Breakup is built around a simple rule: look for services on your iPhone, not on our servers. This policy explains the small amount of information that leaves your phone, why it is needed, and how it is protected.
Last updated: 30 July 2026.
The short version
- Gmail stays local. Your scan and service matching happen on your iPhone. Email bodies, subjects, snippets, message IDs, and raw Gmail headers are not sent to our backend. An encrypted service map may be stored for restore and sync, but our backend cannot read it.
- Your local data is protected. Mailbox-derived files use iOS Complete File Protection and are excluded from device backups. Account ownership is bound in the device-only Keychain.
- You approve every send. Breakup asks for Gmail send access only when you confirm requests you have reviewed.
- Sync is unreadable to us. Private app state is encrypted on your device before it is uploaded.
- No advertising business. We do not sell personal information, build ad profiles, or use Gmail data to train AI models.
What Breakup reads from Gmail
When you connect Gmail, Breakup requests metadata access. On your iPhone, it uses the exact sender address, Gmail's delivery and authentication results, limited forwarding and mailing-list indicators, message labels, and delivery time to identify services safely. It matches that evidence against a signed public list of sender identities that Breakup has independently certified as belonging to the service shown.
Breakup does not scan email bodies. Subjects, snippets, message and thread IDs, and raw headers stay on your device. Mailbox observations and scan checkpoints stay local and are not restored from server sync as proof that a service should appear.
Gmail send access is requested separately, when you confirm a cleanup. It is used only to send messages you reviewed and approved from your Gmail account. Breakup does not use it to modify, archive, or delete your Gmail messages.
What stays on your device
Your mailbox observations and scan progress stay on your device. For restore and sync, Breakup may upload one encrypted state file containing your service list, decisions, review history, request records, and certified sender details retained in sent history. Your device encrypts it with a key held in iCloud Keychain, so our backend cannot read it.
Mailbox-derived local files are unreadable while your iPhone is locked and excluded from device backups. Breakup keeps a separate, non-synchronising Keychain marker on that device so one Google account cannot inherit another account's local state.
Your Google profile image is fetched using a temporary network session and stored only in Breakup's protected, backup-excluded cache for offline display. Switching or disconnecting accounts removes the previous account's cached image.
When information leaves your device
Service matching. As the precision update rolls out, newer versions download a signed public eligibility list and match it to authenticated sender evidence on your iPhone. Unknown senders are not submitted for identification. An older app version may still send a bare company domain for identification after the pre-connection disclosure and consent shown in that version. That legacy lookup contains no Gmail content, message details, or Breakup user ID. Company logos come from Breakup's shared cache, so logo providers do not see your IP address paired with a company domain.
User-approved requests. When you approve a paid request, our backend receives a random request ID, public eligibility-list version information, and a non-reversible commitment proving that the app used certified evidence. It does not receive the readable sender evidence or a request-to-company map.
Company replies. A request may use a random Breakup reply address. When a company replies, a short plain-text excerpt of up to 2 KB may be sent to Anthropic to identify a simple status such as completed, refused, or action needed. Breakup replaces email addresses in that classifier copy before sending it. Anthropic says commercial API data is not used to train its models and is normally deleted within 30 days, subject to limited security and legal exceptions.
Breakup encrypts the useful part of the reply for your device and discards the raw message from normal processing. Our backend keeps the encrypted excerpt and a generic status that does not quote the company. During an outage, Cloudflare may hold an encrypted recovery copy for up to 14 days. Its recovery key is held offline by the developer.
Optional credit review. If a company says it cannot find your data, you can tap They Couldn't Find My Data and separately confirm a review. Breakup then encrypts that specific reply together with the exact sender, recipient, and authentication evidence used to show the service. Only the privacy review key can open it. A human reviewer uses it solely to decide whether one Breakup should be returned; no other Gmail content is included.
What our systems keep
- Your account ID and basic Google sign-in information, such as your email address.
- Public encryption keys. The private keys stay with you.
- Random request IDs and reply addresses, timestamps, statuses, public eligibility-list versions, and non-reversible evidence commitments.
- Encrypted reply excerpts, optional encrypted credit-review evidence, and your encrypted app-state file.
- A notification token if you enable notifications.
- Purchase, entitlement, and credit records handled with Apple and RevenueCat.
- Small security and abuse-prevention records.
- Service-route feedback. It uses a one-way code to prevent duplicate reports rather than placing your user ID in the feedback record.
