This page says what data Brain Buffer needs, where it goes and how long it lives. "In development" means a feature doesn't exist yet or hasn't been verified: a plan is not a promise, and we don't pass one off as the other.
In short
Brain Buffer needs your data to work: to store reminders, understand your messages and deliver notifications. We don't sell it.
There are no ads now. If we add them, we'll tell you in advance through an update to these rules. Ads chosen using your data will be shown only with your separate consent.
Messages and document photos are processed by the Claude language model from Anthropic (USA). Voice messages to the Telegram bot are not transcribed at the moment, and go nowhere.
Reminders for saved places are checked on the phone itself. For "near a supermarket" reminders the phone sends its position to our server — but only while you have such a reminder.
Your family sees the reminders it set for you and your reactions to them. It does not see where you are.
Brain Buffer is an assistant, not a supervisor: a reminder can be late or not arrive. For important things keep a second way. We don't read prescriptions or other medical documents from photos — this is not a medical app.
Chat history is kept while the account exists. Choosing a retention period and a "delete everything" button are in development.
We are in beta testing right now: message text is stored for testers only, encrypted, for up to 14 days (section 8).
The service is provided, and your personal data handled, by ФОП Ощипок О. В., Україна.
You can download a copy of all your data yourself: on the web — Settings → “All my data”, in the Telegram bot — the /mydata command. Questions and requests for a copy or deletion of your data: privacy@telegramaireminder.com. We reply within 30 days.
A dedicated "Data request" item in the app, on the website and in the bot is in development.
2. What we collect, why, where and for how long
Data
Why
Stored at / sent to
How long
Account: name, email, handle, Telegram id and username, Google id, language, time zone
sign-in, notifications, family invitations
our database (Supabase, EU)
while the account exists
Password, if you set one
sign-in
only an Argon2id hash in our database
until you change it or delete the account
Your messages, bot replies, history of fired reminders
the core of the service: one history across app, web and bot
our database; message text goes to Anthropic (USA) for parsing
while the account exists. Choosing a period (1, 3 or 12 months) and automatic cleanup are in development
Reminders, notes, timetables, courses
the core of the service
our database
until you delete them. A deleted reminder (and a one-off that has fired) disappears from every list at once and is erased from the database 30 days later; course lessons live as long as the course. A note you cleared can be restored from the archive
Photos: timetables, pictures in chat
read the document and create reminders
Anthropic (USA) for reading; our database
as you choose: don't keep, 30, 90, 365 days, or forever (365 days by default). A photo in a note is kept as long as the note
Saved places: name, coordinates, radius, Wi-Fi and Bluetooth hashes, NFC tag ids
so places work on all your devices
our database
until you delete the place; a deleted one is erased from the database 30 days later
Current position for "near a supermarket / fuel station / ATM…" reminders
find the nearest such places
our server; where we hold no copy of the OpenStreetMap data (currently outside Ukraine), also the Overpass service
not written to your account — the position lives in the server's memory for the length of the lookup. Your history keeps a record of the fired reminder with the place name and distance
Movement type, battery level, charging, steps; the Wi-Fi network name only from an app older than 1.0.31 or as a condition of another reminder
fire the matching reminders
our server
not stored if nothing fires; a fired reminder goes into your history
Google Calendar events: title and time, up to 50 events at a time
reminders for events
our database
only if you turned sync on; stored as ordinary reminders
Family: members, names, invitations (the invitee's email, handle or Telegram), messages and reactions
shared reminders
our database; names also go to Anthropic as context for the model
while the family exists or you're in it. An invitation lasts 7 days, a six-digit code 10080 minutes
Notification tokens (Firebase, Web Push)
deliver notifications
our database; Google Firebase; your browser's push service
while the token is valid on the device
Payments: plan and Premium expiry date; a record of each payment — amount, plan, date, Telegram payment id
Premium; refunds; tax records
our database; Telegram (Stars)
the plan — while the account exists; payment records — 3 years and 3 months, also after the account is deleted: Ukrainian tax law requires it (Tax Code, Art. 44.3)
