● Breathe ← back

Privacy Policy

Comprehensive draft — pending final Dutch jurist sign-off. This document has been written to be complete and faithful to how the Breathe app actually works, so that a qualified Dutch privacy/consumer-law jurist can give a final review and sign-off rather than fill gaps. It has not yet been formally reviewed by counsel. Do not treat this document as lawyer-approved until the jurist review is closed out.

Last updated: 2026-07-10 · Document version: 13

Effective date: the "Last updated" date above is the effective date of this version.

Studio: Richicinschi (eenmanszaak) · KvK: 42105331 · BTW: NL005496987B03 · Registered address: Van Delfthof 263, 5038 BX Tilburg, the Netherlands · Website: https://richicinschi.com · Contact: hi@richicinschi.com

© 2026 Richicinschi. All rights reserved.


At a glance (plain-language summary)

This short summary is provided for convenience. It does not replace the full policy below, and the detailed sections control where they differ.

Accessibility & languages. This policy is provided in English — the language of the App and of all our communications — in the App and on our website. If you need the policy in another accessible format, email hi@richicinschi.com and we will provide one.


1. Who we are

This app ("Breathe") is published by Richicinschi, a sole proprietorship (eenmanszaak) registered in the Netherlands at the Kamer van Koophandel under KvK number 42105331, with registered business/correspondence address Van Delfthof 263, 5038 BX Tilburg, the Netherlands and BTW (VAT) number NL005496987B03. Richicinschi is the data controller under Regulation (EU) 2016/679 (the GDPR — in Dutch, the Algemene Verordening Gegevensbescherming or AVG) for personal data processed in connection with the app.

Richicinschi is the registered trade name (handelsnaam) of the studio's sole proprietorship in the KvK Handelsregister (Trade Register).

For any privacy question, request, or complaint described in this policy, contact us at hi@richicinschi.com or by post at Van Delfthof 263, 5038 BX Tilburg, the Netherlands. Because Richicinschi is a sole proprietorship, your request is read and actioned by the studio's owner personally.

No Data Protection Officer. We have not appointed a Data Protection Officer (DPO) because none of the triggers in Article 37(1) GDPR apply to us: we are not a public authority, our core activities do not consist of large-scale regular and systematic monitoring of data subjects, and our core activities do not consist of large-scale processing of special categories of data. This determination is documented in our internal compliance records and reviewed at least annually. For any data-protection matter, contact hi@richicinschi.com.

EU representative. Because Richicinschi is established in the European Union (the Netherlands), it is not required to appoint an Article 27 GDPR representative.

UK users. For users in the United Kingdom, the UK GDPR applies in parallel to the EU GDPR. The need (if any) for a UK Article 27 representative is under assessment with our jurist; international transfers affecting UK users are addressed in §7.

2. Definitions

For clarity, in this document:

3. Categories of personal data, sources, and lawful basis

We collect only what is necessary to run the Service, secure your account, improve the experience, and meet our legal obligations. The lists below set out every category, when it is collected, where it comes from, and the legal basis under Article 6 GDPR for processing it.

Sources of personal data. Across the categories below, personal data reaches us in three ways: (a) directly from you (e.g. your email, display name, the sessions you complete, your reminder preference); (b) automatically through your use of the App and via the Firebase SDKs (e.g. the anonymous identifier, analytics events, crash diagnostics, server-log data); and (c) from third parties (your chosen sign-in provider supplies your email and, for Apple, an optional name; RevenueCat supplies your subscription status). Each entry below identifies its source.

3.1 Always collected (from first launch)

Firebase Analytics and Crashlytics are off by default. You can turn them on — and off again — at any time under Settings → Data & privacy; a single combined switch controls both. Nothing is collected or transmitted until you enable them. In the Netherlands these device-storage/telemetry functions require your prior consent under the ePrivacy Directive (art. 5(3)) and the Telecommunicatiewet (art. 11.7a), so they are opt-in, not opt-out; legitimate interest does not displace that consent requirement. Device language/locale is auto-collected as a default Analytics property only while Analytics is on.

3.2 Collected when you create an account

Data collected during the sign-up/account-creation flow is processed under Article 6(1)(b) as steps taken at your request prior to entering into the contract (the pre-contractual limb), as well as for performing the contract once your account exists. Providing the account data in this section is a contractual requirement: without an email address (or a federated sign-in) you cannot create an account or use the account-based features of the Service. Providing consent-based data (analytics, crash diagnostics, reminders) is always optional, and declining it has no consequences for your use of the App.

