Privacy Policy — all112
Last updated: September 29, 2026 · Effective: September 29, 2026
Bravely Studios LLC (“we,” “our,” or “us”) operates the all112 application (the “App”). This Privacy Policy explains how we handle information when you use our App.
Introduction
all112 is a time ledger: its whole purpose is to store how you choose to describe your week. That is personal by nature, so this policy is specific about what the App keeps, and everything it keeps exists to show YOU your own reports. We do not sell your information and we do not use your ledger for advertising.
Information We Collect
Account Information
When you sign in with your Bravely Account we receive your email address and account identifier. If you sign in with Google or Apple, the identity provider shares your email address with us.
Your Ledger
The App stores what you put in it: the categories you name, time entries (start and end times, the category, and any note you attach), and your weekly budgets. Entries you delete are removed from your views immediately and purged on a rolling basis; copies made before then stay in our backups until those backups expire, as described under "Backups" below.
Your Hour Audit
The Hour Audit stores your answers — your typical sleep schedule, work hours, household upkeep, and time with the people in your life — plus the numbers derived from them, and your timezone. These answers describe how you spend your time. They are used only to build your categories, budgets, and reports.
Subscription Information
If you subscribe, we store your subscription status and the transaction identifiers the billing platform gives us so we can verify your access. We never see or store payment card details.
Product Analytics
The web app records product events (for example, that a timer was started, without which category it was) tied to a pseudonymous identifier, so we can see which features work. You can turn this off in Settings at any time.
Error and Diagnostic Reports
The apps can send automatic error reports, and a diagnostic report when you tap Send Diagnostic Report or when something goes wrong. What each contains and how long we keep it are described under "Error Reports and Diagnostic Reports" below.
API Tokens & Webhooks
all112 has a public API. If you create a personal access token, we store only a cryptographic hash of it — we cannot show it to you again. If you configure a webhook, the App will deliver your ledger events (timers, entries, weekly reports) to the endpoint URL you chose. You control those endpoints; anything delivered to them is governed by whoever operates them, so only point webhooks at services you trust.
How We Use Your Information
Your information is used solely for:
• Showing you your own ledger, budgets, and reports
• Authenticating you and keeping your account secure
• Verifying your subscription across platforms
• Understanding, in aggregate, which features are used
• Fixing problems you report to us
We do not use your ledger, your audit answers, or anything else you store in all112 for advertising, profiling, or marketing.
Data Storage & Security
Your data is stored in our managed application database with servers located in the United States. All data is encrypted in transit via HTTPS/TLS and encrypted at rest. Passwords are handled by our central authentication system and are never visible to us in plain text.
Data Sharing
We do not sell, rent, or share your personal information. Your data leaves our systems only in these circumstances:
• Webhooks you configure — delivered to endpoints you chose, under your control.
• Service providers — trusted vendors that process data on our behalf for hosting, authentication, analytics, and payment processing, listed below under Sub-processors.
• When required by law.
Data Retention & Deletion
Your data is retained for as long as your account is active. You can ask us to delete your account and your all112 data by contacting us at support@bravely.dev. Upon receiving a deletion request, we will delete your all112 data within 30 days, and your Bravely Account is deleted as described in the Bravely Account privacy policy, which also lists the records we keep after a deletion. Copies made before then stay in our backups until those backups expire, as described under "Backups" below.
Children's Privacy
The App is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
Error Reports and Diagnostic Reports
all112 can send us two kinds of technical report, which you control from Help & Diagnostics in its Settings. Automatic error reports do not carry your Bravely Account identifier or your email address. Diagnostic reports carry your Bravely Account identifier. We use both only to find and fix problems, and we do not sell them or use them for advertising.
Automatic error reports
When the app records an error or a warning, it can send us a short report about it. It collects these on your device and sends them in small batches, about once a minute while problems are happening. A report names the app, the platform, the app version and your operating system version. For each problem it gives:
• its category and type, and a short description of it with details removed
• how many times it happened, and when it was first and last seen
• whether you were signed in, whether you had an active plan, and whether the device was online
Some apps also add how long the app had been running, the names of up to three functions in the app's code where the problem happened, and up to ten of the app's own log entries from just before it, with details removed.
