Privacy Policy — Breathing App
Last updated: 7 August 2026
1. Who We Are
Breathing App ("the App", "we", "us") is operated by Abdullah Alansari, an individual developer based in Kuwait.
We are the data controller for the personal information described in this policy.
Contact: q8seaman70@gmail.com
2. What Breathing App Does
Breathing App guides you through timed breathing exercises. An animated circle and a countdown tell you when to inhale, hold and exhale, and the app records how long you practised and how many breathing cycles you completed.
You get two free completed sessions. After that, continued use requires a one-time purchase through the Apple App Store. It is bought once and kept forever — there is no subscription and nothing renews.
The App supports relaxation and general well-being. It is not medical treatment, it does not diagnose or treat any condition, and it does not measure your actual breathing — it only guides timing.
3. Information We Collect
What We Do NOT Collect
We have deliberately kept this list long. The App does not collect:
- ❌ Your location — no GPS, no approximate location, no IP-based geolocation by us
- ❌ Your contacts, microphone, or camera
- ❌ Your photo library — we never read or scan it. If you choose to set a profile picture, only the single image you pick is uploaded (see below)
- ❌ Health or fitness data from your device — we do not connect to Apple Health or any wearable
- ❌ Payment card details — Apple processes payment; we never see your card number
- ❌ Advertising or tracking identifiers — no IDFA, no ad networks, no cross-app tracking
- ❌ Analytics or behavioural tracking — we do not measure which screens you visit, how long you use the App, or anything else about your behaviour. The App does contain a crash-reporting tool, described below — it activates only when something goes wrong
- ❌ Your data for AI training — the App uses no artificial intelligence, and nothing you enter is used to train any model
Account Information
When you create an account we collect:
| Data | Why |
|---|---|
| Email address | To identify your account, verify it, and let you reset your password |
| Password | Stored only as a cryptographic hash — we cannot read it |
| Display name | Shown in the app greeting |
| Account creation date | Account administration |
Profile Photo (optional)
You may set a profile picture. If you do:
- We ask for permission to open your photo library, and only the one image you select is uploaded. We never browse, scan, or read anything else.
- It is stored on our servers and shown to you inside the App.
- You can replace or remove it at any time in Profile, and removing it deletes the file.
- It is deleted along with everything else when you delete your account.
Skipping it costs you nothing — the App simply shows your initial instead.
Practice Data
Each time you complete a session, we store:
| Data | Example |
|---|---|
| Which exercise you did | "Box Breathing" |
| The breathing pattern | 4-4-4-4 |
| Cycles completed | 10 |
| Duration | 160 seconds |
| Date and time | 7 Aug 2026, 09:41 |
| Mood (optional) | Tense / Meh / Calm / Great |
This produces your progress statistics and streaks — and it is how we count your two free sessions.
About mood: recording a mood is entirely optional and you can skip it. Because a mood entry may be considered information about your well-being, we treat it as sensitive: it is stored only in your own account, is never shared with anyone, is never used for advertising, and is deleted when you delete your account. Choosing a mood is your explicit consent to store it. If you would rather not record moods, simply do not select one.
Purchase Information
If you unlock the App, we store that you purchased it and an identifier supplied by our purchase provider. The unlock is permanent, so there is no renewal date. We do not receive or store your payment card details — Apple handles the transaction.
Crash Reports
If the App crashes, a diagnostic report is sent to Sentry so the fault can be found and fixed. This happens only when something goes wrong — nothing is sent during normal use.
A report contains the error, the point in our code where it occurred, and basic device information (model and operating system version). It does not contain your account identifier, your email address, your IP address, your practice history, or your mood entries — the tool is explicitly configured not to attach them.
Reports are processed in Sentry’s European Union (Germany) region. The legal basis is our legitimate interest in keeping the App working.
Stored On Your Device Only
Your vibration preference and your login token are stored on your phone and are never transmitted to us. Deleting the App removes them.
