Help Me Breathe is a guided breathing timer at helpmebreath.com. It is published by one person — Georges Rayess, an individual resident in Lebanon — and not by a company. Reading the site needs nothing from you. The first three timer sessions on a device need no account. When you create an account, this policy says exactly what it holds.
This policy explains what the site keeps on your device, what leaves your device and when, who else is involved, and what you can ask me to do. It is written to be read, not to be survived. If anything here is unclear, write to contact@helpmebreath.com and I will answer in plain words.
The short version
- The timer runs in your browser. Your settings, your session history and your saved patterns stay on your device and are never sent to me.
- An account holds your email address, your sign-in identities, the date it was created and your plan — never your practice. There are no passwords.
- Payments are handled end to end by Stripe as merchant of record. I never see your card details, and I do not store them anywhere.
- One free trial per person. Checking that uses a one-way hash of your email address and a random identifier in a cookie on this device, and those two things only. There is no browser fingerprinting.
- Analytics and advertising cookies are set to denied before anything loads, and stay denied unless you choose "Accept all" in the cookie banner.
- Every record has a retention period with a number on it. Trial records are kept for 24 months, and this page says why.
- I do not sell personal information and I do not share it for cross-context behavioural advertising.
1. Who is responsible for your data
The controller for this site is Georges Rayess, an individual, contactable at contact@helpmebreath.com. There is no data protection officer, because a one-person project does not need one and I would rather not pretend otherwise.
Two other parties are controllers in their own right for the parts they handle: Stripe, which sells the subscription as merchant of record and holds the payment record, and Google, for the analytics and advertising services described below. Two more act as processors on my instructions: the authentication and database service that hosts account records, and the email service that sends sign-in links and receipts. Each is described in the section that covers it.
2. What is stored in your browser
The timer keeps a small amount of information in your browser's local storage, under keys that all begin with hmb., and the sign-in library keeps your session under its own key. This is storage on your own machine. It is not sent with your requests, and I cannot read it.
| What | Why it exists |
|---|---|
| Settings | Your chosen technique, session length, sound and vibration toggles, so the timer opens the way you left it. |
| Session history | A short list of finished sessions — date, technique, seconds, breath count, whether you finished. Capped at the most recent 500. It powers the streak view and the CSV export, and it is the offline fallback for counting your free sessions. |
| Consent choice | Whether you chose "Accept all" or "Essential only" in the cookie banner, so you are not asked on every page. |
| Saved presets | Custom breathing patterns you build and name yourself, in the pattern builder. |
| Small flags | Whether you have acknowledged a safety note, whether night mode is on, and whether a prompt has already been shown once. |
| Sign-in session | Once you sign in, the authentication library keeps a short-lived session token in local storage so you stay signed in. It is refreshed automatically and cleared when you sign out. |
| Entitlement copy | A signed note from this site saying which plan you are on and until when, so the paid features keep working for up to 14 days offline. It carries your account identifier, your plan and dates, and nothing else. |
| Device identifier mirror | A copy of the random identifier from the __Host-hmb_did cookie in section 4, so the count of free sessions survives a browser that clears cookies but not storage. It only works if it matches the server's signature; a made-up one is ignored. |
All of it is written and read by code running on your device. Your settings, history, presets and flags are never transmitted to me, to Google, or to anyone else. The sign-in session and the entitlement copy are sent to this site's own server when the page asks it about your account, and to no one else. You can wipe every bit of it by clearing site data for this domain in your browser, and the site will work the same afterwards — it will have forgotten your preferences, and you will need to sign in again.
If your browser blocks storage — a private window, a locked-down profile, a full quota — the timer keeps the same values in memory for that page's lifetime instead, and forgets them on reload. Nothing breaks.
3. What leaves your device, and when
3.1 Loading a page
Like every website, asking for a page means your browser sends a request. The host that serves this site receives your IP address, the page requested, your user-agent string and the referring page, and keeps short-lived operational logs for security and troubleshooting. This is ordinary web hosting, not a profile of you.
Pages on this site also load the Figtree and DM Mono typefaces from Google Fonts. That request reveals your IP address to Google. When you sign in, and on every page of the site while you hold a signed-in session, your browser loads the Supabase library from the jsDelivr CDN (cdn.jsdelivr.net); that request reveals your IP address to jsDelivr and its hosting networks.
