Privacy Notice (GDPR)
Snorium — AI Snore Analysis For Users in the European Economic Area and United Kingdom
Effective date: June 02, 2025 Last updated: June 02, 2025
1. Introduction
ICI Tech Teknoloji A.Ş. processes your personal data in compliance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and, where applicable, the UK GDPR.
| Data Controller | ICI Tech Teknoloji A.Ş. |
| Website | /en/ |
| app@icitech.com.tr | |
| Country of establishment | Republic of Turkey |
EU Representative (Article 27 GDPR): As a company established outside the EEA offering services to EEA residents, we are in the process of designating an EU representative per Article 27 GDPR. Updated contact details will be published at /en/privacy once appointed. Contact app@icitech.com.tr in the meantime.
Data Protection Officer: We do not currently meet the threshold for mandatory DPO appointment under Article 37 GDPR. All data protection enquiries: app@icitech.com.tr.
Medical Disclaimer: Snorium is not a medical device, diagnostic tool, or clinical treatment. It is a personal wellness self-tracking companion. Consult a qualified healthcare professional for any sleep disorder or breathing concern.
2. Special Category Data — Health and Sleep Data
Under GDPR Article 9, the following data processed by Snorium may constitute data concerning health:
Sleep audio recordings relate to physiological activity during sleep. Snorium Score, breath stability, and disturbance index relate to respiratory and sleep health. Lifestyle factors (alcohol consumption, sleep position, stress) may reveal health context.
We process all special category data only on the basis of your explicit consent under GDPR Article 9(2)(a). You provide this consent when you grant microphone permission and complete your first recording session. You may withdraw this consent at any time — see Section 6.
3. Audio Data — GDPR Clarification
Sleep audio recordings are processed entirely on your device and are never transmitted to our servers.
| Data Type | On device | On our servers |
|---|---|---|
| Sleep audio files | Yes — stored locally, replayable | Never |
| Snorium Score | Yes | Yes |
| Breath stability, disturbance index | Yes | Yes |
| Trend data | Yes | Yes |
| Factors and remedies | Yes | Yes |
Because we never receive audio files, we cannot process data subject access requests for audio we do not hold. Audio remains entirely under your control on your device.
4. Third Parties in the Recording Environment
If another person (partner, roommate) is in the room while you record, their voice may also be captured. Under GDPR, recording another person without their knowledge may engage their privacy rights under Article 5(1)(a) (lawfulness, fairness, transparency). You are responsible for: informing persons sharing your sleep space before using Snorium; ensuring you have a lawful basis to capture ambient sound that may include their voice; and responding to any privacy objections they raise.
5. Data We Process
Account information: Email address, password (hashed), optional display name and profile photo. An account is required to use Snorium.
Sleep analysis metadata (Special Category): Snorium Score, sleep class, breath stability, disturbance index, confidence score, recording timestamps and duration. Synced to our cloud servers.
Sleep audio recordings (Special Category): Microphone audio captured during sleep. Stored on device only — never uploaded.
Trend and progress data: Weekly and monthly summaries. Synced to cloud servers.
Lifestyle factors and remedies: Manually entered data about sleep habits. Synced to cloud servers.
Subscription data: Subscription status, purchase date, transaction ID.
Device and technical data: Device type, OS version, app version, IP address (truncated), crash logs.
6. Legal Bases for Processing (GDPR)
| Purpose | GDPR Legal Basis |
|---|---|
| Account creation and management | Art. 6(1)(b) — Performance of contract |
| On-device audio recording | Art. 9(2)(a) — Explicit consent (microphone permission) |
| Local storage of audio recordings | Art. 9(2)(a) — Explicit consent |
| Cloud sync of sleep metadata | Art. 6(1)(b) — Performance of contract |
| Trend generation and insights | Art. 6(1)(b) — Performance of contract |
| Subscription management | Art. 6(1)(b) — Performance of contract |
| App quality and crash analysis | Art. 6(1)(f) — Legitimate interests |
| Security monitoring | Art. 6(1)(f) — Legitimate interests |
| Support requests | Art. 6(1)(b) — Performance of contract |
| Legal obligations | Art. 6(1)(c) — Legal obligation |
| Marketing | Art. 6(1)(a) — Consent |
Legitimate interests: Where we rely on Art. 6(1)(f), we have balanced our interests against your rights. You may object — contact app@icitech.com.tr.
