Your Data, Your Sanctuary

गोपनीयता संरक्षण

Privacy Policy

Just as the lotus grows in water but remains untouched by it, we process your data while respecting your privacy. Last updated: July 25, 2026.

Information We Collect

We collect only the essential information needed to provide you with a personalized Nirvana experience:

Personal Information:

  • Full Name - To personalize your wellness journey and address you properly in communications
  • Email Address - For account access, important updates, and personalized insights
  • Wallet Address - For secure blockchain-based features and future token rewards
  • Profile Picture (optional) - To customize your profile and community presence
  • Region/Location - To provide timezone-appropriate sleep schedules and local wellness insights
  • IP Address - For security purposes and to optimize app performance based on your region
  • Reown (WalletConnect) AppKit — when you sign in on the website, Reown may process wallet addresses, email used for embedded login, or social login metadata according to their policies
  • Transactional email — a welcome message after sign-up may be sent via Resend to the email address on your account
  • Google Fit (optional) — if connected, we may process activity summaries such as daily steps, active minutes, and calories to populate dashboard analytics
  • Wellness Data:

  • Sleep patterns and REM cycle data (stored locally on your device by default)
  • Heart rate variability readings
  • Body temperature variations
  • Movement and activity data during sleep
  • Usage Data:

  • App interaction patterns (anonymized)
  • Feature preferences and settings
  • Device type and operating system for compatibility
  • How We Protect Your Data

    Your privacy is sacred to us. We implement multiple layers of security:

    Encryption:

  • All data transmission uses TLS 1.3 encryption
  • Sensitive data at rest is encrypted using AES-256
  • Wallet addresses are hashed and never stored in plain text
  • Biometric data never leaves your device unless explicitly synced
  • Security Measures:

  • Regular security audits by third-party firms
  • Multi-factor authentication for account access
  • Automated threat detection and prevention systems
  • Secure data centers with 24/7 monitoring
  • Zero-knowledge architecture where possible
  • Blockchain Security:

  • Wallet connections use the Reown (WalletConnect) protocol via AppKit
  • No private keys are ever stored or accessed by us
  • Smart contract interactions are transparent and verifiable
  • How We Use Your Information

    Your data serves only to enhance your personal journey toward mindfulness and better sleep:

    Personalization:

  • Tailoring meditation recommendations to your sleep patterns
  • Adjusting lucid dreaming cues based on your REM cycles
  • Providing timezone-appropriate sleep schedules
  • Customizing the app interface to your preferences
  • Sending relevant wellness tips and insights
  • Generating activity analytics and trend summaries when you connect Google Fit
  • Service Improvement:

  • Analyzing anonymized usage patterns to improve features
  • Detecting and fixing technical issues
  • Optimizing app performance for your device
  • Communication:

  • Account-related notifications
  • Weekly sleep summary reports (if opted in)
  • Important product updates
  • Security alerts
  • We NEVER:

  • Sell your data to third parties
  • Use your data for advertising targeting
  • Share identifiable information with partners
  • Access your wallet funds or private keys
  • Program Privacy & Cohort Data Use

    If you apply to or participate in a SeekNirvana cohort or guided program, we may collect additional information to support program delivery, scheduling, safety, and product improvement.

    Program Data We May Collect:

  • Cohort application details such as your name, email, timezone, attendance preference, and stated goals
  • Wellness-context information you choose to share, such as sleep concerns, dream recall familiarity, current stress patterns, and reflective notes
  • Attendance, participation, and submitted journaling or cohort feedback
  • Device-linked wellness data that you intentionally connect during the program experience
  • How Program Data May Be Used:

  • To review applications and organize cohort placement
  • To personalize cohort guidance, prompts, and support materials
  • To improve curriculum design, safety messaging, and product workflows
  • To develop or refine custom AI systems using de-identified or aggregated patterns only
  • No PII In Model Training:

  • We do not use directly identifying personal information such as your name, email address, phone number, or precise contact details to train AI models
  • We do not intentionally place private cohort applications or raw personal notes into a model training pipeline in identifiable form
  • If cohort-derived data is ever used for model improvement, it is first stripped of direct identifiers and handled under controlled internal processes
  • Your Choice Matters:

  • You should avoid sharing information you do not want reviewed for cohort support
  • You may request deletion of submitted cohort application information, subject to legal and operational retention needs
  • Program participation is optional, and your core legal rights remain governed by this Privacy Policy
  • Organization Pilot & Employee Privacy

    When an organization asks about a SeekNirvana pilot, we collect only the contact and planning details needed to respond and shape the proposed experience. Please do not include employee health details in the inquiry form.