3.2 Analytics — Google Analytics 4 with Consent Mode
I use Google Analytics 4 to see which pages help people and which do not. It runs with Google Consent Mode v2, and every consent signal starts at "denied" — analytics storage, advertising storage, advertising user data and advertising personalisation are all refused before any Google script has a chance to run.
If you choose "Essential only" in the cookie banner, or ignore it, they stay denied. No analytics cookie is written. If you choose "Accept all", analytics is enabled and Google Analytics records page views, the technique you selected, whether a session started or completed, whether a sign-in or checkout was started, and similar interaction events. IP anonymisation is on. Events never carry an email address, an account identifier, a device identifier, a token or a payment identifier. Payments, renewals, declines and refunds are never reported to Google Analytics at all; they are facts I read from my own records.
Google puts it this way: Your web browser automatically sends certain information to Google. This includes the URL of the page you're visiting and your IP address.
Those sentences are from Google's page on how it uses information from sites that use its services. You can change your decision at any time by clearing this site's storage, which brings the banner back.
3.2a Advertising measurement — Google Ads conversions
From 15 September 2026 I advertise the timer on Google Ads. To learn whether an ad led to a subscription, the same Google tag reports one thing to Google Ads: that a checkout completed on this site, together with the plan's list price and the random checkout reference shown on the receipt page. That reference is a random identifier, not your identity, and it cannot be turned into one. Nothing else is reported: no email address, no user identifier, no card detail, no name.
Whether that report can be tied to the ad you clicked depends on the cookie banner. If you chose "Accept all", Google's advertising cookies (the _gcl_ family, listed in section 4) remember the click for up to 90 days so the conversion can be attributed to it. If you chose "Essential only", or never answered, no advertising cookie is written, the click identifier is redacted from what your browser sends, and Google receives only an unattributed, cookieless count. This measurement is not used to build an advertising profile of you, it does not change what you see on this site, and I do not share your data with Google for cross-context behavioural advertising.
3.3 Advertising — Google AdSense on content pages only
Some of the free written guides carry advertising from Google AdSense. This pays for the hosting. The rules I hold myself to are narrow and worth stating:
- Ads appear on content and comparison pages only, below the fold. Never inside the breathing viewport.
- There are no ads at all on the anxiety and panic-attack pages, on the product pages, on the sign-in and account pages, or on this page.
- Ads are hidden while a breathing session is running, and never sit next to a sign-in prompt.
- Anyone with an active subscription sees no advertising anywhere on the site. The ad loader checks before it loads, and stops if you have one.
- If you did not accept advertising cookies, the loader requests non-personalised ads instead.
Google's own explanation is that Cookies help to make advertising more effective.
You do not have to accept that trade. To opt out of personalised advertising across Google's products, use Google's advertising page, which states that You can use ad settings to manage the Google ads you see and turn off personalized ads.
The settings hub itself is at myadcenter.google.com, and the choice you make there follows you across sites, not just this one. Declining advertising cookies in our banner, or holding an active subscription, also works.
3.4 Your account, and what it holds
You do not need an account to read the site or to run your first three timer sessions on a device. You create one to keep using the timer and to subscribe, and an account is for one person or one household.
You sign in with an email link, a six-digit code sent to that email, or a Google account. There is no password, so there is no password to store, to leak or to reuse somewhere else. Signing in with Google tells Google that you signed in here and tells this site the email address, the name and the account identifier Google returns; it does not give this site access to your Google data. If you use the email link on one day and Google on another, with the same address, they are one account, not two.
The account holds exactly this, and nothing else:
- your email address;
- the sign-in identities you have used — the email link, the Google account, or both;
- the date the account was created, and the date you were last seen;
- your plan, its status and its period dates — when the trial or the current period started and when it ends, and any cancellation, pause or resume date;
- the payment provider's subscription identifier and customer identifier, so a receipt, a cancellation or a refund can be matched to the right account;
- the amount and currency the provider actually charges you, exactly as the provider states it, so your account page can show you the real figure rather than a guess;
- a short-lived record of each checkout you started — the plan, whether a trial was granted, and why — which expires after 30 minutes and is deleted a week later.
