Privacy Policy
Last updated: 18 September 2026
This Privacy Policy explains how BreathePilot (“BreathePilot”, “we”, “us”, or “our”) collects, uses, and protects information when you:
-
visit BreathePilot.com (the “Site”); or
-
use the BreathePilot™ mobile application, including its Apple Watch functionality (the “App”).
The Site and the App may present this Privacy Policy in different formats or levels of detail, but they are intended to describe the same privacy practices.
1. Who we are
BreathePilot operates the BreathePilot website and mobile application from Switzerland.
For privacy and support enquiries, you can contact us at:
BreathePilot
Email: support@breathepilot.com
2. Information we collect
A. Information you provide directly
When using the Site, you may provide information when you contact us by email or through our support contact form. This may include:
-
your first and last name;
-
your email address; and
-
the content of your message.
The support contact form is provided through our website platform, Wix.
When using the App, you may choose settings and preferences such as:
-
Nudge schedules;
-
sounds and soundscapes;
-
breathing-session settings;
-
selected modes and durations;
-
daily goals;
-
analytics preferences; and
-
Apple Health permissions.
Most App preferences, session information, and history are stored locally on your device.
B. Information collected automatically through the Site
When you visit the Site, BreathePilot and our website provider, Wix, may automatically process certain technical information, such as:
-
IP address;
-
browser and device type;
-
operating system;
-
language;
-
approximate geographic region;
-
pages viewed;
-
interactions with the Site; and
-
cookies or similar technologies used for security, functionality, preferences, or analytics.
More information about cookies is provided in Section 9 below.
C. Privacy-preserving App analytics
BreathePilot uses TelemetryDeck for privacy-preserving analytics.
The App sends a minimal anonymous baseline consisting of general app-session, device and app-version context, analytics-consent choices, and aggregate paywall or purchase-funnel events.
If you enable “Share detailed anonymous usage,” the App also sends additional product-interaction events, such as:
-
features opened;
-
breathing-session metadata;
-
selected modes or durations; and
-
broad Nudge outcomes.
TelemetryDeck uses a privacy-preserving device or installation identifier.
We do not provide TelemetryDeck with your name, email address, advertising identifier, or our own raw installation identifier.
This information is not used for advertising or cross-app tracking.
We do not transmit Apple Health or HealthKit data to TelemetryDeck.
D. Purchases and subscriptions
Purchases are processed by Apple through the App Store.
Apple and RevenueCat process purchase-history and transaction information needed to validate purchases, restore purchases, manage subscriptions, and determine access to premium features.
BreathePilot receives entitlement and subscription-status information but does not receive your full payment-card details.
Our current RevenueCat configuration uses an anonymous generated App User ID rather than a BreathePilot account identifier linked to your name or email address.
RevenueCat may process purchase history and related technical information for purposes including App functionality and analytics associated with subscription management.
E. Notifications
If you enable Nudges, the App schedules notifications locally on your device.
BreathePilot does not currently operate a server-based push-notification service or collect an APNs device token.
You can manage notification permissions at any time through your device settings.
3. Apple Health / HealthKit
If you choose to connect BreathePilot with Apple Health on your iPhone or Apple Watch, the App may access HealthKit only after you grant the relevant permissions.
Depending on the features you choose to use:
-
the App may write breathing minutes or related breathing activity into Apple Health so that your breathing practice can appear in your overall health information;
-
any HealthKit data accessed by BreathePilot is used only to provide or improve the relevant health or breathing functionality;
-
HealthKit information is not used for advertising, behavioural profiling, or unrelated marketing;
-
HealthKit information is not sold to third parties; and
-
BreathePilot does not transmit HealthKit data to TelemetryDeck, RevenueCat, or BreathePilot-operated servers.
Apple Health permissions are controlled by you and can be changed or withdrawn through Apple Health or your device settings.
Because health information may be considered sensitive personal data under applicable law, we rely on your explicit permission and, where required by law, your explicit consent before accessing relevant HealthKit information.
