Privacy
The short version
önd is designed to collect as little as possible:
- önd has no ads or analytics, and you do not have to create an account.
- Our server recognises your phone by a random ID. The ID is not based on you or your device.
- We store your onboarding answers and practice data so the app can keep your history and streaks. Sign in with Apple lets you recover them on a new phone.
- We do not sell your data.
If you ask the coach a question, we send some of what you have told us to Amazon Bedrock so a language model can answer. That information is not used to train a model, and it is not kept. See The coach and the language model for the exact details.
önd can record your sessions and mood responses in Apple Health. If you opt in, it can also read four Health measures: three give the coach some context, and one lets your phone draw your heart rate around each session. See Health for what önd reads and writes.
Who we are
önd is made and operated independently by Tim Holmes-Mitra of Bath, United Kingdom. He is the data controller under the UK GDPR. You can reach us at support@ondbreathe.app.
Your identity, and the optional sign-in
When you first open önd, the app creates a random identifier and stores it in your device's Keychain. Our server uses this identifier to recognise your data on later requests. It is not based on your hardware, Apple ID, phone number, or anything else about you.
We never ask for an email address or password. Sign in with Apple is optional and appears in Settings, never as a gate. Its only purpose is to recover your history on a new phone. If you use it, we store the account identifier Apple creates for önd. That identifier is stable for önd and meaningless to anyone else. We do not ask Apple for your name or email address, so Apple sends us neither.
Signing in on a second device adds that device's history to your account and retires its original random identifier. Signing out gives the device a new random identifier but leaves its local practice history in place. The history linked to your Apple account remains available for next time. Deleting your account removes the Apple identifier with everything else.
The app starts without a sign-in, and most people never add one. Without a sign-in, we cannot recover your history if you lose both the device and its identifier. We also cannot confirm by email that a record is yours without that identifier. After you sign in, the identifier alone is no longer enough to reach your account. A device must also present a credential issued by önd after Sign in with Apple.
What we store
Everything below is stored against your random identifier and nothing else.
- The answers you give us
- Onboarding asks four optional questions: your first name, what you want from breathing, your experience, and how often you want reminders. Settings includes four more optional fields: a decade-wide birth-year band, your gender, a leaderboard display name, and a short note about what brought you here. Each field stays blank until you fill it in and becomes blank again if you clear it. Only you see your first name. Other people can see your display name if you join a leaderboard.
- What you breathe
- For each session you keep, we store the exercise, start time, duration, number of cycles and breaths, and whether you completed it or ended it early. An early end is never treated as a failure. If you measure your comfortable pause, we store its length in seconds and the date. If you count your resting breathing rate, we store the breaths per minute and the date.
- Your subscription, if you have one
- We store the App Store transaction identifier for your subscription and its expiry date. This tells the server what you have paid for. Apple handles the payment, so we never see your card, billing address, or Apple ID.
- A credential for the device you signed in on
- If you sign in with Apple, we issue the device a random credential and store only a one-way hash of it. Your identifier alone is then no longer enough to reach your account. The credential says nothing about you and is never shown to you. It remains valid on that device until you sign out successfully or delete your account.
- Exercises you write yourself
- If you make a breathing exercise, we store its name, your description, the goal, its stages, and its timings. This lets the exercise move to a new phone. Nobody else can read it, and it never appears on a leaderboard. The coach learns only that you practised "another exercise." It never receives the name or description you wrote.
- A daily counter, if you use the coach
- We store one number per day: how many language-model calls you have made. This lets us limit the cost of the model.
- What our server logs
- We log one line for each request your app makes. It records the operation, whether it succeeded, how long it took, and your random identifier. For coach calls, it also records the request and reply sizes in tokens, but never the words. We use these logs to investigate faults. The logs have a size limit, so newer entries replace older ones. They are not deleted on a fixed schedule, and deleting your account does not remove them.
Reminders are off until you create one. The app asks iOS for notification permission when you add your first schedule, never before. Your schedules stay on your device, and we never see them.
The coach and the language model
The coach uses a large language model to answer. We do not run that model ourselves. Calls go directly from our server to Amazon Bedrock, Amazon Web Services' model service, with no broker or reseller. The credentials for those calls stay on our server and are never included in the app.
To answer usefully, the request sent to Bedrock includes some of what you have told us:
- Your goals and your stated experience level
- Your birth-year band and gender, if you gave them, because published comfortable pause reference ranges differ by both
- Your free-text note, in your own words, if you wrote one
- Your recent practice, comfortable pauses, and resting breathing rates, if you have recorded any
- A coarse heart summary, if you turned that setting on — see Health below
- The question or technique you asked about
Your display name and random identifier are never sent. Without the identifier, the model service cannot link one conversation to another. Take care with the free-text note because it is the one place where you can enter anything. We include that note word for word.
We do not store prompts, replies, or explanations in our database or logs. Only the daily counter described above and a log line with the size of the call remain on our side. Amazon handles coach requests under our instructions and contract. Your words are not used to train or improve a model, and Amazon does not retain them after the answer returns. The company that built the model does not receive them.
The coach gives general wellness guidance about breathing. It is not a doctor. It cannot diagnose, and nothing it says is medical advice.
Health
önd writes two kinds of information to Apple Health. If you ask it to, it also reads four Health measures. Nothing read from or written to Health is stored on our server. Reading is off until you switch it on.
- What we write to Health
- Each session you keep can be recorded on your device as Mindful Minutes. The entry contains its start time and duration, and nothing else. Your iPhone and Apple Watch each write the sessions they ran. iOS asks for permission the first time there are minutes to record. If you decline, only the Health entry is lost.