What the account does not hold is as important: no card number, no expiry date, no security code, no billing address, no session history, no streak, no saved pattern and nothing about what you practised or when. Those stay in your browser, as section 2 describes. No card details ever reach us at all.
Account records are held by Supabase, an authentication and database service acting as a processor on my instructions, in a data-centre region in the United States (Northern California). Your browser talks to Supabase only to sign you in; everything else about your account is read through this site's own server. The tables that hold your data accept no direct access from a browser at all.
3.5 Subscribing — Stripe as merchant of record
I do not sell to you directly and I never touch your payment details. The subscription is sold by Stripe (Stripe, Inc., and Stripe Payments Europe, Ltd. for customers in Europe) as the merchant of record, under its Managed Payments service: the contract of sale is between you and Stripe. It takes the payment, calculates and remits sales tax and VAT, issues the receipt, runs the billing portal and is the controller of your payment data — your card details, your billing address and the fraud signals it collects — under its own privacy policy at stripe.com/privacy.
Because Stripe holds its own copy of your purchase record as a separate controller, a request to erase the payment record itself goes to Stripe, not to me; section 8.2 explains how.
What reaches me is limited to what section 3.4 lists: your email address, your plan and its dates, Stripe's subscription and customer identifiers, the country used for tax, and the amount and currency you were charged. When Stripe tells this site about a payment, a renewal, a decline or a cancellation, that message is kept as a record for a limited time — section 7 gives the number — so that a dispute or a missed message can be checked against what actually happened. I never receive your card number.
3.6 The free-trial check
One free trial per person. When you start a free trial we check whether this email address has already had one. To do that we store a one-way fingerprint of your email address — we cannot turn it back into an email — and a random identifier in a cookie on your device. We do not do this on any other page, and never for reading the site.
In more detail. The email hash is computed on this site's server from the address on your account, using a secret key that never leaves the server, at the moment you ask to start a trial. It is stored in a trial ledger with the date, the outcome of that trial — reserved, started, converted, cancelled, refunded, or charged back — and the provider's identifiers for it. The random identifier is issued by the server, signed so that it cannot be invented, and stored in the __Host-hmb_did cookie described in section 4, with a record of when that device last started a trial and how many times. Someone who has already had a trial, or who has ever held a subscription, is offered a straight subscription instead. The check can only ever remove the trial offer; it never blocks you from subscribing, and it never blocks you from reading the site. If our own records are unreachable, the check fails to "no trial", never to "no access".
There is no browser fingerprinting. Nothing reads your fonts, your screen size, your time zone, your hardware, your canvas, your audio stack, your installed plugins or any other signal your browser gives away, and nothing builds a device profile. The only device signal is the cookie, and a cleared cookie simply looks like a new device. Your IP address is used to rate-limit how often anyone can ask for a trial, and is never used to decide whether you get one.
A hash you cannot reverse is still personal data, because I hold the key and could confirm a match if I already had your address. It is pseudonymised, not anonymous, and this policy treats it that way: it has a legal basis in section 6 and a retention period in section 7.
3.7 Email you receive from the account
Creating an account and running a subscription involves a small number of emails: the sign-in link or code, a confirmation when a trial starts that states the plan, the date the card will be charged and the amount, and a note if a payment fails or the provider changes. These are sent through our email service provider, a third-party platform that acts as a processor and sees your address and the message. They are part of the service, not marketing, and cannot be switched off while the account exists. Stripe sends the receipt and the trial-ending reminder separately, under its own policy.
You can also ask for occasional email — a note when a new technique or guide goes up. It is entirely optional, works on double opt-in, and every email carries an unsubscribe link, one click, no questions. Only a twelve-character hash prefix of an address ever appears in this site's own logs. Write to contact@helpmebreath.com and the address is removed from the list.
3.8 Writing to me
If you email me, I have your address and whatever you wrote, for as long as the conversation is useful and my records need to exist. I read that email in Lebanon. Support correspondence is not added to the mailing list.
5. Affiliate links
A small number of pages link to products I think are genuinely worth the money — currently Headspace and moonbird. Those are affiliate links, marked as sponsored, and if you buy after clicking one I may earn a commission at no extra cost to you. Clicking such a link takes you to that company's own site, where its own privacy policy and its own cookies apply, and it may set a cookie to attribute the sale. Nothing about you is sent to them by me. If you do not click, no data is shared. The recommendation on those pages is never for sale — the comparison page still concludes that the free option is enough for most people.
6. Legal bases for processing — one per purpose
For readers in the European Economic Area and the United Kingdom, each purpose below rests on exactly one basis. I do not hold two in reserve for the same thing, because a basis cannot be swapped after the fact.
- Performance of a contract — your account, your subscription and its trial, the payment, the emails the service needs to send, and supporting you while it runs.
- Legitimate interest — the one-way hash of your email address in the free-trial ledger, and the random identifier in the
__Host-hmb_didcookie together with the small device record it points to. The interest is keeping a card-required free trial to one per person, so that the offer is not drained by repeat sign-ups and can go on being offered to everyone else. The check is deliberately the least a rule like that can be built on — a hash and a random number, with no fingerprinting and no profile — it can only ever withhold the trial offer, never access, and it applies to nobody who has not asked to start a trial or finished a session on the timer. I have written the balancing test down; it is kept on file and you may ask for a copy. You have the right to object, in section 8.3. - Consent — analytics and advertising cookies, and the optional mailing list, and nothing else. Consent Mode starts at denied. Withdrawable at any time, and withdrawing is as easy as giving it. Nothing the account or the subscription needs in order to work relies on consent, and nothing is refused to you for declining.
- Legal obligation — tax and accounting records, which Stripe holds as the seller.
There is no browser fingerprint, so there is no fingerprint to consent to and no basis claimed for one.
7. How long things are kept
Browser storage lives on your device until you clear it, and nothing expires it on a schedule. The rest has a number, and a weekly job on the server deletes what has passed it:
- Account data — kept for as long as the account exists. When you delete the account, the record is removed straight away; a copy may persist in the database provider's backups for up to 30 days and is then gone.
- Subscription records — kept while the subscription exists and while the account does. If you delete the account with a subscription attached, the subscription record is kept but detached from you: your account identifier is removed, and only the provider's identifiers, the plan and the dates remain, so that a message from the provider about that subscription can still be matched and a refund or a dispute can still be handled. A detached record is expired seven days after access ends and deleted with the ordinary cleanup.
- Free-trial records — the one-way email hash, and the device record behind the
__Host-hmb_didcookie, are kept for 24 months from the last activity on that record, then deleted. The reason is plain: otherwise deleting an account, or clearing a device, would reset the free-trial limit and the rule would mean nothing. Twenty-four months is longer than anyone's patience for repeat trials and short enough to be defensible. Deleting your account removes your account identifier from these records but does not shorten the 24 months. - Checkout records — each checkout you start expires after 30 minutes and is deleted 7 days after that.
- Messages from Stripe — the body of each processed payment message is kept for 30 days and then blanked; the bare record that it was received is kept for 180 days. A message that could not be processed keeps its body until it has been, so that a missed payment can be put right.
- The
__Host-hmb_didcookie — 2 years. The__Host-hmb_entcookie — 14 days. - Rate-limit counters keyed on your account or your network — 2 days.
- Mailing list entries — kept until you unsubscribe.
- Purchase and tax records — kept by Stripe, as the seller, for as long as its own law requires.
- Server logs — short-lived and operational. Email correspondence — kept while it is useful, then deleted.
8. Your rights, and how to use them
Depending on where you live, you may have the right to access the personal data held about you, to correct it, to delete it, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent. Under the GDPR and the UK GDPR those rights are yours as a matter of law.
Under the California Consumer Privacy Act, as amended by the CPRA, California residents may also ask what personal information is collected, ask for it to be deleted or corrected, and opt out of sale or sharing. I do not sell personal information and I do not share it for cross-context behavioural advertising, so there is nothing to opt out of there. You will never be treated differently for exercising a right.
