k-level Logo
Support

Privacy Policy for Battle Sleep

This policy covers the Battle Sleep mobile app. For the k-level.xyz website (including waitlists and cookies), see our website privacy policy.

Last updated: September 2026

App: Battle Sleep (formerly Sleep With Me)

Package ID: xyz.klevel.sleepwithme

Publisher: k-level.xyz (Joshua Krause)

Summary

Battle Sleep is a sleep league app. You create an account with email and password. Challenges, invites, extracted sleep fields, scores, display names, and the world board sync through our database (Supabase). Sleep screenshots stay on your device. To read a screenshot, the app sends the image to Google Gemini and stores the extracted fields, not the original vendor score. Optional morning reminders run locally. Challenge events can use Expo push notifications. Stake text is free text only. The app does not process payments. The current app release does not include third-party analytics or crash reporting. Website waitlist emails are covered by the separate website privacy policy.

1. Who we are

Controller: Joshua Krause (k-level.xyz), Waldstr. 93, 47057 Duisburg, Germany. Privacy contact: privacy@k-level.xyz. Support: support@k-level.xyz. This policy covers the Battle Sleep mobile application only (package xyz.klevel.sleepwithme).

2. Account

Battle Sleep requires an account for invites, challenges, and the world board. We process:

  • Email address and password (authentication via Supabase Auth)
  • Display name
  • Account identifiers and session tokens stored on the device
  • Optional Expo push token so challenge events can reach your device

You can sign out, change your display name, or delete your account in the app (Danger Zone). Account deletion removes your profile and related cloud league data we control. Copies held by Google for Gemini requests follow Google’s retention rules.

3. Data we store on your device

The app also keeps a local copy (AsyncStorage via Zustand, plus screenshot files). Depending on use, this may include:

  • Challenges, member names, dates, and stake text
  • Confirmed nights: extracted fields, Battle Sleep score, check-in timing, local screenshot file paths
  • Theme, morning reminder time, and info-hint flags

Local data remains until you delete it in the app, clear app storage, or uninstall. Screenshot image files are written to app storage on the device.

4. Data we store in the cloud

When Supabase is configured (production builds), Battle Sleep syncs league data to a database we operate through Supabase. That includes profiles, challenge metadata, invite emails you enter, member status, extracted night field JSON, scores, check-in timing, moons totals, and world-board aggregates.

Screenshot image files are not uploaded to k-level.xyz or Supabase Storage in this version. The cloud night record may store local file path strings, extracted fields, and scores.

Other signed-in users can see your display name and average score on the world board. Challenge partners see your display name, nights, scores, and any stake text you share in that challenge.

5. Screenshots, camera, and photo library

To check in a night, Battle Sleep asks for photo library access and, if you photograph a screen, camera access. You choose the image. It is used only to enter that night into the league.

  • Bedtime and wake time
  • Total sleep duration
  • Deep sleep and REM minutes
  • Optional extra fields such as awake minutes, tracker source, and screenshot night date
  • Internal authenticity signals used to reduce manipulated screenshots

The vendor sleep score shown on the screenshot is ignored as a number. Battle Sleep computes its own 0 to 100 score from the raw fields.

Without photo permission you cannot complete a screenshot check-in. You can still use account, challenges you already have, and settings.

6. Optional AI reading (Google Gemini)

When a Gemini API key is configured in the app build, Battle Sleep sends the screenshot (image bytes) over HTTPS to Google’s Generative Language API so Gemini can read the sleep fields. Google processes that content under its own terms and privacy policy. We do not sell screenshots or use them for advertising. Do not upload images you are not willing to send to Google for this purpose. If Gemini is unavailable, the check-in cannot be auto-read.

7. Notifications

If you enable reminders and grant notification permission, Battle Sleep may:

  • Schedule a local morning reminder on the device (no k-level push server for that alert)
  • Register an Expo push token on your profile so challenge events (invite accepted, stake updates, challenge ended) can notify you

Push delivery uses Expo’s notification service. You can disable notifications in system settings. You can turn the morning reminder off in the app.

8. Stakes and payments

Stake prompts are free text that you and the other person type. Battle Sleep does not take money, run payments, or hold a wallet. Do not put payment credentials into stake fields.

9. Network use

  • Account, sync, invites, and world board via Supabase
  • Screenshot reading via Google Gemini
  • Optional Expo push token registration and challenge push
  • Opening this privacy policy, support email links, or other URLs you choose

Without a network connection, local data may still be visible. Sync, invites, world board, and Gemini reading need a connection.

10. Analytics and crash reporting

The current Battle Sleep app release does not include third-party analytics or crash-reporting SDKs (for example no PostHog or Sentry in the app).

11. Children

Battle Sleep is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has created an account, contact privacy@k-level.xyz so we can delete it.

12. Website waitlist (not stored in the app)

If you join the Battle Sleep waitlist on k-level.xyz, your email is processed by our website stack (Resend) under the website privacy policy. That email is not written into the Battle Sleep app database unless you later create an account with the same address.

13. Legal bases (EEA/UK users)

Where the GDPR applies, we rely on:

  • Art. 6(1)(b) — providing the account, challenges, check-ins, and world board you request
  • Art. 6(1)(a) — consent where required (camera and photo permissions, website waitlist, optional notifications)
  • Art. 6(1)(f) — legitimate interests in running a fair league (including authenticity checks) and keeping the service secure, balanced against your rights

Google and Supabase may process data outside the EEA. Where applicable, such transfers rely on their contractual safeguards with customers (including Standard Contractual Clauses).

14. Retention

Cloud league data remains until you delete your account or we delete it after a support request. On-device data remains until you wipe it, clear storage, or uninstall. Gemini prompts follow Google’s retention rules. Waitlist emails are retained until you ask us to remove them or we close the waitlist.

15. Your rights and choices

  • Deny or revoke camera, photo, or notification permissions in system settings
  • Skip uploading a screenshot so that image is never sent to Gemini
  • Edit display name; leave or delete challenges you host, where the app allows it
  • Delete local data or delete your account in Danger Zone
  • For waitlist emails, account deletion help, or other privacy requests: privacy@k-level.xyz
  • EEA/UK users may also lodge a complaint with a supervisory authority

16. Security

Accounts use hashed passwords via Supabase Auth. Device security (screen lock, OS updates, who can unlock your phone) protects on-device screenshots. No method of electronic storage is perfectly secure.

17. Changes

We may update this policy when the product or legal requirements change. The Last updated date will change accordingly. Material changes for store users may also be reflected in release notes or in-app notices.

18. Contact

Privacy questions: privacy@k-level.xyz
General support: support@k-level.xyz