App technical data: version, CPU architecture, update result, enabled features
updates and support
our database
while the account exists
Failed sign-ins: address, IP, browser
protection against password guessing
our database, the admin's audit log
90 days, then deleted automatically
Server technical logs
fixing bugs
Fly.io (Sweden)
they hold no message text. Retention is Fly.io's; a single line cannot be taken back out of them
Encrypted tester records
fixing bugs during beta
our database
up to 14 days (section 8)
Problem reports you send (the form in the app and on the website, /feedback in the bot) and reports about a bot reply — with that reply and your comment
reply and fix
our database; a problem report's text also arrives in the developer's Telegram (for a reply report, only a notice that there is one)
in the database — while the account exists; the developer deletes the Telegram copy by hand
Emails: sign-in links, invitations, email changes
delivery
our mail service (currently Resend)
retention is Resend's; we keep no archive of sent mail
Letters you write to our address: sender, subject, text
reply to you; sort out spam; briefly label what the letter is about (a category and a one-line summary) — done by Anthropic's language model
our database; the letter's text goes to Anthropic (USA) for the label; the developer gets a Telegram notice with the sender's address, the subject and that one-line summary (not for spam)
in the database — 12 months from arrival, then deleted automatically; the developer deletes the Telegram notice by hand
We don't collect phone numbers.
Inactive accounts. We don't delete an account just because you haven't signed in for a while: yearly reminders have to keep working.
Backups. Every night we make an encrypted copy of the database (without the map reference data) and keep it for 14 days in private Supabase storage (EU); older copies are deleted automatically. So what is deleted from the database may remain in these copies for up to 14 days. We use them only to restore the database after a failure — and then we delete again the accounts their owners deleted after the copy was made: for that, an encrypted list of deleted account numbers sits beside the copies for 14 days.
Legal basis
Contract: providing the service you chose. This covers reminders, history, the language model, notifications, places and family. We don't ask for consent for this, because the service can't work without it.
Legitimate interest: security, fixing bugs and corresponding with you. This covers logs, sign-in attempts, update data and event counts — without them we could not protect accounts or find out why a reminder did not arrive — and letters to our address and problem reports: to reply, to filter spam and to label what a letter is about. You can object to this (section 14).
Your choice, which you can withdraw and keep using the service. This covers calendar sync, frequent-place suggestions, photo storage and being findable by handle or email. Being found by handle or email is off until you turn it on (choosing a handle in the chat turns it on — the bot says so). Since 3 October 2026 this holds for every account, including older ones.
Legal obligations. This covers payment records.
Anthropic, Google and our mail service (currently Resend) are in the USA, so some data leaves Ukraine and the EU. Transfers to Anthropic are protected by the EU Standard Contractual Clauses (Commission Decision 2021/914) built into its data processing agreement; Anthropic is not part of the EU-U.S. Data Privacy Framework. Google and Resend are certified under the EU-U.S. Data Privacy Framework, and Resend's data processing agreement also includes the Standard Contractual Clauses. For people in Ukraine the transfer is also needed to perform the contract: having the model read your messages is the service.
3. Location
Saved-place reminders ("when I get home")
We store the place (name, coordinates, radius) in your account so it works on all your devices.
Whether you've arrived is checked by the phone itself: it compares its position and the visible Wi-Fi networks with the saved ones. Your current position is not sent to the server for this.
Matching by Bluetooth devices and NFC tags exists in the code but has not been verified — treat it as in development.
When a reminder fires, the phone tells the server which reminder fired. That way it appears in your history on all your devices. So the server knows when a place reminder fired, but not where you were in between.
When you save a place "here", the phone sends its exact coordinates, the identifiers of nearby Wi-Fi networks and the names of connected Bluetooth devices, once. We keep network and device identifiers only as hashes. A hash makes an identifier harder to recover, but not impossible. You can also pick a place on the map or send your location to the Telegram bot.
If your time zone isn't set yet, we may work it out from the first position we receive.
