SafeSound (“SafeSound,” “we,” “us,” or “our”) is a meditation and audio relaxation mobile application. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
By using SafeSound, you agree to this Privacy Policy. If you do not agree, please do not use the app.
Contact: [email protected]
1. Who this policy covers
This policy applies to the SafeSound iOS app (and any related Android or web versions we release) operated under the bundle identifier com.safesound.app.
SafeSound is designed so you can use the app without creating a traditional account with an email or password.
2. Who is responsible for your data
SafeSound is operated by an individual, who is the data controller for personal data processed through the app:
Graham Vonnegut, 13 Horace Court, Brooklyn, NY 11218, USA
Contact for all privacy questions and requests: [email protected]
3. Information we collect
3.1 Account identifier (anonymous)
When you first open SafeSound, we create a private anonymous account in our backend (Supabase Auth). That account is identified by a random user ID. We do not require an email address, phone number, or password to use the app.
We also record, against that ID, when you last opened the app (updated at most about once an hour) and, if you had SafeSound Pro, when it ended. We use this only to delete inactive accounts (see Section 8) and to time the warnings we send before that happens.
3.2 Profile information you provide
During onboarding (and if you later update settings), you may provide:
- A display name (optional first name or nickname)
- A wellness goal / category preference (for example Anxiety Relief, Falling Asleep, Focus)
We store these in your profile (hosted by Supabase) so we can personalize the experience. Your wellness goal is used only to personalize your onboarding and recommendations. We do not send it to our analytics provider, and we never share it with advertisers or use it for advertising.
3.3 Favorites and app preferences
If you heart a track or meditation, we store that favorite against your anonymous user ID so it appears on your Favorites tab across sessions.
On your device only, we may also store preferences such as:
- Onboarding progress flags
- Notification on/off preference and local trial-reminder metadata
- Which catalog tracks you have enabled for 8D playback
- Offline library / download index for content you save on device
3.4 Subscription and purchase status
If you start a free trial or purchase SafeSound Pro, Apple (or Google, if applicable) processes the payment. We use RevenueCat to verify entitlement status and sync a high-level subscription status to your profile (for example free, free trial, or subscribed / premium).
We do not receive your full payment card number. Apple/Google handle billing. RevenueCat and our servers receive purchase/entitlement metadata needed to unlock premium content and restore purchases.
3.5 Aggregate content popularity (not a personal listening history)
When anyone plays a catalog track, we may increment that track’s overall play count so we can surface popular sounds. This is an aggregate counter on the track, not a personal listening log tied to your identity in the product UI.
Usage limits: To prevent abuse and keep costs fair, when your device requests a catalog audio file we record, against your anonymous user ID, which file was requested, its size, and when. So limits apply per subscription rather than per install, we store a one-way hashed identifier derived from your store subscription on your profile. We also record when your device calls our servers so we can limit excessive requests. We use this only to enforce limits, and we delete these records after about 31 days (request records after about 1 day).
3.6 Product analytics and diagnostics (PostHog)
We use PostHog to understand how people use SafeSound — for example which screens are reached, whether onboarding and playback work, and high-level subscription funnel events. Analytics events are tied to your anonymous user ID and may include:
- App screens you visit and that you tapped a button or item (not its text or label, and never what you type)
- Feature usage: play starts, listen milestones, favorites, downloads, and 8D-ifier actions. These events do not say which track or meditation it was or what category it belongs to (for example Anxiety Relief or Falling Asleep)
- Account status attributes such as subscription status, whether you finished onboarding, and whether notifications are on
- Device model, operating system and app version, language, and time zone
- Error reports if something goes wrong in the app (the error message, where in the app it happened, and app and device version)
Session replays (off unless you turn them on). Session replays are off by default. They only happen if you turn on Profile → Privacy → Share usage recordings, and you can turn that off at any time; recording stops right away. While it is on, PostHog records a visual replay of how the app is used: which screens you open, where you tap and scroll, and how the app responds. We watch replays to find bugs and screens that are confusing or broken. To protect your privacy:
- All text on screen and everything you type is masked (covered with solid blocks) on your device, before the replay is sent. Your display name is also specifically hidden wherever it appears.
