Privacy policy
Last updated: August 19, 2026
DOZZI operates this store, website, and the Dozzi baby monitor application, including all related information, content, features, tools, products and services, in order to provide you, the customer, with a curated shopping experience and smart baby monitoring service (the "Services"). Our online store is powered by Shopify, which enables us to provide e-commerce Services to you. This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction using the Services, use the Dozzi mobile application or hardware device, or otherwise communicate with us. If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal information.
Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you have read this Privacy Policy and understand the collection, use, and disclosure of your information as described in this Privacy Policy.
Part 1: Store & Website
The following sections apply to our online store, website, and general e-commerce Services.
Personal Information We Collect or Process
When we use the term "personal information," we are referring to information that identifies or can reasonably be linked to you or another person. Personal information does not include information that is collected anonymously or that has been de-identified, so that it cannot identify or be reasonably linked to you. We may collect or process the following categories of personal information, including inferences drawn from this personal information, depending on how you interact with the Services, where you live, and as permitted or required by applicable law:
- Contact details including your name, address, billing address, shipping address, phone number, and email address.
- Financial information including credit card, debit card, and financial account numbers, payment card information, financial account information, transaction details, form of payment, payment confirmation and other payment details.
- Account information including your username, password, security questions, preferences and settings.
- Transaction information including the items you view, put in your cart, add to your wishlist, or purchase, return, exchange or cancel and your past transactions.
- Communications with us including the information you include in communications with us, for example, when sending a customer support inquiry.
- Device information including information about your device, browser, or network connection, your IP address, and other unique identifiers.
- Usage information including information regarding your interaction with the Services, including how and when you interact with or navigate the Services.
Personal Information Sources
We may collect personal information from the following sources:
- Directly from you including when you create an account, visit or use the Services, communicate with us, or otherwise provide us with your personal information;
- Automatically through the Services including from your device when you use our products or services or visit our websites, and through the use of cookies and similar technologies;
- From our service providers including when we engage them to enable certain technology and when they collect or process your personal information on our behalf;
- From our partners or other third parties.
How We Use Your Personal Information
Depending on how you interact with us or which of the Services you use, we may use personal information for the following purposes:
Provide, Tailor, and Improve the Services. We use your personal information to provide you with the Services, including to perform our contract with you, to process your payments, to fulfill your orders, to remember your preferences and items you are interested in, to send notifications to you related to your account, to process purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, to facilitate any returns and exchanges, to enable you to post reviews, and to create a customized shopping experience for you, such as recommending products related to your purchases. This may include using your personal information to better tailor and improve the Services, and to conduct internal research, analytics, and product development to operate, secure, analyze, and improve our current and future products and services. Where this involves health or biometric data, that data is handled only as described in the "Biometric Data — BIPA Disclosure" and "Optional Algorithm Contribution" sections in Part 2 below.
Marketing and Advertising. We use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email, text message or postal mail, and to show you online advertisements for products or services on the Services or other websites, including based on items you previously have purchased or added to your cart and other activity on the Services.
Security and Fraud Prevention. We use your personal information to authenticate your account, to provide a secure payment and shopping experience, detect, investigate or take action regarding possible fraudulent, illegal, unsafe, or malicious activity, protect public safety, and to secure our services. If you choose to use the Services and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password or other access details with anyone else.
Communicating with You. We use your personal information to provide you with customer support, to be responsive to you, to provide effective services to you and to maintain our business relationship with you.
Legal Reasons. We use your personal information to comply with applicable law or respond to valid legal process, including requests from law enforcement or government agencies, to investigate or participate in civil discovery, potential or actual litigation, or other adversarial legal proceedings, and to enforce or investigate potential violations of our terms or policies.
How We Disclose Personal Information
In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy. Such circumstances may include:
- With Shopify, vendors and other third parties who perform services on our behalf (e.g. IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping).
