Privacy Policy — Scry
Last updated: September 29, 2026 · Effective: September 29, 2026
Bravely Studios LLC (“we,” “our,” or “us”) operates the Scry application (the “App”). This Privacy Policy explains how we handle information when you use our App.
Introduction
Scry is Bravely Studios LLC’s remote desktop product for your own computers and invited support sessions. This Privacy Policy covers the Scry browser app at scry.bravely.dev, the marketing hub at bravely.dev/scry, and the native host and client apps for macOS, Windows, iPhone, iPad, and Android.
Data We Collect
Here is a summary of the personal data Scry collects, in the categories the App Store uses for its privacy details. None of this data is used to track you across other companies’ apps or websites, and we never sell it.
• Email Address (Contact Info) — your account email address. Used for app functionality; linked to your identity.
• User ID (Identifiers) — your Bravely Account identifier. Used for app functionality; linked to your identity.
• Product Interaction (Usage Data) — feature-usage events. Used for analytics; you can opt out where a client offers the toggle. In versions that send our newer diagnostic reports, those reports also carry a record of your recent activity in the app, used to find and fix problems and linked to your identity.
• Crash Data (Diagnostics) — details of a crash, which Scry can send in the error reports and diagnostic reports described in the next point. Used for app functionality, to keep Scry reliable.
• Other Diagnostic Data (Diagnostics) — automatic error reports, which describe warnings and errors and are not linked to your identity, and diagnostic reports, which Scry sends when you send one yourself or, on its own, when something goes wrong, and which are linked to your identity. Used for app functionality, to find and fix problems.
• Customer Support (User Content) — information you choose to send us when you contact support or send a diagnostic report yourself. Used for app functionality; linked to your identity.
The sections below describe how each of these is handled in more detail.
Account Information
When you sign in to Scry, we store the account details needed to identify you and secure access to your devices. This can include your Bravely Account identifier, email address, sign-in method, and the display name returned by that sign-in method. We do not store your password in plain text; credential handling is delegated to our authentication system and the sign-in method you use.
Download Links by Email
If you ask us to email you Scry’s download links on bravely.dev/scry/download, we use your address to send that one email; it doesn’t sign you up for anything. For this, we don’t store the address itself: we keep a record of the request with a keyed fingerprint of your address and of the network address the request came from, so we can limit repeat requests, look into abuse and honor delivery blocks. We keep that request record until you ask us to delete it; the fingerprint of your address and a record of the email we sent stay after that, so we can keep honoring delivery blocks. If you’ve ever subscribed to our emails with the same address, or you later subscribe or create a Bravely Account with it, these records are linked to that address. Our email delivery provider keeps its own delivery log of the email, including your address and the subject line.
Device, Session, and Relay Data
To make remote access work, Scry stores the devices attached to your account and the metadata needed to establish sessions between them. This includes device names, platform type, online/offline state, ownership and sharing state, session identifiers, timestamps, and connection diagnostics such as connection-allocation details and coarse network errors. When direct peer-to-peer connection is unavailable, some active session traffic may pass through Bravely-managed relay systems so the session can stay connected.
How We Use Your Information
We use Scry data only to operate the product:
• authenticate you and protect access to your devices
• show your device list and current availability
• establish, route, and troubleshoot active remote sessions
• enforce preview and paid-feature access rules
• answer support requests and investigate abuse or fraud
We do not sell your information or use it for advertising.
Analytics and Diagnostics
Scry uses product analytics to understand aggregate product usage, feature adoption, and coarse failure states. Events may include app version, platform, anonymous device identifiers, account-linked identifiers where needed for Pro access troubleshooting, and high-level session lifecycle events. Where a client exposes an analytics toggle, you can opt out there. We do not use Scry analytics to record the contents of your desktop, your files, or the text you type into another app. Error reports and diagnostic reports, including the diagnostic reports Scry sends on its own when a session ends unexpectedly, are described under "Error Reports and Diagnostic Reports" below.
