01
Who we are
BeeBaby HK Limited ("we," "us," "our") runs the WakeFail app and the related services. For the data processing described in this Policy, we generally act as the data controller (or play a similar role under your local law).
WakeFail combines early-morning alarm challenges with social features โ a public feed, nearby discovery, direct messages, and an optional video identity verification flow.
How to reach us: BeeBaby HK Limited, email support[AT]beebaby.ai, registered office at Rm 603, 6/F Laws Commercial Plaza, 788 Cheung Sha Wan Road, Hong Kong.
If our footprint changes and we ever need to designate a data protection officer, EU representative, or UK representative, we'll update this Policy and list their contact details here.
02
Information we collect
In short
The data we collect comes from three places: things you tell us, things generated when you use the app on your device, and things returned by third-party platforms (App Store, Google Play, Apple Sign-In, Google Sign-In) when you sign in, pay, and similar.
| Category | Examples | Source | Necessity |
|---|---|---|---|
| Account Information | Phone number, nickname, profile picture, birthday, gender | You provide during registration or profile edit | Partially required |
| Third-Party Sign-In Return | Apple Sign-In: user identifier, email (returned on first consent, supports Hide My Email relay), name (on first consent); Google Sign-In: account email, name, profile picture | When you sign in with Apple / Google | Required for sign-in |
| Profile Information | Hometown, height, education, income range, religious beliefs, smoking/drinking habits, relationship goals, interest tags | You provide voluntarily | Typically optional |
| User Content | Photos, challenge self-recorded videos, text posts, Ice Breakers answers, customer support feedback | You upload or submit | Required when using relevant features |
| Payment & Subscription Information | Subscription status, order receipts, transaction results | Returned by App Store / Google Play after payment processing | Only when transactions occur |
| Identity Verification Information (optional) | Verification video frames, face comparison results, similarity scores, failure reasons | When you actively apply for video identity verification | Only for this optional feature |
A note on sensitive data
Some profile fields (like religious beliefs) and the face data involved in video identity verification can count as sensitive personal information โ or "special category" data โ under certain laws. We don't process any of it unless you choose to share it and, where the law requires, give us a separate consent first.
2.1 Subscription and auto-renewal data
What we receive โ and what we do not
Because WakeFail VIP subscriptions are sold and processed exclusively through the Apple App Store and Google Play, we do not receive or store your payment instrument (e.g., card number, bank account, CVV, or device wallet credentials). Those data are collected and processed by Apple and Google under their own terms and privacy policies.
To provision your membership, reconcile transactions, prevent fraud, and provide billing support, we receive and store the following categories of subscription-related data from Apple and Google and on our own systems:
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Transaction identifiers | App Store transaction ID and original transaction ID; Google Play purchase token and order ID | Returned by App Store / Google Play at purchase and on each renewal | Verify the purchase, grant entitlements, and reconcile billing events |
| Subscription metadata | Product identifier (plan SKU), billing period, start date, current period end date, renewal status, cancellation status, trial status, storefront country code, sandbox / production environment | App Store Server Notifications and Google Play Real-Time Developer Notifications; verification responses | Manage entitlements, display subscription status, and apply price-change or refund events |
| Receipts and verification responses | Signed receipt blobs and the verification response payloads returned by the App Store and Google Play verification endpoints | App Store / Google Play | Validate authenticity of purchases and prevent fraud |
| Internal subscription record | The active / expired / refunded status of the membership tied to your WakeFail account, the next renewal date, the plan currently in effect, and an audit log of subscription events | Generated by us based on the above | Grant or revoke benefits in the app and respond to your billing inquiries |
| Refund and chargeback events | Refund or chargeback notifications from the App Store or Google Play, including the affected transaction identifier and event timestamp | App Store / Google Play | Adjust entitlements and maintain financial records as required by law |
We do not receive your full payment-instrument data, billing address, or device-wallet tokens from Apple or Google as part of these flows. We may receive a storefront country code and an obfuscated account identifier where the platform provides one; these are used solely to operate the subscription and are not used for advertising.
Auto-renewal terms, cancellation procedures, refund handling, and platform-specific disclosures are set forth in the User Agreement — Subscriptions and Auto-Renewal and the Auto-Renewal Service Agreement. Retention periods for subscription and financial records are described in Section 9 (Data Retention & Deletion) below.
