Legal
Privacy
policy.
How Awakenn handles your information across the app and awakennapp.com. Written to be read, not skimmed past.
1. Who we are
Awakenn is a morning-devotion and alarm app for iOS (“Awakenn”, the “App”), provided by Awakenn Pte. Ltd. (UEN 202616337E), a company incorporated in Singapore (“we”, “us”, “our”). We are the data controller.
This Policy is presented to you before you create an account and before we collect personal data, satisfying our notification obligation under s.20 of Singapore’s Personal Data Protection Act 2012 (PDPA). It is governed by Singapore law; any dispute about it is subject to the dispute-resolution and governing-law provisions of the Terms of Use. For privacy questions or to exercise your rights, contact business@awakennapp.com or our Data Protection Officer (Section 13).
2. A note on faith-related data
Awakenn is a Christian devotional app. Information about your use of the App — which devotions you play, complete, bookmark, or highlight — can reveal that you hold religious beliefs. Where the EU/UK GDPR applies to you this is special-category data (Article 9), and it is “sensitive data” under several US state privacy laws (see Section 10.3). In all cases we treat it as sensitive.
Our legal basis is your explicit, affirmative consent, which we ask you to give through a clear opt-in step when you start using the App. You can withdraw this consent at any time — it is as easy to withdraw as it was to give: turn off devotional-data processing in Settings → Privacy (this disables the personalised devotional features that depend on it) or delete your account entirely (Section 10). Withdrawal does not affect processing already carried out.
We use this data to operate the devotional features. Separately, and only if you give optional consent, we record devotional-engagement events (which devotions you play, complete, bookmark, highlight, or reflect on — tagged with your anonymous identifier, never your name, email, or the text you write) and analyse them in aggregate to understand which content resonates and to plan and improve devotional content. This optional consent is never bundled with the consent required to use the App, and you can switch it off at any time in Settings → Privacy (Section 3.3). We never build advertising profiles, and we never sell this data.
3. What we collect, and why
3.1 Account and identity
| Data | When | Purpose | GDPR basis |
|---|---|---|---|
| Anonymous account identifier (random UUID) | First launch | Operate your account; link content, subscription, analytics | Contract |
| Your name | Via Sign in with Apple, if shared | Display your account | Contract |
| Your email (incl. Apple private-relay) | Via Sign in with Apple | Account identification; service communications | Contract |
| Apple sign-in identifier | With Sign in with Apple | Stored only on your device (iOS Keychain) to keep you signed in; not sent to us | Contract |
3.2 Subscriptions and payments
Purchases are processed by Apple — we never receive or store your card number or full payment details.
| Data | Source | Purpose | GDPR basis |
|---|---|---|---|
| Purchase/subscription history; entitlement; product, renewal, expiry | Apple StoreKit + RevenueCat | Unlock paid features; manage subscription | Contract |
| Billing events (price, country, store, cancellation reason); Apple subscription notifications | RevenueCat / Apple → our backend | Billing integrity; fraud prevention; accounting | Legitimate interests (accurate billing and preventing fraudulent entitlement claims; narrowly scoped, no profiling); legal obligation (tax) |
| Cancellation feedback you optionally type | You | Understand churn; improve the App | Consent |
3.3 Usage and analytics (you control this)
We record two kinds of usage events. Both are processed by PostHog and tagged with your anonymous identifier — never your name or email — and we do not send your personal content (reflection/journal text, highlighted passages, free-text feedback) to PostHog.
- Devotional-engagement events — playback started/finished, devotions completed, bookmarks and highlights created, reflections saved/discarded, prayers shown/completed (the event and the content item, never the text you write). Because these events can reveal religious belief (Section 2), they are recorded only if you give the separate optional consent described in Section 2 — wherever you live — and they stop when you withdraw it in Settings → Privacy. Legal basis: explicit consent.
- General usage events — app opened/installed/updated, onboarding steps, alarms set/fired, paywall views, subscription changes, downloads, and notification-permission outcomes, with your app version and OS version (no devotional-content identifiers). Legal basis: consent. For users in the EU/EEA and the UK these are off by default and run only if you opt in (affirmative consent, GDPR Art. 4(11)); elsewhere, they may be on by default and you can turn them off at any time in Settings → Privacy, effective by your next session.
3.4 Crash and diagnostic data
To keep the App stable we collect crash reports, performance/diagnostic data, a crash-correlation installation identifier, and limited technical breadcrumbs via Firebase Crashlytics, not linked to your name or email. Legal basis: legitimate interests (maintaining stability and diagnosing faults; minimal pseudonymous data, 90-day retention). You can object via business@awakennapp.com.
