Privacy policy
Effective 15 July 2026 · Version 2
Who we are
Sablier is operated by Théophile Louvart (sole proprietor, France) — the data controller under the EU General Data Protection Regulation (GDPR). Contact: [email protected].
What we collect
- Health & fitness data from Google Health, with your explicit consent via Google OAuth: sleep sessions and stages, heart rate, heart-rate variability, respiratory rate, SpO₂, skin-temperature variation, steps, active-zone minutes and VO₂ max.
- Account basics: the display name from your Google Health identity, your timezone, and preferences you set (sleep need, wake window, context tags).
- Profile you provide (optional): sex, birth year, height and weight. We use these only to personalize your sleep-stage reference ranges and sleep-need target. Height and weight may be pre-filled from your device where available; age and sex are only ever what you enter. You can edit or clear them anytime in Settings.
- Billing (Pro only): handled by Polar.sh; we store your subscription status, never your card details.
We collect nothing else — no advertising identifiers, no third-party trackers, no behavioral analytics sold to anyone.
Why we process it, and the legal basis
One purpose: computing your private sleep and recovery analytics (scores, trends, correlations, alarm planning) and showing them to you. Health data is special-category data under GDPR Article 9; we process it only on the basis of your explicit consent (Art. 9(2)(a)), given when you connect Google Health. You can withdraw it at any time by disconnecting or deleting your account.
Google user data — Limited Use
Sablier's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: Google user data is used only to provide the analytics you see, is never sold, never used for advertising, and never transferred to third parties except as necessary to host the service or as required by law. Humans do not read your data.
Storage & security
- OAuth tokens are encrypted at rest (AES-256-GCM).
- All traffic is TLS; session cookies are signed, httpOnly and same-site.
- Data is hosted in the European Union.
- Access is limited to your authenticated session — there is no admin view of your health data.
Retention & deletion
We keep your data for as long as you keep your account, so your long-term history works. Deleting your account (Settings → Delete account & data) immediately and permanently removes every record — nights, sessions, raw provider data, plans, achievements — and revokes our Google access grant. Export is available anytime in JSON/CSV.
Sharing & subprocessors
We never sell or share your health data. Two subprocessors run the service: our EU hosting provider (infrastructure) and Polar.sh (payments, Pro subscribers only). Neither receives your health metrics for any purpose beyond storing what the app itself stores.
Your rights
Under GDPR you can access, export, rectify, delete and port your data — access, export and deletion are built into the app itself, and you can email us for the rest. You may also lodge a complaint with the CNIL (cnil.fr).
Cookies
One cookie: sablier_session, a signed session identifier required to keep you logged in. No advertising or analytics cookies.
Changes
If this policy changes materially, we'll show a notice in the app before the change takes effect and keep prior versions available on request.