Privacy Policy for Sleep Diary App
Last Updated: 01/23/2025
1. Introduction
Welcome to the Sleep Diary App, a sleep research and clinical tool developed for research studies and clinics conducted by Dr. Anne Richards at the San Francisco VA Medical Center and the University of California, San Francisco. This Privacy Policy explains how the Sleep Diary App collects, uses, and safeguards data. By using the app, you agree to the terms outlined in this policy.
2. Entity Information
The Sleep Diary App is managed by Dr. Anne Richards and the Richards Lab research team at the San Francisco VA Medical Center and the University of California, San Francisco (UCSF.) For privacy-related inquiries, please contact us at [[email protected]].
3. Data Collection
The Sleep Diary App collects non-personally identifiable data related to sleep behaviors and symptoms for research and treatment planning purposes. Specific details include:
- User-Provided Information: Participants log into the app using a coded ID and user-specific password. These credentials are issued by Dr. Richards or study personnel. It is therefore not possible to utilize the app without a username and password issued by Dr. Richards’ team.
- Sleep Diary Entries: The app collects daily sleep-related assessments (morning and evening). The sleep diary may also collect nighttime information about sleep experiences and behaviors, and/or periodic health surveys, depending on the project the data are being collected for.
- Partner Entries: In projects where bed partners participate, bed partners use a separate version of the app to complete their assessments.
- Reminder Settings: Participants may enable optional reminders to complete assessments.
4. Data Usage and Sharing
- Research Use: Data is used to study sleep patterns, behaviors, and related conditions . For most studies, data are analyzed in the aggregate and are not used to identify individual participants. For clinical treatment studies, Dr. Richards and the research staff may analyze individual data to guide clinical research treatment planning, as per IRB-approved protocols. Only authorized research clinicians are able to link app data to individual users, in accordance with an IRB-approved protocol.
Clinical Use: For clinic use, Dr. Richards and her clinical collaborators may analyze an individual’s data to guide treatment planning, after the individual patient signs a VA or UCSF Release of Information (ROI) form. Only the individual patient’s clinicians, as authorized by the ROI, are able to link app data to individual users.
- Data Sharing: Only authorized personnel have access to the data. For research, data is shared solely with research collaborators as required and within the scope of IRB-approved protocols. For clinic, data is shared solely with patients’ clinicians and Dr. Richards’ app administrators as per the signed release of information (ROI). No data, whether research or clinical, is sold or shared with external parties for commercial purposes.
5. Data Retention and Deletion
- Retention Policy: Research data is retained for the duration of the study and as required by regulatory guidelines. Aggregated, de-identified data may be retained for future research purposes. Data collected in Dr. Richards’ clinic is retained for the duration of treatment, and is deleted upon completion of treatment.
- Deletion Policy: Users may contact Dr. Richards and the research team to inquire about data retention and deletion. Research data must be retained as per UCSF and VA research policy.
6. Data Security
- Data entered into the app is encrypted using Secure Socket Layer (SSL) protocols and stored temporarily on Amazon Web Services (AWS) servers approved by the IRB for UCSF and SFVAHCS. These servers do not store any personally identifiable information (PII).
- Once transferred, data is stored on a password-protected, secure VA server accessible only by authorized personnel.
- Participants are instructed to uninstall the app after completing the study or clinical intervention.
7. App Functionality and Contingencies
- Technical Issues: If the app is temporarily unavailable, participants may complete assessments on paper forms or alternative online platforms (e.g., Qualtrics) approved for the study or clinic in question.
8. Participant Instructions
- Daily Entries: Participants are instructed to log data in the morning and evening, with optional entries at night, depending on the project data are being collected for.
- Periodic Assessments: Some versions of the app include brief periodic surveys to report health symptoms and/or other project-specific details on a weekly basis or other periodic schedule.
- Partner Entries: Bed partners may be invited to complete their own assessments depending on the project.
9. Compliance and Accessibility
- The policy is hosted on a secure, non-editable, and geofence-free URL.
- The app complies with all relevant IRB-approved protocols and applicable privacy regulations (e.g., HIPAA).
10. Changes to This Policy
We may update this policy periodically to reflect changes in app functionality, research goals, or legal requirements. Updates will be communicated via the app and the Google Play Store listing.
11. Contact Information
If you have any questions or concerns, please contact us at [[email protected]].
Thank you for your participation and for supporting our mission to advance sleep health research and clinical practice.