- With business and marketing partners to provide marketing services and advertise to you. For example, we use Shopify to support personalized advertising with third-party services based on your online activity with different merchants and websites. Our business and marketing partners will use your information in accordance with their own privacy notices. Depending on where you reside, you may have a right to direct us not to share information about you to show you targeted advertisements and marketing based on your online activity with different merchants and websites.
- When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations.
- With our affiliates or otherwise within our corporate group.
- In connection with, or during negotiations of, any merger, acquisition, financing, due diligence, reorganization, sale of company assets, or other business transaction (including bankruptcy or a similar proceeding), in which case personal information may be transferred to the successor or acquiring entity. Any successor or acquirer will remain bound by the commitments in this Privacy Policy — including our biometric, health, and children's data commitments — with respect to information collected before the transaction. For biometric, health, or children's information, we or our successor will obtain your affirmative consent before applying any materially new use to information collected before the transaction; for other information, we will provide notice and obtain consent where required by applicable law. Any disclosure of personal information during diligence or negotiations is limited to what is reasonably necessary and is made under written confidentiality obligations.
- To comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service or policies, and to protect or defend the Services, our rights, and the rights of our users or others.
Relationship with Shopify
The online store Services are hosted by Shopify, which collects and processes personal information about your access to and use of the Services in order to provide and improve the Services for you. Information you submit to the Services will be transmitted to and shared with Shopify as well as third parties that may be located in countries other than where you reside, in order to provide and improve the Services for you. In addition, to help protect, grow, and improve our business, we use certain Shopify enhanced features that incorporate data and information obtained from your interactions with our Store, along with other merchants and with Shopify. To provide these enhanced features, Shopify may make use of personal information collected about your interactions with our store, along with other merchants, and with Shopify. In these circumstances, Shopify is responsible for the processing of your personal information, including for responding to your requests to exercise your rights over use of your personal information for these purposes. To learn more about how Shopify uses your personal information and any rights you may have, you can visit the Shopify Consumer Privacy Policy.
Part 2: Dozzi App & Device
The following sections apply specifically to the Dozzi baby monitor mobile application for iOS and watchOS, the Dozzi hub device, and the related cloud services that power alert routing and monitoring.
What Dozzi Does
Dozzi is a smart baby monitor system. A hub device in your baby's room detects infant crying and sends alerts to caregivers via Apple Watch haptic vibrations. When multiple caregivers are set up, the App uses health and biometric data to determine which caregiver is most awake and routes the alert to them — letting the other caregiver continue sleeping.
Information the App Collects
Account Information - Name, email address, and password (via Firebase Authentication) - Caregiver role and household setup (e.g., which caregivers are linked to which hub)
Health and Biometric Data When you enable monitoring with an Apple Watch, we collect: - Heart rate — sampled approximately every 30 seconds in Smart Mode or every 60 seconds in other alert modes, from Apple Watch via Apple HealthKit - Resting heart rate — read from HealthKit to establish your personal baseline - Heart rate variability (HRV) — a variability measure we derive from the heart-rate samples above; we do not read HealthKit's own HRV records. Used as one input to the wakeability score. - Motion and movement data — from Apple Watch accelerometer, processed into movement intensity scores used to detect wakefulness - Sleep stages recorded by your Apple Watch — Apple's own sleep staging for the night (awake, REM, core/light, deep), read from Apple HealthKit. Read-only; we never write to your Health records. Available only if you have set up sleep tracking on your Apple Watch — if you haven't, we simply receive nothing, and the App treats that as a normal state rather than an error. Apple finalizes these stages hours after you wake, so they are never available during monitoring and are never used to route a live alert. - Dozzi's own sleep-stage estimate — an approximation of your sleep stage that we compute from your heart rate and motion and store with your monitoring session. - Watch battery level — monitored during sessions to alert you if battery is low
Heart rate, HRV, and motion are used to calculate a "wakeability score" that determines which caregiver is most alert when your baby needs attention. For your sleep summary in the Insights tab, the App shows your Apple Watch's own sleep stages when they are available, and Dozzi's own estimate otherwise — and it labels which of the two you are looking at, so an estimate is never presented as a measurement. Your Apple Watch's stages are also used to retrospectively evaluate and improve our alert routing.
