Privacy Policy
How we collect, use, store, and protect your data across Breathe Connective — built on WordPress + PeepSo with AI safety tooling.
On this page
1) Who we are (Data Controller)
Website: https://breatheconnective.com
Controller / operator: Painted Sky Connective LLC (trading as “Breathe Connective”)
Privacy contact: privacy@breatheconnective.com
If you are in the EEA/UK, we process your data as a “controller” under GDPR/UK GDPR. Where data leaves the EEA/UK, we use Standard Contractual Clauses and supplementary measures where required.
2) Scope
This Policy applies to visitors and registered members who access our public pages and community features (profiles, activity stream, Circles/Groups, messages, notifications, events, media uploads, and email digests where enabled).
3) What we collect
a) You provide
- Account & profile: name, username, email, password, profile fields configured by us (bio, interests, city/region).
- Community content: posts, comments, reactions, uploads (avatars, cover images, photos/videos), Circle participation, event RSVPs.
- Messages: direct & group messages (Better Messages / PeepSo messaging, if enabled).
- Preferences & consents: privacy settings, notification choices, cookie preferences, acceptance of Terms/Privacy.
- Transactions (if applicable): billing name, email, and limited payment metadata. We do not store full card numbers.
b) Collected automatically
- Device/usage: IP address, browser/OS, language, page views, referrers, timestamps, approximate location (city/region), diagnostics.
- Cookies/local storage: login persistence, security, preferences, analytics, and community UX.
- Server logs & security telemetry: error logs, abuse-prevention signals, rate limiting.
c) From others / integrations
- Anti-spam & security tools: risk scores and abuse indicators.
- Embeds & connected services: when you interact with third-party embeds, they may collect data under their own policies.
- Gravatar: we may send a hashed email to fetch your avatar.
4) PeepSo-specific notes
- Features: profiles, activity streams, reactions, media, Circles (Groups), messaging, notifications, and content visibility controls.
- Visibility: you can choose who sees your content (public, members, friends, only me) subject to admin-configured options.
- Export/erasure: we support WordPress core privacy tools and PeepSo’s GDPR export queue to deliver your community data and process erasure.
- Storage: community data lives in our WordPress database and media library on our hosting infrastructure.
5) Our use of AI
We use AI to enhance safety and user experience, including:
- Safety & moderation: spam/abuse detection and policy-violation flags (public content; private messages only if reported or where minimal automated filtering is necessary).
- Assistive features: summarization, translation, recommendations, smarter search, captioning/transcription.
- Support & ops: routing tickets and anonymized trend analysis.
What may be processed: public posts/comments, titles, tags, limited metadata; reported private content; necessary context (e.g., language). We minimize personal data and apply access controls.
Model providers: we prioritize self-hosted models or reputable providers under data processing terms. We do not allow providers to train their foundation models on your personal data without your explicit consent.
Automated decisions: we do not make decisions with legal or similarly significant effects solely by automated means. Human review is available.
Your choices: you may opt out of AI-driven personalization where technically feasible. Safety/abuse detection remains active.
6) Why we use your data (legal bases)
- Provide the Services (Contract / Legitimate interests)
- Moderation & security (Legitimate interests / Legal obligation)
- Improve & analyze (Legitimate interests / Consent where required)
- Communications (Contract / Legitimate interests / Consent)
- Compliance (Legal obligation)
7) Cookies & similar tech
We use essential cookies (login/session, security), functional cookies (preferences, UI), analytics, and third-party cookies set by embeds or tools you interact with. Use our cookie banner (where shown) and your browser settings to manage choices. Disabling essential cookies will break some features. We honor Global Privacy Control (GPC) where required.
WordPress sets typical cookies for login, comments, and screen options; PeepSo may add functional cookies to support community UX.
8) Comments
When you comment, we collect the form data, your IP, and user agent to fight spam. After approval, your avatar (e.g., via Gravatar) may display with your comment.