Billing and Entitlements
Scry has a paid Pro tier. We store your Bravely Account identifier, contact email, Pro access status, platform customer identifiers, and transaction identifiers so we can unlock the correct features on your account across supported platforms. Payment card details are handled by the platform that billed you, not by Bravely Studios LLC.
Permissions and Local Access
Native Scry builds may request system permissions such as screen capture, accessibility/input control, microphone access, notifications, or file access when those capabilities are part of the feature you are actively enabling. Granting a permission does not by itself publish your data to other users; the permission is used so the app can perform the remote access or support action you requested on your own device.
Data Sharing
We share Scry data only in these limited cases:
• with service providers that run parts of the service on our behalf, including authentication, hosting, analytics, Pro access, billing, and app-store providers
• with another person you explicitly authorize once support-session or trusted-sharing features are enabled in your build
• with OpenAI, only when you arrive at bravely.dev/scry from one of our ads in ChatGPT, to measure those ads, as described under "When You Arrive From One of Our Ads in ChatGPT"
• when required by law, legal process, or to protect the safety and integrity of the service
We do not sell or rent your data to advertisers or data brokers.
When You Arrive From One of Our Ads in ChatGPT
We advertise some of our products with ads in ChatGPT, OpenAI's assistant. Those ads link to a page on bravely.dev, such as the Scry page at bravely.dev/scry or the Mac Utility Bundle page at bravely.dev/mac. This section applies only when you arrive from one of those ads.
When you do, that page loads OpenAI's measurement pixel so we can tell whether our ads work. OpenAI adds an ad-click identifier to the link you followed. The pixel keeps it in a cookie on bravely.dev for 30 days, sets a second cookie holding a random identifier for your browser that it keeps for up to a year, and reports that you viewed the page. While the ad-click cookie is kept, the pixel also runs on that app's download page and on the page you see right after a checkout. It reports which download you click on these pages (such as the Mac installer, the App Store or Google Play), and, when you start a trial or complete a purchase, the product and plan, the amount and currency of a purchase, and the checkout's transaction reference. OpenAI also receives your network address and browser details with these reports. The pixel also looks for contact details shown or typed on these pages, such as an email address, and sends any it finds to OpenAI only as one-way hashes rather than readable text, to help match the report to the ad. We do not pass OpenAI any contact details ourselves, and the pixel does not load anywhere else on bravely.dev, in our apps, or for anyone who did not arrive from one of our ads.
OpenAI uses this to report our ads' results to us and to measure and deliver ads, and it may also use it to improve its own products and services. It processes this data as an independent controller under its own privacy policy.
You can stay out of this entirely:
• We honor the Global Privacy Control signal automatically. If your browser sends it, the pixel never loads.
• Our ads in ChatGPT are shown only in the United States.
• You can email privacy@bravely.dev to opt out of sharing; the California section below describes that right.
Security Claims and Session Content
Every Scry session is end-to-end encrypted between your two devices using WebRTC’s DTLS-SRTP. The connection is direct when your network allows it; otherwise it goes through a relay that only forwards the encrypted packets, so our servers never see your screen. Our own services use authenticated accounts, transport encryption, and device/session authorization checks. We do not make privacy or security claims beyond what we have shipped and documented publicly.
Data Retention and Deletion
We retain account, device, session, and Pro access records only as long as reasonably necessary to operate Scry, investigate abuse, comply with legal obligations, and support customer requests. You can delete your Bravely Account at any time from within Scry — open Settings and choose “Delete Account.” Deletion runs on a 30-day grace period: you are signed out immediately and can restore your account by signing back in within those 30 days. After that, your account is deleted as described in the Bravely Account privacy policy, which also lists the records we keep after a deletion, and any subscription billed directly by Bravely Studios LLC is canceled. Scry’s list of your devices is not yet removed automatically when your account is deleted; email privacy@bravely.dev and we will remove it. Copies of your Bravely Account’s records, including its sign-in and purchase records, made before the deletion stay in our encrypted backups until those backups expire, as described under "Backups" below. The device list, session records and device-login records that Scry’s relay keeps are not in those backups; diagnostic reports, including the session details they describe, are. Subscriptions purchased through the App Store or Google Play are managed by that store and should be canceled there. You can also email support@bravely.dev to have us process the deletion for you.