Separately from all this, you can set a country and city in settings. That is your answer, not data from your phone: the country decides which features are available where you are, and from the city's name we work out its coordinates once, to compute sunrise, sunset and the weather. If you set nothing, we may guess the country from your phone's time zone or from a place you saved — and we always show you what we guessed.
"Near a supermarket, ATM, fuel station…"
These reminders need a database of places, so the phone sends its position to our server. It does so only while you have an active reminder of that kind, that is, while you use this feature.
That is why such a reminder runs for 3 days by default, unless you say "always" or name a duration of your own. One that runs with no end we ask about once, after a week: is it still needed? And when it fires near a place with a name, we offer to save that place as yours: the phone then checks the reminder, and no position is sent for it.
The position is sent about every 2 minutes. More often only if you turn on a faster sync yourself: in "instant" mode, about every 30 seconds.
Where we hold our own copy of the OpenStreetMap data — currently Ukraine — the server looks places up in it, and the position does not leave our server. Where we have no such copy (abroad, or somewhere truly remote), the server asks the OpenStreetMap Overpass service: only the coordinates and the search radius go there, with no account data.
We don't write that position into your account. When the reminder fires, your history gets a record with the name of the place found and its distance.
When you delete your last such reminder the phone stops sending its position — within a few minutes, as soon as the reminder list on the device refreshes.
Other sensors
From app version 1.0.31, "when I connect to Wi-Fi" reminders are checked by the phone itself, and the network name is not sent anywhere. If the reminder names a saved place ("my home Wi-Fi"), the phone compares the network with that place's Wi-Fi. Older versions of the app send the network name to the server.
"When I'm walking / driving" reminders are checked by the server: the phone sends the movement type. If any of your reminders has an "on such-and-such Wi-Fi" condition, the phone adds the network name to the events the server checks (movement, battery, steps) so it can check that condition.
The phone reports battery, charging and steps to the server even when you have no such reminder. With no matching reminder the server stores none of it; sending it only to people who need it is in development.
"Suggest frequent places" is off by default. If you turn it on, the log of visited spots stays on the phone and isn't sent anywhere. Turning the feature off erases the log. If Android backup is on, the log may be included in the backup in your Google account.
You can remove location access in Android settings at any time. Only location-based reminders will stop working.
4. Family
A family shares reminders, not location.
Your family sees
your name in the family. Every member can check at any time who is in the family, who has been invited and whether a removal vote is open;
the contact an invitation was sent to (email, handle or Telegram);
reminders they set for you: the text, the condition and whether it's paused. If you edit, pause or delete such a reminder, its author is notified. When you mark it done, too — but you can switch that off in your family settings, separately for place reminders;
your reaction (👍 ❤️ 🙂 😞) to a reminder set for you, and how many times it has fired — except for place-based reminders (see below);
family chat messages and reactions to them. A member can send a loud alert that sounds even on a silenced phone; you can mute a specific person;
a timetable they send you: if you already have one with the same name and theirs is newer, it replaces yours and you are told. Whoever sends it learns when yours was last changed.
Your family does not see
where you are now or where you've been;
your saved places, or your own reminders and notes;
your family settings — who you have muted and what you call your family members;
your devices and sign-in sessions.
A reminder tied to a place (or to a Wi-Fi network, a Bluetooth device or an NFC tag) that a family member set for you: the author does not see whether or how often it fired, nor your reaction to it. Honestly, what remains: if you mark it done, the author is told, unless you switched that off in your family settings ("When I mark a reminder done"); a one-off reminder disappears from their list once it has fired. You can delete or pause such a reminder — the author learns only that.
Rules
Only people who accepted an invitation join a family. You can invite by email, handle or Telegram. An invitation link lasts 7 days, a six-digit code 10080 minutes, and a code is confirmed by the person who invited you.
Someone can find you by email or handle to invite you only if you allowed it: it is off until you turn it on (choosing a handle in the chat turns it on and says so). Invitation links and codes always work.