Our sleep-stage estimates are approximations, not medical measurements. They are not diagnostic, are not reviewed by a clinician, and should not be used to make health decisions.
We access health data through Apple HealthKit with your explicit permission. The App uses a HealthKit workout session on your Apple Watch to maintain continuous heart rate sensor access during overnight monitoring — no workout data is saved to your Apple Health records. You can revoke HealthKit access at any time in your iPhone's Settings > Privacy & Security > Health > Dozzi. Sleep-stage access is a separate HealthKit permission you can decline or revoke independently. Doing so has no effect on Smart Mode routing, and your Insights sleep summary continues to work — it falls back to Dozzi's own estimate and says so.
Device Information - Device identifiers — Firebase Cloud Messaging (FCM) tokens and Apple Push Notification Service (APNs) tokens, used to deliver cry alerts to your iPhone and Apple Watch - Device model and OS version — for compatibility and debugging - Hub device identifier — MAC address of your Dozzi hub, used to associate your account with your hub
Hub Telemetry Data The Dozzi hub periodically reports operational metrics to our cloud backend: - WiFi signal strength (RSSI) — used to monitor hub connectivity health - Ambient noise level — averaged sound level in the baby's room (no audio is recorded or stored) - Near-miss count — number of times the baby fussed but self-soothed without triggering an alert
Monitoring and Alert Data - Cry detection events — timestamps, duration, intensity level, and detection diagnostics of detected crying. No audio is ever recorded, transmitted, or stored. - Derived acoustic measurements — if you opt in to Algorithm Contribution, a short sound-level-over-time curve around a detected cry or near-miss, computed on the hub. No audio, and no frequency content, from which the original sound could be reconstructed. - Alert routing decisions — which caregiver was alerted, the wakeability scores and sleep state factors used in the decision, and whether alternating or smart routing was applied - Session data — monitoring start/stop times, session duration, and alert counts - Response data — whether and when an alert was acknowledged or snoozed - Proximity data — Bluetooth signal strength (RSSI) between your Apple Watch and the hub, used to determine if a caregiver is already near the baby
Bluetooth Beacon Proximity Data - Beacon region monitoring — The App uses Bluetooth beacon technology (iBeacon) to detect when your iPhone is near the Dozzi hub. This is used solely to keep the monitoring connection reliable overnight, allowing the App to automatically reconnect if the connection is interrupted. This feature uses your device's Bluetooth hardware to detect the hub's beacon signal — it does not use GPS, cellular location, or Wi-Fi location services. No geographic location data is collected, stored, or transmitted. The App requests location permission because iOS requires it for Bluetooth beacon detection, but no actual location information is accessed or recorded.
Feedback Data When you submit beta feedback through the App, we collect: - Your rating, selected tags, and written comments - Session context (duration, alert count, sleep score, alert mode) - App version and hub firmware version - Optionally, a diagnostic debug report containing a summary of your monitoring session (see Diagnostic Data below)
Diagnostic Data - App crash logs, error reports, and performance metrics - Debug reports (generated on-demand by the user) containing monitoring session summaries. When submitted with beta feedback, debug reports are uploaded to our cloud backend. Debug reports DO contain raw biometric data: up to ~8 hours of per-30-second heart-rate, movement, and sleep-stage samples from the session, alongside session and alert records. They are generated only when you ask for one, and we use them solely to diagnose the problem you reported.
