Breathawear
Privacy Policy
Last updated July 24, 2026
This policy explains how Breathawear handles information when you use our current public mobile app, website, and signed-in dashboard.
Information we collect
- Account information: email address, name or display name, account identifier, authentication records, and the preferences you choose.
- Guided-practice information: session start and end times, duration, selected pattern and cue timing, cycles presented by the guide, guide pace, and optional feedback you provide. These values describe the guidance shown by the app; they are not physiological measurements.
- Live simulated breath-mirror information: when you use the signed-in phone-to-web mirror, your phone and browser exchange low-rate simulated timing and control heartbeats through an authenticated private Supabase Realtime Broadcast channel. These heartbeats can include a random stream or viewer identifier, sequence number, timestamp, simulated elapsed time and pace, and active, paused, stopped, watching, or leaving state. The browser recreates the waveform locally from that sparse state. It is simulated, not a physiological measurement, and does not contain a wearable or sensor waveform.
- Local practice-challenge information:the mobile Bet You Can't practice challenge uses a simulated NPC rival and temporary answers, breath-source state, and scores on that phone. The round is unranked, is not matched with another person, offers no wagers or prizes, and is not saved or uploaded.
- Local simulated-breath review information: the mobile simulator can briefly change its generated rhythm and, only after that rhythm settles, offer a local reflection card. The card stores the simulated segment, its timing, and an optional tag you choose. It is demonstration data generated by the app, not a physiological measurement, diagnosis, or sensor reading, and it is not uploaded.
- App and diagnostic information: app events, crash details, and limited technical logs used to secure, operate, and improve the service.
- Service network information: hosting, authentication, and delivery providers may process IP address and basic request metadata needed to secure and provide their services. The public mobile app does not send your device time zone to your Breathawear profile.
The 500 most recent completed guest practices are stored locally on that phone and are not uploaded to Breathawear; older guest entries are replaced as new ones are saved. If you sign in, eligible account and guided-practice records can sync to Breathawear so they remain available in your signed-in history and web dashboard.
The app keeps at most one pending simulated-breath reflection and up to 128 prior reflections for each local account partition on that phone. A newer pending reflection replaces an older unreviewed one and records the older reflection as untagged. Reflections can remain after ordinary sign-out so the same local account can review them later. Delete Forever clears that account's reflection partition while preserving another person's partition on a shared phone; guest deletion clears the guest partition, and uninstalling clears ordinary app-local reflection data.
If a signed-in practice from the web dashboard cannot sync immediately, up to 100 unsynced practice records may be kept temporarily in that browser for account-specific recovery. They remain after ordinary sign-out so the same account can retry without losing the practice. They are removed after confirmed sync, when that account is deleted, or when you clear Breathawear site data in the browser.
Live breath-mirror packets are ephemeral Realtime Broadcast messages and are not written as raw waveform rows in the Breathawear database or added to your practice history. Supabase processes those packets in transit to relay them between sessions authenticated to the same account. A completed guided-practice summary may sync separately under the guided-practice behavior described above.
When browser account deletion begins, that browser temporarily stores the account ID, the exact Breathawear backend identity, and an opaque deletion request capability. This local recovery record prevents another tab or account from taking over the unfinished request and is removed after deletion is confirmed. Clearing Breathawear site data removes the record and may prevent automatic recovery; contact support if that happens while deletion is pending.
Public Store app permissions
The Breathawear app distributed through the Apple App Store and Google Play does not request Bluetooth, nearby-device, location, Apple Health, or Health Connect access. The Store binary does not scan for or connect to a wearable and does not include the prototype BLE transport.
Its current breath features are guided practice, a phone-generated simulated breath, an optional private same-account phone-to-web mirror of that simulation, and a local challenge against a simulated NPC rival. The Store app does not provide measured biofeedback. The browser recreates the simulated waveform locally, so the mirror does not change this permission or measurement boundary.
Separate supervised Review build (not the Store app)
Breathawear may separately distribute a supervised Review build to designated hardware testers. That build is not the app distributed through the Apple App Store or Google Play. It may let a tester explicitly start a foreground scan for their own nearby Breathawear prototype and choose one device.
In the Review build, BLE v1 does not authenticate the device or its owner and does not require pairing or link encryption. Testers should connect only to their own nearby prototype. The Review build subscribes to breathing-related motion from the selected device and does not send Breathawear control or firmware-update commands.
Nearby-device names, process-local identifiers, signal strength, and breathing-related motion samples handled by the Review build remain on the phone for the active foreground connection. They are not saved to practice history, uploaded to Breathawear, sent to the web mirror, or used for human or ranked play. Some older Android versions label the operating-system permission used for Bluetooth discovery as Location; Breathawear does not read, save, or upload the phone's location.
How we use information
- Provide account access, guided practice, local history, and optional cloud sync.
- Relay a low-rate, same-account simulated breath clock so your browser can recreate the live visual locally.
- Run an unranked, unsaved local practice challenge against a simulated NPC rival.
- Offer an optional, local reflection on a clearly simulated change in breathing rhythm.
- Show signed-in guided-practice history in the mobile app and web dashboard.
- Provide optional local reminders and respond to support requests.
- Protect the service, diagnose failures, prevent abuse, and improve reliability.
- Meet legal obligations and enforce our terms.
Sharing and service providers
We do not sell personal information. We use service providers to run Breathawear, including Supabase for authentication, database, account sync, and private Realtime Broadcast; Expo and app-store or operating-system providers for app delivery and local notifications; and Google for Android platform services and, when you choose it, Google sign-in. These providers process information for the services they perform for us and under their own applicable terms.
We may disclose information when required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards.
Data security, retention, and deletion
We use encrypted network connections, authenticated access, and database access controls to protect information sent to Breathawear services. The separate Review build's BLE v1 radio link is not an internet connection and is not authenticated or encrypted by those network safeguards. No system can guarantee absolute security.
We retain account information and associated synced guided-practice records while your account is active or as needed to provide the service. Technical logs are retained only as needed for security, diagnostics, and operations. Information may be retained longer when required for legal, fraud-prevention, or security reasons.
Live simulated timing and control packets are transport messages rather than durable breath-history records. Breathawear does not insert them as raw waveform rows. Basic request, security, and delivery metadata may still be processed as described under service network information and by the providers operating the relay.
You can permanently delete your account and associated user data in the app or request deletion using our account deletion page. Delete Forever in the app also removes its secure credentials and account-linked local data, including that account's local simulated-breath reflections. Uninstalling removes ordinary app-local history, reflections, and cache, but operating-system secure credential storage can persist after uninstall. You can remove browser recovery data by clearing Breathawear site data.
Account-attributed records are removed with the account. Older or shared-device records that cannot be safely attributed to one account are scheduled for automatic cleanup about 24 hours after ingestion; records attributed to a different person who used a shared device are preserved for that person.
Your choices
You can manage optional notifications in the app or operating-system settings, use guest mode without cloud sync, stop the live simulated breather or close its signed-in browser view, tag or skip a local simulated-breath reflection, sign out, or delete your account. Guided practice, the simulator, and the local NPC challenge do not require a wearable. Designated Review-build testers can separately decline nearby-device permission or disconnect their own prototype. You may request access, correction, or deletion by contacting us.
Children and health information
Breathawear is not designed for children under 13, and we do not knowingly collect their personal information. Breathawear supports wellness and breathing awareness; it is not a medical device and does not diagnose, treat, cure, or prevent a medical condition.
Contact us
For privacy questions or requests, email nick@breathawear.com. For product help, visit Breathawear support.