03
Device permissions & auto-collected info
In short
Features like nearby discovery, recording, upload, notifications, sign-in security, and troubleshooting need certain device permissions or technical info. You can turn any of these off in your phone's system settings โ the relevant feature will just stop working.
| Data/Permission | Use Case | Default Principle |
|---|---|---|
| Location Permission Foreground ยท One-Time or Approximate | Used for nearby discovery, region-related recommendations, and region sorting | Only used after you enable relevant features and grant permission; the relevant features may be unavailable when disabled |
| Camera / Microphone | Recording self videos for alarm challenges; publishing public feed content; profile picture; optional video identity verification | Triggered by feature; unavailable when disabled |
| Photo Library Access | Uploading photos or videos; saving challenge content locally | Triggered by feature |
| Notification Permission | Local alarm reminders, interaction notifications, account security alerts | Triggered by feature |
| Device & App Information | Device model, OS version, app version, language setting, timezone | Used for compatibility, security, and troubleshooting |
| Logs & Diagnostics | Crash logs, error events, basic runtime diagnostics | Used to fix issues and maintain stability |
| Push Token | Sending reminders, account security alerts, interaction messages | Generated by device push mechanism |
| Usage & Analytics Data | Which screens you open and how long you stay, taps, and key in-app actions (e.g., signing in, setting an alarm, completing a challenge, starting a purchase) and whether they succeeded | Collected through our analytics provider to see how features perform and improve them; tied to an in-app analytics ID, never to advertising identifiers |
About product analytics
We use Mixpanel, a third-party product-analytics service, to understand how people actually use WakeFail so we can fix what's broken and make the app better. It only records in-app usage (such as which screens you open and which features you use); it isn't used for advertising and isn't used to track you across other apps.
These usage events are linked to your account. They're keyed to an in-app analytics ID derived from your account ID, along with a few coarse account attributes (such as your membership tier), so we can make sense of behavior per user and per session. We've disabled Mixpanel's automatic collection of advertising identifiers (such as Apple's IDFA/IDFV or the Android Advertising ID); we never use this data for advertising, and we don't combine it with other companies' apps or websites to track you. That's why WakeFail doesn't ask for App Tracking Transparency permission. These analytics are processed on Mixpanel's servers in the United States.
About on-device face detection in challenge videos
When you record a challenge video, the app uses Google ML Kit Face Detection on your device to check whether a face is in the frame. This runs entirely on your phone, nothing is sent to our servers, and we don't use it to build a face profile or do background face recognition.
About the optional video identity verification
Video identity verification is opt-in. It only runs when you start it yourself and give an explicit, separate consent. If you don't opt in, none of the steps below happen, and it doesn't affect any other core feature of WakeFail.
- The verification video is uploaded to our S3 storage.
- Our backend pulls the frames it needs from the video and calls Amazon Web Services (AWS) Rekognition (deployed in the AWS US region) to run DetectFaces and CompareFaces, comparing the frame against the public photos you've uploaded.
- The call uses inline byte transmission โ the frame isn't written to AWS persistent storage.
- The verification video is retained in our S3 storage for up to 30 days and is then automatically deleted โ we do not keep the raw verification video beyond that window. Only the verification result and the minimal audit records we are required to keep are retained for the life of your account, and are handled afterwards under our internal retention and deletion practices.
Explicit, separate consent: because this feature involves sensitive biometric data, the first time you enter the verification flow the app will ask for an explicit, separate consent. You can decline or exit at any point.
04
How we use information
In short
We only process data when we have a clear business reason and a valid legal basis. For users in the EU/UK, that's usually performance of contract, consent, legitimate interests, or a legal obligation.
