Brew

Privacy

Brew holds a record of someone's life, so this page is specific. It says what is stored, where it lives, who else can see it, and how to get it all back or destroy it. It describes what the software actually does. If you find a difference between this page and the product, that is a bug, and the address at the end is where to report it.

Who is responsible

Brew is operated by Prathik Jain, an individual based in India, who is the data fiduciary for the personal data described here. Questions, requests and grievances: [email protected].

What Brew stores

What you write

Every capture is recorded twice: as an event in an append-only log, and as a memory projected from it. Nothing in that log is ever rewritten. A correction is stored beside the original wording rather than replacing it, so both are kept and can be told apart.

What Brew derives from it

People, places and topics found in your captures; observations about patterns across them; the answers Brew gives you; and task lists read out of what you wrote. All of it is generated by a language model, and every row carries the model name, the prompt version and the time it was produced. Each can be corrected or deleted on its own.

A numeric index of every memory

Each memory is turned into a vector - a list of numbers standing for its meaning - so it can be found by what it is about rather than by the words in it. Producing that vector is the one thing that sends every memory off the server. See Who else sees it below.

Your account

The name, email address and profile picture Google provides when you sign in; the token that sign-in issues; and one session record per signed-in browser or device.

Brew has no password to store. It does not collect your location, contacts, photos, calendar, health data, advertising identifier or device identifiers, and it reads nothing on your device beyond what you type into it.

What Brew does not do

Who else sees it

OpenAI

Brew uses OpenAI for two jobs.

OpenAI acts as a service provider here. Their API terms state that data submitted through the API is not used to train their models. Brew has no separate arrangement with them beyond those terms, and asks them for nothing about you.

Google

Sign-in only. Google learns that you signed in to Brew. Nothing you write is ever sent to Google.

The two providers that hold the machine

Neon stores the database and Railway runs the application, both in Singapore. They hold the data on Brew's behalf and are not permitted to use it for anything else.

That is the whole list. Nobody else receives your data, except where a law compels it - and if that ever happens you will be told, unless telling you is itself unlawful.

Where it is

The database and the application are in Singapore. OpenAI processes the text described above in the United States. If you are in India, this means your data is processed outside India.

Cookies

One cookie, and it is the session that keeps you signed in (better-auth.session_token). It is not used to track you, it is not shared, and there are no third-party cookies. In the phone app the same session is held in memory instead and is gone when the app closes.

How long it is kept

Your memories are kept until you delete them. There is no expiry and no automatic clear-out: an archive that quietly forgot things would not be one.

Deleting removes the data from the live database immediately. The database provider also keeps point-in-time backups for a limited disaster-recovery window, on the order of days, and deleted data disappears from those as the window rolls forward. Backups are only ever used to restore the service after a failure.

Your rights

Under India's Digital Personal Data Protection Act, 2023 you can ask for access to your data, its correction, and its erasure, and you can raise a grievance. In Brew the first three are buttons rather than requests.

Requests to that address are answered within thirty days, and usually the same week. You will not be asked why.

Children

Brew is not for anyone under 18, and accounts are not knowingly created for them. If you believe a child has an account, email the address above and it will be deleted.

Security

Traffic is encrypted in transit. The database is reachable only by the application. Sign-in is Google's, so Brew never handles a password. Access is invite-only while Brew is early: only addresses on its list can sign in at all. None of this makes a breach impossible - if one happens that affects your data, you will be told, and so will the Data Protection Board.

When this page changes

The date at the top says when it last changed. Where a change materially affects how your memories are handled, it will be stated in the app rather than left here to be discovered.

Contact

Prathik Jain - [email protected]