7. What We Do Not Do
We do not sell personal data. We do not upload audio recordings — ever. We do not share sleep data, health metrics, or audio with Meta, TikTok, Google Ads, or any advertising network. We do not use advertising identifiers. We do not use your recordings to train AI models. We do not make automated decisions with significant legal effects based on your health data (Art. 22 GDPR).
8. Your Rights Under GDPR
Right of access (Art. 15): Obtain a copy of the personal data we hold about you. Note: we do not hold audio files — those are on your device only.
Right to rectification (Art. 16): Correct inaccurate data in-app or via app@icitech.com.tr.
Right to erasure (Art. 17): Request deletion of your account and server-side metadata.
Right to restriction (Art. 18): Limit cloud sync in Settings → Privacy.
Right to data portability (Art. 20): Receive your metadata in a structured, machine-readable format — contact app@icitech.com.tr.
Right to object (Art. 21): Object to processing based on legitimate interests — contact app@icitech.com.tr.
Right to withdraw consent (Art. 7(3)): Withdraw recording consent by revoking microphone permission in device settings. Withdraw metadata sync consent in Settings → Privacy. Withdraw marketing consent in Settings → Privacy → Marketing Preferences.
Right to lodge a complaint (Art. 77): Contact your national supervisory authority.
Email app@icitech.com.tr — subject "GDPR Data Subject Request — Snorium". We respond within one month, free of charge.
9. Right to Lodge a Complaint
| Country | Authority | Website |
|---|---|---|
| 🇫🇷 France | CNIL | https://www.cnil.fr |
| 🇩🇪 Germany | BfDI + state DPAs | https://www.bfdi.bund.de |
| 🇪🇸 Spain | AEPD | https://www.aepd.es |
| 🇬🇧 United Kingdom | ICO | https://ico.org.uk |
| Other EEA | Your national DPA | https://edpb.europa.eu/about-edpb/about-edpb/members_en |
10. International Data Transfers
ICI Tech Teknoloji A.Ş. is established in Turkey. The European Commission has not issued an adequacy decision for Turkey under GDPR Article 45. For all transfers of metadata from the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, UK IDTAs for UK transfers, and GDPR Article 49 derogations where applicable. Audio data is never transferred internationally — it never leaves your device.
11. Data Retention
Account data is retained for the duration of your account plus 3 years after deletion. Sleep analysis metadata is retained for the duration of your account plus 1 year after deletion; withdrawn consent triggers deletion within 30 days. Audio recordings are stored on your device — we retain nothing. Subscription records are retained for 10 years. Support communications are retained for 3 years. Crash logs are deleted after 12 months.
12. Security
TLS 1.2+ in transit; encryption at rest for all server-stored metadata. Audio files never reach our servers. Breach notification: We notify the competent supervisory authority within 72 hours (Art. 33) and affected users without undue delay for high-risk breaches (Art. 34).
13. Children's Privacy
Snorium is for users 18 and older. Contact app@icitech.com.tr for immediate deletion if a child has submitted data.
14. Cookies
Our website uses cookies with a consent banner on first visit. Strictly necessary cookies serve core functionality. Analytics and marketing cookies require your consent and can be managed via the cookie banner. We do not use cookies to infer health status or sleep data.
15. Changes
Material changes notified 14 days in advance. Current version: /en/privacy/gdpr.
16. Contact Us
Email: app@icitech.com.tr Subject: "GDPR Data Subject Request — Snorium" Website: /en/
We acknowledge enquiries within 5 business days and resolve within one month.