Privacy notice
Deep Breathe Privacy Notice
This notice explains how Deep Breathe handles information when you use deepbreathe.app. Deep Breathe is an independent project maintained by Dhruv Sachdev. The app is designed to work without an account, and breathing settings, session history, and progress statistics are stored in your browser by default.
Last updated: 21 August 2026
Information stored on your device
When you use the app without signing in, settings, session records, streak information, interface preferences, recovery state, and offline resources may be stored using browser storage, Cache Storage, and a service worker. This information normally remains on that browser and device. You can remove it through the app’s controls where available or by clearing site data in your browser, though doing so may erase unsynced history and offline files.
Optional accounts and synchronized data
If you create an account, the authentication provider and Supabase process account details such as your email address, sign-in provider, account identifiers, and optional profile information. Deep Breathe may synchronize breathing settings, session history, aggregate statistics, email preferences, and profile images so they are available across devices. Authentication tokens are stored in the browser to keep you signed in.
You do not need an account for the core breathing experience. Account controls in the app provide available profile, export, sign-out, and deletion actions. A deletion or access request can also be sent to hi@dhruvsach.dev; verification may be required before acting on an account request.
Analytics and operational data
Deep Breathe uses service and analytics providers including Vercel Analytics, Google Analytics, Simple Analytics, and, when configured, PostHog. These tools may receive technical and usage information such as page path, referral source, device or browser characteristics, approximate region, session events, feature settings, and error fingerprints. The app’s custom event layer removes fields that look like passwords, tokens, email addresses, names, cookies, and user identifiers before sending event properties. Query strings are stripped from URLs sent through the PostHog integration.
PostHog is configured to respect Do Not Track, avoid automatic element capture, identify only signed-in users, mask text and input fields if replay is explicitly enabled, and disable replay by default. Simple Analytics is loaded with its Do Not Track option. Other providers apply their own privacy and retention practices. Browser settings, content blockers, and Do Not Track controls may limit some analytics, but not every provider responds to the same signal.
Email, sharing, and third-party services
Weekly summary email is optional and must be enabled by a signed-in user. If enabled, the account email address and breathing summary data are used to create and deliver that message; each summary includes an unsubscribe route. When you share a challenge or use an external support link, the receiving service processes the information under its own terms. Background audio and other assets may be delivered from content-hosting providers, which receive ordinary network request information such as IP address and user agent.
Purpose, retention, security, and choices
Information is used to operate the breathing sessions, save preferences and progress, synchronize optional accounts, send requested summaries, prevent abuse, diagnose failures, understand feature use, and improve the product. Local information remains until you clear it or the browser removes it. Account, analytics, and operational records are retained according to product needs and provider settings, then deleted or aggregated when no longer reasonably required, subject to security and legal obligations.
Reasonable technical measures are used, but no web service can guarantee absolute security. You can use the app without an account, decline weekly email, block analytics scripts, clear local site data, export supported data, or request account deletion. Questions or privacy requests can be emailed to hi@dhruvsach.dev. Material changes to this notice will be published on this page with a revised date.