Zurück zu Luzide

Datenschutzerklärung für die App Luzide

Stand: 09.10.2026

1. Verantwortlicher

Joobin Khavand (Einzelunternehmer)

Flensburgstraße 4, 58093 Hagen

E-Mail: luzide.app@gmail.com

Einen Datenschutzbeauftragten haben wir nicht benannt.

2. Das Wichtigste in Kürze

3. Welche Daten wir verarbeiten

3.1 Konto und Anmeldung

Die E-Mail-Adresse wird nicht in unsere Datenbank geschrieben, nur von Firebase Authentication verwaltet und in der App angezeigt. Ein Profilbild wird nicht gespeichert.

3.2 Profil und Fragebogen

Luzide trennt die Angaben in zwei Stufen. Stufe a gehört zur Kernfunktion und ist Teil der Pflicht-Einwilligung. Stufe b, die "Erweiterten Angaben", ist eine eigene, freiwillige Einwilligung.

a) Pflicht-Einwilligung (Kernfunktion)

Ohne diese Einwilligung startet keine Traumreise (siehe "Pflicht zur Bereitstellung"). Sie umfasst folgende Kategorien:

Die meisten dieser Angaben sind Gesundheitsdaten im Sinne von Art. 9 DSGVO. Zweck: Schlafphasen erkennen, dir Signale geben, dein persönliches Modell trainieren und dir deine Auswertungen zeigen. Rechtsgrundlage ist deine ausdrückliche Einwilligung, Art. 9 Abs. 2 lit. a in Verbindung mit Art. 6 Abs. 1 lit. a DSGVO.

b) Freiwillige Einwilligung "Erweiterte Angaben"

Diese Einwilligung ist freiwillig. Das Kästchen ist nicht vorangekreuzt, und die Nutzung der App hängt nicht davon ab. Du kannst sie jederzeit widerrufen; der Widerruf löscht die Angaben dieser Stufe. Das Quiz steht nur PRO-Nutzern offen. Die Einwilligung umfasst:

Diese Angaben sind überwiegend Gesundheitsdaten im Sinne von Art. 9 DSGVO, die psychischen Angaben eingeschlossen. Zweck: Empfehlungen und Techniken an dich anpassen, Sicherheitshinweise geben und Modelle mit deinen Angaben füttern. Rechtsgrundlage ist deine eigene, ausdrückliche Einwilligung, Art. 9 Abs. 2 lit. a in Verbindung mit Art. 6 Abs. 1 lit. a DSGVO. Du kannst jede Frage unbeantwortet lassen.

Ohne diese Einwilligung gibt es kein Quiz, keine Gewohnheitsangaben im Onboarding, der Abend-Check-in stellt nur die Pflichtfragen, und Modelle und Empfehlungen arbeiten mit Standardwerten. Widerrufst du sie, löscht Luzide das Quiz-Profil mit allen Rohantworten, das Archiv früherer Durchläufe, die daraus übernommenen Felder, die Gewohnheits-Schalter aus dem Onboarding und die zusätzlichen Antworten im Abend-Check-in.

Altersgrenze: Eine Traumreise startet nur ab 18 Jahren. Liegt ein Geburtsdatum unter 18 vor, ist der Start gesperrt; fehlt das Geburtsdatum, fragt die App einmalig "mindestens 18" ab. Die Bestätigung wird lokal je Nutzerkennung und im Nutzerdokument gespeichert. Andere Teile der App (z. B. das Tagebuch) sperrt die Altersgrenze nicht.

3.3 Messdaten während einer Traumreise

Erfasst nur während einer Traumreise, die du selbst startest.

Die Speicherorte liegen jeweils unter users/{uid}/.

PPG-Rohdaten (Lichtsignal des Pulssensors) werden nicht erfasst. Die Herzwerte liefert der Sensor bereits fertig berechnet.

Zur Atemerkennung: Das Mikrofon läuft nur während einer aktiven Traumreise. Es wird kein Ton gespeichert, nur Atemfrequenz und Variabilität. Standardmäßig aus.

