legalpolicyplain language
Legal index ->

Privacy Policy

Plain language We want the data policy to read like a promise a real person can understand: no ads, no selling data, no advertising trackers following you around, and clear rules before private material is used for model training.

Last updated:
July 21, 2026
Format:
Plain-language policy

The Short Version

We do not sell your data, we do not share it with advertisers, we do not run ads, and we do not use advertising trackers to follow you across the web.

We collect data to run the products you choose to use, keep accounts and payments working, improve the tools, and protect the service. When product data is useful for improvement, we use privacy-preserving versions wherever practical: aggregated, anonymized, de-identified, or pseudonymized.

What We Collect

Owl + Kestrel may collect account details such as email address, display name, login sessions, communication preferences, billing and entitlement records, support messages, and security logs.

We also use first-party site analytics to count visits, pages viewed, referrers, browser locale, coarse screen size, and a pseudonymous browser identifier. We do not use advertising pixels or cross-site ad tracking.

We use Google Analytics 4 to understand how visitors find and use our WEBSITES (page views, approximate geographic location from IP, referrer, browser and device info, session duration). Google Analytics runs on owlandkestrel.com and the Circadia website at circadia.owlandkestrel.com. It does NOT run in the Circadia iOS/Android app — the app uses only our own first-party, anonymous usage analytics (described above) and sends nothing to Google or any other third party, so the app does no cross-app or cross-site tracking. On the web we do not send Google any of your sleep data, account email, or other personal information — only standard page-view events, with IP anonymization enabled. You can opt out on the web using Google's official browser add-on: https://tools.google.com/dlpage/gaoptout.

Inside the Circadia app we also keep anonymous, aggregate usage analytics on our own servers — which screens (tabs) get used and roughly how long, and which features are tapped. These records carry only a random device identifier, never your account, email, or any sleep data, so they can show us overall patterns but can never reveal what any individual person did. They help us decide what to improve. Honours your browser's Do-Not-Track setting.

Individual products may collect their own product data. Circadia may store sleep logs, sleep windows, wake periods, forecasts, imports, exports, and related notes. Sieve may store lists, items, votes, ratings, rankings, comparisons, preferences, and interaction events. AI products may store prompts, replies, chat transcripts, generated outputs, feedback, and debugging context.

Why We Use It

We use data to provide the products, sync or restore user state when a product supports accounts, send updates you asked for, handle payments and access, respond to support requests, debug problems, prevent abuse, and understand whether the tools are useful.

When you voluntarily share data with us for research, testing, feedback, alpha programs, or product improvement, we may use that data for research and development, including analysis, evaluation, benchmarking, and publication of aggregated or de-identified findings where appropriate.

We may use de-identified, aggregated, or pseudonymized product data to improve rankings, recommendations, forecasts, product quality, evaluations, and model behavior. We do not treat anonymization as magic; sensitive datasets still get extra care.

AI Training and Fine-Tuning

Some Owl + Kestrel products may involve AI conversations or generated content. We may use transcripts and feedback to provide the service, debug issues, evaluate quality, and improve product behavior inside that service.

Model training or fine-tuning with private chats only happens when a product clearly says so and either you have opted in or the data has been de-identified under that product's rules. Product-specific notices or settings take priority when they offer stricter controls.

Circadia has no chatbot or generated-AI features. It uses traditional machine learning (statistical modelling, not generative AI) to improve its adaptive predictions model, trained only on opted-in, anonymized sleep data, and never on the data of people who haven't chosen to share. See the Circadia section below for the details.

Your Control and Rights

You can unsubscribe from emails at any time. Where account tools are available, you can request access, correction, export, deletion, or anonymization of personal data tied to your identity.

Some product data may be retained, deleted, anonymized, or pseudonymized according to product-specific rules. Aggregate, de-identified, pseudonymized, backup, security, accounting, or legally required records may remain after deletion when that is necessary and allowed. When that happens, we remove direct identity links where we can.

Product-Specific Terms

Some products handle more sensitive or more specialized data than the main site. Circadia sleep data, Sieve preference graphs, paid products, and AI transcript features may each have additional product-specific notices or controls.

If a product-specific policy gives you stronger protections or more specific rules, that policy controls for that product. Otherwise, this policy applies.

Circadia: Sleep Data and Research Sharing

Circadia is a sleep-tracking app for Non-24-Hour Sleep-Wake Disorder (N24) and related circadian conditions. Your sleep log lives on your device by default. It syncs to our database only when you sign in, and even then only your account email is linked to it. We do not sell sleep data, share it with advertisers, or expose it to other Circadia users.

