Back to home

Your privacy

Privacy Policy

Last updated: 21 July 2026

SomaVibe is built to be private by design. Your sessions, check-ins and biofeedback live on your device — not on our servers. This policy explains exactly what is and isn't collected, and the choices you have.

The short version

  • No account, no login. You don't create a profile or give us your name, email or phone number to use the app.
  • Your data stays on your phone. Session history, check-ins, your calm score and biofeedback readings are stored locally on your device and are not uploaded to us.
  • Optional, privacy-limited telemetry. Anonymous product events and technical crash/performance reports are on by default and can be switched off separately in Settings. They never contain your name, your heart rate, the mood you picked, or anything you typed — but they do include coarse, non-identifying signals about app usage, described in full below.
  • No advertising tracking. We do not use advertising, attribution or cross-app tracking SDKs.
  • Purchases go through the store. The optional one-time SomaVibe+ purchase is handled by Apple or Google. We never see your card details.
  • Works offline. The core experience runs without an internet connection.

Who we are

SomaVibe ("SomaVibe", "we", "us") provides the SomaVibe mobile application, a wellness and relaxation tool. This policy applies to the SomaVibe app and the somavibe.app website. If you have any questions, you can reach us at contact@somavibe.app.

For data-protection purposes, the data controller is ONITUM SOFTWARE MAREK KARWACKI ("Onitum Software"), a sole proprietorship registered at ul. Harcerska 21, 20-805 Lublin, Poland, reachable at the email address above.

SomaVibe is a wellness product, not a medical device. It does not diagnose, treat, cure or prevent any condition. See our Terms of Use for the full wellness disclaimer.

Data that stays on your device

Almost everything SomaVibe records is stored locally on your phone, in the app's private storage. We do not have access to it, and it is not sent to our servers. This includes:

  • Session history — which sessions you played, when, and for how long.
  • Check-ins and mood / "weather" entries — how you felt before or after a session.
  • Your calm score and progress — derived on-device from your own activity.
  • Biofeedback samples — passive signals read while a session runs: subtle chest movement from your phone's accelerometer, and, if you choose to connect one, heart-rate data from a Garmin, Apple Watch or compatible Wear OS watch. These signals are used in the moment to let a session gently follow your rhythm, and are stored only on your device.
  • Reminders you set — the time of a daily or program reminder, so the app can schedule a local notification. Reminders are scheduled on your device by the operating system; we are not told when one fires.
  • App settings and preferences — such as your chosen session length and placement.

Because this data lives on your device, it is removed when you delete the app, clear its data, or reset your phone. We cannot recover it for you, and it is not backed up to us. (Your own device or cloud backup, if you use one, is controlled entirely by you and your phone's operating system.)

Apple Health, Bluetooth and device permissions

A few operating-system permissions are involved when you connect optional hardware. In every case the data is used live during a session and stored only on your device.

  • Apple Health (HealthKit), on Apple Watch. If you use the SomaVibe watch app, it asks your permission to read your heart rate from Apple Health during a session. To keep that reading available while the screen is off, watchOS requires the app to start a temporary mind & body workout session — this is a technical requirement of the platform, and the workout is not saved to Apple Health. We do not write your heart rate or any other sample to Apple Health, we do not read any other health category, and health data obtained through HealthKit is never used for advertising, marketing, or shared with any third party, including our analytics and diagnostics providers. You can revoke this permission at any time in the Apple Health app.
  • Bluetooth. Used only to discover and connect a heart-rate wearable you choose to pair. We do not scan for, catalogue or transmit information about other nearby devices.
  • Location (Android 11 and older only). Older versions of Android required apps to hold the location permission in order to scan for Bluetooth devices at all. On those versions SomaVibe declares it for that reason alone — we do not collect, use, store or transmit your location. On Android 12 and newer the permission is not requested.
  • Notifications. Used only to deliver the reminders you set yourself. We do not send marketing or promotional push notifications.

Optional analytics and diagnostics

The core experience works offline. If the corresponding controls are enabled in Settings, SomaVibe sends two deliberately limited types of telemetry. These controls are independent and enabled by default, and can be turned off at any time; disabling one stops new reports of that type from being sent.

  • Anonymous product analytics (TelemetryDeck). We send a small, fixed set of categorical events, with no free text and no identity attached. In full, these are: a paywall being displayed; a purchase being started and its outcome; premium being activated; a session being completed; enrolling in a program, completing a program day, and finishing a program; setting, tapping and completing a reminder; viewing an insight and starting a session from one; saving and reusing a ritual; and a review prompt being requested. Alongside the event we send coarse parameters such as the session's category (for example "unwind" or "sleep"), the session or program identifier, whether the session was completed or cut short, and two yes/no flags derived from your check-in: whether you reported feeling a result, and whether your before-to-after shift was positive. TelemetryDeck also processes an anonymized per-installation identifier, a timestamp and basic app, operating-system and device metadata. See TelemetryDeck's privacy information.
  • Technical diagnostics (Sentry). We send crashes, unhandled technical errors and a small sample of performance measurements together with stack traces, app version, device model and operating-system details needed to diagnose them. We disable default PII collection, screenshots, Session Replay, UI/console/network breadcrumbs, logs and failed-request capture. We do not set a user identity and remove request, user and open-ended additional data before sending. See Sentry's privacy information.
  • What is never sent. Neither service receives your name or email address, your heart rate or any Apple Health data, the specific mood you selected, your numeric calm score, anything you typed, or your stored session-history records. The two check-in flags described above are the only signals derived from a check-in that ever leave your device, and they are sent as plain yes/no values with no identity attached.
  • No advertising use. These services are used only to improve SomaVibe and diagnose reliability; we do not use them for ads, profiling or cross-app tracking, and we do not sell or share them.
  • Turning them off. Both controls are in Settings, work independently, and are enabled by default. Switching one off stops new reports of that type immediately.