3.3 Collected when you complete a session

3.4 Collected when you set up a reminder

Enabling reminders triggers your device's notification-permission prompt (the iOS notification dialog, or the Android 13+ POST_NOTIFICATIONS prompt). At onboarding we explain why daily reminders are useful before offering to enable them; you can grant or deny the permission then, and you can revoke it at any time in your device's system settings. All reminders are scheduled locally on your device; Breathe uses no Firebase Cloud Messaging or other remote-push provider, so no reminder is sent from, or routed through, our servers.

3.5 Collected when you subscribe

3.6 Support and feedback

If you email us for support, or send us feedback or a testimonial, we process the content of that message (and your email address) to answer you and to operate and improve the App. There are no in-app surveys and no in-app feedback forms that transmit free-text to us. Lawful basis: Art. 6(1)(b) (handling a request that relates to your contract) and/or Art. 6(1)(f) (legitimate interests in supporting and improving the Service). Retention is described in §8.

3.7 Special-category data

We do not collect any data that constitutes special categories under Article 9 GDPR (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for identification, health data, or data concerning a person's sex life or sexual orientation). The App does not record symptoms, diagnoses, medical history, biometrics, or any health measurements. Breathe is a general-wellness app — it is not a medical device and not a personal health record, and the practice data it stores (technique, number of rounds, timestamps, derived streak) is not health data. For the avoidance of doubt, your session records (breathing technique, number of rounds, timestamps, and the derived streak) are general-wellness usage data and do not constitute Article 9 health (including mental-health) data.

4. What we do not collect

For the avoidance of doubt and to align exactly with our Apple App Privacy label and Google Play Data Safety declaration, we do not collect:

We serve no advertising, use no advertising SDKs, and use no AI/ML processing of your data.

If you spot a discrepancy between this policy and either store's published declarations, the store declarations are authoritative while we correct this document.

5. How we use your data

Each use ties back to a lawful basis listed in §3. Where more than one basis applies, the primary basis is listed first and any secondary/fallback basis follows.

Any personalisation is limited to the preferences you set yourself (e.g. audio defaults, reminder time) and the streak derived from your own sessions. We do not build behavioural profiles. We do not use your data to build advertising profiles, train machine-learning models on it, sell it, or share it with marketing networks or data brokers.

Legitimate-interests assessment. For each purpose relying on Article 6(1)(f) (for example, securing your account, server-log security and abuse-prevention, and the pseudonymous app identifier), we have carried out and recorded an internal Legitimate Interests Assessment (purpose, necessity, and balancing test). Factors that weigh in favour of processing include: the data is aggregate and contains no free text, no special categories, and no advertising identifiers; and storage is EU-region. Analytics and crash diagnostics do not rely on legitimate interest — they are based on your consent (opt-in, off by default; see §3.1), which you can withdraw at any time (§9). You can object to legitimate-interest processing as described in §9.

New purposes. Before processing your personal data for any new purpose, we will assess whether the new purpose is compatible with the original purpose under Article 6(4) GDPR. Where the new purpose is incompatible and relies on consent, we will obtain fresh, specific, opt-in consent before processing. We review the lawful basis for each processing activity at least annually and whenever a processing operation materially changes.

6. Recipients and processors

We rely on a small number of third parties to deliver the Service. Except as set out in this section, we do not share personal data with any other third party. Each processor below is a processor under Article 28 GDPR — it acts only on our documented instructions, under a contract containing the obligations required by Article 28(3) (confidentiality, security, sub-processing controls, assistance, deletion/return, and audit), and may not use the data for its own purposes.

Independent controllers (payment processing). When you buy a subscription, Apple App Store (iOS) and Google Play (Android) act as the merchant of record and as independent controllers for the payment data they handle, determining the purposes and means of that processing for their own purposes. Their handling of your payment data is governed by Apple's and Google's own privacy policies. We never see your payment-card or banking details (see §3.5). The same applies when you use Google Sign-In or Apple Sign-In: Google LLC and Apple Inc. process your use of their sign-in service as independent controllers under their own privacy policies; we receive only the email address, optional name, and account identifier described in §3.2.