Samsung Health Sensor SDK: "The Samsung Health Sensor SDK does not share data with Samsung Health." (https://developer.samsung.com/health/sensor/faq.html).

Uhr und Handy: Die Uhr speichert keine Messreihen dauerhaft und hat keine Verbindung zu Firebase; sie sendet über die Wearable Data Layer API an dein Handy.

3.4 Schlafdaten aus Health Connect

Wenn du es erlaubst, liest Luzide aus Health Connect deine Schlafsitzungen mit Schlafphasen (wach, leicht, tief, REM), und zwar nur die von Samsung Health. Luzide liest nur, es schreibt nichts nach Health Connect. Gespeichert im Nachtdokument. Zweck: Vergleich mit der eigenen Erkennung und Training deines persönlichen Modells.

Herkunft wird gespeichert (seit 05.10.2026): Zu jeder Nacht speichert Luzide, welche App wie viele Schlafabschnitte geliefert hat, also den Paketnamen der schreibenden App und eine Anzahl. Gespeichert im Nachtdokument und im Messprotokoll. Zweck: nachvollziehen, woher die Vergleichsdaten stammen.

Nur Samsung Health (seit 06.10.2026): Luzide liest und importiert aus Health Connect ausschließlich Schlafsitzungen, die Samsung Health geschrieben hat. Schlafdaten anderer Apps, die nach Health Connect schreiben, werden nicht gelesen. Beide Lesepfade fragen Health Connect mit diesem Herkunftsfilter ab. Die Herkunftszählung oben bleibt bestehen.

3.5 Traumtagebuch, Traumzeichen, Diktat

Abend-Check-in: Die Pflichtfragen gehören zur Pflicht-Einwilligung. Die zusätzlichen Fragen (Stress, letzte Mahlzeit, Bildschirmzeit, Koffein, Alkohol, Sport, Meditation, emotionaler Tagesverlauf) stellt der Check-in nur, wenn du in die Erweiterten Angaben eingewilligt hast (3.2 b). Der Check-in erscheint nur in den höheren Verpflichtungsstufen. Die Antworten werden mit der jeweiligen Nacht in deinem Konto gespeichert.

Die Erkennung von Traumzeichen läuft auf dem Handy ohne Netz.

Diktat: Du kannst Einträge per Sprache diktieren.

3.6 Eigene Sprachaufnahme als Reiz

Wenn du für die Tages-Reize eine eigene Aufnahme machst, speichert Luzide sie als Datei nur auf deinem Handy. Sie wird nicht an die Uhr und nicht in die Cloud gesendet.

3.7 Persönliches Schlafmodell

Das Modell wird auf deinem Handy trainiert; die lokale Datei ist maßgeblich. Eine komprimierte Sicherungskopie liegt in deinem Konto unter users/{uid}/personalModel, damit es nach einem Gerätewechsel nicht verloren geht. Auf dem Handy werden höchstens 30 ältere Fassungen aufbewahrt.

3.8 Käufe

Für PRO nutzen wir den Abrechnungsdienst von Google Play und RevenueCat. Luzide meldet RevenueCat deine Firebase-UID als Kundenkennung. RevenueCat erhält von Google Play die Kaufhistorie: "RevenueCat collects a customer's purchase history" (https://www.revenuecat.com/docs/platform-resources/google-platform-resources/google-plays-data-safety). Zahlungsdaten (Karte, Konto) sehen wir nicht; sie bleiben bei Google Play.

3.9 Absturzberichte

In Release-Fassungen sendet die App Absturzberichte an Firebase Crashlytics, solange du das nicht abschaltest. Crashlytics erfasst laut Google "Crashlytics Installation UUIDs, Firebase installations ID, Crash traces, Breakpad minidump formatted data (NDK crashes only)" (https://firebase.google.com/support/privacy). Wir verknüpfen Berichte nicht mit deiner UID.

