Skip to content
Legal

BreathBeats Privacy Policy

Effective date: July 8, 2026 · Last updated: July 8, 2026 BreathBeats is operated by SHORESIDE LLC ("BreathBeats," "we," "us"), a U.S. limited liability company. Contact: [email protected] · 221 1st Ave SW, Suite 610, Rochester, MN 55902.

This policy explains what we collect, why, and the choices you have, when you use the BreathBeats mobile app (the "App") or breathbeats.app (the "Site"). Washington and Nevada residents: our Consumer Health Data Privacy Policy supplements this policy for health-related data.

The short version

  • Your camera images never leave your phone. When you turn on camera mode, frames are analyzed on your device in real time to detect breathing motion. We do not record, store, or transmit video or photos — to us or anyone.
  • We store your account, your session history, and any wellbeing ratings you choose to enter, so the App can show your progress. Wellbeing ratings are optional.
  • We do not sell your personal information, and we do not share it for advertising. There are no ads in BreathBeats.
  • You can delete your account and data from inside the App, or by emailing us.

1. Information we collect

a. Account information. Email address, optional first/last name, a hashed password (if you use email sign-in), or an identifier from Apple or Google if you use Sign in with Apple/Google. Guest use is available; guest sessions are keyed to a device identifier until you create an account.

b. Breathing session data. When you complete a session, we store: the technique or genre used, the reason or goal you select for a session (for example, sleep, focus, stress, or an anxious moment), start/end time and duration, whether the session was completed, and — if camera mode was on — limited derived signals about detection quality (for example, a detection-accuracy score for the session and a yes/no flag indicating whether mouth-breathing was detected for exhale guidance). These derived signals are numbers and flags, not images.

c. Optional wellbeing ratings and notes. The App may invite you to rate how you feel before and after a session (for example mood, stress, energy, or anxiety level on a numeric scale) and to add free-text notes. These are optional — you can always skip them. If you provide them, we store them with your session history so you can see change over time. This is health-related information and is handled under our Consumer Health Data Privacy Policy where applicable law provides additional protections.

d. Camera data (processed on device only). In camera mode, the App uses your front camera to detect breathing-related motion (such as chest/shoulder movement and whether your mouth is open for exhale guidance). This processing happens in real time, on your device. Camera frames and any facial landmark data are processed transiently and are not recorded, stored, or transmitted. The only camera-related information we keep is the small set of derived, non-image signals described in §1(b) — a numeric detection-quality score and a yes/no mouth-breathing flag stored with your session record — which cannot be used to reconstruct any image and cannot identify you. We do not collect, capture, purchase, receive, possess, or retain any biometric identifier or biometric information as defined by biometric privacy laws (including the Illinois Biometric Information Privacy Act and Texas's Capture or Use of Biometric Identifier Act). All camera analysis runs on your device, under your control, and nothing capable of identifying you is created, stored, or transmitted.

e. Purchases. Subscriptions are processed by Apple's App Store or Google Play and our subscription-management provider (RevenueCat). We receive subscription status (plan, trial, renewal state) and pseudonymous transaction identifiers. We never receive or store your full payment card details.

f. Usage and device data. We collect a limited set of analytics events (such as app opened, session completed, subscription started) with device type, app version, and coarse technical context, using PostHog configured with session replay and autocapture off. We use this to understand what's working and to fix problems.

g. Communications. If you email us or submit feedback, we keep the correspondence. If you join our email list on the Site, your email is managed by our newsletter provider (Beehiiv) and every email includes an unsubscribe link.

We do not collect: precise location; contacts; photos or media libraries; advertising identifiers for tracking; and we do not run third-party advertising or cross-context behavioral advertising of any kind.

2. How we use information

To provide and operate the App (sessions, history, streaks, personalization such as favorite techniques); to process and manage subscriptions; to secure accounts and prevent abuse; to provide support; to understand aggregate usage and improve the App; to send transactional messages (receipts, account notices) and — only if you opted in — marketing emails; and to comply with law. We do not use your wellbeing ratings, session data, or camera-derived signals for advertising, and we do not sell them.

3. Legal bases (EEA/UK users)

Where GDPR/UK GDPR applies: performance of a contract (providing the App you request, including session history you ask us to keep); consent (optional wellbeing ratings; camera mode; marketing emails — withdrawable anytime); legitimate interests (securing and improving the service, limited analytics, defending legal claims); and legal obligation. Where we rely on consent for health-related data, you may withdraw it at any time in the App or by contacting us.