Circadia has no chatbot or generated-AI features, and we never sell your data. Its forecasts use traditional machine learning, which is statistical modelling of your circadian rhythm, not the generative AI that the word 'AI' usually brings to mind. To make Circadia's adaptive predictions model more accurate for everyone, we fit it on real sleep data, but only data from people who have opted into sharing, and only in anonymized form. If you have not opted into sharing, your data never feeds the adaptive model; it only ever powers your own predictions. You can opt out at any time, which stops any future use of your data for this.

Inside Circadia you can choose between two share tiers, both opt-in: 'simple' (anonymized log shared only with the Circadia developer for algorithm tuning) and 'research-level' (anonymized log + pre-consent to future academic research collaborations). Both tiers link your sleep entries — timestamps, durations, quality ratings, and optional flags like stress or light exposure — into a research view under an anonymous identifier. Your email, name, IP, and account ID are not included. Revoking sharing at any time deletes the anonymous-share linkage immediately. Your own sleep log remains in your account.

From May 26 2026 onward, each new sleep entry and sleepless-gap record also carries your browser's IANA timezone (for example 'America/Guayaquil' or 'Europe/Berlin'). We capture this so that timestamp math stays correct if you move or travel — it lets us tell 11pm-in-Ecuador apart from 11pm-in-Berlin within the same dataset. The timezone is included in research-tier and simple-tier shared exports because it's needed to interpret the timestamps correctly; it is not used for advertising, location targeting, or any purpose other than making your sleep data analyzable. If you would prefer your timezone not be stored, email dayahdover@gmail.com.

Right now no outside researchers have access to Circadia data. N24 is a rare and under-studied disorder — the largest published clinical cohorts contain only a few dozen patients — so we want to keep the option open to share anonymized, aggregated, or de-identified data with academic sleep researchers in the future, where doing so could meaningfully advance understanding or treatment of N24 and adjacent rhythm disorders.

If you opt in to 'research-level' sharing, your anonymized data may be included in future academic research collaborations without further individual notice. You can revoke at any time, which immediately destroys the anonymous-share linkage. 'Simple'-tier users keep their data private to the developer; if researcher sharing ever becomes relevant for that tier, we would only proceed with separate opt-in.

Any researcher access would be limited to anonymized data, governed by a written data-use agreement, restricted to non-commercial scientific use, and never include personally identifying information. We will not auto-enroll anyone in research-level sharing — the choice is always explicit, in-app.

If you have questions about how Circadia data is used or want to request deletion, contact dayahdover@gmail.com. You can also delete your account yourself in the app, under Settings; that deletes your account and its data without needing to email anyone.

Circadia: Cycle Tracking (Optional)

Circadia has an optional cycle-tracking feature. It is off by default. When you turn it on, you can tag a sleep entry with period flow (light, medium, or heavy) and a PMS flag. These are stored as optional tags on the sleep entry itself, in your own log.

Cycle tags are never sold and never sent to third-party analytics. Google Analytics runs only on our websites and never receives health data of any kind, cycle tags included. If you opt into a research share tier, cycle tags travel with your entries under the same rules as the other optional flags described above: anonymized, under an anonymous identifier, revocable at any time. If you never opt in, they never leave your account.

Deleting a sleep entry deletes its cycle tags with it. Deleting your account deletes them all.

Circadia: Children's Data

Some Circadia accounts are used by a parent or guardian to track a child's sleep. In that case the parent or guardian is the account holder and the only person who signs in; the child does not use or log into the app. We collect the child's age range and their sleep data. A guardian may also choose to add medication markers, behavior or sensory tags, and school-schedule details to a managed child profile. We never collect the child's name, birth date, or contact details. Everything on a child profile gets the same protections: research sharing is off by default, only the guardian can sign in, and the guardian can delete it at any time.

Before an account is used to track a minor, the parent or guardian confirms that they are the child's parent, legal guardian, or a caregiver legally authorized to act for them, and that they consent to recording the child's sleep on the child's behalf. Tracking a child's sleep stays private to your account unless you choose to share it.

A child's data is included in research, or in published research, only with the guardian's separate, explicit, opt-in consent, which is off by default and can be withdrawn at any time for future use. As with all Circadia sharing, any data shared for research is anonymized under an anonymous identifier with no name, email, or contact details, and a child's free-text sleep notes are never shared. Before any data is sent to outside researchers we notify users first, so a guardian always has the chance to remove a child's data beforehand.

