Privacy Policy
Last updated: February 2026
For the Sine App and the website sine-immersive.com
Thank you for your interest in Sine. Protecting your personal data is of utmost importance to us. This privacy policy explains in detail how we collect, use, store, and protect your information in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the ePrivacy Directive 2002/58/EC, and other applicable European and international data protection laws.
This policy applies to all services offered through the Sine mobile application (iOS) and the website sine-immersive.com. We encourage you to read this policy carefully to understand our practices regarding your personal data.
1. Data Controller
The data controller responsible for the processing of your personal data within the meaning of Art. 4(7) GDPR is:
Divinebeingmetatron Ltd
Reg. Number: HE 470351
Mesopotamia 8
7401 Oroklini, Larnaca
Cyprus
VAT: CY60134085Z
Director: Gerome Raphael Seiffert
E-Mail: dev@sine-immersive.com
Website: sine-immersive.com
The appointment of a Data Protection Officer (DPO) is not required under Art. 37 GDPR given the nature and scope of our data processing activities. Our core business does not involve regular and systematic monitoring of data subjects on a large scale, nor does it involve large-scale processing of special categories of data. However, you may contact us at any time with data protection inquiries using the email address provided above.
2. Overview of Data Processing
The following provides a comprehensive overview of the types of personal data we process, the categories of individuals affected, and the purposes for which data is processed. This serves as a summary; further details are provided in the sections that follow.
2.1 Types of Data Processed
| Data Category | Examples |
|---|---|
| Identity data | First name, last name, alias / display name, profile picture |
| Contact data | Email address |
| Content data | Audio presets (frequency configurations, ambient sounds, noise settings), mood check-in data (energy, stress, focus, mood scores), free-text session notes |
| Usage data | Page views, session duration, feature interactions, meditation streaks, Academy progress, AI token usage, community interactions (likes, downloads) |
| Health data (Art. 9 GDPR) | Heart rate, heart rate variability (HRV), resting heart rate, sleep analysis data |
| Purchase data | Subscription status (free/premium), subscription type and duration, transaction confirmations, token balances and purchase history |
| Meta / communication data | Device type, operating system version, app version, IP address, browser type and version, access timestamps |
2.2 Categories of Data Subjects
- App users: Individuals who have downloaded and use the Sine app, whether registered with an account or using the app in a limited capacity before registration.
- Website visitors: Individuals who visit sine-immersive.com, including those who make purchases through the website checkout.
2.3 Purposes of Processing
- Provision and operation of the Sine app, including delivery of core audio and meditation features
- User account management, authentication, and profile personalization
- Premium subscription management, billing verification, and in-app purchase processing
- Community features, including preset sharing, discovery, likes, and downloads
- AI-powered preset generation based on user mood inputs and preferences
- Bio-Resonance analysis (exclusively on-device processing of health data from HealthKit)
- Streak tracking, gamification, and reward systems to encourage regular meditation practice
- Website hosting, delivery of web pages, and website-based checkout processing
- Customer support and response to user inquiries
- App improvement and optimization through anonymized, aggregated analytics
- Security, fraud prevention, and protection of our services
3. Legal Bases for Processing
We process personal data only when there is a valid legal basis under the GDPR. Below, we explain each legal basis that applies to our data processing activities, along with specific examples.
3.1 Consent, Art. 6(1)(a) GDPR
Where you have given us your freely given, specific, informed, and unambiguous consent to process your personal data for one or more specific purposes. Consent is always voluntary, and you may withdraw it at any time with effect for the future without affecting the lawfulness of processing carried out prior to withdrawal. This legal basis applies in particular to:
- HealthKit data access: Opt-in consent granted through the iOS system permission dialog before any health data is read.
- Push notifications: Opt-in consent granted through the iOS notification permission dialog.
- Non-essential website cookies: Such as the FirstPromoter affiliate tracking cookie.
- Community preset sharing: Your voluntary decision to make a preset publicly available.