Abschalten: Einstellungen, Abschnitt "KONTO & DATEN", Schalter "Absturzberichte senden". Standard: an. Die Wahl wird auf dem Handy gespeichert und wirkt beim Start und sofort beim Umschalten. In Debug-Fassungen sendet die App nie, unabhängig vom Schalter. Nach einer Löschung der Daten auf dem Handy steht der Schalter wieder auf dem Standard "an" (die Wahl liegt in den lokalen Einstellungen, die die Löschung leert).

3.10 Schriftarten

Alle Schriftarten sind in der App enthalten. Die App ruft keine Schriften von Google-Servern ab, dafür wird also auch keine IP-Adresse an Google übertragen. Fehlt eine Datei, bricht das Paket ab, statt still aus dem Netz zu laden. Die Schriften stehen unter der SIL Open Font License 1.1; die Lizenztexte sind im Lizenz-Bildschirm der App eingetragen.

3.11 Nachladbare Audio-Inhalte (gebaut, in der Store-Fassung aus)

Die Audio-Bibliothek ist gebaut, in der Store-Fassung aber ausgeschaltet. Der Speicherort ist entschieden: Firebase Storage in einer kostenlosen US-Region. Der Bucket ist noch nicht angelegt. Die App holt die Download-Adresse und legt die Dateien auf dem Handy im Support-Ordner ab.

Die Einwilligung in Fassung 2 nennt diesen Abruf.

3.12 Freiwillige Datenspende (vorbereitet, heute ohne Übertragung)

Heute wird nichts gespendet und nichts übertragen. Der Upload ist nicht gebaut und abgeschaltet. Er kommt erst, wenn Samsung die Weitergabe der Sensordaten schriftlich bestätigt hat. Gebaut ist nur die Einwilligung:

Was eine Spende später enthalten soll, sagt der Text in der App: Messreihen von Uhr und Handy, Schlafphasen aus Samsung Health, ob Reize gegeben und ob du geweckt wurdest, Altersgruppe und Geschlecht, nie Tagebuch, Name, E-Mail oder Datum der Nacht. Diese Aussagen beschreiben einen Upload, den es noch nicht gibt. Dieser Abschnitt wird neu gefasst, sobald der Upload gebaut ist.

3.13 Beta-Auswertung

Nur in Testversionen für Beta-Tester fragt Luzide eine zusätzliche, freiwillige Einwilligung ab: die Beta-Auswertung. In der Store-Fassung ohne Tester-PRO gibt es sie nicht.

4. Rechtsgrundlagen

Art. 9 Abs. 2 lit. a DSGVO: "the data subject has given explicit consent to the processing of those personal data for one or more specified purposes" (https://eur-lex.europa.eu/eli/reg/2016/679/oj).

Die Einwilligung holt die App auf einem eigenen Bildschirm mit zwei Pflicht-Kästchen und einem freiwilligen dritten Kästchen für die Datenspende ein. Sie wird mit Fassung, Datum und Speicherort im Nutzerdokument festgehalten. Ändert sich der Text, fragt die App erneut. Die Erweiterten Angaben holt die App getrennt davon ein: eigenes Kästchen, nicht vorangekreuzt, keine Bedingung für die Nutzung.

Zwei Fassungen:

5. Speicherorte

Keine Android-Sicherung: Handy-App und Uhr-App schließen die automatische Android-Sicherung aus. Daten der App auf dem Handy oder der Uhr gehen damit nicht in die Sicherung deines Google-Kontos.

Ist-Zustand seit 06.10.2026: Die App schreibt in die Datenbank luzide-eu mit Standort eur3 (EU). Die alte Datenbank (default) mit Standort nam5 (USA) bleibt bis zum 20.10.2026 unverändert als Rückfallebene stehen und wird an diesem Tag gelöscht. Kopiert wurde nicht über einen Cloud-Storage-Export, sondern mit eigenen Skripten über die REST-Schnittstelle; deren Exportdateien liegen lokal beim Betreiber. Firebase Authentication bleibt in den USA; einen EU-Standort gibt es dafür nicht (Zeile oben).