3.5 Content you create
When signed in, these sync across your devices via our backend: bookmarks, saved albums, alarm settings, highlights (including the text you highlight), and reflections (the journal text you write, up to about 64 KB). Legal basis: contract; plus special-category consent where content reveals religious belief (Section 2).
3.6 Data that stays on your device
Your devotion completion history and your downloaded audio and transcripts never leave your device.
3.7 Device permissions, notifications, marketing
- Alarms and notifications: local notifications and alarms only — no remote push token is created or sent to us.
- The App does not request microphone, camera, location, or contacts access, and does not track you across other apps or websites (Section 7).
- Marketing: we send service communications (for example, subscription confirmations). We do not currently send marketing email; if we do, it will carry the “ADV” label required by Singapore’s Spam Control Act, with a working unsubscribe honoured within 10 days. Consent to marketing is separate and optional — never a condition of using the App. We send no marketing SMS or calls.
4. Automated decision-making and profiling
We do not make decisions about you that produce legal or similarly significant effects through solely automated processing (GDPR Arts. 13(2)(f), 22). Your daily devotion is chosen by a rules-based algorithm (not a profile); subscription access is determined by Apple and RevenueCat from your purchase record (contractual — contest errors at business@awakennapp.com); analytics are aggregate only. We do not use AI to generate content or make automated decisions about your experience.
5. How we share data (processors)
We do not sell your personal data and do not share it for cross-context behavioural advertising. We share only with vetted processors under data-processing agreements (all in place):
| Processor | Receives | Purpose | Where |
|---|---|---|---|
| Supabase | Account data, your content, subscription records | Database and backend hosting | Singapore (ap-southeast-1) |
| RevenueCat | Anonymous id, purchase data | Subscription management | United States |
| PostHog | Anonymous id, usage events (if analytics on) | Product analytics | United States |
| Firebase Crashlytics (Google) | Crash data, installation id | Crash reporting | United States |
| Apple | Payment and purchase data | App Store billing | Per Apple |
We may also disclose data where required by law, to enforce our terms, to protect rights and safety, or in a merger or acquisition (you will be notified of any change affecting your data). We may use aggregate or de-identified data that cannot identify you; it is not personal data.
6. International data transfers
Your account data and content are hosted by Supabase in Singapore (ap-southeast-1), so they are not transferred out of Singapore. Some other processors (RevenueCat, PostHog, Firebase Crashlytics) are in the United States. Where we transfer personal data out of Singapore we comply with the Transfer Limitation Obligation (s.26 PDPA) by ensuring comparable protection — through the EU Standard Contractual Clauses (which the PDPC recognises as satisfying s.26) and/or the ASEAN Model Contractual Clauses in our processor agreements. For EU/EEA and UK personal data, because Singapore is not subject to an EU or UK adequacy decision, we rely on the EU SCCs and the UK Addendum for the transfer to our Singapore-hosted backend and to any US processor. Request a copy of safeguards at business@awakennapp.com.
7. Tracking and advertising
Awakenn shows no advertising and does not track you across other companies’ apps or websites. Our App Privacy Manifest declares no tracking (NSPrivacyTracking = false); we do not use Apple’s advertising identifier (IDFA) or show the App Tracking Transparency prompt. We do not “sell” or “share” personal data; we honour the Global Privacy Control signal, which has no further practical effect on our processing.
8. Data retention
We keep data only as long as needed, consistent with our Retention Limitation Obligation (s.25 PDPA).
| Data | Retention |
|---|---|
| Account, profile, and content (bookmarks, highlights, reflections, alarms, saved albums) | Until you delete it or your account; removed within 30 days, backups purged within 90 days |
| Subscription, entitlement, and billing records | As required by tax and accounting law — up to 5 years |
| Product analytics (PostHog) | Up to 24 months, then aggregated or deleted |
| Crash and diagnostic data | Up to 90 days |
| Cancellation feedback | Up to 24 months |
9. Security and data-breach notification
We protect your data with encryption in transit (TLS) and at rest, access controls, and device-only storage (iOS Keychain) for sign-in credentials. No method is perfectly secure. Where a breach involving your personal data is notifiable, we will notify Singapore’s PDPC as soon as practicable and in any case within 3 calendar days of determining the breach is notifiable (PDPA Part 6A, s.26D — where the breach is likely to result in significant harm to affected individuals, or affects 500 or more individuals), the relevant EU or UK supervisory authority within 72 hours (GDPR Art. 33), and you without undue delay where there is high risk to you (GDPR Art. 34). Report a suspected issue at business@awakennapp.com.
