BreathCare

Legal

Privacy Policy

Last updated 19 September 2026

BreathCare is a breathing app. It has no accounts and no server of its own. This page says exactly what happens to your data — what stays on your iPhone, the one thing that leaves it, and what you can ask us to do.

The short version

1. Who is responsible for your data

The controller of the personal data described here is:

Grzegorz Mróz Ventures
Krajewskiego 1/29
01-520 Warszawa
Poland
[email protected]

Write to that address with any question about this policy or about your data. We have not appointed a Data Protection Officer; the same address reaches the person who decides how BreathCare handles data.

This policy covers the BreathCare app for iPhone and this website. It does not cover Apple, whose handling of your App Store purchase is governed by Apple's own privacy policy.

2. What stays on your iPhone

BreathCare has no backend of its own. Everything the app records about your practice is written to its own storage on your iPhone, inside the app's container, and it stays there. We have no copy and no way to get one.

This is what the app stores on the device:

Why: this is the app. Without it there is no history, no streak, no custom pattern and no reminder.

Lawful basis: Article 6(1)(b) GDPR — processing necessary to provide the service you asked for. In practice we are not a party to it: the data never reaches us.

How long: until you delete it in the app, or until you delete the app. Deleting BreathCare removes all of it from your iPhone. There is nothing left behind on a server, because there is no server.

A consequence worth knowing before you rely on it: there is no backup, no sync and no export. If you delete the app, or lose the phone without an iPhone backup, your history is gone and we cannot restore it.

3. Apple Health

Writing to Apple Health is optional. It is off until you grant permission through Apple's own permission prompt.

If you grant it, the app writes one Mindful Minutes sample to the Health app when a session finishes. That is all it does.

The app only ever writes to Health. It never reads anything from Health — not your heart rate, not your sleep, not your activity, nothing.

The sample is stored by Apple's Health app on your device, under your control. We never receive it.

Lawful basis: your explicit consent — Article 6(1)(a) and Article 9(2)(a) GDPR — given through the Health permission prompt.

Withdrawing it: open the Health app, go to Sharing → Apps → BreathCare, and turn the permission off. You can also delete individual Mindful Minutes entries there. Turning it off stops future writes; it does not delete what is already in Health, which only you can do.

4. Analytics

This is the one part of BreathCare that sends data off your phone, so it gets the longest section.

Who processes it, and where

We use PostHog as a processor, on its EU Cloud (https://eu.i.posthog.com). The events are stored in the European Union.

The identifier, honestly

The analytics library generates a random identifier for your installation of the app and stores it in the app's container on your device. It is not your name, your email address, your Apple ID, your phone number, your advertising identifier or your device's serial number — it is a random string created on your phone the first time you open the app.

It is still personal data under the GDPR, because it lets events be grouped together as coming from one installation. That is called a pseudonymous identifier, and calling it “completely anonymous” would be wrong. So we do not call it that. It disappears when you delete the app; a reinstall generates a new one, unconnected to the old one.

What is sent

A fixed list of events, written into the app by hand. Nothing else is collected:

What is never sent

What is switched off

Why we do it

To see which parts of the app are used, where people give up, and whether a change made things better or worse. Without it we would be guessing.

Lawful basis: our legitimate interests — Article 6(1)(f) GDPR — in understanding and improving the app. We have weighed that against your privacy: the data is a short fixed list with no content in it, no profile is built, nothing is sold or shared for advertising, and the identifier cannot be linked to you by us or by anyone else.

How to object — read this, because there is no switch yet

The app does not currently have an in-app control to turn analytics off. We are telling you that plainly rather than describing a toggle that is not there.

You have two ways to stop it:

5. When you email us

“Contact us” and “Report a bug” do not send anything themselves. They open your own Mail app with a message already addressed to [email protected]. You decide whether to send it. Your mail provider carries it, and we receive whatever your mail identity shows — normally your email address and the name on the account.

A bug report can attach a diagnostics block. If you leave it in, it contains:

It contains no advertising identifier, no identifier for vendor, no location and nothing about your sessions. You can see the whole block before you send it, and you can delete it.