Übermittlung in die USA:

6. Empfänger

Wir verkaufen keine Daten und geben sie nicht an Werbenetzwerke. Google Play verbietet dies für Gesundheitsdaten ausdrücklich: "Transferring or selling user health or fitness data to third parties like advertising platforms, data brokers, or any information resellers" (https://support.google.com/googleplay/android-developer/answer/12991134).

7. Speicherdauer

8. Löschen

In der App unter Einstellungen (Zahnrad oben rechts auf dem Startbildschirm), Abschnitt "KONTO & DATEN": "Alle Daten löschen" oder "Account komplett löschen".

Kurz zum Ablauf: zuerst alle Daten in deinem Konto in der Datenbank samt Nutzerdokument (dazu gehören auch die Spende-Zustimmung und die Altersbestätigung), dann ein Löschbefehl an die Uhr, die Abmeldung bei RevenueCat, die Daten auf dem Handy, auf Wunsch das Konto, die Abmeldung und der lokale Datenbank-Zwischenspeicher. Auf dem Handy leert die App den Dokumente-Ordner, den externen App-Ordner, den Temp- und den Cache-Ordner, alle lokalen Einstellungen (auch die Spender-Kennung) und native Einstellungsdateien. Als letzter Schritt leert sie den gesamten Support-Ordner, auch die heruntergeladenen Audios. Die Uhr löscht ihre Daten, sobald sie verbunden ist und keine Traumreise aktiv ist. Wird die Löschung unterbrochen, setzt die App sie beim nächsten Start fort. Fehlt für das Löschen des Kontos eine frische Anmeldung und brichst du sie ab, zeigt die App einen Hinweis mit "Jetzt anmelden".

Der Widerruf der Pflicht-Einwilligung löscht keine Daten: "Bereits gespeicherte Daten bleiben erhalten, bis du sie in den Einstellungen löschst."

9. Website

Dieser Abschnitt gilt für den Besuch dieser Website und für die Beta-Anmeldung. Die übrigen Abschnitte beschreiben die App.

9.1 Hosting über GitHub Pages

Die Website wird über GitHub Pages bereitgestellt. Anbieter ist GitHub, Inc., 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USA. Beim Aufruf der Seiten verarbeitet GitHub technisch notwendige Daten. Laut der Datenschutzerklärung von GitHub gehören dazu die IP-Adresse und Protokolldaten: "We collect data about your interactions with the Services, such as IP address." und "We automatically log data about your Website interactions." Welche Daten GitHub speziell für GitHub Pages erfasst, nennt GitHub dort nicht gesondert. Quelle: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement (abgerufen am 09.10.2026)

Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO. Unser berechtigtes Interesse ist die sichere und stabile Bereitstellung dieser Website.

Dabei können Daten in die USA übermittelt werden. GitHub nennt dafür selbst zwei Grundlagen: Es gibt an, das EU-U.S. Data Privacy Framework einzuhalten ("GitHub also complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF)"), und es stützt sich nach eigener Angabe im Allgemeinen auf die von der Europäischen Kommission veröffentlichten Standardvertragsklauseln (Durchführungsbeschluss 2021/914). Quelle: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement (abgerufen am 09.10.2026)

9.2 Keine Cookies, keine Analyse

Auf den Seiten Datenschutz, Impressum, Nutzungsbedingungen und Konto löschen setzen wir keine Cookies, keinen Analyse- oder Tracking-Dienst und keine Werbung ein. Die Schriften werden von dieser Website selbst ausgeliefert (lokal eingebunden); von Servern Dritter werden keine Schriften oder anderen Ressourcen nachgeladen. Die Sprachwahl (DE/EN) wertet nur dein Browser aus der Adresse aus; sie wird nicht gespeichert.

