Alarmy - Loud alarm clock Security & Privacy Scorecard
by Delight Room Co., Ltd. · iOS
Standard usage and device data may be shared with the app developer and integrated services. The breakdown below lists the data types and third parties involved.
Best for
General use with standard privacy expectations
Findings
- 0 critical
- 1 high
- 6 medium
- 8 low
- 12 info
1 issue identified across security and privacy analysis.
Top security issues
- Hardcoded HMAC API Request Signing Keys in Production Binary
- ATS Globally Disabled — All Domains Exempt from HTTPS Enforcement
- Realm Primary Database Has No Visible Encryption Configuration
Top privacy issues
- NSPrivacyTracking and Tracking Domains Missing from Main App PrivacyInfo.xcprivacy
- Dual Consent Management Platforms Create IAB TCF Signal Conflict
- ATT Permission Description Uses Consequence-Framing
Full analysis
<!-- TRUSTEDVERDICTHEADER -->
Did not meet TRUSTED criteria
The app was assessed and did not meet all of the criteria for the TRUSTED mark. The specific items are listed below so the result can be weighed before installing.
Trust Pillars
- Secure by Design: Not met. Did not meet one criterion in this area.
- Data Respect: Not met. Did not meet one criterion in this area.
- Honest Experience: Not met. Did not meet one criterion in this area.
- User Control: Strong. Strong result in this area.
- Child-Safe: Not applicable. Does not apply to this app.
<!-- /TRUSTEDVERDICTHEADER -->
Security & Privacy Scorecard
Alarmy
What This Means for You
Behavioral data and device information are shared with more than 30 advertising and analytics services. Sleep recordings and snoring audio are processed on the device and stay there.
Recommendation: Solid
Reliable alarm and sleep tracker with strong core features. Heavy ad and analytics integration means behavioral data is broadly shared across advertising and analytics partners. Best for casual users; those prioritizing data privacy should consider alternatives.
Best For: Casual users who want reliable alarm and sleep tracking features and are comfortable with an ad-supported model that shares usage data with multiple advertising partners.
Key Findings
Data Security: 1 finding (1 medium)
Network Security: 1 finding (1 low)
Code Safety: 1 finding (1 high)
Privacy: 1 finding (1 low)
Privacy Concerns
What Data is Collected
- Sleep and snoring audio: processed on the device and stays there
- Sleep stage history and alarm records: kept on the device in local storage
- Behavioral usage data (app interactions, alarm patterns): shared with analytics and advertising partners
- Device information (device identifiers, operating system): shared with advertising and analytics services
- Account information (email address): used for account management and may be shared with payment processors
Third-Party Data Sharing
Third parties that may receive data from the app:
Google (Firebase Analytics, Firebase Crashlytics, Firebase Remote Config, Firebase Messaging, Google AdMob) - analytics, crash reporting, advertising, and push notifications
Meta Audience Network - advertising
Amplitude - behavioral analytics
Snowplow (developer-operated infrastructure) - event analytics
Airbridge - attribution and marketing analytics
Braze - user engagement and messaging
AppLovin MAX, Unity Ads, Vungle/Liftoff, Mintegral, Chartboost, TikTok Pangle, InMobi, Fyber/Digital Turbine, Moloco, PubMatic OpenWrap, Amazon TAM, HyBid/PubNative, BidMachine, FiveAd, Daro Ads - advertising and ad mediation
Open Measurement SDK - ad measurement
Stripe - payment processing
RevenueCat - subscription management
Zendesk - customer support
Datadog - infrastructure monitoring
Didomi / Google UMP - consent management
hCaptcha - bot protection
Understanding the Scores
Security: 84/100
Privacy: 72/100
Security Breakdown
Data Security: 50/100. Sleep history, snoring records, and alarm behavioral data appear to be stored in local databases without explicit encryption configured, leaving this data readable from device backups or after a device's first unlock.
Network Security: 62/100. Ad content may load over unencrypted connections through bundled advertising SDKs, and the app's connection settings appear to allow unencrypted traffic more broadly than just ad delivery.
Code Safety: 85/100. Core application code is well-structured and shows solid engineering practices. The lottery feature includes hardcoded request-signing secrets that could be managed more securely through external configuration.
Privacy Breakdown
Data Collection: 72/100. Sleep audio and snoring recordings stay on the device. Behavioral usage data, device identifiers, and interaction patterns are shared with a large number of advertising and analytics partners as part of the ad-supported model.
Data Sharing: 72/100. Data flows to more than 30 third-party services spanning analytics, advertising, attribution, and infrastructure. The developer runs its own Snowplow analytics infrastructure, which limits external exposure for some event data.
User Control: 78/100. The app includes consent management tools (Didomi and Google UMP) to manage advertising preferences. European users benefit from Amplitude data routing to EU-based servers.
Positive Security Features
Keychain items are set to device-only protection, keeping sleep schedule data from syncing to iCloud or other devices
Facebook automatic event logging is disabled, limiting unsanctioned behavioral data forwarding to Meta
Amplitude analytics for European users routes to EU-based servers, supporting data residency
Event analytics flow through developer-operated Snowplow infrastructure rather than a third-party collector
TikTok tracking is currently fully disabled despite the SDK being present in the binary
Payment data is processed via Stripe with local encryption applied before transmission
Areas for Improvement
GDPR / CCPA Compliance
The app's privacy practices could be strengthened by:
Full Disclosure of All Data Collection Destinations
A telemetry domain with private registration appears in the binary but is not documented in the published privacy policy. Disclosing all data collection destinations publicly would improve transparency and alignment with GDPR and CCPA requirements.App Privacy Manifest Completeness
Adding a comprehensive app privacy manifest could make the App Store privacy label more complete and give users a clearer picture of all tracking domains in use.
Security Enhancements
Health Data Storage Encryption
Sleep history, snoring records, and alarm behavioral data could be better protected by applying explicit encryption settings to local database storage, reducing exposure if a device backup is accessed by an unauthorized party.Secure Ad Content Delivery
Ad SDK resources that may load over unencrypted connections could be hardened by configuring SDKs to enforce secure delivery for all ad creative assets, reducing exposure on untrusted networks.
Technical Context
App Type: Sleep tracking and smart alarm (health, sensitive data, ad-supported)
Classes Analyzed: 0 (iOS binary analysis)
Third-Party Services: 35 identified
Context Tags: health, ads, sensitive_data
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is a static review of the iOS application binary, intended to help people make informed decisions about app security and privacy.
App Details
Developer: Delightroom
Version: 26.31.0 (build 7161734)
Analysis Date: 2026-07-23
Package: droom.sleepIfUCanFree
Analysis Limitations
- Static analysis only (review of the app binary without running the app)
- Based on version 26.31.0 analyzed on 2026-07-23
- May not reflect server-side security controls
- Cannot detect all runtime behaviors
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #5 (current) | 76/100 | |
| #2 | 59/100 |