Privacy Policy
Bramble is a private shared calendar, chat, and photo space for you and the people you invite. This policy explains exactly what we collect, why, and what we don't do with it.
What we collect
Account information
- Name and email — provided when you sign in with Google or Apple. Used to identify you to other members of your bramble. Apple sign-in users may choose to hide their email; in that case we receive Apple's relay address instead.
- Profile photo — pulled from your Google account when you sign in. Apple sign-in does not provide a photo; you can also sign in without one.
- Display name — the name you choose to show in chat and on RSVPs (defaults to your Google / Apple name).
Content you create
- Events you add to your bramble's calendar (titles, dates, times, locations, descriptions, attachments).
- Chat messages, photos, and voice notes you send.
- Comments and reactions on events.
- RSVPs to events.
This content is shared with the other members of the bramble you posted it in. It is not shared with anyone outside that bramble unless you forward it to another bramble you belong to.
Technical data
- Notification subscriptions — when you enable browser notifications, the browser-issued endpoint and encryption keys are stored so we can deliver pushes.
- Last seen timestamp — refreshed periodically while you have the app open. Used to show "online" / "5m ago" badges to other members. You can disable this in Settings → Privacy.
- Read receipts — when you view a chat message, a record links your user id to that message id. You can disable this in Settings → Privacy; doing so also hides others' read state from you.
- Crash reports — when the app encounters an error, we send the error message, stack trace, and your build/browser version to our server logs. We do not include the contents of your messages or events.
What we don't do
- We don't sell your data. Ever.
- We don't run ads or third-party trackers.
- We don't share your content with third parties for marketing.
- We don't use your messages or events to train AI models.
- We don't read your content. The app surfaces it to you and your bramble members; access is gated by row-level security policies in the database.
Where your data lives
Bramble's backend is built on Supabase, which hosts the database and file storage. Database access is gated by row-level security policies that limit reads and writes to members of the relevant bramble. Photos and voice notes you upload are stored as files in Supabase storage, accessed via signed URLs that expire.
How long we keep your data
- Active content stays as long as your bramble exists.
- If you leave a bramble, your messages and events stay (with your name visible) so the other members' conversation history isn't shredded — same pattern as iMessage / WhatsApp / Slack.
- If you delete your account (Settings → Manage → Delete account), we hard-delete your profile, memberships, RSVPs, reactions, push subscriptions, and per-user preferences. We anonymize content you posted — your name is replaced with "Deleted user" and the messages/events stay so other members aren't left with holes in their history.
- If you delete a bramble (the last member to leave triggers this), all events, chat, photos, and metadata associated with that bramble are permanently deleted.
Your controls
- Display name, photo, sign-in — managed in Settings → Profile.
- Notifications — granular per-type and per-bramble controls in Settings → Notifications. Quiet hours available.
- Privacy toggles — "Show me as online" and "Read receipts" in Settings → Privacy.
- Download my data — Settings → Storage & Data exports your events, brambles, and prefs as a JSON file you can keep.
- Leave a bramble — Settings → Manage. Owners must transfer ownership before leaving.
- Delete your account — Settings → Manage → Delete account. Irreversible.
Children
Bramble is intended for use by families and isn't directed at children under 13. We don't knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact us and we'll delete it.
Security
Authentication uses Google OAuth. Database access is gated by row-level security. Photos and voice notes are served through expiring signed URLs. Push notification credentials are stored encrypted in the database.
That said, no online service can guarantee perfect security. If you discover a vulnerability, please report it (see contact below) and we'll respond promptly.
Changes to this policy
If we make material changes to this policy, we'll update the "last updated" date below and surface a notice in the app the next time you open it. Continued use of Bramble after a change indicates acceptance of the new terms.
Contact
Questions, requests, or vulnerability reports: bramblecustomerservice@gmail.com.