Store-provided aggregate analytics. As the App's distributors, Apple and Google also provide us, as independent controllers of their own platform analytics, with aggregate, non-identifying statistics about the App — for example install and update counts, aggregate crash and performance metrics (including Google Play's Android Vitals), and coarse regional/territory and device-mix breakdowns. These are statistics about the App in aggregate, not individual records we can tie to you, and they reach us regardless of whether you have enabled the in-App analytics and crash diagnostics in §3.1. We use them only to understand the App's reach and stability at a population level. Because these reports are aggregate and do not identify you, they are not personal data about you under the GDPR (Recital 26). (Google appears in this section in two distinct roles: as our processor for the Firebase services listed above, and — together with Apple — as an independent controller of the store-distribution statistics described here.)

Outbound transactional email. Of the three transactional emails in §13, email-address verification and password reset (items 1–2) are sent through Firebase Authentication; the one-time purchase & withdrawal-waiver confirmation (item 3) is queued in our database and delivered via the Firebase "Trigger Email" extension through Google Workspace (Gmail) SMTP — the studio's email provider in the processor list above — from the verified sender noreply@richicinschi.com, with replies directed to hi@richicinschi.com.

Beta-testing programs. If you take part in a pre-release test via Apple TestFlight or Google Play internal/closed testing, Apple or Google process your tester identifier (e.g. the tester email you enrol with) and any feedback or crash data you submit through their beta channels as independent controllers under their own terms. Any tester feedback that reaches us is handled like support feedback (§3.6), under the retention in §8.

Other recipients. In addition to the processors above, personal data may occasionally be made available, only to the minimum extent necessary, to:

Sub-processors. Our processors engage their own sub-processors. Under each processor's DPA we have given general written authorisation for sub-processors with the right to be notified of changes and to object; processors may only engage sub-processors on terms consistent with Article 28(2) and (4). The current sub-processor lists are maintained by each processor and can be found on Google Cloud's, RevenueCat's, and Cloudflare's published sub-processor pages.

Disclosures required by law or to protect rights. We may disclose personal data where we believe in good faith that it is necessary to: (a) comply with a legal obligation, applicable law, regulation, or a valid legal request, court order, subpoena, warrant, or other enforceable legal process (Art. 6(1)(c)); (b) establish, exercise, or defend legal claims, or enforce our Terms, or protect the rights, property, or safety of Richicinschi (Art. 6(1)(f)); (c) protect the vital interests of you or another person in a genuine emergency (Art. 6(1)(d) — expected to be rare, as we hold no health or biometric data); or (d) prevent fraud or abuse. When responding to a law-enforcement or legal request, we disclose only the minimum data legally required, check the validity and legal basis of the request, and — where lawful and feasible — notify the affected user. These disclosures are an exception to the statement above that we do not share data with other third parties.

Business transfers. If Richicinschi is involved in a merger, acquisition, reorganisation (including incorporation as a BV), insolvency, bankruptcy, liquidation, or a sale of all or part of its assets, personal data may be transferred to, or accessed during due diligence by, the successor or prospective buyer as part of that transaction. Any such recipient will be required to honour this Privacy Policy (or a policy at least as protective), and your rights under the GDPR will not be diminished. We will notify you of any resulting change of data controller — via the in-App version banner and/or email — before or promptly after the transfer takes effect.

Liability split. As controller, Richicinschi is responsible for its own processing decisions; each processor is responsible, under its Article 28 DPA, for processing carried out on our documented instructions.

Compliance review. We review our processing activities and our processor list periodically, and maintain an internal record of processing activities (Article 30 GDPR).

7. International data transfers

Most of your personal data is stored in the European Union (Google's europe-west1 region, in Belgium). Transfers outside the EEA occur only in the limited cases described below, and each is covered by appropriate safeguards under Chapter V GDPR:

Transfer-safeguard verification. Before launch and at least annually, we verify on dataprivacyframework.gov that each US importer relying on the DPF (currently Google LLC, and Apple/Google for payment processing) holds an active EU-US DPF certification covering the relevant data; for importers relying on SCCs (RevenueCat, Inc.), we keep the signed SCCs and our transfer-impact assessment on file. We retain dated evidence of each check.

Schrems II / transfer-impact. We are aware of the CJEU "Schrems II" ruling (Case C-311/18, 16 July 2020). For US transfers, we rely on the EU-US Data Privacy Framework where the importer is certified, and on the 2021/914 SCCs supplemented by a documented transfer-impact assessment and proportionate supplementary measures (EU-region storage where available, TLS encryption in transit, Google-managed encryption at rest, data minimisation, and the absence of free-text content in analytics) where the DPF does not apply. Our transfer-impact assessment is kept as an internal compliance record.

