← Back to site

Important Medical Disclaimer

Dozewise provides CBT-I based sleep improvement tools for educational purposes only. It is NOT a medical device and does NOT diagnose, treat, or cure insomnia or any medical condition.

The Cognitive Behavioural Therapy for Insomnia (CBT-I) content within Dozewise is self-guided, educational, and for general wellness purposes. It is not a substitute for professional medical care.

Always consult a qualified healthcare professional — including a GP, sleep specialist, or registered psychologist — before beginning any sleep programme, especially if you have a diagnosed sleep disorder, mental health condition, or other medical condition.

In the case of a medical emergency, contact emergency services immediately (000 in Australia).

Privacy Policy

Effective date: 21 March 2026  ·  Last updated: 18 April 2026  ·  Version 2.1

Short version: Your CBT-I data, sleep diary, and all personal health information stay encrypted on your device. We cannot read it, sell it, or lose it in a breach — because personal sleep logs are not readable by us.

1. Introduction

Dozewise is a sleep improvement app for adults dealing with insomnia, incorporating evidence-based Cognitive Behavioural Therapy for Insomnia (CBT-I) principles. We understand that data about sleep difficulties and insomnia is health information and warrants the highest level of privacy protection.

Our commitment is structural: your personal sleep data, CBT-I progress, and all health information in Dozewise lives on your device only. Our servers have never received it and cannot receive it. This Privacy Policy explains how that works, what minimal data we do handle, and your full rights under Australian law. Dozewise is a brand of Sleep Portfolio, Queensland, Australia.

2. Health Data — Why Privacy Matters Most Here

Dozewise handles data that intersects with personal health: sleep difficulties, insomnia patterns, anxiety and arousal scores (as used in CBT-I assessment), and therapeutic progress. We take a deliberately conservative approach for two reasons:

  1. Legal obligation. Under the Australian Privacy Act 2024, health information is a category of "sensitive information" requiring heightened protections.
  2. User trust. People seeking help with insomnia should not have to worry about their health data being held by a third party, sold, or exposed in a breach. Our zero-knowledge architecture removes that risk at a technical level.

3. Zero-Knowledge Architecture

Your insomnia history, sleep diary, CBT-I session progress, and all related health data stays on your device. We do not have it. We cannot access it.

4. Health Information — Heightened Protections

Dozewise data about sleep difficulties and insomnia is classified as health information under the Privacy Act 2024 (Cth), which requires elevated protection. Our compliance measures:

5. Data We Collect and Store

5.1 On-Device Data (Never Transmitted to Our Servers)

None of this data is ever transmitted to Dozewise servers. We have no access to it.

5.2 Data Transmitted to Our Servers

DataWhenWhyStored?
Anonymous AI Coach request (no PII — e.g. "adult managing insomnia, week 3 CBT-I programme")When you use AI CoachTo generate a relevant responseNo — discarded after response
Anonymous analytics event (e.g. "module_completed")During app useTo understand feature engagementYes — no PII attached
Push notification device tokenWhen you enable notificationsTo send remindersYes — token only
Account email addressAt account creation (optional)For account recoveryYes — encrypted at rest
Website waitlist: email, first name, last name, country, and city or regionWhen you submit the join-waitlist form on dozewise.comTo send launch and beta updates and for light-touch regional planningYes — in our secure database (encrypted at rest). Not used for AI Coach prompts and not sold to third parties
Subscription statusVia RevenueCat/Apple/GoogleTo unlock premium contentNo — RevenueCat is source of truth

5.3 Analytics

Analytics events contain: a random session identifier (not linked to your identity), event type (e.g. "module_completed"), timestamp, device type and app version. They do not contain your name, email, sleep data, health information, CBT-I data, or any identifying information.

6. CBT-I Programme — Data Architecture

The CBT-I programme involves guided sessions, sleep diaries, and therapeutic exercises. All programme data — including your progress through modules, sleep diary entries, and thought restructuring records — is stored exclusively on your device.

