Privacy Policy
Circa Ailarm
Effective date: May 31, 2026
Last updated: August 10, 2026
1. Introduction
This Privacy Policy ("Policy") describes how Ceyhan Girca ("we", "our", "us") collects, uses, and protects your personal data when you use the Circa Ailarm mobile application ("App").
Circa Ailarm is a science-based alarm application that supports your morning wake-up routine while minimizing personal data collection. Data minimization is our core principle.
This Policy explains your rights under the GDPR, California's CCPA, and Turkey's KVKK.
2. Data Controller
- Data Controller: Ceyhan Girca
- Email: support.circaailarm@gmail.com
3. Personal Data We Process
3.1 Data You Provide Directly
- Your name (first name only, optional) — stored on device. To address you in briefings.
- Chronotype — on device. Pre-wake phase calculation.
- Alarm preferences — on device.
- Voice preference (TTS) — on device.
3.2 Data Accessed via Device Permissions
- Approximate location (GPS, ~10m) → Weather queries via OpenWeather.
- Calendar events → Brief summaries. Only the summary is processed locally; event titles are never sent.
- Notifications → To show alarm notifications.
3.3 Data We Generate Automatically
- Rotation identifier (UUID) — An anonymous random identifier generated on the device. Used to keep brief wording from repeating; it never leaves the device and is not sent to any server.
- Device identifier (UUID) — A second anonymous random identifier generated on the device. It is sent with every call to our API proxy in the X-Device-Id header. Its only purpose is abuse prevention: the server uses it to count daily requests. The counter is deleted automatically after 2 days and is not linked to your name, location, address, or any other personal data.
- Wake logs — When you dismissed alarms. On device (last 100).
- TTS audio cache — Synthesized audio. On device (temporary).
- Subscription status — Whether your Premium access is active; written to the alarm record (on device).
- Motion sensor data — During wake verification (motion check), accelerometer data is processed only on-device and in real time; it is not stored and never sent to any server.
3.4 Data You Provide for the Traffic Feature (Optional)
- Home and work address/coordinates — on device. To calculate home → work travel time.
Your address stays on your device; relevant coordinates are sent to Google Maps Platform.
4. Legal Basis for Processing
- Alarm data → Performance of contract (KVKK 5/2-c, GDPR 6.1.b)
- Location → Explicit consent (KVKK 5/1, GDPR 6.1.a)
- Calendar access → Explicit consent
- Brief text (OpenAI) → Explicit consent
- Address/coordinates (Google) → Explicit consent
- Anonymous usage logs → Legitimate interest (KVKK 5/2-f, GDPR 6.1.f)
- Subscription/purchase status (RevenueCat) → Performance of contract (KVKK 5/2-c, GDPR 6.1.b)
5. Third-Party Service Providers
5.1 OpenAI (Text-to-Speech)
- Data sent: Brief text (time, weather info, calendar summary, name)
- Location: USA
- Retention: Max 30 days; not used for model training
5.2 OpenWeather (Weather data)
- Data sent: GPS coordinates
- Location: United Kingdom
5.3 Apple / Google (OS services)
Your device's OS converts location to city names using its own services.
5.4 Push Notification Services
Only local notifications — Apple/Google push services (APNs/FCM) are not used.
5.5 Google Maps Platform (Traffic — Distance Matrix)
- Data sent: Coordinates of home and work (only if you use the traffic feature)
- Location: USA
5.6 RevenueCat (Subscription management)
- Data sent: Anonymous app user identifier (randomly generated by RevenueCat), purchase/subscription status, device platform
- Location: USA
- Purpose: Verifying and restoring your subscription status across devices. Your card/payment details are never sent to RevenueCat; payments are processed by Apple/Google.
5.7 Cloudflare (API proxy)
The OpenAI, OpenWeather, and Google Maps calls above are not made directly from your device but through our own intermediate server running on Cloudflare Workers. The purpose is to keep service keys out of the app package; the keys never reach your device.
- Data sent: The request to be forwarded to the relevant service (brief text, coordinates, or address coordinates) and the device identifier (see 3.3)
- Location: Cloudflare's global edge network — the request is handled at the data centre nearest to you
- Retention: Request contents are not stored and no request logs are kept. The only data held on the server is the daily request counter used for abuse prevention; it is deleted automatically after 2 days.
6. What We Do NOT Collect
- No account registration (no email, no password)
- No advertising SDKs
- No analytics tools
- No crash reporting tools
- No social media integration
- No card/payment data (payments are processed by Apple/Google; only subscription status is shared with us)
- No platform device identifiers (IMEI, IDFA, Android ID) — the identifiers we use are random values generated by the app itself (see 3.3)
- No behavioral tracking
- No cookies
7. Data Retention
- Alarm preferences and settings → Until you uninstall or "Reset all data"
- Wake logs → Last 100; older ones auto-deleted
- TTS audio cache → Until next cache cleanup
- Location data → Last coordinates for 7 days, then auto-deleted
- Brief text sent to OpenAI → 30 days (server-side)
- Abuse counter (device identifier + date) → 2 days, then auto-deleted
- Subscription status → For the duration of the subscription plus the time needed for verification (on RevenueCat's side)
8. Data Security
Device data is protected by OS-level sandboxing. Third-party API communications use HTTPS (TLS 1.2+). We will notify you and authorities within 72 hours of any data breach.
9. Your Rights
9.1 Under GDPR (EU users)
Access, rectification, erasure, restriction, portability, objection, consent withdrawal.
9.2 Under KVKK (Turkey users)
Per KVKK Art. 11: information about processing, purpose, third parties, correction, deletion, objection, compensation.
9.3 Under CCPA (California users)
Right to know, deletion, opt out of sale (we do not sell), non-discrimination.
9.4 How to Exercise Your Rights
Settings → Reset all data deletes device data instantly. For other requests, write to support.circaailarm@gmail.com. We respond within 30 days.
10. Children's Privacy
The App is designed for users aged 13 and over.
11. International Data Transfers
Third-party services may process data outside your country. Depending on the feature, these transfers are based on your explicit consent or on the performance-of-contract legal basis, and occur only when you use the relevant feature.
12. Changes to This Policy
We may update this Policy from time to time. Significant changes will be announced within the App.
13. Contact
Ceyhan Girca
support.circaailarm@gmail.com