4. When we share information

We share personal information only with:

  • Service providers (processors) who handle it for us under contract and only on our instructions — our cloud hosting and database provider, subscription-management service, analytics service, transactional-email service, newsletter service (Site list only), and Apple/Google (distribution, payments, and any sign-in option you choose). We maintain a current list of these providers and will disclose it on request (see §6).
  • Legal and safety: if required by law or legal process, or to protect the rights, safety, and security of users, the public, or BreathBeats — and where a request seeks health-related data we will resist overbroad demands to the extent the law allows.
  • Business transfers: if BreathBeats is involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction; this policy will continue to apply to it, and we will notify you of material changes.

We do not sell personal information. We do not "share" personal information for cross-context behavioral advertising (as those terms are defined in California law), and we have not done so in the preceding 12 months.

5. Retention

We keep personal information only as long as reasonably necessary for the purposes described above, then delete or de-identify it. The criteria we use: account, session, and wellbeing data are kept for the life of your account and deleted or de-identified within 30 days of account deletion; guest data, analytics events, support correspondence, server logs, and backups are each kept on limited, rolling cycles no longer than needed for their purpose; newsletter data is kept until you unsubscribe or ask us to delete it; and records we are legally required to keep are retained only as long as the law requires. Camera images are never retained (see §1(d)).

6. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal information; to withdraw consent; and to appeal a decision we make on a rights request. We honor these rights as follows:

  • Everyone, regardless of state: you can delete your account and associated data in the App (Settings → Account → Delete Account) or by emailing [email protected]. You can skip wellbeing ratings entirely, use the App without camera mode, and unsubscribe from marketing at any time.
  • California: rights to know/access, delete, correct, and portability. We use sensitive personal information (your optional wellbeing entries) only to provide the services you request, so California law does not require a "Limit the Use of My Sensitive Personal Information" link. We do not sell or share personal information — including of anyone under 16 — so there is no sale/sharing to opt out of; we nonetheless honor the Global Privacy Control signal where it applies. We will never discriminate against you for exercising rights. Requests: [email protected]; authorized agents may submit requests with proof of authorization.
  • Colorado, Connecticut, Virginia, Texas, Oregon, Minnesota, Montana, and other states with comprehensive privacy laws: access, correction, deletion, portability, and opt-out rights as provided by your state's law — including, where your state provides it (for example Oregon and Minnesota), the right to a list of the specific third parties to which we have disclosed personal data (see §4 — processors only) — with an appeal process: reply to our decision email and a different reviewer will respond within the statutory period.
  • Washington and Nevada (consumer health data): see the Consumer Health Data Privacy Policy for rights to access, withdraw consent, and delete consumer health data.
  • EEA/UK: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to your supervisory authority (we'd appreciate the chance to resolve concerns first).

We verify requests using your account email; we respond within the time your law requires (generally 30–45 days).

7. Security

We use encryption in transit (TLS) for all App–server communication, hashed passwords, access controls limiting who can touch production data, and the principle that the most sensitive input — your camera feed — is engineered never to leave your device at all. No system is perfectly secure; if a breach affects your unsecured personal information, we will notify you and regulators as applicable law (including the FTC Health Breach Notification Rule) requires.

8. Children

BreathBeats is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact [email protected] and we will delete it. Users 13–17 may use BreathBeats only with a parent or guardian's permission.

9. International users

We are based in the United States and process data there. The Service is currently offered from and directed to users in the United States. If you use BreathBeats from outside the U.S., you understand your information is processed in the U.S. For EEA/UK users (if and where the Service is made available there), we rely on appropriate safeguards (including Standard Contractual Clauses with our processors) for transfers.

10. Third-party links and services

The Site and App may link to third-party services (for example, crisis-support resources like 988 or findahelpline.com, or the app stores). Their privacy practices are their own; this policy doesn't cover them.

11. Changes to this policy

We'll post changes here and update the date above. For material changes, we'll give you reasonable advance notice (in-App notice or email). Your continued use after the effective date means the updated policy applies — except that where law requires it (including for consumer health data), we will obtain your fresh, affirmative consent rather than rely on continued use.

12. Contact

[email protected] · SHORESIDE LLC, 221 1st Ave SW, Suite 610, Rochester, MN 55902. California residents may also reach us with Shine the Light inquiries at the same address.