Privacy Policy
Vagal - Breathing Exercise App
Last updated: September 28, 2026
On this page
- Overview
- 1. Data We Collect
- 2. How We Use Your Data
- 3. Data Sharing
- 4. Data Retention
- 5. Your Rights
- 6. Security
- 7. Children's Privacy
- 8. Third-Party Services
- 9. Changes to This Policy
- 10. Contact Us
- 11. California Residents (CCPA)
- 12. European Residents (GDPR)
- 13. Not a Medical Device
- 14. Washington Residents: Consumer Health Data Privacy Policy
Overview
Vagal ("the app") is a breathing exercise application operated by Entropy Ventures LLC ("we", "our", "us"), the data controller for the personal data described here. We are committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
The short version: We collect minimal data, store most of it only on your device, never sell your data, and don't show ads.
Washington residents: our Consumer Health Data Privacy Policy is §14.
1. Data We Collect
1.1 Data Stored Only on Your Device (Local)
The following data is stored locally on your device and never leaves your device unless you use Cloud Sync, export it yourself, or opt in to analytics:
- Session history: Breathing patterns used, duration, cycles completed, completion status
- Mood check-ins: The optional one-word mood tag you can attach to a session
- Calibration data: Your personalized breathing rate (BPM)
- App preferences: Sound settings, haptic preferences, reminders, goals, your first name if you enter one
- Recommendation data: Usage patterns for personalized suggestions, computed on your device
- Integration tokens: Oura access and refresh tokens, held in the operating system's secure keystore (iOS Keychain / Android Keystore)
1.2 Health Data (Apple HealthKit / Google Health Connect)
If you grant permission, we may read:
- Heart Rate Variability (HRV, SDNN on iOS / RMSSD on Android): To show before/after session improvements
- Heart Rate: For wellness insights during and around a session
- Mindful Minutes (iOS only): To recognize sessions you have already logged
If you grant permission, we may write:
- Mindful Minutes / Mindfulness Sessions (iPhone / Android): each breathing session you complete on your phone is logged as mindful minutes
- Workouts (Apple Watch only): each session you complete on the Vagal Watch app is saved to Apple Health as a Mind and Body workout, with its start and end time and the heart rate the watch measured during it. Phone-led sessions mirrored on the watch are saved the same way.
On Apple Watch, Vagal also reads your heart rate and heart rate variability during a session to show them live and in the session summary; those readings are sent to the Vagal app on your paired iPhone and handled as described here.
Oura (only if you connect your Oura account, see §8): we read your daily readiness (score and contributors, such as resting heart rate), daily sleep (score and total, REM and deep sleep), and heart-rate samples, including heart rate variability where Oura provides it. Oura data is fetched from Oura directly to your device and used there; an HRV reading from Oura can be attached to a session as its before/after HRV, and is then handled like the other session data in §1.3.
Where health data goes. Health data is read on your device and used on your device. If you use Cloud Sync (§1.3), the before/after HRV readings and average heart rate attached to a session are uploaded with that session summary. Nothing else from Apple Health or Health Connect is uploaded: we never upload raw HealthKit records, and we never use health data for advertising, marketing, or any purpose other than the features described in §2.
You can revoke health permissions at any time in your operating system's settings (on iOS: Settings → Privacy & Security → Health → Vagal). Revoking does not delete data already synced; use "Delete all data" (§5) for that.
1.3 Cloud Sync (Optional, User-Initiated)
Vagal works fully offline. Sessions are queued on your device and nothing is uploaded until you tap Settings → Data → Cloud Sync. When you do, we store:
- Anonymous device identifier: A random ID generated on your device (not tied to your Apple/Google ID, your name, or your email)
- Session summaries: Pattern, duration, cycles completed, start time, and — where you recorded them — before/after HRV, average heart rate, and your mood tag
- Calibration history: BPM changes over time
- Device context: Platform (iOS/Android), app version, timezone, and whether premium is active
1.4 Support and Access Requests
If you email us — for support, or to ask for free access if you can't afford a subscription — we receive your email address and whatever you write to us. If an in-app access-request form is used, we also store the reason you give and your device identifier, so we can review the request and tell you the outcome. We never ask for your email in order to use the app: Vagal works without one.
1.5 Product Analytics (Opt-In, Off by Default)
Analytics are off unless you turn them on in Settings → Privacy → Analytics. When enabled, we record named product events (for example session_completed, premium_viewed) against a random identifier generated on your device. There is no autocapture, no session replay, and no screen recording. No health values, no mood tags, no email addresses, and no names are ever included in an analytics event.
1.6 Purchases
Subscriptions are processed by Apple or Google. We never see your payment details. Our subscription provider (RevenueCat) receives your purchase and entitlement status keyed to an app-generated identifier.
1.7 Crash Reports and Diagnostics
When the app hits an unhandled error, it sends a crash report to Sentry, our crash-reporting processor, so we can find and fix the fault. This is diagnostics, not analytics: it is separate from §1.5, it is not tied to the analytics opt-in, and it is the only category on this page that is on by default.
What a crash report contains:
- The error itself: exception type, message, and the stack trace — file names, function names and line numbers inside Vagal's own code
- Breadcrumbs: a short trail of the app's own log lines and navigation events leading up to the error
- Device and build context: device model, operating-system name and version, app version and build number, locale, and free-memory/disk figures
- A crash-free-session flag: whether the app session ended in a crash, so we can tell whether a release is stable
What is removed before the report leaves your device. Every crash report and every breadcrumb passes through a scrubber (src/services/crashReporting.ts) before it is transmitted. The scrubber:
- Replaces the value of any field whose name refers to health or identity with
[redacted]— this covers HRV, heart rate, BPM, resting rate, anything named "health", and device, installation and analytics identifiers, as well as any field named for an email address. The field name is kept so the report still describes the shape of the failure; the value is destroyed. - Redacts any email address found anywhere in any text in the report — including inside an error message or a log line — replacing it with
[redacted-email].
The practical effect: no health or fitness value, and no email address, is sent to Sentry, and a crash report cannot be tied to your synced data, because the device identifier that addresses that data is redacted too. Performance tracing is switched off entirely (sample rate zero), so we collect no performance profiles and no timing traces.
Retention. Crash reports are held by Sentry under Sentry's default retention for error events — 90 days — and are then deleted automatically. Because the reports carry no identifier that points back to you, we cannot look up "your" crash reports, and they are not covered by the export or deletion paths in §5.
Turning it off. There is no in-app switch for crash reporting in this release: the only data it sends is the non-identifying diagnostic material listed above. If you would prefer to send none of it, stop using the app or write to support@vagal.app and we will tell you when an opt-out ships.
1.8 What We Never Collect
- Your name (unless you type one into the app, which stays on your device), postal address, or phone number
- Raw HealthKit / Health Connect records on our servers
- Location data
- Contacts, photos, microphone, or camera
- Advertising identifiers (IDFA/AAID) — the app contains no ad or attribution SDKs
2. How We Use Your Data
2.1 Core App Functionality
- Display your session history and statistics
- Personalize breathing recommendations based on time of day and usage
- Calculate optimal breathing rate from calibration
2.2 Health Integration
- Show HRV improvement after sessions
- Track mindfulness minutes in Apple Health / Health Connect
2.3 Cloud Features (User-Initiated Only)
- Sync sessions across devices when you use Cloud Sync
- Provide streak tracking and insights
- Download anonymized, population-level recommendations (which patterns work well at which time of day). This is a download only, and it requires a separate cloud-ML opt-in that is not enabled in this release — your sessions are not part of the population data set.
2.4 Stability and Diagnostics
- Diagnose crashes and fix the bugs behind them, using the scrubbed crash reports described in §1.7
- Judge whether a release is stable enough to keep shipping
2.5 What We Do Not Use Your Data For
- No advertising or marketing profiling of any kind
- No selling, renting, or sharing with data brokers
- No automated decision-making with legal effects
- No medical or diagnostic determinations — see §13
3. Data Sharing
We Do NOT:
- Sell your data to third parties
- Share identifiable data with advertisers
- Use your data for targeted advertising
- Share health data with anyone beyond the processors listed in §8
We May Share:
- Anonymized, aggregated statistics: For research or app improvement (e.g., "80% of users prefer morning sessions")
- With service providers acting on our instructions: Only as necessary to operate the app — see the full list in §8
4. Data Retention
| Data Type | Retention |
|---|---|
| Local session and preference data | Until you delete the app, or use "Delete all data" |
| Synced session data on our servers | Until you use "Delete all data" or ask us to delete it |
| Access-request emails | Deleted with "Delete all data"; otherwise until the request is resolved plus 12 months |
| Gift-code redemption records | Retained as a transaction record (which code was used by which device), so a single-use gift code cannot be redeemed twice and a limited-use promotional code cannot be redeemed more times than it allows. Contains no health data. |
| Anonymized statistics | Indefinitely — keyed to an irreversible hash, with bucketed times and durations, so it cannot be traced back to you or deleted on request |
| Analytics events (if you opted in) | 12 months, then deleted |
| Crash reports and diagnostics (§1.7) | 90 days — Sentry's default retention for error events — then deleted automatically. Carries no health value, no email address and no device identifier, so it cannot be traced back to you or deleted on request |
| Support communications | 2 years |
5. Your Rights
You have the right to:
- Access / Export: Get a copy of everything Vagal stores about you on this device, as a JSON file you can open or keep
- Delete: Erase your data on this device and delete the copy synced to our servers
- Opt-out of analytics: Analytics are off by default and can be switched off again at any time
- Control cloud sync: Nothing is uploaded unless you tap Cloud Sync
- Revoke health access: Remove HealthKit / Health Connect permissions in your operating system's settings
To exercise these rights:
| Right | Exact path in the app |
|---|---|
| Access / Export | Settings → Privacy → Export my data |
| Delete everything | Settings → Privacy → Delete all data |
| Analytics opt-out | Settings → Privacy → Analytics (toggle) |
| Health permissions | iOS: Settings → Privacy & Security → Health → Vagal; Android: Health Connect app |
Or email support@vagal.app and we will action the request.
What "Delete all data" removes: every Vagal record on this device (sessions, mood check-ins, settings, calibration, analytics identifier), the Oura tokens held in your device's secure keystore, and every row on our servers tied to your device identifier — synced sessions with their HRV values, calibration history, insights, and any access request you submitted. It cannot remove the anonymized statistics described in §4, because those cannot be linked back to you. If we cannot reach our servers at that moment, the app tells you so and keeps the identifier needed to finish the server-side deletion on your next attempt.
What we cannot delete for you: data held by third parties under their own policies — Oura's copy of your ring data (use Oura's privacy dashboard), Apple Health / Health Connect records (use your operating system), and Apple's or Google's purchase records.
6. Security
We protect your data using:
- Encryption in transit: All network requests use HTTPS/TLS
- Encryption at rest: Our database provider (Supabase) encrypts stored data at rest
- Secure credential storage: Integration tokens are held in the iOS Keychain / Android Keystore, never in ordinary app storage, and are excluded from data exports
- Minimal data collection: We only collect what's necessary
- No account required: Use the app fully without creating an account
One honest limitation. Because there is no account, your synced data is addressed by a random identifier generated on your device. Anyone holding that identifier could reach the sessions synced under it. We never place it in a URL, share it, or use it for advertising, and it can be reset by using "Delete all data". If you need account-level protection, do not use Cloud Sync.
7. Children's Privacy
Vagal is not directed at children under 13. We do not knowingly collect data from children. If you believe we have collected data from a child, contact us immediately.
8. Third-Party Services
We use the following third-party services:
| Service | Purpose | Data it receives | Privacy Policy |
|---|---|---|---|
| Supabase | Cloud database and functions (optional sync) | Device identifier, session summaries incl. HRV, calibration, access-request email | supabase.com/privacy |
| RevenueCat | Subscription management | App-generated identifier, purchase and entitlement status | revenuecat.com/privacy |
| PostHog | Product analytics — only if you opt in | Random analytics identifier, named product events, platform | posthog.com/privacy |
| Sentry | Crash reporting and diagnostics (§1.7) | Stack traces and breadcrumbs from Vagal's own code, device model, OS version, app version. No health values, no email addresses and no device identifiers — all are stripped on your device before the report is sent | sentry.io/privacy |
| Apple HealthKit | Health data integration (on-device) | Nothing is sent to us by Apple; we read with your permission | apple.com/privacy |
| Google Health Connect | Health data integration (on-device) | Nothing is sent to us by Google; we read with your permission | google.com/policies/privacy |
| Oura | Optional ring integration, authorized by you via OAuth | With your authorization, your device reads your daily readiness, daily sleep and heart-rate data from Oura (OAuth scopes daily and heartrate only; we do not request your Oura personal-info scope). The one-time sign-in exchange passes through our Supabase function, which stores nothing | ouraring.com/privacy-policy |
Apple and Google also process your subscription purchase under their own terms.
9. Changes to This Policy
We may update this policy occasionally. We will notify you of significant changes via:
- In-app notification
- App Store update notes
The "Last updated" date at the top of this policy always reflects the current version. Continued use after changes constitutes acceptance.
10. Contact Us
For privacy questions, access requests, or deletion requests:
- Data controller: Entropy Ventures LLC
- Email: support@vagal.app
- Website: https://vagal.app/privacy
11. California Residents (CCPA)
California residents have additional rights under CCPA:
- Right to know what personal information is collected — see §1, or use Export my data
- Right to delete personal information — see §5
- Right to opt-out of sale of personal information (we don't sell data, and we do not "share" it for cross-context behavioural advertising)
- Right to non-discrimination for exercising privacy rights
We do not sell or share personal information, so we do not offer a "Do Not Sell or Share My Personal Information" link.
12. European Residents (GDPR)
For EU/EEA residents:
- Legal basis: Consent for health data, optional cloud sync and analytics; contract for subscriptions; legitimate interest for security and fraud prevention (for example gift-code redemption records)
- Data controller: Entropy Ventures LLC, which operates Vagal — contact support@vagal.app
- Privacy contact: support@vagal.app (we have not appointed a Data Protection Officer; this address reaches the person responsible for privacy)
- Transfers: Our processors may store data outside the EEA under standard contractual clauses
- Right to lodge complaint: With your local data protection authority
13. Not a Medical Device
Vagal is a general wellness app. It does not diagnose, treat, cure, or prevent any disease or medical condition, it is not a medical device, and it is not a substitute for professional medical or mental-health care. The HRV figures it displays come from consumer sensors and are not clinical measurements.
If you are in crisis or thinking about harming yourself, please use the resources in Settings → About → Crisis resources, or contact your local emergency number. If you have a medical condition, consult a healthcare professional before starting any breathing practice.
14. Washington Residents: Consumer Health Data Privacy Policy
This section is our Consumer Health Data Privacy Policy under Washington's My Health My Data Act (RCW 19.373). It applies to "consumer health data" about Washington consumers, and it works together with the rest of this policy.
Categories of consumer health data we collect, and why.
| Category | Purpose and how it is used |
|---|---|
| Heart rate and heart rate variability (from Apple Health, Health Connect, Apple Watch or Oura) | To show how your body responded before, during and after a session (§2.2) |
| Oura readiness and sleep data | To show your readiness and sleep context on the Oura screen (§1.2) |
| Mindful minutes and breathing-session history (pattern, duration, cycles, time) | To show your history and insights, recommend patterns, and log sessions to Apple Health / Health Connect as mindful minutes or Mind and Body workouts |
| Mood check-ins | To show your mood alongside your sessions |
| Breathing-rate calibration | To personalise the Sync (Resonance) pattern to your breathing rate |
We do not use consumer health data for advertising, and we do not sell it.
Sources. You (what you enter in the app); your devices and apps you connect, with your permission: Apple Health / Health Connect, Apple Watch, and Oura.
Categories we share, and with whom. We share consumer health data only with our processors, who act on our instructions, and only for the purposes above:
- Supabase (cloud database), and only if you tap Cloud Sync (§1.3): session summaries with before/after HRV, average heart rate and mood tag, and calibration history.
- We do not share consumer health data with any affiliate, advertiser or data broker. Sentry and PostHog receive no health values (§1.5, §1.7).
Consent. We collect consumer health data only with your consent: the operating-system permission prompts for Apple Health, Health Connect and Apple Watch, connecting Oura, and entering a mood or calibration yourself. Uploading anything requires you to tap Cloud Sync. You can withdraw consent at any time by revoking the permission, disconnecting Oura, or not using Cloud Sync.
Your rights and how to exercise them. You have the right to confirm whether we collect, share or sell your consumer health data and to access it (including a list of the third parties we have shared it with), to withdraw consent, and to have it deleted. In the app: Settings → Privacy → Export my data and Settings → Privacy → Delete all data (which also deletes the copy on our servers). Or email support@vagal.app with the subject "Washington health data request". We respond within 45 days, which we may extend once by another 45 days where reasonably necessary, and we will tell you if we do. If we decline your request, you may appeal by replying to our answer with the subject "Appeal"; we will respond to an appeal within 45 days, and if you are not satisfied you may contact the Washington State Attorney General at atg.wa.gov/file-complaint.
Contact. Entropy Ventures LLC, support@vagal.app (see §10).
This privacy policy is effective as of September 18, 2026.