Overview
Drowse helps you understand your sleep using information you choose to provide, permission-based access to Apple Health, on-device microphone analysis, and app preferences. We do not sell your personal information, and we do not use your data for third-party advertising or tracking.
Who operates Drowse
Drowse is operated by Suraj Mahraj, an independent developer based in India. Suraj Mahraj is the data controller for personal data where Drowse determines why and how it is processed. Privacy and data-rights requests can be sent to support@drowse.co.in. The verified business correspondence details are provided in the Contact section below.
For customers in the European Union, Apple separately verifies and displays Drowse’s trader address, phone number, and email address on Drowse’s App Store product page under the Digital Services Act. That marketplace disclosure is distinct from the privacy-controller contact provided in this policy.
Website downloads
The website no longer collects email addresses through an early-access form. Its App Store links and QR code take you to Apple, and Drowse does not receive your Apple account details or download information from those links.
If you submitted an email address through the former early-access form, it was processed by Web3Forms and delivered to Drowse. Drowse keeps that address only while needed for the updates you requested or until you ask us to remove it. Web3Forms states that form submissions may remain in its systems for up to three years unless deleted earlier; Drowse will request earlier removal when required to honor a valid deletion request.
Website analytics
We use Umami Cloud to understand website traffic and improve the site. It records information such as page views, referral and campaign information, browser and device type, approximate country, and interactions with the download card and App Store links. The site is configured without analytics cookies, and Drowse does not send Apple account or App Store purchase information to Umami.
Data we use
Depending on the features you enable, Drowse may use:
- Information from a previous website early-access signup, such as an email address submitted before the form closed.
- Aggregate website usage information, such as page views, traffic source, device type, and interactions with the download card or App Store links.
- Account information from Sign in with Apple, such as your Apple user identifier and, if provided, your name and email address.
- A short-lived Apple authorization code used only when you ask Drowse to revoke Sign in with Apple access during account deletion.
- Sleep goals, app preferences, and verified Drowse Pro entitlement state.
- Apple Health sleep information, when you grant permission.
- Microphone input for on-device snore pattern analysis, when you grant permission.
- Short detected snore clips, clip timing and waveform metadata, and session summaries stored locally on your iPhone.
- Notification permission for alarms and wind-down reminders.
Legal bases
Where European data-protection law applies, Drowse relies on the following legal bases:
- Consent: for any previous website early-access signup and for permission-based features you choose to enable, including Apple Health access, microphone analysis, and notifications. To the extent that sleep, health, or audio-derived information is treated as special-category data, Drowse relies on your explicit consent. You can withdraw permission in iOS Settings or ask Drowse to delete a previously submitted email address at any time.
- Performance of a contract or steps you request: to create and maintain your Drowse account, sync enabled preferences, verify Drowse Pro entitlement, provide requested support, and complete account deletion and Apple authorization revocation.
- Legitimate interests: to operate and secure the website and service, prevent misuse, diagnose failures, and understand aggregate website performance using limited, cookie-free analytics. These interests are balanced against your privacy and do not involve third-party advertising or cross-site profiles.
- Legal obligations: where information must be used or retained to comply with applicable law, respond to valid legal requests, or establish and defend legal claims.
Withdrawing consent does not affect processing that was lawful before withdrawal. Some requested functionality may stop working when its permission is withdrawn.
Audio and microphone
Drowse uses microphone access to analyze possible snoring while you sleep. Analysis runs on your iPhone. Drowse does not keep a continuous overnight recording and does not upload microphone audio to Drowse, Apple iCloud, Google, or another cloud service.
When the on-device model detects a qualifying event, Drowse saves a short playback clip, its timing, and waveform metadata locally on your iPhone so you can review it. Clips are protected on disk, excluded from device backup, and automatically removed after seven nights. You can delete an individual clip sooner from Insights.
