Last updated: April 2026
1. Data Controller
ZZleep ("we", "the application") is responsible for processing your personal data in accordance with the European Union General Data Protection Regulation (GDPR).
2. Data We Collect
We collect the following categories of data:
- Account data: email address and optional name.
- Wellbeing data (special category): information you choose to share about your mood, rest, or worries to personalize the session. This data is processed with your explicit consent (Art. 9.2.a GDPR).
- Voice biometrics: your voice is processed in real time during sessions to enable AI interaction. Audio is not stored after the session ends.
- Subscription data: billing information managed by Stripe or Google Play depending on the platform. We do not store card details directly.
3. Legal Basis for Processing
- Explicit consent (Art. 6.1.a and 9.2.a GDPR) for health-related data and voice biometrics.
- Performance of a contract (Art. 6.1.b GDPR) for account and subscription data.
- Legitimate interest (Art. 6.1.f GDPR) for anonymous usage analytics and abuse prevention.
4. Data Residency
Data is processed on servers located in the European Union (Frankfurt, Germany). Our providers, including Supabase and Google, operate under the EU-US Data Privacy Framework where applicable, providing an adequate level of protection.
5. Your Rights (GDPR)
You have the right to:
- Access: request a copy of your data.
- Rectification: correct inaccurate data.
- Deletion ("right to be forgotten"): request deletion of your account or associated personal data. You can review the process on the account and data deletion page. We may retain minimal records when necessary for legal, tax, accounting, security, fraud prevention, dispute resolution, or purchase and subscription administration obligations.
- Portability: receive your data in a structured format.
- Withdrawal of consent: withdraw consent at any time without affecting the lawfulness of previous processing.
6. Artificial Intelligence
ZZleep uses AI systems to generate conversational responses, breathing exercises, and personalized stories based on information you choose to share during the session. Your conversations are not used to train AI models.
7. Data Retention
We keep the data needed to operate your account, preferences, and app experience while your account is active. We also retain minimal technical records when necessary for security, billing, legal compliance, and abuse prevention.
8. Account or Data Deletion
You can request deletion of your full account or specific data associated with your account by writing to support@zzleep.app from the email linked to your account. The full process is available on the account and data deletion page.
9. Contact
To exercise your rights or ask any privacy question, contact us at: support@zzleep.app
You can also review our Terms of Service.