How the App Uses Your Information
| Data | Purpose |
|---|---|
| Heart rate, HRV, motion | Calculate wakeability scores for intelligent alert routing (Smart Mode) |
| Apple Watch sleep stages | Your sleep summary in the Insights tab, labelled as coming from your watch; and retrospectively evaluating and tuning our alert-routing algorithm. Never used to route a live alert — Apple produces them only after you wake. |
| Dozzi's sleep-stage estimate | Your sleep summary in Insights when your Apple Watch's own stages aren't available, labelled as an estimate; internal quality telemetry |
| Watch battery level | Alert you if watch battery is low during a monitoring session |
| Device tokens (FCM/APNs) | Deliver cry alert notifications to your iPhone and Apple Watch |
| Account info | Manage your account, link caregivers to hubs |
| Hub telemetry (WiFi RSSI, ambient noise, near-miss, and derived acoustic measurements — a sound-level-over-time curve computed on the device, with no frequency or spectral content, from which audio cannot be reconstructed) | Monitor hub health, improve cry detection algorithms |
| Cry detection events | Route alerts, generate your baby's session summaries |
| Alert routing decisions | Improve fairness of alert distribution between caregivers |
| Proximity data | Suppress follow-up alerts when a caregiver is already near the baby |
| Beacon proximity | Keep the monitoring connection reliable overnight by detecting when your phone is near the hub (no GPS or location tracking) |
| Feedback data | Improve app reliability and user experience during beta testing |
| Diagnostic data | Debug issues, improve app reliability |
We do NOT use your health or biometric data for advertising, marketing, or data mining. Ever.
Research and Product Development. We may use information collected through the App to conduct internal research, analytics, and product development — including building, training, evaluating, and improving the algorithms, models, and features that power the Dozzi monitoring service. Data we obtain from Apple HealthKit (heart rate, resting heart rate, motion, and Apple Watch sleep stages), together with anything we derive from it (including HRV and our own sleep-stage estimates), is used solely to deliver the monitoring service and, only if you opt in to Algorithm Contribution, in de-identified or aggregated form to improve it; this HealthKit-derived data is never used to train models for, or to build, products unrelated to infant monitoring and caregiver alerting, and is never sold or used for advertising. If we develop materially new products or services that would use information collected for the purposes described above, we will treat that as a new purpose under "New Uses of Information" in Part 3 below.
Biometric Data — BIPA Disclosure
If you are a resident of Illinois, the Illinois Biometric Information Privacy Act (BIPA) provides you with specific rights regarding biometric data. This section serves as our written notice under BIPA.
What biometric data we collect: - Heart rate, resting heart rate, and wrist motion data from your Apple Watch - Heart rate variability, which we derive from those heart-rate samples - Sleep stages recorded by your Apple Watch, read from Apple HealthKit (only if you have set up sleep tracking on your watch) - Sleep-stage estimates that we compute from your heart rate and motion
Purpose of collection: - To calculate wakeability scores that determine which caregiver receives cry alerts during Smart Mode routing - To show you your own sleep summary in the App's Insights tab - To retrospectively evaluate and improve the accuracy of that alert routing
This data is used solely for app functionality — not for identification, authentication, advertising, or sale. We do not use it to identify you: it is tied to your account because you asked us to monitor with it, never used as a means of recognizing who you are.
Consent: We obtain your informed, electronic consent before collecting any biometric data, through our in-app Biometric Data Consent screen presented during onboarding. You must affirmatively tap "I Consent" before any health data is accessed.
