← BreakDawn Legal
    BreakDawn

    Privacy Policy

    Last updated: 13 June 2026 · Effective: 13 June 2026

    1. Who we are

    BreakDawn is operated by Narmis Services Ltd ("we," "us"), a company registered in England and Wales (company number 14687093), registered office Regents Court, Kingston KT2 5AQ, United Kingdom. We are the data controller for personal information processed through the BreakDawn web application and related services (the "Service"). This policy explains what we collect, how we use it, and your rights. If you do not agree, please do not use the Service.

    The most important point: contrary to what an earlier version of this policy may have said, your recovery data is stored on our servers, not only on your device. We hold it on managed infrastructure in the EU (Ireland) and are technically able to access it to operate the Service. We explain below exactly what this means and how we protect it.

    2. Information we collect

    2.1 Information you provide

    • Account details - your email address and authentication credentials.
    • App Lock PIN - a PIN you can set to lock the app. It is held on your device as a salted cryptographic hash, not as the PIN itself. The App Lock is a convenience layer to deter casual access; it is not a substitute for your device's own lock screen, which we recommend you enable.
    • Sobriety date and recovery progress - the date you set and your milestone progress.
    • My Circle contacts - names, email addresses, and optionally phone numbers for up to 8 people you choose. We use email to contact them; phone numbers, if added, are used only for in-app tap-to-call.
    • Messages and SOS alerts to your Circle - delivered by email and stored on our servers.
    • Mood and craving logs and notes - ratings, tags, and any notes you record.
    • Chat with Ikki - your conversations with our AI assistant. To generate replies, your message content is sent to Google Gemini via the Lovable AI Gateway.
    • Saved venues - places you save from the Sober Social Finder.

    2.2 Information collected automatically

    • Device and app information (device/browser type, operating system, app version).
    • Usage data, error and crash reports, and performance metrics.
    • Location - only when you actively use the Sober Social Finder, to search for nearby alcohol-free venues. It is not tracked continuously.

    2.3 What we do not collect

    We do not collect government identification, payment-card details (handled by our payment provider), health-insurance information, biometric data, audio or video recordings, or your browsing history outside the Service.

    3. How we use your information

    • To provide the Service: track your progress, run the Ikki chat, deliver Circle and SOS emails, and find venues.
    • To keep users safe: run deterministic crisis detection and deliver crisis follow-up check-ins.
    • To improve and secure the Service: diagnose issues, analyse aggregated usage, and prevent fraud or abuse.
    • To communicate with you: service notifications, push notifications you have enabled, and responses to support requests.
    • To comply with legal obligations and respond to lawful requests.

    4. Where your data is stored and how it is protected

    4.1 Server-side storage

    Your data is stored in a managed Supabase (PostgreSQL) database hosted in the EU (region EU-West-1, Ireland), with access controlled by row-level security. This includes your account, sobriety date and recovery fields, mood and craving logs, journal entries, chat history, Circle contacts and messages, crisis and follow-up records, saved venues, Pathway progress (your start date and which day numbers you've completed - no reflection text is stored). Because this data is held server-side, we are technically able to access it - for example to operate, support, secure, or back up the Service, or where the law requires.

    4.2 Encryption - honestly stated

    Data is transmitted over HTTPS/TLS. Your Ikki chat history and your journal entries are additionally encrypted at rest using AES-256-GCM; however, the encryption key is derivable on our servers, so this is not zero-knowledge encryption - we can decrypt them. Other data is held within our managed database, which provides provider-level encryption at rest, but is not separately encrypted by the application. Your App Lock PIN is stored on your device as a salted hash. No system is perfectly secure, and we cannot guarantee absolute security; please keep your device secure and use its built-in lock.

    4.3 Crisis and email logging

    When crisis detection triggers, we record only metadata (such as a user reference, trigger type, and severity) - not the content of your message. Email delivery is logged as metadata only. We do not log the content of crisis messages.

    5. How we share your information

    5.1 With people you choose

    When you add Circle members and send them messages or SOS alerts, that information is shared with them by email. You control what you send.

    5.2 With our service providers (processors)

    • Supabase - database and backend hosting (EU-West-1, Ireland).
    • Lovable AI Gateway / Google Gemini - processes your Ikki chat content to generate AI replies. If you use the journal "Reflect" feature, it also processes the journal entry you choose to reflect on, together with a short window of your recent entries and mood ratings, to generate that reflection. This content is sent only when you tap Reflect; it is not stored or logged on our servers beyond producing the reflection. The AI provider processes it under its own terms.
    • Lovable email service - sends transactional, crisis, and Circle emails (sender notify.breakdawn.io).
    • Google Places API - venue search (receives your location and search query when you use the Social Finder).
    • Web Push services - your browser's push provider delivers notifications you have enabled.

    5.3 What we do not do

    We do not sell your personal information, and we do not share it with advertisers, insurers, or employers.

    5.4 Legal and business transfers

    We may disclose information where required by law, to enforce our Terms, or to protect rights and safety. If the business is involved in a merger or acquisition, your information may transfer; we will give notice.

    6. Your rights and choices

    You can view and update much of your information directly in the app. You can also:

    • Export your data - the app's data-export feature provides a copy of your data.
    • Erase your data - wipe your recovery data from our servers while keeping your account.
    • Delete your account - a separate action that fully deletes your account and associated data. See our Account & Data Deletion page for steps and details.
    • Control location and notification permissions in your device or browser settings.

    6.1 Your rights under UK and EU GDPR

    If you are in the UK or EU, you have the rights to access, rectification, erasure, restriction, data portability, objection, and to withdraw consent, and the right to lodge a complaint with a supervisory authority. To exercise these rights, contact team@breakdawn.io; we aim to respond within one month.

    6.2 California (CCPA)

    If you are a California resident, you have rights to know, to delete, to opt out of "sale" (we do not sell personal information), and to non-discrimination. Contact team@breakdawn.io.

    7. Children

    BreakDawn is for adults aged 18 and over. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact team@breakdawn.io and we will delete it.

    8. Data retention

    We keep your data while your account is active. When you erase your data or delete your account, we remove it from our active systems, subject to limited exceptions where we must retain certain records - for example, billing records for accounting, and email suppression records needed to honour unsubscribe and bounce requests. Metadata logs (such as crisis-event and email-delivery metadata) and aggregated analytics are retained for limited periods for safety, support, and service-improvement purposes.

    9. International transfers

    Your core data is stored in the EU (Ireland). Some processors - including Google Gemini (via the Lovable AI Gateway), Lovable's email service, and Google Places - may process data outside the EEA. Where that happens, we rely on appropriate safeguards (such as adequacy decisions or standard contractual clauses) as required by UK and EU data-protection law.

    10. Third-party links

    The Service may link to third-party sites (for example, emergency-support websites). We are not responsible for their privacy practices; please read their policies.

    11. Changes to this policy

    We may update this policy. We will change the "Last updated" date and notify you of material changes via the Service or by email.

    12. Contact us

    Privacy questions or requests: team@breakdawn.io.

    Data protection contact: Narmis Services Ltd, Regents Court, Kingston KT2 5AQ, United Kingdom.

    If you are in the UK or EU and believe we have not complied with data-protection law, you can complain to your supervisory authority. In the UK this is the Information Commissioner's Office (ICO), ico.org.uk.

    Narmis Services Ltd trading as BreakDawn.

    Registered office: Regents Court, Kingston KT2 5AQ, United Kingdom. Registered in England and Wales, company number 14687093.

    Contact: team@breakdawn.io · www.breakdawn.io