9) Media
Avoid uploading images with embedded EXIF GPS data. Visitors can download and extract location data from publicly available images.
10) Embedded content & external links
Embedded content (videos, images, articles) behaves as if you visited the other site. Those providers may set cookies and track your activity, particularly if you are logged in to their services. Review their privacy policies.
11) Messaging (Better Messages / PeepSo PM)
Messages are intended to be private between participants. Administrators access message content only when necessary for safety, legal compliance, or technical troubleshooting, and under strict access controls. Some deployments use vendor WebSocket relays for real-time delivery; these relays are for transport and not for storing private message content.
12) Who we share your data with
- Service providers / processors: hosting, CDNs, analytics, security, email/SMS, payments, AI infrastructure (under DPAs).
- Legal & safety: to comply with lawful requests, enforce terms, and protect users/the public.
- Business transfers: data may transfer in a merger/acquisition under this Policy’s safeguards.
If you request a password reset, your IP may appear in the reset email for security.
13) International data transfers
Your data may be processed outside your country. For EEA/UK data transferred to jurisdictions without an adequacy decision, we use Standard Contractual Clauses and supplementary measures.
14) How long we keep data
- Account & profile: for the life of your account; limited security logs up to 12 months after deletion.
- Posts/comments/media: until you delete them or request erasure; public copies made by others may persist.
- Messages: retained while accounts are active; participants may retain their copies.
- Server logs & security telemetry: up to 12 months.
- Backups: rolling backups typically up to 90 days.
- Support & ops records: up to 24 months after closure.
We may keep anonymized/aggregated data longer for analytics.
15) How we store & protect data
- Encryption: TLS in transit; encryption at rest where supported.
- Access controls: least-privilege; MFA for staff where possible.
- Audit & segmentation: admin action logging; environment separation.
- Patching: timely security updates to WordPress, PeepSo, and extensions.
- Incidents: if a breach risks your rights/freedoms, we’ll notify affected users and regulators as required.
16) Your rights
EEA/UK (GDPR/UK GDPR)
Rights include access, rectification, erasure, restriction, objection, and data portability. Where processing relies on consent, you may withdraw it any time. You may complain to your Data Protection Authority.
California (CCPA/CPRA)
Residents can know, access, correct, delete, and opt out of sharing/sale of personal information (we do not sell PI). We honor GPC where required. We do not use sensitive PI to infer characteristics without your consent.
How to exercise
Email privacy@breatheconnective.com from your account address. We support WordPress/PeepSo privacy tools to export or erase your community data. We may need to verify your identity.
17) Children’s privacy
Our Services are not directed to children under 16 (or local age of digital consent). If you believe a child provided data, contact us for deletion.
18) Changes to this Policy
We may update this Policy to reflect changes in law or our Services. We’ll post updates with a new effective date and, where material, provide in-product or email notice.
19) Contact
Breathe Connective (Painted Sky Connective LLC)
Email: privacy@breatheconnective.com
Appendix A — WordPress-typical cookie summary
- comment_author_*, comment_email_*, comment_url_* (up to 1 year) – commenter convenience.
- wordpress_logged_in_* (session/2 days/2 weeks if “Remember Me”) – authentication.
- wp-settings-* (1 year) – screen/options preferences.
- wp-postpass_* (session) – access to password-protected posts.
- Editor/post edit cookie (1 day) – indicates the post ID you edited.
Appendix B — AI practices (summary)
- Purposes: moderation/safety, assistance (summaries, translation), recommendations, support triage.
- Data handling: minimal necessary inputs; access controls; processor DPAs; no provider training on your personal data without explicit consent.
- Human oversight: moderation outcomes can be appealed; no solely automated decisions with legal/similarly significant effects.
- Opt-outs: request to disable AI personalization where feasible; safety/abuse detection remains active.
- Providers & regions: self-hosted or reputable providers; SCCs for non-EEA regions; current list available upon request.