    Organization Inquiry Data:

  • Contact name, work email, organization name, country, audience size, pilot preferences, timing, and context you choose to provide
  • We use these details to respond, plan the pilot, and provide operational follow-up
  • Employee Data Stays Private:

  • Employees control their personal wellness experience and individual data
  • An organization may receive enrollment, activation, participation, completion, anonymous feedback, and thresholded aggregate trends
  • An organization does not receive individual biometrics, sleep records, readiness or stress scores, journals, AI guide conversations, or expert-session details
  • Choice & Retention:

  • Consent is required before an organization inquiry can be submitted
  • You may request deletion of inquiry information, subject to legal and operational retention requirements
  • Data Storage & Retention

    We believe in data minimization and user control:

    Storage Locations:

  • Primary servers located in secure, ISO 27001 certified data centers
  • Backup data encrypted and distributed across multiple regions
  • Biometric data primarily stored on your local device
  • Blockchain data is immutable and public per blockchain design
  • Retention Periods:

  • Account data: Retained while account is active, deleted 30 days after account closure
  • Sleep data: Stored according to your preferences (default: 1 year, then anonymized)
  • Usage logs: Anonymized after 90 days
  • IP logs: Retained for 30 days for security, then deleted
  • Communication records: Retained for 2 years for legal compliance
  • Your Control:

  • Export all your data at any time
  • Request immediate deletion (right to be forgotten)
  • Choose local-only storage for sensitive biometric data
  • Set custom retention periods for sleep history
  • Disconnect Google Fit and revoke sync access at any time from dashboard settings
  • Data Sharing & Third Parties

    We maintain strict boundaries around data sharing:

    What We Don't Share:

  • Your personal information with advertisers
  • Your biometric data with any external parties
  • Your wallet address with marketing partners
  • Individual sleep patterns in identifiable form
  • Limited Sharing Only When:

  • Service Providers: Trusted vendors who help us operate (hosting, analytics, customer support) under strict confidentiality agreements and only with necessary data
  • Legal Requirements: When required by law, court order, or to protect our rights and safety
  • Business Transfers: In case of merger or acquisition, with notice to users
  • With Your Consent: Only when you explicitly authorize sharing
  • OAuth Providers: Google may process authentication and authorization metadata during Google Fit sign-in under Google's terms
  • Blockchain Transparency:

  • On-chain transactions are public by nature
  • We use privacy-preserving techniques where possible
  • You control what data links to your public wallet address
  • Your Privacy Rights

    You have complete control over your personal information:

    Access & Portability:

  • Download all your data in standard formats (JSON, CSV)
  • View complete logs of data access and processing
  • Receive clear explanations of automated decision-making
  • Correction & Deletion:

  • Update your information at any time in account settings
  • Request correction of inaccurate data
  • Delete your account and all associated data permanently
  • Opt-out of data processing where legally applicable
  • Control Options:

  • Adjust privacy settings granularly
  • Choose local-only vs cloud storage
  • Opt-out of non-essential communications
  • Disable specific data collection features
  • Manage cookie preferences
  • Regional Rights:

  • GDPR rights for EU residents (access, erasure, portability, objection)
  • CCPA rights for California residents (know, delete, opt-out, non-discrimination)
  • Similar rights honored for all users globally
  • Account Deletion

    When you choose to leave, your data leaves with you:

    Deletion Process:

    1. Initiate deletion from account settings

    2. 7-day grace period to prevent accidental loss

    3. Irreversible deletion of personal information

    4. Anonymization of sleep data used for research

    5. Confirmation email upon completion

    What Gets Deleted:

  • Profile information and settings
  • Email and contact details
  • Wallet address associations
  • Profile pictures and personal media
  • Account activity logs
  • Communication history
  • What Remains:

  • Anonymized sleep data patterns (stripped of identifiers)
  • Blockchain transaction records (immutable by design)
  • Legal compliance records (as required by law)
  • Post-Deletion:

  • 30-day recovery window (then permanent)
  • No marketing communications
  • Option to return with fresh start