UK and Switzerland. For UK-resident users, we rely on the UK's recognition of EEA adequacy for UK↔EEA flows, and on the UK Extension to the EU-US DPF and/or the UK Addendum to the EU SCCs (IDTA) offered by our US processors for onward US transfers, under the UK GDPR. For Swiss-resident users, where applicable we rely on the Swiss-US DPF and the Swiss FADP. The precise UK/Swiss positions are flagged for confirmation in our jurist review.

Ongoing monitoring. We monitor legal developments affecting international transfers (the EU-US DPF's adequacy status, relevant CJEU rulings, and SCC revisions) and will update the safeguards above and this policy accordingly. You may request a copy of the SCCs governing any of these transfers by emailing us at hi@richicinschi.com.

8. How long we keep your data

Anonymisation vs. deletion. When a retention period ends, account-related data is deleted. Where we instead retain data in anonymised form, it is processed so that the Firebase UID and any direct or indirect identifiers are irreversibly removed, so the data can no longer be attributed to, or re-identified as, an individual; such anonymised data falls outside the GDPR (Recital 26). Fully anonymised, aggregated statistics that cannot be linked to any person may be retained indefinitely for statistical and product-improvement purposes.

Backups. Data lives in our processor's primary, durable storage (Firestore) rather than in separate backups we maintain. When data is purged from live systems, any replicas or backups held by our processor are overwritten or expire on the processor's standard cycle (for Firestore, point-in-time recovery retains recent changes for up to 7 days).

Your device backups (Android Auto Backup). On Android, the App participates in Android's standard device backup. If you have device backup enabled, Android may include the App's local data (your on-device session history, challenge progress, reminder time, and preferences) in the device backup stored with Google under your own Google account and restore it when you set up or migrate a device. That backup is created by your operating system on your behalf: it is encrypted by Android, we cannot access it, and it is never transmitted to our servers. You can exclude the App from backups, or turn device backup off, in your device's Android backup settings; deleting the backup is likewise managed through your Google account, not by us.

Legal-obligation and legal-claim overrides. Notwithstanding the periods above: (a) where Dutch or EU law requires it (e.g. the 7-year fiscal obligation), the relevant records are retained for the statutory period; and (b) we may retain personal data beyond the periods above where necessary to establish, exercise, or defend legal claims, for as long as such claims may be brought (under Dutch law, generally up to the applicable limitation period).

Review. We review the retention periods set out above at least annually to confirm they remain no longer than necessary, and maintain an internal retention schedule. We do not retain personal data "just in case".

9. Your rights under the GDPR

As a data subject you have the rights set out below. You may exercise them by emailing hi@richicinschi.com (or by post to Van Delfthof 263, 5038 BX Tilburg, the Netherlands). Many can also be exercised directly in the App, as noted.

Identity verification. To protect your data, we may ask you to send your request from the email address associated with your account, or otherwise to confirm your identity, before we act (Art. 12(6) GDPR). We do not require additional ID for standard requests and will seek only proportionate further verification where there is genuine doubt about your identity.