Why we're allowed to process this (legal bases)

Where the GDPR applies, we rely on the following legal bases for the limited data that leaves your device:

  • Your consent (Art. 6(1)(a)) — for wearable health-data access and for information submitted to the former launch waitlist. You can withdraw consent at any time by disconnecting a wearable, changing the relevant device permission, or emailing us; withdrawing does not affect processing already carried out.
  • Performance of a contract (Art. 6(1)(b)) — for verifying your purchase and unlocking the app.
  • Our legitimate interests (Art. 6(1)(f)) — for the privacy-limited analytics and diagnostics described above, keeping the app secure and reliable, improving the product, and handling your support requests. You can disable analytics and diagnostics independently in Settings.

Data that never leaves your device is not processed by us at all, so no legal basis is required for it. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

Where your data goes

We have no servers of our own holding your app data. The limited data described above is processed by the providers named in this policy, acting as our processors:

  • TelemetryDeck — anonymous product analytics, processed in the EU.
  • Sentry — technical diagnostics. Depending on the configured region this may involve a transfer outside the EEA; where it does, the transfer is covered by the European Commission's Standard Contractual Clauses.
  • Apple and Google — purchases and app distribution, under their own privacy policies and as independent controllers for the payment relationship.

Purchases

SomaVibe is free to download. The optional SomaVibe+ unlock is a one-time ("lifetime") purchase made through the in-app purchase system available on your device. The payment, your billing details and any refund are handled entirely by the relevant app store under its own privacy policy — we never see or store your payment-card information. The store tells the app whether a valid purchase exists so it can unlock; restoring a purchase works the same way through the store.

Former launch waitlist

The launch waitlist is closed, and this website no longer collects email addresses. Before launch, the waitlist submitted the email address you provided together with the form location, browser locale, page path and submission timestamp. We used that information only for launch communication, did not connect it to app data or share it, and delete each record no later than 12 months after it was submitted. You can ask us to delete a former waitlist record at any time by writing to the support address below. The app itself never sends us your email.

What we don't do

  • We don't sell or rent personal information, including former waitlist records or details you include in a support request.
  • We don't run third-party advertising or ad-tracking SDKs.
  • We don't require you to create an account or sign in.
  • We don't upload your session-history records, your check-in answers, your calm score or your biofeedback readings — they stay on your device.
  • We don't use your health data for advertising or share it with data brokers.
  • We don't track you across other apps or websites.

Children's privacy

SomaVibe is intended for adults and is not directed at children under 13 (or the minimum age of digital consent in your country, where higher). We do not knowingly collect personal information from children. If you believe a child has used the app in a way that concerns you, contact us at contact@somavibe.app and we'll help.

Your rights (GDPR, CCPA and similar laws)

Because SomaVibe is local-first and does not hold wellness data tied to your identity, most data about you never leaves your device, and you control it directly: you can view, change or delete it in the app, and you can remove all of it by deleting the app.

Depending on where you live, you may have rights under laws such as the EU/UK General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA) — including the right to access, correct, delete or port your data, and to object to or restrict certain processing. Because SomaVibe keeps your wellness data on your device, you exercise most of these rights directly: view or change it in the app, and delete all of it by removing the app. Anonymous telemetry may not be linkable back to you, but you can stop future collection using the controls in Settings. We do not "sell" or "share" personal information as those terms are defined under the CCPA, and we do not offer financial incentives in exchange for personal information. To make any request or ask a question, email contact@somavibe.app. We will respond within the time limits the applicable law sets — under the GDPR, normally within one month. We will not discriminate against you for exercising any of these rights.

Right to complain. If you think we have handled your data improperly, we'd like the chance to put it right first — but you also have the right to lodge a complaint with a data protection authority. Our lead supervisory authority is the Polish Urząd Ochrony Danych Osobowych (UODO, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl). If you live elsewhere in the EEA or the UK, you may complain to your local authority instead.

Data retention and security

On-device data is kept until you delete it or remove the app — deleting the app deletes all of it, and no separate deletion request is needed. Anonymous analytics events are retained by TelemetryDeck in aggregate form; diagnostic events are retained by Sentry for a limited period (currently 90 days) and then deleted. Former waitlist records are handled as described above. We use reasonable technical measures to protect the limited data the app handles, though no method of storage or transmission is ever completely secure.

Changes to this policy

We may update this policy as the app evolves. When we do, we'll change the "last updated" date above and, for significant changes, note it in the app or on this page. Continued use of SomaVibe after an update means you accept the revised policy.

Contact us

Questions about your privacy, or want to make a request? Email contact@somavibe.app and we'll get back to you.