Privacy Policy for Bracie
Last Updated: 08/11/2025
This Privacy Policy explains how Bracie Ltd (“we”, “us”) handles information in the Bracie mobile application (the “App”).
Who we are & how to contact us
Controller: Bracie Ltd, United Kingdom. Email: info@bracie.app. If you’re unhappy with our response, you can complain to the UK Information Commissioner’s Office (ICO).
What we do (summary)
- Your treatment notes, visits, photos, and reminders live on your device. iCloud sync is optional and controlled by your iOS settings.
- We do not use cross-app advertising or tracking.
- Analytics & personalization are off by default and only enabled if you opt in. If the treatment recipient is under 13, analytics are disabled.
Data we handle
A. On-device content you add (local by default)
Visits & care instructions, brushing entries, photos, audio notes, and next appointments are stored in the app’s local database on your device. If you disable iCloud for Bracie, your data stays on that device.
B. Optional sync via iCloud / CloudKit
If iCloud is enabled, Apple syncs your app data across your devices under your Apple account. Apple’s documentation explains that iCloud data is encrypted in transit and on server by default (“Standard Data Protection”), and some categories may be end-to-end encrypted. Availability of Advanced Data Protection (which expands end-to-end encryption) can vary by region and settings. See Apple’s iCloud data security overview. We don’t control your iCloud configuration.
C. Device permissions you may choose to grant
- Photos / Camera: to add progress photos.
- Microphone: to record notes or appointments.
- Calendar: to create a calendar event you request.
- Notifications: to deliver reminders you turn on.
D. Purchase & subscription information (processor: RevenueCat)
We use RevenueCat to validate App Store purchases and entitlements. This involves processing transaction metadata (e.g., receipts). RevenueCat acts as a processor under its GDPR guidance and Data Processing Addendum.
E. Optional analytics & personalization (processor: PostHog)
If you opt in to Analytics, we send pseudonymous product-interaction events (e.g., onboarding answers, feature usage) to PostHog Cloud EU hosted in Frankfurt. We do not enable cross-app tracking or advertising. See PostHog’s GDPR guidance and Cloud EU details. If you also opt into Personalization, we attach non-sensitive properties (e.g., “is_caregiver”, age bracket, goal) to tailor in-app tips. If the subject is under 13, analytics remain off.
Legal bases (UK GDPR)
- Providing the App (core features, on-device storage, requested calendar entries, notifications you enable): performance of a contract / legitimate interests.
- Analytics & personalization: consent (you can withdraw any time in Settings; we’ll stop sending events).
- Support emails you send us: legitimate interests (to respond).
- Children: analytics suppressed for under-13s.
Do we share data?
- We do not sell your personal data.
- Processors we use:
- Apple iCloud/CloudKit (if you enable iCloud sync) – storage/sync under your Apple account.
- PostHog Cloud EU (analytics, opt-in).
- RevenueCat (purchases/entitlements).
International transfers
PostHog Cloud EU is hosted in Frankfurt and states that EU data does not leave the EU. RevenueCat may process data in the United States and provides contractual safeguards in its DPA. See the links above for details.
Retention
- On-device content: you control it. Delete items in the app or delete the app to remove local data; manage any iCloud data via iOS Settings.
- Analytics (if enabled): we retain analytics data for 12 months, then delete or anonymize it. If you withdraw consent, we stop sending new events; you can also request deletion (see below).
Your rights
You have rights to access, rectification, erasure, restriction, objection, portability, and to withdraw consent. We respond without undue delay and within one month (extensions possible for complex requests). You can complain to the ICO.
How to make a deletion request
- In the App: Settings → Privacy → Delete my data explains options and shows your Bracie (analytics) ID.
- Email info@bracie.app with subject “Delete my data” and include your Bracie ID. We’ll remove associated analytics/person data at our processors and confirm when complete.
- Deleting the app removes local data on that device; manage any iCloud-synced data via iOS Settings → [your name] → iCloud.
Children
Bracie isn’t directed to children under 13. If the subject is under 13, analytics remain disabled and we do not knowingly collect personal data for analytics. Parents or guardians can contact us (include the Bracie ID) to request deletion.
Changes to this policy
We’ll post updates in-app and/or on our website. Please review periodically.
Contact
Bracie Ltd — info@bracie.app