Privacy policy
For the rules governing the service, read the Terms of use.
Privacy
Giulio Orlandi is responsible for the personal data CoWake processes, as its data controller. Contact help@cowake.app about your data.
CoWake has no ads or third-party analytics SDKs. It doesn't request access to your contacts or location, sell personal data, or share it for advertising. CoWake doesn't record calls.
Data CoWake handles
- Account and profile: your account ID, display name, profile picture, privacy settings, and Apple sign-in identifier if linked.
- Friends and alarms: friendships, blocks, invites, alarm times and time zones, schedules, members, and synchronization records.
- Mornings: attendance and confirmation times, including the device's UTC offset where recorded, used to show wake history and shared mornings.
- Devices and calls: notification tokens, device and app information, connection details, and presence needed to connect calls and show who has arrived.
- Reports: the people and call involved, the reason, the time, and any explanation you provide.
- Purchases: subscription and entitlement information. Apple handles payment details.
- Usage: first-party events used to understand how CoWake is used, stored in its own database.
- Feedback: posts, votes, reports, verification status, contribution counts and times, and an anonymous account session stored in your browser's local storage.
- Email: your email address and whatever you include in messages.
- Hosting: IP addresses and request information processed by service providers to deliver and protect the service.
The website doesn't set advertising or analytics cookies. A morning selfie you choose to share uses your phone's sharing tools; CoWake doesn't upload it to its servers. A profile picture you set is uploaded so other people can see it.
Who can see it
Your friends can see your profile according to your visibility settings. People sharing an alarm can see its roster and whether you showed up. Anyone with an invite link can see the inviter's name and the alarm time when one is included. Anyone can read the feedback wall, without seeing the author's name.
Calls and encryption
Every call is encrypted end to end, with keys made on the participants' phones. Cloudflare, which carries the calls, never receives a key and can't see or hear them. CoWake doesn't record calls.
Two-person calls connect directly between phones when possible. A direct connection exposes your IP address to the other participant. When it can't connect directly, Cloudflare relays the call without being able to read it.
Calls with three or more people pass through Cloudflare's servers, which forward each person's audio and video without being able to decrypt it. To do that, Cloudflare sees technical details such as your IP address, when you're connected, and the size and timing of the data.
CoWake's servers pass each phone's public key to the others in the call, and never receive the keys that encrypt it. The encryption relies on those servers passing the public keys on unaltered: a server that swapped one could read the call. CoWake doesn't offer a way to compare keys in person, as some calling apps do.
Service providers
- Supabase: database, authentication, profile-picture storage, presence, and server functions.
- Cloudflare: website hosting, call infrastructure, and human verification on the feedback wall.
- Apple: sign-in, push notifications, and App Store purchases.
- Google: support email.
These providers may process data outside your country. The final policy will identify the relevant international-transfer safeguards.
Why data is processed
CoWake uses data to provide accounts, alarms, and calls; show shared mornings; manage purchases; prevent abuse; answer messages; and understand overall usage.
Where data protection law requires a legal basis, the proposed bases are performance of the service contract, legitimate interests in security and service improvement, consent where required for optional processing, and compliance with legal obligations. These bases are subject to the final legal review.
Camera, microphone, alarm, and notification access are controlled through your iPhone's permissions. A device permission is separate from the legal basis for processing personal data.
Keeping and deleting data
Account deletion is not the same as immediate erasure of every database record or backup. Some account and history records may remain after an account is closed.
Retention periods for account records, history, reports, usage events, support messages, backups, and hosting logs are still being finalized. This draft does not promise a deletion deadline or an account-recovery period.
Before this policy takes effect, those periods or the criteria used to determine them must be documented alongside the deletion process. You can contact help@cowake.app with a deletion request.
Your choices and rights
Depending on applicable law, you can request access, correction, deletion, or a copy of your data; object to or restrict processing; and withdraw consent where processing relies on it. Email help@cowake.app. CoWake may need to verify that the request relates to your account.
You can also complain to your data protection authority. CoWake does not sell personal information or share it for advertising.
CoWake is not intended for children under 13. Contact help@cowake.app if you believe a child below that age has an account.
For a security issue, email help@cowake.app. The same contact is published in security.txt.
Changes to this policy will be published here. Significant changes will be explained before they take effect.