DeepWake Privacy Policy

Last updated: 2026-08-05

This Privacy Policy explains how Next Analytica ("we", "us", "our") collects, uses, shares, and protects information when you use the DeepWake mobile application (the "App", Android package com.nextanalytica.deep_wake).

By using the App you agree to the practices described here. If you do not agree, please do not use the App.

What changed in this version. Analytics no longer starts off everywhere: its starting state now depends on whether your region requires us to ask first (Section 3.3). Section 3.6 now describes what Google receives when an ad is requested, including that an ad request reveals your approximate location through your IP address. Sections 2 and 3.1 correct an earlier statement that the App creates a guest account for you — it does not.

Contact: info@nextanalytica.com Data controller: Next Analytica, Bursa, Türkiye Policy URL: https://na-deepwake-prod.web.app/privacy


1. Summary of what we collect

DeepWake works without an account, and it does not create one for you in the background. Crash diagnostics stay off until you switch them on, in every country. Analytics is the one signal whose starting state depends on where you are — Section 3.3 explains exactly how, and where the switch is. The table is a quick overview; details follow in Section 3.

Category Examples Collected Consent required
Account identifiers Firebase user ID (UID) Only if you choose to sign in No — created by you, at sign-in
Account contact info Email, display name, profile photo URL Only with Google, Apple, or email sign-in No (provided by you at sign-in)
App content Your alarms and schedules, wake log, Voice Wake name, app settings Never — stays on your device Not collected
Camera Camera image, to read a QR code for the QR dismiss challenge Never — decoded on your device, not stored Yes (Android camera permission)
Purchase data Purchase history, app user ID When you buy / restore a purchase No (essential to transaction)
Advertising data Advertising ID and device identifiers, app interactions, diagnostics, IP address (which implies approximate location) Whenever an ad is requested, i.e. for non-paying users Asked where required (EEA/UK/CH) — see 3.6 for what your answer does and does not change
Analytics App activity, device identifiers Depends on your region Asked where required; on by default where it is not (3.3)
Crash diagnostics Crash logs, device/diagnostic data Only after you opt in Yes (off by default, everywhere)
Anti-abuse attestation App Check / Play Integrity tokens Always (security) No (essential security)

2. The App is usable without an account

You can use everything DeepWake does — alarms, challenges, the reliability dashboard — without an account, and the App does not create one for you. There is no guest or anonymous account: if you never sign in, no user ID exists for you and nothing in Section 3.1 applies to you.

Signing in is optional. Its purpose is to attach a premium purchase to an account so it survives a reinstall or a new device. Your alarms and settings are unaffected either way, because they never leave the device in the first place (Section 3.2).


3. Data we collect and why

3.1 Authentication and account data (Firebase Authentication)

If you choose to sign in, Firebase Authentication processes:

There is no anonymous or guest sign-in path in the App. Purpose: to create and secure your account, and to enable features that require an account (such as carrying your premium entitlement across devices).

3.2 App content and preferences (stored on your device)

Your alarms and their configuration (time, repeat schedule, challenge-to-dismiss type, volume-ramp and snooze settings), your app settings and preferences, your wake log (when each alarm fired, how long you took to dismiss it, how many times you snoozed), and your Voice Wake settings — including the name you type for the App to speak and the audio file rendered from it — are stored locally on your device. They are not uploaded to our servers and do not sync across devices. Voice Wake speech is rendered by an on-device voice engine; if no on-device voice is available the App falls back to a plain tone rather than sending the name to a cloud service.

Camera. If you pick the QR-code dismiss challenge, the App opens the camera to read the code. The image is decoded on the device; nothing is stored, uploaded, or shared, and the App keeps no photos. This one feature is why Android lists the camera permission for DeepWake. If you decline the permission, the challenge offers a maths fallback instead.

The only thing we hold on a server under your user document (users/{uid}) in Cloud Firestore is:

The App itself makes no Cloud Firestore calls at all. Firestore Security Rules let you read your own document and let no client — including yours — write it. Purpose: to apply your premium entitlement reliably, including after a reinstall.

3.3 Analytics (Firebase Analytics) — the default depends on your region

We use Firebase Analytics to see which features are used and where the App runs into trouble: screens viewed, features used, and device information such as Android version and manufacturer family. Event values are coarse buckets. We do not send your alarm times, alarm labels, or anything else you typed.

Whether analytics starts on or off depends on the country you are in, because the law does. Google's consent SDK reports whether a consent requirement applies to you, and we use that answer for analytics as well as for ads.

Your own choice always beats the regional default, in both directions, and it sticks. Turn analytics off in Türkiye and it stays off if you travel to Germany; allow it in Germany and it stays allowed wherever you go next.

How to check which one applies to you, and how to change it: open Settings > Privacy & data in the App. The line under Analytics consent tells you which of four states you are in — allowed, declined, on by default where you are, or off until you choose — so you never have to infer it from this page. The toggle next to it changes the setting, and it is in the same place in every country.

Switching analytics off stops collection from that moment onward. It does not delete data already sent — see Section 6.

3.4 Crash diagnostics (Firebase Crashlytics) — opt-in, off by default

We use Firebase Crashlytics to capture crash reports and diagnostic data (e.g. stack traces, device model, OS version) so we can fix stability problems.

Crash collection is off by default in every region, with no regional exception. It turns on only when you explicitly allow data collection: the Analytics consent toggle in Settings > Privacy & data, and the Allow button on the consent prompt where one is shown, govern crash diagnostics as well as analytics.

So in a country where analytics starts on by default, crash reporting still does not. The regional default turns on analytics only; crash diagnostics wait for you to say yes. Switching the toggle off stops collection from that moment; reports already uploaded are not recalled.