9.3 Beta-Anmeldung über MailerLite

Für die Anmeldung zur Beta-Phase nutzen wir den Dienst MailerLite. Vertragspartner ist laut MailerLite bei einer Rechnungsadresse im Europäischen Wirtschaftsraum MailerLite Limited, 88 Harcourt Street, Dublin 2, D02 DK18, Irland. MailerLite verarbeitet die Angaben als Auftragsverarbeiter in unserem Auftrag ("We process Personal Data as a Processor on behalf of the Customer."). Die Auftragsverarbeitung richtet sich nach dem Data Processing Agreement von MailerLite. Quellen: https://www.mailerlite.com/legal/privacy-policy und https://www.mailerlite.com/legal/data-processing-agreement (abgerufen am 09.10.2026)

10. Deine Rechte

Du hast nach der DSGVO das Recht auf Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung (Art. 18), Datenübertragbarkeit (Art. 20) und Widerspruch gegen Verarbeitungen auf Grundlage berechtigter Interessen (Art. 21). Quelle: https://eur-lex.europa.eu/eli/reg/2016/679/oj

Den Absturzberichten (3.9) widersprichst du am einfachsten direkt in der App: Einstellungen, "KONTO & DATEN", Schalter "Absturzberichte senden" ausschalten. Ab dann sendet die App keine Berichte mehr.

Du kannst dich bei einer Datenschutz-Aufsichtsbehörde beschweren (Art. 77 DSGVO). Zuständige Behörde für uns: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf.

Eine Export-Funktion für Nutzer gibt es in der App heute nicht. Anfragen nach Art. 15 und 20 bitte an luzide.app@gmail.com.

11. Widerruf der Einwilligung

Du kannst deine Einwilligung jederzeit mit Wirkung für die Zukunft widerrufen: Einstellungen, "Datenschutz und Einwilligung", "Einwilligung widerrufen". Danach startet keine neue Traumreise mehr. Die Rechtmäßigkeit der Verarbeitung bis zum Widerruf bleibt unberührt: "The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal." (Art. 7 Abs. 3 DSGVO, https://eur-lex.europa.eu/eli/reg/2016/679/oj)

Die Atemerkennung schaltest du getrennt in den Einstellungen aus.

Die Erweiterten Angaben (3.2 b) widerrufst du getrennt und jederzeit; die Pflicht-Einwilligung bleibt dabei bestehen. Mit dem Widerruf löscht Luzide das Quiz-Profil mit allen Rohantworten, das Archiv früherer Durchläufe, die daraus übernommenen Felder, die Gewohnheits-Schalter aus dem Onboarding und die zusätzlichen Antworten im Abend-Check-in. Danach gibt es kein Quiz, keine Gewohnheitsangaben im Onboarding, der Abend-Check-in stellt nur die Pflichtfragen, und Modelle und Empfehlungen arbeiten mit Standardwerten.

Die freiwillige Datenspende (3.12) widerrufst du getrennt mit dem Schalter "Nächte spenden" unter "Datenschutz und Einwilligung"; die Pflicht-Einwilligung bleibt dabei bestehen. Widerrufst du die Pflicht-Einwilligung, widerruft die App die Spende mit und entfernt die Spender-Kennung vom Handy.

12. Pflicht zur Bereitstellung

Die Messdaten sind freiwillig. Ohne Einwilligung kannst du die App öffnen, aber keine Traumreise aufzeichnen und kein Tagebuch speichern. Eine Traumreise ist außerdem erst ab 18 Jahren möglich (3.2).

Die Erweiterten Angaben (3.2 b) sind vollständig freiwillig. Ohne sie nutzt du alle Kernfunktionen: kein Quiz, keine Gewohnheitsangaben im Onboarding, der Abend-Check-in stellt nur die Pflichtfragen, Modelle und Empfehlungen arbeiten mit Standardwerten.

13. Kein Medizinprodukt

Luzide ist kein Medizinprodukt und stellt keine Diagnosen. Siehe Nutzungsbedingungen.

Back to Luzide

Privacy policy for the Luzide app

As of: 9 October 2026

1. Controller

Joobin Khavand (sole proprietor)

Flensburgstraße 4, 58093 Hagen, Germany

E-mail: luzide.app@gmail.com

We have not appointed a data protection officer.