  1. Right of access (Art. 15). Confirmation of whether we process personal data about you and, if so, a copy of that data, together with: the purposes of processing; the categories of personal data; the recipients or categories of recipients; the retention period (or the criteria used to set it); the source of the data where not collected from you; the existence of your other rights and of the right to lodge a complaint; and information about any international transfers and their safeguards. The first copy is provided free of charge and in a commonly-used electronic format (e.g. JSON or PDF) unless you ask for another form. The copy comprises all personal data we hold about you (cross-referencing §3); note that the free-user on-device session history described in §8 never reaches us, so it is not in our possession to provide.
  2. Right to rectification (Art. 16). Correction of inaccurate personal data, and completion of incomplete data, including by your providing a supplementary statement. Your display name can be edited from inside the App (Settings → Account); to correct your account email address, or anything else, write to us at hi@richicinschi.com and we will make the change for you after verifying the request. Where you contest accuracy, you may also ask us to restrict processing while we verify (Art. 18(1)(a)).
  3. Right to erasure ("right to be forgotten", Art. 17). Beyond the always-available in-App deletion (§11), you may request erasure on the Article 17(1) grounds — the data is no longer necessary; you withdraw consent and there is no other basis; you object and there are no overriding grounds; processing is unlawful; a legal obligation requires erasure; or the data was collected from a child for online services. Limits (Art. 17(3)): we may retain certain data where required to comply with a legal obligation (e.g. tax records, or payment records held by Apple/Google) or for the establishment, exercise, or defence of legal claims (see §8 and §11).
  4. Right to restriction of processing (Art. 18). You may obtain restriction where: (a) you contest the accuracy of the data (for a verification period); (b) the processing is unlawful and you prefer restriction to erasure; (c) we no longer need the data but you need it for a legal claim; or (d) you have objected under Art. 21 pending verification of overriding grounds. Effect (Art. 18(2)): while restricted, your data is only stored and not otherwise processed, except with your consent, for legal claims, to protect another person's rights, or for important public interest. We will inform you before any restriction is lifted (Art. 18(3)).
  5. Right to data portability (Art. 20). For personal data you provided to us that we process by automated means on the basis of your consent or a contract (Art. 6(1)(a)/(b)) — e.g. your email, display name, and the session/streak history and challenge progress you generated as a subscriber — you may receive a copy in a structured, commonly-used, machine-readable format (we provide JSON). Where technically feasible, you may also ask us to transmit this data directly to another controller (Art. 20(2)); in practice we currently provide a JSON export you can transfer yourself rather than an automated controller-to-controller channel. Excluded: data processed under legitimate interests (e.g. the server-log/security processing in §3.1) is not portable but is covered by the right of access (item 1); analytics events (consent-based, account-linked pseudonymous usage events rather than content you provided) are likewise covered by the right of access; inferred or derived data (e.g. aggregate analytics insights) is not included, as you did not provide it; and free-user on-device session history never reaches us and so cannot be exported by us.
  6. Right to object (Art. 21). You may object, on grounds relating to your particular situation, to processing carried out on the basis of our legitimate interests (for example, the pseudonymous app identifier, and our security and server-log processing). (Analytics and crash diagnostics are based on your consent and are off by default, so you control them through the right to withdraw consent in item 7 below, not this objection right.) On a valid objection we will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or for the establishment, exercise, or defence of legal claims. Any future direct marketing carries an absolute right to object at any time, free of charge, after which marketing stops immediately (Art. 21(2)-(3)).
  7. Right to withdraw consent (Art. 7(3)). Where processing is based on your consent (analytics & crash diagnostics, which are off until you enable them; the reminders feature; any future marketing list), you may withdraw consent at any time, and as easily as you gave it — without needing to email us: turn the reminder toggle off (Settings) or revoke OS notification permission; turn Analytics/Crashlytics off under Settings → Data & privacy; and any future marketing email will carry a one-click unsubscribe. Withdrawal does not affect the lawfulness of processing before withdrawal. Withdrawing any consent (reminders, analytics, or crash reporting) has no detriment: it does not disable, limit, or reduce the quality of any other part of the App, and all Free and Pro features remain available.

How to exercise your rights

Email hi@richicinschi.com describing what you want. We respond within one calendar month of receipt as required by Article 12(3) GDPR. If your request is complex or you have made several requests, we may extend by up to two further months, in which case we will tell you within the first month and explain why. We do not charge a fee for normal requests; we may decline manifestly unfounded or excessive requests, or charge a reasonable fee, in line with Article 12(5). If we refuse a request, we will, without undue delay and within one month, inform you in writing of the reasons and of your right to lodge a complaint with the supervisory authority and to seek a judicial remedy (Art. 12(4)). Where appropriate, we communicate rectification or erasure to the recipients/processors to whom the data was disclosed (Art. 19). Access and portability exports are delivered securely (to the verified account email, e.g. via an authenticated or expiring download link, rather than as unprotected attachments).

Right to lodge a complaint

You have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (AP), or with the supervisory authority of your EU country of residence:

Autoriteit Persoonsgegevens Postbus 93374, 2509 AJ Den Haag, Netherlands Telephone: 088-1805250 Website: autoriteitpersoonsgegevens.nl

Lodging a complaint with the AP is free of charge and does not require you to contact us first or to exhaust any other remedy. For cross-border processing, the AP may act as the lead supervisory authority under the GDPR's one-stop-shop mechanism.

10. Automated decision-making and profiling

We do not engage in automated decision-making which produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. We do not profile you for credit, employment, insurance, or any similar purpose. Our analytics events are account-linked (§3.1) but are analysed only in aggregate to inform product decisions; they do not produce individual decisions that affect your access to the Service.

11. Account deletion

You can delete your account and all associated data from inside the App:

Settings → Account → Delete account → type DELETE to confirm.