Error Reports and Diagnostic Reports
Scry can send us two kinds of technical report, which you control from Help & Diagnostics in its Settings, with one exception, described below: Scry for Mac has no switch for automatic diagnostic reports. Automatic error reports do not carry your Bravely Account identifier or your email address. Diagnostic reports carry your Bravely Account identifier. We use both only to find and fix problems, and we do not sell them or use them for advertising.
Automatic error reports
When the app records an error or a warning, it can send us a short report about it. It collects these on your device and sends them in small batches, about once a minute while problems are happening. A report names the app, the platform, the app version and your operating system version. For each problem it gives:
• its category and type, and a short description of it with details removed
• how many times it happened, and when it was first and last seen
• whether you were signed in, whether you had an active plan, and whether the device was online
Some apps also add how long the app had been running, the names of up to three functions in the app's code where the problem happened, and up to ten of the app's own log entries from just before it, with details removed.
Before a report leaves your device, the app removes details such as email addresses, account identifiers and file paths from its text. Our server removes those details again before the report is stored, and also removes network addresses, long strings of hexadecimal characters and sign-in tokens in the common JWT format. Error reports do not contain your Bravely Account identifier or your email address, and our server does not record your IP address with them. Our apps are built to keep the contents of your remote sessions out of error reports. Instead of a device identifier, each report carries a code that the app works out from a random identifier it keeps for its installation and from the date, so the code changes every day. We use the code to count how many devices ran into a problem on a given day and to limit how many reports one device can send.
When you first use the app, it asks our server which country your connection comes from, and the server answers without storing the answer. If the country is in the European Economic Area or the United Kingdom, automatic error reports are off until you turn them on. Everywhere else, they are on until you turn them off. Our web and Android apps keep reports off until the answer arrives, and if no answer comes, they go by the region in your browser's or device's language settings. Our other apps keep reports on until the answer arrives, and some of them leave reports on if no answer comes. Scry for Linux does not ask yet, so there automatic error reports are on until you turn them off, wherever you are. You can turn automatic error reports on or off at any time under Help & Diagnostics.
We delete each report after 30 days, and the hourly counts we make from reports after 7 days. We keep a summary of each kind of problem with no set end date: its category, type and description with details removed, the app versions it happened in, how many times it happened, on how many devices it happened each day, when it was first and last seen, and a recent example of the log entries that led up to it.
Diagnostic reports
A diagnostic report is a fuller report about one problem. The app sends one when you press Send Diagnostic Report. Unless you turn automatic diagnostic reports off under Help & Diagnostics, it also sends one when something fails in a way you might not notice, such as a sync that keeps failing or a remote session that ends unexpectedly, and at most once an hour for the same kind of problem. Versions of Scry that send our newer diagnostic reports, described below, can also send one, except on the web, when the app stops responding for 5 seconds or more, or the next time you open it after it closed unexpectedly. Automatic diagnostic reports are on by default wherever you are. In Scry for Windows, the switch for automatic error reports also turns automatic diagnostic reports on and off. Scry for Mac does not have a switch for them. Diagnostic reports are sent only while you are signed in.
A diagnostic report contains the app version, your operating system version, a few counts and settings from the app (for example, how many documents are open, or whether sync is on) and, where the app keeps them, its own recent log entries. A Scry report also describes the remote session, such as its connection statistics and why it ended. In versions of Scry that send the newer reports, a report can also contain:
• A record of your recent activity in the app: the names its code gives to its screens and to events such as signing in, changing a setting, the network going offline or a key press the app ignored, with details limited to numbers, yes-or-no values and fixed words that the app's code defines, such as a count or which part of the app something started from. Any other word is left out, so the record is built to leave out names, what you typed, which keys you pressed, file names, addresses, identifiers and the contents of your remote sessions. The app keeps this record, up to its latest 200 entries, only in its memory while it runs, and it leaves your device only inside a diagnostic report.
