Somlora Privacy Policy (EN)

Somlora Sleep AI – Privacy Policy

Effective: August 2025


1. Introduction & Controller

This Privacy Policy explains how AMoCha GmbH (“we”, “Somlora”) processes your personal data when you use our AI-powered audio meditation service Somlora Sleep AI.

We follow a Privacy by Design approach:
- No storage of sensitive health data
- No permanent storage of prompt texts
- Cookie-less service (no tracking cookies)
- Only minimal data necessary for providing the service

Our practices are primarily based on the EU GDPR and also comply with the Austrian DSG, UK GDPR, Swiss FADP, the California Consumer Privacy Act (CCPA/CPRA), and the Canadian PIPEDA.


2. Data We Process

2.1 Account Data

2.2 Audio Data

2.3 Prompt Processing (Privacy by Design)

2.4 Contract & Payment Data

2.5 Technical & Audit Data


Purpose GDPR Legal Basis CCPA Equivalent PIPEDA Equivalent
Account creation & management Art. 6(1)(b) Business Purpose Contract fulfillment
Prompt sanitization/reframing & TTS audio generation Art. 6(1)(b) Business Purpose Contract fulfillment
Payment processing (Stripe) Art. 6(1)(b) Business Purpose Contract fulfillment
IT security & fraud prevention Art. 6(1)(f) Legitimate Interest Legitimate interest
Email verification Art. 6(1)(a) Consent Consent
(Optional/future) Marketing/Newsletter Art. 6(1)(a) Consent / No Sale Consent
Safety monitoring & abuse detection Art. 6(1)(f) Security & Fraud Prevention Legitimate Interests

4. Privacy by Design – Our USP

Note: For safety reasons, we may store anonymized metadata (e.g. classification label, timestamp, pseudonymized user ID) when harmful or abusive input is detected (e.g. self-harm, violence). Prompt text is never stored. This processing is based on Art. 6(1)(f) GDPR (legitimate interest).


5. Third-Party Providers & Data Transfers

OpenAI (USA)

ElevenLabs (UK/EU)

Stripe (Ireland/USA)

Hetzner (Germany, EU)

Google Fonts (USA)

⚠️ Note on US transfers: Despite safeguards (SCCs/DPF), US authorities may access data under certain laws. We mitigate risks via encryption, strict access controls, and data minimization.


6. Retention & Deletion

Data Type Retention Deletion
Prompts (original/reframed) Only during generation Immediately after
Audio files & metadata Until account deletion Immediately after
Access tokens 30 minutes Auto-expire
Refresh tokens 7 days Auto-expire
Audit logs 1 year Script-based cleanup
Consent records 7 years Legal obligation
Email verification token 24 hours Auto-expire

7. Your Rights (International)

Under GDPR (EU/EEA)

Under CCPA/CPRA (California)

Under PIPEDA (Canada)

UK & Switzerland

📧 To exercise rights: contact [email protected] (responses within 30 days).


8. Security Measures


9. International Compliance

Somlora is compliant with:
- GDPR (EU)
- UK GDPR
- Swiss FADP
- CCPA/CPRA (California, USA) – No Sale/Share
- PIPEDA (Canada)


10. Contact & Supervisory Authorities

Controller:
AMoCha GmbH
Kolschitzkygasse 23
1040 Vienna, Austria
Email: [email protected]

Supervisory authorities (excerpt):
- Austria: Datenschutzbehörde – https://www.dsb.gv.at
- Germany: State Data Protection Authorities – https://www.datenschutzkonferenz-online.de
- Switzerland: FDPIC – https://www.edoeb.admin.ch
- UK: ICO – https://ico.org.uk
- California: Office of the Attorney General – https://oag.ca.gov/privacy/ccpa
- Canada: Office of the Privacy Commissioner – https://www.priv.gc.ca


11. Automated Decision-Making & Profiling


12. Updates to This Policy

We may update this Privacy Policy from time to time. The version available at the time of your use is binding. We will inform you of material changes appropriately.


Quick Summary