- How you say you feel
- An iPhone session can ask how you feel before it starts and again at the end. Each answer is written to Health as a State of Mind entry. The entry contains a point on Apple's pleasantness scale and the time you tapped it. önd does not store the answer, and it never reaches our server. Skipping the question writes nothing. You can stop the questions under Settings → Ask how you feel before and after. iOS asks for this permission separately from Mindful Minutes when you first answer.
- What we read, only if you turn it on
- Settings → Read my heart data is off until you switch it on. That action asks Health for access to four measures: sleeping breathing rate, resting heart rate, heart rate variability (HRV), and heart rate around your sessions. önd reads nothing else. Turning the setting off means the next coach request contains no Health summary. The same setting appears under Coach → Check-ins, beside the figures it reads.
- Your heart rate around a session
- With the same setting on, Home draws one mark for each recent session. The mark is your average heart rate during that session, read from Health when the card appears. The individual readings are reduced to one number and then discarded. Nothing is kept between drawings or added to a coach request. A session has a mark only if your Watch recorded enough heart data; otherwise, it stays blank.
- What actually leaves your phone
- Your individual Health readings never leave your phone. The phone reduces the last eight weeks to whole-number summaries: a seven-day average and, when there is enough history, one number showing how it has changed. Only those summaries are attached to the coach request you make. They include no dates or individual readings, and nothing is sent when the setting is off. Coach → Check-ins shows you the same summaries. Opening that screen sends nothing.
We do not store Health data. A Health summary exists on our server only for the length of one coach request. It is sent to Bedrock with that request and then dropped. It is never written to our database or logs.
We rely on your explicit consent to process this Health data. Switching the setting on gives that consent, and switching it off withdraws it. Turning the setting off does not remove Apple's permission. You can remove that separately in the Health app.
Leaderboards are opt-in
You appear on a leaderboard only if you choose a display name. Without one, the service leaves you out of every board. This rule is enforced when each leaderboard is built.
If you set a display name, other people see that name and the value being ranked: practice minutes, your current streak, your best comfortable pause, or your slowest resting breathing rate. They never see your other answers, note, or session history. Clear your display name to leave the boards again.
What we never do
- We do not show advertising or use ad identifiers.
- We do not include third-party analytics, attribution, or crash-reporting software. The app's only outside code is two open-source libraries used to talk to our server: one for network calls and one for the message format.
- We do not sell, rent, or share your data for anyone else's purposes.
- We do not track you across other apps or websites.
- We do not ask for your location, contacts, photos, or microphone.
- We read only the four Health measures described in Health, and only after you switch the setting on.
Where your data lives
Your stored data lives on one server in Amazon Web Services' London region (eu-west-2), in the United Kingdom. Each night, we make an encrypted database backup in Amazon's storage service in the same region. The backup is deleted automatically after 30 days.
Coach requests are the one exception. We send them to Bedrock's London endpoint. When it needs more capacity, Bedrock may process a request in Ireland, Frankfurt, Paris, Stockholm, Milan, or Spain. A coach request may therefore leave the United Kingdom, but it remains within the United Kingdom or the European Economic Area. It stays inside Amazon Web Services and is not stored by önd or Bedrock.
How long we keep it
We keep your profile, practice history, and personal exercises until you erase them. Sessions you delete in the app are deleted from the server during the next sync. Coach conversations are never stored, so there is nothing to retain.
There are two exceptions. A nightly database backup contains whatever was stored when it ran and is deleted after 30 days. Server logs contain only the request details described above and are removed as newer entries reach the size limit, not on a fixed date.
Your rights, and how to erase everything
Under the UK GDPR, you can ask for a copy of your data, ask us to correct or erase it, or object to how we process it. You can also edit most of this data directly in the app.
You can erase everything yourself without waiting for us. Go to Settings → Delete account → Delete everything. This action:
- Removes your profile, sessions, comfortable pause measurements, resting breathing rate measurements, personal exercises, coach counter, Apple sign-in link, and account row from our server.
- Clears the copies on your iPhone and paired Apple Watch, including reminder schedules and notifications queued with iOS.
This is a deletion, not a hidden account state. Nothing in the app or live server can restore it. A nightly backup may still contain the data until it expires within 30 days. We open a backup only to restore the whole database after a failure.
Deleting your account does not cancel an önd subscription. Only Apple can do that. Use Manage subscription in the app or open your name in the system Settings.
If you want us to delete the data for you, email support@ondbreathe.app. We hold no name or email address that could identify your record, so include your Support ID. This is a short prefix of your random identifier. It identifies the record without granting access to it. Open Settings, find Support ID under Account, tap the row to copy it, and paste it into your message.
Deleting the app does not erase data from the server. The identifier is stored in the Keychain and may survive a reinstall. To erase your data, use the in-app control or write to us.
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
Our lawful bases
- We process your onboarding answers, practice history, personal exercises, and subscription details to provide the app. This is performance of a contract. If you sign in, the same basis covers using your Apple account identifier to restore your history.
- We process your optional first name, birth-year band, gender, note, and display name with your consent. You give consent by filling in a field and withdraw it by clearing the field.
- Health trends are special-category health data under the UK GDPR. We process them with your explicit consent and for no other purpose. Turning the setting on gives consent, and turning it off withdraws it.
- We use our legitimate interest in controlling service costs to process the daily coach counter.
- We use our legitimate interest in investigating faults and recovering the service to keep server logs and nightly backups.
Children
önd is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has given us data, email support@ondbreathe.app and we will erase it.
Changes to this policy
If we change how we handle your data, we will update this page and move the date at the top.