Privacy Policy
Effective date: September 7, 2026 · Last updated: September 7, 2026
Draft. This document is pending legal review and is not yet in force.
This policy explains what FiuFiu collects, why, where it goes, how long it stays, and what you can do about it. It covers the FiuFiu mobile app and the website at https://fiufiuapp.com. We have written it to match what the app actually does today; when the app changes, this page changes with it.
1. Who we are
FiuFiu is made by FiuFiu Labs. For anything about your data, write to privacy@fiufiuapp.com.
2. The website
This website is a set of static pages. It sets no cookies, runs no analytics, loads nothing from third-party servers, and has no forms. The only data involved is the standard access log our hosting provider, Vercel, keeps for each request: your IP address, browser identifier, the page requested, and the time. Vercel keeps those logs for a short period on our behalf; we do not export or analyse them.
3. The app: what we collect and why
The app works without an account. Everything below applies only once you sign in, which turns on cloud sync so your alarms and progress survive a new phone.
3.1 Your account
- Email and password. If you sign up with email, we store your address and a hashed password. We send a one-time code to verify the address; that email is delivered by Resend.
- Sign in with Apple. We receive the name and email address Apple shares. Apple may give us a relay address instead of your real one.
- Sign in with Google. We receive your name, email address, and profile picture link.
- Sessions. When you sign in, our authentication system creates a session that lasts up to one year unless you sign out. Session records may include the IP address and the browser or device description (the user agent) of the sign-in, which we use to protect your account.
3.2 A device identifier
The app creates a random identifier on each phone the first time it syncs and keeps it on that phone. It tags the data that phone sends so we can tell your devices apart. It is not a hardware identifier or an advertising identifier, and it is deleted with your account.
3.3 Alarms, schedule, and wake-ups
- Alarms and wake schedule: wake times, repeat days, bedtimes, overrides, your sleep goal, the alarm label and sound, which challenges you chose, and settings such as "surprise me", committed mode, and whether app blocking is on.
- Wake sessions: when an alarm fired, when you finished, the result (completed, dismissed, or abandoned), which challenges ran, and for each attempt when it started and ended and how many times it failed. We do not store photos, video, or audio from challenges.
- Streak: your current streak, your best streak, and the last day you completed.
- Onboarding answers: the habits you picked during setup, including anything you typed into the "other" field, the challenges you chose, your sleep goal and preferred times, your device language, and the app version.
3.4 Sleep and mood
On iPhone, with your permission, the app reads your sleep from Apple Health to show how last night went. That reading stays on your phone. We never write to Health, and Health data is never used for advertising, never sold, and never shared with anyone. The only sleep-related data that syncs to your account is the mood you tap each morning (rough, okay, or rested) and when you tapped it.
3.5 Camera, motion, and microphone
Challenges use your phone's sensors, and the processing happens on the phone:
- Photo missions use the camera and Apple's on-device image recognition. Photos never leave your phone. If you set up a personal reference object, the app saves a name, an emoji, and a numeric descriptor of what the object looks like (or, for a barcode, its type and value), plus optional descriptive labels. That descriptor is what syncs, not the photo.
- Movement challenges use the camera and the motion and step sensors to check that you are moving. Nothing from the camera or sensors is stored or sent; only the attempt result is.
- The singing challenge uses the microphone to measure loudness. Audio is not sent to us.
- App blocking on iPhone uses Screen Time. Which apps you choose to block is held by iOS on your phone; we only sync whether blocking is on.
You can withdraw any of these permissions at any time in your phone's Settings. The related challenges will stop working until you turn the permission back on.
3.6 Subscriptions and purchases
Payments are handled by Apple or Google, and subscriptions are managed through RevenueCat. We never see your card or bank details. What we receive and keep:
- which plan you have, its status, when it renews or expires, the store, the product, the billing period type (trial, introductory, or regular), and whether it will renew;
- store transaction identifiers and the purchase events the store sends us, including cancellations and refunds;
- a running ledger of your Stop Alarms and snooze allowance;
- a link between your FiuFiu account and your App Store or Google Play account, made with a key the store provides rather than your store email, so purchases can be matched to the right account, and records of any transfer of a subscription between FiuFiu accounts.
