Last updated: September 6, 2026
This Privacy Policy describes how Lotus Breath (“the App”, “we”, “us”, or “our”) collects, uses, and shares information when you use our iOS application. By using the App, you consent to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the App.
The App has no user accounts and no sign-in. Your breathing exercises, history, and progress live on your device and sync through your own private iCloud account, which we cannot access. Two kinds of data leave your device to us: anonymous usage analytics, crash reports, and performance measurements, which you can turn off at any time, and — only if you open the in-app store — a record of any purchase, which we need in order to give you what you paid for and to restore it on your other devices. Payment itself is handled entirely by Apple; we never see your card or billing details.
We use Mixpanel, a third-party analytics service, to understand how the App is used and to improve it. We also use Sentry, a third-party error monitoring service, to detect and fix crashes and errors and to measure the App’s performance.
When analytics is enabled, the following data is collected:
Event properties never include text you have typed. Exercises you create yourself are identified in analytics by a random identifier and their numeric breathing pattern, not by the name you gave them. Names are only included for the App’s own built-in exercises.
We do not collect or send to any server:
Mixpanel’s automatic event tracking is disabled — apart from the device and app context described above, only the events listed here are sent. Sentry collects data when an error or crash occurs and when a session is sampled for performance measurement, and it is configured not to send your IP address.
Anonymous analytics is on by default. You are shown the choice during onboarding, on the final setup step, where you can switch it off before you start using the App. You can also change it at any time afterwards in the App’s Settings screen under “Privacy”. Your choice is stored alongside your other settings and syncs through your private iCloud account, so switching it off applies on every device signed in to the same iCloud account.
We rely on legitimate interest rather than consent for this processing — see “Legal Basis for Processing” below — and you have an unconditional right to object by switching it off.
When you turn anonymous analytics off:
Crash reporting and performance measurement via Sentry remain active regardless of the analytics setting, as they are necessary to keep the App stable and usable. This data is minimal and anonymous, and it is not used to build a picture of how you personally use the App.
The App stores your breathing exercises, practice history, settings, streak data, and anything an in-app purchase has granted you (an active XP boost and your streak freeze balance) locally on your device using Apple’s on-device database. This data is automatically synced across your devices through your private iCloud account via Apple’s CloudKit service. The synced data is stored in your personal iCloud storage and is not accessible to us. Apple’s iCloud terms and privacy policy govern this data.
The App has no user accounts and no sign-in. Aside from the analytics, crash reporting, and purchase verification services described in this policy, we do not operate servers that hold your data, and we have no access to your iCloud data.
A small amount of additional information is kept in Apple’s iCloud key-value storage rather than in the database: whether the App has been installed on your iCloud account before, and the purchase identifier and applied-purchase list described under “In-App Purchases”. This storage belongs to your iCloud account and we cannot read it.
If you enable Sync to Apple Health, each completed breathing session is written to Apple HealthKit on your device as a mindful session, so it counts towards your mindfulness minutes. The App only ever writes this data — it does not request permission to read anything from Health, and we never see it.
If you enable the daily reminder, the App schedules a local notification on your device at the time you choose. The reminder text is fixed and generated on your device. Local notifications are handled entirely by iOS — no reminder content is sent through us or any third party.
We do not send you push notifications and we run no service capable of doing so. The App does permit the silent background notifications that Apple’s iCloud sync uses to signal that your data has changed on another device. These are sent by Apple, carry no content, and are never shown to you.
The App offers optional in-app purchases: XP boosts, which multiply the experience you earn for a limited period, and streak freezes, which protect your streak on a missed day. Nothing in the App is locked behind a purchase.
All payment processing is handled entirely by Apple through the App Store. We do not collect, process, or store any payment information such as card numbers, billing addresses, or Apple ID credentials, and we never learn who bought what.
Apple issues a cryptographically signed receipt for each transaction. The App sends that signed receipt to our purchase verification service so that we can confirm it is genuine and work out what it entitles you to. We verify signatures on our own server rather than trusting the device, because otherwise a modified copy of the App could grant itself unlimited boosts.
Along with the receipt, the App sends a purchase identifier: a random UUID generated on your device. It is stored in Apple’s iCloud key-value storage so that it survives reinstalling the App and follows your other devices, which is what makes restoring a purchase possible. It is not derived from your Apple ID, is not linked to your name or email address, and is never included in analytics events or crash reports.
The App contacts this service when you open the store screen, not only when you buy something: it fetches the current list of products and any entitlements already on record. That request carries your purchase identifier but no transaction, so nothing is recorded. The identifier is created at that point if it does not already exist, which means it can come into being before you have bought anything.
We store a record of each verified purchase containing:
From these records we calculate your current entitlements — the multiplier and expiry of any active XP boost, and the total number of streak freezes you have bought — and send them back to the App, which applies them to your progress.
As with any request to an internet service, our purchase verification service receives your device’s IP address in order to respond. We do not store it: there is no IP address in your purchase record and our code never reads or logs one. Our hosting provider may retain it briefly in its own infrastructure logs, as described in their privacy policy.
This information is pseudonymous: it is tied to a random identifier rather than to your identity, and we have no way to connect it to a person. Because a purchase record is nonetheless personal data under GDPR, see the “Legal Basis for Processing” section below.
Apple’s App Store terms and privacy policy govern the payment transaction itself. For more details, see Apple’s Privacy Policy.
We do not use your data for advertising, profiling, or selling to third parties.
We process data under the following legal bases:
The App has no accounts and requires no registration, so we process no data for the purpose of identifying you.
Analytics data is sent to Mixpanel, Inc., a US company. Mixpanel acts as a data processor under GDPR and processes data solely on our instructions. Mixpanel is SOC 2 Type II certified. The App sends analytics to Mixpanel’s EU data ingestion endpoint, so the data is held on Mixpanel’s EU infrastructure.
As the App is provided by a Finnish company, any transfer of that data to Mixpanel in the US is covered by Standard Contractual Clauses in accordance with GDPR requirements.
For more details on how Mixpanel handles data, see:
Crash reports, error reports, and performance measurements are sent to Functional Software, Inc. (Sentry), based in the United States, and are stored on Sentry’s US infrastructure. Sentry acts as a data processor under GDPR and processes data solely on our instructions. The App is configured not to send personally identifying information, including your IP address, and does not attach a user identity to reports. Sentry is SOC 2 Type II certified.
As the App is provided by a Finnish company, transfers of data to Sentry in the US are covered by Standard Contractual Clauses in accordance with GDPR requirements.
For more details on how Sentry handles data, see:
Purchase verification and the record of your purchases are handled by Supabase, Inc., which hosts the database and the verification service we operate. Supabase acts as a data processor under GDPR and processes data solely on our instructions. Our project is hosted in the European Union (Frankfurt, Germany), so purchase records are stored in the EEA. Supabase is a US company, and any access from outside the EEA for support or maintenance is covered by Standard Contractual Clauses under its Data Processing Addendum.
Supabase receives only the purchase data described in the “In-App Purchases” section. It receives no analytics, no health data, and none of your breathing exercises or practice history.
For more details on how Supabase handles data, see:
Payment for in-app purchases is processed by Apple through the App Store, and Apple issues the signed transaction records we verify. Your app data syncs through Apple’s CloudKit service using your private iCloud account. If you opt in to Apple Health sync, completed sessions are written to HealthKit; the App never reads your Health data. Apple’s privacy policy applies to all of these. For more details, see Apple’s Privacy Policy.
The App’s menu contains links to our pages on Instagram and Facebook, and the share button hands your progress image to whichever app you pick from the iOS share sheet. These open outside the App and are entirely up to you. Once you leave, the privacy policy of that service applies rather than ours. We do not embed any social media tracking in the App, and those companies receive nothing from us unless you choose to share.
Because the App has no accounts, there is no account to delete. You can remove your data as follows:
You can also switch analytics off in Settings at any time to stop all future analytics collection.
If you are in the European Economic Area, you have the right to:
The App does not knowingly collect any personally identifiable information from children under the age of 13. If you believe a child has provided personal data to us, please contact us so we can take appropriate action.
We will update this Privacy Policy when our data practices change. If we make material changes, we will notify you through an in-app notice or by updating the App Store listing before the changes take effect. Changes will be posted on this page with an updated “Last updated” date.
The following reflects what we declare in our App Store privacy labels:
If you have any questions about this Privacy Policy, you can contact us by email:
valtteri.e.laine@gmail.com