Privacy
Do Breathwork stores as little as it can. The native app and browser app work a little differently, and this page says exactly what each one does.
Controller and contact
The controller is the Do Breathwork operator identified in the legal notice, with full address to be published before commercial release. Privacy requests can be sent to hello@dobreath.work. See the legal notice for the complete operator details.
iPhone and Mac app
The native Do Breathwork app has no account, advertising, analytics or third-party tracking. Your exercise settings and session history — the exercise, date, duration and breath-hold times — are stored only on your device. The developer cannot see them, and the app does not send them to a server.
You can erase all native-app session history from Settings. Deleting the app also deletes its locally stored data. The native app does not read from or write to Apple Health.
Optional tips and reminders
Optional tips are processed by Apple through the App Store. They unlock no features, and the app stores no receipt or purchase history. If you choose a daily reminder, it is scheduled privately on your iPhone; no reminder data is sent to a server.
Browser app: signed out
Every session you record — the exercise, the length, the holds, the date — is written to your browser's local storage. Signed out, it is never sent anywhere. Clearing your browser data deletes it, and nobody else can read it.
Browser app: signing in is optional
The app works fully without an account. You only need one if you want the same record on more than one device.
There is no password. You give an address, we email you a link, and clicking it signs you in. The link works once and expires in 15 minutes.
What an account stores
Your email address, and your sessions: for each one the exercise, when it started, how long it ran, whether you finished it, and your breath-hold times. That is the whole list. No name, no profile, no device fingerprint, no IP address, no user-agent, no third-party trackers.
Signing in merges, it never overwrites. Sessions recorded on this device are added to your account, and sessions from your account are added to this device. Nothing is deleted by signing in, and signing out leaves this device's copy alone.
If you leave an address on the waitlist instead of signing in, we store that address and a one-way hash of your IP, salted so it cannot be reversed. The hash exists to stop one source flooding the form. The IP itself is never written down.
Analytics
We count page views and a few anonymous events — a session started, finished, or left early, plus the exercise and its length in whole seconds — through Vercel Analytics. It sets no cookies and builds no profile of you. We use it to learn whether people finish what they start.
Purposes and legal bases
Optional account and waitlist information is processed with your consent and to provide the sync or email service you request. Essential security, abuse prevention, service reliability, and privacy-filtered error diagnosis are processed for the legitimate interest of operating a safe, dependable service. You can withdraw waitlist consent at any time; this does not affect earlier lawful processing.
Service providers and transfers
Vercel hosts the website and provides aggregate analytics; Neon hosts the account database; Resend delivers account email; and Sentry receives privacy-filtered technical error reports when configured. These providers act under their own contractual and security terms. Some processing may occur outside Germany or the European Economic Area using the transfer safeguards offered by the provider. The provider list and safeguards must be confirmed in the final legal review before commercial release.
Retention
Magic-link verification records are removed after they expire. Account sessions expire after 90 days. Cloud session history and the account email remain until you delete the account. Waitlist entries are removed when you unsubscribe and, unless another lawful reason applies, no later than 90 days after the public launch. Production error reports should use a 30-day retention period.
Error reports
If the app fails, Sentry receives the technical error, its code location, your browser and operating-system version, and the page path. Query strings and request contents are removed first. We do not send your email address or breathing-session history. Session replay, performance tracing and console recording are disabled. We use these reports only to find and fix defects.
Removing your data
While signed in, choose Delete account to receive a verification link. Confirming it removes the account, authentication records, cloud session history, and matching waitlist entry. You can also email hello@dobreath.work. The copy on your own device remains yours; clearing browser storage removes it.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent. You may also complain to the competent data-protection authority. Contact the address above so the request can be verified without exposing data to someone else.
Health
Do Breathwork is not a medical device and gives no medical advice. Strong breathing and breath holds can cause light-headedness and, rarely, fainting. Practise sitting or lying down, never in or near water. If you are pregnant, or have a heart condition, epilepsy, or a history of fainting, skip the Guided Release exercise.