3.2 Performance of Contract, Art. 6(1)(b) GDPR
Processing that is necessary for the performance of a contract to which you are a party (our Terms of Use), or in order to take steps at your request prior to entering into a contract. This applies to:
- User account creation, authentication, email verification, and profile management
- Subscription processing, renewal management, and premium feature activation
- Preset creation, saving, editing, and cloud synchronization
- AI-powered features including preset generation and sequencer configuration
- Mood check-ins and session tracking as core features of the wellness experience
- Community participation, including uploading, browsing, and downloading shared presets
- Token management (allocation, usage tracking, and top-up purchases)
3.3 Legal Obligation, Art. 6(1)(c) GDPR
Processing that is necessary for compliance with a legal obligation to which we, as the data controller, are subject. This includes:
- Retention of purchase and transaction records for tax, accounting, and VAT compliance purposes (typically 6–10 years under applicable Cypriot and EU tax law)
- Response to lawful requests from competent public authorities or courts
- Compliance with consumer protection regulations
3.4 Legitimate Interests, Art. 6(1)(f) GDPR
Processing that is necessary for the purposes of legitimate interests pursued by us or by a third party, except where such interests are overridden by your fundamental rights, interests, or freedoms requiring the protection of personal data. We have conducted a balancing test for each of the following processing activities:
- Anonymized analytics: Firebase Analytics helps us understand feature usage patterns and improve app quality. Our interest: maintaining and improving our service. Impact on you: minimal, as data is anonymized and aggregated.
- Security and fraud prevention: Firebase App Check verifies app integrity. Our interest: protecting our infrastructure and users. Impact on you: negligible.
- Crash reporting and error diagnosis: Helps us identify and resolve technical issues promptly. Our interest: service reliability. Impact on you: minimal, as reports contain only technical data.
- Affiliate tracking (FirstPromoter): Helps us measure the effectiveness of our partnership program. Our interest: business development. Impact on you: limited to a single cookie.
You have the right to object to processing based on legitimate interests at any time (see Section 8.6).
3.5 Explicit Consent for Special Categories, Art. 9(2)(a) GDPR
Health data, including heart rate, heart rate variability (HRV), resting heart rate, and sleep analysis data, constitutes a special category of personal data under Art. 9 GDPR. Such data receives enhanced protection and may only be processed under specific conditions.
We process health data exclusively on the basis of your explicit consent, which is obtained through the iOS HealthKit permission dialog before any health data is accessed. This consent is granular (you can grant or deny access to individual data types) and can be revoked at any time in your iOS Settings without affecting the lawfulness of prior processing.
4. Security Measures
We implement appropriate technical and organizational measures in accordance with Art. 32 GDPR to ensure a level of security appropriate to the risk of processing. These measures are regularly reviewed and updated to address emerging threats. They include:
- Encryption in transit: All data transmissions between your device, our servers, and third-party services are encrypted using TLS/SSL (HTTPS). No data is transmitted in plaintext.
- Firebase Security Rules: Granular, server-enforced access control rules ensure that authenticated users can only read and write their own data in Firestore, Firebase Storage, and Realtime Database. These rules are tested and audited regularly.
- Server-side API key management: Sensitive API keys (e.g., for OpenAI) are stored exclusively in Firebase Cloud Functions environment variables and are never exposed to or embedded in the client application.
- Firebase App Check: Verifies the integrity and authenticity of every app request, protecting backend resources against unauthorized access, API abuse, and bot traffic.
- Data minimization: We collect only the data that is strictly necessary for the respective processing purpose. We do not collect data speculatively or for undefined future use.
- Encrypted password storage: User passwords are hashed and salted using industry-standard algorithms by Firebase Authentication. We never have access to plaintext passwords.
- Regular security updates: All dependencies, libraries, and infrastructure components are kept up to date to address known security vulnerabilities promptly.
- Access controls: Internal access to production data is restricted to authorized personnel on a need-to-know basis.
5. Disclosure of Personal Data
We share your personal data with third parties only in the following clearly defined and limited circumstances. In each case, we ensure that appropriate safeguards are in place to protect your data.
- Data processors (Art. 28 GDPR): We engage certain service providers to process data on our behalf under written data processing agreements. These processors may only process your data in accordance with our instructions and are contractually bound to implement appropriate security measures. Our processors include: Firebase/Google (backend infrastructure), RevenueCat (subscription management), OpenAI (AI features), Paddle (website payments), Vercel (website hosting), and FirstPromoter (affiliate tracking).
- Apple Inc.: For payment processing through the App Store, iCloud synchronization via CloudKit, health data access via HealthKit (on-device only), and push notification delivery via APNs.
