← bravely.dev

Privacy Policy — Bravely Account

Last updated: July 26, 2026 · Effective: July 26, 2026

Bravely Studios LLC (“we,” “our,” or “us”) operates Bravely Account, the single sign-in and purchase record that works across every Bravely app and service. This policy covers the account itself: how you sign in, what we store about you as an account holder, and how your purchases follow you between apps. Each app also has its own policy at bravely.dev/privacy covering the data that app handles.

What Bravely Account Is

One Bravely Account signs you in everywhere we operate — our desktop, mobile, and web apps, the free tools at bravely.dev/tools, and client portals such as brands.bravely.dev. It holds your identity and the record of what you have bought, so a purchase made on one platform unlocks the app on the others. Sign-in is handled by our central authentication system; individual apps never see your password.

Account Information We Store

• Bravely Account identifier — a server-generated identifier (formatted ba_...) that is the key we use everywhere internally. We use this rather than your email address so your identity is not tied to a mailbox you might change. • Email address — used to identify you, send sign-in codes and receipts, and reach you about your account. • Sign-in method and provider identifiers — whether you use Sign in with Apple, Sign in with Google, or email and password, plus the identifier that provider returns. • Display name — where your sign-in method returns one. • Password — only if you choose email and password. We never store it in readable form; it is salted and hashed by our authentication system. • Email verification state — whether you have confirmed your address. We require verification before a trial, a purchase, or a restore. • Sessions and devices — session records, refresh tokens, approximate sign-in times, app and platform, and coarse device metadata, so you can stay signed in and we can show you and end sessions you do not recognize. • Consent records — whether you accepted our terms at signup, and your marketing choices, with the wording and timestamp of each.

Purchases, Trials, and Entitlements

When you buy a Bravely app or start a trial, we record your Bravely Account identifier, the product and plan, the store or checkout that billed you, transaction and subscription identifiers, entitlement status, start and renewal dates, and refund or cancellation events. We keep a per-account record of trials already used so a trial can be offered once per app. We never receive or store your card number, expiry, or security code — those go directly to the payment provider that billed you.

Sign-In and Security Events

We record authentication events — sign-in started, completed, or failed, along with method, app, platform, and timestamp — to operate the account, show you your sessions, detect credential stuffing and abuse, and debug sign-in problems. These records are tied to your account identifier. We also keep a short-lived record of password-reset and email-verification tokens so they can be used once and then expire.

How We Use Account Data

We use account data only to run your account: • sign you in and keep you signed in across your devices • confirm what you have purchased and unlock it everywhere • verify your email before a trial, purchase, or restore • send transactional email such as sign-in codes, receipts, password resets, and account notices • protect the account against fraud, abuse, and unauthorized access • answer your support requests We do not sell your account data, and we do not use it for advertising or to build a profile of you for anyone else.

Marketing Choices

Marketing email is separate from your account and always optional. We ask for it with a checkbox whose default depends on where you are — pre-ticked only where local law allows, and never pre-ticked in the EEA, UK, or Canada. Declining costs you nothing and changes nothing about your account. Transactional messages about a purchase or account you already have are not marketing and are not affected by unsubscribing. The full marketing-email policy is at bravely.dev/privacy/bravely-newsletter.

Deleting Your Account

You can delete your Bravely Account from within most of our apps (Settings, then Delete Account) or at bravely.dev/delete-account. Deletion runs on a 30-day grace period: you are signed out immediately and can restore the account by signing back in within those 30 days. After that, your account and the personal data attached to it — profile, sessions, sign-in records, and entitlements — are permanently deleted. Subscriptions bought through the App Store or Google Play are managed by that store and must be cancelled there; deleting your Bravely Account does not cancel them. We keep the minimum records the law requires us to keep, such as transaction and tax records, and any suppression record needed to honor a prior unsubscribe.

Data Retention

We keep account records for as long as your account exists, and then through the 30-day grace period described above. Sign-in and security event records are kept for a limited period for abuse investigation and then discarded or de-identified. Purchase, refund, and tax records are kept for as long as tax and accounting law requires, typically seven years, even after account deletion. Consent and suppression records are kept so we can prove your choices and avoid re-adding you to a list by mistake.

Children's Privacy

Bravely Account is intended for adults. We do not knowingly create accounts for anyone under 13, and in the EEA, UK, and other places where 16 is the relevant age for information-society services, we do not knowingly create accounts for anyone under 16. If you believe a child has created an account, email privacy@bravely.dev and we will delete it.

