Privacy Policy for the WakeYa App
Last updated: 24 July 2026
This Privacy Policy explains how personal data is processed when the mobile application “WakeYa” (the “App”) is used. It applies to the App, including its live AI, alarm, Fajr, diagnostics and support features. A separate privacy policy applies to the website wakeya.app if additional processing takes place there.
This English version is a translation of the German Privacy Policy. In the event of any inconsistency, the German version shall prevail to the extent permitted by applicable law. Mandatory data protection rights remain unaffected.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Inan Software OG
Wagramer Straße 155/3/26
1220 Vienna
Austria
Commercial register number: FN 677527 p
Commercial register court: Commercial Court of Vienna
VAT identification number: ATU83440901
Email: [email protected]
Telephone: +43 676 3249861
We have not appointed a data protection officer because, based on our current assessment, we are not legally required to do so. Privacy-related enquiries may be sent using the contact details above.
2. WakeYa’s approach to privacy
WakeYa is designed to minimise the use of personal data:
- There are no user accounts, registrations or logins.
- Alarms, settings, local statistics and local AI personalisation generally remain on the device.
- Our application server is stateless: it does not maintain user accounts, a profile database or conversation content.
- There is no advertising, advertising tracking, sale of personal data or disclosure for behavioural or cross-context advertising.
- We do not use Google Analytics, Firebase Analytics or a comparable analytics SDK. Firebase Crashlytics is used exclusively for error diagnostics and can be disabled.
- The App does not use cookies.
- Location information used for prayer times and the Fajr alarm is processed exclusively on the device and does not leave it.
- If an online feature fails or is not used, the classic alarm remains available.
Despite this privacy-focused design, certain data transmissions are necessary for the live AI wake-up call, abuse prevention, subscription verification and, if enabled, error diagnostics. These processing activities are explained below.
3. Processing activities
3.1 Local App data
The following data is generally stored and processed only on the device:
- alarms, timers, reminders, labels and schedules;
- selected language, personality and hardness level;
- local usage and wake-up statistics;
- local AI personalisation values;
- settings and permission choices; and
- the city selected or coordinates entered by the user for prayer times and the Fajr alarm.
WakeYa does not transmit the user’s name or any free-form profile notes to our server or the AI service. Local data can be deleted within the App. When the App is uninstalled, it is removed from the device in accordance with the operating system’s rules. We have no control over device backups created by Apple, Google or another backup service selected by the user.
Purpose: Providing and personalising local App features.
Legal basis: Article 6(1)(b) GDPR (performance of a contract) and, where voluntary information is involved, Article 6(1)(a) GDPR (consent).
3.2 Live AI wake-up call and audio data
When the live AI wake-up call is used, the App accesses the microphone after the relevant operating-system permission has been granted. During the wake-up conversation, audio data is transmitted via an encrypted connection directly from the App to the paid Google Gemini Developer API. Google processes the audio data to understand speech input and generate the spoken AI response.
For this purpose, the App receives only a short-lived session token from our server. The secret API key remains on our server. Our server neither receives nor stores microphone recordings or conversation transcripts. Conversation content is also not stored in our diagnostic or usage metrics.
In particular, the following data may be transmitted to Google to manage the wake-up conversation:
- technically required session and App information;
- the selected language, personality and hardness level;
- numerical wake-up and response values, such as previous wake-up duration, periods of silence or the frequency of fallback to the classic alarm; and
- optional calendar data under Section 3.4 if the user has expressly enabled that feature.
WakeYa uses a paid service account for the live AI wake-up call. Under the terms applicable to paid Gemini API services, Google does not use the transmitted content to improve or train its generative AI models. Optional developer features for logging, creating datasets or sharing data are not enabled for WakeYa. Google may, however, process or log inputs and outputs to a limited extent and for a limited period where this is necessary for abuse prevention, security or compliance with legal obligations.
Purpose: Providing the live AI wake-up conversation requested by the user.
Legal basis: Article 6(1)(b) GDPR. The microphone permission is an additional technical control provided by the operating system and may be withdrawn there at any time. Without microphone permission, a live conversation is not possible; the classic alarm remains available.