- System screens are not captured, including the file picker used by 8D-ifier, Apple’s purchase and review sheets, and permission prompts.
- Images in the app, which are SafeSound catalog artwork, appear as-is.
- Replays do not include audio, your microphone or camera, files you pick in 8D-ifier, the app’s console logs, or network requests.
- Replays are linked to your anonymous user ID, like other analytics events.
We do not send your display name, the wellness goal you chose, which content you listen to, email, precise location, or contact lists to PostHog.
3.7 Media you process in 8D-ifier
The 8D-ifier lets you pick an audio or video file from your device and apply a spatial (“8D”) effect. For videos, only the audio track is used. Processing happens on your device. We do not upload your picked files to our servers for 8D-ifier processing. If you export or share the result, you choose where it goes through the system share sheet.
The 8D-ifier screen may use your device’s motion sensors to gently tilt its animated background as you move your phone. Motion readings are used only on your device, in the moment, and are never stored or sent to us or anyone else.
3.8 Notifications
If you allow notifications, SafeSound may schedule local reminders on your device (for example a daily unwind reminder or a trial-expiry reminder). If you have a free account, SafeSound also schedules notices warning you before your account is deleted for inactivity (see Section 8). These reminders are managed on-device. We do not sell notification data.
3.9 Information we do not intentionally collect
We do not intentionally collect:
- Email, phone number, or postal address (unless you email us for support)
- Precise location
- Contacts, calendar, or health/medical records from Apple Health
- Advertising identifiers for third-party ad networks
We also do not sell your personal information.
4. How we use information
We use the information above to:
- Provide and operate SafeSound (accounts, playback, favorites, offline library)
- Personalize onboarding and content recommendations based on your goal
- Unlock and restore SafeSound Pro entitlements
- Improve catalog ranking using aggregate play counts
- Understand product usage and fix problems via analytics, session replays, and error reports
- Send optional local reminders you allow
- Delete free accounts that have not been used for 6 months, and warn you before we do
- Respond when you contact support
- Maintain security, prevent abuse, and comply with law
5. Legal bases (EEA, UK, and similar laws)
Where laws like the GDPR apply, we rely on these legal bases:
- Performance of a contract: to provide the app you asked for: your anonymous account ID, display name and goal, favorites, and subscription status.
- Legitimate interests: to understand and improve SafeSound through analytics and error reports, to rank content using aggregate play counts, to prevent abuse and keep the service affordable through usage limits and request limits, and to avoid keeping data about people who have stopped using SafeSound by recording when you last opened the app and deleting inactive accounts. You can object to this processing by emailing us.
- Consent: for session replays, which only happen if you turn on Share usage recordings in Profile, and for notifications. You can turn either off at any time in the app (and notifications also in system Settings).
- Legal obligation: to keep limited purchase and accounting records where the law requires it.
6. How we share information
We share information only as needed to run the app:
| Recipient | Role |
|---|---|
| Supabase | Hosts authentication, your profile, favorites, and catalog data |
| RevenueCat | Verifies and manages in-app subscription entitlements |
| PostHog | Processes product-analytics events, session replays, and error reports described above |
| Apple / Google | Processes payments and may share purchase receipts / transaction metadata needed for subscriptions |
| Service providers we engage | Only if needed to operate SafeSound (hosting, email support tools), under obligations to protect your data |
We do not sell personal information. We do not share personal information with third parties for their own advertising.
We may disclose information if required by law, legal process, or to protect the rights, safety, or integrity of SafeSound, our users, or the public.
If SafeSound is involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction, subject to this policy or a successor policy with notice where required.
7. Data storage and security
Profile, favorites, and related account data are stored in our cloud database (Supabase). Analytics events and session replays are processed by PostHog. Session tokens and some preferences are stored locally on your device.
We use reasonable administrative, technical, and organizational measures designed to protect information. No method of transmission or storage is 100% secure.
8. Data retention
We retain profile and favorites data for as long as your anonymous account exists and the data is needed to provide SafeSound.