- Community (voluntary disclosure): If you choose to share a preset in the Sine community, your chosen display name and preset data (title, description, audio parameters, mood tags) will become publicly visible to other users. This is entirely voluntary and initiated by you.
- Legal obligations: We may disclose data when required to do so by applicable law, court order, subpoena, or regulatory authority, in accordance with Art. 6(1)(c) GDPR.
We explicitly confirm: We do not sell your personal data to anyone, under any circumstances. We do not share your data with advertising networks, data brokers, or marketing partners. We do not engage in data brokering, data trading, or any form of commercial data exploitation.
6. Data Processing in Third Countries
Some of our service providers operate outside the European Economic Area (EEA). Whenever personal data is transferred to a third country, we ensure that the transfer is carried out in compliance with Chapter V of the GDPR and that adequate safeguards are in place.
6.1 United States
The following service providers are based in the United States of America:
- Google / Firebase: Certified under the EU-US Data Privacy Framework (DPF), ensuring an adequate level of data protection as recognized by the EU Commission. Additionally, Firebase application data is stored in the EU region (eur3), minimizing actual data transfers to the US.
- RevenueCat Inc.: Data transfer is governed by Standard Contractual Clauses (SCCs) as approved by the EU Commission (Decision 2021/914). RevenueCat only processes anonymized user IDs and subscription metadata.
- OpenAI, L.L.C.: Data transfer is governed by SCCs. Importantly, only anonymized mood and preference data is transmitted to OpenAI. No personally identifiable information is included in any AI request (see Section 17.3 for details).
- Vercel Inc.: Our website hosting provider. Certified under the EU-US DPF and additionally governed by SCCs. Processes server logs containing IP addresses and HTTP request metadata.
6.2 European Union / Ireland
- Paddle.com Market Limited (Dublin, Ireland) Processes all website purchases within the EEA. As an Irish company, Paddle is directly subject to the GDPR. No third-country data transfer is required.
- Google Ireland Ltd (Dublin, Ireland) Acts as the data controller or processor for Firebase services within the EEA.
6.3 Firebase EU Region
Firebase Firestore, Cloud Functions, and Firebase Storage are configured to use the EU multi-region (eur3), which spans data centers in Belgium and the Netherlands. This ensures that your primary application data, including account information, presets, mood data, session insights, and entitlements, remains stored within the European Union.
7. Data Retention and Deletion
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. We regularly review our retention practices to ensure compliance with the principle of storage limitation (Art. 5(1)(e) GDPR).
| Data Category | Retention Period |
|---|---|
| Account data (email, name, alias, profile picture) | Until account deletion by the user |
| Health data (HealthKit) | Session duration only; aggregated values stored locally on your device |
| Mood check-in data | Until account deletion by the user |
| Presets and usage data | Until account deletion or manual deletion by the user |
| Purchase / subscription data | Until account deletion + statutory retention period (6–10 years for tax and accounting purposes) |
| Analytics data (Firebase) | 14 months (Firebase Analytics default retention) |
| Community presets | Until manual deletion by the user or account deletion |
| Website data (sessionStorage) | Browser session only (cleared when tab/browser is closed) |
| Website data (localStorage) | Until manually cleared by the user in browser settings |
After you delete your account, all personal data is removed from our active systems within 30 days. Data that is subject to statutory retention obligations (such as purchase records required for tax compliance) will be retained for the legally mandated period and then deleted. During this retention period, such data is restricted from further processing and used only for compliance purposes.
How to Delete Your Account
You can delete your account at any time using one of the following methods:
- In the app: Navigate to Profile → Settings → Delete Account
- By email: Send a deletion request to support@sine-immersive.com
Upon account deletion, the following data is permanently removed:
- All account and profile data (name, email, alias, profile picture)
- All saved presets (both local and cloud-synced copies)
- All session history, mood check-ins, and progress data
- All streak data and token balances
- All community presets (anonymized or removed from public view)
Please note that active subscriptions are managed separately through Apple (for app purchases) or Paddle (for website purchases). You should cancel any active subscription before deleting your account to avoid continued billing.