Apple Health
If you allow Apple Health access, Drowse reads sleep information such as time asleep, time in bed, and sleep stages to calculate SleepRings, SleepScore, and related insights on your device. Drowse does not write those HealthKit samples to CloudKit or upload them to Drowse. You can change Apple Health permissions at any time in the iOS Settings or Health app.
iCloud and CloudKit
Drowse uses your private iCloud/CloudKit database to sync limited account and preference data, including your Apple user identifier, Apple-provided name or email, alarm choice, sleep goals, bedtime and wake-time settings, reminder settings, score weights, and an updated timestamp.
HealthKit samples, microphone audio, snore clips, waveforms, snore summaries, SleepScore history, and detailed sleep session history are not written to CloudKit by Drowse.
Service providers and international transfers
Drowse uses a small number of providers only where needed to operate the app, website, support, and account-deletion flow:
- Apple provides Sign in with Apple, StoreKit, HealthKit, notifications, and your private CloudKit database.
- Vercel hosts the website and the short-lived server function used to complete Sign in with Apple revocation.
- Web3Forms processed email addresses submitted through the former website early-access form and delivered them to Drowse.
- Umami Cloud provides cookie-free website analytics and campaign measurement.
- Cloudflare routes email sent to Drowse contact addresses and may process routing and security information needed to deliver it.
Drowse is operated from India, and these providers may process limited personal data in India, the United States, the European Economic Area, or other countries where they operate. When European law restricts a transfer outside the EEA, Drowse and its providers use an applicable adequacy decision, approved Standard Contractual Clauses, or another lawful transfer mechanism. You can contact Drowse for more information about safeguards relevant to your data.
Account deletion and Apple authorization
When you confirm account deletion, Drowse sends a fresh, short-lived Apple authorization code and your opaque Apple user identifier over HTTPS to a Drowse-operated server function hosted by Vercel. The function uses them only to validate the request with Apple and revoke Drowse's Sign in with Apple authorization.
Drowse does not retain the authorization code, Apple's access token, or Apple's refresh token after the revocation request, and the function is designed not to include those values in application logs.
Drowse clears the account’s local data after the deletion request is safely secured. It then removes the private CloudKit preference record. If iCloud is temporarily unavailable, the app keeps a protected deletion marker and retries that CloudKit cleanup when the service becomes available; the deleted account is not restored while cleanup is pending.
Purchases
Drowse Pro subscriptions are handled by Apple through the App Store. Drowse may use StoreKit purchase information to unlock paid features, restore purchases, and keep your subscription state current.
Retention
Detected audio clips and their recovery metadata are automatically removed from the iPhone after seven nights. Local session summaries remain on the device to support your history until you delete the account or remove the app. Synced preferences remain in your private CloudKit database until you delete your Drowse account. Email addresses submitted through the former early-access form are kept only while needed for the requested updates or until deletion is requested. Short-lived Apple authorization codes and the access or refresh tokens obtained solely for revocation are not retained by Drowse after the request. App Store transaction records are retained by Apple under Apple's policies.
Your choices and rights
You can change Health, microphone, and notification permissions in iOS Settings. You can delete individual clips from Insights, sign out, or delete your Drowse account from the app. Account deletion asks you to confirm with Apple, revokes Drowse’s Sign in with Apple authorization, clears the account’s local Drowse data, and removes or queues removal of its private CloudKit preference record. It does not delete data stored by Apple Health or cancel an App Store subscription; subscriptions are managed separately in your Apple account settings.
Depending on where you live and subject to applicable exceptions, you may have rights to access, correct, delete, restrict, or receive a portable copy of personal data, and to object to certain processing. Where processing is based on consent, you may withdraw that consent at any time. Send a request to support@drowse.co.in; Drowse may need enough information to verify the request and will respond within the period required by applicable law.
If you are in the EEA and believe your data-protection rights have not been respected, you may lodge a complaint with the supervisory authority in your country. The European Data Protection Board maintains a list of EU and EEA supervisory authorities.
Contact
Questions about this policy or requests concerning personal data can be sent to the controller and operator using the details below.
View controller and EU trader contact
This is a business correspondence address verified by Apple for Drowse’s EU trader disclosure. It is not an in-app data field and is not used to profile Drowse users.