The AI component works as follows: your device sends the AI only a de-identified, contextual summary (e.g. "user is in Week 3 of sleep restriction, has not logged difficulty with rising time"). No diary content, no thought records, no personal identifiers are transmitted.

The CBT-I approach within Dozewise is designed to support self-directed behaviour change. It is not a medical device and does not constitute medical advice or treatment. Please see the medical disclaimer at the top of this document.

7. On-Device Storage and Encryption

All data is stored in an encrypted SQLite database using AES-256 encryption. The key is held in your device's secure enclave (iOS) or Android Keystore (Android) and is never transmitted anywhere. Deleting the app permanently and irrecoverably deletes all on-device data. We hold no copy.

8. Optional Encrypted Backup

9. AI Sleep Coach

The AI Sleep Coach is powered by the Anthropic API (Claude). When you interact with the Coach:

Anthropic's privacy policy: anthropic.com/privacy

10. Push Notifications

When you enable notifications, we store your device push token to deliver reminders (sleep diary prompts, module reminders, bedtime alerts). Push tokens are not linked to your personal identity. Disabling notifications triggers deletion of your push token from our servers.

11. Payments

Consumer subscriptions are processed through Apple App Store or Google Play, managed by RevenueCat. Dozewise never sees or stores your payment card details.

12. Third-Party Services

ServicePurposeData Shared
Anthropic (Claude API)AI CoachAnonymous, non-identifying request text
Apple APNsPush notifications (iOS)Device push token
Google FCMPush notifications (Android)Device push token
RevenueCatSubscription managementAnonymous user ID, subscription events
Apple App Store / Google PlayIn-app purchasesGoverned by Apple/Google
ResendTransactional email (e.g. waitlist confirmation)Your email address; standard template content only
SentryError reportingAnonymous error logs, no PII

13. Your Rights

Because your CBT-I data, sleep diary, and all health information are stored exclusively on your device, you already have complete control. You can view, export, and delete everything directly within the app.

Australian Privacy Act 2024 — Health Information

Dozewise acknowledges that on-device data constitutes "health information" under the Privacy Act 2024. We respect your rights:

Dozewise acknowledges the Privacy Act 2024 statutory tort for serious invasions of privacy and is committed to compliance with the Australian Privacy Principles (APPs).

GDPR — Special Categories of Data

Under GDPR Article 9, health data is a "special category". Dozewise's zero-knowledge architecture means health data is never processed by our servers, removing the Article 9 compliance burden from our server-side operations. For the minimal server-side data we hold, your GDPR rights include access (Art. 15), rectification (Art. 16), erasure (Art. 17), portability (Art. 20), restriction (Art. 18), and objection (Art. 21). Contact sleepportfolio@gmail.com — we respond within 30 days.

14. Right to Erasure — Account Deletion

To request deletion of your account and all server-side data:

We will process deletion requests within 30 days.

15. Data Retention

Data TypeRetention
On-device sleep diary and CBT-I dataIndefinite — you control this; deleted when you delete the app
Account emailUntil account deletion
Website waitlist (email, name, country, city)Until you request removal or unsubscribe from waitlist email; contact sleepportfolio@gmail.com
Push tokenUntil notifications disabled or account deleted
Anonymous analytics24 months rolling, then automatically deleted
AI Coach message hashes12 months, then automatically deleted

16. Children

Dozewise is designed for adults aged 18 and over. We do not knowingly collect personal information from individuals under 18. If you believe a person under 18 has registered, contact sleepportfolio@gmail.com and we will delete the account within 48 hours.

17. Security

18. Changes to This Policy

We will provide at least 30 days' notice of material changes via in-app notification. The "Last updated" date reflects the most recent revision.

19. Contact

Privacy enquiries and rights requests:
sleepportfolio@gmail.com

Postal address:
Dozewise Privacy Officer (Sleep Portfolio)
Queensland, Australia

OAIC: oaic.gov.au  ·  1300 363 992