Somlora Privacy Policy (EN)
Somlora Sleep AI – Privacy Policy
Effective: August 2025
1. Introduction & Controller
This Privacy Policy explains how AMoCha GmbH (“we”, “Somlora”) processes your personal data when you use our AI-powered audio meditation service Somlora Sleep AI.
We follow a Privacy by Design approach:
- No storage of sensitive health data
- No permanent storage of prompt texts
- Cookie-less service (no tracking cookies)
- Only minimal data necessary for providing the service
- Controller: AMoCha GmbH, Kolschitzkygasse 23, 1040
Vienna, Austria
- Email for privacy inquiries: [email protected]
- Data Protection Officer: not appointed
- Server location: EU (Hetzner, Germany)
Our practices are primarily based on the EU GDPR and also comply with the Austrian DSG, UK GDPR, Swiss FADP, the California Consumer Privacy Act (CCPA/CPRA), and the Canadian PIPEDA.
2. Data We Process
2.1 Account Data
- Email address
- Password hash (bcrypt)
- First/last name (optional)
- User ID (UUID)
- Provider/Provider-ID (if OAuth login is used)
2.2 Audio Data
- Audio metadata (filename, size, duration, voice preset/ID,
status)
- Generated audio files (stored until account deletion)
- ❌ No storage of original or reframed prompts
2.3 Prompt Processing (Privacy by Design)
- Purpose: Prompt sanitization & reframing with
AI → TTS audio generation
- Lifecycle: Receive → Sanitize → Reframe → Generate
Audio → Delete
- Retention: Prompts are processed only temporarily and deleted immediately after generation
2.4 Contract & Payment Data
- Subscription tier (Free/Basic/Premium)
- Stripe Customer ID
- Stripe webhook events (payment processing)
2.5 Technical & Audit Data
- IP address & User-Agent (only during authentication/security
events)
- Timestamps of actions
- Event types (e.g., login, audio generation)
- Audit metadata for potentially harmful or abusive user prompts (only if classified as such, e.g. “selfharm”, “violence”, “abuse” – includes category, timestamp, pseudonymized user ID, optionally: IP)
2.6 Consent Management
- Consent records (version, type, IP, timestamp, User-Agent)
- Email verification token (24h validity)
3. Purposes & Legal Bases
| Purpose | GDPR Legal Basis | CCPA Equivalent | PIPEDA Equivalent |
|---|---|---|---|
| Account creation & management | Art. 6(1)(b) | Business Purpose | Contract fulfillment |
| Prompt sanitization/reframing & TTS audio generation | Art. 6(1)(b) | Business Purpose | Contract fulfillment |
| Payment processing (Stripe) | Art. 6(1)(b) | Business Purpose | Contract fulfillment |
| IT security & fraud prevention | Art. 6(1)(f) | Legitimate Interest | Legitimate interest |
| Email verification | Art. 6(1)(a) | Consent | Consent |
| (Optional/future) Marketing/Newsletter | Art. 6(1)(a) | Consent / No Sale | Consent |
| Safety monitoring & abuse detection | Art. 6(1)(f) | Security & Fraud Prevention | Legitimate Interests |
4. Privacy by Design – Our USP
- No sensitive health data collected
- No prompt texts stored (neither original nor reframed)
- Cookie-less service (no tracking, no cross-device profiling)
- Minimal data collection
Note: For safety reasons, we may store anonymized metadata (e.g. classification label, timestamp, pseudonymized user ID) when harmful or abusive input is detected (e.g. self-harm, violence). Prompt text is never stored. This processing is based on Art. 6(1)(f) GDPR (legitimate interest).
5. Third-Party Providers & Data Transfers
OpenAI (USA)
- Purpose: Prompt sanitization & reframing
- Legal basis: Art. 6(1)(b) GDPR
- Transfer: Standard Contractual Clauses (SCCs) and
EU-US Data Privacy Framework (where applicable)
- Storage: Prompts are not stored
ElevenLabs (UK/EU)
- Purpose: Text-to-Speech audio generation
- Legal basis: Art. 6(1)(b) GDPR, UK GDPR
- Transfer safeguards: EU–UK adequacy decision or SCCs
Stripe (Ireland/USA)
- Purpose: Payment processing
- Legal basis: Art. 6(1)(b) GDPR
- Transfer: EU operations + possible US transfers
under SCCs/DPF
- PCI-DSS compliant
Hetzner (Germany, EU)
- Purpose: Hosting
- Legal basis: Art. 28 GDPR (processor
agreement)
- Location: EU only
Google Fonts (USA)
- Purpose: Website font display
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest
in technical presentation)
- Transfer: Standard Contractual Clauses (SCCs) and
EU-US Data Privacy Framework (DPF)
- Data transmitted: IP address and User-Agent
(automatically on page load)
- More information: Google Privacy Policy
⚠️ Note on US transfers: Despite safeguards (SCCs/DPF), US authorities may access data under certain laws. We mitigate risks via encryption, strict access controls, and data minimization.
6. Retention & Deletion
| Data Type | Retention | Deletion |
|---|---|---|
| Prompts (original/reframed) | Only during generation | Immediately after |
| Audio files & metadata | Until account deletion | Immediately after |
| Access tokens | 30 minutes | Auto-expire |
| Refresh tokens | 7 days | Auto-expire |
| Audit logs | 1 year | Script-based cleanup |
| Consent records | 7 years | Legal obligation |
| Email verification token | 24 hours | Auto-expire |
7. Your Rights (International)
Under GDPR (EU/EEA)
- Access, rectification, deletion, restriction, portability, objection
Under CCPA/CPRA (California)
- Right to know
- Right to delete (45 days)
- Right to correct
- Right to opt-out of sale/share (we do not sell/share)
- Right to non-discrimination
Under PIPEDA (Canada)
- Right of access
- Right of correction
- Withdrawal of consent
- Right to challenge compliance
UK & Switzerland
- Equivalent rights apply
📧 To exercise rights: contact [email protected] (responses within 30 days).
8. Security Measures
- TLS encryption (HTTPS)
- bcrypt password hashing with salt
- Least-privilege access control, logging
- Rate-limiting & CORS protection
- No server-side sessions (only browser session storage)
- Regular backups and recovery processes
9. International Compliance
Somlora is compliant with:
- GDPR (EU)
- UK GDPR
- Swiss FADP
- CCPA/CPRA (California, USA) – No Sale/Share
- PIPEDA (Canada)
10. Contact & Supervisory Authorities
Controller:
AMoCha GmbH
Kolschitzkygasse 23
1040 Vienna, Austria
Email: [email protected]
Supervisory authorities (excerpt):
- Austria: Datenschutzbehörde – https://www.dsb.gv.at
- Germany: State Data Protection Authorities –
https://www.datenschutzkonferenz-online.de
- Switzerland: FDPIC – https://www.edoeb.admin.ch
- UK: ICO – https://ico.org.uk
- California: Office of the Attorney General –
https://oag.ca.gov/privacy/ccpa
- Canada: Office of the Privacy Commissioner –
https://www.priv.gc.ca
11. Automated Decision-Making & Profiling
- Use of AI: We use AI only for
prompt sanitization & reframing, followed by text-to-speech audio
generation.
- No automated decisions with legal or significant
effects.
- No profiling: We do not create personality
profiles.
- Personalization is limited to user input and chosen voice presets (no biometric analysis).
12. Updates to This Policy
We may update this Privacy Policy from time to time. The version available at the time of your use is binding. We will inform you of material changes appropriately.
Quick Summary
- ✅ No prompt storage, no health data, no tracking cookies
- ✅ Hosted in the EU (Hetzner)
- ✅ SCCs/DPF for US transfers
- ✅ CCPA & PIPEDA rights covered
- 📧 Contact: [email protected]