4. How we use information
We use information processed through the Site and App to:
-
provide and operate the Site and App;
-
deliver the features and functionality you request;
-
store and apply your App settings and preferences;
-
provide breathing sessions, Nudges, soundscapes, and other App functionality;
-
validate subscriptions and provide premium features;
-
respond to support requests and other communications;
-
maintain security and diagnose technical issues;
-
understand in aggregate how the Site and App operate;
-
understand aggregate subscription and purchase conversion;
-
improve the design, reliability, performance, and usability of BreathePilot;
-
comply with applicable legal obligations; and
-
protect or enforce our legal rights.
We do not build advertising profiles based on your App usage.
The App does not contain third-party advertising networks, and BreathePilot does not sell App usage information for cross-app behavioural advertising.
5. Legal bases for processing
Where the GDPR, UK GDPR, or another legal framework requiring a legal basis applies, we rely on the following bases as appropriate:
Consent – for optional detailed analytics, non-essential website cookies where consent is required, notifications, and Apple Health / HealthKit access. For HealthKit data, we rely on explicit consent where required by applicable law.
Legitimate interests – for minimal privacy-preserving baseline analytics used to understand App operation and aggregate purchase conversion, maintain security, respond to support requests, and improve the Site and App, balanced against your rights and interests. This legal basis applies to the extent the relevant processing constitutes personal data under applicable law.
Performance of a contract – where processing is necessary to provide purchased subscriptions, premium features, and other App functionality you request.
Legal obligation – where processing is necessary for us to comply with applicable law.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before consent was withdrawn.
You can change detailed analytics preferences within the App and manage HealthKit, notification, and website-cookie permissions through the relevant App, operating-system, or Site settings.
6. Sharing of information and service providers
We use third-party services to operate the Site and App.
Wix
Wix provides website hosting, infrastructure, security, Site functionality, the support contact form, and certain cookie-related functionality.
Apple
Apple provides services including:
-
distribution of the App through the App Store;
-
App Store purchases and subscriptions;
-
Apple Health / HealthKit functionality;
-
operating-system functionality; and
-
device-level services used by the App.
RevenueCat
RevenueCat helps us validate App Store purchases and manage subscription entitlements.
Apple and RevenueCat process purchase-history and transaction information needed for subscription management.
BreathePilot receives entitlement and subscription-status information but does not receive your full payment-card details.
TelemetryDeck
TelemetryDeck provides privacy-preserving App analytics.
TelemetryDeck receives the minimal baseline analytics described above and, where you enable detailed anonymous usage sharing, the additional product-interaction events described in Section 2.
We do not provide TelemetryDeck with your name, email address, advertising identifier, HealthKit information, or our own raw installation identifier.
Depending on the service and processing activity, these providers may act as our service providers/processors or as independent controllers under their own privacy terms.
We may also disclose information where reasonably necessary:
-
to comply with applicable law, regulation, court order, or legal process;
-
to protect the rights, security, or safety of BreathePilot, our users, or others;
-
to investigate fraud, abuse, or security incidents; or
-
in connection with a merger, acquisition, restructuring, financing, sale of assets, or similar business transaction.
We do not sell your personal information or share it for cross-context behavioural advertising.
7. RevenueCat and subscription information
Purchases and subscriptions are made through Apple rather than directly with BreathePilot.
Apple processes your payment information and provides transaction information necessary to complete and manage the purchase.
RevenueCat processes purchase-history and transaction information necessary to validate purchases, restore purchases, manage subscription entitlements, and provide subscription-related analytics.
BreathePilot receives information such as whether a subscription or entitlement is active, expired, cancelled, or otherwise available.
BreathePilot does not receive your complete payment-card number or other full payment-card details from Apple.
Our RevenueCat implementation currently uses an anonymous generated App User ID rather than a custom BreathePilot account identifier.
8. International data transfers
BreathePilot operates from Switzerland, while some of our service providers may process information in other countries.
Depending on the provider and service, information may be processed within Switzerland, the European Economic Area, the United Kingdom, the United States, or other jurisdictions.
Where personal data is transferred internationally and applicable law requires additional safeguards, appropriate transfer mechanisms may include:
-
adequacy decisions;
-
recognised international data-transfer frameworks;
-
standard contractual clauses approved by relevant authorities; or
-
other lawful safeguards provided under applicable data protection law.
