Siren is operated by WAQYSTUDIOS LTD ("Siren", "we", "us" or "our"). This Privacy Policy explains what personal data we collect when you use the Siren app and website (together, the "Service"), why we collect it, who processes it on our behalf, how long we keep it, and the choices and rights you have. It applies to the Siren app for iPhone and Android (published on the App Store and Google Play as "Siren Mind") and to this website.

At a glance
  • You sign in with an email address and password. Your password is handled by Firebase Authentication and is never stored on our servers.
  • The app keeps what it needs to work: where you are in each session, your favourites, your daily listening totals (for your streak), the affirmation themes you subscribe to and the affirmations you have received.
  • The morning reminder is off by default. Turn it on and we store a notification token for your device so we can send one message a day; turn it off and we delete it.
  • No advertising, no analytics SDKs, no selling of data, and no AI systems process your data.
  • You can edit your name and delete your account from the Profile tab. Deletion completes after a 30-day grace period.

1. Who we are

WAQYSTUDIOS LTD is the data controller for personal data collected through the Service. If you have any questions about this policy or how we handle your data, contact us at privacy@waqystudios.com.

2. Data we collect

When you create an account

  • Email address and a unique account identifier (your Firebase user ID). We use Firebase Authentication (a Google service) for sign-in: it handles your password and password resets, and we only ever receive a signed token confirming who you are. We never see or store your password.

Profile details you choose to give us

  • First name, last name, and the name you would like Siren to call you. All three are optional, can be left blank, and can be edited or cleared at any time from the Profile tab. We use them only to personalise the app.

Your device's time zone

  • The app reads your device's time zone identifier (for example "Europe/London") and stores it against your profile so that your streak and your daily affirmation follow your local day, even when you travel. This is a time zone name, not your location: we do not collect GPS or other location data.

Listening data, created as you use the app

  • Progress in each session: how far through a session you are (so it can resume where you left off), whether you have completed it, and when you last listened.
  • Daily listening totals: how many seconds you listened each day, per session. This is what powers your streak, your weekly listening chart and your totals on the Home tab.
  • Favourites: the sessions you have marked as favourites.

Affirmation data

  • Your themes: the affirmation categories you have subscribed to.
  • Your history: each affirmation delivered to you, with its date and theme, kept so the app can show you what you received on earlier days, together with whether a reminder notification was sent for it.

Notification data (only if you turn the morning reminder on)

  • A push notification token for your device, issued by Firebase Cloud Messaging, and whether the device is an iPhone or an Android phone. We store one token per account; registering a new device replaces the previous one. The token is deleted when you turn the reminder off or sign out.

Account status

  • If you ask us to delete your account, the date of your request and the date the deletion is scheduled for, so we can honour the grace period and let you cancel.

Technical data

  • When the app talks to our servers we receive the standard technical information any web service receives: your IP address, request timestamps, the requests the app makes and any errors they produce. Session audio and artwork are streamed to your device from our media hosting provider (Amazon Web Services), which receives the same kind of request data when a file is fetched. We use this data to run and secure the Service and to diagnose problems. We do not build profiles from it.

Stored only on your device

  • Your appearance preference (light, dark or system), the position of the morning-reminder switch, and the sign-in session that keeps you signed in between launches. These live on your phone and are not sent to us, other than the session token that authenticates the app's requests.

What we do not collect

We do not collect your location, contacts, photos, microphone audio, health data or advertising identifiers. The app contains no advertising, analytics, attribution or crash-reporting SDKs from third parties. Siren is currently free, so we hold no payment details. Reading this website requires no account, and the website sets no cookies of its own.

3. How we use your data

Each purpose below uses only the data listed next to it.

  • Signing you in and keeping your account secure Email address, account identifier and the signed session token from Firebase.
  • Personalising the app The names you give us, so the app can greet you.
  • Playing sessions and picking up where you left off Your per-session progress, which also feeds the "Continue listening" shelf on the Home tab.
  • Your streak, weekly chart and totals Daily listening totals and your time zone, so each day is counted in your local time.
  • Remembering your favourites The sessions you have marked.
  • Delivering one affirmation a day and keeping your history Your theme subscriptions, your delivery history (so we can avoid repeating recent lines and show you past days) and your time zone.
  • Sending the morning reminder Your notification token, only while the reminder is switched on.
  • Honouring an account deletion request The request and scheduled dates.
  • Keeping the Service running, secure and free of bugs Technical data.
  • Complying with the law Whatever a specific legal obligation requires.

We do not make automated decisions about you, we do not profile you, and we do not send marketing email. The only emails you will receive are account emails sent through Firebase, such as a password reset you have requested.

