Privacy Policy

Last updated: August 14, 2026

Your privacy matters to us. This policy explains what data we collect, how we use it, and the rights you have over your personal information.

1. Information We Collect

We collect the following personal information when you create an account:

  • Full name
  • Email address
  • Respiratory therapy license number(s)
  • State(s) of practice
  • CEU records (course title, provider, credits, completion date)
  • Certificate images (uploaded photos or files)
  • NBRC credential information (credential type, cycle dates)

2. How We Use Your Information

Your information is used solely for the purpose of providing the Breathe service:

  • Tracking CEU progress toward state license renewal requirements
  • Generating compliance reports for state boards and employers
  • Sending license renewal reminders via email and SMS (Pro plan)
  • Syncing CEU records to CE Broker (Pro plan, when enabled)
  • Providing NBRC credential cycle tracking and competency management

3. What We Do NOT Do

We are committed to your privacy. Specifically, we do NOT:

  • Sell your personal data to third parties — ever
  • Share your CEU records or personal information with employers without your explicit consent
  • Use your data for advertising or marketing purposes beyond service-related communications
  • Share your data with data brokers or analytics networks

4. CEU Records and HIPAA

Your CEU records, certificate images, and license information are professional development records, NOT Protected Health Information (PHI) under HIPAA. They do not contain patient medical data. Breathe is not a HIPAA-covered entity, and your CEU data is not subject to HIPAA regulations.

5. Data Security

We take the security of your data seriously and employ industry-standard protections:

  • Passwords are hashed using bcrypt — we never store plaintext passwords
  • CE Broker credentials (if provided) are encrypted using AES-256 via Python's Fernet symmetric encryption
  • Authentication uses JWT (JSON Web Tokens) with signed, time-limited tokens
  • All API communication uses HTTPS/TLS encryption
  • Certificate images are stored securely and accessible only to the account owner

6. Data Retention

Your personal data and CEU records are retained for as long as your account is active. When you request account deletion, all associated data — including CEU records, certificate images, and personal information — is permanently deleted from our systems within 30 days.

The only data retained after account deletion is anonymized Stripe transaction records required for financial compliance.

7. Your Rights

You have the following rights regarding your personal data:

  • Access — view all personal data stored in your account at any time
  • Export — download your CEU records and account data in a portable format
  • Delete — permanently delete your account and all associated data
  • Correct — update or correct any inaccurate personal information

8. Third-Party Services

Breathe integrates with the following third-party services. Each has its own privacy policy that governs how they handle your data:

  • Stripe — payment processing for Pro plan subscriptions ($22/year). Stripe receives your payment information directly; we do not store credit card numbers.
  • Resend — transactional email delivery for renewal reminders and account notifications.
  • Deepgram — used in the OCR pipeline to extract text from uploaded certificate images (Pro plan feature).

9. Cookies

Breathe uses minimal session cookies solely for authentication purposes. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Session cookies are essential for maintaining your login state and are deleted when you close your browser.

10. Children's Privacy

Breathe is designed for licensed respiratory therapists and does not knowingly collect information from children under 13. If you believe a child has provided personal information, please contact us and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Users will be notified of material changes via email or in-app notification. Continued use of the service after changes take effect constitutes acceptance of the updated policy.

12. Contact

For questions about this Privacy Policy or to exercise your data rights, contact: ron.sublett@gmail.com