Privacy Policy
Last updated: July 24, 2026
This policy describes how the Circadian app collects, uses and shares your data when you use our mobile services (Android, iOS) and our website. It applies in accordance with the EU General Data Protection Regulation (GDPR) and equivalent legislation.
1. Data controller
The Circadian app is published by its independent developer ("we").
Contact:
2. Data we process
2.1 Account
When you create an account, we process your email address and a unique user identifier. Authentication is handled by Supabase Auth; your password is hashed and never stored or transmitted in plain text.
2.2 Profile and reference rhythm
To compute your adaptation plans, you declare: your home city and its time zone, your chronotype, your usual bedtime and wake time, your sleep duration goal, your default trip objective and your cue preferences (melatonin, caffeine). This data is provided voluntarily and can be changed at any time in the app.
2.3 Trips
The itineraries you enter: airports (IATA codes), departure and arrival times, flight numbers if you provide them, and the trip objective (sleep / alertness / comfort).
2.4 Sleep diary
The nights you log manually: date, bedtime and wake time, perceived quality (optional). This well-being data is provided voluntarily, is used solely to calibrate your plans and your alignment score, and can be deleted entry by entry from the app. Circadian currently connects to no wearable or health platform (Garmin, Apple Health…).
2.5 Generated plans and cues
Adaptation plans (light, sleep, melatonin and caffeine windows) are computed on your device, then stored on our backend together with their follow-up status ("done / not done") so they stay in sync across your sessions.
2.6 Flight number lookup
If you use automatic flight detection, the flight number and date — and nothing else — are sent through our server to the flight data provider AeroDataBox (RapidAPI). The request contains no personal identifier; the response (airports, schedules) is cached server-side with no link to your account.
2.7 Bot protection
Account creation and sign-in are protected by Cloudflare Turnstile, which analyses technical signals of the session (without advertising tracking cookies) to tell humans and bots apart.
2.8 Notifications
Reminders (start of a cue window, recommended bedtime, day before departure) are local notifications, scheduled on your device from your plan. No server push service is used. They can be disabled via the in-app setting or the system permission.
2.9 What Circadian does not collect
- no location data (neither foreground nor background);
- no access to the camera, your photos or your contacts;
- no analytics, no advertising tracker, no third-party crash reporting.
Android permissions used: INTERNET,
POST_NOTIFICATIONS (local notifications) and
RECEIVE_BOOT_COMPLETED (rescheduling reminders after a reboot).
3. Purposes and legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Account creation and management | Performance of the contract (art. 6 §1 b) |
| Computing and syncing adaptation plans | Performance of the contract |
| Sleep diary and alignment score | Performance of the contract |
| Flight number lookup | Performance of the contract |
| Local notifications | Consent (art. 6 §1 a) |
| Bot protection, security and fraud prevention | Legitimate interest |
4. Processors and recipients
We rely on the providers below, bound by data processing agreements:
| Provider | Role | Region |
|---|---|---|
| Supabase | Database, authentication | EU |
| Cloudflare | Bot protection (Turnstile) | USA / worldwide |
| AeroDataBox (via RapidAPI) | Flight data — receives only flight number + date | USA / worldwide |
| Firebase / Google Cloud | Hosting of this website only | USA / worldwide |
We never sell your data and we do not use it for targeted advertising.
5. Transfers outside the EU
Some processors are located in the United States. Transfers are carried out under the European Commission's Standard Contractual Clauses or the Data Privacy Framework where the provider is certified.
6. Retention
- Account, profile, trips, sleep diary, plans: for as long as your account is active. Deleted upon request (see Data deletion).
- Flight lookup cache: contains no personal data (flight number + date + public schedules only).
- Backend technical logs: 90 days maximum.
7. Your rights
Under the GDPR, you have the following rights:
- right of access, rectification and erasure;
- right to restriction and portability;
- right to object to processing based on legitimate interest;
- right to withdraw your consent at any time (revoking system permissions or turning off in-app settings);
- right to lodge a complaint with your local supervisory authority (in France, the CNIL).
To exercise your rights or delete your account:
8. Security
All communications use TLS. Passwords and tokens are never stored in plain text. Backend access is restricted by Row Level Security (RLS) at the database level: each user can only read and modify their own data. Third-party API keys stay server-side and are never embedded in the app.
9. Health disclaimer
Circadian is not a medical device. The generated cues (light, sleep schedules, melatonin, caffeine) are educational well-being information based on the scientific literature of chronobiology, and do not constitute medical advice. Consult a healthcare professional before taking melatonin, or if you have a sleep disorder, are pregnant or are undergoing treatment.
10. Children
Circadian is not intended for children under 13. If you become aware that a minor has provided us with data without parental consent, contact us for deletion.
11. Changes
This policy may evolve. The date at the top of the page indicates the latest update. For any substantial change, a notice will be shown in-app.
12. Contact
For any question about your data: