Privacy
Privacy Policy
How we collect, use, and protect your information.
Last updated: April 21, 2026
Privacy at a Glance
- We collect only what we need to operate Phoenix Breath.
- We do not sell your personal information.
- Your wellness and health data is treated with heightened care.
- You can request access or deletion at any time.
This Privacy Policy explains how Arise Health LLC ("Arise Health," "we," "us") collects, uses, shares, and protects information when you use Phoenix Breath (the "App") and related services (collectively, the "Services").
Phoenix Breath is intended for adults 18 and older and is a wellness product, not a medical service.
1. Information We Collect
We collect information in the following categories:
A) Information You Provide
- Account information: email address (via email registration, Google OAuth, or Apple Sign-In), and any optional profile information you choose to provide. If you sign in using Google OAuth, we receive your name and email address from Google. We do not receive your Google password. If you sign in using Apple Sign-In, we receive an identity token, your email address (or a private relay address if you use Apple's "Hide My Email" feature), and your full name on first sign-in only — Apple does not return your name on subsequent sign-ins. If you use Hide My Email, we receive a randomized relay email and cannot contact you outside of that relay.
- Health screening responses: information you provide during the pre-session health screening, including whether certain medical conditions apply to you. This data is used solely to enforce safety protocols and session eligibility.
- Wellness inputs: responses to in-app check-ins and intake questions (for example, stress level, nervous system state, physical sensations), including self-reported emotional or physical state before and after breathwork sessions.
- Journaling and reflections: any text you enter during post-session journaling prompts or reflective exercises within the App.
- Intake and chat interactions: information you share during guided conversations with Ember, our in-app virtual guide powered by Google's Gemini API.
- Consent and waiver records: your acceptance of the Safety & Informed Consent and Release of Liability, including timestamps, versions accepted, and typed confirmations (such as "I AGREE").
- Support communications: messages you send to us for help or feedback, and any information you include.
B) Information Collected Automatically
- Session history: which sessions you start and complete, session duration, timestamps, whether you ended a session early, and how you exited (completed, used Soften, or ended manually).
- Device and technical data: device type, operating system version, app version, language/locale, unique device identifiers, and diagnostic data.
- Usage data: how you interact with the App, including screens visited, features used, navigation patterns, and in-app events.
- Crash and performance data: crash logs and basic performance metrics (if enabled).
- Log data: IP address, access times, and error reports.
C) Purchase Information
Purchases are processed through Apple's App Store and Google Play. We do not receive or store your full payment card details. We may receive limited purchase status information (for example, whether your purchase is active) to provide access to paid features.
2. How We Use Your Information
We use information to:
- Provide and operate the Services: create and manage your account, authenticate your identity, deliver breathwork sessions, and power the Ember guided experience.
- Enforce safety protocols: determine session eligibility based on health screening responses, enforce session gating requirements (such as requiring shorter sessions before access to longer ones), and display appropriate safety information.
- Personalize your experience: tailor guidance, summaries, and session recommendations based on your check-ins, emotional state data, and session history.
- Support consent and legal compliance: maintain records of your informed consent and liability waiver acceptance, and demonstrate compliance with applicable law.
- Improve the Services: analyze usage patterns, session data, and feedback to improve app performance, session design, and the overall user experience.
- Communicate with you: respond to support requests, send service-related notifications, and, if you opt in, send product updates or marketing communications. You can opt out of marketing communications at any time.
- Protect security: monitor for fraud, prevent abuse, and protect the security and integrity of the Services.
We do not use your health screening responses, emotional state data, or journaling content for advertising purposes.
3. Sensitive Information
Some information we collect may be considered sensitive or health-related under applicable law, including your health screening responses and emotional state check-ins. We treat this information with heightened care:
- Health screening data is used solely to enforce safety protocols and session eligibility. It is not shared with third parties for marketing or advertising.
- Emotional state data is used to personalize your experience and improve the Services. It is not sold or shared for commercial purposes.
- Journaling content is stored for your personal use and is not analyzed for advertising or shared with third parties.
- We do not use health or emotional data to make automated decisions that produce legal or similarly significant effects on you.
4. Third-Party Services and Data Sharing
We do not sell your personal information. We do not share your personal information with third parties for their own marketing purposes.
We use the following third-party services to operate the Services:
| Service | Purpose | Data Processed |
|---|---|---|
| Google Firebase | User authentication, database, and cloud infrastructure | Account info, session history, consent logs, health screening responses, emotional state data, journaling content |
| Google Gemini API | Powers Ember, the in-app virtual guide | Intake conversation content, user messages to Ember |
| Google Analytics / Mixpanel | App usage analytics and product improvement | Device info, usage patterns, session events (anonymized or pseudonymized where possible) |
| Google OAuth | Account sign-in | Authentication tokens; we receive your name and email from Google |
| Apple Sign-In | Account sign-in on iOS | Identity token; we receive your name and email (or private relay email) from Apple. No session or wellness data is shared with Apple. |
| Apple App Store / Google Play | Purchase processing | Purchase status; we do not receive full payment details |
These providers are authorized to use personal information only as needed to provide services to us.
We may also share information:
- For legal and safety reasons: to comply with law, enforce our terms, or protect rights, safety, and security.
- Business transfers: in connection with a merger, acquisition, or sale of assets. If this happens, we will provide notice as required by law.
5. AI and Automated Processing
Ember, the in-app virtual guide, is powered by Google's Gemini API. When you interact with Ember, your messages are sent to Google's servers for processing and a response is returned to the App.
We do not use your conversations with Ember to train third-party AI models. However, Google may process this data in accordance with their own terms and policies. We encourage you to review Google's privacy and AI data policies.
Ember does not make medical, diagnostic, or treatment decisions. It provides guided intake, safety information, and session facilitation only.
6. Data Security
We use reasonable administrative, technical, and organizational measures designed to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication through Google OAuth and Firebase Authentication
- Access controls limiting who can view personal data
- Regular review of data collection and storage practices
No system is 100% secure, and we cannot guarantee absolute security.
7. Data Retention
We retain personal information only as long as necessary for the purposes described in this policy, unless a longer period is required or permitted by law. Specific retention practices:
- Account information: retained until you delete your account.
- Consent and waiver records: retained indefinitely for legal compliance purposes, even after account deletion. This is necessary to demonstrate that you provided informed consent before using the Services.
- Health screening responses: retained for the duration of your account; deleted upon account deletion, except as incorporated into consent logs.
- Emotional state data and journaling content: retained for the duration of your account; deleted upon account deletion.
- Session history: retained for the duration of your account; deleted upon account deletion.
- Analytics data: retained in anonymized or aggregated form and may persist after account deletion.
If you delete your account, we will delete or anonymize your personal information within 30 days, except where we must retain certain information for legal, security, or fraud-prevention purposes (such as consent and waiver logs).
8. Your Choices and Rights
You can:
- Access, update, or correct certain account information in the App
- Request deletion of your account and personal information
- Opt out of marketing communications at any time
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you may have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- Right to Know: You may request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is required.
- Right to Limit Use of Sensitive Personal Information: Your health screening and emotional state data are used only for the purposes disclosed in this policy. You may request that we limit use of this data.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To submit a privacy request, contact us using the information in Section 13. We may need to verify your identity before processing your request. We will respond within 45 days.
European Economic Area, UK, and Swiss Residents (GDPR)
If you are located in the EEA, UK, or Switzerland, we process your personal data on the following legal bases:
- Contract: processing necessary to provide the Services you requested.
- Legitimate interest: analytics and product improvement.
- Consent: processing of health screening and emotional state data.
- Legal obligation: retention of consent and waiver records.
You also have the right to data portability and the right to lodge a complaint with your local supervisory authority.
9. Cookies and Tracking Technologies
Phoenix Breath may use SDKs and similar technologies to:
- Remember preferences
- Understand app usage and performance
- Improve reliability and user experience
You can limit certain tracking through your device settings. Disabling certain tracking may affect app functionality.
Some browsers transmit "Do Not Track" (DNT) signals. There is no industry standard for how to respond to these signals. We do not currently respond to DNT signals.
10. Children's Privacy
Phoenix Breath is not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take steps to delete it promptly.
11. International Transfers
Your information may be processed in countries other than your own, including the United States. Where required by applicable law, we use appropriate safeguards to protect personal information during international transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last Updated" date at the top of this page. If changes are material, we will provide additional notice (for example, in-app notification). Your continued use of the Services after any update constitutes your acceptance of the revised policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Arise Health LLC
17225 Bollinger Canyon Rd, Unit B223
San Ramon, CA 94582