← Back to Breathe

Privacy & Data

Effective 7 July 2026
No account needed — just breathe. Add one only if you want your journal to sync across devices: we store your email solely to sign you in, never sell it, never use it for advertising or third-party tracking, and you can delete it and all your data in one tap.

Anonymous by default

Breathe works fully without an account. When you use it anonymously, your journal, streak, and totals live only in your browser's local storage on this device. That data never leaves your device. We serve no ads, embed no third-party trackers, and run no behavioural analytics.

The one exception: when you finish a session, we add 1 to a plain per-day total of completed anonymous sessions, so we can see roughly how much the app is used without accounts. That is the entire signal — a single daily number. We set no cookie, mint no identifier, and store no IP address, no device details, and no per-person row; the count cannot be tied back to you or to any device. We honour your browser's "Do Not Track" setting, and you can switch even this off on this device by running localStorage.setItem('breathe_anon_optout','1') in your browser console.

If you create an account

Accounts are optional and exist for one reason: to sync your journal across your devices.

Account administration

To run, support, and moderate the service, our authorized administrators can view account information — your email and your synced breathing-session history (protocol, duration, timestamps, counts) — and can remove an account. There is no separate diary or free-text content: the "journal" is simply the log of breathing sessions listed above, so that is the extent of what an administrator can see. This access is limited to signed-in administrators, protected by the same authentication as the rest of the app, and is used only to operate the service — never for advertising, profiling for ads, or sharing with outside parties. Anonymous use (above) involves no account and none of this applies.

Who processes your data

We keep our stack small. Authentication and the synced journal are hosted on Supabase; the app and its functions are hosted on Vercel; magic-link sign-in emails are delivered through our email provider solely to send that link. These providers process data only to run the service, never for their own advertising.

Deleting your data

You are always in control. Anonymous data clears when you clear the journal or your browser storage. If you have an account, you can erase everything — your account and all synced data — in one tap from within the app (the "Delete account & data" action). Deletion is immediate and permanent: your account, journal, and every associated record are removed, and your email is deleted from the authentication store. We keep only a non-identifying audit marker (a salted, one-way hash — not your email or user id) to record that a deletion occurred.

Prefer to have us do it, or don't have access to the app? Email us and we'll delete your account and data.

Your rights

You can access the data tied to your account (it's your journal, shown in the app), export it by keeping your local copy, correct it by editing entries, and delete all of it at any time. For any request, contact us below.

Contact

Questions, or a data/deletion request: ivan.dimitrov28@gmail.com.

Changes

If this policy changes, we'll update the effective date above and, for material changes affecting account holders, note it in the app.