Lawful basis: Article 6(1)(b) GDPR where you are asking for support with a subscription, and Article 6(1)(f) — our legitimate interest in answering messages and fixing the app — otherwise.

How long: we keep support correspondence for 24 months after the matter is closed, then delete it. If a message matters for a legal claim or a tax record, we keep it for as long as the law requires.

6. Subscriptions and the App Store

BreathCare's subscription — annual or monthly, with a 7-day free trial — is sold through the App Store. Apple takes the payment and manages renewal and cancellation.

We never see your card number, your billing address or the email address on your Apple Account. Apple does not give them to us.

Cancelling happens in the App Store, in your Apple subscription settings — not in BreathCare and not by writing to us.

The “Billing history” screen in the app shows the transactions Apple has recorded for this app, read from the App Store on your device. It is your device asking Apple about your own purchases; it does not send anything to us.

Apple is its own controller for the purchase, the payment and the subscription record. What Apple does with that data is described in Apple's privacy policy.

Lawful basis for the part that happens in the app: Article 6(1)(b) GDPR — giving you the subscription you paid for.

7. Reminders and notifications

Reminders are scheduled entirely on your device, through iOS's own notification system. Nothing is sent from a server, and there is no push token — we have no technical way to send you a notification.

The reminder's name, its time and its days live on your phone with the rest of your data, and are covered by section 2.

Lawful basis: Article 6(1)(b) GDPR. iOS also asks for your permission before it will show notifications at all, and you can withdraw that at any time in Settings.

8. What BreathCare does not do

Stated as a list so you do not have to infer it from silence:

9. How long data is kept

10. Where your data is processed

Most of it is not processed anywhere but your own phone.

Analytics events go to PostHog's EU Cloud and are stored in the European Union. We have not authorised any transfer of analytics data outside the European Economic Area. We are established in Poland, and support email reaches us in Poland.

Apple processes your purchase under its own arrangements, which may involve transfers outside the EEA under the safeguards Apple describes in its privacy policy. That part is Apple's decision, not ours, and we have no access to that data.

11. Your rights

Under the GDPR you have the right to:

To exercise any of them, write to [email protected]. We answer within one month, and tell you if we need longer, as Article 12(3) allows.

What having no account means in practice

Because there is no sign-up, we hold nothing that connects you to an identity. Honestly stated:

12. Complaining to a supervisory authority

If you think we have handled your data unlawfully, you can lodge a complaint with the Polish supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office)
ul. Stawki 2
00-193 Warszawa
Poland
uodo.gov.pl

If you live in another EEA country, you can complain to your own national data protection authority instead. You can also go to court. Please consider telling us first — it is usually faster.

13. Children

BreathCare is not directed at children under 16, and we do not knowingly process their personal data. If you are under 16, please use the app only with a parent's or guardian's agreement.

If you are a parent and want the app's data gone from a child's phone, deleting the app does it completely. If you want to raise anything else, write to [email protected].

14. Security

Data the app stores sits inside the app's own container, protected by iOS's sandbox and by the device encryption that your passcode unlocks. Keeping a passcode on your iPhone is the single most effective thing you can do for this data.

Analytics events travel over an encrypted HTTPS connection. PostHog holds them as our processor and handles them only on our instructions, under Article 28 GDPR.

No system is perfect, and we will not claim otherwise. What we can say is that the amount of your data we hold is deliberately as close to nothing as we could make it.

15. Changes to this policy

When this policy changes, the date at the top of the page changes with it, and this page always carries the current version.

Because you have no account, we have no way to email you about a change — we do not know your address. If we make a change that materially affects your rights, we will say so on this page, and we will describe it rather than leave you to compare two versions.

16. Contact

Grzegorz Mróz Ventures
Krajewskiego 1/29
01-520 Warszawa
Poland
[email protected]

BreathCare is a wellness app, not a medical device. It does not diagnose, treat or prevent anything. A wellness practice, not medical care — stop if you feel unwell.