The contact an invitation was sent to is needed only for that invitation: 30 days after it was accepted, declined or expired, the record is deleted together with the contact.
You can leave at any time, without anyone's confirmation.
When someone leaves the family or is removed, the reminders between them and everyone else come apart: what they set for you stays with you as your own, and they no longer see it, can't change it and get no notices about it. The same holds the other way round, for what you set for them.
Members are equal to one another, removal included: any member can ask for another to be removed, and it happens when every other member agrees, or when the person being removed agrees. If nobody has answered within 24 hours, the member who created the family can complete it — for when a person is unreachable, a lost phone for example; a refusal is an answer too and closes that fallback. In a family of two, "everyone else" is one person, so that person's decision is final.
A removed member can be invited back, on the ordinary terms: they have to accept the invitation.
Everyone chooses what to call the others in the family ("Mum", "Ira"); those names are seen by that person only.
Member names — including the ones you call your family by — are passed to the language model so it understands requests like "remind Mum".
A shared reminder tied to a place, and an "I'm here" button, are in development. "I'm here" will be sent only when you tap it yourself, and your family will see the place name you chose, not coordinates.
Sharing by link — not only with family
You can give out a link to your timetable or a reminder. Whoever opens it sees its text — as it is in your account right now — and can take a copy of their own. The link page does not show who shared it. The link works until you stop it; copies already taken stay with the people who took them. We see only how many times it was viewed and copied — not by whom.
5. The language model and voice
Messages you write in the app, on the web or to the Telegram bot, and photos of timetables, are processed by Claude language models from Anthropic (USA). Along with your message the model receives the names of your saved places, family member names and your time settings. Without them it can't tell what "at home" or "in the morning" means.
We don't pass the coordinates of your places to the model, only their names. A photo is sent for reading at full quality but without the data about where and when it was taken (EXIF): we remove that before it is read, as we do before it is stored.
Under Anthropic's terms for developers this data is not used to train models and is deleted within 30 days; only requests flagged as breaking its usage policy are kept longer — up to 2 years. Those are Anthropic's terms, not ours.
Chat replies are written by a language model, not a person. The chat says so too — in a line by the message box, and in the Telegram bot's welcome.
We don't read prescriptions or medical documents from photos (section 6): the model only recognises that a photo is one, and we take nothing from it.
Voice in the app is transcribed by your phone's speech recognition service. That's usually Google, depending on your phone's settings. We receive only the text. Reading notifications aloud happens on the phone.
Voice messages to the Telegram bot are not transcribed at the moment: the bot asks you to type instead, and the audio is neither downloaded nor sent anywhere. If transcription comes back, it will only be through a service with a data processing agreement — and this section will say so first.
Course plans and lessons are written by the model itself, from your request for a course.
How the transfer of this data to the USA is protected — section 2 ("Legal basis").
The model can make mistakes, so check what was actually created.
6. Prescriptions and medical documents
Brain Buffer is not a medical app and does not process medical data. We don't read prescriptions, doctor's orders or other medical documents from photos.
if a photo is such a document, the language model only recognises that, without transcribing anything from it — we keep nothing from it and reply that such photos are not supported;
reminders you write yourself are your own text; we don't ask for medical details in them.
Brain Buffer is not intended to be a medical device and does not give medical advice. If a reminder you set differs from your doctor's prescription or the medicine leaflet, the prescription and the leaflet are right.
7. Why a reminder might not arrive
Brain Buffer is an assistant, not a supervisor. We work to make reminders arrive on time, but we can't guarantee it: they travel through your phone, browser, Telegram and notification delivery services. A reminder can be late or not arrive when:
the phone is off or offline;
Android has restricted the app in the background (to save battery, for example), or you haven't opened the app since the phone restarted;
notifications or location access are turned off;
there's no GPS signal, including during air-raid alerts;
a service we rely on fails: Google Firebase, Telegram, hosting.
For anything your health, safety, money or deadlines depend on, keep a second way: an alarm, a person nearby, a written schedule.
8. The current period: beta testing and detailed records
This section describes what happens right now, while beta testing is running. When it ends we'll remove this section and delete what it collected.