Retention and destruction schedule: - Real-time biometric readings (heart rate, HRV, motion): Retained in our cloud database for up to 7 days, then archived to secure cloud storage for up to 90 days for incident investigation (or until you delete your account, whichever is sooner), then permanently deleted - Nightly baseline calculations: Recalculated from the most recent 7 days of data; older data is not retained for baseline purposes - Detailed sleep staging (the minute-by-minute record your Apple Watch produced for the night): Retained for up to 90 days, then permanently deleted — the same schedule as your raw biometric readings - Nightly sleep summary (the four percentages behind your Insights trends): Retained with your monitoring session record, and deleted when you delete your account - Aggregated analytics (daily and weekly summaries, not raw biometric data): Retained for the lifetime of your account - Anonymized algorithm data (if you opt in): De-identified data with no personally identifiable information, retained permanently (see Optional Algorithm Contribution below) - On account deletion: All identifiable biometric data associated with your account is permanently deleted within 30 days - Maximum retention: If you stop using Dozzi, identifiable biometric data is permanently deleted no later than 3 years after your last monitoring session
Your rights under BIPA: - You may revoke your biometric data consent at any time in the App under Settings - Revoking consent disables Smart Mode alert routing; the App will fall back to Alternating mode - You may request deletion of all biometric data by contacting us at info@dozzisleep.com - We will never sell, lease, trade, or otherwise profit from your biometric data - We will never disclose your biometric data to third parties without your consent, except as required to provide the service (see below) or as required by law
Optional Algorithm Contribution
The Dozzi hub uses derived acoustic measurements to detect cries and to tune detection for your own room — this is part of how the monitor works. Separately, you may opt in to contribute anonymized detection data to help improve Dozzi for everyone (App → Settings → Algorithm Contribution). This contribution is optional and off unless you turn it on, and you can turn it off at any time; cry detection and alerts work the same either way.
During onboarding, you may optionally opt in to contribute anonymized, de-identified biometric patterns to help improve Dozzi's sleep detection algorithms. If you opt in:
- Your data is de-identified before storage: direct identifiers including your name, email, and device identifiers are removed, and your hub ID is replaced with a one-way cryptographic hash (SHA-256), using reasonable technical and organizational measures designed so the result is not reasonably linkable to you
- Anonymized nightly summaries (such as sleep stage percentages, alert counts, response times, and cry event statistics) are stored permanently in a secure analytics database (Google BigQuery)
- No raw biometric readings (individual heart rate samples, HRV values, or motion data) are included — only aggregated per-night statistics
- Used solely to improve sleep stage detection and alert routing accuracy
- You can opt out at any time in Settings; opting out stops future data from being de-identified and stored, but previously de-identified data is not reasonably linkable back to you and is not deleted (as it no longer contains identifying information)
This is entirely optional and does not affect your use of the App.
Ring Camera Integration (Optional)
If you choose to connect a Ring camera, the App accesses it through Ring's official partner program (operated by Amazon/Ring), using only the permissions you grant in the Ring app. This integration is entirely optional and is an additional convenience layer — your core cry-alert monitoring works whether or not a camera is connected.
- Live video. When you view your nursery, video streams directly between your phone and Ring. Dozzi never receives, records, or stores your live video — our servers relay only the brief connection handshake, never the video itself.
- Snapshots. When you request a still image ("View Nursery"), we retrieve a single recent frame, store it transiently in Google Cloud Storage, deliver it to your phone and Apple Watch over a private link that expires within minutes, and delete the stored image on a short schedule. Snapshots are handled only by automated systems — Dozzi personnel do not view, monitor, or manually review your camera's video or images. Because Dozzi keeps no video history or image gallery, there is no stored footage to browse: you view live video or a current snapshot only on demand.
- Camera details. Device name, identifier, and online status, so you can select your nursery camera and see its connection state.
- Connection credentials. An encrypted Ring access token (AES-256-GCM), stored only so the integration can function. We never receive or store your Ring password.
We use this information solely to let you view your own nursery camera in the App. We do not perform facial recognition, do not extract biometric data from any image or video, and do not use camera data for advertising, marketing, algorithm training, or sale. Ring camera data is processed using Google Cloud Platform (listed under our service providers) under Google's Data Processing Agreement, and is not shared with any other third party.
You can disconnect the camera at any time in Settings > Camera > Unlink, which permanently deletes the stored access token, configuration, snapshots, and session data from our systems. Removing the device in the Ring app, or revoking Dozzi's access, also triggers this cleanup on our side.
