authorities within the applicable time limits.
23. Recipients of Personal Data
During normal sleep analysis, HolySleep generally does not receive any sleep data.
Personal data may be received by other parties only in separate situations, for example:
- if you contact us yourself for support,
- through the relevant App Store provider in connection with purchases and subscriptions,
- if you voluntarily connect an external health platform or external device,
- where required by law.
Your sleep data is not shared for advertising or marketing purposes.
If we use external service providers, they receive only the data required for their specific task.
Where legally required, such service providers are contractually required to process and protect personal data appropriately.
24. International Data Transfers
Your regular sleep data is generally processed locally on your device.
HolySleep does not automatically transfer your regular sleep recordings or sleep analyses to another country or to a HolySleep server.
However, separate activities – particularly support or services that you activate yourself – may involve cross-border processing.
Where personal data is transferred internationally or disclosed to recipients in other countries, we assess the applicable legal requirements and implement any safeguards that are required.
Depending on the jurisdiction, these may include in particular:
- contractual data protection safeguards,
- recognised transfer mechanisms,
- assessment of an adequate level of data protection,
- additional technical safeguards or
- explicit consent where required.
Where practicable and legally required, we provide information about the countries in which such recipients are located.
25. Your Rights
Where HolySleep processes your personal data and we are able to identify you from that data, you have data protection rights subject to the requirements of the applicable law.
These may include in particular:
- access to personal data,
- rectification of inaccurate data,
- deletion,
- restriction or limitation of processing,
- data portability,
- withdrawal of consent,
- objection to certain processing activities,
- the right to lodge a complaint with a competent data protection or supervisory authority.
For users in the European Economic Area, these include in particular the rights under Articles 15 to 21 GDPR.
For users in Mexico, statutory rights include in particular the rights to:
- access,
- rectification,
- deletion or cancellation, and
- objection
in accordance with the applicable Mexican data protection laws.
For users in Canada, this includes in particular the right to obtain information about the personal data we hold about them, how it has been used and to whom it may have been disclosed, as well as the right to have inaccurate or incomplete data corrected.
For users in Australia, this includes in particular the right to request access to and correction of personal data and to submit privacy complaints to us.
For users in South Africa, rights under POPIA may include in particular rights of access, correction, deletion and objection.
Because HolySleep deliberately does not collect unnecessary identifying information, there may be cases in which we cannot link you or certain anonymous data to an individual.
We will not request or generate additional personal data solely for the purpose of making information that is already anonymous identifiable again.
26. Privacy Complaints
If you believe that we have not handled your personal data properly, you may contact us at any time in the first instance:
We review privacy complaints and inform you of the outcome and, where applicable, any further steps available to you.
In addition, depending on where you live and the law that applies, you may contact the competent data protection or supervisory authority.
27. Special Information for Users in the United States
For users in the United States, additional state privacy laws may apply alongside generally applicable federal requirements.
HolySleep does not sell personal sleep data and does not use it for behavioural advertising.
Depending on the applicable law, additional rights may apply regarding access to, deletion, correction or use of personal or health-related data.
Certain health apps may also be subject to specific legal requirements concerning notification of security breaches involving identifiable health information.
Where such requirements apply to HolySleep, we comply with the relevant information and notification obligations.
28. Special Information for Users in Mexico
For users in Mexico, this Privacy Policy also serves as information about the essential purposes and conditions governing the processing of personal data.
Where we process sensitive personal data, particularly information concerning health status or health-related information, we expressly draw attention to this.
This data is afforded an enhanced level of protection.
Where Mexican law requires explicit consent for the processing of sensitive personal data, such consent is obtained through an appropriate electronic mechanism.
29. Special Information for Users in South Africa
Where POPIA applies, HolySleep treats health-related information as specially protected personal information.
We implement appropriate technical and organisational measures to protect its confidentiality and integrity.
Users may initially contact HolySleep with questions or complaints and may also contact the competent Information Regulator.
30. Changes to This Privacy Policy
HolySleep continues to evolve.
If new features are added or legal or technical requirements change, this Privacy Policy may be updated.
The current version is available within the app and via the privacy page published for HolySleep.
We will inform you appropriately of material changes.
If the nature, purpose or disclosure of personal data changes materially, we will assess whether renewed information or consent is required.
31. Privacy Contact
If you have any questions about privacy at HolySleep, you can contact us at any time:
Martin Bach (sole proprietorship)
Aggensteinweg 7
87452 Altusried
Germany
Email: info@holysleep.eu
Last updated: September 2026
