Privacy Policy

Effective Date: November 1, 2025
Last Updated: November 2, 2025

This privacy policy applies to the Brain Dump mobile application (hereby referred to as "Application" or "App") created by Steady Labs (hereby referred to as "we," "us," or "Service Provider"). This Application is provided as a commercial service and is intended for use "AS IS."

We are committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding your personal data.

1. Information We Collect

1.1 Authentication & Account Data

Brain Dump uses anonymous authentication, meaning we do not require or collect:

  • Email addresses
  • Phone numbers
  • Real names
  • Passwords

Instead, we collect:

  • Anonymous User ID - A unique identifier generated by our authentication system
  • Device ID - A stable identifier created from your device name, timestamp, and a random string. This helps us maintain your account across app sessions without requiring personal information
  • Timezone - Your device's timezone setting (e.g., "America/New_York") to properly schedule reminders and notifications

1.2 User-Generated Content

We store content you create within the App:

  • Tasks & To-Do Items - Task titles, descriptions, due dates, priorities, estimated completion times, and completion status
  • Task Steps - Sub-tasks and detailed breakdowns you create for your tasks
  • Brain Dumps - The full text of your voice or typed brain dumps. This content is sent to Google Gemini AI to extract actionable tasks
  • Voice Recordings - Audio recordings are temporarily processed through Deepgram's speech-to-text service. Audio files are not permanently stored; only the transcribed text is retained
  • Emotional Check-ins - When you log your emotional state (e.g., focused, struggling, tired), we store the emotion type, timestamp, and context (time of day, related tasks). We keep your last 100 emotional check-ins locally on your device
  • Focus Session History - Records of which tasks you worked on, session duration, and start/end timestamps

1.3 Device Information

  • Device Name - The human-readable name of your device from your device settings (e.g., "John's iPhone")
  • Platform - Whether you're using iOS, Android, or web
  • Push Notification Token - A unique token from Expo's notification service used to send you reminders and notifications
  • Operating System - Your device's operating system type for compatibility purposes

We do NOT collect: Your device's IP address, precise GPS location, or unique device identifiers beyond what's necessary for app functionality.

1.4 Usage & Subscription Data

  • Subscription Status - Whether you're on a trial, active subscription, or free tier
  • Trial Period Dates - Start and end dates of your trial period
  • AI Usage Statistics - Daily count of AI requests, tokens used for processing brain dumps (used for rate limiting and cost management)
  • Notification Preferences - Your preferred times for planning reminders and morning greetings
  • AI Conversation History - Your brain dump inputs and the AI-generated task extraction results, along with metadata about the AI model used and token counts

1.5 App Preferences

  • Theme preferences (light/dark/system)
  • Planning reminder preferences (morning/evening/Sunday/surprise)
  • Preferred planning hour
  • Timestamps of last sent notifications

2. How We Use Your Information

We use the collected information to:

  • Provide Core Functionality - Enable task management, brain dump processing, focus sessions, and emotional tracking
  • AI-Powered Features - Process your brain dumps through Google Gemini AI to extract actionable tasks and suggestions
  • Voice-to-Text - Convert your voice recordings to text using Deepgram's transcription service
  • Send Notifications - Deliver morning greetings, planning reminders, and focus session alerts based on your preferences
  • Sync Across Sessions - Maintain your tasks and preferences across app sessions using your device ID
  • Manage Subscriptions - Track trial periods and subscription status
  • Improve the App - Analyze aggregated, anonymized usage patterns to improve features and performance
  • Provide Support - Respond to your inquiries and troubleshoot issues

We do NOT: Sell your personal information to third parties, use your data for advertising purposes, or share your content with anyone except the third-party services necessary for app functionality (detailed below).

3. Third-Party Services

To provide our services, we share certain data with trusted third-party providers. Each has their own privacy policy governing how they handle your data:

Supabase (Database & Authentication)

Data Shared: All user data, tasks, brain dumps, AI conversations, preferences
Purpose: Backend database and anonymous authentication
Privacy Policy: https://supabase.com/privacy

Google Gemini AI

Data Shared: Brain dump text content, user context
Purpose: AI-powered task extraction from brain dumps
Privacy Policy: https://ai.google.dev/gemini-api/terms

Deepgram (Speech-to-Text)

Data Shared: Voice recordings (audio files)
Purpose: Convert voice brain dumps to text
Note: Audio is processed but not permanently stored by us or Deepgram
Privacy Policy: https://deepgram.com/privacy

Expo (Push Notifications)

Data Shared: Push notification tokens, device platform, device name
Purpose: Deliver reminders and notifications
Privacy Policy: https://expo.dev/privacy