4. How We Use Information
We use your information only to:
- Provide the App — save your practice history, show your progress and streaks
- Manage your account — sign-in, email verification, password reset
- Enforce the free-session limit — determine whether you have used your two free sessions or have purchased the unlock
- Keep the service secure — detect abuse and diagnose faults
- Comply with legal obligations
We do not sell your personal information. We do not share it for advertising. We do not send marketing emails — the only emails we send are transactional ones you request (verification, password reset).
No automated decision-making: nothing in the App makes legally significant decisions about you automatically.
5. Cookies and Similar Technologies
The mobile App uses no cookies and no tracking technologies. It stores a login token and your vibration preference locally on your device, which is necessary for the App to function and cannot be used to track you elsewhere.
If this policy is published on a website, that page may set only strictly necessary cookies. We use no analytics or advertising cookies anywhere.
6. Third-Party Processors
We use a small number of providers. Each processes data only on our instructions.
| Provider | Purpose | Data it receives | Privacy policy |
|---|---|---|---|
| Supabase (hosted on AWS, Frankfurt, Germany) | Database, authentication, hosting | Email, password hash, display name, practice history, purchase status | https://supabase.com/privacy |
| Apple | Payment processing, App Store distribution | Payment details, purchase record — governed by Apple, not us | https://www.apple.com/legal/privacy/ |
| RevenueCat | Purchase validation | Your account identifier and purchase events | https://www.revenuecat.com/privacy |
| Resend | Sending verification and password-reset emails | Your email address and the message content | https://resend.com/legal/privacy-policy |
| Sentry (EU region, Germany) | Crash reporting | Only when the App crashes: the error, where in the code it happened, your device model and OS version. No account identifier, no email, no IP address, no practice data | https://sentry.io/privacy/ |
We do not use any advertising network, behavioural analytics provider, or AI service.
7. Data Retention
| Data | How long we keep it |
|---|---|
| Account information (email, name, password hash) | Until you delete your account |
| Profile photo (if you set one) | Until you remove it or delete your account |
| Practice history and moods | Until you delete your account |
| Purchase record | Until you delete your account (Apple keeps its own transaction records under its policy) |
| Server logs held by our hosting provider | A short technical retention period, typically up to 7 days |
| Email delivery logs at our email provider | Per Resend's own retention policy |
When you delete your account, your profile, your entire practice history and your purchase record are deleted immediately and permanently. They are not recoverable and are not kept in backups indefinitely.
Important: deleting your account does not refund your purchase. Because a one-time unlock stays attached to your Apple ID, you can recover it on a new account with Restore Purchase — but your practice history cannot be recovered.
8. Your Rights
Wherever you live, you can:
- Access the personal data we hold about you
- Correct inaccurate information
- Delete your account and all associated data — available directly in the app under Profile → Delete account, with no need to contact us
- Obtain a copy of your data in a portable format
- Object to or restrict certain processing
- Withdraw consent — for example by deleting mood entries or your account
How to exercise these rights: email q8seaman70@gmail.com. We respond within 30 days. We may need to verify that you control the email address on the account.
Exercising these rights is free, and we will never treat you differently for doing so.
9. International Transfers
Your data is stored on servers located in the European Union (Amazon Web Services, Frankfurt region, operated by Supabase). Our email and purchase providers may process data in the European Union and the United States.
If you are in the EEA, your data stays inside the EU — storing it in Frankfurt means there is no international transfer of your account or practice data at all. If you are in the UK, transfers to the EU are covered by the UK's adequacy regulations. Where a provider processes data in the United States (for example our email provider), that transfer relies on Standard Contractual Clauses or an equivalent safeguard in our agreement with them.
10. Children
Breathing App is not directed to children. You must be at least 13 years old to create an account, or 16 in the European Economic Area and the United Kingdom where local law sets a higher age.
We do not knowingly collect personal information from children below these ages. If you believe a child has created an account, email q8seaman70@gmail.com and we will delete it promptly.
11. Security
- All data is transmitted over encrypted HTTPS/TLS connections
- Data is encrypted at rest on our provider's infrastructure
- Passwords are stored only as cryptographic hashes — we cannot read them, and neither can anyone who obtained our database
- Row-level database security enforces that each account can only ever read its own data, verified by testing
- We never store payment card details
- Access to production systems is limited to the operator
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant supervisory authority as required by law — within 72 hours where GDPR applies.