Before a report leaves your device, the app removes details such as email addresses, account identifiers and file paths from its text. Our server removes those details again before the report is stored, and also removes network addresses, long strings of hexadecimal characters and sign-in tokens in the common JWT format. Error reports do not contain your Bravely Account identifier or your email address, and our server does not record your IP address with them. Our apps are built to keep the contents of your time entries out of error reports. Instead of a device identifier, each report carries a code that the app works out from a random identifier it keeps for its installation and from the date, so the code changes every day. We use the code to count how many devices ran into a problem on a given day and to limit how many reports one device can send.
When you first use the app, it asks our server which country your connection comes from, and the server answers without storing the answer. If the country is in the European Economic Area or the United Kingdom, automatic error reports are off until you turn them on. Everywhere else, they are on until you turn them off. Our web and Android apps keep reports off until the answer arrives, and if no answer comes, they go by the region in your browser's or device's language settings. Our other apps keep reports on until the answer arrives, and some of them leave reports on if no answer comes. You can turn automatic error reports on or off at any time under Help & Diagnostics.
We delete each report after 30 days, and the hourly counts we make from reports after 7 days. We keep a summary of each kind of problem with no set end date: its category, type and description with details removed, the app versions it happened in, how many times it happened, on how many devices it happened each day, when it was first and last seen, and a recent example of the log entries that led up to it.
Diagnostic reports
A diagnostic report is a fuller report about one problem. The app sends one when you press Send Diagnostic Report. Unless you turn automatic diagnostic reports off under Help & Diagnostics, it also sends one when something fails in a way you might not notice, such as a sync that keeps failing or a remote session that ends unexpectedly, and at most once an hour for the same kind of problem. Versions of all112 that send our newer diagnostic reports, described below, can also send one, except on the web, when the app stops responding for 5 seconds or more, or the next time you open it after it closed unexpectedly. Automatic diagnostic reports are on by default wherever you are. Diagnostic reports are sent only while you are signed in.
A diagnostic report contains the app version, your operating system version, a few counts and settings from the app (for example, how many documents are open, or whether sync is on) and, where the app keeps them, its own recent log entries. In versions of all112 that send the newer reports, a report can also contain:
• A record of your recent activity in the app: the names its code gives to its screens and to events such as signing in, changing a setting, the network going offline or a key press the app ignored, with details limited to numbers, yes-or-no values and fixed words that the app's code defines, such as a count or which part of the app something started from. Any other word is left out, so the record is built to leave out names, what you typed, which keys you pressed, file names, addresses, identifiers and the contents of your time entries. The app keeps this record, up to its latest 200 entries, only in its memory while it runs, and it leaves your device only inside a diagnostic report.
• The state of the app when the report was made. For example: the screen, dialog and tool you were using, what kind of control your typing would go to, what kind of item was selected and how many, and which kinds of window were open. It also shows the state of the network, whether you have an active plan or trial, how long the app had been running and, in apps that sync, the state of sync. In some apps, it shows whether the app has the system permissions it uses. In apps with system-wide keyboard shortcuts, it can show up to eight of them, with the keys each is set to and whether it is working, and how long ago the app last noticed any key being pressed. Like the record, it holds only numbers, yes-or-no values and fixed words, never titles, names or text.
• Your display and time zone: the size in pixels and the scale of the display the app is on, and the difference between your time zone and UTC; on a computer, how many displays you have; on Windows and Linux, the version of the software framework the app runs on; and on Linux, which desktop you use and whether it runs on X11 or Wayland.
• Up to 50 recent warnings and errors, each with a description with details removed and, where it has one, a short code, and how many warnings and errors the app had recorded.
• How the app's previous session ended (normally, in a crash, or unexpectedly, for example because it was forced to quit), with its version, how long it ran and the main steps it recorded, such as starting up. To know this, the app keeps a list of those steps in a file on your device, which it starts again each time it opens.
