Privacy Policy
Last updated: September 2026
Softspoken (Slow Sleep Stories) has no accounts and no sign-in. What you listen to, where you stopped, and how you like things set up live on your device and in your own private iCloud. Our servers hold nothing about you, with one exception you choose yourself: if you ask to hear about new content, we store a push token that is linked to nothing else.
Who we are
Softspoken is provided by Arcmill AB, Sweden, the data controller under GDPR. For privacy questions, or to exercise any of the rights described below, write to support@chanflow.app.
No accounts, no user database
There is no sign-up and no login. We never ask for your name, email address or phone number, and we keep no user record of any kind — there is no user table in our systems, so there is nothing for us to link anything to.
Your subscription is verified on your device by Apple's StoreKit. Apple handles the purchase, restores and refunds. We never see your payment details or your Apple Account, and we store no receipts.
What stays on your device
This is the app's memory, and it never reaches us. It lives on your device and, if you use iCloud, syncs to your own private iCloud database, where Apple is the processor and we have no access:
- Listening progress: your position in every book, Ramble and Small Talk.
- Listening history: the nights you listened, including where you drifted off, so a story can pick you back up.
- Preferences: sleep timer, mixer levels, resume behaviour, bedtime, reminder time and your downloads.
- Downloaded audio: kept encrypted in the app's own storage.
Deleting the app removes all of it from the device. "Erase everything", under Privacy in the You tab, removes it from the device and from your private iCloud in one step.
Sleep times from Apple Health
If you already track sleep with an Apple Watch or a similar device, you can let the app read your sleep times from Apple Health. They are used for exactly one thing: placing the moment you fell asleep more precisely, so the story resumes where you actually left it.
- Access is read-only. We never write anything to Apple Health.
- The reading happens on your device and the data never leaves it. It is never sent to us and never included in any report.
- It is optional. Declining, or revoking it later under Settings, Privacy & Security, Health, changes nothing else about the app.
The one thing our servers can hold
If you opt in to hearing about new content, your device sends us a push token: the anonymous address Apple's notification service uses to reach that one installation. We store it with the platform, the notification environment, your device language and the date it was registered, so an announcement can go out in a language you read. It is linked to no identity, no listening data and no other record.
You can remove it whenever you like:
- Turn the new-content toggle off under Notifications in the You tab, and we delete the token. If an announcement happens to be going out at that moment, the copy that send is working from is replaced by a one-way fingerprint as soon as it finishes, so nothing readable is left behind.
- Delete the app, and the token stops working; the next time we send an announcement, Apple tells us the token is dead and we delete it.
Bedtime reminders and any other nudge you see are scheduled by the app on your own device as local notifications. They never involve our servers, so what you listen to, and when, never reaches us.
What we do not do
- No analytics or attribution SDKs in the app, and no advertising identifiers.
- No microphone and no camera. The app never listens to your room.
- Nothing from the phone's motion sensors leaves the device. They are read only to tell whether the phone is lying flat or in your hand, so a cue can be gentle rather than abrupt, and that reading is never stored or sent.
- We retain no IP address from the app. Our anonymous endpoints are rate-limited in memory to blunt abuse, and no request log identifying a device is written to any database.
- No profiling and no automated decision-making.
- No advertising, and no selling or sharing of personal data. There is nothing here to sell.
Processors
- Apple (StoreKit, CloudKit, HealthKit, Apple Push Notification service): subscription verification, your private iCloud sync, on-device access to your sleep times, and delivery of the announcements you opted in to. Apple's own privacy policy governs what Apple does.
- Cloudflare (Workers, D1, R2, CDN): hosts the catalogue, the audio, these pages and the push-token store, and serves what the app asks for.
- Sentry (error monitoring, our servers only): receives a technical report when one of our servers hits an error — the request path and method, the error message and the user-agent string. It receives no identifiers, no listening data and no sleep data. The app on your phone contains no error-reporting or analytics SDK at all.
Where data is handled
Cloudflare runs a global network and Sentry processes error reports in the United States, so the technical data described above may be handled outside your country. It carries no identifiers. We use only processors that maintain appropriate safeguards for such transfers.
How long anything is kept
- Push tokens: kept while you stay opted in. Deleted when you switch the toggle off, and deleted the next time an announcement goes out if Apple tells us the token is dead.
- Backups: our database backups include the push-token table. Daily backups age out after 7 days, weekly backups after 30 days, monthly backups after 365 days, and weekly media backups after 90 days. A token you removed may survive in a backup until that backup ages out.
- Everything else: there is nothing else. No account, no profile and no listening record on our side, so nothing has to age out — it was never written.
Lawful basis
Where GDPR applies:
- Consent covers the parts you switch on yourself: announcements about new content, and reading your sleep times from Apple Health. You can withdraw either at any time, in the app or in system settings.
- Legitimate interest covers keeping the service reliable and unabused: error reports that carry no identifiers, and the rate limits that protect our anonymous endpoints.
Your rights
Under GDPR you have rights of access, rectification, erasure, restriction, objection and portability. We would rather tell you plainly how little there is to exercise them on than imply a process we do not run:
- Access and portability: we hold no personal data about you to hand over. Everything the app knows sits on your device and in your private iCloud, both of which are already yours.
- Erasure: there is no account to delete and nothing on our servers to erase. "Erase everything" clears the device and your private iCloud copy; switching new-content notifications off deletes the push token, the only thing we could hold.
- Sleep times: revoke access under Settings, Privacy & Security, Health at any time.
- Complaints: you may lodge a complaint with your data-protection authority. In Sweden that is Integritetsskyddsmyndigheten (IMY).
- Anything else: write to support@chanflow.app and we will answer.
Children
The app is not directed at children under 13, and we knowingly collect nothing from them. Since we collect no personal data at all, there is no child's data in our systems either.
Changes to this policy
If this policy changes, the copy here and the copy inside the app are updated together and the date at the top moves. Anything material is pointed out in the app.
Contact
Questions about this policy: support@chanflow.app