To find and fix bugs quickly we need the text of real messages. But it is collected from a few people only, and kept in one place:
message text is stored for testers only — the owner and whoever agreed to it. For everyone else neither the logs nor the analytics hold any text, only its length and the parse outcome;
a tester's text sits only encrypted in a table of its own on our server. It can be read only from there, with a key kept in the server's settings rather than in the database. With no key, nothing is recorded at all;
the ordinary server logs (kept by Fly.io) hold no text at all — a line there cannot be taken back;
event analytics ("message received", "reminder created") keep no content for anyone, testers included — counts only;
testers' phrases the bot didn't understand go into a separate list, also encrypted. The developer gets only their number each day and reads the phrases themselves on our server. To teach the model, the developer writes an invented example: a real phrase never becomes one;
a 🙂 or 😞 reaction to a bot reply or a reminder reaches the developer only as a mark — without the text you reacted to;
while investigating a bug, the developer may look at a specific account's data.
How long: each encrypted record lives no longer than 14 days, and a phrase in the not-understood list 14 days from the last time it came up. A daily job deletes them, not a person.
Until 3 October 2026 the rules were weaker: phrase digests and reaction texts arrived in the developer's Telegram. Automatic deletion can't reach there, so the developer deletes those messages by hand.
If you are not a tester, your messages never reach these records. A tester can stop testing at any time: no new records are made, and the existing ones can be deleted on request before the window ends.
9. After release: diagnostics and testing
Everything in this section is in development. It's described here so you can see where this is going, not to promise that it already works.
A "Send diagnostics to the developer" switch will be offered on the screen where you accept the Terms of Use. It will be off by default, and you'll be able to accept the Terms without turning it on. If you turn it on, the developer will receive phrases the bot didn't understand, crash reports (app and Android version, phone model, error code) and a place-check log (distance, GPS accuracy, number of visible networks — without coordinates or names).
The switch will cover only these extra reports. It doesn't change how your reminders and messages are processed: that processing is described above and the service needs it to work.
Testers. You'll be able to become a tester and get new features earlier than others. A tester separately agrees that the developer receives more detailed data. You'll be able to stop testing at any time: detailed data stops coming, and you can ask us to delete what was already sent. Nobody becomes a tester unless they choose to.
10. Who else receives data
We pass data to the services Brain Buffer runs on:
Service
What it receives
Why
Where
Fly.io
all traffic to the server, technical logs
hosting
Sweden (Stockholm)
Supabase
everything we store
database
EU
Cloudflare
traffic to brainbuffer.me and telegramaireminder.com; letters you write to our address
website delivery and protection, mail forwarding
global network
Anthropic
message text, document photos, context for the model (place names, family names)
language model
USA
Google
notification text (Firebase); Google sign-in; the text of reminders the app writes into your Calendar if you enabled sync
notifications, sign-in, calendar
USA / global
Telegram
messages to the bot and its replies; Stars payments
bot, payments
per Telegram's own rules
Resend
email address and email text
sign-in, invitation and email-change emails
USA
OpenStreetMap: Overpass (FOSSGIS)
coordinates for place search — only where we hold no copy of the data (currently outside Ukraine)
places
Germany (EU)
OpenStreetMap: map tiles (the OSM Foundation)
your IP address and the map tiles you view
the map
United Kingdom; delivered by a global network
OpenStreetMap: Nominatim (OSMF) and OSRM (FOSSGIS)
your city's name — to work out the time zone and the weather; for a "N minutes before I arrive" reminder, the starting point and the destination
city, travel time
United Kingdom, Germany
OpenWeather
city name
weather reminders
United Kingdom
Your browser's push service (Google, Mozilla, Apple)
an encrypted notification
web notifications
—
jsDelivr
your IP address when a page loads
the map library in the web app
global network
accounts.google.com, telegram.org
your IP address and browser details when the sign-in page loads
the "Sign in with Google" button, Telegram sign-in
USA / global
This is the list as it stands today, and it can change: a service may get more expensive, become unreliable, or stop fitting, and we will replace it. The current list is always here, on this page. If a replacement materially changes where your data goes — to another country, say — we tell you in advance, as with any other change to the terms (section 17). The only change we make without notice is one that sends data to the same place or closer — from someone else's server to our own, for instance.
