Last updated: July 28, 2026
This policy explains what personal data Obsomnia ("we", "us") collects when you use the app at obsomnia.com, why we collect it, and the rights you have under the General Data Protection Regulation (GDPR) and similar laws.
Account data: the email address you register with, a securely hashed version of your password (we never store or see your plain-text password), and the date/time you gave consent to this policy.
Content you create: the goals, tasks and hierarchies you build in the app, linked to your account.
Technical data:your IP address, used only transiently to rate-limit requests to our endpoints (see "Cookies & similar technologies" below) and recorded in short-lived server request logs used for operating and securing the service.
We do not use advertising, analytics, or third-party tracking scripts of any kind.
To provide the service (performance of a contract with you): creating and securing your account, signing you in, and storing the content you create.
With your consent:processing your account data as described here, which you agree to when you register. You can withdraw consent at any time by requesting account deletion (see "Your rights" below) — this does not affect the lawfulness of processing carried out before withdrawal.
Legitimate interest: rate-limiting and abuse/fraud prevention across our endpoints, and keeping operational logs to diagnose and secure the service.
We set exactly one cookie: a session cookie that keeps you signed in. It is marked HttpOnly (not readable by page scripts), Secure in production, and SameSite=Lax. It is strictly necessary for the app to function — without it you couldn't stay signed in — and is cleared when you sign out.
We do not set any advertising, analytics, or third-party cookies. Because we only use strictly-necessary cookies, we don't show a cookie-consent banner, as none is required under ePrivacy/GDPR rules for this category of cookie — this section exists to disclose it to you regardless.
We don't sell your data or share it with advertisers. A small number of infrastructure providers process data on our behalf, strictly to run the service. Currently, these include:
Amazon Web Services (SES) — sends transactional emails (registration confirmation, login links).
Digital Ocean — hosts the servers, database and cache described below.
Self-hosted MongoDB and Redis — our own database and rate-limiting infrastructure, running on our hosting provider; not operated by a separate third party.
We may also use additional infrastructure providers in the future — for example, a content delivery network, reverse proxy, or DDoS-protection service sitting in front of our servers — to operate, secure, and improve the performance of the service. Such providers would process only technical data (like IP addresses and request metadata) needed to route and protect traffic, under their own security commitments.
We may disclose data if required by law, or to protect the rights, property, or safety of Obsomnia, our users, or others.
Account and content data is kept while your account is active. If you request deletion, we aim to fully delete it within 60 days.
Registration and login-link tokens are single-use and expire automatically 15–30 minutes after being issued.
Rate-limiting data keyed by IP address or email is kept for at most one hour and then expires automatically; it is never written to our database.
Operational request logs (which can include IP addresses) are retained for a limited period, targeted at around 90 days, for security monitoring and abuse investigation.
Under the GDPR, you have the right to: access the personal data we hold about you; correct inaccurate data; request erasure ("right to be forgotten"); restrict or object to certain processing; receive your data in a portable format; and withdraw consent at any time.
To exercise any of these rights, email us at contact@obsomnia.com. We aim to acknowledge requests within 7 days and fulfill them within 30 days. You also have the right to lodge a complaint with the data protection authority in your country.
Passwords are hashed using an industry-standard algorithm and never stored in plain text. Traffic to the app is encrypted with HTTPS, and the session cookie is inaccessible to page scripts. Our endpoints are rate-limited to deter brute-force and credential-stuffing attacks. No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard practices.
Obsomnia is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will delete it.
Some of our service providers (such as AWS) may process data on servers located outside your country. Where this happens, we rely on the safeguards those providers offer, such as standard contractual clauses, to protect your data.
We may update this policy from time to time. We'll update the "Last updated" date above when we do; if changes are material, we'll make reasonable efforts to let registered users know.
Questions about this policy or your data? Email us at contact@obsomnia.com.