For children under 13 in the United States, we follow the Children's Online Privacy Protection Act (COPPA). A guardian can review or delete a child's data at any time in Settings or by contacting dayahdover@gmail.com. We never include children's data in published datasets without the guardian's explicit consent, and we keep a child's data only as long as the account is active or until a guardian asks us to delete it.

Circadia: Shared Sleep Sessions and Second Caregivers

A guardian can invite a second parent or caregiver to help track a managed child profile. When two caregivers share tracking, each logged sleep session stores the session itself and which caregiver logged it, so both can see who recorded what.

Both caregivers see the child profile data the guardian granted access to, and nothing beyond it. The guardian controls what is granted.

Circadia: Share Links (Doctor Report and Continuity Links)

Circadia can generate a tokenized link that shares a read-only report: a doctor report today, and continuity links between caregivers when that feature launches. The URL itself is the credential. Anyone who has the link can view the report, so treat it like a key and give it only to the person it is for.

Every link expires after 90 days, and you can revoke a link at any time in the app, which disables it immediately. Links only ever contain an allowlisted set of fields: sleep timing, sleep totals, handoff time, and a medication marker for continuity links. The doctor report never includes your notes, tags, or diary.

Circadia: Notifications and Web Push

If you opt into push notifications in a web browser, the browser gives us a push subscription endpoint and we store it, keyed to your account, so we can deliver the notifications you asked for. It is deleted when you turn push off or delete your account. The native iOS and Android apps use local notifications only, scheduled on your device; no push endpoint is stored for them.

Circadia: Blocks and Content Reports

If you block another user, we store the pair of accounts involved so the block can be enforced. If you report content, we store a snapshot of the reported content so moderation can review it even if the original is later edited or deleted.

Circadia: Wearable Connections (Apple Health, Fitbit via Google Health, Oura)

You can optionally connect a wearable so your sleep sessions import into your own Circadia log automatically. These connections are entirely opt-in, read-only, and revocable at any time — disconnecting stops all future syncing immediately, and already-imported entries stay in your log under your control like anything you typed by hand (you can edit or delete them at any time).

Fitbit (via the Google Health API): when you connect, Circadia requests one read-only Google permission — your Google Health sleep data — and nothing else. We use it for exactly one purpose: importing your sleep session start and end times into your own private sleep log, where they power the same features as manually logged sleep (your history, your circadian statistics like cycle length and drift, and your sleep-debt readout). We store the minimum needed to do this: an access credential so syncs work without reconnecting, and the imported sleep times themselves.

Circadia's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In plain terms: Google Health data is used only to provide the sleep-tracking features you see, is never sold, is never used for advertising or marketing, is never used to train AI or machine-learning models, and is never read by humans except with your explicit permission for support, for security purposes, or where required by law. It is shared with no one beyond what you yourself choose to share inside Circadia's own sharing features, which are documented above and always under your control.

Apple Health (HealthKit): on iPhone you can grant Circadia permission to sync sleep with Apple Health. This is opt-in and you control it any time in iOS Settings → Health → Circadia. With your permission Circadia reads your sleep samples from Apple Health — for example nights recorded by an Apple Watch or another sleep app — and imports them into your own Circadia log; if you additionally turn on "save my logged sleeps to Apple Health," the sleeps you record in Circadia are written back to Health. Apple Health data is used only to provide these sleep-tracking features. It is never sold, never used for advertising or marketing, and never used to train machine-learning models except through the same anonymized, opt-in research tiers described above — which apply to Health-imported entries exactly as they do to hand-logged ones, so connecting Apple Health opts you into nothing. It is never shared with any third party for their own use. To stop syncing, revoke Circadia's access in iOS Settings → Health; already-imported entries stay in your log under your control.

Oura: connecting works by pasting a personal access token that you create and can revoke in your own Oura account. The same rules apply — read-only sleep times, imported into your own log, used for nothing else.

Wearable-imported entries participate in Circadia's optional research sharing only under the same anonymized, opt-in tiers described above — connecting a wearable does not opt you into anything.

To disconnect: Settings → Connected services → Disconnect, and for Fitbit you can additionally revoke Circadia's access from your Google Account permissions page at any time. To delete imported data, delete the entries in your log or contact dayahdover@gmail.com for full account deletion.

Technical Details

We use service providers for hosting, authentication, payments, email, storage, analytics, security, and AI infrastructure. They may process data for us only as needed to provide those services.

We use reasonable security measures for the size and stage of the project. No internet service can promise perfect security, but we try to collect deliberately, retain thoughtfully, and avoid surprise uses.

Contact

Questions, deletion requests, or privacy concerns can be sent through the contact path listed on Owl + Kestrel. If a better dedicated contact address is published later, use that instead.

Related