• The state of the app when the report was made. For example: the screen, dialog and tool you were using, what kind of control your typing would go to, what kind of item was selected and how many, and which kinds of window were open. It also shows the state of the network, whether you have an active plan or trial, how long the app had been running and, in apps that sync, the state of sync. In some apps, it shows whether the app has the system permissions it uses. In apps with system-wide keyboard shortcuts, it can show up to eight of them, with the keys each is set to and whether it is working, and how long ago the app last noticed any key being pressed. Like the record, it holds only numbers, yes-or-no values and fixed words, never titles, names or text.
• Your display and time zone: the size in pixels and the scale of the display the app is on, and the difference between your time zone and UTC; on a computer, how many displays you have; on Windows and Linux, the version of the software framework the app runs on; and on Linux, which desktop you use and whether it runs on X11 or Wayland.
• Up to 50 recent warnings and errors, each with a description with details removed and, where it has one, a short code, and how many warnings and errors the app had recorded.
• How the app's previous session ended (normally, in a crash, or unexpectedly, for example because it was forced to quit), with its version, how long it ran and the main steps it recorded, such as starting up. To know this, the app keeps a list of those steps in a file on your device, which it starts again each time it opens.
• In Scry: how the most recent attempt to connect went (which end this device was, the session's identifier, the kind of device at the other end and its version of Scry, how far the attempt got, how long it took and how it ended, and the kinds of network connection it tried, but not their addresses); whether the device is online for remote sessions and registered to your account; and, on a computer that others connect to, the state and version of Scry's background service.
If you have turned off usage analytics in the app, its newer reports leave out the record of your activity and the previous session's list of steps. In their place they carry a note that the record was left out and a few counts: how many entries the app recorded, combined or dropped to stay within its limit, how many event names or details its filter refused or replaced, and how many times the signed-in account changed. The rest of the report, including the state of the app and the previous session's last step, is still sent, because it describes the problem rather than how you use the app. When a different account signs in, the app first discards everything it recorded for the newer reports until the previous account signed out (or, with no sign-out, until the switch), keeping only a count of how many times the account has changed since the app started. What it recorded while no one was signed in, such as the steps of signing in, can appear in the new account's reports.
The app removes details such as email addresses, file paths, and keys or tokens from log entries before they go into a report, and our apps are built to keep the contents of your remote sessions out of a report. In the newer reports, the app also removes text in common quotation marks, network (IP) addresses, the names of document and media files it recognizes by their endings, and your user and computer names, though some details, such as a name it does not recognize, can still appear. Reports from versions of Scry that do not send the newer reports can still contain some of these: in some of them, such as Scry for Mac, the connection statistics include the network addresses a connection used, and Scry for Windows also sends the computer's name, the Windows user names and session details of the accounts signed in to it, and the titles of Scry's windows. Some apps have a switch that records more detail in their own log for 24 hours and then turns itself off. That log stays on your device, apart from the entries that go into a report.
With each diagnostic report we record your Bravely Account identifier, the user agent of the app or browser that sent it, the country your connection came from and when it arrived. When you send a report yourself, the app shows you a short code, such as DIAG-7K2QM, to give to support so we can find it.