Your Privacy Rights

Depending on where you live, you have rights over the personal data we hold about you. We honor these rights for everyone who asks, regardless of where you live. • Access — ask what personal data we hold about you and get a copy. • Correction — ask us to fix data that is wrong or incomplete. • Deletion — ask us to delete your personal data by emailing privacy@bravely.dev from the address on your account. Where a product has a built-in Delete Account control you can use that instead; bravely.dev/delete-account explains what applies to each product. • Portability — ask for your data in a portable, machine-readable format. • Objection and restriction — ask us to stop or limit certain processing. • Withdraw consent — where we rely on consent (marketing email, optional analytics), you can withdraw it at any time without affecting processing that already happened. • Non-discrimination — we will not degrade your service or charge you more for exercising any of these rights. EEA and UK residents also have the right to lodge a complaint with your local supervisory authority. California residents may use an authorized agent; we may verify the agent's authority and confirm the request with you first. Other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect) have equivalent rights, including a right to appeal a denied request — reply to our decision email with "Appeal" and we will respond in writing within the period the law requires. Canadian residents have access, correction, and consent-withdrawal rights under PIPEDA; Australian residents have access and correction rights under the Australian Privacy Principles. To exercise any right, email privacy@bravely.dev. We respond within the timeframe the applicable law requires — generally 30 days under GDPR and 45 days under the CCPA, with an extension where the law permits one. We may need to verify your identity before acting, usually by confirming control of the email address on the account.

Legal Basis for Processing

If you are in the EEA or UK, we rely on these lawful bases under the GDPR and UK GDPR: • Performance of a contract — creating and securing your account, delivering the features you paid for, syncing your content, processing purchases, and providing support. • Legitimate interests — keeping the service secure and reliable, preventing fraud and abuse, understanding aggregate product usage, and improving the product. We balance these against your rights and do not use them to justify intrusive tracking. • Consent — marketing email, and optional analytics where a client offers a toggle. You can withdraw consent at any time. • Legal obligation — keeping tax, accounting, and consent records, and responding to lawful requests.

International Data Transfers

Bravely Studios LLC is a US company. We and our sub-processors process data in the United States and in other countries where they operate. For personal data originating in the EEA, UK, or Switzerland, we rely on appropriate transfer safeguards in our processor agreements — such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — where those safeguards are required. Email privacy@bravely.dev if you want more detail about the safeguards that apply to you.

California Notice at Collection

For California residents, the categories of personal information we collect for this product are: • Identifiers — your Bravely Account identifier, email address, and device or installation identifiers. • Commercial information — records of purchases, subscriptions, entitlements, trials, and refunds. • Internet or other electronic network activity — aggregate feature-usage events, app version, platform, crash and error reports. • Coarse geolocation — a country-level signal derived from your network connection, used for consent rules and tax. • Your content — only the content the product is built to store or sync for you, described in the sections above. We collect this from you, your device, and our own systems, and we use it to run the product, honor what you have bought, keep the service secure, and support you. We disclose it to the service providers listed under "Sub-processors," each for a business purpose under a written contract. We do not sell your personal information and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA and CPRA, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for any purpose that would trigger the right to limit. If that ever changes we will update this policy and provide the required opt-out before the practice begins. Retention is described under "Data Retention" above and, for account-level data, in the Bravely Account privacy policy.

Sub-processors

We use the following service providers to run this product. They receive only what they need to perform their service for us, and each is bound by the data-processing terms that apply to our use of their service. Where a provider is not yet covered by a written data-processing agreement with us, its entry below says so. If you need a data-processing agreement in place before you use this product, email privacy@bravely.dev: • Cloudflare, Inc. — hosting, the Workers runtime, D1 databases, R2 object storage, and bot protection for bravely.dev and our app subdomains. See cloudflare.com/privacypolicy. • Google LLC — Firebase Authentication, which backs Bravely Account sign-in (including Sign in with Google). See policies.google.com/privacy. • Apple Inc. — Sign in with Apple, and App Store purchase and receipt handling for our Apple platform apps. See apple.com/legal/privacy. • Paddle.com Market Ltd — our merchant of record for purchases made on the web or in our desktop apps. Paddle handles checkout, payment processing, invoicing, and sales tax/VAT. See paddle.com/legal/privacy. • RevenueCat, Inc. — validates App Store and Google Play receipts and reports subscription lifecycle events so we can unlock what you bought. See revenuecat.com/privacy. • PostHog Inc. — product analytics for aggregate feature usage and reliability. See posthog.com/privacy. • Resend Inc. — sends our transactional email (sign-in codes, receipts, password resets, support replies). See resend.com/legal/privacy-policy. If we add or change a sub-processor in a way that materially changes how your data is processed, we will update this policy and give additional notice where the law or our data-processing commitments require it.

Security

We protect your data with authenticated accounts, encryption in transit, access controls on our backend systems, and a deliberately small number of people who can reach production. No system is perfectly secure, and we do not claim guarantees we have not built and verified. Where a product makes a specific security claim, that claim appears in the app-specific sections above and is limited to what we have actually shipped. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators as required by law.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make a material change — a new category of data, a new sub-processor, a new purpose, or a new legal basis — we will update the "Last updated" and "Effective" dates and give additional notice where the law requires it. Where a change requires fresh consent under the GDPR, UK GDPR, CASL, or a similar regime, we will ask for it before relying on the new purpose. Non-material changes (typos, clarifications, link fixes) are reflected by updating the "Last updated" date.

How to Contact Us

Bravely Studios LLC Privacy and data rights: privacy@bravely.dev Product support: support@bravely.dev Website: https://bravely.dev Postal address: available on request to privacy@bravely.dev.