Privacy Policy
Last updated: 2026-08-14
1. Who we are
Somilo is made by SHUHARY. For anything in this policy, write to support@somilo.app. For the purposes of the EU and UK General Data Protection Regulation, SHUHARY is the data controller.
2. The short version
Somilo’s app makes two kinds of outbound network calls. One is the version check described in Section 7, which unavoidably reveals your IP address and your device’s User-Agent to our server. The other is RevenueCat, described in Section 6, which manages subscriptions and sees an anonymous identifier generated on your device and, if you buy something or restore a purchase, your App Store receipt. There is no account and no analytics SDK inside the app, and we run no server that holds your data. Everything Somilo knows about your nights is stored on your device and stays there. We do not sell or share personal information, and we never have.
The rest of this page explains that in more detail, because “we don’t collect anything” is easy to say and worth being specific about.
3. What is stored on your device
Somilo keeps the following on your iPhone, inside the app’s sandbox:
- the bedtime schedule you set;
- a record of each night — when the shield went up, whether you came back, when the night ended;
- Somi’s growth state, and the gestures and sleeping positions that have opened up;
- the dream gifts Somi has brought back;
- the memory texts written about your nights;
- your app settings and preferences.
None of this is transmitted anywhere. It is not backed up to our servers — we run no server that holds it. If you delete Somilo, or reset or lose your device, this data is gone and we cannot restore it — we never had a copy.
4. Screen Time and the apps you choose
When you choose which apps to shield, iOS does not give Somilo the names of those apps. Apple’s Family Controls framework returns an opaque token — a value that identifies your selection to the operating system but that we cannot read or decode. This is not obfuscation; it is how Apple designed the framework. As a result, SHUHARY never learns which apps you selected, how long you used them, or what you did in them. Somilo asks the system to shield your selection, and the system does the rest.
Somilo requests Screen Time authorization the first time you set up a night. You can revoke it at any time in iOS Settings, under Screen Time.
5. Notifications
Somilo uses local notifications only. These are scheduled on your device by the app itself and delivered by iOS. We do not operate a push notification server, and no notification content is sent to us or through us.
You can turn notifications off at any time in iOS Settings.
6. Purchases
If you purchase a subscription, the transaction is processed by Apple. Your payment details are never sent to SHUHARY and we never see them.
Somilo uses RevenueCat, a subscription management service, to keep track of whether a subscription is active. RevenueCat is contacted from the moment you first open the app, not only if you go on to buy something, because Somilo needs to know your entitlement status before it can show you the right screen. An anonymous app user identifier generated on your device and your App Store receipt are sent to RevenueCat — the identifier from first launch, the receipt when you purchase or restore a purchase. We do not send your name, your email address, your device’s advertising identifier, or any information about your nights.
7. Checking for updates
The update check is one of the two things that leave your device; Section 6 describes the other, RevenueCat. When you open the app, Somilo checks https://config.somilo.app/ios/version.json — a static JSON file — to find out whether a required update exists. This is a plain GET request with no query string, no custom headers, and no request body.
Cookies are disabled for this request, and the app uses an ephemeral URL session for it, which keeps no cookies or cache on your device between launches. No identifier of any kind is sent by the app — no account, no device ID, no advertising ID, no usage data. Nothing about your nights leaves your device for this check.
What reaches the server includes your IP address and your device’s User-Agent string, which any HTTP request carries, along with whatever default headers URLSession attaches on Somilo’s behalf — for example Accept-Language, which reveals your device’s locale. Somilo does not set these headers itself, and it does not strip them either. Somilo caches the response on your device so it can still decide whether an update is required when you are offline.
This endpoint runs on Cloudflare, but on Cloudflare Workers Static Assets — a separate project from the Cloudflare Pages site described in Section 8, kept apart deliberately so that deploying the website can never break the update check.
8. This website
somilo.app is a static website hosted on Cloudflare Pages.
