At RE, we value your privacy. This Privacy Policy explains how we collect, use, store, and protect your information, including health and biometric data, when you use our application.
1. Information We Collect
A. Account Information
When you create an account, we collect your email address and any profile information provided through Google Authentication or email registration.
B. Session and Activity Data
We store your breathing session data (duration, timestamps, breath pace, and intention notes) and meditation records to provide you with a history of your progress.
C. Health and Biometric Data
Wearable Health Data
If you choose to connect a smartwatch or wearable device, RE requests read-only access to the following health metrics through Apple HealthKit (iOS) or Google Health Connect (Android):
Data Type
Purpose
Heart Rate
Measures your cardiac state during scans and verifies wearable connectivity
Heart Rate Variability (HRV)
Assesses nervous system balance and powers your 7-day rolling Balance trend, a personalized resting baseline
How this data is read: Heart rate is read when you explicitly initiate a watch scan. Heart rate variability is read during scans and when loading your recent HRV history to calculate your rolling Balance trend while the app is open. RE does not hold background health-read permissions and cannot access health data while the app is closed. You can also measure biometrics in real time using RE's native Wear OS and Apple Watch companion apps. You can revoke access at any time through your device health settings.
D. Camera-Based Biometric Data (PPG Scanner)
If you do not use a wearable device, RE offers a camera-based photoplethysmography (PPG) scanner. This uses your phone rear camera and flashlight to measure pulse light absorption through your fingertip. The app extracts spatial color averages (1D numerical arrays of brightness, never photos or video) and transmits them over TLS to our Google Cloud Run backend for signal filtering and spectral coherence calculation using HeartPy, SciPy, and NumPy. This data is processed ephemerally in volatile memory and is never written to disk or stored on backend servers. Only the final calculated biometric values (BPM, HRV, Coherence score) are saved to your account.
E. Information Collected Automatically
Usage Data: We use Firebase Analytics to collect anonymized information on app usage (such as features accessed and session durations).
Device Information: We collect technical details (device type, operating system version) for debugging and performance tuning.
Diagnostic Error Logs: Technical crash reports and error logs are stored in your private, isolated account partition to help resolve bugs, and are deleted when your account is deleted.
2. How We Use Your Information
To provide pre-session and post-session biometric comparisons, showing how your nervous system responds to breathing exercises.
To calculate your Balance trend, a 7-day rolling average of your resting heart rate variability compared to your recent baseline.
To track your resonance breathing progress over time with personalized insights.
To improve application performance and reliability through anonymized analytics.
To communicate with you regarding your account or service updates.
What We Never Do
We never sell, rent, or trade your health data to third parties.
We never use health data for advertising, profiling, or data mining.
We never share health data with insurers, employers, or data brokers.
We never read health data in the background while the app is closed.
3. Data Storage and Security
We use Google Firebase and Google Cloud Platform to manage account data, session history, and biometric calculations. Security measures include:
Encryption in Transit: All communications between the app, Firebase, and our Cloud Run backend use TLS encryption.
Encryption at Rest: Data stored in Firebase is encrypted at rest using AES-256.
Access Control: Your personal records are stored in an authenticated account partition. Firestore security rules enforce per-user isolation so only you can access your data.
Ephemeral Signal Processing: Raw PPG optical series and watch interval streams sent to Google Cloud Run are processed in memory and immediately discarded without being retained on the server.
Community and Group Sessions: If you join live Group Resonance sessions, your chosen display name (or an auto-generated anonymous pseudonym) and active breathing state are visible to other participants in that session. Your personal biometric measurements, historical logs, and notes are never shared and remain isolated to your private account.
4. Data Retention and Deletion
Active Account: Your health and session data is retained for as long as your account is active, allowing you to review your full progress history.
Individual Record Deletion: You can delete any individual scan, session, or meditation record at any time from within the app. Deletion is immediate and permanent.
Account Deletion: If you request account deletion through the app Profile settings, all associated data, including health, session, and biometric records, is scheduled for permanent deletion. Your data will be fully purged from our database and authentication systems after a 30-day grace period. You can log back in at any time during these 30 days to cancel the request and restore your account.
Revoking Health Access: Revoking RE access to HealthKit or Health Connect stops future data reads. Previously saved scan results remain in your account unless deleted individually.
5. Third-Party Services
Firebase Authentication: For user authentication and session security.
Cloud Firestore: For storing account settings, session history, and calculated biometric records.
Google Cloud Run: For ephemeral in-memory mathematical processing of camera PPG and watch biometric time-series.
Firebase Storage: For hosting and streaming guided mindfulness audio tracks (cached on-device for offline playback).
Firebase Analytics: For anonymized app telemetry and diagnostics.
Apple HealthKit and Google Health Connect: For reading heart rate and HRV metrics from your wearable device with your permission.
6. GDPR and CCPA Data Rights
Under GDPR, CCPA, and applicable privacy regulations, you have the following rights regarding your personal and health data:
Right to Access and Portability: Access all personal and health data we hold about you. You can export your full session history and biometric logs directly from the Profile settings as a standard JSON file.
Right to Rectify: Correct or update inaccurate or incomplete information.
Right to Erasure (Deletion): Request that your personal data be permanently deleted. When requested through the app, your account enters a 30-day grace period before complete automated erasure.
Right to Withdraw Consent: Revoke consent for health data access at any time through your device system settings.
Right to Object: Object to analytical processing of your usage patterns.
To exercise any of these rights, use the tools in the Profile section of the app, or contact us at the email provided below.
7. Medical Disclaimer
Important
RE is not a medical device. It is a breathing and wellness tool intended for relaxation and coherence training. Heart rate, HRV, and other biometric readings provided by RE are for personal wellness insights only and must not be used for medical diagnosis, treatment, or monitoring. Please consult a healthcare professional before starting new breathing or meditation practices if you have underlying health conditions.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised effective date. Continued use of RE after changes constitutes acceptance of the revised policy.
9. Contact Us
If you have questions about this Privacy Policy or how your data is handled, please contact: