Privacy
For the Sotto app for iPhone and this website. Effective 4 October 2026.
- In short
- What stays with you
- Usage statistics
- Weekly progress, if you choose
- Ask
- Purchases
- iCloud
- When you write to us
- This website
- Who processes data
- How long we keep it
- Your rights
- Children
- Changes
Aiden Buis makes Sotto in the Netherlands and is the controller of the data described here under the EU General Data Protection Regulation (GDPR). “We” in this policy means him. For anything about your data, write to hello@getimaginalis.com. If you live in the United States, our consumer health data policy applies too.
In short
- There’s no account to make. Your diary lives on your iPhone and in your own iCloud. We never see it.
- The app sends usage statistics to PostHog, on its servers in the EU. They carry a random ID and no health value: no pauses, no pulse, no answers about your health, no words. Only if you turn on weekly progress does a rounded weekly change of your pause go with them. You can turn them off in Settings › Privacy.
- Ask, the app’s question box, is the one place your practice log leaves your devices. Only after you agree, it sends your question and a summary of your diary to DeepSeek, an AI service in China, through our server. DeepSeek gets no name, account, ID or IP address.
- Apple takes your payment. RevenueCat checks your purchase for us, so the app knows you’re a member.
- We show no ads, we don’t track you across other apps or websites, and we don’t sell your data.
What stays with you
Your diary. Your pauses, your pulse, your sessions, your night and day logs, your notes, your plan, your questions to Ask with their answers, and where you are on the Path all live on your iPhone, in a file iOS keeps locked while your iPhone is locked. If you use iCloud, they sync through your own iCloud account, in the app’s private database there. We have no access to that database, and no servers of our own that hold a copy.
Your answers about your health. The safety questions you answer when you start, and again later, stay on your iPhone and in your iCloud. They never go into the usage statistics. Only the result, one letter for how gently the app should guide you, goes with a question to Ask.
Spoken notes. When you speak a note, your iPhone turns your voice into text on the device. The recording waits on your iPhone until its words are in, and the app then deletes it. Recordings never go to iCloud, to us or to Ask.
Reminders are set on your iPhone, and the answers you give in the introduction are stored there too. The app sends some of those answers with the usage statistics below, never the safety ones.
The lock. If you turn on the lock in Settings › Privacy, iOS checks your face or passcode itself. The app only hears yes or no, never sees or stores your Face ID data, and sends nothing anywhere.
Usage statistics
Unless you turn it off, the app sends short records of what happens in it to PostHog, our analytics service. A record says, for example, that someone opened the Diary, reached a step of the introduction, measured a pause, started a gentle session, finished a lesson or started the free week. With it go the app and iOS version, the kind of device, and a random ID the app makes when you first open it. PostHog keeps a profile for that ID: your answers in the introduction (such as why you’re here and whether you’ve practised before), your reminder settings, whether you’re a member and on which plan, how many lessons you’ve walked, whether Ask is on, and the dates of your first pause, session, note and lesson.
Apart from the weekly progress below, which you have to turn on, the app never sends a health value. No pause or pulse numbers, no results of a session, no answers to the safety questions or the letter they lead to, no symptom scores, no medicines. It never sends the words you write, ask or say. It sends no name, no email address and no advertising ID, it doesn’t record your screen, and it doesn’t know your location. We have set PostHog to drop your IP address and not to work out your location from it.
We use these statistics to find bugs and to see where people get stuck or give up, so we can make the app better. Our legal basis is our legitimate interest in improving Sotto (Article 6(1)(f) GDPR), balanced by the switch that lets you stop it at any time.
The random ID ties your records together, even though we can’t tell who you are. Under the GDPR that makes the data pseudonymous.
To turn it off, tap the gear at the top of Today, then turn off Share usage statistics under Privacy. The app stops sending at once and forgets its random ID. If you turn it back on, it starts again with a new ID.
Weekly progress, if you choose
Settings › Privacy has a second switch, Share my weekly progress. It is off unless you turn it on. When it’s on, and usage statistics are on too, the app sends once a week how much your 7-day morning pause moved, rounded into a 2-second range (such as “0 to 2 seconds up”), and how many weeks of data that rests on. Never the pause itself. It goes with your usage statistics, under the same random ID, so it is pseudonymous like them, not anonymous. It helps us see whether the course works. Because it says something about your health, our legal basis is your explicit consent (Article 9(2)(a) GDPR), which you withdraw by turning the switch off.
Ask
Ask answers your questions about the method from Sotto’s lessons and your own diary. The answers come from DeepSeek, a third-party AI service, on its servers in China. Nothing is sent until you’ve read what Ask shares and tapped “Agree and ask”.