This places your account into a soft-deleted state immediately. The App explains, before you confirm, that deletion places your account into a 30-day recoverable state; signing back in within that window shows the restore countdown and lets you cancel the deletion. We do not send an account-deletion confirmation email (the in-App flow itself provides this information). After 30 days, an automated Cloud Function permanently removes:

Deleting your account does NOT automatically cancel a paid subscription. Subscriptions are billed by Apple or Google, not by us. If you have an active subscription, cancel it first with the Store before deleting your account, otherwise the Store may continue to bill you. You can reach the Store's cancel flow via Settings → Account → Manage subscription in the App, or directly through your Apple App Store / Google Play account settings.

Irreversibility. After the 30-day grace period the deletion is permanent and irreversible — the data cannot be recovered by you or by us.

If an automated deletion attempt fails (for example, a temporary outage at one of our processors), the deletion is retried automatically every day until it completes, and we keep the minimal operational record described in §8 ("Erasure bookkeeping") so the request is never silently dropped. Your account continues to show as pending deletion until the erasure completes.

What we may retain after deletion. We may keep: (a) fully anonymised/aggregated analytics that cannot be tied to you (within the §8 windows); (b) payment/tax records held by Apple/Google, and the minimal tax/transaction records we are legally required to keep (§8); (c) a minimal pseudonymous deletion marker (your bare account identifier and the deletion date), kept as evidence the erasure was honoured and to prevent late subscription events from re-creating deleted data (lawful basis: Art. 6(1)(c) — see §8); and (d) anything we must retain to comply with a legal obligation or to establish, exercise, or defend legal claims. Data is removed from live systems on purge; processor backups/replicas are overwritten or expire on the processor's standard cycle.

If for any reason you cannot access the App (lost device, locked out of your account), email hi@richicinschi.com from the email address associated with your account and we will action deletion within 30 days of receipt.

12. Children

The App is not directed at children and is intended for users aged 16 and over — the default age of digital consent under Article 8 GDPR (the Netherlands has not lowered this threshold to 13). Account creation is gated behind a 16+ self-attestation checkbox at sign-up — it is not pre-ticked, and sign-up cannot proceed until you confirm it; we record the confirmation timestamp (ageConfirmedAt) on your account (see §3.2). We do not knowingly collect personal data from anyone under 16.

United States (COPPA). The App is not directed at children under 13 and we do not knowingly collect personal data from them without verifiable parental consent. US users with a children's-privacy concern may also contact the U.S. Federal Trade Commission (reportfraud.ftc.gov / ftc.gov/complaint) in addition to the deletion route below.

Parents and guardians. If you are a parent or guardian and believe a child under 16 has provided us personal data or created an account, contact hi@richicinschi.com. After we verify your relationship to the child, you may review the child's data, refuse further collection, and request deletion, and we will delete the account.

The correct store age rating (not child-directed) and a pre-launch onboarding age-appropriateness review are completed as part of our store submission.

13. Marketing communications

We send only transactional emails: (1) email-address verification, (2) password reset, and (3) a one-time purchase & withdrawal-waiver confirmation when a subscription purchase that starts a new contract activates (once per contract — sent again when a re-subscription after expiry starts a new contract, never on renewals) — the durable-medium record EU consumer law requires of the immediate-performance consent you gave on the paywall (see Terms §6); it states your plan, store, purchase date, and the date of that consent. Emails (1) and (2) are sent through Firebase Authentication; email (3) is delivered via the Firebase "Trigger Email" extension through Google Workspace (Gmail) SMTP, as described in §6. All three are sent from our verified sender address noreply@richicinschi.com, and replies reach us at hi@richicinschi.com. We do not send an account-deletion confirmation email — account deletion is confirmed in-App (see §11).

All purchase confirmations, receipts, and renewal/billing notices are issued by Apple or Google (the merchant of record), not by us; apart from the one-time withdrawal-waiver confirmation above, we do not originate any subscription, receipt, or billing email.

We do not maintain a marketing email list, and we do not send promotional or newsletter emails. If we ever wish to send marketing, we will collect a separate, explicit, unbundled opt-in consent first, kept distinct from your acceptance of the Terms, and every such email will carry a one-click unsubscribe.

14. Security

We use industry-standard technical and organisational measures appropriate to the risk:

No system is perfect. If you discover a security issue, please email hi@richicinschi.com and we will respond promptly.

15. Data breach notification

If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will:

We maintain an internal breach register documenting the facts, effects, and remedial action for every personal-data breach (Article 33(5)), including breaches that are not notifiable, and we follow an internal incident-response procedure.