8. Your Rights Under the GDPR
As a data subject, you have comprehensive rights under the GDPR. To exercise any of these rights, please contact us at support@sine-immersive.com. We will confirm receipt of your request and respond within one month. In complex cases or where we receive a large number of requests, this period may be extended by a further two months, in which case we will inform you of the extension within the initial one-month period.
8.1 Right of Access, Art. 15 GDPR
You have the right to obtain confirmation as to whether personal data concerning you is being processed by us. If so, you have the right to access that data and to receive information about the purposes of processing, the categories of personal data concerned, the recipients or categories of recipients to whom the data has been or will be disclosed, the envisaged retention period, the existence of your rights, and the source of the data (if not collected directly from you). We will provide a copy of your personal data free of charge upon request.
8.2 Right to Rectification, Art. 16 GDPR
You have the right to obtain the rectification of inaccurate personal data concerning you without undue delay. Taking into account the purposes of the processing, you also have the right to have incomplete personal data completed, including by means of providing a supplementary statement. You can update most of your profile data directly within the Sine app.
8.3 Right to Erasure, Art. 17 GDPR
You have the right to obtain the deletion of your personal data without undue delay (the "right to be forgotten") where one of the following grounds applies: the data is no longer necessary for its original purpose; you withdraw consent and there is no other legal ground for processing; you object to processing and there are no overriding legitimate grounds; the data has been unlawfully processed; or the data must be erased to comply with a legal obligation. This right is subject to certain exceptions, such as where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims.
8.4 Right to Restriction of Processing, Art. 18 GDPR
You have the right to obtain the restriction of processing where: the accuracy of the data is contested (for the period needed to verify accuracy); the processing is unlawful and you oppose erasure but request restriction instead; we no longer need the data but you require it for legal claims; or you have objected to processing pending verification of whether our legitimate grounds override yours.
8.5 Right to Data Portability, Art. 20 GDPR
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format (e.g., JSON or CSV). You also have the right to transmit that data to another controller without hindrance from us, where the processing is based on consent or contract performance, and the processing is carried out by automated means.
8.6 Right to Object, Art. 21 GDPR
Right to Object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data which is based on Art. 6(1)(e) or (f) GDPR, including profiling based on those provisions. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims. Where personal data is processed for direct marketing purposes, you have the right to object at any time, and we will cease such processing immediately.
8.7 Right to Withdraw Consent, Art. 7(3) GDPR
Where processing is based on your consent, you have the right to withdraw that consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. You can withdraw specific consents as follows:
- HealthKit access: iOS Settings → Health → Data Access & Devices → Sine
- Push notifications: iOS Settings → Notifications → Sine
- Community sharing: Delete individual presets from the community within the app
8.8 Right Regarding Automated Decisions, Art. 22 GDPR
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. For details on how this applies to Sine's AI and Bio-Resonance features, see Section 21.
8.9 Right to Lodge a Complaint, Art. 77 GDPR
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR. For the competent supervisory authority, see Section 23.
9. Provision of the App and Website
9.1 Website Hosting, Vercel
Our website sine-immersive.com is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. When you visit our website, Vercel automatically processes the following technical data as part of standard web hosting operations, for the purpose of delivering web pages, ensuring security, and preventing abuse:
- IP address
- Browser type and version
- Operating system
- Date and time of access
- Requested URL and page path
- Referring URL (the page that linked you to our site)
- Amount of data transferred
This data is processed in server log files and is not combined with other data sources. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing and securing the website).
Privacy policy: vercel.com/legal/privacy-policy
9.2 App Provision via the Apple App Store
The Sine app is distributed exclusively through the Apple App Store. When you download the app, Apple processes certain technical data (such as your Apple ID, device identifiers, and download metadata) in accordance with Apple's own privacy policy. We receive only anonymized, aggregated download statistics from Apple and no personally identifiable information from the download process itself.
10. Registration and Account
User authentication is provided by Firebase Authentication, a service operated by Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland. Firebase Authentication handles the secure storage and verification of user credentials.
When you create an account with Sine, we collect the following data:
- Email address (required) Used for account identification, login, password reset, and essential account communications.
- Password (required) Hashed and salted by Firebase Authentication using industry-standard algorithms. We never have access to or store your plaintext password.
- First name (optional) Used for personalization and community display name.
- Last name (optional) Used for community display name (shown as initial only, e.g., "John S.").