| Purpose | Data Involved | Common Legal Basis |
|---|---|---|
| Registration, sign-in, account security maintenance | Phone number, third-party sign-in returns, profile, device and security logs | Core feature; legitimate interest in fraud prevention where necessary |
| Displaying profile, building social connections, providing content interaction | Nickname, profile picture, age range, city, user-published content, profile fields | Core feature; content you proactively make public or submit |
| Nearby discovery and location-related recommendations | Location data, region setting, profile information | Your consent |
| Optional video identity verification | Verification video, necessary video frames, public photos, comparison results | Your explicit consent; legitimate interest in platform security where necessary |
| Processing payments and subscriptions | Transaction receipts, subscription status | Core feature; performance of financial obligations |
| Preventing fraud, abuse, harassment, and illegal activity | Report content, logs, device information, activity records | Legitimate interest; legal obligation |
| Performance optimization, diagnostics, and customer support | Crash logs, diagnostic information, support records | Legitimate interest |
| Understanding how features are used and improving them | Usage and analytics events, coarse account attributes (e.g., membership level) | Legitimate interest in operating and improving the Services; consent where local law requires it |
When we rely on legitimate interests, those interests usually include keeping the platform safe, fighting fraud and harassment, fixing bugs, keeping the service stable, and improving features without disproportionate privacy impact.
When we rely on consent, you can withdraw it through your device permission settings, the relevant in-app screens, or by contacting us. Withdrawing doesn't affect the lawfulness of anything we did before you withdrew, but some features may stop working.
05
Automated recommendations & content moderation
In short
To keep social content relevant and safe, we use automated rules and ranking logic for recommendations, risk detection, and to help our moderation team.
For example, we may pick which users, posts, or ordering to show you based on your profile, age range, city or region, the filters you choose, your interactions in the app, and safety signals.
We also use automated tools to spot content that may break the community guidelines, suspected abuse, or suspicious accounts, and we route a portion of those signals to human reviewers.
Given how the product works today, this automated processing is mainly for recommendations and safety โ it doesn't produce decisions with legal or similarly significant effects on you without any human involvement. If you have questions about a recommendation or a moderation outcome, you can reach us through the channels listed in this Policy.
06
When we share your information
Our core commitment
We don't sell your personal info, and we don't use your data to target you with ads outside WakeFail.
That said, here are the situations where some of your info ends up with others:
- With other users: when you make something public on your profile or in social features, other users can see it โ profile picture, nickname, age range, city, public photos and videos, and any "about me" you've made public.
- With our cloud storage provider: photos, videos, alarm challenge recordings, and identity verification videos are uploaded to our S3 storage for hosting.
- With our face comparison provider (only when you opt in to video identity verification): the necessary video frames and the public photos you've uploaded are sent by inline byte transmission to AWS Rekognition (US region) for DetectFaces / CompareFaces. This sharing is covered by the AWS Data Processing Addendum (DPA) and Standard Contractual Clauses (SCCs).
- With our analytics provider: in-app usage events are processed on our behalf by Mixpanel (United States) under its data processing terms, only to help us understand and improve how WakeFail is used. Mixpanel isn't allowed to use this data for its own purposes or for advertising.
- With the app stores and payment processors: in-app purchases are handled by the App Store / Google Play. We only receive the transaction results and receipts we need to verify subscriptions or handle after-sales support.
- With third-party sign-in providers: when you use Apple Sign-In or Google Sign-In, that provider handles the identity check and returns the account info we need.
- For legal, law enforcement, or safety reasons: when the law, a court order, or a valid government request requires it โ or when we need to protect the rights, safety, and interests of users, the public, us, or third parties โ we may disclose what's needed, as the law allows.
- In a corporate transaction: in a merger, acquisition, reorganization, financing, or asset sale, relevant data may be part of what's transferred. The receiving entity will be bound by privacy and confidentiality obligations at least as protective as this Policy.
07
Cross-border transfers
In short
We're a Hong Kong company and we use international cloud services, so your info may be processed outside your country or region.
If you're in the European Economic Area, the United Kingdom, Switzerland, or another region with cross-border transfer rules, we put contractual, organizational, and technical safeguards in place where required. These can include data processing agreements, appropriate transfer clauses (e.g., SCCs), access controls, and encryption in transit.
If you opt in to video identity verification, that step may involve a provider in the US region (AWS US).
Our product-analytics provider (Mixpanel) also processes usage data on servers in the United States.
08
Data security
In short
We use reasonable administrative, technical, and physical safeguards to protect your info. No system is 100% bulletproof, but here's what we do.
- All data in transit is encrypted with TLS.
- For sensitive or high-risk data, we apply access controls, the principle of least privilege, and audit logging.
- We limit who can access data โ employees, contractors, and service providers only get what they need to do their jobs.
