← Back

Privacy Policy

Last updated: July 24, 2026

This policy describes how the Circadian app collects, uses and shares your data when you use our mobile services (Android, iOS) and our website. It applies in accordance with the EU General Data Protection Regulation (GDPR) and equivalent legislation.

1. Data controller

The Circadian app is published by its independent developer ("we").
Contact:

2. Data we process

2.1 Account

When you create an account, we process your email address and a unique user identifier. Authentication is handled by Supabase Auth; your password is hashed and never stored or transmitted in plain text.

2.2 Profile and reference rhythm

To compute your adaptation plans, you declare: your home city and its time zone, your chronotype, your usual bedtime and wake time, your sleep duration goal, your default trip objective and your cue preferences (melatonin, caffeine). This data is provided voluntarily and can be changed at any time in the app.

2.3 Trips

The itineraries you enter: airports (IATA codes), departure and arrival times, flight numbers if you provide them, and the trip objective (sleep / alertness / comfort).

2.4 Sleep diary

The nights you log manually: date, bedtime and wake time, perceived quality (optional). This well-being data is provided voluntarily, is used solely to calibrate your plans and your alignment score, and can be deleted entry by entry from the app. Circadian currently connects to no wearable or health platform (Garmin, Apple Health…).

2.5 Generated plans and cues

Adaptation plans (light, sleep, melatonin and caffeine windows) are computed on your device, then stored on our backend together with their follow-up status ("done / not done") so they stay in sync across your sessions.

2.6 Flight number lookup

If you use automatic flight detection, the flight number and date — and nothing else — are sent through our server to the flight data provider AeroDataBox (RapidAPI). The request contains no personal identifier; the response (airports, schedules) is cached server-side with no link to your account.

2.7 Bot protection

Account creation and sign-in are protected by Cloudflare Turnstile, which analyses technical signals of the session (without advertising tracking cookies) to tell humans and bots apart.

2.8 Notifications

Reminders (start of a cue window, recommended bedtime, day before departure) are local notifications, scheduled on your device from your plan. No server push service is used. They can be disabled via the in-app setting or the system permission.

2.9 What Circadian does not collect

Android permissions used: INTERNET, POST_NOTIFICATIONS (local notifications) and RECEIVE_BOOT_COMPLETED (rescheduling reminders after a reboot).

3. Purposes and legal basis

PurposeLegal basis (GDPR)
Account creation and managementPerformance of the contract (art. 6 §1 b)
Computing and syncing adaptation plansPerformance of the contract
Sleep diary and alignment scorePerformance of the contract
Flight number lookupPerformance of the contract
Local notificationsConsent (art. 6 §1 a)
Bot protection, security and fraud preventionLegitimate interest

4. Processors and recipients

We rely on the providers below, bound by data processing agreements:

ProviderRoleRegion
SupabaseDatabase, authenticationEU
CloudflareBot protection (Turnstile)USA / worldwide
AeroDataBox (via RapidAPI)Flight data — receives only flight number + dateUSA / worldwide
Firebase / Google CloudHosting of this website onlyUSA / worldwide

We never sell your data and we do not use it for targeted advertising.

5. Transfers outside the EU

Some processors are located in the United States. Transfers are carried out under the European Commission's Standard Contractual Clauses or the Data Privacy Framework where the provider is certified.

6. Retention

7. Your rights

Under the GDPR, you have the following rights:

To exercise your rights or delete your account:

8. Security

All communications use TLS. Passwords and tokens are never stored in plain text. Backend access is restricted by Row Level Security (RLS) at the database level: each user can only read and modify their own data. Third-party API keys stay server-side and are never embedded in the app.

9. Health disclaimer

Circadian is not a medical device. The generated cues (light, sleep schedules, melatonin, caffeine) are educational well-being information based on the scientific literature of chronobiology, and do not constitute medical advice. Consult a healthcare professional before taking melatonin, or if you have a sleep disorder, are pregnant or are undergoing treatment.

10. Children

Circadian is not intended for children under 13. If you become aware that a minor has provided us with data without parental consent, contact us for deletion.

11. Changes

This policy may evolve. The date at the top of the page indicates the latest update. For any substantial change, a notice will be shown in-app.

12. Contact

For any question about your data: