Privacy · Policy

Privacy policy.

Last revised: 2026-09-14.

TL;DR

If you only read one section, read this one.

What we collect. Your email (used for sign-in and as your account identifier), your onboarding self-assessment answers, your practice history (which sessions you start or complete, and when), and your daily check-in state — practiced, rested, or skipped, with no free-text content stored. Today, your practice history and check-ins live on your device (see Local Storage on Your Device).

Analytics, ads, and crash reporting. The app uses one product-analytics tool: Google Analytics for Firebase. In the European Economic Area, the UK, and Switzerland, analytics stays off until you allow it — the app asks once, and you can change your answer anytime in Settings → Usage analytics. Everywhere else it's on by default, with the same Settings switch to turn it off. Analytics receives usage events and technical context — never your email address. Our website at breathewithme.app is separate, and it uses Google Analytics too — with cookies that stay off unless you accept them (see Website Analytics and Cookies). We may later use Facebook, Instagram, and the Google Marketing Platform for advertising and measurement — we'll update this policy before any of that turns on. We never share the free-text content of your journals or check-in notes with any third party — not analytics, not ads, not crash reports. Sentry is our only crash reporter; every report it sends runs through a two-layer scrubber that strips email-shaped substrings, your signed-in email address, and any data field labeled email, note, journal, journalText, content, or body. We don't sell your personal data.

Delete or export your data. Tap Settings → Account actions in the app. A deletion request goes to our servers, which disable your account right away; a data-copy request is recorded on your device. Either way, we finish within 30 days and email you once it's complete.

Where your data lives. Your account record lives in the US, encrypted at rest and in transit, on Neon Postgres with Firebase Auth. Your practice history lives on your device.

What This App Is

Breathe With Me is a contemplative-practice and breathwork companion app designed to help you develop a consistent breathing practice. We're in iOS beta as of late May 2026. This privacy policy describes how we handle your data.

It covers two surfaces, and they behave differently: the app, which is the subject of every section below unless a section says otherwise, and our website at breathewithme.app, which is covered by Website Analytics and Cookies. The website is a marketing and support site — it has no access to your practice history, journals, or check-ins.

What Data We Collect

When you use Breathe With Me, we collect:

  • Your email address. We use it as your account identifier and to deliver sign-in links. We don't sell your email, and it is never sent to analytics. See Analytics and Advertising and Measurement below for the limited ways usage data is shared with service providers.
  • Self-assessment answers. During onboarding, you tell us your experience level and what you're hoping to work with. We use these answers to personalize session suggestions for you.
  • Practice history. The app records which sessions you start and complete, when you do them, and how long you stay — on your device. This helps the app compute your streak and recommend your next practice.
  • Check-ins. Each day you can mark whether you practiced, rested, or skipped. The app stores that day-state on your device (no free-text content) so it can compute your streak and draw your practice calendar.
  • Usage and device data (analytics). When analytics is on (see Analytics below for when that is), Google Analytics for Firebase collects app-usage events (screens viewed, features used, session timing, and which practice categories you engage with), technical context (app version, OS version, device class), and a per-install analytics identifier. It does not receive advertising identifiers — we disable advertising-ID collection on both platforms — and we never send the free-text content of your journals or check-in notes, or your email address.

What We Do NOT Collect

We don't collect your location, contacts, photos, or ask for microphone or camera access. We don't store the free-text content of your journals or check-in notes on our servers, and we never share that content with any third party — not analytics, not ads, not crash reports. We don't sell your personal data.

This describes the app. Our website collects a smaller, different set of things, described in Website Analytics and Cookies.

Analytics

The app uses Google Analytics for Firebase — one product-analytics tool, and only that one; a build-time check blocks other known analytics SDKs from shipping. We use it to understand which screens and features get used, how long sessions run, and where people drop off, so we can improve the app.

Whether it's on is up to you.

  • In the European Economic Area, the UK, and Switzerland: analytics is off until you allow it. The app asks once, after you've signed in; "Not now" keeps it off. Nothing is collected before you answer.
  • Everywhere else: analytics is on by default.
  • Either way, the Settings → Usage analytics switch shows the current state and changes it, anytime. Turning it off stops collection at the SDK — not just a preference flag.

What it collects when on: usage events with technical context (app version, OS version, device class) and a per-install analytics identifier. The usage events can include category-level signals like which kind of practice you opened (for example, breathwork versus meditation), but never the free-text content of your journals or check-in notes, and never your email address. Advertising-identifier collection is disabled on both platforms, and we do not use analytics for ads or cross-app tracking.

Website Analytics and Cookies

This section is about our website, breathewithme.app. The app's analytics are described in Analytics above.

The website uses Google Analytics 4 to understand which pages people visit, how they arrive, and which writing is worth doing more of. Google Analytics receives the pages you view, the referring URL, general technical context (browser, operating system, device type, screen size, language), and your IP address, which Google uses to derive an approximate location and does not retain.

We ask before those cookies are set. On your first visit you'll see a short banner. Until you accept, Google Analytics runs with consent denied: it stores no analytics cookies and no advertising identifiers on your device, and it sends no advertising signals. If you decline, it stays that way, and nothing on the site stops working — no page, feature, or link is withheld based on your answer. We deny advertising storage and personalization outright, so the website's analytics are not used to build or measure ad audiences.

We store one small record of your own choice, so the banner doesn't ask again on every page. That record stays in your browser. Clearing your browser's storage for breathewithme.app clears it, and the banner will ask again — which is also how you change your mind.

The website has no access to your practice history, journals, or check-ins. That data is in the app, on your device, and is never sent to the website or to its analytics.

Advertising and Measurement

As we grow, we may use advertising and measurement platforms — including Facebook and Instagram (Meta) and the Google Marketing Platform — to reach new people and to measure how well our marketing works. This can involve sharing limited data — such as app events (for example, that you opened or completed a session in a given practice category) or a hashed (non-reversible) identifier — with those platforms to build and measure ad audiences. We never share the free-text content of your journals or check-in notes with any advertising platform. We do not sell your personal data. If we ever introduce data sharing that requires your consent, we'll ask for it before turning it on.

Where Your Data Lives

Your account record — your email address and account identifier — is stored on Neon Postgres with Firebase Auth, in the US, encrypted at rest and in transit.

Your practice history and check-ins are stored on your device (see Local Storage on Your Device). Cross-device sync is planned for a future release; we'll update this policy when it ships.

Your email address is held by the authentication provider (Firebase Auth). Email contents are never stored on our servers—the provider keeps only the email address itself for delivering sign-in links.

Signing In

You can sign in with your Apple or Google account, or with a one-time link delivered to your email through the authentication provider's transactional email service. (The email-link option may not always be visible on the sign-in screen while we improve it.) A sign-in link expires after a short window — treat it as sensitive.

When you sign in with Apple or Google, we receive your email address (or Apple's private relay address, if you choose to hide yours) and an account identifier. We don't receive your contacts, photos, or anything else from those accounts.

Crash and Error Reporting

We use Sentry to catch crashes and errors so we can fix them quickly. Every report passes through our own scrubbing layer on the way out, and a second scrubbing pass runs inside the Sentry client itself so that anything Sentry collects automatically (breadcrumbs, native crash reports, performance traces) gets the same treatment.

What we send: stack traces, the part of the app where the error happened, app version, OS version, an anonymous device class, and an opaque account identifier from the authentication provider (not your email address).

What we strip before sending: anything that looks like an email address, your current signed-in email address as a substring (kept in memory only — never transmitted), and any data field labeled email, note, journal, journalText, content, or body. If you don't see your category listed, assume we send only the technical fingerprint above.

Local Storage on Your Device

Your practice history and check-ins are stored locally on your phone using SQLite. Today they live only on your device: they are not uploaded to our servers, and deleting the app deletes that local history with it. Cross-device sync — so your history can follow you to a new phone — is planned for a future release; we'll update this policy when it ships.

Deleting Your Data

Tap Settings → Account actions → Delete account and confirm. Your request is sent to our servers, which disable your account right away and sign you out. We'll permanently remove your account and everything associated with it from our servers within 30 days, and email a confirmation once it's complete. (Your practice history lives on your device, so deleting the app removes it — see Local Storage on Your Device.)

You can also tap Settings → Account actions → Request a copy of my data. We record this request on your device, and we'll prepare and email you a copy of your practice history within 30 days.

Children

Breathe With Me is not intended for anyone under 13, and we don't knowingly collect data from children under 13.

Changes to This Policy

If this policy changes in a material way, we'll update the "Last revised" date at the top of this document. The next time you open the app after a major change, you may be asked to acknowledge the new version.

Questions

If you have privacy questions or concerns, reach out to hello@breathewithme.app.