- Where we can, we de-identify or aggregate logs, diagnostics, and internal reporting data.
- We maintain monitoring and audit tooling to catch account abuse and policy violations.
If we learn of an incident that may have affected your personal info, we'll take the steps the law requires โ investigate, remediate, and notify regulators and/or you where applicable.
09
Data retention & deletion
In short
We keep personal info only as long as we need to for the purposes in this Policy. After that, we delete it, anonymize it, or keep it only where the law tells us to.
| Data type | How long we keep it |
|---|---|
| Account info & profile | Kept for the life of the account. Typically deleted within 30 days after we process your deletion request โ unless we need to keep something for legal or security reasons. |
| Content you post | Deleted when you delete it, or removed by the system once the account deletion flow finishes. |
| Video identity verification: video file | Up to 30 days in S3. |
| Video identity verification: result | For the life of the account. |
| Crash logs & basic diagnostics | Up to 180 days (de-identified for analytics), unless we need to keep them longer for an active safety issue or legal dispute. |
| Usage & analytics events | Retained while your account is active and removed or de-identified after the account deletion flow finishes; aggregated, non-identifying statistics may be kept longer. |
| Order receipts & financial records | Kept for as long as financial, accounting, or dispute-resolution rules require. |
You can start account deletion in one of two ways:
- In the app: "Settings โ Delete Account."
- By email: support[AT]beebaby.ai, including the registration details we need to verify it's you.
10
Your rights
In short
Depending on where you live, you may have rights to access, correct, delete, restrict, object, port your data, and withdraw consent.
- Access and info: find out what personal info we hold about you and how we use and share it.
- Correction: ask us to fix info that's wrong or incomplete.
- Deletion: ask us to delete your account or specific personal info. We may need to keep some data for legal, safety, or dispute-resolution reasons.
- Withdraw consent: pull back consent for processing that runs on consent (like location and the optional video identity verification). You can also revoke the relevant permissions in your device settings.
- Object or restrict: where the law allows, object to certain processing based on legitimate interest, or ask us to restrict processing.
- Complain: file a complaint with the data protection or consumer regulator in your region.
If you live in one of the US states with a privacy law, you may have additional rights โ to know, delete, correct, and not be discriminated against for exercising your rights. Given how WakeFail is built today, we don't sell your personal info, and we don't "share" it for cross-context behavioral advertising.
You can reach us at the email at the bottom of this Policy. We'll verify it's you before we act on the request. Unless the law says otherwise, we aim to get back to you within 15 business days and to finish processing within whatever timeframe the law sets.
11
Protecting minors
Important
WakeFail is for adults 18 and over. People under 18 aren't allowed to register or use the service.
If we find out we've collected personal info from a minor without meaning to, we'll take reasonable steps to delete it and shut down the account. If you think an account belongs to a minor, please report it using the contact info at the bottom of this Policy. Our full child-safety policy is in our Child Safety Standards (CSAE).
12
Identifiers, logs & notifications
In short
Because WakeFail is a native mobile app, we don't rely on browser cookies. We do use device- and app-level identifiers to keep you signed in, secure transactions, run diagnostics, and deliver notifications.
- Push token (device token): a push-channel token issued by iOS or Android, used to send reminders, system messages, and interaction notifications to your device.
- Session and security identifiers: keep you signed in, prevent account abuse, and protect transactions and account security.
- Crash and diagnostic identifiers: link error reports to device environments so we can debug.
- Analytics identifier: an in-app identifier derived from your account that lets our analytics tooling group usage events by session and user. It's cleared when you sign out.
- Device model / OS version / app version / language / timezone: used for compatibility, security, and troubleshooting.
Unless this Policy says otherwise, we don't use these identifiers for cross-app or cross-site targeted advertising tracking.
13
Policy updates & how to reach us
If we make material changes to this Policy โ say, adding new purposes, expanding how we use data, or adding new recipients โ we'll let you know through in-app prompts, in-app messages, email, or another reasonable channel. Where the law requires it, we'll ask for your consent again.
For smaller changes, we'll just bump the "Last Updated" date at the top of this page. We suggest checking back from time to time for the latest version.
If you have questions, requests, or concerns about your privacy, email us at support[AT]beebaby.ai โ we read every message.