Back

3 Breaths Privacy Policy

Version: draft-v1.0 · Effective: Private beta launch

3 Breaths is a connection and wellbeing service for adults. This policy explains what the service collects, why it uses the data, who processes it, how long it is kept, and the choices available to you. 3 Breaths is not therapy, medical care, crisis support, or an emergency service.

We do not sell personal or consumer health data. We do not use it for cross-app advertising or tracking.

1. Data we collect and how we collect it

  • Account and profile data you provide: email address, password credentials handled by our authentication provider, display name, profile image, gender category, time zone, age attestation, terms acceptance, and email preferences.
  • Community and matching data created through your use: memberships and roles, favorites and blocks, invite audience and intention choices, open invitations, matches, practice selections, schedules, reminders, streaks, badges, and participation timestamps.
  • Wellbeing and feedback data you choose to provide: whether a breath happened, before-and-after state or mood ratings, private feedback, public reflections, safety reports, and technical-issue descriptions. Because this can reveal wellbeing information, we treat it as consumer health data where applicable.
  • Communications and community content you submit: posts, comments, reactions, announcements, inbox messages, support requests, and moderation reports.
  • Audio, video, and images: live camera and microphone streams needed for a requested video breath; optional video testimonials; mutually consented session recordings; and profile images. Live video is not retained as a recording unless the app clearly shows and obtains the applicable recording permission.
  • Device and technical data generated when the service runs: account and internal user IDs, device-scoped ID, push subscription or APNs token, notification state, app/browser version, requested path, timestamps, coarse network and security information, delivery results, and redacted error or operational logs.
  • Information another user provides about you, such as a safety report, block, or participation in the same match or conversation.

2. How we use data

  • Create and secure accounts, maintain sessions, and provide support.
  • Operate communities, eligibility and safety filters, invitations, first-accepter matching, private video rooms, practices, feedback, reminders, notifications, and account history.
  • Show profile information and content to the community audience you select, and keep private feedback and safety details out of ordinary member views.
  • Deliver match-ready and other requested alerts, including through Apple Push Notification service, browser push services, or an optional linked Telegram account.
  • Investigate safety reports, enforce the Terms, prevent fraud or abuse, troubleshoot failures, maintain service security, and comply with law.
  • Measure service reliability and aggregated product use. We do not use advertising SDKs or combine this information with data from other companies for tracking.
  • Use an optional testimonial, PR Champion story, recorded session, or public reflection for the separately disclosed purposes only when the required permission applies. You can withdraw future permission and ask us to review or remove an existing use.

3. Who receives or processes data

We disclose only the data reasonably needed for the service or an authorized purpose. Our current processor categories and services are:

  • Supabase for authentication, database, realtime updates, and profile-image storage.
  • Fly.io for application hosting and request processing.
  • Cloudflare for DNS, encrypted traffic proxying, availability, and security.
  • Daily for live audio/video rooms and for optional recordings when the required recording permission exists.
  • Resend for account and support email delivery.
  • Logflare for short-retention, redacted operational logs.
  • Apple and browser push providers for notification delivery; Google services will process Android delivery when that beta is enabled.
  • Telegram only when you choose to link Telegram notifications.
  • Dropbox for client-side encrypted disaster-recovery archives; Dropbox does not receive the archive decryption key.

Authorized 3 Breaths administrators may access information only as needed for support, moderation, safety, media review, and service operation. Other members receive only the profile, invitation, and content data permitted by the app’s audience controls. We may disclose information when legally required or reasonably necessary to protect people, rights, and service security.

We require service providers acting for us to protect data and use it only for the instructed service purpose, with protection at least equivalent to this policy and applicable law.

4. Consumer health data

Consumer health data can include your state or mood ratings, breathing-practice activity, session outcomes, wellbeing reflections, safety information, and audio or video whose content reveals wellbeing. Sources are you, your use of 3 Breaths, another participant in a shared interaction, and service providers that return operational or recording status.

We use this data to provide the practices and connection service you request, show history and progress, operate safety features, resolve technical issues, and support optional media uses you separately permit. Necessary processors listed above may process the categories relevant to their service. We do not sell consumer health data and do not share it with unaffiliated third parties for their own advertising.

You may ask whether we hold consumer health data about you, access it and a list of recipients, withdraw consent for future collection or sharing where consent is the basis, or request deletion. We respond without undue delay and generally within 45 days. If reasonably necessary, we may extend once by 45 days after notifying you. If we refuse a request, you may appeal by replying with “Privacy appeal”; we respond to the appeal within 45 days and, if denied, explain how to contact the appropriate regulator.

5. Retention and deletion

  • Account, profile, community, matching, feedback, and content data is ordinarily retained while the account is active so the requested service, history, safety, and moderation features work.
  • Live audio and video is processed for the call and is not retained as a recording unless the applicable optional recording permission exists. Optional recordings are kept until deleted, the account is deleted, permission is withdrawn and removal is required, or an administrator removes them.
  • Push addresses are removed when you disable notifications, sign out that device, delete the account, or when a provider reports that an address is no longer valid.
  • Redacted Logflare operational logs are ordinarily retained for three days. Email and support records are retained only as reasonably needed for delivery, support, abuse prevention, and legal obligations.
  • Deleting an account removes live account data and associated provider recordings. Restricted encrypted backup copies age out no later than 180 days after a verified deletion request. They are isolated from ordinary use; if recovery requires a backup before it expires, deletion requests must be reapplied before service resumes.
  • We may retain a narrowly limited record when reasonably necessary and permitted by law for security, fraud prevention, legal compliance, or the establishment or defense of claims. It is isolated and not used for ordinary product or marketing purposes.

6. Your choices

  • Access or correction: edit available profile and preference fields in Settings, or contact us for other account data.
  • Public content: choose whether to post a reflection publicly and use available edit, delete, audience, and consent controls.
  • Notifications and optional media: turn notifications, reminders, testimonial prompts, Telegram, and future session-recording permission on or off in Settings.
  • Account deletion: use Settings → Delete account. If you cannot sign in, use the public account-deletion page and contact us from the account email so we can authenticate the request.
  • Other privacy rights: request access, correction, deletion, withdrawal, or an appeal by emailing us. You do not need to create a new account to make a request.

Visit the account-deletion page or email support@3breaths.org. We may request information reasonably needed to authenticate the request. Exercising a privacy right does not change the price or quality of the service, though withdrawing data necessary for a requested feature can prevent that feature from working.

7. Security and international processing

We use access controls, row-level authorization, encrypted network transport, short-lived video meeting tokens, encrypted backups, and limited administrator access. No online service can promise perfect security. Providers may process data in the United States or other places where they operate, subject to their contracts and applicable safeguards.

8. Adults only

3 Breaths is for people age 18 and older. We do not knowingly offer accounts to children. Contact us if you believe a child provided personal data so we can investigate and delete it.

9. Changes and contact

We may update this policy as the service changes. We will update the version and effective date and provide reasonable notice of material changes. We will not collect or use additional consumer health data categories for a new purpose that requires consent without first providing the required notice and choice.

Questions, requests, and appeals: support@3breaths.org.