A report's log file, which holds its log entries and, in the newer reports, the record of your activity, the recent warnings and errors and any steps from the previous session, is deleted automatically after 90 days. We keep the rest of the report with no set end date, so we can see patterns across reports: its short code if it has one, your account identifier, the app and its versions, why it was sent, the Scry session details, the counts and settings, the user agent and country, when it arrived, and, in the newer reports, the state of the app, the details of the most recent attempt to connect, your display and time zone details, how many warnings and errors the app had recorded and, if it had recorded any, a short label for the most recent error (or, if there was none, the most recent warning), and, where the app records it, how the previous session ended and its last step. Deleting your Bravely Account deletes your diagnostic reports from our live systems. Our data warehouse keeps its copy of what we keep from each report, without the user agent and country, under your account identifier, as the Bravely Account privacy policy describes. To have a report deleted sooner, email privacy@bravely.dev.
Where reports are kept
Both kinds of report are stored in database and file storage that Cloudflare runs for us, and copied into a data warehouse that we run ourselves. Diagnostic reports, apart from their log files, are also copied each night into our encrypted backups, described under "Backups" below. When our team looks into a problem, they can attach a diagnostic report to an issue in our own issue tracker, whose data Google stores for us. The issue keeps the report's short code (or its number), the app and platform, the app and operating system versions, whether the report was sent by hand or automatically, when it arrived and, for a newer report, a one-line summary of what it shows, such as the screen in use and the most recent problem. It stores the sender only as "customer account", not their account identifier or email address (for a member of our team, it stores their name or email address and their account identifier), and it keeps all of this after the report itself is deleted. While the report and the sender's account exist, our team can see the sender's email address when they view the issue.
Backups
We keep backups so that we can recover our customers' data if it is ever lost. Each night we copy the databases that hold accounts, purchases and the content our apps and services keep for their users, including sign-in records and the protected form of passwords, and we copy the files stored with us, such as documents, screenshots and attachments. Unless a section above says otherwise, the account, purchase and content records this policy describes, and the files you store with us, are in these backups.
Where backups are kept
Backups are kept in two places, both in the United States: on storage equipment that we own, and in Amazon S3, a storage service run by Amazon Web Services. Every copy of a database or of sign-in records is encrypted, with a key that only we hold, before it is stored in either place. The copies of stored files that we keep in Amazon S3 are also encrypted with a key that only we hold, file names included; the copy of those files on our own equipment is not separately encrypted. Amazon does not have our keys, so it cannot read your data in the backups.
How long backups are kept
Each night's copy of our databases and sign-in records is deleted after 90 days and fully purged within 30 days after that, so it is kept for about four months at most. One copy each month is kept for up to 12 months instead, and fully purged within 30 days after that, so it is kept for about 13 months at most. The backup of stored files keeps each file for as long as it is stored with us; when a file is deleted or replaced, the backup keeps the earlier version for 90 days and then deletes it. Separately, Cloudflare, which runs most of our databases, keeps a recovery history of each of them for 30 days.
How backups are used
We use backups and that recovery history only to restore data after it has been lost, for example in an outage, through a mistake or in an attack, and we also use backups to test that restoring works. Deleting something, or deleting your account, does not remove it from backups made before the deletion or from the recovery history: those copies stay until they are deleted on the schedules above. If we restore data from a backup or from the recovery history, we re-apply the deletions made after the point we restore to, including account deletions, so that the restore does not bring back data that had been deleted.
Your Privacy Rights
Depending on where you live, you have rights over the personal data we hold about you. We honor these rights for everyone who asks, regardless of where you live.
• Access — ask what personal data we hold about you and get a copy.
• Correction — ask us to fix data that is wrong or incomplete.
• Deletion — ask us to delete your personal data by emailing privacy@bravely.dev from the address on your account. Where a product has a built-in Delete Account control you can use that instead; bravely.dev/delete-account explains what applies to each product.
• Portability — ask for your data in a portable, machine-readable format.
• Objection and restriction — ask us to stop or limit certain processing.
• Withdraw consent — where we rely on consent (for example, marketing email), you can withdraw it at any time without affecting processing that already happened.
• Non-discrimination — we will not degrade your service or charge you more for exercising any of these rights.
