Privacy Policy
Last updated: August 25, 2026
Sombra (“Sombra,” “we,” “us,” or “our”) provides a mobile application that helps you keep a consistent bedtime by shielding distracting apps after your bedtime and letting you earn access back through a physical activity challenge. This policy explains what information we collect through the Sombra app, why, and what rights you have over it, wherever in the world you’re using Sombra from, including the European Economic Area (EEA)/UK (GDPR), and the United States (including California’s CCPA/CPRA).
Legal entity: Ziad El Ismaili, an individual operating Sombra as sole operator, residing in Morocco.
1. Who this applies to
Sombra is intended for users 16 years of age or older. The app itself will not let you complete account creation with a birth date indicating you’re younger than that. We do not knowingly collect information from anyone under 16. If you believe a user under 16 has provided us information, contact us (below) and we’ll delete it.
2. Information we collect
We collect only what’s needed to run the app’s core features. We do not collect location data, contacts, photos, or browsing history, and Sombra contains no advertising or analytics SDKs of any kind.
Account information, collected when you create an account (via email/password, Sign in with Apple, or Sign in with Google):
- Email address, first and last name
- Date of birth (used only to confirm you meet the 16+ age requirement)
- IANA timezone identifier (e.g. “Europe/Paris”), used so your bedtime, reminders, and daily challenge windows are calculated correctly in your local time, not our server’s
If you sign in with Apple or Google, we receive your name and email from that provider (Apple may mask your real email via “Hide My Email,” which we support); we never receive your Apple or Google password.
Sleep and usage data:
- Your configured weekday/weekend bedtime
- The specific apps and categories you choose to shield after bedtime (see “Screen Time data” below)
- Nightly usage events: how many minutes you used a shielded app after your bedtime, used to determine whether a challenge is triggered
- Your challenge history (type, difficulty, target, completion status) and activity streak
Screen Time data (iOS Family Controls / DeviceActivity), only if you grant this permission:
- An opaque “Family Activity Selection” token representing the specific apps/categories you’ve chosen to shield. Apple’s on-device Screen Time framework means we never see which individual apps are on your device or what you use them for. We only see the usage duration for the apps you selected to shield, and whether they’re currently shielded.
Health data (iOS HealthKit), only if you grant this permission:
- Read-only access to your workouts (
HKWorkoutTypeIdentifier) and walking/running distance (HKQuantityTypeIdentifierDistanceWalkingRunning) - Used solely to automatically verify you completed a physical-activity challenge (e.g. confirming you actually walked/ran the required distance)
- We never write to HealthKit, and never use this data for any purpose other than challenge verification. It is not shared with any third party, used for advertising, or used to build a health profile beyond that single yes/no verification
Subscription data:
- Your subscription plan, status, and renewal date, and Apple App Store transaction identifiers, obtained from Apple’s App Store Server API to verify and manage your Sombra Pro subscription
- We never see or store your payment card details. All billing is handled entirely by Apple through the App Store
Device data:
- If you grant notification permission, your device’s Expo push notification token and platform (iOS/Android), used only to deliver notifications you’d expect (e.g. a bedtime reminder), and a record of notifications sent to your device so you can view/manage your notification history in the app
3. How we use your information
We use the information above only to:
- Operate the core bedtime-shielding, challenge, streak, and reminder features
- Authenticate you and keep your account secure
- Verify and manage your Sombra Pro subscription with Apple
- Send you notifications you’d reasonably expect from using the app (e.g. a reminder before bedtime), which you can disable at any time in your device’s notification settings
- Respond to support requests you send us
- Maintain and improve the reliability of the service (e.g. diagnosing a bug you report)
We do not sell your personal information, use it for advertising or ad targeting, or share it with data brokers. (“Sell” and “share” here are used in the sense CCPA/CPRA defines them; we do neither.)
4. Legal bases for processing (EEA/UK users)
Under GDPR, we process your information on these bases:
- Performance of a contract: account info, bedtime/usage data, and subscription data, because we can’t provide the app’s core functionality without them.
- Consent: HealthKit data and Screen Time data are both permissions you explicitly grant (and can revoke at any time in iOS Settings), and notification data depends on you granting notification permission. HealthKit data specifically is “special category” data under GDPR Article 9, which is why it’s strictly opt-in, read-only, and used for nothing beyond challenge verification.
- Legitimate interest: keeping basic technical logs to diagnose and fix problems with the service.
5. Who we share data with
We share the minimum necessary data with the following service providers, each acting as our processor/subprocessor:
| Who | What they process | Why |
|---|---|---|
| Apple | Sign in with Apple identity, HealthKit data (on-device, not sent to Apple by us), Screen Time/Family Controls (on-device), App Store subscription transactions | Authentication, health/Screen Time permissions are Apple platform APIs, subscription billing & verification |
| Sign in with Google identity | Authentication | |
| Amazon Web Services (AWS) | Account credentials (Cognito), application database (RDS/PostgreSQL), hosted in eu-central-1 (Frankfurt, Germany) | Authentication and application hosting |
| Expo (650 Industries, Inc.) | Push notification device tokens | Delivering push notifications to your device |
We do not share your data with any other third party, and we do not permit any of the above to use your data for their own advertising purposes.
6. International data transfers
Our infrastructure is hosted in the EU (AWS eu-central-1). Some of our service providers above (Apple, Google, Expo) are US-based companies that may process data outside the EEA/UK. Where that happens, we rely on the mechanisms those providers make available for international transfers (such as Standard Contractual Clauses) to ensure your data remains protected to a standard equivalent to the GDPR.
7. Data retention
We keep your account and usage data for as long as your account is active, so the app can function (e.g. your streak and challenge history rely on it). If you delete your account (see below), we delete your personal data within 30 days, except where we’re required to retain limited records for legal, tax, or fraud-prevention purposes (e.g. subscription transaction records).
8. Your rights
If you’re in the EEA/UK (GDPR): you have the right to access, correct, delete, or export your data, restrict or object to our processing, and withdraw consent at any time (which won’t affect processing that already happened before withdrawal). You also have the right to lodge a complaint with your local data protection authority.
If you’re a California resident (CCPA/CPRA): you have the right to know what personal information we’ve collected about you, request its deletion, correct inaccuracies, and opt out of “sale” or “sharing” of your data, which, as noted above, we don’t do. We won’t discriminate against you for exercising any of these rights.
Wherever you are, you can exercise any of these rights, or ask us any question about this policy, by emailing us (below). We’ll respond within a reasonable time and in any case within the timeframe required by applicable law.
Practically, in the app itself you can already: revoke HealthKit and Screen Time permissions at any time in iOS Settings, and disable notifications at any time in iOS Settings.
9. Account and data deletion
To delete your account and associated personal data, or for any other request about your data, email us at the address below.
10. Data security
We use industry-standard measures to protect your information, including encryption in transit (TLS) for all network communication, encrypted authentication credentials (we never store your password; Apple/Google/Cognito handle authentication directly), and access controls limiting who can reach production data. No method of transmission or storage is 100% secure, but we work to protect your information using commercially reasonable safeguards appropriate for the type of data involved.
11. Children’s privacy
Sombra is not directed at, and we do not knowingly collect information from, anyone under 16. See “Who this applies to” above.
12. Changes to this policy
If we make material changes to this policy, we’ll update the “Last updated” date above and, where required by law, notify you directly (e.g. via email or an in-app notice).
13. Contact
Questions about this policy, or to exercise any of your rights above: contact@sombra-app.com.