Privacy Policy
Effective date: 29 August 2026; Last updated: 29 August 2026
Somnus is published by Somnus Health Pty Ltd (ABN 40 162 093 969), a company registered in Queensland, Australia. I'm Dr Paul Martin, the company's sole director & employee, and the solo developer/designer of Somnus. In this policy, "I", "me" and "my" refer to Somnus Health Pty Ltd, and "you" refers to the user of the Somnus app — typically a clinician. For any privacy-related question, contact me at privacy@somnusapp.com.
Somnus is built so that clinical data you enter never leaves your device unless you choose to export it, or you enable iCloud sync — in which case it goes directly from your device to your own private iCloud account. I do not operate any servers that receive, store, or process your clinical data, and I have no ability to access it. Because of this design, you are the data controller for any patient or clinical information you record in Somnus. Compliance with privacy and health-records legislation in your jurisdiction (for example, the Privacy Act 1988 (Cth) and applicable state health-records legislation in Australia, HIPAA in the United States, or the UK and EU GDPR) is your responsibility as the clinician using the app.
I do not collect personal information about you as the user of the app unless you contact me. There is no account registration, no identifier assigned to you, and no collection of your name, email, location, device identifiers, or usage analytics by me directly.
Clinical and patient data you enter into the app is never received, seen, or stored by me. It is held locally on your device, and — if you enable iCloud — synced to your private iCloud account using Apple's CloudKit. I do not use shared or public CloudKit containers.
If you enable location features, your device compares your current GPS position with locations you have saved in Somnus. This comparison happens entirely on your device, and no location data is transmitted to me.
If you have opted in to "Share with App Developers" in your iOS, iPadOS, or macOS settings, Apple provides me with aggregated, de-identified analytics such as crash counts, retention, and device type breakdown. I cannot identify individual users from this data, and you can revoke it at any time in your device settings. Somnus contains no third-party analytics, advertising, or tracking SDKs.
If you email me for support, I will have your email address and the contents of your message. I use these only to respond to you and resolve your enquiry, and I do not add you to any mailing list.
My website at somnusapp.com is hosted on Squarespace, which sets cookies for basic site functionality and aggregate visitor analytics. Submissions via the contact form are sent to me by email. See Squarespace's privacy policy for details of their processing.
If you enable iCloud sync, your Somnus data is synchronised to your personal iCloud account. This is a direct relationship between your device and Apple — I am not a party to it. Apple encrypts this data in transit and at rest (minimum AES-128), access is controlled by your Apple ID credentials, and I have no access to your iCloud container. For details of Apple's handling of iCloud data, see apple.com/legal/privacy.
Somnus' AI features - such as Theatre List Import and Label Analysis - run entirely on your device by default. Nothing they process is sent to me or to anyone else. If you have a Somnus Pro subscription and are running iOS 27 or later, you can optionally switch AI Processing to Apple's Private Cloud Compute in Settings → Pro Features. When you do, the content these features process - text, and for photo-based imports the photographs themselves, which may include patient information - is sent to Apple's Private Cloud Compute servers, which may be located outside Australia. Apple states this data is encrypted in transit, used solely to fulfil your request, never stored, never accessible to anyone (including Apple), and never used to train models, with these protections cryptographically enforced and open to independent inspection (see security.apple.com/blog/private-cloud-compute). I never receive, see, or store any of this data. The feature is off by default, is explained in the app before you can enable it, and automatically falls back to on-device processing whenever Private Cloud Compute is unavailable. If you handle patient information, enabling this feature is your decision as the treating practitioner, and you remain responsible for ensuring it is consistent with your obligations under the Privacy Act 1988 (Cth), applicable state and territory health records legislation, and any policies of your hospital or employer.
Any export, backup, or report you generate from Somnus is created on your device and saved or shared by you. Once an export leaves the app — for example by AirDrop, email, cloud storage, or being saved to Files — its handling and security become your responsibility. You should ensure exports containing patient information are handled in accordance with your professional and legal obligations.
Somnus is a professional clinical tool intended for use by registered healthcare practitioners. It is not directed at, or intended for use by, children under 16, and I do not knowingly collect personal information from children.
Somnus is sold worldwide via the Apple App Store. Because I collect no personal data from you through the app, no international transfer of your personal data occurs as a result of using Somnus. The one exception is the optional Private Cloud Compute feature described above: if you choose to enable it, the text processed by Somnus' AI features is sent to Apple servers that may be located outside Australia, under the protections described in that section. This never happens by default and requires your explicit opt-in within the app. If you contact me by email from outside Australia, your message will reach me in Australia, and by emailing me you consent to that transfer. For users in the EU and UK, I do not process personal data in a manner that engages the GDPR or UK GDPR with respect to the app itself. Where I do hold limited information such as support email correspondence, my lawful basis is legitimate interest in responding to your enquiry, and you may request access to, correction of, or deletion of that correspondence at any time by emailing privacy@somnusapp.com.
Because I hold essentially no personal data about you, most rights of access, correction, and deletion under the Privacy Act 1988 (Cth), GDPR, UK GDPR and similar laws are exercised by you directly on your own device and within your own iCloud account. For the limited information I may hold, such as support emails, you may contact privacy@somnusapp.com to request access, correction, or deletion.
In the unlikely event of a data breach affecting information I hold about you, I will notify affected users and, where required, the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.
If you have a concern about how I have handled your information, please contact me first at privacy@somnusapp.com. Australian users who remain dissatisfied may lodge a complaint with the OAIC at oaic.gov.au. EU users may lodge a complaint with their national data protection authority, and UK users may complain to the Information Commissioner's Office.
All names and patient identifiers shown in App Store screenshots, the website, and marketing material are fictional. Any other potentially identifying imagery has been blurred or removed.
I may update this policy from time to time. The "Last updated" date at the top will reflect the most recent change, and material changes will be highlighted on this page for at least 30 days.
For any privacy enquiry, contact Somnus Health Pty Ltd, ABN 40 162 093 969, at privacy@somnusapp.com or PO Box 213, Toowong, Queensland, 4066, Australia.