EEA and UK residents also have the right to lodge a complaint with your local supervisory authority. California residents may use an authorized agent; we may verify the agent's authority and confirm the request with you first. Other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect) have equivalent rights, including a right to appeal a denied request — reply to our decision email with "Appeal" and we will respond in writing within the period the law requires. Canadian residents have access, correction, and consent-withdrawal rights under PIPEDA; Australian residents have access and correction rights under the Australian Privacy Principles.
To exercise any right, email privacy@bravely.dev. We respond within the timeframe the applicable law requires — generally 30 days under GDPR and 45 days under the CCPA, with an extension where the law permits one. We may need to verify your identity before acting, usually by confirming control of the email address on the account.
Legal Basis for Processing
If you are in the EEA or UK, we rely on these lawful bases under the GDPR and UK GDPR:
• Performance of a contract — creating and securing your account, delivering the features you paid for, syncing your content, processing purchases, and providing support.
• Legitimate interests — keeping the service secure and reliable, preventing fraud and abuse, understanding how our products are used through usage events tied to an installation or to your account, and improving the product. We balance these against your rights and do not use them to justify intrusive tracking. Where an app lets you turn its usage analytics off, doing so is one way to object.
• Consent — marketing email, and anything else we ask your permission for before we collect it. You can withdraw consent at any time.
• Legal obligation — keeping tax, accounting, and consent records, and responding to lawful requests.
International Data Transfers
Bravely Studios LLC is a US company. We and our sub-processors process data in the United States and in other countries where they operate. For personal data originating in the EEA, UK, or Switzerland, we rely on appropriate transfer safeguards in our processor agreements — such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — where those safeguards are required. Email privacy@bravely.dev if you want more detail about the safeguards that apply to you.
California Notice at Collection
For California residents, the categories of personal information we collect for this product are:
• Identifiers — your Bravely Account identifier, email address, and device or installation identifiers.
• Commercial information — records of purchases, subscriptions, entitlements, trials, and refunds.
• Internet or other electronic network activity — usage events, which carry an installation or browser identifier, your Bravely Account identifier, an identifier for a single request or purchase, or only a shared identifier for the app and platform; app version and platform; crash and error reports; and, if you arrive from one of our ads, ad-click identifiers and the measurement events described in the advertising section above.
• Coarse geolocation — a country-level signal derived from your network connection, used for consent rules and tax.
• Your content — only the content the product is built to store or sync for you, described in the sections above.
We collect this from you, your device, and our own systems, and we use it to run the product, honor what you have bought, keep the service secure, and support you. We disclose it to the service providers listed under "Sub-processors," each for a business purpose under a written contract.
We do not sell your personal information. When you arrive at one of our advertising landing pages from an ad, we share limited identifiers with the advertising platform that showed you the ad so we can measure whether our ads work, as described in the advertising section above; under the CCPA and CPRA that measurement may count as "sharing" for cross-context behavioral advertising. You have the right to opt out of that sharing, and you can exercise it at any time: we honor the Global Privacy Control browser signal automatically as an opt-out, and you can also email privacy@bravely.dev. Measurement for our ads in ChatGPT began on September 28, 2026. We do not use or disclose sensitive personal information for any purpose that would trigger the right to limit.
Retention is described under "Data Retention" and "Backups" above and, for account-level data, in the Bravely Account privacy policy.
Sub-processors
We use the following service providers to run this product. They receive only what they need to perform their service for us, and each is bound by the data-processing terms that apply to our use of their service. Where a provider is not yet covered by a written data-processing agreement with us, its entry below says so. If you need a data-processing agreement in place before you use this product, email privacy@bravely.dev:
• Cloudflare, Inc.: hosting, the Workers runtime, D1 databases, R2 object storage, and bot protection for bravely.dev and our app subdomains. See cloudflare.com/privacypolicy.
• Google LLC: Firebase Authentication, which backs Bravely Account sign-in (including Sign in with Google). See policies.google.com/privacy.
• Apple Inc.: Sign in with Apple, and App Store purchase and receipt handling for our Apple platform apps. See apple.com/legal/privacy.