We use Cloudflare Web Analytics to see roughly how many people visit and which pages they read. It does not use cookies, does not fingerprint your browser, and does not build a profile of you across sites. That is why you do not see a cookie consent banner here — there are no cookies to consent to.
As the infrastructure provider, Cloudflare may process technical request data (such as IP addresses) in order to deliver the site and protect it from abuse. This is standard for any website and is governed by Cloudflare’s own privacy terms.
9. Children
Somilo is not directed to children under 13, or under 16 where a higher age applies under local law. We do not knowingly collect personal data from children.
Neither of the outbound channels described in this policy — the update check (Section 7) and RevenueCat (Section 6) — collects anything that identifies who is using the app, child or adult: no name, no email address, no date of birth. The update check leaves the IP address, User-Agent, and default network headers described in Section 7, none of which we retain in an identifiable form. RevenueCat holds an anonymous, device-generated identifier and, on purchase or restore, an App Store receipt, tied to no account and no personal profile. So there is nothing in either place that identifies a specific child for us to delete. But if you believe a child has provided us with information in some other way, please contact us.
10. Legal basis for processing
Under the GDPR, processing personal data requires a legal basis.
For the update check described in Section 7, our legal basis is legitimate interest (Article 6(1)(f)) — specifically, being able to tell you when an update is required. The personal data involved is the IP address, User-Agent, and default network headers that unavoidably accompany that request, described in Section 7.
For RevenueCat, described in Section 6, our legal basis is performance of a contract (Article 6(1)(b)) — administering the subscription you purchase, and the entitlement check that has to happen before you purchase anything, requires knowing which device holds which entitlement.
For the website analytics described in Section 8, our legal basis is legitimate interest (Article 6(1)(f)) — understanding aggregate traffic in a way that does not identify anyone.
11. Your rights
If you are in the EU, the UK, or another region with comparable law, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability.
In practice, we keep no records of our own about the update-check request. That endpoint just serves static files from Cloudflare; there is no application code of ours behind it, and no logging of our own. What reaches it is the IP address, User-Agent, and default network headers described in Section 7, none of which remain with us in a form that identifies you or that we could return to you. There is nothing about that specific request for us to disclose, correct, or delete.
RevenueCat is different: we do hold a per-customer record there — an anonymous app user identifier, your purchase history, and your App Store receipt, described in Section 6. That record is retrievable and deletable. Write to support@somilo.app and identify yourself well enough for us to find your record (for example, the approximate date and device of purchase), and we will retrieve, correct, or delete it in RevenueCat on your request.
If you are a California resident, the CCPA and CPRA give you the right to know what personal information is collected, to have it deleted, and to opt out of its sale or sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising. We never have. The RevenueCat record described above is available to you on request in the same way.
Under Japan’s Act on the Protection of Personal Information, the same applies: alongside the IP address, User-Agent, and default network headers from the update-check request, which we do not record or hold ourselves, the RevenueCat record described above is retrievable, correctable, and deletable on your request.
If you are in the EU or the UK and believe we have handled your data improperly, you have the right to lodge a complaint with your local supervisory authority. We would appreciate it if you wrote to us first.
12. International transfers
The IP address, User-Agent, and default network headers described in Section 7 are processed on Cloudflare’s global network, described in Section 8, which means they may reach a server outside your country.
RevenueCat, described in Section 6, is a United States service. The app user identifier generated on your device, and, if you purchase or restore a subscription, your App Store receipt, are sent to RevenueCat’s servers in the US — an international transfer of personal data.
The website is served from Cloudflare’s global network, which means the page you are reading may be delivered from a server outside your country.
13. Changes to this policy
We may update this policy as the app changes. When we do, we will post the updated version on this page and change the “Last updated” date at the top. If a change is significant, we will also make it visible inside the app.
14. Contact
Somilo is made by SHUHARY.
For anything about privacy, write to support@somilo.app.