The live AI wake-up call is not intended to collect special categories of personal data within the meaning of Article 9 GDPR. Users should not disclose health data, religious or political beliefs or other particularly sensitive information during the conversation. Where such information is intentionally to be processed in a live conversation, WakeYa obtains explicit consent under Article 9(2)(a) GDPR before the feature is used for the first time. Consent may be withdrawn at any time with effect for the future. The classic alarm can be used without this consent.
3.3 Numerical personalisation and session values
To adapt AI wake-up calls, the App calculates numerical values locally, for example, the average wake-up duration, the number of prompts required, the length of silent periods or the use of the classic fallback alarm. Only the values required for a particular live session are transmitted to our server and then to the AI service.
These values do not contain a name, email address, account identifier or free-form text. Our server does not store them in a database or use them to create a persistent server-side user profile.
Purpose: Providing a personalised live AI wake-up call.
Legal basis: Article 6(1)(b) GDPR.
3.4 Optional calendar access
If calendar access is expressly enabled, the App reads events scheduled for the current day. Only the following information is used for the live AI wake-up call:
- the event title; and
- the start time.
Notes, locations, participants, contact details and attachments are not transmitted.
The selected information is technically limited in both number and length, treated by the server as data rather than instructions and passed to Google only to prepare the current AI session. Our server does not store calendar data in a database or in logs. The calendar feature is optional, and the AI wake-up call also works without it. The permission and consent may be withdrawn at any time with effect for the future, either in the App or in the operating-system settings.
Event titles may reveal sensitive information in individual cases. We therefore also obtain explicit consent for the processing of any special categories of personal data that may be contained in event titles.
Purpose: Optionally including the day’s schedule in the live AI wake-up call.
Legal basis: Article 6(1)(a) GDPR and, where special categories of personal data may be involved, Article 9(2)(a) GDPR.
3.5 Premium subscriptions and entitlement verification
Subscriptions are purchased, billed, renewed and cancelled through the Apple App Store or Google Play. The privacy notices of the relevant store also apply. We do not receive full payment-card or bank-account details.
We use RevenueCat to manage and verify Premium entitlements. In particular, the following data may be processed:
- App Store and product identifier;
- purchase, expiry and renewal status;
- free-trial status;
- Premium entitlement; and
- a pseudonymous identifier generated by the App or RevenueCat.
The identifier does not allow us to identify a person directly. Some of this data is obtained indirectly from Apple or Google. The App and, where necessary, our server use it to determine whether Premium features may be enabled.
Purpose: Entering into and performing the subscription agreement, restoring purchases and enabling Premium features.
Legal basis: Article 6(1)(b) GDPR.
3.6 App and interface protection using Firebase App Check
We use Firebase App Check to protect our interfaces against modified apps, automated access and abuse. Depending on the operating system, Apple App Attest or DeviceCheck, or Google Play Integrity, is used for this purpose.
Technical device and App attestation information is sent to Apple or Google, and a time-limited App Check token is generated. The token confirms that a request is likely to originate from an unmodified instance of the authentic App. Personal App content and conversation content are not part of this token.
Purpose: Security, prevention of abuse and protection of paid infrastructure.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the secure and economically sustainable operation of the App. App Check is technically necessary to access protected online features.
3.7 Error diagnostics using Firebase Crashlytics
We use Firebase Crashlytics to detect crashes and errors. Crashlytics may process, in particular:
- the Crashlytics Installation UUID, Firebase installation ID and session ID;
- the time of the error, App ID and App version;
- operating system, device model, CPU, memory and storage information;
- information indicating whether the device has been rooted or jailbroken; and
- stack traces, crash logs and technical state information.
These identifiers are pseudonymous, not anonymous. We do not transmit names, email addresses, calendar content, audio recordings or conversation transcripts to Crashlytics. Fallbacks from the AI alarm to the classic alarm may also be reported as technical, non-content-related error events.
Crashlytics is not used for advertising, audience measurement or the creation of user profiles. Diagnostics can be disabled under Settings → Diagnostics. Once disabled, the App will not transmit new Crashlytics data for as long as the feature remains disabled. Data already transmitted is deleted in accordance with the retention periods below.
Purpose: Error analysis and reliable operation, particularly monitoring the safety-relevant fallback to the classic alarm.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the stability and security of the App. The user may object to future processing by disabling diagnostics.
3.8 Our own usage metrics
When diagnostics are enabled, the App may send individual technical milestones and counters to our server, for example:
- “wake-up call started”;
- “classic fallback alarm triggered”;
- “onboarding completed”; or
- aggregated success and error counters.
The transmitted payload does not contain a user, account or installation identifier, advertising ID, name, calendar data or conversation content. Individual reports are immediately added to overall counters and are not retained as a personal event history. We do not create cohorts or track users across sessions.
The IP address is nevertheless temporarily visible when a technical connection is established. It may be included in infrastructure logs together with the time, requested endpoint, HTTP status and basic information about the client used. Request content, audio and calendar data are not logged. The logs are not combined with the aggregated metrics.
The transmission of our own usage metrics can be disabled under Settings → Diagnostics.
Purpose: Identifying technical problems and measuring whether the classic fallback alarm is triggered reliably.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the reliable and safe operation of an alarm clock. Users may object to future processing by disabling diagnostics.
3.9 Technical server and abuse-prevention logs
When online features are used, our server, hosted on Google Cloud Run in Frankfurt, Germany (europe-west3), processes technically necessary connection data. This may include the IP address, timestamp, endpoint, response status, user agent and App and protocol version.
This data is needed to transmit requests, detect errors, prevent attacks and enforce technical and daily usage limits. It is not used for advertising or persistent user profiles. The application server does not maintain an account or profile database. Request content, calendar data, prompts, audio data and transcripts are not stored in infrastructure logs.
Purpose: Providing and securing online features and preventing abuse.
Legal basis: Article 6(1)(b) GDPR where processing is necessary to provide the requested function, and Article 6(1)(f) GDPR for security and abuse prevention.
3.10 Support enquiries
When a user contacts us by email, we process the contact details provided, the content of the message and the correspondence required to deal with the enquiry. Technical information supplied voluntarily, such as the App version, operating system and subscription status, is used only to process the request. Health data, conversation recordings, passwords or complete payment details should not be sent by email.
Our email-hosting provider may process data on our behalf for the technical transmission and storage of email.
Purpose: Handling enquiries, errors and complaints.
Legal basis: Article 6(1)(b) GDPR for contract-related enquiries and otherwise Article 6(1)(f) GDPR. Our legitimate interest is responding to and documenting support enquiries.
4. Required and optional data
No transmission of data to us is generally required for the local alarm features.
An internet connection, microphone access and the processing described in Sections 3.2, 3.3, 3.6 and 3.9 are required for the live AI wake-up call. If they are not provided, the live AI wake-up call will not be available; the classic alarm and locally available voice packs may still be used.
Subscription and entitlement data is required to enable Premium features. Calendar access, Crashlytics and our own usage metrics are optional or can be disabled.
5. Recipients and data protection roles
We transmit data only to the extent necessary for the purposes described above. Potential recipients include:
| Recipient/service | Role and purpose | Typical data |
|---|---|---|
| Google Gemini Developer API; depending on the contractual relationship, Google Cloud EMEA Limited, Ireland, and/or Google LLC, USA | Processor for the live AI wake-up call; Google may process certain service and security data as an independent controller under its own terms | Audio, AI inputs and outputs, session data, numerical personalisation values and – with consent – limited calendar data |
| Google Cloud Run; depending on the contractual relationship, Google Cloud EMEA Limited and/or Google LLC | Processor for hosting, session tokens and technical interfaces | Connection and log data; session data processed temporarily |
| Firebase App Check and Firebase Crashlytics; Google Ireland Limited and/or Google LLC | Processor for App protection and error diagnostics; participating attestation providers may be independent controllers | Attestation data and tokens; pseudonymous technical diagnostic and crash data |
| RevenueCat, Inc., USA | Processor for subscription and entitlement management | Pseudonymous App identifier, product, purchase, expiry, trial and renewal status |
| Email-hosting provider | Processor for the transmission and storage of support communications | Email address, message content and correspondence data |
Apple and Google generally process data as independent controllers under their respective privacy notices when the Apple App Store or Google Play, store accounts, purchases, billing or payment processing are used. The same may apply to Apple App Attest, Apple DeviceCheck and Google Play Integrity where Apple or Google independently determines the purposes and means of processing.