12. Changes to This Policy
We may update this policy. The "Last updated" date at the top always reflects the current version. If we make a material change to how we use your data, we will notify you in the App or by email before it takes effect.
Continuing to use the App after a change takes effect means you accept the updated policy.
13. Contact
Email: q8seaman70@gmail.com Operator: Abdullah Alansari, Kuwait Response time: within 30 days
14. Regional Supplements
14.1 European Economic Area and United Kingdom (GDPR / UK GDPR)
Legal bases for processing (Article 6):
| What we process | Legal basis |
|---|---|
| Account data, practice history | Contract — necessary to provide the service you asked for |
| Purchase and free-session enforcement | Contract |
| Mood entries | Explicit consent — optional, withdrawable at any time |
| Security, abuse prevention, fault diagnosis | Legitimate interests — keeping the service working and safe |
| Responding to legal requests | Legal obligation |
Your rights (Articles 15–22): access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent at any time without affecting prior processing.
Right to complain: you may lodge a complaint with your national data protection authority. In Ireland this is the Data Protection Commission (dataprotection.ie); in the UK, the Information Commissioner's Office (ico.org.uk).
Transfers: see §9. Your account and practice data are stored inside the EU. Any onward transfer by a sub-processor is safeguarded by Standard Contractual Clauses.
Representative: as a sole developer established outside the EEA processing a limited volume of data, we have not appointed an Article 27 representative. Contact us directly at q8seaman70@gmail.com.
No automated decision-making within the meaning of Article 22 takes place.
14.2 California (CCPA / CPRA)
We do not sell or share your personal information, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information for any purpose other than providing the App.
Personal information collected in the past twelve months, by CCPA category:
| Category | Collected | What |
|---|---|---|
| A. Identifiers | ✅ Yes | Email address, account identifier |
| B. Customer records | ✅ Yes | Display name |
| C. Protected classifications | ❌ No | |
| D. Commercial information | ✅ Yes | Purchase status |
| E. Biometric information | ❌ No | |
| F. Internet activity | ❌ No | No analytics or browsing history |
| G. Geolocation | ❌ No | |
| H. Audio/visual | ❌ No | |
| I. Employment information | ❌ No | |
| J. Education information | ❌ No | |
| K. Inferences / profiles | ❌ No | We build no profiles about you |
| Sensitive personal information | ⚠ Limited | Optional mood entries, used only to show you your own history |
Your California rights: to know, to delete, to correct, to opt out of sale or sharing (we do neither), and to limit use of sensitive personal information. Exercise any of them at q8seaman70@gmail.com, or delete your account directly in the App. An authorised agent may act on your behalf with written permission.
Non-discrimination: we will not deny service, charge different prices, or provide a lower quality of service because you exercised a privacy right.
14.3 Kuwait and Other Jurisdictions
The operator is based in Kuwait, and this policy is governed by Kuwaiti law, without prejudice to the mandatory rights described above for users in the EEA, UK and California.
Appendix — Apple App Store Privacy Labels
Not part of the policy. Use this when filling in App Privacy in App Store Connect. It must match this policy, or App Review may reject the submission.
Data Used to Track You: None Data Linked to You:
| Type | Purpose |
|---|---|
| Email address | App Functionality, Account Management |
| Name | App Functionality |
| Purchase history | App Functionality |
| Photos (optional profile picture) | App Functionality |
| Other User Content (session history, optional mood) | App Functionality |
Data Not Linked to You:
| Type | Purpose |
|---|---|
| Crash Data (under Diagnostics) | App Functionality |
Crash reports carry no account identifier, so they are not linked to the user.
Declare no tracking, no advertising data, no location, no behavioural analytics, no third-party advertising SDKs. Answer "No" to the App Tracking Transparency question — the App contains no tracking SDK. Do tick Crash Data under Diagnostics; leaving it out would understate what the App sends.