10. Your privacy rights
You may have rights of access, correction, deletion, portability, restriction, objection, and withdrawal of consent. You will not be discriminated against for exercising them. Data portability, where it applies, covers the personal data you provided that we process by automated means on the basis of consent or contract (GDPR Art. 20); it does not extend to data we infer or to records we must keep by law.
- Delete your account and data in the App at Settings → Account → Delete account, or email business@awakennapp.com.
- Turn off analytics in Settings → Privacy.
- Any other request: email business@awakennapp.com. We verify and respond within 30 days (PDPA/GDPR); where a US state law applies, within the period it requires (typically 45 days, extendable).
10.1 EU/EEA and UK users (GDPR / UK GDPR)
We currently direct the App at users in Singapore, the United States, and other markets. The App can be downloaded in the EU/EEA and UK through Apple’s worldwide App Store, but we do not specifically direct it at, market it in, or localise it for the EU/EEA or UK. If and when we begin offering the App to users in the EU/EEA or UK, the EU/UK GDPR applies to that processing and you may exercise all GDPR rights above and lodge a complaint with the supervisory authority where you live or work (list at edpb.europa.eu; in the UK, the ICO). At that point we will have appointed EU and UK Article 27 representatives (Section 13) and completed the related steps (a data-protection impact assessment and records of processing). Until then, if you are in the EU/EEA or UK and use the App, we still treat your faith-related data as sensitive and honour the access, correction, deletion, and withdrawal choices described above.
10.2 Singapore users (PDPA)
- Access (s.21): request your personal data and how it was used or disclosed in the prior 12 months; we respond within 30 days or tell you when we can.
- Correction (s.22): request correction of errors; we send corrections to relevant third parties.
- Withdraw consent (s.16): via business@awakennapp.com or Settings → Privacy; this does not affect prior processing, and may mean we cannot continue providing some features.
- Overseas transfers (s.26): see Section 6. Data portability (Part VIB): enacted but not yet in force; we will provide it when it commences.
- Complaints: contact our DPO (Section 13); if unresolved, the PDPC (pdpc.gov.sg, 1800-7372-529).
10.3 United States users
We do not sell or share your personal information for cross-context behavioural advertising.
- California (CCPA/CPRA). Awakenn is not currently a “business” under the CCPA/CPRA — it does not meet the revenue or volume thresholds in Cal. Civ. Code §1798.140(d). Those obligations therefore do not yet apply; if that changes we will publish a full California notice. Meanwhile, California residents may exercise choices by emailing business@awakennapp.com.
- Other US states — sensitive data (for example Virginia, Colorado, Connecticut, Texas, Oregon). Several state comprehensive privacy laws classify information that reveals religious beliefs as “sensitive data” requiring consent before processing. Most (Virginia, Colorado, Connecticut, Oregon) only apply once a controller meets a volume threshold (commonly 100,000 state residents), which a newly launched app does not yet meet; Texas has no volume threshold but its hard rule bars selling sensitive data without consent — and we do not sell data. So these duties are largely not yet triggered for us. Even so, because your devotional use can reveal religious belief, we ask for your affirmative consent before processing it as a forward-looking, conservative measure — the same opt-in step described in Sections 2 and 3.5 — and we honour requests to access, correct, delete, or opt out at business@awakennapp.com.
- Consumer health data (for example Washington’s My Health My Data Act). We do not knowingly collect or use “consumer health data” as those laws define it: we do not use your reflections, highlights, or alarm activity to infer your physical or mental-health status, we do not geofence, and we do not sell any such data. We do not hold ourselves out as a “regulated entity.” If you choose to write health-related thoughts in a free-text reflection, that text stays in your account, is not analysed to derive health status, and is deleted with your account. We will reassess if our practices materially change.
11. Children
Awakenn is directed at adults and not to children under 13 (or under the minimum age of digital consent where you live, up to 16 in some EU states). We do not knowingly collect personal data from children under that age; if we learn we have, we delete it promptly. Parents and guardians: contact business@awakennapp.com, subject “Child Account.”
12. Changes to this Policy
We may update this Policy. If changes are material we give reasonable notice (in-app or email) before they take effect, and we review it at least annually. Previous versions are available on request at business@awakennapp.com, and listed in the version archive.
13. Contact
Awakenn Pte. Ltd. · Privacy: business@awakennapp.com
Data Protection Officer (PDPA, ss.11(3)–(5)): reachable at business@awakennapp.com. A designated individual serves as our DPO; this business contact is published under s.11(5). We aim to acknowledge requests within 5 business days.
EU Representative (GDPR Art. 27) and UK Representative (UK GDPR Art. 27): to be appointed if and when we offer the App in the EU/EEA or the UK, as described in Section 10.1. Until then no representative is appointed, and requests should come to the privacy address above.