- Alias / display name (optional) An alternative name shown in the community if you prefer not to use your real name.
- Profile picture (optional) Stored securely in Firebase Storage. Visible to other users in the community.
Legal basis: Art. 6(1)(b) GDPR (performance of contract, necessary to provide the app service under our Terms of Use).
You can update your profile data at any time within the app (Profile → Edit Profile). You can delete your account at any time via Profile → Settings → Delete Account, or by emailing support@sine-immersive.com.
11. HealthKit Data in Detail (Art. 9 GDPR)
Special Category of Personal Data: Health data is classified as a special category of personal data under Art. 9 GDPR and receives the highest level of protection. Its processing requires your explicit consent (Art. 9(2)(a) GDPR), which is obtained through the iOS HealthKit permission dialog. This consent is granular and can be revoked at any time without affecting the functionality of other app features.
The Sine app integrates with Apple HealthKit to support the Bio-Resonance feature, which provides personal insights into the physiological effects of your meditation practice. HealthKit access is entirely optional and is only activated when you explicitly grant permission.
Data Types Read from HealthKit
- Heart rate Measured during active meditation sessions to track cardiovascular response.
- Heart rate variability (HRV) Measured during meditation to assess autonomic nervous system balance.
- Resting heart rate Used for baseline comparison and long-term trend analysis.
- Sleep analysis Used for delayed correlation between meditation and sleep quality.
Data Types Written to HealthKit
- Workout sessions Completed meditation sessions are optionally logged as mindfulness workout entries in your HealthKit data.
Our Guarantees Regarding HealthKit Data
We provide the following binding guarantees for your HealthKit data:
- HealthKit data is processed exclusively on your device. Raw health measurements never leave your iPhone.
- Health data is never transmitted to our servers, Firebase, or any third party whatsoever.
- HealthKit data is not used for advertising, marketing, data mining, or data brokering purposes.
- HealthKit data is not shared with insurance companies, employers, data brokers, or any other third parties.
- HealthKit access is entirely optional and can be revoked at any time in iOS Settings → Health → Data Access & Devices → Sine.
- The app functions fully without HealthKit access. All features except Bio-Resonance analysis remain fully available.
When you use the Bio-Resonance feature, raw health measurements are temporarily cached in memory for the duration of the active meditation session only. After the session concludes, only aggregated values (averages and trends) are stored locally on your device as part of the session insight. These aggregated values are never uploaded to any server or cloud service.
12. Mood and Emotion Data
Sine offers optional mood check-ins before and after meditation sessions to help you track the impact of your practice over time. The following data points are collected per check-in:
- Energy Scale of 1 to 10
- Stress Scale of 1 to 10
- Focus Scale of 1 to 10
- Mood Scale of 1 to 10
- Free-text notes Optional personal reflections or observations
Mood data is stored both locally on your device and in Firebase Firestore (cloud backup) as part of your session insights, ensuring your data is preserved across device changes.
While mood and emotion data does not constitute health data under Art. 9 GDPR (as it reflects subjective self-assessments rather than objective physiological measurements), we treat it with particular care given its personal nature and apply protective measures comparable to those used for health data.
Legal basis: Art. 6(1)(b) GDPR (performance of contract, mood tracking is a core feature of the Sine wellness experience). You can skip mood check-ins entirely by using the "Just Play" option when starting a meditation session.
13. Community Features
Sine includes a community feature that allows users to share audio presets with other users worldwide. Participation in the community is entirely voluntary and requires a premium subscription.
When you share a preset to the community, the following data becomes publicly visible to other Sine users:
- Your chosen display name (either your alias, or your first name with last name initial)
- Preset title and description (as written by you)
- Audio parameters (frequencies, binaural beat settings, ambient sounds, noise settings)
- Mood tags and category classification
Review system: All community presets undergo a review process before becoming publicly visible. An administrator reviews each submitted preset for quality, appropriateness, and compliance with our community guidelines before it is published. During review, the preset is visible only to you (with a "pending" status indicator).
Anonymous interactions: Likes and downloads are counted in aggregate. Other users cannot see who specifically liked or downloaded a particular preset.
Legal basis: Art. 6(1)(a) GDPR (consent, you voluntarily choose to share) and Art. 6(1)(b) GDPR (performance of contract, the community feature is part of the premium service).