If you have turned off usage analytics in the app, its newer reports leave out the record of your activity and the previous session's list of steps. In their place they carry a note that the record was left out and a few counts: how many entries the app recorded, combined or dropped to stay within its limit, how many event names or details its filter refused or replaced, and how many times the signed-in account changed. The rest of the report, including the state of the app and the previous session's last step, is still sent, because it describes the problem rather than how you use the app. When a different account signs in, the app first discards everything it recorded for the newer reports until the previous account signed out (or, with no sign-out, until the switch), keeping only a count of how many times the account has changed since the app started. What it recorded while no one was signed in, such as the steps of signing in, can appear in the new account's reports.
The app removes details such as email addresses, file paths, and keys or tokens from log entries before they go into a report, and our apps are built to keep the contents of your time entries out of a report. In the newer reports, the app also removes text in common quotation marks, network (IP) addresses, the names of document and media files it recognizes by their endings, and your user and computer names, though some details, such as a name it does not recognize, can still appear. Some apps have a switch that records more detail in their own log for 24 hours and then turns itself off. That log stays on your device, apart from the entries that go into a report.
With each diagnostic report we record your Bravely Account identifier, the user agent of the app or browser that sent it, the country your connection came from and when it arrived. When you send a report yourself, the app shows you a short code, such as DIAG-7K2QM, to give to support so we can find it.
A report's log file, which holds its log entries and, in the newer reports, the record of your activity, the recent warnings and errors and any steps from the previous session, is deleted automatically after 90 days. We keep the rest of the report with no set end date, so we can see patterns across reports: its short code if it has one, your account identifier, the app and its versions, why it was sent, the counts and settings, the user agent and country, when it arrived, and, in the newer reports, the state of the app, your display and time zone details, how many warnings and errors the app had recorded and, if it had recorded any, a short label for the most recent error (or, if there was none, the most recent warning), and, where the app records it, how the previous session ended and its last step. Deleting your Bravely Account deletes your diagnostic reports from our live systems. Our data warehouse keeps its copy of what we keep from each report, without the user agent and country, under your account identifier, as the Bravely Account privacy policy describes. To have a report deleted sooner, email privacy@bravely.dev.
Where reports are kept
Both kinds of report are stored in database and file storage that Cloudflare runs for us, and copied into a data warehouse that we run ourselves. Diagnostic reports, apart from their log files, are also copied each night into our encrypted backups, described under "Backups" below. When our team looks into a problem, they can attach a diagnostic report to an issue in our own issue tracker, whose data Google stores for us. The issue keeps the report's short code (or its number), the app and platform, the app and operating system versions, whether the report was sent by hand or automatically, when it arrived and, for a newer report, a one-line summary of what it shows, such as the screen in use and the most recent problem. It stores the sender only as "customer account", not their account identifier or email address (for a member of our team, it stores their name or email address and their account identifier), and it keeps all of this after the report itself is deleted. While the report and the sender's account exist, our team can see the sender's email address when they view the issue.
Backups
We keep backups so that we can recover our customers' data if it is ever lost. Each night we copy the databases that hold accounts, purchases and the content our apps and services keep for their users, including sign-in records and the protected form of passwords, and we copy the files stored with us, such as documents, screenshots and attachments. Unless a section above says otherwise, the account, purchase and content records this policy describes, and the files you store with us, are in these backups.
Where backups are kept
Backups are kept in two places, both in the United States: on storage equipment that we own, and in Amazon S3, a storage service run by Amazon Web Services. Every copy of a database or of sign-in records is encrypted, with a key that only we hold, before it is stored in either place. The copies of stored files that we keep in Amazon S3 are also encrypted with a key that only we hold, file names included; the copy of those files on our own equipment is not separately encrypted. Amazon does not have our keys, so it cannot read your data in the backups.
How long backups are kept
Each night's copy of our databases and sign-in records is deleted after 90 days and fully purged within 30 days after that, so it is kept for about four months at most. One copy each month is kept for up to 12 months instead, and fully purged within 30 days after that, so it is kept for about 13 months at most. The backup of stored files keeps each file for as long as it is stored with us; when a file is deleted or replaced, the backup keeps the earlier version for 90 days and then deletes it. Separately, Cloudflare, which runs most of our databases, keeps a recovery history of each of them for 30 days.
