Privacy Policy

Last updated: August 18, 2026

Somnara ("we", "the app") is built with privacy as a foundation. We collect the minimum data necessary to provide sleep journaling and AI-powered dream analysis. This policy explains exactly what data is collected, where it goes, and your rights.

1. Data stored locally on your device

Dream Journal Entries

Your dream titles, descriptions, mood ratings, vividness scores, and dates are stored only on your device — using Apple's on-device storage on iOS, or Android's local app storage on Android. This data never leaves your device unless you explicitly use the AI Analysis feature described below.

Sleep & Health Data (Apple HealthKit — iOS)

On iOS, Somnara requests read-only access to your Apple Health sleep data. This data is displayed within the app and is never uploaded to any server. It is governed by Apple's HealthKit privacy rules and cannot be used for advertising or sold to third parties.

Sleep & Health Data (Health Connect — Android)

On Android, Somnara integrates with Health Connect, the on-device health data store managed by your phone's operating system:

Somnara does not have a separate, brand-specific integration with Fitbit or Garmin. If you use a Fitbit or Garmin device, their Android apps write your sleep, heart rate, and related data into Health Connect the same way any other health app does — Somnara simply reads it from there, the same as it would for any other connected source. Somnara has no direct connection to Fitbit's or Garmin's own servers or accounts.

This data is never uploaded to any server — it is read from and written to Health Connect locally on your device only. Access requires explicit permission grants that you control and can revoke at any time through Health Connect's own permission settings. Health Connect data cannot be used for advertising or sold to third parties.

App Preferences

Settings such as smart light configurations and onboarding status are stored locally and never transmitted off your device.

2. Data sent off your device

AI Dream Analysis — Powered by Claude (Anthropic)

What is sent: The text of your dream journal entry for that session.

Who receives it: Anthropic, Inc. — the company that operates the Claude AI — via their secure API at api.anthropic.com.

Why: To generate an AI-powered interpretation of your dream.

What is NOT sent: Your name, email address, Apple ID, device identifier, location, or any other personal information. Only the dream text itself is transmitted.

When it happens: Only when you explicitly tap "Analyze with AI" and only after you have given consent through the in-app consent screen. This feature is off by default.

Anthropic's data practices: Data transmitted to the Claude API is processed under Anthropic's Privacy Policy. Anthropic provides equivalent or greater data protection as required by Apple's guidelines.

We do not store your dream text on any Somnara server. Once the AI analysis is returned to your device, your data is not retained by us.

Weather Data (Open-Meteo)

To display sleep-weather correlations, your approximate geographic coordinates are sent to Open-Meteo, a free, privacy-friendly weather API. No account or identifier is associated with this request.

Smart Light APIs (Philips Hue, Govee, WiZ)

Light control commands are sent directly from your device:

In-App Purchases (Apple StoreKit — iOS)

On iOS, subscription purchases are handled entirely by Apple through StoreKit 2. We never see or store your payment information.

In-App Purchases (Google Play Billing — Android)

On Android, subscription purchases are processed entirely by Google Play's billing system. We never see or store your payment information (card number, billing address, etc.) — that is handled entirely by Google Play.

We use RevenueCat, a subscription management service, to verify and keep track of your entitlement status (i.e., whether you currently have an active subscription). RevenueCat receives your purchase and subscription status and an anonymous app user identifier — never your payment details. RevenueCat's own data practices are governed by their privacy policy, linked above.

3. Data we do not collect

4. Third-party data sharing

We do not sell, rent, or share your personal data with any third party for advertising or marketing purposes. The only third-party data transfers are those listed in Section 2, all of which are initiated by you.

Third-party services used by Somnara and their privacy policies:

5. Data retention and deletion

All personal data is stored locally on your device. To delete your data:

6. Children's privacy

Somnara is not directed to children under 13. We do not knowingly collect information from children. If you believe a child has provided personal information, please contact us at privacy@somnara.io.

7. Security

All API communications use HTTPS/TLS encryption. HealthKit data access requires explicit user authorization granted through iOS; Health Connect data access requires explicit user authorization granted through Android. We do not operate servers that store your personal data.

8. Changes to this policy

We will update this policy when features change materially. The "Last updated" date at the top reflects the most recent revision. Continued use of the app after changes constitutes acceptance of the updated policy.

9. Contact

For privacy questions or data deletion requests:
privacy@somnara.io