14. Push Notifications
Sine uses the Apple Push Notification Service (APNs) to deliver optional notifications to your device. We use push notifications exclusively for the following purposes:
- Meditation reminders: Scheduled reminders that you configure yourself within the app.
- Streak notifications: Daily encouragement to maintain your meditation streak.
- Session reminders: Notifications about pending mood check-ins from incomplete sessions.
We do not send marketing, promotional, or advertising push notifications. We do not use push notifications to promote purchases or third-party content.
Push notification consent is requested through the standard iOS system dialog on first use. You can revoke this consent at any time by navigating to iOS Settings → Notifications → Sine and disabling notifications.
Legal basis: Art. 6(1)(a) GDPR (consent).
15. In-App Purchases and Subscriptions
15.1 App Store Purchases (Apple Inc.)
The following in-app purchases are available through the Apple App Store:
- Premium Monthly Monthly auto-renewing subscription with a 7-day free trial.
- Premium Yearly Annual auto-renewing subscription with a 7-day free trial.
- Token Top-Up (10 Tokens) One-time consumable purchase of 10 additional AI tokens.
Apple handles all payment processing for App Store purchases. We never receive, access, or store your credit card number, bank account details, or any other payment instrument data. From Apple, we receive only a transaction confirmation (receipt) and the current subscription status, which is used to activate your premium features.
15.2 Website Purchases (Paddle)
Purchases made through our website (sine-immersive.com) are processed by Paddle.com Market Limited, Core B, Block 71, The Plaza, Park West, Dublin 12, Ireland. Paddle acts as the Merchant of Record, meaning Paddle is the legal seller for all website transactions, not Divinebeingmetatron Ltd.
As the Merchant of Record, Paddle directly collects and processes:
- Full name and email address
- Payment information (credit card, PayPal, Apple Pay, Google Pay, etc.)
- IP address and device/browser information
- Billing address and country
- Tax-related information (VAT number, if applicable)
From Paddle, we receive: transaction confirmation, subscription status, and the customer email address. We never receive or store your credit card number or payment details.
Privacy policy: paddle.com/legal/privacy
16. Payment Methods
We want to be absolutely clear about payment data handling: we never access, store, or process credit card numbers, bank account details, CVV codes, or other sensitive payment information. All payment processing is handled entirely by trusted, PCI-DSS-compliant third-party payment processors:
- App purchases: Processed entirely by Apple through the App Store payment system, which supports Apple Pay and stored payment methods linked to your Apple ID.
- Website purchases: Processed entirely by Paddle, which supports credit cards, debit cards, PayPal, Apple Pay, Google Pay, and various local payment methods.
Subscription status is synchronized to your Sine account via RevenueCat (for app purchases) or Paddle webhooks (for website purchases). This synchronization ensures that your premium features are properly activated regardless of where you made your purchase.
17. Third-Party Services in Detail
The following section provides detailed information about each third-party service we use, including what data is processed, why it is processed, and where you can find additional information about each provider's privacy practices.
17.1 Firebase (Google Ireland Ltd)
Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland.
Firebase is the primary backend infrastructure for the Sine app. We use the following Firebase services:
- Firebase Authentication: Processes email address, password hash (bcrypt), and a unique user ID for secure account registration, login, and session management.
- Cloud Firestore (database): Stores user profile data, presets, settings, entitlements, streaks, mood check-in data, session insights, and token history.
- Firebase Storage: Stores user-uploaded profile pictures in the EU region.
- Firebase Analytics: Collects anonymized, aggregated usage statistics (feature usage, screen views, session counts) for app improvement. We do not use IDFA, ATT, or any advertising identifiers.
- Cloud Functions: Server-side processing environment for AI requests (proxied to OpenAI), webhook handling (RevenueCat, Paddle), and scheduled background tasks.
- App Check: Verifies the integrity and authenticity of app instances to protect our backend from unauthorized access and abuse.
All Firebase application data is stored in the EU multi-region (eur3). Google Ireland Ltd is the data processor and is certified under the EU-US Data Privacy Framework.