How backups are used
We use backups and that recovery history only to restore data after it has been lost, for example in an outage, through a mistake or in an attack, and we also use backups to test that restoring works. Deleting something, or deleting your account, does not remove it from backups made before the deletion or from the recovery history: those copies stay until they are deleted on the schedules above. If we restore data from a backup or from the recovery history, we re-apply the deletions made after the point we restore to, including account deletions, so that the restore does not bring back data that had been deleted.
Your Privacy Rights
Depending on where you live, you have rights over the personal data we hold about you. We honor these rights for everyone who asks, regardless of where you live.
• Access — ask what personal data we hold about you and get a copy.
• Correction — ask us to fix data that is wrong or incomplete.
• Deletion — ask us to delete your personal data by emailing privacy@bravely.dev from the address on your account. Where a product has a built-in Delete Account control you can use that instead; bravely.dev/delete-account explains what applies to each product.
• Portability — ask for your data in a portable, machine-readable format.
• Objection and restriction — ask us to stop or limit certain processing.
• Withdraw consent — where we rely on consent (for example, marketing email), you can withdraw it at any time without affecting processing that already happened.
• Non-discrimination — we will not degrade your service or charge you more for exercising any of these rights.
EEA and UK residents also have the right to lodge a complaint with your local supervisory authority. California residents may use an authorized agent; we may verify the agent's authority and confirm the request with you first. Other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect) have equivalent rights, including a right to appeal a denied request — reply to our decision email with "Appeal" and we will respond in writing within the period the law requires. Canadian residents have access, correction, and consent-withdrawal rights under PIPEDA; Australian residents have access and correction rights under the Australian Privacy Principles.
To exercise any right, email privacy@bravely.dev. We respond within the timeframe the applicable law requires — generally 30 days under GDPR and 45 days under the CCPA, with an extension where the law permits one. We may need to verify your identity before acting, usually by confirming control of the email address on the account.
Legal Basis for Processing
If you are in the EEA or UK, we rely on these lawful bases under the GDPR and UK GDPR:
• Performance of a contract — creating and securing your account, delivering the features you paid for, syncing your content, processing purchases, and providing support.
• Legitimate interests — keeping the service secure and reliable, preventing fraud and abuse, understanding how our products are used through usage events tied to an installation or to your account, and improving the product. We balance these against your rights and do not use them to justify intrusive tracking. Where an app lets you turn its usage analytics off, doing so is one way to object.
• Consent — marketing email, and anything else we ask your permission for before we collect it. You can withdraw consent at any time.
• Legal obligation — keeping tax, accounting, and consent records, and responding to lawful requests.
International Data Transfers
Bravely Studios LLC is a US company. We and our sub-processors process data in the United States and in other countries where they operate. For personal data originating in the EEA, UK, or Switzerland, we rely on appropriate transfer safeguards in our processor agreements — such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — where those safeguards are required. Email privacy@bravely.dev if you want more detail about the safeguards that apply to you.
California Notice at Collection
For California residents, the categories of personal information we collect for this product are:
• Identifiers — your Bravely Account identifier, email address, and device or installation identifiers.
• Commercial information — records of purchases, subscriptions, entitlements, trials, and refunds.
• Internet or other electronic network activity — usage events, which carry an installation or browser identifier, your Bravely Account identifier, an identifier for a single request or purchase, or only a shared identifier for the app and platform; app version and platform; crash and error reports.
• Coarse geolocation — a country-level signal derived from your network connection, used for consent rules and tax.
• Your content — only the content the product is built to store or sync for you, described in the sections above.
We collect this from you, your device, and our own systems, and we use it to run the product, honor what you have bought, keep the service secure, and support you. We disclose it to the service providers listed under "Sub-processors," each for a business purpose under a written contract.
We do not sell your personal information and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA and CPRA, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for any purpose that would trigger the right to limit. If that ever changes we will update this policy and provide the required opt-out before the practice begins.
Retention is described under "Data Retention" and "Backups" above and, for account-level data, in the Bravely Account privacy policy.
