A starry Himalayan night sky
Continuous Compliance & Real-Time Monitoring

Trust, Security & Data Privacy.

Mindful Slumber protects your sleep, journal, and meditation practice with enterprise-grade cryptography, strict European data privacy standards, and zero data monetization.

Audited annually · Last updated August 2026 · Security team SLA < 24h

TLS 1.3 / AES-256

End-to-End Cryptography

All network traffic is TLS 1.3 encrypted. Database volumes and storage backups are encrypted at rest with AES-256.

99.98% Uptime

Edge & Cloud Resilience

High-availability architecture backed by ISO 27001 European data centers (Hetzner), Cloudflare edge DDoS mitigation, and WAF rules.

100% Private

Zero Data Monetization

We never sell or rent user data. Corporate wellbeing sponsors receive only aggregated, anonymized group statistics.

GDPR / HIPAA

Global Privacy Standards

Full compliance with EU/UK GDPR, CCPA/CPRA, and standard enterprise Data Processing Agreements (DPA).

Compliance & Certifications

Enterprise frameworks built on privacy-by-design.

We align with international security and data protection standards to satisfy demanding procurement and legal requirements.

GDPR
Fully Compliant

EU & UK GDPR

Strict adherence to General Data Protection Regulation (EU 2016/679) & UK DPA 2018. Includes Standard Contractual Clauses (SCCs), data portability, and full right-to-be-forgotten deletion workflows.

SOC 2
Controls Aligned

SOC 2 Type II Alignment

Security controls structured around AICPA Trust Services Criteria: Security, Availability, and Confidentiality. Backed by automated continuous compliance tracking.

HIPAA
Health Data Isolated

Health Privacy & Apple Health

Strict isolation of sleep duration, meditation minutes, and biometric indicators. Apple HealthKit integration runs locally on device with explicit permission gates.

CCPA
CPRA Ready

CCPA & U.S. State Privacy

Complies with California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We support the right to know, delete, and opt-out of automated processing.

ISO
ISMS Aligned

ISO/IEC 27001 Controls

Information Security Management System (ISMS) controls aligned with ISO/IEC 27001 standard. Documented policies for risk evaluation, vendor review, and asset management.

SIG
Available on Request

SIG Standard Questionnaires

Pre-completed Standard Information Gathering (SIG) questionnaires and vendor security assessment packs ready for fast-track enterprise IT procurement.

Architecture & Controls

Deep-tier security across every layer.

Explore our rigorous operational controls, data segregation architecture, and internal governance policies.

Encryption In Transit

All data transmitted between client applications (iOS, Android, Web) and our APIs is encrypted using modern TLS 1.2 and TLS 1.3 with strict HSTS enforcement and forward secrecy cipher suites.

Encryption At Rest

All primary database volumes, file storage, and automated backups are encrypted at rest using industry-standard AES-256 with keys managed through dedicated Key Management Services.

Salted Password Hashing

User credentials are never stored in plaintext. Passwords are cryptographically salted and hashed using compute-hardened algorithms with per-user unique salts.

Key Rotation & Secrets

API keys, database credentials, and symmetric encryption keys are rotated automatically via encrypted secret stores with strict role-segregated access and audit logging.

Journal Pseudonymization

Personal dream journal entries and reflective practice notes are decoupled from direct identity markers, ensuring internal queries cannot link sensitive experiences without authorization.

Cryptographic Data Erasure

When an account or journal entry is deleted, all corresponding cryptographic keys and database rows are purged permanently across active clusters and backup rotation lifecycles.

Documentation & Downloads

Security documentation for procurement teams.

Download public whitepapers or request confidential audit reports and assessment questionnaires under NDA.

Under NDA

SIG Questionnaire (Core)

Standard Information Gathering (SIG) spreadsheet with detailed responses across 19 security domains.

Enterprise Ready

Standard DPA & SCCs

Standard Data Processing Agreement incorporating EU Standard Contractual Clauses (SCCs) for corporate customers.

Under NDA

Security Policy Pack

Comprehensive information security policies including Access Control, Password Standards, and Data Retention.

Summary Public

Incident Response Plan

Standard operating procedures for rapid triage, containment, customer notification, and post-mortem analysis.

Under NDA

Business Continuity & DR

Multi-region disaster recovery protocols, tested failover procedures, and backup restoration schedules.

Vendor Transparency

Authorized Subprocessor Directory.

Mindful Slumber engages trusted infrastructure and service providers to deliver our apps and services. All partners are subject to strict security vetting and Data Processing Agreements.

Showing 6 of 6 authorized partners

Service ProviderPurpose & Service RoleHosting LocationData Categories ProcessedSecurity Standards
HZ Hetzner Online GmbH
Dedicated cloud infrastructure, encrypted application databases & backup volumesGermany & Finland (EU)Encrypted user accounts, app state, practice logsISO 27001 / GDPR
CF Cloudflare, Inc.
Content delivery network (CDN), DDoS mitigation, edge firewall (WAF) & DNS routingGlobal Edge NetworkTransient network traffic, IP routing, rate limitsSOC 2 / ISO 27001
AP Apple Inc. (App Store)
iOS app distribution, payment handling, and in-app subscription billingGlobalAnonymized purchase tokens, receipt validationPCI-DSS / SOC 2
GP Google LLC (Google Play)
Android mobile app distribution and in-app subscription billingGlobalAnonymized purchase tokens, receipt validationPCI-DSS / ISO 27001
AD Google AdMob (Google LLC)
Contextual mobile advertisement delivery for free-tier usersGlobalPseudonymous advertising IDs, ad engagement metricsISO 27001 / GDPR
HK Apple HealthKit (On-Device)
Local mindfulness and sleep duration synchronization (explicit user consent only)Local Device OnlyNo server transfer · Stored locally under device sandboxHIPAA Aligned

Frequently Asked Questions

Privacy & Security Inquiries.

Common questions regarding our data governance, B2B workplace privacy, AI safeguards, and encryption.

Your dream entries, audio notes, and mindfulness reflections are treated as highly confidential personal data. All data is encrypted in transit using TLS 1.3 and at rest with AES-256 in secure ISO 27001 European facilities (Hetzner). Entries are stored pseudonymously and are never indexed for advertising, sold, or shared with unauthorized parties.
Never. Employers, insurers, and wellbeing sponsors receive strictly aggregated, anonymized group statistics (e.g., total organizational meditation minutes or overall program adoption percentage, provided group size minimum thresholds are met). No individual user practice sessions, dream entries, or sleep metrics are ever accessible to your organization.
Reverie AI leverages zero-data-retention enterprise inference endpoints. Your dream texts and journal reflections are processed ephemerally to produce insights and are never used to train or fine-tune public language models.
In compliance with GDPR and CCPA, you can initiate a full data export in standard JSON format directly from the app settings under Account > Data & Privacy. You may also execute immediate permanent deletion of your account and all associated records with one click, or email [email protected].
Yes. We offer standard enterprise DPAs incorporating EU/UK Standard Contractual Clauses (SCCs) and custom terms for corporate wellbeing partnerships. You can request our standard DPA by clicking or reaching out to [email protected].