Effective 20 July 2026
Privacy Policy
How Breath Cycle handles information.
This policy covers the Breath Cycle iPhone app, its optional encrypted Pro backup service, and the public Breath Cycle website. The core app works without a Breath Cycle account, advertising, or third-party analytics.
Who provides Breath Cycle
Breath Cycle is developed and provided by Domenico Marco Di Donna. Questions about this policy may be sent to domenico.dd@gmail.com.
Local app data
Preferences, breathing sessions, optional reflections, calibration results, custom patterns, and plan progress are stored on your device. Breath Cycle uses this information on-device to provide history, restore your choices, and generate deterministic recommendations. Your iPhone remains the primary copy.
Breath Cycle 1.0 does not use third-party analytics, advertising SDKs, remote configuration, or anonymous aggregate uploads.
Optional Encrypted Pro Backup
Encrypted Pro Backup is an optional subscription feature and does not start when you subscribe. It starts only after you separately choose Enable Encrypted Pro Backup in Settings and confirm the data explanation.
If enabled, Breath Cycle creates a copy of supported sessions, reflections, calibration results, custom patterns, and plan progress. The app encrypts that archive on your iPhone using AES-GCM before upload. The encrypted archive is stored in a private Cloudflare R2 bucket configured for the European Union. Cloudflare receives ciphertext and cannot read the archive contents.
A random encryption key is stored in the Apple Keychain and may synchronize between your devices through iCloud Keychain, subject to your Apple settings and Apple’s privacy terms. If that key is unavailable, Breath Cycle cannot decrypt the cloud copy. The app does not upload the key to Cloudflare.
Backup identity and subscription verification
No Breath Cycle login is required. For each backup request, the app sends Apple-signed app and Pro subscription records over HTTPS. The service verifies Apple’s signatures, the Breath Cycle bundle identifier, the subscription product, expiration, revocation, and grace-period information. The records can include Apple’s stable app-transaction identifier and purchase status. Breath Cycle hashes the app-transaction identifier before using it as the private R2 object path; it does not store the raw identifier or payment-card details in the backup object.
This information is processed to authenticate the request, keep one private backup per Apple Account and app, prevent unauthorized access, and enforce Pro access. A lapsed subscription pauses upload and restore but does not delete local data. Cloud deletion remains available without an active Pro subscription.
Sharing and service providers
Breath Cycle does not sell app data or share it with advertising, analytics, or marketing companies. Apple provides StoreKit and iCloud Keychain under Apple’s terms and privacy policy. Cloudflare provides the Worker, private R2 storage, networking, and security used for optional encrypted backup. Cloudflare processes encrypted backup content, request metadata such as IP address and HTTP headers, and Apple-signed verification data on the developer’s behalf under the Cloudflare Privacy Policy.
Subscriptions
Breath Cycle Pro subscriptions are processed by Apple through StoreKit. Apple handles payment and transaction-account information under Apple’s privacy policy. Breath Cycle checks Apple-signed subscription status on the device to provide Pro access and respond to expiration, refunds, revocation, billing retry, or grace-period status. The developer does not receive your full payment-card details.
Performance diagnostics
The optional Performance Test measures frame timing, renderer failures, Low Power Mode, and thermal state on the device. Results stay in local app preferences and are not sent to the developer.
Your privacy choices, export and deletion
You can export supported local records in JSON and CSV formats, delete local app history, turn encrypted backup off, or permanently delete the encrypted cloud copy from Breath Cycle Settings. Turning backup off stops synchronization but does not delete the existing cloud copy; use Delete Cloud Backup for deletion.
Local records remain until you delete them or remove the app, subject to standard device-level iOS backup and restore behavior. The encrypted cloud copy remains until you delete it. Uninstalling the app or ending Pro does not automatically delete it. If backup is still enabled on another device, that device can create a new copy after deletion, so turn backup off on all devices when you want synchronization to stop everywhere.
You may also request access, correction, deletion, restriction, or portability of personal information where applicable by emailing domenico.dd@gmail.com. Because backup contents are client-side encrypted and indexed by a one-way hash, in-app deletion is the fastest and most reliable way to remove the cloud copy.
Website hosting
The Breath Cycle website is static and does not set analytics or advertising cookies. Cloudflare provides website hosting and network security and may process technical request information, such as an IP address and HTTP headers, to deliver and protect the site.
Support communications
If you email support, the developer receives your email address and any information you choose to include. It is used only to answer your request and is retained only as long as reasonably necessary for support and legal obligations. You may request deletion by emailing domenico.dd@gmail.com.
Children
Breath Cycle is a general wellness utility and is not directed to children under 13. The app does not knowingly collect children’s personal data.
International use
Local app data remains on your device unless you explicitly enable encrypted backup. Backup objects are stored in Cloudflare’s EU jurisdiction. Apple, Cloudflare, and email providers may process operational information in other locations in accordance with their services, contractual safeguards, terms, and privacy policies.
Legal bases
Where data-protection law requires a legal basis, optional backup content is processed with your consent and to provide the feature you request; subscription evidence is processed to perform the subscription service; security and limited operational request information are processed for legitimate interests in protecting and reliably operating the service. You can withdraw backup consent by turning it off and can delete the stored copy in Settings.
Changes to this policy
If app behavior changes, such as adding analytics, an account system, new processors, or aggregate uploads, this policy and the App Store privacy disclosure will be updated before that behavior is released. The effective date above will also be revised.
Contact
Domenico Marco Di Donna
domenico.dd@gmail.com