Privacy Policy
Last updated: July 3, 2026
BeatMySleep ("the app", "we", "us") is a sleep-score game with leaderboards, operated by Ben Sirota as an individual. This policy explains what data we collect, how we use it, and the choices you have. Questions or requests: privacy@beatmysleep.com.
What we collect
- Account information — your email address, a password (stored only as a secure hash, never in plain text), the username you choose, and the date you created your account.
- Sleep summaries — with your permission we read sleep data from Apple Health (HealthKit) or Google Health Connect on your device. For each night, we upload only aggregate figures: total time asleep, time in bed, minutes spent in each sleep stage (deep, REM, light, awake), number of awakenings, and the date you woke up. From these we compute a 0–100 quality score.
What we do not collect
- We do not collect or upload raw sleep timelines, heart rate, or any other health metric — those never leave your device.
- We do not collect your location, contacts, or advertising identifiers, and we do not use third-party analytics or tracking.
How we use your data
- To run the app: show your scores, history, and streaks, and rank you on the leaderboards.
- Leaderboards display your username and score/sleep duration to other users. Your email address is never shown to anyone.
- To sign you in and keep your account secure, and to send you essential emails (email confirmation and password reset).
Legal basis (EU/UK users)
We process your account data to provide the service you signed up for (performance of a contract). Sleep data is health data — a special category — which we process only with your explicit consent, given when you grant the in-app health permission. You can withdraw consent at any time by revoking that permission or by deleting your account.
Who we share it with
We do not sell your data and do not use it for advertising. We rely on a few service providers to operate the app:
- Supabase — database and authentication; stores your account and sleep summaries (hosted in the EU, Paris region).
- Google Cloud (Cloud Run, Firebase Hosting) — runs our backend.
- Resend — sends our confirmation and password-reset emails; receives your email address for that purpose only.
In line with Apple HealthKit and Google Health Connect requirements, health data is never used for advertising or marketing, never sold, and never shared with third parties for any purpose other than operating the app at your request.
Retention and deletion
We keep your account and sleep history for as long as your account exists. You can delete everything yourself in the app (Settings → Delete account). Deleting your account is immediate and permanent: it removes your sign-in record, your profile, and all of your uploaded sleep data. You can also email privacy@beatmysleep.com to request deletion.
Your rights
Depending on where you live (e.g. under GDPR or CCPA), you have the right to access, correct, delete, or export your data, and to object to certain processing. You can exercise deletion directly in the app, or contact us at privacy@beatmysleep.com for any other request.
Security
Passwords are hashed by our authentication provider and never stored in plain text. All data is encrypted in transit using HTTPS/TLS.
Children
BeatMySleep is not directed to children under 16, and we do not knowingly collect data from them.
Changes to this policy
We may update this policy from time to time. We will revise the "Last updated" date above when we do.
Contact
Ben Sirota · privacy@beatmysleep.com
← BeatMySleep