RevenueCat knows you by the same account identifier we use, or by an anonymous identifier before you sign in.
Refund requests. Apple sometimes asks the developer whether a purchase was used before deciding a refund. We answer only if you have switched on the optional setting in the app that allows it. If you have, we tell Apple whether you used any Stop Alarms; we send nothing else.
3.7 Optional product analytics
If you allow it, the app sends usage events to PostHog so we can see which parts of FiuFiu people use and where they get stuck. We ask once during setup, with equal Allow and Decline buttons, and you can change your answer at any time in the app's Settings. Nothing is collected or stored for analytics before you allow it, and declining changes nothing else in the app.
An event contains its name (for example an onboarding step completed, an alarm created, a challenge finished, or a subscription started), a few fixed properties from a short allowlist, the app version, the platform, and the app environment. Events never include your email, free-text answers, Health data, your exact sleep schedule, or your IP address, which is not stored (it is replaced with zeros); location lookup is switched off. Before you sign in, events carry a random identifier; after you sign in they carry your account identifier so we can count returning users. Withdrawing consent stops new events immediately. Events already sent are deleted when you delete your account. Analytics is currently available on iPhone only, and our PostHog project is hosted in the European Union.
Separately from your choice, our backend sends PostHog a small number of operational signals about itself, such as failure counts and processing health. These describe the service, not you, and carry no account identifier.
3.8 What we do not collect
The app has no crash reporting, no advertising, and no over-the-air update client. It does not access your location, contacts, or photo library, and it does not collect push notification tokens. Alarm notifications are scheduled locally on your phone.
4. Why we use this data and on what basis
- To provide the service you asked for: syncing alarms, schedules, sessions, streaks, and subscriptions across your devices (performance of our contract with you).
- With your consent: reading Apple Health, using the camera, motion sensors, and microphone, sending product analytics, and answering Apple's refund questions. You can withdraw consent at any time as described above.
- To keep the service secure and working: session records, hosting logs, and the backend's operational signals (our legitimate interest in running a reliable service).
We do not use your data for advertising or profiling, and we do not sell it.
5. Who processes data for us
- Convex — backend, database, and authentication storage — United States.
- Vercel — hosting this website — United States, with a global edge network.
- RevenueCat — subscription management — United States.
- Resend — sending sign-in and account emails — United States.
- PostHog — optional product analytics and backend operational signals — European Union.
- Apple and Google — sign-in, payments, and app distribution, under their own privacy policies — their own regions.
If you are outside the United States, account and purchase data is transferred there to be processed by the providers above; analytics data stays in the European Union.
6. How long we keep data
- Account data and everything synced to it: until you delete your account.
- Sessions: up to one year, or until you sign out.
- Analytics events: for the retention period set in our PostHog project, and no longer than your account exists; deleting your account deletes the events linked to it.
- Purchase and refund records: while your account exists, and afterwards for as long as accounting and consumer law require.
- Website access logs: the short period Vercel keeps them.
7. Your rights and choices
You can ask us to show you the data we hold, correct it, delete it, or send you a copy. Where a law gives you further rights, such as objecting to processing or restricting it, you can exercise those too. Write to privacy@fiufiuapp.com from the email address on your account. We reply within two business days and complete requests within 30 days.
To delete your account, follow the steps on the Delete your account page. To stop the app reading Health data or using the camera, motion sensors, or microphone, change the permission in your phone's Settings. To stop syncing, sign out.
8. Children
FiuFiu is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, write to us and we will delete it.
9. Security
Data travels over encrypted connections and is stored with providers that encrypt it at rest. Access is limited to what is needed to run the service. No system is perfectly secure, so please use a strong, unique password.
10. Changes to this policy
When we change this policy we update the dates at the top of this page and, for changes that matter to you, we tell you in the app before they take effect.