There are no ads and no third-party analytics trackers now, either on the website or in the app. If an ad network is ever added, it will appear in this list before it receives any data (section 11).
The developer has access to the server and the database. While investigating a hard bug he may use development tools that display data from the database — in which case the service those tools run on sees that data too.
11. Ads
There are no ads in Brain Buffer now. If we add them, it will only be through an update to these rules, announced in advance (section 17).
Ads chosen using your data will be shown only with your separate consent.
We don't use the text of reminders, notes or messages, photos, places or location, health or family data to choose ads.
We don't sell your data. If the service ever passes to another owner, the data goes with it — and we'll tell you in advance.
12. Security
What we do
All connections use HTTPS only. The app connects directly to our server on Fly.io; the website runs through Cloudflare.
You can sign in with Google, with an email link, with a password, through the Telegram bot, or with a quick start in the app that needs no email or password.
A sign-in link is valid for 24 hours and works only once.
Passwords are stored only as salted Argon2id hashes. A password must be at least 10 characters, the most common passwords are rejected, and each address gets at most 5 attempts per minute.
A failed sign-in always gets the same response, so it can't reveal whether an account exists for that email. We record failed attempts with the IP address and browser to spot password guessing.
Your email can only be changed through a link sent to the new address. The link is valid for 24 hours and does not sign you in. The old address gets a notice about the change.
The database is hosted by Supabase (EU) and encrypted on disk.
A family invitation can only be accepted by the person invited. Joining with a six-digit code also needs confirmation from the person who sent the invitation.
What's not there yet
The app's sign-in key is long-lived and has no expiry. It is kept in Android's protected storage, but the same key also reaches other places: the browser's storage on the website, the address of the "open in app" link, and the bot's reply when you ask it to show your token. Treat it like a password.
"Sign out" on the website removes the key only from that browser; it keeps working on your other devices. The app has no sign-out yet. A list of devices you're signed in on, signing out everywhere else, QR sign-in and key replacement are in development. If you think someone has access to your account, write to us (section 1).
App notifications are delivered by Google Firebase, and the reminder text passes through it without end-to-end encryption.
Chats with the Telegram bot, like chats with any bot, are not end-to-end encrypted.
What you can already do
Sign out on the website with the "Sign out" button.
Change your name and email in your profile.
Set or change a password.
Choose how long photos are kept.
Stop others from finding you by handle or email.
Download a copy of all your data: on the website under Settings → "All my data", in the Telegram bot with /mydata. Reminders alone can be exported as JSON or CSV, in the app or on the website.
Delete your account with all its data — in the app, on the website, or with /delete_account in the bot. It happens at once.
Remove location, microphone or calendar access in your phone's settings.
Leave your family.
13. Data and storage
Available now: choose how long photos are kept (don't keep, 30, 90, 365 days, or forever; 365 days by default); download a copy of all your data; delete an individual reminder, note or place; delete the account with all its data.
In development — a "Data and storage" screen in the app and on the website:
choosing how long chat history is kept (1, 3 or 12 months, or while the account exists), and automatic cleanup;
a "delete now" button for history, photos, places, notes and reminders;
permanently erasing notes you cleared into the archive;
chat commands: "what do you store?" gets a short answer and a link here; "delete my photos" opens that screen with the items already ticked, and deletes only after you confirm.
If you delete your history, your family members keep their own copies of the messages you sent to the family chat.
What deleting the account does not remove
reminders you set for your family — they stay with them, without your name;
your messages in the family chat — they stay in your family's history;
copies other people took through your links — those are theirs;
letters to our address — 12 months from arrival;
payment records — 3 years and 3 months, as tax records require.
If you created the family, it passes to the member who has been in it longest.