This website uses no advertising cookies or analytics scripts. Cloudflare may process ordinary request details, such as IP address, browser, page, and time, to deliver and protect it.
Who helps run Breakup
Breakup uses Google for sign-in and Gmail access; Supabase for accounts and backend storage; Cloudflare for the website and reply routing; Apple and RevenueCat for purchases; Anthropic for limited reply classification and service research; Firecrawl for public web research; and Logo.dev for public company logos cached by Breakup's backend.
These providers may process information in Australia, the United States, and other countries where they or their subprocessors operate. We use them only to provide, protect, and support Breakup.
How Google user data is shared
We do not sell Google user data. We disclose or transfer it only as described below to provide features the user requests:
- Gmail metadata and OAuth tokens: Raw Gmail headers, message and thread IDs, access tokens, and refresh tokens are processed on the user's iPhone and are not disclosed to Breakup's backend, Supabase, Anthropic, Firecrawl, Logo.dev, advertisers, data brokers, or other third parties.
- Google sign-in information: A nonce-bound Google ID token and basic profile information, such as the user's Google account ID and email address, are disclosed to Supabase only to authenticate the user's Breakup account. The profile image is fetched from Google and cached only on the user's device.
- Service matching: As the precision update rolls out, newer versions perform signed exact-sender matching on the iPhone and do not disclose unknown senders for identification. An older version may disclose only a bare company domain to Supabase, Anthropic, and Firecrawl for the consented legacy lookup described above. They do not receive Gmail content, raw headers, OAuth tokens, or the user's Google or Breakup account ID for that lookup.
- Encrypted app state: Supabase stores an end-to-end encrypted state file that may contain the service list, decisions, review history, request records, and certified sender details retained in sent history. The encryption key remains in the user's iCloud Keychain, so Supabase and Breakup cannot read this information. Mailbox observations and scan checkpoints are not restored from this file as eligibility evidence.
- User-approved outgoing email: When the user approves a request, the displayed recipient, subject, and body are disclosed to Google for delivery through Gmail and to the company the user selected as the recipient. Breakup does not send other messages or add undisclosed recipients.
- Optional credit review: Only after the user separately confirms a specific review, Supabase stores an HPKE-encrypted copy of that reply and the exact sender, recipient, and authentication evidence used to show the service. A member of Breakup's privacy review team may decrypt only that submitted evidence to decide whether to return one Breakup. No other Gmail content is shared.
How long we keep it
We keep account and request records only while they are needed to run Breakup, protect the service, maintain purchase records, meet legal obligations, or resolve disputes. Encrypted reply content is kept for no more than 180 days. Optional credit-review ciphertext is deleted seven days after review and always within 30 days of submission. Records used to avoid processing the same reply twice are removed after 180 days. Cloudflare recovery copies expire after 14 days.
Deleting your Breakup account removes the linked profile, devices, requests, encrypted state, credit-review claims, credits, related backend records, and protected local cache. We request deletion of the linked RevenueCat customer and revoke the Google connection. We keep only an irreversible, empty blocklist marker for each old random reply address so deleted addresses can never create new message content. It contains no address, user ID, email content, or account link.
Your choices
- Review every request before it is sent.
- Decline an optional credit review and keep the reply private to your device.
- Disable notifications in iOS Settings.
- Revoke Breakup's access from your Google Account settings.
- Delete your Breakup account in the app.
- Ask to access, correct, or delete personal information we hold.
Our Google data commitment
Breakup's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising or credit decisions, or use it to develop, improve, or train generalised or non-personalised artificial intelligence or machine-learning models. Humans do not read Google user data unless you give specific consent, it is necessary for security, or the law requires it.
Security
Breakup uses device-only and iCloud Keychain storage for different purposes, iOS Complete File Protection, backup exclusion, encryption, HTTPS, access controls, random reply addresses, and data minimisation. No system can promise perfect security, but Breakup is designed so our backend does not hold your sensitive Gmail content or the keys needed to read your synced app state.
Questions, requests, or complaints
Email the Privacy Officer at privacy@trybreakup.com to ask for access, correction, or deletion, or to make a complaint. We may need to verify your identity. We will acknowledge a complaint and aim to respond within 30 days.
If you are not satisfied and the Australian Privacy Act applies, you may contact the Office of the Australian Information Commissioner.
About this policy
Breakup is operated by the independent Australian developer identified as its seller on the Apple App Store. We may update this policy when the app, our providers, or the law changes. We will publish the revised policy and give notice in the app if a change materially affects personal information or Google user data.