A|T

Privacy Policy

Last updated: May 28, 2026

1. Overview

AltSleep / A|T Sleepnum ("A|T", "A|T Sleep", "we", "us") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights regarding that data.

2. Data We Collect

Account Data

DataPurposeRetention
Email addressAccount login, notificationsUntil account deletion
NameDisplay, reportsUntil account deletion
Date of birthAge-adjusted wellness insightsUntil account deletion
Height, weight, sexPersonalized sleep analysisUntil account deletion
Optional health context, medications, and symptomsPersonalized wellness reports and baseline interpretationUntil account deletion or user correction/deletion request

Health Data

DataSourceFrequency
Heart rateWearable ringEvery 5 minutes (overnight)
Blood oxygen (SpO2)Wearable ringEvery 5-6 minutes
Motion/accelerometerWearable ringDuring connected sessions
Sleep duration & qualityComputed from aboveDaily
Symptom self-reportsUser-submittedUntil account deletion

Device Data

DataPurpose
Hub MAC addressDevice identification
Ring MAC addressDevice pairing
Firmware versionOTA updates
WiFi SSID and WiFi password entered during setupConnecting SleepStax to your home network and reusing saved credentials for future hub setup. WiFi credentials are not sold or used for advertising.

Location Data

DataPurposeRetention
Approximate or precise device location permission state, nearby-device scan context, WiFi/network discovery signals, and GPS-derived workout distance or speed when activity features are enabled Finding and setting up nearby A|T hardware, selecting the correct WiFi network during SleepStax setup, keeping supported devices connected when the app is allowed to run in the background, and estimating optional activity or workout distance when you enable those features Setup/discovery location signals are used during the setup or connection session and are not stored as a continuous location history. Activity records may retain derived distance, speed, duration, and point count; raw GPS coordinates are not uploaded in normal activity summaries.

Android may require location permissions, including background location on supported versions, for nearby-device discovery, WiFi setup, and connected-device monitoring even when A|T Sleep is not trying to determine where you are. You can change these permissions in Android settings. We do not sell location data, do not use it for advertising, and do not use it for credit, insurance, employment, or eligibility decisions.

Android Permissions and APIs We May Request

A|T Sleep shows an in-app prominent disclosure and requires affirmative consent before Android runtime permission requests for personal or sensitive data. The app may request or use the following Android permissions and APIs to provide the service:

Permission or APIData accessed, collected, transmitted, synced, or storedWhy A|T Sleep uses it
Approximate location, precise location, and background locationLocation permission state, nearby-device scan context, WiFi/network discovery signals, and optional GPS-derived workout distance/speedFind and set up nearby SleepStax and AltSleep devices, discover/select WiFi networks during setup, keep connected-device monitoring working when the app is closed or not in use, and support optional workout/activity distance.
Bluetooth, Bluetooth scan, Bluetooth connect, Bluetooth advertise, and nearby devicesNearby device identifiers, advertised names, connection state, battery, raw wearable packets, heart rate, SpO2, sleep, and device telemetryPair with supported SleepStax hubs and AltSleep wearable sources, collect live overnight ring telemetry, and sync device history to your account.
Nearby WiFi devices, WiFi state, change WiFi state, change network state, internet, and network stateWiFi SSID, nearby WiFi scan results, setup network state, internet connectivity state, and hub setup credentials that you enterConnect SleepStax to your home network, communicate with the backend, send bed commands, upload telemetry, fetch reports, and recover/reconfigure devices.
Activity recognition, step sensors, and optional GPS for workoutsSteps, walking/jogging/running classification, activity duration, derived distance/speed, and workout summariesProvide activity context for sleep intelligence, correlate daytime activity with sleep quality, and build personal baselines.
Notifications and Firebase Cloud Messaging tokenPush token, notification delivery status, and alert/report notification contentSend report-ready messages, reminders, device status notices, and wellness threshold alerts.
Foreground service for connected devicesPersistent connected-device monitoring status and ongoing wearable/hub collection activityKeep overnight ring monitoring and device sync active when the app is not in the foreground.
Wake lock and ignore battery optimizationsDevice power-management state needed to keep monitoring alivePrevent Android from stopping overnight connected-device monitoring and keep the monitoring screen awake when the phone is plugged in.
Secure local storageAuthentication tokens, encrypted local health readings waiting to sync, phone cryptographic keys, and trusted hub keysKeep you signed in, protect device communication, update local telemetry immediately, and retry uploads safely.