RevenueCat (Subscription Management)

Data Shared: Anonymous user ID, subscription status, purchase events
Purpose: Manage in-app subscriptions and purchases
Privacy Policy: https://www.revenuecat.com/privacy

PostHog (Planned Analytics - Not Yet Active)

Status: The PostHog analytics library is installed but not currently active or collecting data
Future Use: We plan to use PostHog for privacy-friendly analytics to understand how users interact with the app
If Enabled: We will update this policy and may request your consent before activation
Privacy Policy: https://posthog.com/privacy

We may disclose your information if required by law, such as to comply with a subpoena or similar legal process, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

4. Data Storage & Retention

Where Your Data is Stored

  • Cloud Database (Supabase): Tasks, brain dumps, AI conversations, usage statistics, user preferences, subscription data
  • Local Device Storage: Tasks cache (for offline access), focus history, emotion tracking (last 100 entries), theme preferences, device ID
  • Third-Party Servers: Temporary processing by Google Gemini (AI) and Deepgram (voice transcription)

How Long We Keep Your Data

  • Tasks & Content: Stored until you delete them or delete your account
  • Brain Dump Conversations: Stored in our database for your reference until you delete your account
  • Emotion Tracking: Last 100 entries kept locally on your device
  • AI Usage Statistics: Retained for billing and rate limiting purposes
  • Account Data: Retained until you request account deletion

When you delete your account, all associated data is permanently removed from our servers within 30 days, except where we're required by law to retain certain information for longer periods.

5. Data Security

We take the security of your information seriously and implement industry-standard measures to protect it:

  • Encryption: All data transmitted between your device and our servers is encrypted using HTTPS/TLS
  • Access Controls: Access to user data is restricted to authorized personnel only
  • Secure Infrastructure: We use Supabase's secure cloud infrastructure with built-in security features
  • Anonymous Authentication: By not collecting email/password, we reduce the risk of credential-based attacks

However, no method of electronic storage or transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Your Rights & Choices

You have the following rights regarding your personal data:

Access & Export

You can access all your data within the app. To request a complete export of your data, contact us at [email protected].

Deletion

You can delete individual tasks, brain dumps, or focus sessions within the app. To delete your entire account and all associated data, contact us at [email protected]. We will process your request within 30 days.

Opt-Out

  • Notifications: You can disable push notifications in your device settings or within the app
  • Voice Features: You can choose not to use voice brain dumps; the app works fully with text input
  • Emotional Check-ins: These are optional and can be dismissed
  • Complete Opt-Out: Uninstall the app to stop all data collection

GDPR Rights (EU Users)

If you're in the European Economic Area, you have additional rights under GDPR:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

CCPA Rights (California Users)

If you're a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt-out of the sale of personal information (we don't sell your data)
  • Right to deletion
  • Right to non-discrimination for exercising your rights

7. Children's Privacy

Brain Dump is not intended for use by children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children under these ages.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected], and we will take immediate steps to delete such information from our servers.

8. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.

Our primary infrastructure is provided by Supabase, which uses cloud providers with global data centers. When we transfer your data internationally, we ensure appropriate safeguards are in place to protect your information in accordance with this privacy policy and applicable laws.

9. Permissions

The app requests the following permissions:

Android Permissions

  • RECORD_AUDIO: Required for voice brain dumps feature
  • POST_NOTIFICATIONS: Required to send you reminders and focus session alerts
  • WAKE_LOCK: Keeps screen on during active focus sessions
  • FOREGROUND_SERVICE: Allows background processing for ongoing focus sessions
  • FOREGROUND_SERVICE_MICROPHONE: Allows voice recording during focus sessions

iOS Permissions

  • Microphone Access: Required for voice brain dumps feature
  • Notifications: Required to send you reminders and focus session alerts

All permissions are requested at the time they're needed, and you can manage them in your device settings at any time.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make significant changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you through the app or via email (if we have your contact information)
  • In some cases, request your consent to the new terms

We encourage you to review this Privacy Policy periodically. Your continued use of the app after changes are posted constitutes your acceptance of the updated policy.

11. Your Consent

By downloading, installing, and using Brain Dump, you consent to the collection, use, and processing of your information as described in this Privacy Policy.

If you do not agree with any part of this Privacy Policy, please do not use the app.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please contact us:

Steady Labs

Email: [email protected]

We aim to respond to all inquiries within 48 hours.

Important Notice: Brain Dump is a self-help productivity tool designed to help manage tasks and thoughts. It is not a medical device and does not provide medical advice, diagnosis, or treatment. If you are experiencing mental health concerns, please consult with a qualified healthcare professional.