Last updated: 13 June 2026 · Effective: 13 June 2026
BreakDawn is operated by Narmis Services Ltd ("we," "us"), a company registered in England and Wales (company number 14687093), registered office Regents Court, Kingston KT2 5AQ, United Kingdom. We are the data controller for personal information processed through the BreakDawn web application and related services (the "Service"). This policy explains what we collect, how we use it, and your rights. If you do not agree, please do not use the Service.
We do not collect government identification, payment-card details (handled by our payment provider), health-insurance information, biometric data, audio or video recordings, or your browsing history outside the Service.
Your data is stored in a managed Supabase (PostgreSQL) database hosted in the EU (region EU-West-1, Ireland), with access controlled by row-level security. This includes your account, sobriety date and recovery fields, mood and craving logs, journal entries, chat history, Circle contacts and messages, crisis and follow-up records, saved venues, Pathway progress (your start date and which day numbers you've completed - no reflection text is stored). Because this data is held server-side, we are technically able to access it - for example to operate, support, secure, or back up the Service, or where the law requires.
Data is transmitted over HTTPS/TLS. Your Ikki chat history and your journal entries are additionally encrypted at rest using AES-256-GCM; however, the encryption key is derivable on our servers, so this is not zero-knowledge encryption - we can decrypt them. Other data is held within our managed database, which provides provider-level encryption at rest, but is not separately encrypted by the application. Your App Lock PIN is stored on your device as a salted hash. No system is perfectly secure, and we cannot guarantee absolute security; please keep your device secure and use its built-in lock.
When crisis detection triggers, we record only metadata (such as a user reference, trigger type, and severity) - not the content of your message. Email delivery is logged as metadata only. We do not log the content of crisis messages.
When you add Circle members and send them messages or SOS alerts, that information is shared with them by email. You control what you send.
We do not sell your personal information, and we do not share it with advertisers, insurers, or employers.
We may disclose information where required by law, to enforce our Terms, or to protect rights and safety. If the business is involved in a merger or acquisition, your information may transfer; we will give notice.
You can view and update much of your information directly in the app. You can also:
If you are in the UK or EU, you have the rights to access, rectification, erasure, restriction, data portability, objection, and to withdraw consent, and the right to lodge a complaint with a supervisory authority. To exercise these rights, contact team@breakdawn.io; we aim to respond within one month.
If you are a California resident, you have rights to know, to delete, to opt out of "sale" (we do not sell personal information), and to non-discrimination. Contact team@breakdawn.io.
BreakDawn is for adults aged 18 and over. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact team@breakdawn.io and we will delete it.
We keep your data while your account is active. When you erase your data or delete your account, we remove it from our active systems, subject to limited exceptions where we must retain certain records - for example, billing records for accounting, and email suppression records needed to honour unsubscribe and bounce requests. Metadata logs (such as crisis-event and email-delivery metadata) and aggregated analytics are retained for limited periods for safety, support, and service-improvement purposes.
Your core data is stored in the EU (Ireland). Some processors - including Google Gemini (via the Lovable AI Gateway), Lovable's email service, and Google Places - may process data outside the EEA. Where that happens, we rely on appropriate safeguards (such as adequacy decisions or standard contractual clauses) as required by UK and EU data-protection law.
The Service may link to third-party sites (for example, emergency-support websites). We are not responsible for their privacy practices; please read their policies.
We may update this policy. We will change the "Last updated" date and notify you of material changes via the Service or by email.
Privacy questions or requests: team@breakdawn.io.
Data protection contact: Narmis Services Ltd, Regents Court, Kingston KT2 5AQ, United Kingdom.
If you are in the UK or EU and believe we have not complied with data-protection law, you can complain to your supervisory authority. In the UK this is the Information Commissioner's Office (ICO), ico.org.uk.