Legal information
Privacy Policy
This policy explains how the Breath of Life Android application handles information when you use breathing practices, track wellbeing progress, enable reminders or choose optional account backup.
Publisher and data controller: Denis Plashchik. Support contact: breathoflife.support@gmail.com. English is the primary legal version of this policy; Russian and Hebrew are provided for accessibility.
1. Scope and important health context
Breath of Life is a wellbeing and guided-breathing application. It is not a medical device, diagnosis, emergency service or substitute for professional medical care. Information you enter about tension, goals, habits, notes or practice outcomes may be sensitive wellbeing information. Do not enter information you do not want stored.
Age: Breath of Life is intended only for people aged 18 or older.
2. Information handled by the app
Account and authentication
An account is optional for core use. If you sign in with Google, Firebase Authentication may process your Firebase user ID, email address, display name, profile image URL, authentication provider and sign-in metadata. Google handles the Google sign-in interaction under its own terms.
Practice, progress and wellbeing information
The app may store practice technique, date and time, duration, completion status, goals, experience level, streaks, minutes, sessions, progress, preferences, selected language and theme, reminder settings, custom breathing settings, course progress, pre- or post-practice tension, selected state, free-text notes and acknowledgements of safety information.
Diagnostics, analytics and device information
Firebase Analytics may collect app interactions such as onboarding, session, reminder, desired-state, cloud-sync and course events, together with automatically collected app/device information. Firebase Crashlytics may receive crash traces, diagnostic events, app state and device or installation identifiers. Google/Firebase may process IP and network metadata, from which approximate location can be inferred. The merged application configuration includes Google/Firebase advertising-identifier capability; the current app does not show ads.
Communications
If you email support, we receive your email address and the content and attachments you choose to send. Please do not send passwords, access tokens, identity documents, medical records or unnecessary sensitive information.
3. Where information is stored
- On your device: Room databases and DataStore/preferences hold progress, sessions, settings, reminders and related app state. Some local app data may be included in Android system backup if device backup is enabled.
- In Firebase Firestore: when signed in and cloud backup is used, the app writes a latest backup under your Firebase user account. It can include statistics, sessions, preferences, reminders, course/practice state, tension values, notes and safety acknowledgements.
- In Firebase services: Authentication, Analytics and Crashlytics process the account, usage and diagnostic categories described above.
The audited application does not use Firebase Storage at runtime. It does not currently process purchases through Google Play Billing and does not operate an advertising network.
Reminder schedules are stored through app preferences and scheduled locally with Android WorkManager. Notifications are delivered by the Android operating system. WorkManager is a local scheduling mechanism, not an independent cloud data recipient; reminder-setting changes may still be included in optional backup or Analytics events as described above.
4. Why information is used
- Provide sessions, progress, settings, reminders, safety gates and app navigation.
- Authenticate an optional account and back up or restore supported app data.
- Maintain reliability, diagnose crashes, understand feature operation and prevent abuse.
- Answer support, privacy and deletion requests.
- Meet legal obligations and protect users, the service and others where necessary.
Where applicable, processing is based on providing the service you request, legitimate interests in secure and reliable operation, consent for optional choices, and legal obligations. Available legal bases depend on your jurisdiction.
5. Service providers and sharing
Breath of Life uses Google services including Firebase Authentication, Cloud Firestore, Firebase Analytics and Firebase Crashlytics, and Google Sign-In. These providers process information to operate the relevant service and may process it in multiple countries under their terms and safeguards.
Information may also be disclosed when required by law, to protect rights or safety, or as part of a business transfer with appropriate safeguards. Breath of Life does not sell personal information, does not rent it to advertisers and does not use it to display third-party ads. “No sale” does not mean no service provider receives data.
6. Retention
Local data generally remains until you delete the account in the app, clear app storage or uninstall, subject to Android backup behavior. The active Firestore user document and its nested account data remain while the account exists or until automatic account deletion succeeds. Support correspondence is kept only as long as reasonably needed to answer the request and maintain necessary records.
Analytics, crash reports, authentication records and provider backups follow applicable Firebase/Google retention settings and operational backup cycles. Deletion from active systems may not remove encrypted provider backups immediately; residual copies can remain for a limited period before rotation, and limited records may be retained where legally or security-required.
7. Security
The app uses Android platform protections, authenticated access to account backup and encrypted HTTPS transport; cleartext traffic is disabled in the audited application configuration. Access is limited according to operational need. No security measure is perfect, so absolute confidentiality or zero risk cannot be promised. Keep your Google account and device secure.
8. Your choices and rights
- Use core app features without signing in, where available.
- Control reminders and notification permissions in the app or Android settings.
- Review or change app preferences and remove local data by clearing app storage or uninstalling, considering Android backup.
- Request access, correction, deletion, restriction or objection where your local law provides those rights.
- Withdraw consent for future processing where consent is the legal basis.
- Complain to an applicable data-protection authority.
We may need to verify identity before acting on an account-specific request. Rights are not absolute and lawful exceptions may apply.
9. Account and data deletion
You may use the in-app deletion option or the authenticated account deletion page. After recent Google reauthentication and explicit confirmation, the automatic service recursively deletes the active Firestore user document and nested account data, then deletes the Firebase Authentication user. The in-app flow also purges personal Room and DataStore content, reminder work and notifications on that device after the server confirms success. The website cannot remotely erase app data already stored on other devices; clear app storage or uninstall there as needed. Provider backups, security logs and Analytics/Crashlytics data remain subject to the limited retention described above.
10. International processing
Google/Firebase and support systems may process information outside your country. Depending on location, this can include jurisdictions with different data-protection laws. Appropriate provider contractual and technical safeguards are used where required, but no statement here guarantees that every jurisdiction offers identical protection.
11. Changes to this policy
The policy may be updated when features, providers, law or data practices change. Material changes should be communicated through the website, app or another reasonable channel before or when they take effect. The published page will show its effective date.
Change history
- August 23, 2026: automatic authenticated account deletion, controller identity, 18+ audience and effective date documented.
12. Contact
Privacy, access or deletion questions: breathoflife.support@gmail.com.
Operator: Denis Plashchik · 18+ · English is the primary legal version.