
Trust, Security & Data Privacy.
Mindful Slumber protects your sleep, journal, and meditation practice with enterprise-grade cryptography, strict European data privacy standards, and zero data monetization.
Audited annually · Last updated August 2026 · Security team SLA < 24h
End-to-End Cryptography
All network traffic is TLS 1.3 encrypted. Database volumes and storage backups are encrypted at rest with AES-256.
Edge & Cloud Resilience
High-availability architecture backed by ISO 27001 European data centers (Hetzner), Cloudflare edge DDoS mitigation, and WAF rules.
Zero Data Monetization
We never sell or rent user data. Corporate wellbeing sponsors receive only aggregated, anonymized group statistics.
Global Privacy Standards
Full compliance with EU/UK GDPR, CCPA/CPRA, and standard enterprise Data Processing Agreements (DPA).
Compliance & Certifications
Enterprise frameworks built on privacy-by-design.
We align with international security and data protection standards to satisfy demanding procurement and legal requirements.
EU & UK GDPR
Strict adherence to General Data Protection Regulation (EU 2016/679) & UK DPA 2018. Includes Standard Contractual Clauses (SCCs), data portability, and full right-to-be-forgotten deletion workflows.
SOC 2 Type II Alignment
Security controls structured around AICPA Trust Services Criteria: Security, Availability, and Confidentiality. Backed by automated continuous compliance tracking.
Health Privacy & Apple Health
Strict isolation of sleep duration, meditation minutes, and biometric indicators. Apple HealthKit integration runs locally on device with explicit permission gates.
CCPA & U.S. State Privacy
Complies with California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We support the right to know, delete, and opt-out of automated processing.
ISO/IEC 27001 Controls
Information Security Management System (ISMS) controls aligned with ISO/IEC 27001 standard. Documented policies for risk evaluation, vendor review, and asset management.
SIG Standard Questionnaires
Pre-completed Standard Information Gathering (SIG) questionnaires and vendor security assessment packs ready for fast-track enterprise IT procurement.
Architecture & Controls
Deep-tier security across every layer.
Explore our rigorous operational controls, data segregation architecture, and internal governance policies.
Encryption In Transit
All data transmitted between client applications (iOS, Android, Web) and our APIs is encrypted using modern TLS 1.2 and TLS 1.3 with strict HSTS enforcement and forward secrecy cipher suites.
Encryption At Rest
All primary database volumes, file storage, and automated backups are encrypted at rest using industry-standard AES-256 with keys managed through dedicated Key Management Services.
Salted Password Hashing
User credentials are never stored in plaintext. Passwords are cryptographically salted and hashed using compute-hardened algorithms with per-user unique salts.
Key Rotation & Secrets
API keys, database credentials, and symmetric encryption keys are rotated automatically via encrypted secret stores with strict role-segregated access and audit logging.
Journal Pseudonymization
Personal dream journal entries and reflective practice notes are decoupled from direct identity markers, ensuring internal queries cannot link sensitive experiences without authorization.
Cryptographic Data Erasure
When an account or journal entry is deleted, all corresponding cryptographic keys and database rows are purged permanently across active clusters and backup rotation lifecycles.
Documentation & Downloads
Security documentation for procurement teams.
Download public whitepapers or request confidential audit reports and assessment questionnaires under NDA.
Security Whitepaper
Technical overview of platform architecture, encryption standards, European cloud isolation, and Reverie privacy protocols.
SIG Questionnaire (Core)
Standard Information Gathering (SIG) spreadsheet with detailed responses across 19 security domains.
Standard DPA & SCCs
Standard Data Processing Agreement incorporating EU Standard Contractual Clauses (SCCs) for corporate customers.
Security Policy Pack
Comprehensive information security policies including Access Control, Password Standards, and Data Retention.
Incident Response Plan
Standard operating procedures for rapid triage, containment, customer notification, and post-mortem analysis.
Business Continuity & DR
Multi-region disaster recovery protocols, tested failover procedures, and backup restoration schedules.
Vendor Transparency
Authorized Subprocessor Directory.
Mindful Slumber engages trusted infrastructure and service providers to deliver our apps and services. All partners are subject to strict security vetting and Data Processing Agreements.
Showing 6 of 6 authorized partners
| Service Provider | Purpose & Service Role | Hosting Location | Data Categories Processed | Security Standards |
|---|---|---|---|---|
Hetzner Online GmbH | Dedicated cloud infrastructure, encrypted application databases & backup volumes | Germany & Finland (EU) | Encrypted user accounts, app state, practice logs | ISO 27001 / GDPR |
Cloudflare, Inc. | Content delivery network (CDN), DDoS mitigation, edge firewall (WAF) & DNS routing | Global Edge Network | Transient network traffic, IP routing, rate limits | SOC 2 / ISO 27001 |
Apple Inc. (App Store) | iOS app distribution, payment handling, and in-app subscription billing | Global | Anonymized purchase tokens, receipt validation | PCI-DSS / SOC 2 |
Google LLC (Google Play) | Android mobile app distribution and in-app subscription billing | Global | Anonymized purchase tokens, receipt validation | PCI-DSS / ISO 27001 |
Google AdMob (Google LLC) | Contextual mobile advertisement delivery for free-tier users | Global | Pseudonymous advertising IDs, ad engagement metrics | ISO 27001 / GDPR |
Apple HealthKit (On-Device) | Local mindfulness and sleep duration synchronization (explicit user consent only) | Local Device Only | No server transfer · Stored locally under device sandbox | HIPAA Aligned |
Frequently Asked Questions
Privacy & Security Inquiries.
Common questions regarding our data governance, B2B workplace privacy, AI safeguards, and encryption.
Responsible Disclosure & Bug Reporting.
We believe security is a continuous partnership. We welcome responsible reports from security researchers and promise prompt, good-faith collaboration.
Acknowledgment within 24 business hours
Safe harbor for researchers following responsible disclosure guidelines
Public recognition in our security acknowledgments (with consent)
Security Inbox
Please include detailed reproduction steps and impact analysis.