we collect almost nothing
PRIVACY POLICY.
last updated 21 august 2026
- the short version
- what stays on your phone
- what leaves your phone
- what we never collect
- your choices
- your rights
- contact
THE SHORT VERSION
There is no account. No email, no password, no profile, no name. We do not know who you are.
Your workouts stay on your phone. Streak, minutes, badges, track, settings — all of it is stored locally, and none of it is uploaded to us.
A little anonymous usage data may leave the device so we can tell whether the app works: crashes, app opens, a set finished. No names attached, and you can switch it off in Settings.
Payments go through Apple and Google. We never see your card.
We do not sell your data. There is not much to sell, and we would not anyway.
1. WHO THIS IS
This policy explains how NapFit (“NapFit”, “we”, “us”) handles information in the NapFit mobile app and on this website. Questions go to support@napfit.app.
2. WHAT STAYS ON YOUR PHONE
NapFit is local-first. The app works with no network connection and no login, because everything it needs is on the device. The following is written to your phone's private app storage and is never sent to us:
- your track (gentle or full send) and the date you told us a provider cleared you;
- your settings: vibration cues, nap nudges, pace, one-round toggle;
- your history: completed sets, minutes moved, day streak, weekly minutes, total sets, badge unlocks;
- session state, so a set survives a phone call.
Deleting the app deletes all of it, immediately and permanently. We hold no backup, so we cannot restore it and we cannot hand it to anyone else.
3. WHAT LEAVES YOUR PHONE
Three narrow categories, and that is the whole list.
a. Anonymous product analytics — optional
To find crashes and understand which parts of the app people actually use, NapFit can send anonymous, aggregated event data through our analytics and backend providers, Layers and amba. A typical event is “app opened”, “set completed”, “onboarding finished”, or “crash, with a stack trace”.
These events are keyed to a random, app-generated identifier. That identifier is not your name, your email, your phone number, or your device's advertising ID, and it is regenerated if you reinstall the app. Events also carry ordinary technical context: app version, operating system version, device model, country-level region, and a timestamp.
You can turn analytics off in Settings. The app keeps working exactly the same with it off.
b. Install attribution — optional, limited
If you arrived from an ad or a shared link, our attribution provider may record that the install came from that campaign. It answers “did this ad work”. It does not build a profile of you, and it is covered by the same Settings switch and by your device's App Tracking Transparency choice on iOS. Declining tracking on iOS is respected, always.
c. Purchases
When you start a trial or subscribe, Apple or Google processes the payment, and RevenueCat validates the receipt so the app knows whether Premium is active. What we see is a subscription status and an anonymous customer identifier. We never receive your card number, billing address, or Apple/Google account details.
d. Push notifications — only if you say yes
If you opt in to nap nudges, your device gives us a push token so Apple's or Google's push service can deliver the notification. A token identifies a device installation, and it is deleted when you turn notifications off or delete the app.
4. WHAT WE NEVER COLLECT
- Your name, email address, phone number, or postal address — unless you email support, in which case we have whatever you put in the email.
- Health records, medical history, delivery details, or anything you tell the app about your body. The track selector answer stays on the device.
- Contacts, photos, camera, microphone, or precise location. NapFit never asks for these permissions.
- Anything at all about your baby. The app has no field for it.
- Audio of any kind. There is no microphone use and no audio in the app, in either direction.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California law.
5. WHY WE'RE ALLOWED TO DO THIS (GDPR)
If you are in the UK, EU, or EEA, our legal bases are:
- Contract — processing purchase and entitlement data so we can give you the subscription you bought.
- Consent — analytics, attribution, and push notifications. You give it by opting in and you withdraw it in Settings at any time.
- Legitimate interests — crash diagnostics and keeping the service secure, balanced against your privacy.
6. HOW LONG WE KEEP THINGS
- On-device data: until you delete the app.
- Anonymous analytics events: up to 24 months, then deleted or further aggregated.
- Purchase and subscription records: as long as the store and tax law require, typically up to 7 years.
- Support emails: up to 24 months after the conversation ends.
7. YOUR CHOICES
- Turn analytics off in the app's Settings screen.
- Decline tracking in the iOS App Tracking Transparency prompt, or turn off “Allow Apps to Request to Track” entirely.
- Turn notifications off in the app, or in your phone's notification settings.
- Delete everything by deleting the app. That is the complete erasure path for on-device data, and it needs no request to us.
- Email us at support@napfit.app for anything else.
8. YOUR RIGHTS
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing, and to withdraw consent. Residents of California may request disclosure of the categories of personal information collected and may opt out of sale or sharing — we already do neither.
Email support@napfit.app and we will respond within 30 days. Be aware of the honest limit here: because NapFit has no account, we usually cannot connect a request to a specific person's data, and we will tell you plainly when that is the case rather than guess. If you are in the UK, EU, or EEA you may also complain to your local data protection authority.
9. CHILDREN
NapFit is for adults. We do not knowingly collect personal information from anyone under 18, and the app collects nothing whatsoever about the baby who is, we hope, asleep. If you believe a child has provided us with personal information, email support@napfit.app and we will delete it.
10. THIS WEBSITE
This site sets no cookies, runs no analytics, and has no tracking pixels or embedded third-party scripts. It loads the Unbounded and Archivo typefaces from Google Fonts, which means Google receives your IP address as part of that request — that is the only third party this page contacts. Everything else is served from our own host.
11. SECURITY AND TRANSFERS
Data in transit is encrypted with TLS. On-device data is protected by your phone's own app sandbox and disk encryption, so a passcode on the phone is genuinely the strongest control here. Our providers may process data in the United States and elsewhere; where required we rely on Standard Contractual Clauses or equivalent safeguards for international transfers.
No system is perfectly secure. We keep the amount of data we hold small, which is the most effective protection we can offer you.
12. CHANGES
If this policy changes we will update the date at the top and, for anything material, say so in the app. Continued use after a change means you accept the updated policy.
13. TALK TO US
Privacy questions, deletion requests, or a suspicion that something is off?
Email support@napfit.app. A person reads it.
See also the Terms of Service.