Legal

Privacy Policy

Last updated: June 2026

1. Who We Are

CalmEcho ("we", "us", "our") operates the CalmEcho meditation and wellness application available at thecalmecho.com and associated mobile and web applications. We act as the data controller for the personal data described in this policy.

For privacy enquiries, contact us at our contact page or email: privacy@thecalmecho.com

2. What Data We Collect

We collect the following categories of personal data:

Account Data

  • Email address (required for account creation)
  • Display name / full name
  • Password (stored as a hashed credential by Supabase — we never see your plain-text password)
  • Profile photo URL (optional, from Google OAuth)
  • Date of birth (optional, if provided in settings)
  • Timezone and language preference (optional)
  • Bio (optional)

Usage, Wellness & Health Data

  • Meditation session history (type, duration, completion status)
  • Mood entries (before/after session, if provided) — classified as health information under GDPR Art. 9
  • Session notes (if provided)
  • Breathing exercise sessions
  • Activity statistics and streaks
  • Daily goal setting (stored locally in your browser)

Mood entries and wellness session data may constitute health-related personal data (a special category under GDPR Art. 9). See Section 4 for the additional lawful basis we rely on for processing this data.

Payment Data

  • Stripe customer ID (a reference token, not card details)
  • Subscription status, tier, and renewal date
  • Payment history (via Stripe — card numbers are never stored by us)

Technical Data

  • Authentication session token (stored in browser local storage by Supabase)
  • IP address and user agent (logged by our infrastructure providers)

3. How We Use Your Data

  • To create and manage your account
  • To deliver the meditation and breathwork service
  • To process subscription payments and send billing confirmation emails
  • To send transactional emails (welcome, premium activation, password reset) via Resend
  • To track your wellness progress and generate statistics
  • To maintain security and prevent fraud
  • To respond to your support requests
  • To comply with legal obligations

4. Lawful Basis for Processing (GDPR Art. 6)

Consent — Art. 6(1)(a)

You give explicit consent when you create an account by accepting these terms. You may withdraw consent at any time by deleting your account.

Contract — Art. 6(1)(b)

Processing is necessary to fulfil the subscription contract when you purchase Premium access.

Legal Obligation — Art. 6(1)(c)

We retain payment records to comply with tax and accounting laws.

Legitimate Interests — Art. 6(1)(f)

Security monitoring, fraud prevention, and service improvement.

Special Category Health Data — Art. 9(2)(a)

Mood entries and wellness session data constitute special category personal data (health information) under GDPR Art. 9. We process this data on the basis of your explicit consent under Art. 9(2)(a), given when you tick the consent checkbox at registration. You may withdraw this consent at any time by deleting your account; your data will be purged within 30 days.

5. Third-Party Data Processors

We share data only with the following processors, each bound by data processing agreements:

Supabase

Authentication and database hosting · EU (AWS Frankfurt)

Stripe

Payment processing and subscription billing · USA (Standard Contractual Clauses apply)

Resend

Transactional email delivery · USA (Standard Contractual Clauses apply)

Google

OAuth sign-in (if used) · Global

We do not sell your data to any third party.

6. Data Retention

  • Account data is retained while your account is active.
  • Wellness and session data is retained for as long as you hold an account.
  • After an account deletion request, personal data is purged within 30 days except where we are legally required to retain billing records (typically 7 years).
  • Authentication logs are retained for 90 days for security purposes.

7. Your Rights Under GDPR (EU/UK Users)

If you are in the European Economic Area or United Kingdom, you have the following rights:

Right of Access (Art. 15)

Request a copy of all data we hold about you.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete data.

Right to Erasure (Art. 17)

Request deletion of your data ("right to be forgotten").

Right to Portability (Art. 20)

Receive your data in a machine-readable format.

Right to Restriction (Art. 18)

Limit how we process your data.

Right to Object (Art. 21)

Object to processing based on legitimate interests.

To exercise any right, contact us via our contact page. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

8. Cookies & Local Storage

We use strictly necessary storage only:

  • Supabase authentication token — stored in browser local storage to keep you signed in. This is essential for the service to function.
  • Daily goal preference — stored in browser local storage under the key "zenmind_daily_goal". This never leaves your device.
  • No analytics cookies, no advertising trackers, no third-party cookies.

Because we use only strictly necessary storage, no cookie banner is required under GDPR Recital 30. You can clear this data at any time by signing out or clearing your browser storage.

Do Not Track: Some browsers transmit "Do Not Track" (DNT) signals. We do not currently alter our data practices in response to DNT signals, as no industry-wide standard for responding to them has been adopted. California residents may exercise opt-out rights under Section 12 instead.

9. International Data Transfers

Stripe and Resend are US-based companies. Data transferred to them is protected under the EU Standard Contractual Clauses (SCCs) approved by the European Commission, which provide equivalent data protection safeguards. Supabase stores your database on AWS infrastructure in the EU (Frankfurt) by default.

10. Children's Privacy

CalmEcho is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

11. Security

We implement appropriate technical and organisational measures to protect your data: row-level security (RLS) on all database tables, encrypted connections (HTTPS/TLS), server-side JWT verification for all authenticated API calls, and service-role database access restricted to the backend only.

In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify affected users without undue delay and report to the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Art. 33–34.

12. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights in addition to those above:

Your California Rights

Right to Know

Request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.

Right to Delete

Request deletion of personal information we have collected, subject to certain exceptions.

Right to Correct

Request correction of inaccurate personal information we maintain about you.

Right to Opt-Out of Sale

We do not sell or share your personal information for cross-context behavioural advertising. No opt-out action is required.

Right to Limit Sensitive Data Use

We do not use sensitive personal information (wellness data, mood entries) for purposes beyond delivering the Service.

Right to Non-Discrimination

We will not discriminate against you for exercising any CCPA right — no price changes, service denial, or reduced quality.

Categories of Personal Information Collected (Last 12 Months)

  • Identifiers: name, email address, account ID
  • Personal records: date of birth, timezone, language preference (if provided)
  • Internet or network activity: authentication logs, app usage
  • Commercial information: subscription status, payment history reference via Stripe
  • Sensitive personal information: wellness session data and mood entries

Do Not Sell or Share

CalmEcho does not sell and does not share your personal information with third parties for cross-context behavioural advertising purposes. No opt-out link is required, but we include this confirmation for transparency.

To exercise any California right, contact us via our contact page or email privacy@thecalmecho.com. We will respond within 45 days (with a possible 45-day extension where reasonably necessary). We will not require you to create an account to submit a request.

Other US State Privacy Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with comprehensive privacy laws have similar rights to access, correct, delete, and port their data, and to opt out of sale and targeted advertising. The same contact process applies. We will respond within the timeframe required by your state's law.

13. Business Transfers

If CalmEcho is involved in a merger, acquisition, asset sale, bankruptcy, or reorganisation, your personal data may be transferred to the acquiring entity as part of that transaction. We will notify you by email or prominent in-app notice at least 30 days before your data is transferred and becomes subject to a different privacy policy. The successor entity will be required to honour all commitments made in this policy or obtain fresh consent from you.

14. Changes to This Policy

We may update this policy from time to time. We will notify you by email at least 30 days before any material change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.

Questions? Contact us or view our Terms of Service.