Privacy Policy — Clock It
Effective date: 19 July 2026 · Last updated: 10 August 2026
This Privacy Policy explains how the developer of Clock It ("we", "us") collects, uses, and shares information when you use the Clock It mobile application ("the App"). By using the App you agree to this Policy.
1. Summary
- We collect the minimum needed to run the App: an account identifier, your alarms and wake statistics, and (optionally) a profile picture, Photo Match reference photos, and sleep-sampler metrics.
- The optional microphone "sleep sampler" runs only while the App is open and you have turned it on. It records briefly to measure loudness, then deletes the recording immediately — only derived numbers (e.g. how long it took to fall asleep, snore counts) are saved. The audio itself is never stored or uploaded.
- Those sleep numbers are general wellness information, not medical information. Clock It is not a medical device, makes no diagnosis, and must not be used to detect or treat any condition.
- Only two kinds of image ever leave your device — your profile picture and a Photo Match reference photo, both only if you choose them. Wake Screen photos and videos, and the photos taken to complete a wake mission, never leave your device.
- The App does not use location services and does not collect your location, and our analytics provider is configured not to derive an approximate location from your IP address.
- Our product analytics do not include your name, email, or any directly identifying information — only an opaque account ID and your subscription tier.
- We do not sell your personal information.
2. Information we collect
Account information. When you create an account we process your email address (for one-time passcode sign-in) or, if you use Apple sign-in, the identifier Apple returns. This is handled by our authentication provider (Supabase) and is used to create and secure your account. You may also add a display name, which is optional and shown only to you.
Profile picture (optional). If you set a profile picture, the image is uploaded to our backend provider (Supabase) and linked to your account. Profile pictures are stored in a private storage bucket and are accessed through short-lived signed links that the App requests when needed. You can replace the picture at any time, and you never have to set one.
Alarm and usage data. Your alarms, chosen wake "missions", chaos-window settings, snooze events, streaks, and wake outcomes (e.g. whether you dismissed an alarm on time). This is stored so your data syncs across devices and powers your stats.
Camera (wake missions). Some wake missions ask you to photograph something or scan a QR code to prove you are out of bed. The camera is used only for those missions, and the pictures you take to complete one are held in the App's memory just long enough to compare or scan them. They are never saved to your photo library and never uploaded. You can decline the camera permission and choose a mission that does not use it.
Photo Match reference photos (optional). The Photo Match mission works by comparing a photo you take at wake time against a reference photo you take when you set the alarm up. That reference photo is uploaded to our backend provider (Supabase) so it survives reinstalling the App, and it is stored in a private bucket — the App fetches it over a short-lived signed link (valid for five minutes) at wake time. Only you can retrieve it. If you never choose a Photo Match mission, no reference photo is ever taken or uploaded.
Wake Screen media (stays on your device). If you set one of your own photos or videos as a Wake Screen, the App copies that file into its own private storage on your device. It is used to draw the alarm screen and to attach the image to the alarm notification on your lock screen. It is never uploaded to us or to anyone else.
Sleep-sampler metrics (optional, microphone). If you enable the in-App sleep sampler, the App uses the device microphone while open to compute sleep-related metrics — estimated time to fall asleep, sleep duration, snore events, and a restlessness score. It works only from loudness (decibel) readings. We never read, retain, or transmit the audio itself; the recording is deleted as soon as those readings are taken, and only the derived metrics are stored. These metrics are general wellness information, not medical information: Clock It is not a medical device, does not diagnose, screen for, or treat any condition (including sleep apnea or any other sleep disorder), and should not be relied on for any health decision. Talk to a qualified clinician about anything health-related. You can decline the microphone permission and use the rest of the App normally.
Subscription information. Purchases of Clock It Premium and the Emergency Pass are processed by Apple and managed through RevenueCat. We receive your subscription status (active/expired, plan, renewal dates) but not your full payment details (card numbers etc. stay with Apple).
Diagnostics. We use Sentry for crash reporting; crash reports are tied only to your opaque account ID, not to your name or email.
Product analytics. We use PostHog to understand how the App is used — which screens are opened, which features are used, and app-lifecycle events such as install, update and open. Events are attributed to an opaque account identifier plus non-identifying traits (subscription tier, account-creation date, and your selected onboarding "persona" archetype). We do not send your email, name, phone number, or alarm contents to analytics, and we have switched off PostHog's IP-based location lookup, so no city or country is derived from your connection.
Advertising (free tier only). If you use the free tier, we show ads via Google AdMob. We request non-personalised ads only, rated for general audiences. AdMob may process device-level advertising identifiers as described in Google's policies. We do not use any of this for tracking you across other companies' apps or websites, and the App does not ask for tracking permission.
Email delivery. Sign-in passcodes and any service emails we send you are delivered through Resend, our email provider. Resend processes your email address and the contents of that message solely to deliver it on our behalf.
3. How we use information
We use the information above to: create and secure your account; schedule and fire alarms; run the wake mission that unlocks the alarm; compute streaks and stats; provide the optional sleep and wellness metrics; process subscriptions; show ads on the free tier; send you sign-in passcodes; diagnose crashes; and improve the App. We do not use any of it to make health claims about you or to give you medical advice. We rely on your consent (e.g. microphone, optional features), performance of our agreement with you (running the App you signed up for), and our legitimate interests (security, analytics, improvement) as legal bases where applicable.
4. Who we share information with
We share information only with the service providers that operate the App on our behalf:
- Supabase — authentication, database, file storage (profile pictures and Photo Match reference photos), and backend functions (data hosting).
- Resend — delivery of sign-in passcodes and service emails.
- RevenueCat and Apple — subscription management and payment processing.
- PostHog — product analytics (no PII, as described above).
- Sentry — crash diagnostics.
- Google AdMob — advertising on the free tier.
- Expo — to deliver push notifications (if enabled).
We do not sell your personal information and do not share it for cross-context behavioural advertising. We may disclose information if required by law or to protect our rights and users' safety.
5. Data retention and deletion
We keep your data for as long as your account is active. You can delete your account from within the App (Profile → account deletion), which removes your account and the records attached to it — alarms, wake sessions, streaks, sleep metrics and subscription records — together with any images you uploaded, namely your profile picture and any Photo Match reference photos. This is subject to limited retention required by law or for fraud prevention. Images captured to complete a wake mission are never uploaded, so there is nothing to delete on our side. You may also contact us at clockit.support@gmail.com to request access to or deletion of any of your data.
6. Your rights
Depending on where you live (e.g. EEA/UK under GDPR, California under CCPA/CPRA), you may have rights to access, correct, delete, or port your data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact clockit.support@gmail.com. You will not be discriminated against for exercising your rights.
7. Data security
We use industry-standard measures to protect your data, including encrypted transport (HTTPS), access-controlled databases (row-level security), and server-authoritative entitlement checks. Your authentication session is stored on your device. No method of transmission or storage is 100% secure, but we work to protect your information.
8. Children
Clock It is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us data, contact us and we will delete it.
9. International transfers
Your information may be processed in countries other than your own (including the United States) where our service providers operate. We rely on appropriate safeguards for such transfers where required.
10. Changes to this Policy
We may update this Policy from time to time. We will update the "Last updated" date above and, for material changes, provide notice in the App. Continued use after changes means you accept the updated Policy.