With each question, the app sends:
- your question, and your last three questions with their answers;
- which of Sotto’s lessons it’s about (two to four); our server adds their passages from its own copy of the lessons;
- a summary of your diary, made on your iPhone for that question: your morning pauses of the last 28 days, your 7-day morning number and how it changed, your overnight changes, your resting pulse and your pulse before and after sessions, your sessions of the last 14 days, your plan, your night logs (hours slept, alcohol, a late meal, mouth tape, sleep position, waking in the night, the bedroom), your day logs (a closed mouth, nose exercises, and your scores for nose, sleep, calm and breathing comfort), your notes of the last 7 days (cut to about 1,500 characters), the one-letter result of the safety questions with any safety stops of the last 14 days, and where you are in the course.
It never sends your answers to the safety questions, the medicines you log, Health app data, voice recordings, your name or your location.
The question goes to our server, a Cloudflare Worker. Ask is part of the membership, so the app also sends our server the random ID RevenueCat gave your membership, and our server asks RevenueCat whether that membership is active. It then passes the question on to DeepSeek without that ID, your IP address, an account or a device ID. DeepSeek can’t tell who asked. Our server stores nothing of the question or your diary and logs none of it; it keeps only a scrambled form (a hash) of the membership ID, with the times of your recent questions and RevenueCat’s answer, to limit how many questions one membership can ask, and deletes it a day after your last question. DeepSeek processes the request on its servers in China, under its own terms for its API.
Your questions and answers are saved in your diary, on your iPhone and in your iCloud. Delete them with Delete Ask history in Settings › Ask, or with Delete everything. Turn Ask off in Settings › Ask and nothing more is sent. Our legal basis is your consent, given in the app before the first question and withdrawn by turning Ask off.
Purchases
You buy a membership from Apple, through the App Store. Apple handles the payment under its own privacy policy. We never see your card, your name or the email address of your Apple Account.
RevenueCat runs the membership for us. It receives the App Store record of your purchases (which plan, when it started, renewals, a free week, a cancellation or a refund) together with a random ID it makes for your install. The app uses this to open the membership and to restore it on a new iPhone, and we use it to count trials, renewals and cancellations. Our legal basis is our contract with you (Article 6(1)(b) GDPR): the app needs this record to know you’ve paid.
iCloud
Apple stores your diary in your iCloud account under Apple’s privacy policy. We can’t read it. You can turn iCloud off for Sotto in your iPhone’s settings, and the diary then stays on that iPhone alone.
Delete everything, in the app’s settings, removes your diary from your iPhone and the copy in your iCloud, your Ask history, and the app’s settings. It can’t be undone.
When you write to us
If you email us, from the app or elsewhere, we receive your address and whatever you write, and we use them only to answer you.
This website
This site sets no cookies and runs no analytics, trackers or scripts. Cloudflare hosts it and handles the technical data any web server needs to send you a page, such as your IP address.
Who processes data
These services process data on our behalf:
- PostHog, usage statistics, stored in its EU cloud in Frankfurt, Germany.
- DeepSeek, the answers to Ask, in China. It receives no name, account, ID or IP address.
- Cloudflare, the server between Ask and DeepSeek, and this website. It stores nothing of your questions; for a day, a hash of the membership ID with the times of recent questions.
- RevenueCat, purchases, and the membership check before Ask answers, in the United States. Transfers there rely on the EU’s Standard Contractual Clauses.
Apple is not our processor. It provides the App Store and iCloud to you directly, under Apple’s privacy policy.
How long we keep it
- Usage statistics stay in PostHog for the retention period of our PostHog plan, and PostHog then deletes them.
- Ask’s questions are kept by neither us nor our server. DeepSeek handles them under its own API terms. The hash of the membership ID our server limits questions by is deleted a day after the last question.
- Purchase records stay with RevenueCat while you have a membership, and afterwards as long as we need them to handle refunds and questions, unless you ask us to delete them.
- Emails we keep until your question is settled and any follow-up is done. Ask, and we delete them sooner.
- Your diary stays on your iPhone and in your iCloud for as long as you keep it.
Your rights
Under the GDPR you can ask us for a copy of your data, and ask us to correct it, delete it, or limit how we use it. You can object to our use of it, withdraw a consent you gave, and take data you gave us elsewhere. Write to hello@getimaginalis.com and we’ll answer within a month.
The random ID isn’t shown in the app, so we can’t always tell which usage records are yours. Tell us what you’d like and we’ll do what we can. Some things you can do yourself:
- Stop usage statistics with Share usage statistics, and weekly progress with its own switch, under Privacy in the app’s settings.
- Stop Ask in Settings › Ask.
- Take your diary with you: Export, in the Diary or in the app’s settings, gives you a practice log (CSV) or everything (JSON).
- Delete your diary, here and in iCloud, with Delete everything in the app’s settings. More on the support page.
You can also complain to a data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens; elsewhere in the EU, the authority where you live.
Children
Sotto isn’t meant for children under 13, and we don’t knowingly collect data from them. If you think a child under 13 has sent us data, write to us and we’ll delete it.
Changes
When this policy changes, we’ll post the new version here with a new date. If a change affects what the app sends, we’ll also say so in the App Store notes for that update, and Ask will ask for your agreement again.