Breathaway

Draft — pending review by legal counsel.

Privacy Policy

Effective [effective date]

This policy explains what personal data Breathaway collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

This Privacy Policy describes how [Company legal name] (“we”, “us”, “Breathaway”) handles personal data in connection with the Breathaway mobile application and this website (together, the “Service”). It is written to meet the requirements of the EU and UK General Data Protection Regulation (“GDPR”) and India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).

1. Who we are

[Company legal name], [postal address], [jurisdiction], is the controller of your personal data under the GDPR, and the Data Fiduciary under the DPDP Act. Where this policy refers to a Data Principal or a data subject, it means you.

You can reach us about anything in this policy at [contact email]. This notice is available in English; if you would prefer it in another language listed in the Eighth Schedule to the DPDP Act, write to us and we will provide it.

2. The short version

We collect the minimum we need to run the Service. We ask for your consent before we process your personal data, and you can withdraw it as easily as you gave it. We do not sell your personal data and we do not share it with advertisers. You can delete your account, and the data attached to it, at any time.

3. Personal data we collect

Data you give us

  • Account details. Your phone number, which we use to identify your account and to sign you in. Optionally, your first name.
  • Contact identifiers you enter. To connect you with a particular person, the Service uses identifiers you provide — a phone number and, where you choose to give one, a social media handle (for example, an Instagram handle). We store these so that a connection can be recognised.
  • Contacts you select. If you grant contacts permission, the app can help you choose a person from your address book. We only receive the details of the specific person you select — we do not upload your full contact list.
  • Messages you send us. If you email us for support, we keep that correspondence.

Data collected automatically

  • Device and app data. Device model, operating system version, app version, language, and a device or installation identifier, used to deliver notifications and diagnose problems.
  • Usage and diagnostics. Crash reports and aggregated, non-identifying usage events so we can keep the app working.
  • Purchase data. If you buy a subscription, the App Store or Google Play confirms the purchase to us. We never receive your card details.

We do not collect special category data (such as data revealing health, religion, or sexual orientation) and we ask you not to send it to us.

Data about people who are not yet users

Where you provide the contact identifier of a person who has not signed up, we store that identifier so the Service can recognise a connection if that person later joins. We do not contact that person on your behalf, we do not tell them you entered their details, and we do not use their details for marketing or profiling. If you are that person and you would like your details removed, write to [contact email] and we will erase them.

4. Why we use it, and our legal basis

  • To create and secure your account, and to provide the core features of the Service. Performance of our contract with you (GDPR Art. 6(1)(b)); your consent under the DPDP Act.
  • To send notifications you have asked for or agreed to. Your consent (GDPR Art. 6(1)(a); DPDP Act s. 6), withdrawable at any time.
  • To provide support and answer your requests. Performance of our contract, and our legitimate interest in helping you (GDPR Art. 6(1)(f)).
  • To keep the Service safe — preventing spam, abuse, impersonation and fraud. Our legitimate interest in a safe service (GDPR Art. 6(1)(f)), balanced against your rights.
  • To process purchases and provide paid features. Performance of our contract, and compliance with tax and accounting law (GDPR Art. 6(1)(c)).
  • To comply with legal obligations and respond to lawful requests. Legal obligation (GDPR Art. 6(1)(c)); the corresponding legitimate uses permitted by s. 7 of the DPDP Act.

We only use your personal data for the purposes described in this notice or in the notice shown to you in the app, and we collect only what is necessary for those purposes.

5. Consent, and how to withdraw it

Before we process your personal data, we ask for your consent through a clear notice that tells you what data we want, why we want it, and how to exercise your rights. Consent is free, specific, informed, unconditional and given by an affirmative action — never a pre-ticked box.

You can withdraw consent at any time, and withdrawing it is as easy as giving it: turn off the relevant permission in the app or your device settings, or write to [contact email]. Where you withdraw consent, we stop the processing that relied on it and erase the related personal data within a reasonable period, unless we are required by law to keep it. Withdrawal does not affect processing carried out before you withdrew, and it may mean parts of the Service no longer work. Where a Consent Manager registered with the Data Protection Board of India is available to you, you may also give, manage, review and withdraw consent through it.

6. Sharing and visibility

Data you provide is not published to other users, is not browsable by strangers, and is not made public. It is shared with another user only where that is necessary to deliver a feature you have chosen to use, and only to the extent required for that feature.

7. Notifications

With your permission, we send push notifications about activity on your account and important account or security messages. You can turn off push notifications at any time in your device settings; we may still send essential service messages, such as sign-in codes by SMS.

8. Processors we work with

We use a small number of processors (Data Processors under the DPDP Act) who handle personal data on our behalf, under a written contract, and only on our instructions:

  • Google Firebase (Google LLC) — authentication, database and storage, push notifications (Firebase Cloud Messaging), crash reporting, and analytics.
  • SMS delivery providers — to send one-time sign-in codes to your phone number.
  • Apple and Google — app distribution and, where applicable, in-app purchases and subscriptions.
  • Hosting and error monitoring providers — to run and observe the Service.