3.5 Notifications (delivered on-device)

Alarms and reminders are delivered by local, on-device notifications. The App does not mint, collect, or transmit a Firebase Cloud Messaging (FCM) push token, and Firebase Messaging auto-initialization is disabled. On iOS/macOS, showing notifications requires the system notification permission, which you can change at any time in your device settings. Purpose: to show the alarms and reminders you have scheduled on your device.

3.6 Advertising (Google AdMob)

If you are not a premium subscriber, the App shows ads supplied by Google AdMob. Today that is a banner; other formats are built into the App and currently switched off. No ad of any format is shown while an alarm is ringing.

When an ad is requested, and when it is not.

What Google receives when an ad is requested. An ad request is a network call from your device to Google. Per Google's own AdMob disclosure, the data collected and shared for advertising, analytics, and fraud prevention can include advertising and device identifiers, app interaction data, diagnostic information, and your IP address. Declining personalization, or setting Do Not Sell My Data, restricts how that data may be used. Neither stops the request, and neither means "no data is processed".

IP address and approximate location. An IP address indicates roughly where you are, typically at the level of a city or region. Because an ad request carries one, requesting an ad tells Google approximately where you are. To be exact about the limits of this: DeepWake requests no location permission and calls no location API — you can confirm this in the App's permission list on your device, where no location entry appears — and neither the App nor we obtain your precise location. Approximate location by IP is a property of connecting to the internet at all, not something the App adds on top.

Your controls.

Purpose: to fund the free version of the App. See Google's privacy policy in Section 5.

3.7 Purchases and subscriptions (RevenueCat + Google Play / Apple)

In-app purchases and subscriptions are processed by the platform store (Google Play Billing or Apple App Store) and managed through RevenueCat, acting as our purchase-processing provider. We/RevenueCat process:

We do not receive or store your full payment card details — those are handled by the platform store. Purpose: to process purchases, restore them, apply premium entitlements (such as ad-free), and prevent fraud.

3.8 Security and anti-abuse (Firebase App Check)

The App uses Firebase App Check to verify that requests come from a genuine, untampered instance of the App. This uses platform attestation: Play Integrity on Android, App Attest / DeviceCheck on Apple platforms, and reCAPTCHA v3 on web. Purpose: to protect our backend from abuse and fraud. This is an essential security function.


4. Legal bases for processing (GDPR / EEA, UK)

Where the EU/UK GDPR applies, we rely on the following legal bases:

Outside the EEA and UK, where Google's consent SDK reports that no prior-consent requirement applies, our basis for first-party analytics is our legitimate interest in understanding which features are used and where the App fails — which is why analytics starts on there (Section 3.3). Crash diagnostics remain consent-based everywhere. The Settings toggle is an unconditional opt-out in every country.

For California (CCPA/CPRA) residents: we do not "sell" personal information for money. Sharing advertising identifiers with Google for personalized advertising may be considered "sharing" for cross-context behavioral advertising; you can opt out with Do Not Sell My Data in Settings > Privacy & data, and via the consent/ATT controls described above.


5. Third parties we share data with

We do not sell your personal data. We share data with the following service providers strictly to operate the App:

We may also disclose data where required by law or to protect our rights.


6. Data retention

Switching analytics or crash diagnostics off stops collection from that moment. It does not delete data that was already sent, and the App has no control that deletes it. To request erasure of data already collected, delete your account (Section 8) or contact us at info@nextanalytica.com.


7. Your rights and choices

Depending on your jurisdiction (e.g. GDPR, UK GDPR, CCPA/CPRA, Turkey's KVKK), you may have the right to:

How to exercise your choices:

To make any other request, contact us at info@nextanalytica.com. We will respond within the period required by applicable law.


8. Account and data deletion

If you never signed in, there is no account to delete and we hold nothing of yours on a server. Uninstalling the App removes what it stored on your device.

If you do have an account, you can delete it and its associated data directly in the App:

Settings > Account > Delete account (then confirm).

When you delete your account:

Backend purge of your data is completed within 30 days.

You may also request deletion by contacting info@nextanalytica.com. This is also our Google Play account-deletion contact path.


9. Children's privacy (COPPA and similar)

DeepWake is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or the minimum age of digital consent in your country, which may be higher — up to 16 in parts of the EEA). If you believe a child has provided us personal information, contact us at info@nextanalytica.com and we will delete it.

In the Google Play Console the App's declared target audience is 18 and over. That is a statement about who the App is aimed at, not a claim that younger people never use an alarm clock — plainly some do. It means we do not design for, market to, or seek minors as users, and we serve no advertising configured for them. This sentence previously said “rated for users aged 13 and older”, which did not match the Play declaration; the two are now aligned on the Play value. The declaration itself is under review and may change — if it does, this paragraph changes with it.


10. International data transfers

We use Google Firebase and the other providers listed in Section 5, whose infrastructure may process and store data on servers located outside your country, including the United States. Where data is transferred out of the EEA/UK, our providers rely on appropriate safeguards such as the EU Standard Contractual Clauses. Our primary Firebase data region is eur3 (European Union).


11. Data security

We use industry-standard measures including encrypted transport (HTTPS), Firestore Security Rules limiting access to your own data, server-authoritative writes for sensitive fields (entitlements), and Firebase App Check attestation. No method of transmission or storage is 100% secure.

As with any internet service, when the App calls our backend — which it does for entitlement checks and account deletion — the connection carries your device's IP address, and it is logged by Google Cloud as part of running the service.


12. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version at the policy URL above and revise the "Last updated" date. Material changes will be communicated in the App where required.


13. Contact us

Next Analytica Email: info@nextanalytica.com Address: Bursa, Türkiye Governing law / jurisdiction: Republic of Türkiye