Inactive accounts. If you have a free account and do not open SafeSound for 6 months, we automatically and permanently delete your account. If you had SafeSound Pro, the 6 months are counted from whichever is later: the last time you opened the app or the day your subscription ended. We never delete an account while it has an active SafeSound Pro subscription or free trial. Deletion removes the same data as deleting your account yourself (see Section 9): your profile, favorites, usage-limit records, your customer record at RevenueCat, and your PostHog analytics data and session replays. If an automatic deletion fails (for example because a provider is temporarily unavailable), we keep a record of the failed attempt, meaning your anonymous user ID, the time, and the error, so we can retry. That record is removed when the account is deleted.
If you have allowed notifications, SafeSound will warn you on your device about 4 months and 5 months after you last opened the app, and again about 7 days before the deletion date. Because these warnings are scheduled on your device, you will not receive them if notifications are turned off, or if you have deleted the app or reset your device. Opening SafeSound at any time before the deletion date keeps your account and restarts the 6 months.
Deleting an inactive account does not delete files on your device (such as downloads), which remain until you delete the app. If you open SafeSound after your account was deleted, the app creates a new, empty anonymous account. Deletion does not cancel an App Store / Play subscription, and a subscription you buy again, or restore, works with the new account.
Local preferences remain on your device until you clear app data, uninstall the app, or we delete them as part of a reset.
Aggregate track play counts are retained as part of the catalog.
Audio usage-limit records (which file, its size, and when) are deleted after about 31 days, and server request records after about 1 day.
Analytics events, error reports, and session replays in PostHog are kept for 30 days from when they are collected and are then deleted automatically.
If you ask us to delete your account data (see below), we will delete or de-identify personal data we control, including your PostHog analytics data and session replays, except where we must retain information for legal, security, or accounting reasons (for example limited subscription records).
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing.
You can:
- Change your name or goal information in the app where those controls exist
- Remove favorites
- Turn notifications off in SafeSound and/or system Settings
- Manage or cancel SafeSound Pro in your Apple ID / Google Play subscription settings
- Turn session replays on or off at any time in Profile → Privacy → Share usage recordings (off by default)
- Delete your account at any time in Profile → Account → Delete Account. This immediately and permanently deletes your profile, favorites, usage-limit records, subscription customer record at RevenueCat, and PostHog analytics data and session replays, and erases SafeSound data stored on your device. Deleting your account does not cancel an App Store / Play subscription — cancel that separately.
- Keep your account by opening SafeSound at least once every 6 months. Free accounts not used for 6 months are deleted automatically (see Section 8).
- Email [email protected] to request access to or deletion of personal data associated with your account (including related analytics identifiers where feasible)
Because SafeSound uses an anonymous account, please include enough detail for us to locate your account (for example approximate signup timing, device type, and any name you entered). If we cannot verify the account, we may be unable to complete certain requests.
If you are in the EEA, UK, or similar jurisdictions, you may also have the right to lodge a complaint with your local data protection authority.
10. Children’s privacy
SafeSound is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact [email protected] and we will take appropriate steps to delete it.
11. International transfers
We and our providers may process information in the United States and other countries. Those countries may have different data-protection laws than your home country. Where required, we rely on appropriate safeguards for cross-border transfers, such as the European Commission’s Standard Contractual Clauses offered by our providers.
12. Third-party services and links
SafeSound relies on third-party infrastructure described above. Their processing of information is also governed by their own policies, including:
- Supabase privacy documentation
- RevenueCat privacy documentation
- PostHog privacy documentation
- Apple App Store / Google Play terms and privacy practices for purchases
The app may open system share sheets or mail composers you control. We are not responsible for third-party sites or services you choose to use outside SafeSound.
13. Wellness disclaimer
SafeSound provides audio for relaxation and wellness. It is not a medical device and does not provide medical advice, diagnosis, or treatment. Information you share about a wellness goal is used for personalization only. It stays in your profile, is not sent to analytics providers, is never shared with advertisers or used for advertising, and is deleted when your account is deleted.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will change the “Last updated” date at the top and, when changes are material, provide additional notice in the app or by other reasonable means. Continued use of SafeSound after an update means you accept the revised policy.
15. Contact us
Questions about privacy or this policy: