Privacy
Privacy Policy
What AERSŌMA collects, why, and what you can do about it. Written against what the app actually stores.
Overview
This Privacy Policy explains what AERSOMA LLC ("AERSŌMA", "we", "us") collects when you use the AERSŌMA app, the aersoma.com website, and the optional AERSŌMA device, why we collect it, and what control you have over it.
We have tried to write this so that it can be checked. Every category below corresponds to something the app or the website actually stores; where we say we do not collect something, we mean the app has no code path that would.
For people in the European Economic Area and the United Kingdom, AERSOMA LLC is the data controller. Effective: 29 September 2026.
Information we collect
- Account: your email address, and a password held by our authentication provider in hashed form. If you sign in with Apple or Google we receive the account identifier and email address that they release to us. You also choose an AERSŌMA ID (handle) and a display name.
- Breathing activity: your session history - what you practised, when you started, how long it lasted, and whether you finished it. This is what your streak and your minutes are calculated from. It includes time you spend breathing in the Global Rhythm, once you have breathed in it for at least one full breathing cycle.
- Programme progress: which multi-week programmes you have joined and which days you have completed.
- Breath-hold calibration: if you choose to measure it, the comfortable breath-hold time that you record yourself by tapping start and stop. We use it to suggest a suitable difficulty. It is a number you time by hand, not a sensor reading and not a clinical measurement - but in the EEA and the UK it may still count as data concerning health, so we ask for your consent before recording it. It is deleted with your account; there is no separate delete control for it in the app today, so to remove measurements while keeping the account, write to us.
- Content you create: breathing patterns and protocols you build, and which items you have marked as favourites.
- Social features: friend requests and friendships, people you have blocked, reports you have submitted, and rooms you host or join. Lobby chat is ephemeral - messages pass live between people in a room and are not written to our database. The single exception is a message included in a report, which is stored as part of that report so that it can be reviewed.
- Presence: while you are breathing in the Global Rhythm or in a room, we record that you are currently there so the participant count is real. We also keep a record of Global Rhythm visits for a rolling 24-hour window so the counter can show the day rather than the second. Separately from that counter, a Global Rhythm visit of at least one full breathing cycle is saved to your practice history like any other session (see Breathing activity above).
- Notifications: a push token for your device, which notification categories you have switched off, your quiet hours, and your time zone. The time zone is needed to know when your quiet hours actually are.
- Emails: when you created your account, a note that you were shown the line about getting-started emails and when; your time zone, so these emails arrive at a reasonable hour; which of them we have sent you and when; and whether you have turned them off.
- Wearable list: if you leave your address on aersoma.com to hear about the wearable, we keep that address, when you confirmed it, the wording you agreed to, and which page or link brought you there. To stop the form being used to flood someone else's inbox, we also keep one-way hashes of the IP address it was sent from and of the email address, for up to 24 hours.
- Subscription: if you buy AERSŌMA Plus, we store the platform, the product, the subscription status and renewal date, whether it auto-renews, and the identifier the store uses for your subscription. We also keep the raw purchase notifications the stores send us, so that a payment problem can be traced.
- Website visits: when you visit aersoma.com we count page views with Umami. It sets no cookies, does not store your IP address, and keeps nothing that identifies you. It records the page and its title, the site that referred you, the campaign tags in the link you followed (such as utm_source), your browser, operating system, device type, screen size, language, and your country, region and city. Your IP address is used only in passing: to work out that location, and - mixed with your browser details and a secret that changes over time - to tell one visit from another without recognising you later. Anything else in a page address is removed before it is sent. Visits are not linked to an app account. The invite pages - room invites and friend links - are not counted at all, and they do not pass their address on to the next page, because it carries a room code or a person’s handle.
- Technical data: app version and error diagnostics. Crash reports are stripped of account identity before they are sent - no email, handle, or display name - and you can turn them off in Settings under "Share crash reports"; the change takes effect the next time you open the app.
What we do not collect
- Card details. Subscriptions are bought and billed by Apple or Google, and the device is sold through a store or retailer. Your card number never reaches us, and there is no code in the app that could receive it.
- Sensor or biometric data. AERSŌMA has no heart-rate sensor and no camera-based measurement. We do not read Apple Health or Google Fit. The breath-hold time described above is a stopwatch you operate yourself.
- Device telemetry. The AERSŌMA hardware talks to your phone over Bluetooth and never talks to our servers. Nothing about how you used the device is uploaded from it.
- Advertising identifiers. We run no ads, we build no advertising profiles, and there is no advertising or tracking SDK in the app.
- Your location. We do not request or store it.
Why we use it, and on what legal basis
The legal bases below are the ones that apply in the EEA and the UK. Elsewhere, they describe our purposes.
- To give you the service you asked for - running sessions, saving your history, letting you build content, friends, rooms, the Global Rhythm, and delivering AERSŌMA Plus if you buy it. Basis: performance of our contract with you.
- To send notifications you have asked for. Basis: your consent, given when you allow notifications; you can withdraw it per category, by setting quiet hours, or in your device settings.
- To send a few getting-started emails in your first weeks, and to stop them when you ask. Basis: our legitimate interest in helping new users get started. You can stop them from any of these emails or in Settings.
- To email you when the wearable can be ordered, with a date and a price. Basis: your request, for the one email asking you to confirm the address; after that, your consent, given when you confirm it. You can withdraw it from the link in any of these emails.
- To record your breath-hold calibration and use it to suggest a difficulty. Basis: your consent. If you do not give it, the app still works; recommendations simply fall back to time of day.
- To keep people safe - reviewing reports, enforcing the Terms, blocking abuse, and limiting attempts to guess room codes. Basis: our legitimate interest in a safe service, and our legal obligations where they apply.
- To keep the service working - diagnosing crashes, preventing fraud and misuse, and maintaining security. Basis: our legitimate interest in a reliable, secure service. Crash diagnostics can be switched off.
- To know which pages and shared links bring people to the website, from visit counts that identify no one. Basis: our legitimate interest in knowing whether what we publish reaches anyone.
- To answer you when you contact us, and to comply with law. Basis: legitimate interest and legal obligation.
We do not use your information to make automated decisions that produce legal or similarly significant effects about you. Difficulty suggestions are a convenience and never override the safety confirmation shown before an advanced practice.
How we share information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We use a small number of processors that handle data on our instructions:
- Supabase - database, authentication, and realtime messaging. This is where your account and your practice data live.
- Resend - sending email: account emails such as confirming your address or resetting your password, and the getting-started emails described above, and the wearable list emails.
- Expo, Apple Push Notification service, and Google Firebase Cloud Messaging - delivering push notifications to your device.
- Sentry - crash and error diagnostics, receiving anonymised reports only.
- Umami - visit statistics for the aersoma.com website, without cookies and without anything that identifies you.
- Apple and Google - processing subscription payments. To connect a purchase to your account we pass them an account identifier when the purchase is made, and they tell us the status of the subscription. They act as independent controllers of the payment itself under their own privacy policies.
Other people see only what the social features require: your display name and AERSŌMA ID are visible to friends and to people in a room you are in. Friendship is mutual and has to be accepted, and you can block or report anyone.
We may disclose information where the law requires it, or to protect the rights and safety of users and of the service. If we are ever part of a merger or acquisition, information may transfer with the business, and we will say so before it does.
International transfers
We and our processors operate in the United States and elsewhere, so if you are in the EEA or the UK your information is transferred outside your country. Where that happens we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant) together with our processors’ own transfer safeguards. You can ask us for details of the safeguards that apply.
How long we keep it
- Account, practice history, programme progress, content you created, favourites, social connections, and breath-hold calibration measurements: kept while your account exists, and deleted when you delete it.
- Lobby chat: never written to our database at all.
- Presence: a live record while you are breathing, cleared shortly after you stop. The Global Rhythm visit record behind the counter is kept for a rolling 24-hour window. A visit long enough to count as practice is also part of your practice history, and is kept and deleted with it.
- Push tokens and notification preferences: kept while your account exists; a token is removed when you sign out or the store reports it is no longer valid.
- Getting-started emails: the record of which ones we sent is kept for 12 months after each email; the note that you were shown the line about them, your time zone, and your setting are kept while your account exists.
- Wearable list: kept until you leave the list. When you leave, the address is erased at once; we keep only the dates and which link brought you, without the address. An address that is never confirmed is deleted 30 days after the last email asking to confirm it, and at most 90 days after it was entered. The hashes are deleted within 24 hours. Our email provider keeps its own log of each email it delivered for a limited time.
- Subscription and store records: kept while the subscription is active and afterwards for as long as tax and accounting law requires us to keep records of a sale.
- Reports and moderation records: kept after review so that repeat behaviour can be recognised. A copy of reported content is kept as part of the report even if the account that produced it is deleted - otherwise deleting an account would erase the evidence against it.
- Crash diagnostics: kept for a limited period by our diagnostics provider and not linked to your account.
- Website visit statistics: kept by Umami for up to six months, in a form that does not identify you.
Your choices in the app
- Delete your account and its data: Profile, then Account, then Delete account. This is immediate and permanent.
- Turn off crash reports: Settings, "Share crash reports".
- Turn off notification categories and set quiet hours: Settings, Notifications.
- Stop getting-started emails: Settings, "Getting-started emails", or the link at the bottom of any of them. Emails about your account are not affected.
- Leave the wearable list: the link in any email about it.
- Stop the breath-hold calibration being used: do not record one. If you have already recorded measurements, the app has no delete control for them today - write to support@aersoma.com from the address on your account and we will remove them, or delete the account, which removes them with everything else.
Your rights in the EEA and the UK
You have the right to access your personal data, to correct it, to have it erased, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent at any time without affecting what we did before you withdrew it.
You can exercise most of these in the app; for anything else write to support@aersoma.com and we will respond within one month. If you believe we have handled your data badly, you can complain to your local supervisory authority, and we would rather you told us first so that we can fix it.
Your rights in California
Under the CCPA as amended by the CPRA you can ask to know what personal information we collect, use, and disclose; ask for a copy of it; ask us to delete it; ask us to correct it; and limit the use of sensitive personal information. We will not discriminate against you for exercising any of these.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing for you to opt out of on that front.
To make a request, write to support@aersoma.com. We may need to verify that the request is really yours before we act on it.
Information stored on your device
So that the app works without a signal, a copy of the catalogue and your programme progress is kept in the app’s own storage on your phone. If you subscribe, the paid rhythms are cached there too. A practice you finish without a signal is also held there until it can be sent to your account. Your practice history itself is not stored on the phone, so the Activity screen needs a connection to show it. This storage is private to the app and is removed when you delete the app, but it is not separately encrypted by us beyond the protection your phone already provides.
Security
Your data is protected by row-level access rules on our database, which means an account can read and write only its own rows; this is enforced by the database itself rather than by the app being polite. Traffic is encrypted in transit. Nobody can promise perfect security, and we do not.
Children's privacy
AERSŌMA is not for children under 13, or under the minimum age where you live if that age is higher. We do not knowingly collect their information. If you believe a child has given us information, contact us and we will delete it.
Changes to this policy
If we change this policy we will post the new version and update the effective date. If the change is significant we will tell you in the app rather than hoping you re-read the page.
Contact us
Privacy questions and requests: support@aersoma.com.
Postal address: AERSOMA LLC, 5900 Balcones Dr Ste 100, Austin, TX 78731-4298, United States.