• Paddle.com Market Ltd: our merchant of record for purchases made on the web or in our desktop apps. Paddle handles checkout, payment processing, invoicing, and sales tax/VAT. When you open a checkout while signed in, we give it your email address; otherwise you enter it on Paddle's checkout page. Each purchase carries the app it is for, any campaign tags on the link that brought you to checkout, and either your Bravely Account identifier or, for a purchase made before you had signed in, a temporary identifier that we link to your account when you claim the purchase. As the seller of record, Paddle keeps its own records of your purchases. See paddle.com/legal/privacy.
• RevenueCat, Inc.: keeps the purchase record for each Bravely Account. It validates App Store and Google Play purchases and reports subscription changes, and we also record trials and web and desktop purchases with it, so we can unlock what you bought on every platform. We identify you to it by your Bravely Account identifier. The first time you sign in with Apple or Google, and on some other sign-ins, we also send it your email address, your name (when the sign-in provides one), your country and the app you signed in from. Some apps also record with it the name of the device you use, and a few older parts of our service identify you to it by your email address instead. See revenuecat.com/privacy.
• PostHog Inc.: product analytics. Our apps, some of our websites and our account service send it usage events, such as which features are used and the steps of signing in, starting a trial and buying, and our websites and web apps also send it recordings of how their pages are used. An event carries an identifier for the installation or browser it came from, your Bravely Account identifier, or both (most apps add your account identifier once you have signed in); a few events, such as a failed sign-in or a purchase made before you had signed in, carry an identifier for that one request or purchase instead, and some copies of app events that reach it through our account service carry only a shared identifier for the app and platform. PostHog receives the network address each event was sent from. A few apps also send it your email address, and a few older parts of our service identify you to it by your email address instead. The Bravely Account policy describes this under "Usage and Purchase Analytics". See posthog.com/privacy.
• Resend Inc.: sends our transactional email (sign-in codes, receipts, password resets, support replies). See resend.com/legal/privacy-policy.
• Amazon Web Services, Inc.: Amazon S3, which stores our backups in the United States, as described under "Backups". The copies of your data that we keep there are encrypted, with a key that only we hold, before they leave our systems, so Amazon cannot read them. See aws.amazon.com/privacy.
• Google LLC: Google Play, which distributes our Android apps and handles purchases and subscriptions made in them, including payment and refunds under Google's own terms, and confirms each purchase to RevenueCat, which tells us. See policies.google.com/privacy.
• OpenAI OpCo, LLC: advertising measurement for visits that arrive from our ads in ChatGPT. Receives the ad-click and browser identifiers, the page-view, download, trial and purchase events, and any contact details the pixel finds on those pages as one-way hashes, as described in "When You Arrive From One of Our Ads in ChatGPT," only for visitors who came from one of those ads, and processes them as an independent controller under its own privacy policy. See openai.com/policies/privacy-policy.
If we add or change a sub-processor in a way that materially changes how your data is processed, we will update this policy and give additional notice where the law or our data-processing commitments require it.
Security
We protect your data with authenticated accounts, encryption in transit, access controls on our backend systems, and a deliberately small number of people who can reach production. No system is perfectly secure, and we do not claim guarantees we have not built and verified. Where a product makes a specific security claim, that claim appears in the app-specific sections above and is limited to what we have actually shipped. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators as required by law.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make a material change — a new category of data, a new sub-processor, a new purpose, or a new legal basis — we will update the "Last updated" and "Effective" dates and give additional notice where the law requires it. Where a change requires fresh consent under the GDPR, UK GDPR, CASL, or a similar regime, we will ask for it before relying on the new purpose. Non-material changes (typos, clarifications, link fixes) are reflected by updating the "Last updated" date.
How to Contact Us
Bravely Studios LLC
Privacy and data rights: privacy@bravely.dev
Product support: support@bravely.dev
Website: https://bravely.dev
Postal address: available on request to privacy@bravely.dev.