Privacy Policy
Last updated: September 5, 2026
This Privacy Policy describes how Loch Inc. ("Loch", "we", "us", or "our") collects, uses, and shares information when you use the Dhira iOS app and our website at dhira.co (together, the "Service"). By using the Service you agree to this Policy. If you do not agree, please do not use the Service.
1. Who we are
Loch Inc. is the controller responsible for your personal information in connection with the Service. You can reach us about privacy at support@dhira.co.
2. Information we collect
Information you provide
- Account information — your email address and authentication identifiers when you create an account with Sign in with Apple, Google Sign-In, or email and password. If you sign in with Apple or Google, we receive your email and, where you allow it, your name. Passwords for email accounts are handled and stored in hashed form by our authentication provider; we never see your password in plain text.
- Profile & onboarding details — your display name, an avatar you choose from a built-in set, and the answers you give during onboarding, such as your goals, experience level, daily-practice length, interests, and lifestyle preferences.
- Support messages — the category, subject, and content of messages you send through in-app support, so we can respond to you.
Information created through your use of the Service
- Practice data — records of the meditation and breathwork sessions you complete (such as the lesson and duration), playback progress, saved verses, lessons, courses, and breathing exercises, course progress, streaks, and streak freezes.
- Preferences — settings such as your theme, notification preferences, timezone, and recommended-plan selections.
- Subscription data — your subscription and entitlement status (for example, whether you have Dhira Pro, the product purchased, renewal status, and expiry), and purchase events reported to us by our payments provider.
- Referral data — your referral code and, if applicable, referral relationships and offer codes assigned to your account.
Information collected automatically
- Push notification token — if you enable notifications, we store the push token issued by the notification service so we can deliver notifications you have opted into.
- Technical & log data — our infrastructure providers automatically log basic technical information (such as IP address, request timestamps, and device/app metadata) as needed to operate, secure, and troubleshoot the Service. The Dhira iOS app contains no third-party analytics, advertising, or tracking SDKs and does not track you across other apps or websites.
- Website advertising cookies — on dhira.co we use the TikTok advertising pixel to understand which of our ads bring people to the site. It sets a cookie and shares the standard technical details of a web visit with TikTok, such as the pages you viewed and your device, browser, and IP address. It never receives your name, email address, account, or anything you do inside the app. If you are in the EEA, the UK, or Switzerland, the pixel does not load unless you accept it, and you can turn it back off at any time from Cookie settings in the website footer. Elsewhere it runs when you arrive; you can block cookies in your browser settings, or email us at support@dhira.co and we will opt you out. Nothing on the website or in the app depends on your choice, and the Dhira app itself carries no advertising cookies at all.
- Information collected from Meta (Facebook) — if you connect our Service to Meta for marketing or analytics features, we collect data through the Meta Marketing API. This specific data includes ad campaign metadata (e.g., campaign names, budgets, and schedules), ad creative (images, videos, and text), and performance insights (spend, impressions, and clicks).
3. How we use your information
- Provide, operate, and maintain the Service and your account.
- Personalize your experience and generate practice recommendations.
- Track your progress, streaks, and saved content.
- Process and validate subscriptions, purchases, referrals, and offer codes.
- Send notifications and reminders you have opted into.
- Respond to your support requests and communicate with you about the Service.
- Maintain the security and integrity of the Service and detect or prevent fraud and abuse.
- Comply with legal obligations and enforce our Terms of Service.
- Facilitate marketing analytics and campaign management using data retrieved from Meta. We strictly use this data to provide these requested features. We do not use Meta API data to build personal profiles of end-users for unauthorized purposes.
4. Legal bases for processing (EEA/UK users)
If you are in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases: to perform our contract with you (providing the Service, your account, and subscriptions); with your consent (push notifications, and the website advertising cookies described in section 2, which we ask you to accept before loading them if you are in the EEA, the UK, or Switzerland — either of which you can withdraw at any time); for our legitimate interests (keeping the Service secure, improving it, and preventing abuse); and to comply with legal obligations.