We do not sell or rent your personal data, and we do not share it with advertisers or data brokers. We may disclose data if required by law, or where necessary to protect the rights, safety, or property of users or of [Company legal name].

9. International transfers

Our processors may store or process personal data outside your country, including outside the EEA, the UK and India. Where we transfer personal data out of the EEA or the UK, we rely on an adequacy decision, or on the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant), together with additional safeguards where needed. Transfers from India are made only to countries not restricted by the Central Government under s. 16 of the DPDP Act. You can ask us for a copy of the safeguards we use at [contact email].

10. How long we keep it

  • Account data — for as long as your account is active.
  • Contact identifiers you entered — until you remove them, until you delete your account, or up to [retention period] from the date they were entered, whichever comes first.
  • Diagnostics and logs — typically up to 90 days.
  • Records we must keep by law — for the period the law requires (for example, tax records for purchases).

We erase personal data once you withdraw consent or the purpose we collected it for is no longer being served, unless retention is required by law. After deletion, residual copies may remain in encrypted backups for a limited period before being overwritten.

11. Deleting your data

You can delete your account from within the app, or by writing to [contact email]. Deleting your account removes your profile and the data attached to it, subject to the backup period described above and to any records we must keep by law. Step-by-step instructions are on our account deletion page.

12. Your rights

Wherever you live, you can ask us to:

  • confirm what personal data of yours we hold, and give you a copy;
  • correct data that is inaccurate, incomplete or out of date;
  • erase your data;
  • stop processing that relies on your consent, by withdrawing it.

If you are in the EEA or the UK

Under the GDPR you also have the right to restrict processing, to object to processing based on our legitimate interests, and to data portability — to receive the data you gave us in a structured, commonly used, machine-readable format and have it sent to another controller where technically feasible. You have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office).

If you are in India

Under the DPDP Act you have the right to access a summary of your personal data and of our processing, the identities of other Data Fiduciaries and Data Processors with whom it has been shared and a description of what was shared (s. 11); the right to correction, completion, updating and erasure (s. 12); the right to a readily available means of grievance redressal (s. 13); and the right to nominate another person to exercise these rights on your behalf if you die or become incapacitated (s. 14). Please make requests accurately and in good faith — the DPDP Act places duties on Data Principals too, including not filing false or frivolous complaints.

13. Making a request, and complaining

Send any request or complaint to [contact email], from the address or phone number linked to your account where possible, so that we can verify it. We will acknowledge it and respond without undue delay, and in any case within one month, or within any shorter period applicable law requires. If a request is complex we may extend that period and will tell you why. We do not charge for this unless a request is manifestly unfounded or excessive.

If you are not satisfied with our response, you can complain to your data protection authority. In India, you may approach the Data Protection Board of India after exhausting our grievance redressal process. In the EEA or the UK, you may complain to your local supervisory authority. You may also seek a judicial remedy.

14. Automated decisions and profiling

We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing, and we do not profile you for advertising.

15. Security and personal data breaches

We apply reasonable technical and organisational safeguards appropriate to the risk, including encryption in transit, access controls, least-privilege practices, and keeping the amount of data we hold small by design. No method of transmission or storage is completely secure.

If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by GDPR Art. 33, and we will notify the Data Protection Board of India and each affected Data Principal as required by s. 8(6) of the DPDP Act. Where the breach is likely to result in a high risk to you, we will tell you directly and explain what you can do.

16. Children

The Service is only for people aged 18 and over. We do not knowingly process the personal data of children, we do not track or behaviourally monitor children, and we do not direct advertising at them. If you believe a minor is using the Service, contact us at [contact email] and we will remove the account and erase the data.

17. Cookies and analytics on this website

This website uses Google Analytics to understand how many people visit, which pages they read and roughly where they come from. Google Analytics sets cookies in your browser (named _ga and _ga_<id>) and processes your IP address to estimate your location. We use it only in aggregate, to decide what to build and where to open next. We do not use it for advertising, we do not sell this data, and we do not use it to identify you personally.

You can prevent it entirely by using your browser’s tracking protection, an ad blocker, or Google’s opt-out add-on. Refusing it does not affect your use of this site.

When you join the waitlist we also record the city and country your request came from, derived from your IP address, so that we can decide which place to open in next. We do not store your IP address itself. We also use Vercel Analytics, which counts page views without setting any cookies and without building a profile of you. Our web host processes standard server logs to deliver the site securely. Analytics inside the mobile app are described in section 3.

18. Changes to this policy

If we make material changes, we will update the effective date above and notify you in the app or by email before the changes take effect. Where a change requires your consent, we will ask for it.

19. Contact us

Questions, requests or grievances: [contact email], or write to [Company legal name], [postal address], [jurisdiction]. You can also reach us from our contact page.