16. Cookies and similar technologies

The mobile App uses no cookies. It uses standard mobile-platform storage mechanisms — SharedPreferences (Android) and NSUserDefaults (iOS) — for purely local functional/preference settings such as your reminder time and preferred audio defaults. This storage is on-device only: it is not read by, transmitted to, or shared with us or any third party. The App may also keep temporary/cache files on the device (e.g. cached audio assets); these are local-only, are not transmitted, and are cleared when you uninstall the App or use your operating system's "clear storage" control. Separately, Firebase Authentication persists your session/authentication token in the platform's protected app storage (the iOS Keychain; on Android, SDK-managed app-private storage that our backup rules exclude from device backups) on your device; this token stays on-device, is not transmitted to or read by us, and is cleared when you sign out or uninstall the App. We have asked our Dutch jurist to confirm the ePrivacy/cookiewet position for app-local storage; our position is that this purely local storage is outside the scope of consent-requiring tracking.

The public web pages at richicinschi.com/breathe/* (the hosted Privacy and Terms pages required by the app stores) set no cookies at all. We do not serve advertising cookies, do not embed third-party trackers, and do not use analytics on those pages.

Do Not Track and Global Privacy Control. We do not track you across other companies' apps or websites, we do not serve targeted advertising, and we use no advertising identifiers. Because there is nothing cross-site to disable, we do not respond differently to browser "Do Not Track" (DNT) or Global Privacy Control (GPC) signals.

16A. Your California privacy rights (CCPA / CPRA)

This section applies to residents of California and supplements the rest of this policy. It is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA").

Definitions (as used in this section).

No sale, no sharing. We do not sell, and have not sold, personal information, and we do not share personal information for cross-context behavioral advertising — and we have not done so in the preceding 12 months. We run no financial-incentive programs related to personal information.

Categories of personal information we collect (preceding 12 months). Mapping the data in §3 to the CCPA statutory categories:

Sources of this information and the business/commercial purposes for collecting it are described in §3 and §5. The categories of third parties to whom we disclose information are our service providers (§6); we do not disclose personal information to other third parties except as required by law (§6).

Sensitive personal information. We do not collect or use sensitive personal information beyond what is necessary to provide the Service, so there is nothing to limit under the CPRA right to limit.

Your California rights.

How to submit a request. Use either of these designated methods: email hi@richicinschi.com, or the support page at https://richicinschi.com/breathe/support. You may also use the in-App controls (Settings → Account → Delete account; Settings → Data & privacy).

Verification. We verify requests by matching the request to the email address on your account and, where needed, one or more data points we hold; we will not disclose personal information without reasonable verification.

Authorized agents. An authorized agent may submit a Right-to-Know or Right-to-Delete request on your behalf with proof of authorization (e.g. a signed permission or power of attorney); we may also verify the agent's authority and your identity (per §1798.130 and Art. 12 GDPR).

Timeline, fees, and appeals. We confirm receipt within 10 business days and respond to verifiable requests within 45 days, extendable by a further 45 days with notice. Right-to-Know requests are free up to twice per 12-month period. If we deny a request, you may appeal by emailing hi@richicinschi.com with "Appeal" in the subject line; we will respond within a reasonable period. You may also contact the California Privacy Protection Agency or the California Attorney General.

Service-provider contracts. We disclose personal information to service providers and contractors only under written contracts that prohibit them from retaining, using, or disclosing it for any purpose other than performing the specified service, and that impose purpose limitation, retention limits, and reasonable security. Nothing in those arrangements restricts a service provider's or contractor's ability to comply with applicable law.

Shine the Light (Cal. Civ. Code §1798.83). California residents may request, once per calendar year, a list of the categories of personal information we disclosed to third parties for their own direct-marketing purposes in the prior year, and the names of those third parties. We do not disclose personal information to third parties for their direct-marketing purposes, so there is nothing to list. To confirm this or make a request, email hi@richicinschi.com.

17. Changes to this policy

We will update this policy when we add a new processor, collect a new category of data, change a retention period, or make any other material change. For a material change, we will give reasonable advance notice — at least 14 to 30 days before it takes effect — through:

No retroactive changes. Changes apply prospectively only; they do not retroactively reduce the protections that applied to personal data already collected under a prior version.