5. How we share information
We do not sell your personal information. We share it with service providers that process it on our behalf under contract, where required by law, and — on our website only, and where advertising cookies are active — with TikTok, for advertising measurement. Some privacy laws classify that last case as "sharing" for cross-context behavioral advertising, so section 10 explains how to opt out. Our key providers and recipients are:
- Supabase — authentication, database, storage, and backend functions that power the Service.
- Apple — Sign in with Apple and App Store billing for subscriptions and in-app purchases.
- Google — Google Sign-In (if you choose that method).
- RevenueCat — management and validation of subscriptions and purchases.
- Expo — delivery of push notifications via the Expo push notification service (if you enable notifications).
- TikTok — measurement of our website advertising via the TikTok pixel, while advertising cookies are active. Unlike the providers above, TikTok is an independent controller rather than our processor, so its own Privacy Policy governs what it does with the data.
Each provider processes data under its own privacy policy and our agreements with it. We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, in which case we will notify you as required.
6. What we do not do
- We do not sell or rent your personal information.
- We do not use third-party analytics, advertising, or tracking SDKs in the Dhira app, and we do not use the App Tracking Transparency identifier (IDFA). Our website uses a single advertising cookie — see section 2 for how to opt out of it.
- We do not currently collect Apple Health data. If we add optional Apple Health integration in the future, we will request your explicit permission first, and you can revoke it at any time in iOS Settings.
- We explicitly do not sell, rent, or transfer any advertising data retrieved from Meta Platforms to third-party data brokers, ad networks, or unauthorized services.
7. International data transfers
We and our providers may process and store information in the United States and other countries where our providers operate. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. While advertising cookies are active on our website, TikTok receives that data as an independent controller, under its own safeguards. In the EEA, the UK, and Switzerland nothing is sent unless you accept; elsewhere, opting out as described in section 2 stops any further transfer.
8. Data retention
We retain your account, practice data, and authorized Meta API data for as long as your account is active. When you delete your account, we delete your personal data associated with that account, except where we are required to retain limited information to comply with legal, accounting, or security obligations, or to resolve disputes. Any inactive Meta advertising data is automatically purged after 90 days of inactivity. Backups are purged on a rolling basis.
9. Security
We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, and row-level security that restricts your data to your own account. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Your rights and choices
- In-app controls — update your profile, manage notification preferences, and control your practice data from the app's Settings.
- Delete your account — remove your account and associated personal data at any time from Settings → Account → Delete account.
- Notifications — turn notifications on or off in the app and in iOS Settings.
- Subscriptions — manage or cancel through your Apple ID subscription settings.
EEA/UK residents have the right to access, correct, delete, restrict, or object to processing of their personal data, to data portability, and to withdraw consent at any time. You also have the right to lodge a complaint with your local data-protection authority.
California residents have the right to know what personal information we collect and how we use and disclose it, to request access to and deletion or correction of their personal information, and to not be discriminated against for exercising these rights. We do not sell personal information. Our use of the TikTok pixel on dhira.co may count as "sharing" for cross-context behavioral advertising under the California Consumer Privacy Act; you can opt out at any time by blocking cookies in your browser settings or by emailing us at the address below. To exercise any of these rights, contact us at support@dhira.co; we will verify your request through your account and respond as required by law. You may use an authorized agent where permitted.
11. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at support@dhira.co and we will delete it. Users between 13 and 18 should use the Service only with the involvement of a parent or guardian.
12. Third-party links
The Service may link to third-party websites or services that we do not control. This Policy does not apply to those third parties, and we encourage you to review their privacy policies.
13. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice in the app or by email. Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.
14. Contact us
Loch Inc.
2261 Market St.
San Francisco, CA 94105
USA
Email: support@dhira.co