For me buds Privacy Policy
Effective Date: ____, 2026
Sleepwave Inc. (the "Company," "we," "us," or "our") complies with applicable privacy laws, including the Personal Information Protection Act of the Republic of Korea. This Privacy Policy (this "Policy") explains how data is handled in connection with the For me buds mobile application (the "App") and related services (the "Service").
Summary: How For me buds Handles Your Data
- No account, no login. We do not ask for or collect information that identifies you, such as your name, email address, or phone number.
- Sleep and biometric data stay on your device. Data measured by the PPG sensor and accelerometer — such as sleep stages, heart rate, and movement — is processed and stored only on your smartphone and earbuds. It is never transmitted to our servers, and we cannot access it.
- We process only the minimum technical data needed to operate the Service. Limited technical data described in Section 2 is processed for crash reporting, sound content delivery, and firmware updates. This data does not include your sleep data or information that directly identifies you.
1. Information We Do Not Collect
We do not collect:
- Identity information such as name, email address, phone number, or date of birth (except when you voluntarily email us for support — see Section 2.4);
- Account information (no accounts exist);
- Sleep data: sleep stages, sleep duration, tossing and turning, sleep posture, etc.;
- Biometric data: heart rate and other signals from the PPG sensor, movement data from the accelerometer;
- Location information (we do not collect GPS or other precise location data); or
- Personal content on your smartphone, such as contacts, photos, or microphone recordings.
Sleep and biometric data are processed and stored only on your device to provide the App's features and are never transmitted externally, including to the Company.
2. Data We Process, and Why
We process the following minimal data to operate the Service.
2.1 Crash Report Data
- Data: device model, operating system type and version, App version, and logs (e.g., stack traces) captured at the moment of a crash
- Purpose: diagnosing and fixing App errors, improving App stability
- Method: collected automatically via Google Firebase Crashlytics
- Notes: this data is not linked to your name or contact details and does not include sleep or biometric data. You can turn off crash reporting in the App's Settings menu. (The Company does not currently use a separate usage analytics tool.)
2.2 Sound Content Delivery Data
- Data: technical data incidental to network communication, such as IP address, request timestamp, and requested content
- Purpose: streaming and downloading sleep sounds and other content
- Notes: processed transiently as part of the communication and not used to build user profiles.
2.3 Firmware Update Data
- Data: Device model, current firmware version, IP address
- Purpose: checking for and delivering earbud firmware updates
2.4 Customer Support Data
- Data: the email address and inquiry details you provide when you contact us by email or other means
- Purpose: responding to your inquiry and informing you of the outcome
- Notes: this occurs only when you voluntarily contact us.
We do not process data for purposes other than those above. If the purposes change, we will take the measures required by applicable law.
3. Retention Periods
- Crash report data: retained for up to [26] months from collection, then deleted or kept only as anonymized statistics
- Communication records related to content delivery and firmware updates: retained for the period required by applicable law (e.g., 3 months under the Protection of Communications Secrets Act of Korea), then deleted
- Customer support data: retained for [3] years after the inquiry is resolved, in accordance with applicable laws on consumer complaint and dispute records, then deleted
Sleep and biometric data stored on your device are not held by the Company, so no Company retention period applies. You can delete them at any time by using the in-app data deletion feature or by deleting the App.
4. Disclosure to Third Parties
We do not provide the data we process to third parties, except:
- Where required by law, such as lawful requests from investigative authorities; or
- Where urgently necessary to protect the life or safety of a user or a third party.
5. Processors and International Transfers
We entrust the following processing to service providers, which may involve transfers outside your country:
| Processor | Entrusted Work | Data | Country |
|---|---|---|---|
| Google LLC (Firebase Crashlytics) | Crash reporting | Data listed in Section 2.1 | United States |
| [Cloud/CDN provider] | Sound content delivery, firmware distribution | Data listed in Sections 2.2 and 2.3 | [United States, etc.] |
Our agreements with processors require them to safeguard the data as required by applicable law. If our processors change, we will update this Policy.
6. Your Rights and How to Exercise Them
- You can control your data at any time:
- Delete sleep and biometric data: use the in-app data deletion feature or delete the App.
- Opt out of crash reporting: use the toggle in the App's Settings menu.
- You may request access to, correction or deletion of, or suspension of processing of your personal data. However, because the data we process (Section 2) does not identify specific individuals, we may be unable to isolate data relating to you; where applicable law permits, we may decline such requests and will explain the reason.
- You may exercise your rights in writing or by email using the contact details in Section 10, and we will act without undue delay.
7. Children's Privacy
The Service is intended for individuals aged 16 or older. We do not knowingly collect personal data from children under 14 (or the applicable minimum age in your jurisdiction). If we learn that a child's data has been collected, we will delete it promptly.
8. Security Measures
We take the following measures to protect the data we process:
- Encryption in transit (TLS);
- Minimization of access rights and access controls;
- Use of anonymized or pseudonymized statistics; and
- Supervision of our processors.
Protection of sleep data stored on your device depends on your smartphone's security settings (e.g., screen lock). We recommend enabling them.
9. App Permissions
The App uses the following permissions. Each permission is requested via an operating system prompt when you first use the relevant feature. Declining an optional permission only limits that feature.
- Bluetooth (required): connecting to the earbuds and receiving measurement data
- Notifications (optional): sleep-related notifications
- [Add if applicable: e.g., Body Sensors, battery optimization exemption]
10. Privacy Officer and Contact
- Privacy Officer: [Name / Title]
- Address: Sleepwave Inc., 14, Magokjungang 8-ro, Gangseo-gu, Seoul 07801, Republic of Korea
- Phone: +82-2-1551-4024
- Email: contact@dbbeats.com
Users in Korea may also contact the Personal Information Dispute Mediation Committee (1833-6972) or the Privacy Call Center (118).
11. Notice to International Users
If you are located in the European Economic Area, the United Kingdom, the United States, or elsewhere outside Korea, you may have additional rights under local law (such as access, deletion, and objection to processing). The data we process is minimal technical data that does not identify specific individuals, and crash reporting can be turned off in the App's Settings. To exercise your rights, contact us using the details in Section 10.
For EEA/UK users: where we process the data described in Section 2, we rely on our legitimate interests in operating, securing, and improving the Service (Art. 6(1)(f) GDPR).
12. Changes to This Policy
If this Policy changes, we will provide notice through the App at least 7 days before the effective date (30 days for material changes) and update the Effective Date at the top of this Policy.
Addendum
This Policy takes effect on ____, 2026.