A|T Sleep does not request or use camera, microphone, contacts, phone, SMS, call log, calendar, photos, videos, general file storage, or Android body sensor permissions.

Usage & Attribution Data

  • UTM parameters and referral source (how you found us)
  • App usage patterns (anonymized)
  • IP address (for security only, not tracking)

3. How We Use Your Data

  • Sleep analysis: Computing your nightly sleep quality, HR variability, and trends
  • Wellness alerts: Notifying you when wearable readings cross thresholds you configure
  • Trend detection: Identifying when your wellness readings deviate from your personal baseline
  • Bed automation: Controlling smart inflation based on your schedule
  • Nearby device setup: Using Android location-related permissions to discover supported devices and WiFi networks during setup and connected-device operation
  • Optional activity context: Using location permission to estimate movement, distance, and workout context when activity features are enabled
  • Product improvement: Anonymized aggregates to improve our algorithms

4. Data Sharing

We do not sell your personal health data. We do not use health data for advertising, credit, insurance, employment, or eligibility decisions. We share data only in these limited circumstances:

  • Payment processing: Stripe receives your payment details (we never see your full card number)
  • Push notifications: Firebase Cloud Messaging delivers alerts (message content only, not health data)
  • Legal compliance: If required by law, subpoena, or to protect safety

Location data is not sold, rented, shared for advertising, or shared with data brokers. It is used only for the app features described in this policy or when disclosure is legally required.

Future: Research Opt-In Program

In future releases, we may offer an opt-in research data sharing program where anonymized or identified health data may be shared with academic or pharmaceutical partners. This will:

  • Always require your explicit, informed consent
  • Be clearly explained before opt-in
  • Include compensation details
  • Allow you to opt out at any time (data shared before opt-out may be retained per the data sharing agreement)

External Hardware and Compatibility

A|T wearable telemetry features require compatible external hardware, such as supported AltSleep rings or approved third-party wearable integrations. A|T does not use the phone camera or phone body sensors to measure SpO2 or heart rate.

SleepStax setup and supported wearable setup may require Android location and nearby-device permissions. If those permissions are denied, setup, connection, background monitoring, or activity features may not work correctly.

5. Data Security

  • All data transmitted between your devices and our servers is encrypted via TLS
  • Hub authentication uses Ed25519 cryptographic signatures
  • Passwords are hashed with bcrypt (never stored in plaintext)
  • Database access is restricted and audited

6. Your Rights

For All Users

  • Access: You can view all data we hold about you via the app or by contacting us
  • Correction: You can update your profile and health context at any time
  • Deletion: You can request complete account and data deletion with the form below
  • Export: You can request a copy of your data in machine-readable format

Request Account and Data Deletion

Use this form to request deletion of your A|T account and associated personal data. We may need to verify account ownership before completing the request.

California Residents (CCPA)

Under the California Consumer Privacy Act, you have additional rights:

  • Right to know what personal information we collect and how it's used
  • Right to delete your personal information
  • Right to opt out of the sale of personal information (we don't sell data)
  • Right to non-discrimination for exercising your privacy rights

EU Residents (GDPR)

If you are in the European Union, you additionally have:

  • Right to data portability
  • Right to restrict processing
  • Right to object to processing
  • Right to lodge a complaint with a supervisory authority

7. Data Retention

  • Active accounts: All data retained while your account is active
  • Cancelled subscriptions: Data retained for 90 days, then anonymized aggregates only
  • Deleted accounts: All personal data deleted within 30 days; anonymized aggregates may be retained
  • Research data: Data shared under research agreements prior to opt-out may be retained per those agreements

8. Children's Privacy

A|T is not intended for use by anyone under 18 years of age. We do not knowingly collect data from minors.

9. Changes to This Policy

We will notify you of material changes via email or in-app notification at least 30 days before they take effect.

10. Contact Us

For privacy-related requests or questions:

  • Email: [email protected]
  • Subject line: "Privacy Request — [Your Request]"