2. Summary

3. What data we process

3.1 Account and sign-in

The email address is not written to our database. It is only managed by Firebase Authentication and shown in the app. No profile picture is stored.

3.2 Profile and questionnaire

Luzide splits your details into two levels. Level a belongs to the core function and is part of the required consent. Level b, the "Extended details", is a separate, voluntary consent.

a) Required consent (core function)

Without this consent no dream journey starts (see "Obligation to provide data"). It covers these categories:

Most of these details are health data within the meaning of Art. 9 GDPR. Purpose: detecting sleep stages, giving you signals, training your personal model and showing you your evaluations. The legal basis is your explicit consent, Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR.

b) Voluntary consent "Extended details"

This consent is voluntary. The checkbox is not pre-ticked, and using the app does not depend on it. You can withdraw it at any time; withdrawing deletes the details of this level. The quiz is open to PRO users only. The consent covers:

These details are mostly health data within the meaning of Art. 9 GDPR, including the mental health details. Purpose: tailoring recommendations and techniques to you, giving safety notices and feeding models with your details. The legal basis is your own explicit consent, Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR. You can leave any question unanswered.

Without this consent there is no quiz, no habit details in onboarding, the evening check-in asks only the required questions, and models and recommendations work with default values. If you withdraw it, Luzide deletes the quiz profile with all raw answers, the archive of earlier runs, the fields taken from it, the habit switches from onboarding and the additional answers in the evening check-in.

Age limit: A dream journey only starts from the age of 18. If a date of birth under 18 is stored, starting is blocked; if there is no date of birth, the app asks once to confirm "at least 18". The confirmation is stored locally per user ID and in the user document. The age limit does not block other parts of the app (e.g. the journal).

3.3 Measurement data during a dream journey

Collected only during a dream journey that you start yourself.

These storage locations are each located under users/{uid}/.

Raw PPG data (light signal of the pulse sensor) is not collected. The sensor already delivers the heart values in calculated form.

On breath detection: The microphone only runs during an active dream journey. No sound is stored, only breathing rate and its variability. Off by default.

Samsung Health Sensor SDK: "The Samsung Health Sensor SDK does not share data with Samsung Health." (https://developer.samsung.com/health/sensor/faq.html).

Watch and phone: The watch does not store measurement series permanently and has no connection to Firebase; it sends to your phone via the Wearable Data Layer API.

3.4 Sleep data from Health Connect

If you allow it, Luzide reads your sleep sessions with sleep stages (awake, light, deep, REM) from Health Connect, only those from Samsung Health. Luzide only reads, it writes nothing to Health Connect. Stored in the night document. Purpose: comparison with Luzide's own detection and training of your personal model.

Origin is stored (since 05.10.2026): For each night, Luzide stores which app delivered how many sleep segments, i.e. the package name of the writing app and a count. Stored in the night document and in the measurement log. Purpose: being able to trace where the comparison data comes from.

Samsung Health only (since 06.10.2026): From Health Connect, Luzide reads and imports only sleep sessions written by Samsung Health. Sleep data written to Health Connect by other apps is not read. Both read paths query Health Connect with this origin filter. The origin count above remains.

3.5 Dream journal, dream signs, dictation

Evening check-in: The required questions belong to the required consent. The additional questions (stress, last meal, screen time, caffeine, alcohol, sport, meditation, emotional course of the day) are asked only if you have consented to the Extended details (3.2 b). The check-in appears only at the higher commitment levels. The answers are stored with the respective night in your account.

Dream sign detection runs on the phone without a network.

Dictation: You can dictate entries by voice.

3.6 Own voice recording as a cue

If you make your own recording for the daytime cues, Luzide stores it as a file on your phone only. It is not sent to the watch or to the cloud.

3.7 Personal sleep model

The model is trained on your phone; the local file is authoritative. A compressed backup copy is kept in your account under users/{uid}/personalModel so that it is not lost when you change devices. At most 30 older versions are kept on the phone.