14. Your rights
You can:
get a copy of your data — yourself, as described in section 13;
correct your data. You can change your name and email yourself; we'll fix anything else on request;
delete your data — yourself, with a button or a command (section 13); if something doesn't work, write to us (section 1);
opt out of optional things: photo storage, calendar sync, frequent-place suggestions, being findable by handle or email — and later diagnostics, taking part in testing, and personalised ads if they ever come;
object to processing that rests on our legitimate interest (section 2) — event counts, say, or a letter being labelled by the language model. We'll stop processing your data that way unless we have compelling grounds that override your interests, and we'll explain the decision;
restrict processing — ask us to only store the data and do nothing else with it for a while: while we check data whose accuracy you dispute, or your objection; if the processing is unlawful but you don't want the data deleted; if we no longer need the data but you need it to defend your rights;
complain to the Ukrainian Parliament Commissioner for Human Rights. If you're in the EU, you can complain to your country's data protection authority.
How we confirm a request is yours. A request sent from the app, website or bot where you're already signed in counts as yours. Before deleting an account or sending a full copy we'll ask you to confirm once more. We don't ask for copies of documents. Our reply doesn't reveal whether an account exists for an address.
15. Children
The service is for people aged 13 and over. If you are younger than 16, you may use it with the permission of a parent or guardian. That rule comes from the Terms of Use.
We don't ask for your age and we don't verify it — we have no way to confirm it, and we won't collect documents or anything else about you in order to try. So it is a rule, not a check: Brain Buffer is not aimed at children, we don't make it attractive to them, and we don't work out how old you are from what you write.
An adult can add a child to their family and set reminders for them. There are no "parent" and "child" roles in the service: every family member has the same rights, and a child sees and can do the same as everyone else.
16. Data from Google
You can use Brain Buffer with a Google account in two ways. Both are optional.
Sign in with Google (website and app). We receive your Google account id, email address and name (scopes openid, email, profile). The id links your Google account to your Brain Buffer account; the email becomes your account's address if it has none yet — for signing in and messages about your account; the name is used only if you have not chosen one yourself. We do not ask for your contacts, files or anything else.
Google Calendar (Android app, only if you connect it in settings). The phone reads the title and start time of upcoming events in your primary calendar — up to 50, 30 days ahead — and sends them to our server, which turns them into reminders (an all-day event reminds on the morning of its day). Invitations you declined and events Brain Buffer added itself are left out. With the calendar connected, a one-off timed reminder you set for yourself is added by the phone to your primary calendar as an event. Access to your calendar stays on the phone: our server receives neither your Google password nor a calendar access token. The scope is calendar.events.owned: only calendars you own. No one on our team reads reminders made from your events — the admin panel does not show them.
Where it goes: our database and hosting, to provide these features. Imported events are not sent to the language model. We do not sell data from Google, do not use it for advertising, and do not use it to train AI models — ours or anyone else's.
How to stop: disconnect the calendar in the app's settings — this also removes Brain Buffer's access at Google (reminders already made from events stay until you delete them); or remove the access at https://myaccount.google.com/permissions; deleting your account deletes the Google id, the email and the reminders made from events.
17. Changes to these rules
The Terms of Use are a contract. This page only explains what happens to your data; you don't need to accept it.
Each version of this page has a number and a date — they're at the top. An archive of previous versions, and a record of which version of the Terms you accepted, are in development.
How we tell you. We describe changes briefly, like an app update's "What's new".
When. We announce significant changes in advance — at least 30 days before they take effect — except for changes the law, a platform or security requires immediately. Minor edits (typos, clarifications that don't change the meaning) only update the date.
What may change: prices, free-plan limits, the set of features — a free feature may become paid — and the introduction of ads.
Separate consent. If a change means a new use of data we already hold that the law says needs consent (personalised ads, for example), we'll ask separately. The new use doesn't start until you agree.
A paid period keeps the terms you paid under until it ends.
If you disagree, you can export your data and ask us to delete the account. Export and deletion are always available.