Privacy policy: firebase.google.com/support/privacy
17.2 RevenueCat Inc.
633 Howard Street, San Francisco, CA 94105, USA.
RevenueCat provides subscription management and in-app purchase verification. It processes:
- An anonymized app user ID (not your email or name)
- Subscription status, type, and renewal information
- Purchase transaction metadata (transaction IDs, product IDs, timestamps, no payment details)
RevenueCat does not receive any personally identifiable information such as your name, email address, or HealthKit data.
Privacy policy: revenuecat.com/privacy
17.3 OpenAI, L.L.C.
3180 18th Street, San Francisco, CA 94110, USA.
Important: All AI requests are processed server-side through our Firebase Cloud Functions. Your device never communicates directly with OpenAI. No personally identifiable information is included in any request sent to OpenAI. Only anonymized mood descriptors and audio preferences (e.g., "relaxed", "focused", "deep sleep", "432 Hz") are transmitted for preset generation. No health data, email addresses, names, user IDs, or other personal data is ever shared with OpenAI. Furthermore, OpenAI does not use data submitted via their API for model training purposes.
Privacy policy: openai.com/policies/privacy-policy
17.4 Apple Inc.
One Apple Park Way, Cupertino, CA 95014, USA.
We use the following Apple platform services:
- CloudKit (iCloud): Enables cross-device synchronization of your data through your personal iCloud account, subject to Apple's privacy policy.
- APNs (Apple Push Notification Service): Delivers push notifications from our server to your device.
- App Store: Handles app distribution, downloads, in-app purchases, subscription management, and App Store review.
- HealthKit: Provides on-device access to health data. All HealthKit data is processed locally on your device and is never transmitted to Apple's servers or to ours.
17.5 Paddle.com Market Limited
Core B, Block 71, The Plaza, Park West, Dublin 12, Ireland.
Paddle serves as the Merchant of Record for all purchases made through our website. As the legal seller, Paddle directly collects and processes all payment-related data, including credit card information, billing addresses, and tax information. We never receive or store your credit card data. Paddle is PCI-DSS Level 1 certified.
Privacy policy: paddle.com/legal/privacy
17.6 Vercel Inc.
340 S Lemon Ave #4133, Walnut, CA 91789, USA.
Vercel hosts our website (sine-immersive.com) and executes Serverless Functions that power our website's backend logic. Vercel processes IP addresses, HTTP request metadata, and browser information as part of standard web hosting and CDN operations.
Privacy policy: vercel.com/legal/privacy-policy
17.7 FirstPromoter (Jepto SRL)
Jepto SRL, Romania (EU Member State).
We use FirstPromoter for affiliate tracking related to website purchases. When you arrive at our website through an affiliate link, FirstPromoter sets an "fpr" cookie with a 60-day duration to attribute the visit and any subsequent purchase to the referring affiliate partner. It processes:
- Referrer URL (the page that linked you to our site)
- Click ID (a unique identifier for the affiliate click)
- Conversion data (confirmation that a purchase was made, without payment details)
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring the effectiveness of our affiliate partnership program).
Privacy policy: firstpromoter.com/privacy
18. Website Cookies and Local Storage
Our website uses a minimal number of cookies and browser storage entries. We have intentionally kept our use of cookies to the bare minimum. The following table provides a complete and exhaustive overview:
| Name | Type | Purpose | Duration | Category |
|---|---|---|---|---|
| sine-theme | localStorage | Stores your preferred color theme (dark or light mode) | No expiration (persistent until manually cleared) | Essential |
| sine-lang | localStorage | Stores your preferred language (English or German) | No expiration (persistent until manually cleared) | Essential |
| sineQuizDone | sessionStorage | Remembers that the onboarding quiz has been completed during the current session | Browser session (cleared when tab/browser closes) | Functional |
| sineQuizAnswers | sessionStorage | Stores quiz answers for generating personalized recommendations | Browser session (cleared when tab/browser closes) | Functional |
| fpr | HTTP Cookie (FirstPromoter) | Affiliate tracking, attributes purchases to referring affiliate partners | 60 days | Marketing |
| Paddle cookies | HTTP Cookie | Payment processing, fraud prevention, and session management during checkout | Session / persistent (varies by cookie) | Essential |
No advertising cookies. We do not use Google Analytics, Google Tag Manager, Facebook Pixel, Meta Pixel, TikTok Pixel, or any other third-party tracking, retargeting, or advertising scripts on our website. Your browsing behavior on our website is not tracked for advertising purposes.