3.8 Purchases

For PRO we use the billing service of Google Play and RevenueCat. Luzide reports your Firebase UID to RevenueCat as the customer ID. RevenueCat receives the purchase history from Google Play: "RevenueCat collects a customer's purchase history" (https://www.revenuecat.com/docs/platform-resources/google-platform-resources/google-plays-data-safety). We do not see payment data (card, account); it stays with Google Play.

3.9 Crash reports

In release versions, the app sends crash reports to Firebase Crashlytics unless you switch this off. According to Google, Crashlytics collects "Crashlytics Installation UUIDs, Firebase installations ID, Crash traces, Breakpad minidump formatted data (NDK crashes only)" (https://firebase.google.com/support/privacy). We do not link reports to your UID.

Switching off: Settings, section "ACCOUNT & DATA", switch "Send crash reports". Default: on. The choice is stored on the phone and takes effect at start and immediately when switched. Debug versions never send, regardless of the switch. After the data on the phone has been deleted, the switch is back on the default "on" (the choice is part of the local settings that deletion clears).

3.10 Fonts

All fonts are included in the app. The app does not fetch fonts from Google servers, so no IP address is transmitted to Google for this. If a file is missing, the package stops instead of silently loading from the network. The fonts are licensed under the SIL Open Font License 1.1; the licence texts are listed in the app's licence screen.

3.11 Downloadable audio content (built, switched off in the store version)

The audio library is built but switched off in the store version. The storage location has been decided: Firebase Storage in a free US region. The bucket has not been created yet. The app fetches the download address and stores the files on the phone in the support folder.

Version 2 of the consent names this download.

3.12 Voluntary data donation (prepared, no transfer today)

Today nothing is donated and nothing is transferred. The upload is not built and is switched off. It will only come once Samsung has confirmed in writing that the sensor data may be passed on. Only the consent is built:

What a donation is to contain later is described in the app text: measurement series from watch and phone, sleep stages from Samsung Health, whether cues were given and whether you were woken, age group and sex, never journal, name, email or date of the night. These statements describe an upload that does not exist yet. This section will be rewritten once the upload is built.

3.13 Beta evaluation

Only in test versions for beta testers does Luzide ask for an additional, voluntary consent: the beta evaluation. It does not exist in the store version without tester PRO.

4. Legal bases

Art. 9(2)(a) GDPR: "the data subject has given explicit consent to the processing of those personal data for one or more specified purposes" (https://eur-lex.europa.eu/eli/reg/2016/679/oj).

The app obtains consent on a separate screen with two required checkboxes and a voluntary third checkbox for the data donation. It is recorded in the user document with version, date and storage location. If the text changes, the app asks again. The app obtains the Extended details separately: its own checkbox, not pre-ticked, not a condition for using the app.

Two versions:

5. Storage locations

No Android backup: The phone app and the watch app exclude the automatic Android backup. App data on the phone or the watch therefore does not go into the backup of your Google account.

Current state since 06.10.2026: The app writes to the database luzide-eu with location eur3 (EU). The old database (default) with location nam5 (USA) remains unchanged as a fallback until 20.10.2026 and will be deleted on that day. The data was not copied via a Cloud Storage export but with our own scripts via the REST interface; their export files are stored locally with the operator. Firebase Authentication remains in the USA; there is no EU location for it (line above).

Transfer to the USA:

6. Recipients

We do not sell data and do not pass it on to advertising networks. Google Play expressly prohibits this for health data: "Transferring or selling user health or fitness data to third parties like advertising platforms, data brokers, or any information resellers" (https://support.google.com/googleplay/android-developer/answer/12991134).

7. Storage period

8. Deletion

In the app under Settings (gear icon top right on the start screen), section "ACCOUNT & DATA": "Delete all data" or "Delete account completely".