Data may also be disclosed to courts, public authorities or professional advisers where we are legally required to do so or where this is necessary to establish, exercise or defend legal claims.
No data is disclosed for advertising purposes.
6. Transfers outside the EEA
Some service providers or their subprocessors are located in the United States or other countries outside the European Economic Area. Processing outside the EEA may take place in particular in connection with Google, Firebase and RevenueCat, as well as the independently controlled store services provided by Apple and Google.
Where we are responsible for such a transfer, we rely on an adequacy decision of the European Commission, in particular the EU-US Data Privacy Framework where the recipient has a valid certification, and/or the European Commission’s Standard Contractual Clauses, including additional safeguards where required. We enter into agreements with processors in accordance with Article 28 GDPR.
Information about the safeguards specifically used and a copy of the relevant provisions may be requested at [email protected]. Copies may be appropriately redacted to protect trade secrets or security information.
7. Retention periods
We retain personal data only for as long as it is required for the relevant purpose:
| Type of data | Retention period or deletion criterion |
|---|---|
| Local App data | Until deleted within the App or the App is uninstalled; device backups are governed by the backup service selected by the user |
| Audio and transcripts on our server | Not received or stored by our server |
| Session, calendar and numerical personalisation data processed temporarily | Only for preparation and performance of the current session; not stored in an application database or content logs |
| Gemini content held by Google | Not used for model training under the terms applicable to the paid service; limited security or abuse-prevention logging only for the period Google determines to be necessary for those purposes |
| Cloud Run infrastructure logs | No longer than 30 days unless a specific security incident or legal obligation requires longer retention |
| Our own usage metrics | Individual reports are immediately added to non-personal overall counters; no personal event history is retained |
| Crashlytics data | Under Firebase’s requirements, crash stack traces and associated identifiers are retained for 90 days, after which removal from live and backup systems begins. If deletion of the Firebase installation ID is initiated, data linked to that ID is removed from live and backup systems within up to 180 days |
| App Check data | Ordinary App Check tokens are valid for no longer than 7 days and are not retained permanently by Firebase; tokens used for replay protection, if that feature is enabled, are stored for no longer than 30 days |
| RevenueCat data | For the duration of subscription and entitlement management; subsequently deleted or anonymised in accordance with the contractual requirements unless legal obligations or legitimate record-keeping interests require continued retention |
| Support correspondence | Normally for up to three years after the enquiry has been closed; longer only where statutory retention duties or ongoing legal claims require it |
Where longer retention is required because of a legal obligation or to establish, exercise or defend specific legal claims, processing is restricted to that purpose.
8. AI-generated content and automated decisions
The spoken responses during the live wake-up call are generated automatically by a generative AI model. The AI manages the conversation and may determine that the wake-up call should end. This does not, however, constitute a decision based solely on automated processing that produces legal effects or similarly significantly affects a person within the meaning of Article 22 GDPR.
9. Data subject rights
Subject to the applicable statutory requirements, data subjects have the following rights in particular:
- access to personal data being processed (Article 15 GDPR);
- rectification of inaccurate data (Article 16 GDPR);
- erasure (Article 17 GDPR);
- restriction of processing (Article 18 GDPR);
- data portability (Article 20 GDPR);
- objection to processing based on legitimate interests (Article 21 GDPR);
- withdrawal of consent with effect for the future (Article 7(3) GDPR); and
- the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR).
Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
Privacy requests may be sent to [email protected]. Because WakeYa does not maintain accounts and much of the data is stored only on the device, we will frequently be unable to associate data with a particular individual. Local data may be deleted directly within the App or by uninstalling it. Section 10 explains the available deletion methods and any pseudonymous identifiers that may be required.
10. Deleting Your Data
Because WakeYa does not maintain user accounts, most data is held exclusively on the device.
10.1 Local App data
Alarms, settings, statistics and local personalisation values can be deleted directly within the App or removed by uninstalling the App. Removal takes place in accordance with the operating system’s rules.
We have no control over copies stored in device or operating-system backups, such as iCloud or Google Backup. Those copies can be managed and deleted through the settings of the relevant backup service.