Data Storage and Retention
Dozzi uses a three-tier data storage system designed to balance real-time performance, incident investigation, and long-term algorithm improvement:
| Tier | Storage | Retention | Contains PII | Purpose |
|---|---|---|---|---|
| Hot | Google Cloud Firestore | 7 days | Yes | Real-time monitoring, alert routing, active session data |
| Cold | Google Cloud Storage (archive) | 90 days | Yes | Incident investigation, debugging overnight issues |
| Permanent | Google BigQuery | Indefinite | No (anonymized) | Algorithm improvement (opt-in only) |
Detailed retention by data type:
| Data Type | Retention Period |
|---|---|
| Account information | Until you delete your account |
| Heart rate, HRV, motion (cloud database) | 7 days, then archived |
| Archived biometric data (cloud storage) | Up to 90 days. Deleted sooner when your app supports it; otherwise these encrypted archives age out on the 90-day schedule |
| Nightly baseline | Rolling 7-day recalculation |
| Sleep stages (Apple Watch and Dozzi estimates) | Stored with the session record — see the destruction schedule in "Biometric Data — BIPA Disclosure" above |
| Monitoring session records | Kept with the hub, not with your account, and retained for as long as the hub remains in service. Not removed when a single caregiver deletes their account (see "Deleting Your Data"); deletion on request |
| Cry alert audit logs | Kept with the hub, not with your account, and retained for as long as the hub remains in service. Not removed when a single caregiver deletes their account (see "Deleting Your Data"); deletion on request |
| Daily and weekly analytics | Until you delete your account |
| Milestone and badge data | Until you delete your account |
| Feedback (rating, tags, comments, session context) | Until you delete your account |
| Debug reports submitted to support | 90 days from submission, then automatically deleted |
| In-app support chat transcripts ("Chat with Dozzi") | 90 days from each message, then automatically deleted |
| Support escalation transcripts | 90 days, then automatically deleted |
| Hub telemetry (WiFi RSSI, ambient noise level, near-miss count) | Included in audit logs; same retention as audit logs |
| Derived acoustic measurements (diagnostic) | Kept only if you opt in to Algorithm Contribution; retained up to 90 days, then deleted |
| Device tokens | Updated on each app launch; deleted on account deletion |
| Anonymized algorithm data (BigQuery, opt-in) | Permanent; cannot be linked to you |
Deleting Your Data
- Delete your account: Go to Settings > Advanced Settings > Account > Delete Account in the App. All identifiable cloud data associated with your account — including biometric readings, analytics, feedback, support chats, diagnostic reports, and your user profile — will be permanently deleted within 30 days, except encrypted cloud archives, which are deleted within 90 days. Monitoring session records and cry alert audit logs are kept with the HUB rather than with your account, because a hub is often shared by two caregivers and one person leaving must not erase the household's monitoring history. They are retained for as long as the hub remains in service and are not deleted by an individual account deletion; email info@dozzisleep.com to request their deletion. Anonymized data in BigQuery (if you opted in) is not deleted, as it cannot be linked back to you.
- Revoke HealthKit access: Go to iPhone Settings > Privacy & Security > Health > Dozzi and disable access. This stops resting-heart-rate and Apple sleep-stage reads; live heart-rate and motion collection during monitoring stops when you end the monitoring session or remove the Dozzi watch app. Neither step deletes previously collected cloud data.
- Request manual deletion: Email info@dozzisleep.com to request deletion of specific data or to verify that your data has been fully removed.