The privacy-preserving analytics infrastructure used by TelemetryDeck currently includes hosting infrastructure located within Europe.
9. Cookies and similar technologies
The Site is built and hosted using Wix.
Wix and Site functionality may use cookies or similar technologies for purposes such as:
-
essential website functionality;
-
security and fraud prevention;
-
remembering visitor preferences;
-
maintaining website sessions;
-
measuring Site performance; and
-
understanding Site usage.
Essential cookies may be used where they are necessary to operate the Site.
Where applicable law requires consent, non-essential cookies are not intended to be activated until you provide the relevant consent through the Site's cookie banner or preferences tool.
You can review or change available cookie preferences through the Site's cookie-management tools and may also control certain cookies through your browser settings.
Disabling essential cookies may affect the operation of parts of the Site.
10. Data retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including to:
-
provide the Site and App;
-
fulfil the purposes described in this Privacy Policy;
-
respond to support requests;
-
comply with applicable legal obligations;
-
protect our legal rights; and
-
resolve disputes.
In general:
Local App data: App settings, preferences, session information, and similar locally stored data generally remain on your device until you delete the relevant data or uninstall the App.
TelemetryDeck analytics: TelemetryDeck currently states that it does not have a fixed deletion schedule for cold-storage analytics events and expects such events to be retained for approximately 7–10 years, without guaranteeing that timeframe. We retain access to analytics only for as long as reasonably necessary for aggregate product analysis.
Subscription information: Purchase and subscription information is retained by Apple and RevenueCat in accordance with their respective retention requirements and privacy practices. We retain access to entitlement information for as long as reasonably necessary to provide and administer purchased functionality and meet applicable legal requirements.
Support requests: Emails and contact-form requests are retained for as long as reasonably necessary to respond to your request, maintain appropriate support records, and comply with applicable legal obligations.
11. Your privacy rights
Depending on your location and applicable law, you may have rights relating to your personal data, including the right to:
-
request access to personal data about you;
-
request correction of inaccurate information;
-
request deletion of personal data;
-
object to certain processing;
-
request restriction of certain processing;
-
withdraw consent where processing is based on consent;
-
request portability of certain data where applicable; and
-
lodge a complaint with an appropriate data protection authority.
Because most BreathePilot App data is stored locally on your device, removing locally stored App information may require deleting data within the App or uninstalling the App.
Because TelemetryDeck analytics are not associated with your name or email address, we may not be able to identify analytics events as belonging to you.
You may nevertheless contact us with a privacy request, and we will assist where technically and legally possible.
You may contact us at support@breathepilot.com to exercise applicable privacy rights.
We may need to verify a request where reasonably necessary to protect your information and comply with applicable law.
12. Children’s privacy
The Site and App are not intended for children under 13, and we do not knowingly collect personal data from children under 13.
In some jurisdictions, a higher minimum age may apply. We comply with applicable local requirements.
If you believe that a child has provided personal information to BreathePilot in circumstances where this should not have occurred, please contact us at support@breathepilot.com.
13. Security
We use reasonable technical and organisational measures designed to protect information processed through BreathePilot.
These measures include:
-
limiting data collection to what is reasonably necessary;
-
keeping most App information locally on the user's device;
-
using privacy-preserving analytics;
-
relying on platform-level security provided by Apple;
-
using established infrastructure and service providers; and
-
limiting access to information where appropriate.
However, no electronic transmission, software system, or method of storage can be guaranteed to be completely secure.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to:
-
the Site or App;
-
BreathePilot features;
-
the services or providers we use;
-
our data-processing practices; or
-
applicable legal or regulatory requirements.
When we update this Privacy Policy, we will update the “Last updated” date at the top of the policy.
Where a change is material and additional notice is appropriate or legally required, we may provide notice through the Site, the App, or another suitable method.
Where a change requires your consent, we will request consent where required rather than treating continued use of the Site or App as consent.
15. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or BreathePilot's handling of personal information, contact us at:
BreathePilot
Email: support@breathepilot.com
