醒喇喂

Privacy Policy

Last updated: 6 September 2026

This policy explains how 醒喇喂 WakeUpLa (the “app”) handles your data. It is written in plain language, because you should actually be able to read it.

The short version

No ads, no ad networks, no sale of your personal data. We do collect first-party usage analytics and record session replays of the app's own screens, to find where the app is failing people — what is recorded, what is masked and how to opt out are all set out below. Most other data stays on your phone; mission photos are verified and then discarded; health data never leaves your device. This website likewise sets no cookies and loads no trackers.

Who we are

Kwok Hei Iden Tang is the developer of 醒喇喂 WakeUpLa. Contact for all privacy matters: wakeupla.support@proton.me.

Data we collect and why

Account data (optional) — if you sign in with Apple or Google, we receive a user identifier and display name (and an email address where the provider shares it), stored with our backend provider (Supabase) solely to operate your account. Signing in is voluntary; the app works without an account.

Feedback (optional) — if you submit feedback or a bug report in-app (Settings → Feedback), we receive the text you typed, the reply email address you optionally provide (prefilled with your account email when signed in, and editable), and triage context (app version, iOS version, device model, subscription status, roast-tone setting). This is stored with Supabase, used only to read and answer your feedback, and never shown to other users. To limit abuse we count daily submissions per signed-in user id or per one-way hash of the IP address; raw IP addresses are not stored.

Mission photos — when you complete a photo mission, the photo is sent over an encrypted connection to our server function, which passes it to Google's Gemini API for a one-time yes/no verification. The photo is processed transiently: it is not stored by us and is not saved to your photo library. Google processes it as a service provider under its API terms.

Microphone & speech (read-aloud mission) — audio is captured only while you physically hold the mic button, and is processed by Apple's speech-recognition service in the language you chose in the app, which may process audio on Apple servers under Apple's terms. The app itself stores no recordings.

Camera for rep counting (push-ups / squats) — counting runs entirely on-device using Apple's Vision framework; camera frames never leave your phone and are never stored.

Motion data — shake detection uses the accelerometer on-device only; nothing is transmitted.

Health data (optional) — with your explicit permission, the app READS sleep analysis from Apple Health to show your real average sleep in your stats. This data is never transmitted off your device, never shared, and never used for advertising or data mining.

Alarms, wake records, streaks and onboarding answers — stored locally on your device only.

Usage analytics — the app uses PostHog for first-party product analytics, for one purpose: to find where the app is failing people. What we record is behaviour and outcomes: which onboarding step you reached; whether each system permission dialog (camera, microphone, speech recognition, notifications, alarms, health) was granted; the paywall being shown, which plan was selected, the purchase outcome, skips and restores; alarms created, edited, deleted, enabled or disabled, and whether iOS accepted the schedule; the alarm ringing; leaving a ring without finishing the mission; a mission starting, finishing (with how many seconds it took), or being swapped for maths; the result of the wake-up check; and whether a photo mission's AI verification matched, was rejected, errored, or had no image. Every event also carries the app version and build number, your device locale, and whether 粗口模式 (spicy mode) is on.

Event data never contains photo image data, the text the AI writes about a photo, alarm labels, display names, email addresses, barcode payloads, the name you sign on the commitment screen, or free-text onboarding answers. Properties are enum-like strings, integers and booleans only.

These events are joined together under your RevenueCat app user ID — an anonymous $RCAnonymousID value, the same identifier RevenueCat itself uses; the app never sends your email address to PostHog. Person-level properties are your Supabase account UUID (only if you are signed in), subscription state and plan, locale, and tone setting. PostHog also records the IP address an event was sent from and derives an approximate country or region from it.

This is first-party data, used only to improve the app. It is not used for advertising and is not combined with data from other companies.

Session replay — the app uses PostHog session replay, which records screenshots of the app's own screens and stitches them into a replayable session, so we can see where people actually get stuck. Only this app's screens are recorded; other apps, your home screen and your notifications are never captured.

The following are masked in every recording and are not captured: all camera viewfinders (photo mission, push-ups and squats, QR scanning, barcode setup), the captured mission photo, the display name on the account screen, the RevenueCat customer centre, the alarm-label field, the barcode value and label fields, the commitment signature, and the feedback form (your message text, the reply email address you enter there, and the history of messages you have sent). Network telemetry capture is also switched off, so recordings contain no request or response bodies, and automatic screen-view capture is off.

What we do NOT do

  • No advertising and no ad networks
  • No sale of personal data
  • No tracking in Apple's sense — we never link your data with data from other companies for advertising, which is why the app's privacy manifest declares tracking as false
  • No advertising profiles, and no automated decisions made about you

Third-party processors

ProcessorPurpose
SupabaseAccount authentication, the photo-verification server function, and feedback storage
GoogleGemini API — one-time verification of mission photos
AppleSign in with Apple, speech recognition, App Store purchases
RevenueCatSubscription and purchase state — receives an app user ID so we can tell which plan you own
PostHogProduct analytics and session replay — servers in the United States

RevenueCat also passes subscription lifecycle events (trial started, trial converted, cancellation, renewal, subscription cancelled, expiration and initial purchase) to PostHog, where they land on the same person.

These processors are bound by contract or their terms of service to protect your data to at least the standard of this policy.

Hong Kong — Personal Data (Privacy) Ordinance (Cap. 486)

Purposes of collection: as described above — operating your account, providing features such as photo verification, answering your feedback, and analysing how the app is used in order to improve it. Classes of transferees: the processors listed above, namely Supabase, Google, Apple, RevenueCat and PostHog (product analytics and session replay).

Providing personal data is voluntary; however, some features (the photo mission, accounts) will not work without it.

You have the right to request access to and correction of your personal data under the Personal Data (Privacy) Ordinance (Cap. 486). Direct requests to wakeupla.support@proton.me.

Your data may be processed on servers located outside Hong Kong.

EU / UK users (GDPR)

Legal bases: performance of a contract for core features; your consent for optional permissions (such as health data and the microphone); and legitimate interests for usage analytics and session replay — our legitimate interest in understanding and improving the app. Because that is not based on your consent but is opt-out, you may object at any time by turning it off in the app: Settings → Preferences → 分享使用數據 (share usage data).

You have the rights of access, rectification, erasure, portability and objection. To exercise them, email wakeupla.support@proton.me.

Retention & deletion

Account data is kept until you delete your account (in-app: Settings → account → delete, which permanently removes your authentication record, your profile, and any feedback submitted under your account or account email). Feedback submitted as a guest is kept so we can reply; email wakeupla.support@proton.me to have it deleted. Local data is deleted when you delete the app. Photos and audio are never retained.

Usage analytics and session replay — PostHog retains analytics events for up to 84 months (7 years); session recordings are deleted automatically after 30 days.

You can turn analytics off at any time in the app: Settings → Preferences → 分享使用數據 (share usage data). The app then stops sending events and stops recording the screen immediately. This setting applies going forward only — it does not delete data that has already been collected. To request deletion of data already collected, email wakeupla.support@proton.me.

Children

The app is not directed at children under 13 and we do not knowingly collect their data.

Security

All transmissions are encrypted in transit. Our design principle is minimal collection — the less we collect, the less can go wrong.

Changes to this policy

If this policy changes, we will update this page and the “last updated” date above.

Contact

For any privacy enquiry: wakeupla.support@proton.me