Third-Party Service Providers
In addition to the third parties described in Part 1 for our store, the Dozzi App shares information with the following service providers solely to operate the monitoring service:
| Provider | Data Shared | Purpose |
|---|---|---|
| Google Firebase (Firestore, Cloud Functions, Authentication, Cloud Messaging) | Account info, biometric data, device tokens, session data, feedback | Cloud backend — data storage, alert routing logic, push notification delivery, user authentication |
| Google Cloud Storage | Archived biometric data (7–90 days old) | Secure cold storage for incident investigation |
| Google BigQuery | Anonymized nightly summaries (opt-in only) | Algorithm improvement analytics — no PII |
| Apple Push Notification Service (APNs) | Device tokens, alert payloads | Deliver cry alerts directly to Apple Watch |
| Apple HealthKit | Health data read with your permission | Source of heart rate, resting heart rate, motion, and Apple Watch sleep stages. HRV is not read from HealthKit — we derive it from the heart-rate samples. Data stays on-device in Apple Health; we read it with your permission. |
| Anthropic (Claude) | (a) the text of your in-app or website chatbot conversations; (b) if you submit an issue report, the contents of that report — which include your account email, recent session records, and per-30-second heart-rate, motion, and sleep-stage samples from the session | (a) powers the in-app and website support assistants; (b) automated diagnosis of issue reports so we can fix problems faster. Anthropic does not use this data to train its models. Not used for advertising or marketing. |
These providers process data under their own security and privacy commitments: - Google Cloud Privacy - Apple Privacy Policy - Anthropic Privacy Policy
Data Security
We implement the following security measures to protect your data:
- Encryption in transit: All data between your devices and our cloud backend is transmitted over HTTPS/TLS
- Encryption at rest: Data stored in Google Firebase and Google Cloud Storage is encrypted at rest using AES-256
- De-identification: Algorithm contribution data is de-identified before storage in BigQuery — direct identifiers are removed and the hub ID is replaced with an SHA-256 cryptographic hash, using reasonable measures designed so the data is not reasonably linkable back to you
- Access controls: Biometric data is not publicly reachable and is never exposed by an unauthenticated endpoint. The App reaches it only through authenticated cloud functions. A small number of authorized Dozzi personnel can access it directly through authenticated, access-logged Google Cloud credentials, for service operation, incident investigation, and the internal research described above
- Authentication: User accounts are secured through Firebase Authentication with Apple Sign-In support
- No audio storage: The Dozzi hub detects crying events on the device itself and does not record, transmit, or store audio. To improve cry-detection accuracy and reliability, the hub may transmit derived acoustic measurements — a sound-level-over-time curve (a loudness reading ten times per second, with no frequency or spectral content) — that are computed on the device. The original audio cannot be reconstructed from these measurements, and no audio is ever recorded or transmitted. These measurements are used to tune detection and improve the product. Outside Algorithm Contribution these measurements are used only to make the detection decision and are not retained; if you opt in, we keep them for up to 90 days.
- Local hub communication: Communication between your iPhone and the Dozzi hub occurs over your local WiFi network. No audio data passes through the internet.
Push Notifications and Critical Alerts
Dozzi uses push notifications to deliver cry alerts. With your permission, we use Critical Alerts (approved by Apple) that can bypass Do Not Disturb and silent mode to ensure you are notified when your baby needs attention.
- You can manage notification preferences in iOS Settings > Notifications > Dozzi
- Disabling notifications may prevent cry alerts from reaching your devices
- Alert delivery relies on device tokens stored in our cloud backend
Part 3: General Provisions
The following sections apply to all Services, including the store, website, and App.
Third Party Websites and Links
The Services may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Services and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.
Children's Data
The Services are not intended to be used by children, and we do not knowingly collect any personal information about children under the age of majority in your jurisdiction. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted. As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we "share" or "sell" (as those terms are defined in applicable law) personal information of individuals under 16 years of age.
The Dozzi App is designed for parents and adult caregivers to monitor their babies. No one under the age of 18 may create a Dozzi account. The Dozzi hub monitors ambient sound in the baby's room to detect crying, but no audio is recorded or stored — only the timestamp, duration, and intensity of cry detection events are transmitted to the cloud.
