Brain Buffer — Privacy Policy
Last updated: May 2026
Brain Buffer ("we", "app") is a context-aware reminder service. This policy explains what data we collect, why, and how it is protected.
1. Data We Collect
- Location (precise + background): GPS coordinates and WiFi network BSSIDs are sent to our server to match geofence and place-based reminders. Background location is used only when the app's background service is running.
- Physical activity: Walking, running, vehicle, and still activity states are detected on-device and sent to the server to trigger activity-based reminders.
- Device identifier: A randomly generated UUID is created at install time and used to identify your device. It is not linked to your name or email unless you choose to link a Telegram account.
- WiFi networks: SSID names and BSSID MAC addresses of nearby networks are used as a location fingerprint for place-based triggers.
- Bluetooth devices: Connected Bluetooth device names are detected locally to trigger Bluetooth-based reminders. Device names are not stored on our servers.
- NFC tags: NFC tag IDs may be sent to the server to identify which reminder to fire.
- Reminder text: The text of reminders you create is stored on our servers to enable notifications.
- Voice / microphone: If you use voice input, audio is processed by Android's on-device speech recognition. We do not record, store, or transmit audio.
- Google Calendar events: If you enable Calendar sync, event titles and times are sent to our server to create reminders. We do not store your Google credentials.
- Telegram user ID: If you link a Telegram account, your Telegram user ID and username are stored to enable bot notifications.
2. How We Use Your Data
All data is used solely to deliver context-aware reminders. We do not sell, rent, or share your data with third parties for advertising or analytics. Location and activity data are processed on our servers only to match reminder triggers and are not retained beyond the reminder's lifetime.
3. Data Storage and Security
Your API token is stored in Android's encrypted Keystore on your device. Server data is stored in a PostgreSQL database hosted on Supabase with TLS encryption. All communication between the app and server uses HTTPS.
4. Data Retention
Reminders are deleted when you deactivate them. Notification history is stored for 30 days. You can delete your account and all associated data by contacting us.
5. Permissions Explained
- Location (foreground + background): Required for geofence and place-based reminders.
- Activity Recognition: Required for activity-based triggers (walking, running, etc.).
- Microphone (RECORD_AUDIO): Required for voice input when creating reminders. Audio is processed on-device only.
- NFC: Required to scan NFC tags as reminder triggers.
- Bluetooth: Required to detect Bluetooth device connections as triggers.
- Body Sensors (BODY_SENSORS): Required for step-count reminders via pedometer.
- Exact Alarm / Full-Screen Intent: Required to fire alarm-mode reminders at precise times with full-screen notification (e.g., "wake me up at 7am").
- POST_NOTIFICATIONS: Required to display reminder notifications.
6. Children's Privacy
Brain Buffer is not directed at children under 13. We do not knowingly collect data from children.
7. Changes to This Policy
We may update this policy. Continued use of the app after changes constitutes acceptance of the updated policy.
8. Contact
Questions? Email: [email protected]