Version history. The "Last updated" date and "Document version" at the top of this policy always reflect the current version. This is version 13 (2026-07-10), superseding version 12 (2026-06-14). Version 13 completes the studio's trader-identity details following the Kamer van Koophandel registration and the Belastingdienst's issuance of the BTW identification number: the KvK number, the BTW (VAT) identification number, and the registered business address now replace the former administrative placeholders throughout (§1 and the contact sections). It does not change what data we collect, how we process it, or your rights. Version 13 also replaces every table in this document with plain lists so the policy reads clearly on phone and desktop screens alike — a formatting change only, with no change to the content of any disclosure. Finally, version 13 updates §6 for the studio's email-provider change (support mail to hi@richicinschi.com is now hosted by Google Workspace; Cloudflare provides DNS only and no longer routes email) and states the §3.2 consent-record lawful basis more precisely (Art. 6(1)(c) with Art. 7(1), rather than a stacked consent basis). Version 13 likewise names Google Workspace (Gmail) SMTP as the delivery path for the one-time withdrawal-confirmation email (§6, §13) and corrects the stored-data location to the precise europe-west1 (Belgium) region (previously described as the europe-west multi-region). Version 13 further corrects several descriptions to match the shipped App exactly: the subscriber history merge (the App merges the full on-device history and re-runs the sync while you are subscribed — not a one-time 7-day upload), challenge carry-over on subscribing, local-history retention (no automatic pruning; free users see the last 7 days), free-tier session history being device-local, the Android credential-storage wording, the account linkage of the reminder-opened event, and the hosted pages' cookie-free status. Version 13 also withdraws the machine-translated Dutch version of this policy: the App and its legal documents are provided in English only (studio decision of 2026-07-11); a future Dutch localization, if introduced, would ship with professionally reviewed Dutch documents. Version 12 (2026-06-14) makes no changes to this Privacy Policy — it tracks the Terms of Service's version 12 update of the Free vs Pro feature allocation (the technique catalogue expanded to ten techniques; the five new techniques are Pro Features), so one recorded acceptance covers both documents. Version 11 (2026-06-11) adds three disclosure clarifications and does not change what data we collect or your rights: it enumerates the CCPA statutory deletion exceptions and commits to telling you which one applies (§16A); discloses the aggregate, non-identifying app statistics that Apple and Google provide to us as the App's distributors, including Google Play's Android Vitals (§6); and references our internal business-continuity/disaster-recovery plan (§14). Version 10 (2026-06-11) made no changes to this policy (it tracked the Terms of Service's version 10 update of the Free vs Pro feature allocation, so one recorded acceptance covers both documents). Version 9 (2026-06-10) disclosed the one-time purchase & withdrawal-waiver confirmation email and its delivery path (§6, §13), the cloud-synced challenge progress for subscribers (§3.3), the account-identifier linkage of analytics events and crash reports (§3.1), and the erasure retry record and pseudonymous deletion marker (§8, §11). Version 8 (2026-06-10) disclosed the one-time history migration on subscribing, Android Auto Backup, and the email-edit support route. We maintain a version history and keep an archive of superseded versions; the previous version is also available on request from hi@richicinschi.com. We review this policy at least annually.

18. Governing law

This Privacy Policy is governed by the laws of the Netherlands and EU data-protection law, including the GDPR and the Dutch implementing act, the Uitvoeringswet Algemene verordening gegevensbescherming (UAVG). Mandatory EU law (including the GDPR and EU consumer-protection law) applies and prevails where Dutch national law would otherwise conflict with it. Disputes about its interpretation may be brought before the competent Dutch courts, without prejudice to your right as an EU consumer to seek redress before the supervisory authority or courts of your country of residence.

19. Contact and accessibility

For any privacy-related question, request, or complaint: hi@richicinschi.com, or by post to Van Delfthof 263, 5038 BX Tilburg, the Netherlands.

This policy is provided in English, in the App and on our website. If you need it in another accessible format, email hi@richicinschi.com and we will provide one.


20. Health disclaimer

The following statement applies to the entire App. It is adapted from the studio's standard health disclaimer (docs/legal/health-disclaimer.md), tailored to Breathe, and is incorporated into this Privacy Policy by reference.

Important: Not Medical Advice

The content in this app — the breathing exercises and any related wellness content — is provided for general informational and self-care purposes only. It is not medical, mental health, or psychiatric advice, diagnosis, or treatment.

If you are experiencing severe anxiety, depression, a panic attack, suicidal thoughts, or any mental-health crisis, please contact a qualified healthcare professional or one of the resources below. Always consult a doctor before changing a treatment plan or starting a new self-care practice, especially if you have a medical condition.

Crisis resources:

By using this app you acknowledge that the studio is not liable for any decision made based on its content.