Privacy
last updated 27 july 2026
Brew holds a record of someone's life, so this page is specific. It says what is stored, where it lives, who else can see it, and how to get it all back or destroy it. It describes what the software actually does. If you find a difference between this page and the product, that is a bug, and the address at the end is where to report it.
Who is responsible
Brew is operated by Prathik Jain, an individual based in India, who is the data fiduciary for the personal data described here. Questions, requests and grievances: [email protected].
What Brew stores
What you write
Every capture is recorded twice: as an event in an append-only log, and as a memory projected from it. Nothing in that log is ever rewritten. A correction is stored beside the original wording rather than replacing it, so both are kept and can be told apart.
What Brew derives from it
People, places and topics found in your captures; observations about patterns across them; the answers Brew gives you; and task lists read out of what you wrote. All of it is generated by a language model, and every row carries the model name, the prompt version and the time it was produced. Each can be corrected or deleted on its own.
A numeric index of every memory
Each memory is turned into a vector - a list of numbers standing for its meaning - so it can be found by what it is about rather than by the words in it. Producing that vector is the one thing that sends every memory off the server. See Who else sees it below.
Your account
The name, email address and profile picture Google provides when you sign in; the token that sign-in issues; and one session record per signed-in browser or device.
Brew has no password to store. It does not collect your location, contacts, photos, calendar, health data, advertising identifier or device identifiers, and it reads nothing on your device beyond what you type into it.
What Brew does not do
- No analytics. Brew runs no analytics service and receives no usage data about you from any surface: no product telemetry, no session recording, no crash reporting, no advertising or marketing tags. The web app loads no third-party script at all. The phone app links Google's sign-in libraries, which is how the sign-in button works, and starts nothing that reports.
- No advertising, and no profile of you built for one.
- Nothing is sold or rented. Your memories are never shared for anyone else's purposes.
- No training. Brew does not train any model on your memories.
Who else sees it
The most important paragraph on this page: the text of every memory you write is sent to OpenAI once, in order to be indexed.
OpenAI
Brew uses OpenAI for two jobs.
- Indexing. The text of every memory is sent to OpenAI's embeddings API to produce the vector described above. This is how retrieval by meaning works, and it means every memory leaves the server once.
- Answering. When something you write asks Brew a question, a small ranked set of relevant memories is sent along with the question. Your whole history is never sent - only what was retrieved for that one question.
OpenAI acts as a service provider here. Their API terms state that data submitted through the API is not used to train their models. Brew has no separate arrangement with them beyond those terms, and asks them for nothing about you.
Sign-in only. Google learns that you signed in to Brew. Nothing you write is ever sent to Google.
The two providers that hold the machine
Neon stores the database and Railway runs the application, both in Singapore. They hold the data on Brew's behalf and are not permitted to use it for anything else.
That is the whole list. Nobody else receives your data, except where a law compels it - and if that ever happens you will be told, unless telling you is itself unlawful.
Where it is
The database and the application are in Singapore. OpenAI processes the text described above in the United States. If you are in India, this means your data is processed outside India.
Cookies
One cookie, and it is the session that keeps you signed in
(better-auth.session_token). It is not used to track you,
it is not shared, and there are no third-party cookies. In the phone
app the same session is held in memory instead and is gone when the
app closes.
How long it is kept
Your memories are kept until you delete them. There is no expiry and no automatic clear-out: an archive that quietly forgot things would not be one.
Deleting removes the data from the live database immediately. The database provider also keeps point-in-time backups for a limited disaster-recovery window, on the order of days, and deleted data disappears from those as the window rolls forward. Backups are only ever used to restore the service after a failure.
Your rights
Under India's Digital Personal Data Protection Act, 2023 you can ask for access to your data, its correction, and its erasure, and you can raise a grievance. In Brew the first three are buttons rather than requests.
- Take everything. "Export everything" in the footer returns a single JSON file containing every row Brew holds about you, including the generated ones and the evidence behind them.
- Correct anything. Memories, tasks and interpretations can each be corrected where they stand. The original is kept beside your wording, never overwritten.
- Delete everything. "Delete account" ends the account and destroys everything derived from it. See Deleting your data.
- Raise a grievance at [email protected]. You may also complain to the Data Protection Board of India.
- Nominate someone. The Act lets you name a person to exercise these rights if you die or become incapacitated. Email the address above and it will be recorded.
Requests to that address are answered within thirty days, and usually the same week. You will not be asked why.
Children
Brew is not for anyone under 18, and accounts are not knowingly created for them. If you believe a child has an account, email the address above and it will be deleted.
Security
Traffic is encrypted in transit. The database is reachable only by the application. Sign-in is Google's, so Brew never handles a password. Access is invite-only while Brew is early: only addresses on its list can sign in at all. None of this makes a breach impossible - if one happens that affects your data, you will be told, and so will the Data Protection Board.
When this page changes
The date at the top says when it last changed. Where a change materially affects how your memories are handled, it will be stated in the app rather than left here to be discovered.
Contact
Prathik Jain - [email protected]