The process in short: first all data in your account in the database including the user document (this includes the donation agreement and the age confirmation), then a delete command to the watch, signing out of RevenueCat, the data on the phone, if chosen the account, signing out and the local database cache. On the phone, the app empties the documents folder, the external app folder, the temp and cache folders, all local settings (including the donor ID) and native settings files. As the last step it empties the entire support folder, including downloaded audio. The watch deletes its data as soon as it is connected and no dream journey is active. If deletion is interrupted, the app continues it at the next start. If deleting the account requires a fresh sign-in and you cancel it, the app shows a notice with "Sign in now".

Withdrawing the required consent does not delete any data: "Data already stored remains until you delete it in the settings."

9. Website

This section applies to visiting this website and to the beta sign-up. The other sections describe the app.

9.1 Hosting via GitHub Pages

The website is served via GitHub Pages. The provider is GitHub, Inc., 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USA. When you open the pages, GitHub processes technically necessary data. According to the GitHub privacy statement this includes the IP address and log data: "We collect data about your interactions with the Services, such as IP address." and "We automatically log data about your Website interactions." GitHub does not separately state there which data it collects specifically for GitHub Pages. Source: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement (retrieved 9 October 2026)

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable provision of this website.

Data may be transferred to the USA in the process. GitHub itself names two bases: it states that it complies with the EU-U.S. Data Privacy Framework ("GitHub also complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF)"), and it states that it generally relies on the standard contractual clauses published by the European Commission (Implementing Decision 2021/914). Source: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement (retrieved 9 October 2026)

9.2 No cookies, no analytics

On the pages Privacy policy, Legal notice, Terms of use and Delete account we do not use cookies, analytics or tracking services, or advertising. The fonts are delivered by this website itself (included locally); no fonts or other resources are loaded from third-party servers. The language selection (DE/EN) is evaluated only by your browser from the address; it is not stored.

9.3 Beta sign-up via MailerLite

For the beta sign-up we use the service MailerLite. According to MailerLite, the contracting party for a billing address in the European Economic Area is MailerLite Limited, 88 Harcourt Street, Dublin 2, D02 DK18, Ireland. MailerLite processes the data as a processor on our behalf ("We process Personal Data as a Processor on behalf of the Customer."). The processing is governed by the MailerLite Data Processing Agreement. Sources: https://www.mailerlite.com/legal/privacy-policy and https://www.mailerlite.com/legal/data-processing-agreement (retrieved 9 October 2026)

10. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Source: https://eur-lex.europa.eu/eli/reg/2016/679/oj

The easiest way to object to crash reports (3.9) is directly in the app: Settings, "ACCOUNT & DATA", switch off "Send crash reports". From then on the app sends no more reports.

You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Competent authority for us: State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.

There is currently no export function for users in the app. Please send requests under Art. 15 and 20 to luzide.app@gmail.com.

11. Withdrawing consent

You can withdraw your consent at any time with effect for the future: Settings, "Privacy and consent", "Withdraw consent". After that, no new dream journey starts. The lawfulness of processing until the withdrawal remains unaffected: "The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal." (Art. 7(3) GDPR, https://eur-lex.europa.eu/eli/reg/2016/679/oj)

You switch off breath detection separately in the settings.

You withdraw the Extended details (3.2 b) separately and at any time; the required consent remains. With the withdrawal Luzide deletes the quiz profile with all raw answers, the archive of earlier runs, the fields taken from it, the habit switches from onboarding and the additional answers in the evening check-in. After that there is no quiz, no habit details in onboarding, the evening check-in asks only the required questions, and models and recommendations work with default values.

You withdraw the voluntary data donation (3.12) separately with the switch "Donate nights" under "Privacy and consent"; the required consent remains. If you withdraw the required consent, the app also withdraws the donation and removes the donor ID from the phone.

12. Obligation to provide data

The measurement data is voluntary. Without consent you can open the app, but you cannot record a dream journey or save a journal. A dream journey is also only possible from the age of 18 (3.2).

The Extended details (3.2 b) are entirely voluntary. Without them you use all core functions: no quiz, no habit details in onboarding, the evening check-in asks only the required questions, models and recommendations work with default values.

13. Not a medical device

Luzide is not a medical device and does not make diagnoses. See terms of use.