8.1 Getting a copy of your account
Your account page has an Export my data control that hands you a file containing your account record and every subscription record with the provider's identifiers, and only your own data. It contains no hashes and no secret keys. Stripe holds its own copy of the purchase record and provides it separately.
8.2 Deleting your account
Your account page has a Delete my account control. This is what it does, in order, and it does it the same way if you ask by email:
- If a subscription is live, it is cancelled at Stripe first, and the cancellation is confirmed before anything else happens. An account is never deleted with billing left running behind it.
- The subscription record is detached, as section 7 describes, and Stripe's identifiers are kept so that a later refund or dispute can still be matched.
- Your account, your sign-in identities and your checkout records are deleted.
- Your account identifier is removed from the free-trial records; the email hash and the device record run out their 24 months.
Two things it cannot do. It cannot delete an account while a payment dispute is open or a failed payment is outstanding — email contact@helpmebreath.com and we will sort it out by hand. And it cannot erase the payment record Stripe holds as a separate controller; for that, contact Stripe directly through support.stripe.com, or ask me and I will pass the request on.
8.3 Objecting to the trial check
Because the free-trial check rests on legitimate interest, you may object to it. If you do, I will not run the check for you — which means I cannot offer you the trial, since the trial exists only because the check does — and you can subscribe at the ordinary price with the same 14-day unconditional refund, which is longer protection than the trial gives anyway. Email contact@helpmebreath.com and say so.
8.4 Everything else
For anything not covered by a control on your account page, email contact@helpmebreath.com and say what you want. I will answer within thirty days, and sooner if it is simple. Write from the address on the account, or quote the order reference on your receipt, so I can be sure I am answering the right person. If you are unhappy with my answer, you may complain to your national data protection authority.
One honest limitation: most of what this site holds about you is not held by me at all. It is in your browser, where you can read it and delete it yourself in seconds.
9. Children
This site is not directed at children under 13, and I do not knowingly collect personal information from them. Reading the site and running the free sessions needs no personal information from anyone. If you believe a child has sent me an email address or opened an account, write to contact@helpmebreath.com and I will delete it.
10. International transfers
This is a small site with a global audience, so data crosses borders. Pages are served from a content delivery network with locations worldwide, and this site's own server functions run in that network. Account records are held in the United States, as section 3.4 says. If you are in the EEA, the UK or Switzerland, that is an international transfer of your account record; it is covered by Supabase's data processing addendum, which applies to every Supabase customer on acceptance of its terms and incorporates the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and a Swiss addendum. Stripe, the email platform and Google each operate their own international infrastructure and their own transfer safeguards, described in their own policies. The narrow set of account and subscription data reaches Lebanon, because that is where I read email and administer the site; Lebanon has not been the subject of a European Commission adequacy decision. Where you are in the EEA, the UK or Switzerland and need a transfer mechanism for that, ask before you buy and I will sign the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. I will not claim to have safeguards in place that have not actually been signed.
11. Security
The site is served over HTTPS. Secrets live in server environment variables, never in the code and never in a browser. There are no passwords to store, because sign-in is an email link, a code or a Google account. Sign-in tokens are checked on the server against the authentication service's published keys on every request that touches an account. The database tables that hold account, subscription and trial records accept no direct access from a browser at all; every read goes through this site's own server, which identifies you from your verified sign-in and never from anything the page claims about itself. Email addresses in the free-trial ledger are stored only as a keyed one-way hash, email addresses in logs only as a short hash prefix (the one exception is the mailing-list confirmation link, which carries your address in signed form and appears in the hosting provider's request logs for as long as it keeps them), and no payment data reaches this project at all. The account record is deliberately small, so a breach of it would expose an email address and a plan, not a practice history and not a card. No system is perfectly secure, and I will not promise that it is.
12. Changes to this policy
I will update this page when the facts change — a new provider, a new feature, a different ad partner. The date at the top always says when it last changed. If a change is material, I will say so clearly on the page rather than quietly editing a sentence, and account holders will be emailed. Continuing to use the site after a change means the updated policy applies.
13. Contact
Questions, requests and corrections: contact@helpmebreath.com. This site is helpmebreath.com, published by Georges Rayess, an individual.
See also: Terms of Service · Refund Policy · Medical Disclaimer · About this site