10.2 Live AI, calendar and session data
Our server does not store audio recordings, conversation transcripts or calendar data. Calendar, personalisation and session data processed temporarily are not stored in an application database after the relevant session has ended.
Where Google temporarily retains certain AI inputs or outputs for security, abuse prevention or legal purposes, users may submit a deletion request to [email protected]. We will forward the request to Google where the relevant data can be technically identified and no statutory retention ground or exception to the right to erasure applies.
10.3 Diagnostic and usage data
The transmission of Crashlytics data and our own usage metrics can be disabled under Settings → Diagnostics. No new diagnostic data is transmitted while the feature remains disabled. Crash reports that have not yet been transmitted may temporarily remain on the device and will not be transmitted while diagnostics remain disabled.
Our own usage metrics are added immediately to overall counters without a user, account or installation identifier. After aggregation, they can no longer be associated with a person or installation and therefore cannot be deleted individually.
Users may request deletion of pseudonymous Crashlytics data by contacting [email protected]. The **Firebase Installation ID (FID)** displayed in the App’s privacy or diagnostic information may be required to identify the relevant data. When deletion of this identifier is initiated, Firebase begins removing the associated data from its live and backup systems. This process may take up to 180 days. If the App continues to use Firebase services afterwards, a new installation ID may be generated that is not linked to the deleted identifier.
10.4 RevenueCat and subscription data
Users may request deletion of pseudonymous RevenueCat data by contacting [email protected]. We may require the **RevenueCat App User ID** displayed in the App’s privacy information to identify the relevant data.
Deleting data from RevenueCat does not end or cancel a subscription with Apple or Google. Subscriptions must be managed separately in the relevant App Store. If WakeYa is used after deletion with an entitlement that remains active, or if a purchase is restored, RevenueCat may create a new pseudonymous record.
10.5 Support communications
Deletion of support correspondence may also be requested at [email protected]. Deletion may be excluded or deferred where statutory retention duties or the establishment, exercise or defence of legal claims require continued storage.
There is no separate WakeYa user account that needs to be deleted. For deletion requests, we request only the information required to associate the request with the relevant data and prevent unauthorised requests.
11. Location data, prayer times and the Fajr alarm
WakeYa does not request GPS or other device-location permission. Prayer times and the Fajr alarm are calculated locally on the device using a city selected or coordinates manually entered by the user. This information is not transmitted to us, Google Gemini or any other recipient.
12. Data security
We implement appropriate technical and organisational measures to protect personal data. These include encrypted transmission, short-lived session tokens, server-side restriction and separation of data inputs, App attestation, limited logging and the absence of a server-side user or profile database.
No method of data transmission or storage can guarantee absolute security. If the online infrastructure fails, the App falls back to the classic alarm or locally available alarm features.
13. Age restriction
WakeYa is intended exclusively for individuals aged 18 or over and must not be used by anyone under 18. We do not knowingly process data relating to minors. If we receive substantiated notice that a minor has used the App, we will assess whether data can be deleted to the extent that it can be associated with that individual.
14. Right to lodge a complaint
Data subjects may lodge a complaint with a data protection supervisory authority, in particular in the country of their habitual residence, place of work or the place of the alleged infringement.
The Austrian supervisory authority responsible for us is:
**Austrian Data Protection Authority
(Österreichische Datenschutzbehörde)**
Barichgasse 40–42
1030 Vienna
Austria
Email: [email protected]
Website: www.dsb.gv.at
15. Information for users outside the EEA
WakeYa is offered internationally. Mandatory privacy rights that apply under the law of a user’s place of residence remain unaffected. Depending on the applicable law, these may include rights of access, rectification, erasure, portability, restriction or objection.
WakeYa does not sell personal data or disclose it for behavioural or cross-context advertising. Requests concerning applicable local privacy rights may be sent to [email protected].
Additional notices may be required for individual countries or regions. Where such notices are published, they supplement this Privacy Policy.
16. Changes to this Privacy Policy
We update this Privacy Policy when the App, the services used or legal requirements change. The current version is available in the App and at wakeya.app/privacy.
We will provide appropriate notice of material changes before they take effect. Where a change requires new consent, that consent will be requested separately.