Sub-processors
We use the following service providers to run this product. They receive only what they need to perform their service for us, and each is bound by the data-processing terms that apply to our use of their service. Where a provider is not yet covered by a written data-processing agreement with us, its entry below says so. If you need a data-processing agreement in place before you use this product, email privacy@bravely.dev:
• Cloudflare, Inc.: hosting, the Workers runtime, D1 databases, R2 object storage, and bot protection for bravely.dev and our app subdomains. See cloudflare.com/privacypolicy.
• Google LLC: Firebase Authentication, which backs Bravely Account sign-in (including Sign in with Google). See policies.google.com/privacy.
• Apple Inc.: Sign in with Apple, and App Store purchase and receipt handling for our Apple platform apps. See apple.com/legal/privacy.
• Paddle.com Market Ltd: our merchant of record for purchases made on the web or in our desktop apps. Paddle handles checkout, payment processing, invoicing, and sales tax/VAT. When you open a checkout while signed in, we give it your email address; otherwise you enter it on Paddle's checkout page. Each purchase carries the app it is for, any campaign tags on the link that brought you to checkout, and either your Bravely Account identifier or, for a purchase made before you had signed in, a temporary identifier that we link to your account when you claim the purchase. As the seller of record, Paddle keeps its own records of your purchases. See paddle.com/legal/privacy.
• RevenueCat, Inc.: keeps the purchase record for each Bravely Account. It validates App Store and Google Play purchases and reports subscription changes, and we also record trials and web and desktop purchases with it, so we can unlock what you bought on every platform. We identify you to it by your Bravely Account identifier. The first time you sign in with Apple or Google, and on some other sign-ins, we also send it your email address, your name (when the sign-in provides one), your country and the app you signed in from. Some apps also record with it the name of the device you use, and a few older parts of our service identify you to it by your email address instead. See revenuecat.com/privacy.
• PostHog Inc.: product analytics. Our apps, some of our websites and our account service send it usage events, such as which features are used and the steps of signing in, starting a trial and buying, and our websites and web apps also send it recordings of how their pages are used. An event carries an identifier for the installation or browser it came from, your Bravely Account identifier, or both (most apps add your account identifier once you have signed in); a few events, such as a failed sign-in or a purchase made before you had signed in, carry an identifier for that one request or purchase instead, and some copies of app events that reach it through our account service carry only a shared identifier for the app and platform. PostHog receives the network address each event was sent from. A few apps also send it your email address, and a few older parts of our service identify you to it by your email address instead. The Bravely Account policy describes this under "Usage and Purchase Analytics". See posthog.com/privacy.
• Resend Inc.: sends our transactional email (sign-in codes, receipts, password resets, support replies). See resend.com/legal/privacy-policy.
• Amazon Web Services, Inc.: Amazon S3, which stores our backups in the United States, as described under "Backups". The copies of your data that we keep there are encrypted, with a key that only we hold, before they leave our systems, so Amazon cannot read them. See aws.amazon.com/privacy.
If we add or change a sub-processor in a way that materially changes how your data is processed, we will update this policy and give additional notice where the law or our data-processing commitments require it.
Security
We protect your data with authenticated accounts, encryption in transit, access controls on our backend systems, and a deliberately small number of people who can reach production. No system is perfectly secure, and we do not claim guarantees we have not built and verified. Where a product makes a specific security claim, that claim appears in the app-specific sections above and is limited to what we have actually shipped. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators as required by law.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make a material change — a new category of data, a new sub-processor, a new purpose, or a new legal basis — we will update the "Last updated" and "Effective" dates and give additional notice where the law requires it. Where a change requires fresh consent under the GDPR, UK GDPR, CASL, or a similar regime, we will ask for it before relying on the new purpose. Non-material changes (typos, clarifications, link fixes) are reflected by updating the "Last updated" date.
How to Contact Us
Bravely Studios LLC
Privacy and data rights: privacy@bravely.dev
Product support: support@bravely.dev
Website: https://bravely.dev
Postal address: available on request to privacy@bravely.dev.