4. Legal basis for processing (UK and EEA users)

Where UK GDPR or the EU GDPR applies, we rely on the following legal bases:

  • Contract: processing that is necessary to provide the Service you signed up for — your account, profile, listening data and affirmation data.
  • Consent: the morning reminder. You give consent by turning it on in the app and allowing notifications on your device, and you withdraw it by turning it off; withdrawing does not affect anything done before.
  • Legitimate interests: keeping the Service secure, diagnosing faults and preventing abuse, using technical data.
  • Legal obligation: where we are required to process data by law.

5. Who we share data with

We do not sell personal data, and we share it only with the providers below, each of which processes it on our behalf for the purpose described.

  • Google Firebase. Firebase Authentication manages account creation, sign-in, password handling and password-reset emails, and issues the tokens the app uses to prove who you are. Firebase Cloud Messaging delivers the morning reminder to your device (on iPhone, via Apple's Push Notification service), which means it processes your notification token and the text of the affirmation being sent. See Firebase's privacy documentation and Google's Privacy Policy.
  • Amazon Web Services. Session audio and artwork are hosted on AWS. When you play a session, your device fetches the file directly from AWS, so AWS receives your IP address and standard request metadata. It does not receive your account or listening data. See the AWS Privacy Notice.
  • Cloud hosting. Our application server and database run on cloud infrastructure. The hosting provider has no access to your data beyond what is technically required to operate the servers.
  • Apple and Google. If you install Siren from the App Store or Google Play, the store's own privacy policy governs the download and anything you do inside the store.
  • Legal requirements. We may disclose data if required by law, a court order or a lawful request from a public authority, or where necessary to protect the rights and safety of Siren, our users or others.

No AI or machine-learning providers receive your data.

6. Notifications

Siren sends at most one push notification a day: your affirmation, in the morning (around 8 am in your time zone), and only if you have turned the morning reminder on. The reminder is off when you install the app. Turning it on asks your phone for notification permission; if you decline, nothing is sent and no token is stored.

You can turn the reminder off at any time in the app (Profile → Daily affirmations → Morning reminder) or by disabling notifications for Siren in your phone's settings. Turning it off in the app removes your notification token from our servers; so does signing out. If you delete the app without signing out, the token stops working and is removed the next time a send fails.

7. How long we keep your data

  • Your account and everything in it are kept for as long as your account exists.
  • Deleting your account. You can request deletion from the app (Profile → Account → Delete account). A 30-day grace period follows, during which you can cancel from the same place. When it ends, your Firebase sign-in is deleted and your profile, listening data, favourites, affirmation subscriptions and history, notification token and deletion record are permanently removed from our database, normally within a day of the period ending.
  • Technical logs are kept for a limited period for security and troubleshooting and then deleted or overwritten.
  • Backups. Copies of the database held in routine backups are overwritten on their normal cycle.
  • Where the law requires us to keep something for longer, we keep only what it requires, for only as long as it requires.

The session catalogue and the affirmation library are our own content, not personal data, and are unaffected by account deletion.

8. Security

All traffic between the app and our servers is encrypted in transit (HTTPS), every request is authenticated with a signed Firebase token that we verify on our side, and our database lives on access-controlled infrastructure. Passwords never touch our systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we take reasonable steps to protect your data and will tell you if a breach affects you where the law requires it.

9. Your choices and rights

Controls in the app

  • Edit or clear your name: Profile → tap your name.
  • Change your affirmation themes or turn the reminder off: Profile → Daily affirmations.
  • Sign out on a shared device: Profile → Sign out.
  • Delete your account: Profile → Account → Delete account.

Your legal rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Correct data that is inaccurate or incomplete.
  • Delete your data (the in-app deletion flow does this; you can also ask us directly).
  • Receive your data in a structured, machine-readable format (portability).
  • Restrict or object to certain processing, including processing based on legitimate interests.
  • Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email privacy@waqystudios.com. We will respond within one month. We may ask you to confirm the email address on your account before acting. You also have the right to complain to your data protection authority; in the UK that is the Information Commissioner's Office.

10. Children

The Service is not directed at children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, contact us and we will delete it.

11. International transfers

We are based in the United Kingdom. Google Firebase and Amazon Web Services process data in the United States and other countries, and our servers may be located outside your own country. Where data leaves the UK or the European Economic Area, we rely on safeguards recognised under data protection law, such as adequacy decisions and standard contractual clauses (including the UK International Data Transfer Addendum), to protect it.

12. Changes to this policy

We may update this policy as the Service changes. The date at the top of this page shows the latest revision. If a change is material, we will let you know in the app before it takes effect. Continued use of the Service after a change takes effect means you accept the updated policy.

13. Contact

For anything about privacy or your data, email privacy@waqystudios.com.

You may also want to read our Terms & Conditions.