De-Identified and Aggregated Information
We may create, use, and retain de-identified and aggregated information for research, internal analytics, benchmarking, and product development, and may disclose it to our service providers and research partners under written contract. Before treating information as de-identified, we take reasonable technical and organizational measures designed to ensure it cannot reasonably be linked to you or your household, we publicly commit to maintaining it in de-identified form, and we contractually prohibit recipients from attempting to re-identify it except solely to test that de-identification is effective.
This section does not apply to, and we do not sell or disclose for commercial purposes, (i) any data derived from Apple HealthKit or other health or biometric sources, or (ii) any information about a child or infant (including name, birth date, or age) or any identifiable cry-event records. All such information remains governed by the commitments elsewhere in this Privacy Policy, including the "Biometric Data — BIPA Disclosure" and "Children's Data" sections.
Security and Retention of Your Information
Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee "perfect security." In addition, any information you send to us may not be secure while in transit. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.
How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide you with Services, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies. For specific retention periods related to the Dozzi App and biometric data, see the "Data Storage and Retention" section in Part 2 above.
Your Rights and Choices
Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. However, these rights are not absolute, may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.
- Right to Access / Know. You may have a right to request access to personal information that we hold about you.
- Right to Delete. You may have a right to request that we delete personal information we maintain about you.
- Right to Correct. You may have a right to request that we correct inaccurate personal information we maintain about you.
- Right of Portability. You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.
- Right to Opt out of Sale or Sharing for Targeted Advertising. Depending on where you reside, you may have a right to opt out of the "sale" or "share" of your personal information or to opt out of the processing of your personal information for purposes considered to be "targeted advertising", as defined in applicable privacy laws. Please note that if you visit our website with the Global Privacy Control opt-out preference signal enabled, depending on where you are, we will automatically treat this as a request to opt-out for the device and browser that you use to visit the website. If we are able to associate the device sending the signal to a Shopify account, we will apply the opt out request to the account as well. To learn more about Global Privacy Control, you can visit https://globalprivacycontrol.org/. Other than the Global Privacy Control, we do not recognize other "Do Not Track" signals that may be sent from your web browser or device.
- Right to Opt out of Biometric Data Collection. You may revoke your consent to biometric data collection at any time through the Dozzi App Settings or by contacting us. This will disable Smart Mode alert routing.
- Managing Communication Preferences. We may send you promotional emails, and you may opt out of receiving these at any time by using the unsubscribe option displayed in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your account or orders that you have made.
You may exercise any of these rights where indicated on the Services or by contacting us using the contact details provided below. We will not discriminate against you for exercising any of these rights. We may need to verify your identity before we can process your requests, as permitted or required under applicable law. We will respond to your request in a timely manner as required under applicable law.
International Transfers
Please note that we may transfer, store and process your personal information outside the country you live in. If we transfer your personal information out of the European Economic Area or the United Kingdom, we will rely on recognized transfer mechanisms like the European Commission's Standard Contractual Clauses, or any equivalent contracts issued by the relevant competent authority of the UK, as relevant, unless the data transfer is to a country that has been determined to provide an adequate level of protection.
Complaints
If you have complaints about how we process your personal information, please contact us using the contact details provided below. Depending on where you live, you may have the right to appeal our decision by contacting us using the contact details set out below, or lodge your complaint with your local data protection authority.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on this website, update the "Last updated" date and provide notice as required by applicable law. For material changes affecting the Dozzi App, we will also notify you through the App or via email.
New Uses of Information. If we wish to use your personal information for a materially new purpose not described in this Privacy Policy, we will update this Privacy Policy and, where required by law or where the information is sensitive (including biometric, health, or children's information), obtain your additional consent before applying the new use to information collected before the change. We will not retroactively apply a new purpose to previously collected information in a manner inconsistent with the promises in effect when it was collected. When we first apply newly broadened research, analytics, or de-identified-data uses to information collected before the effective date of this update, we will notify active users in advance through the App or by email.
Contact
Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please call or email us at info@dozzisleep.com or contact us at 5900 Balcones Drive, STE 100, Austin, TX 78731, US.