Legal
Privacy Policy
This Privacy Policy explains how the Bramley application ("Bramley", "the Service") collects, uses, shares and protects information when you use it. Bramley is developed and operated by Adam McCann, an individual based in the United Kingdom ("I", "me"). Bramley is not operated by a company. For the purposes of UK and EU data protection law, I am the controller of the personal data described here.
In short: Bramley uses your data only to provide the features you use. I do not sell your data, use it for advertising, or use it to train general-purpose AI models. You can disconnect any source, and ask for your data to be deleted, at any time.
1. Information Bramley collects
Account information
When you sign in with Google, Bramley receives your name, email address and Google account identifier. These are used to create and identify your Bramley account.
Data from sources you connect
When you choose to connect a source, Bramley accesses data from it with your permission. For Gmail, this includes email messages and their metadata (such as sender, recipients, subject, date and labels), attachments, and mail settings such as your signature and send-as addresses. Bramley stores the content it needs to show you your inbox, tasks, people and companies, and keeps it up to date as new mail arrives.
Content you create
Bramley stores what you create or change in the app, such as tasks, notes, corrections, drafts, settings and conversations with agent sessions.
Technical information
Bramley's servers and hosting providers record limited technical information, such as IP addresses, request times and error logs, to operate, secure and debug the Service. Bramley does not use advertising or third-party analytics trackers.
2. How Bramley uses information
- To sign you in and keep your account secure.
- To provide the features you use: syncing your connected sources, classifying messages into what needs action and what is worth knowing, extracting people, companies and commitments, building your task list, searching your data, and preparing drafts for your review.
- To carry out actions you ask for in a connected source, such as applying labels or creating drafts. Bramley does not send email on your behalf without your explicit action.
- To maintain, secure, troubleshoot and improve the Service.
- To contact you about your account or important changes to the Service.
- To comply with legal obligations.
3. Google user data
Bramley requests only the Google permissions it needs for the features you use. These currently are:
-
Basic profile and email address (
openid,email,profile): to sign you in and identify your account. -
Gmail read, compose and label management (
gmail.modify): to read your mail so Bramley can show and organise it, keep it in sync, apply labels, and create drafts you have asked for. -
Gmail basic settings (
gmail.settings.basic): to read your signature and send-as addresses so drafts match how you write.
Bramley's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- Google user data is used only to provide and improve user-facing features that are visible and prominent in Bramley.
- Google user data is not transferred to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to you.
- Google user data is never sold, and never used for advertising.
- Google user data is not used to develop, improve or train generalised or non-personalised AI or machine-learning models.
- No human reads your Google user data unless you have given explicit permission for specific messages (for example, when asking for support), it is necessary for security purposes such as investigating abuse, or it is required to comply with applicable law.
4. AI processing
Bramley uses AI models to provide some features, such as classifying messages and extracting people, companies and commitments. To do this, relevant content (for example the text of an email) is sent to an AI model provider through its API. Currently this is OpenAI. The provider processes that content only to return a result to Bramley, under terms that do not permit it to use the content to train its models.
If you connect your own agent account (for example a Claude or Codex subscription) and start an agent session, the content you share in that session is sent to that vendor under your own agreement with them.
5. How information is shared
Bramley does not sell or rent personal data. Information is shared only:
- With service providers who help run Bramley, under contracts that limit their use of the data to providing their service. These currently include Railway (application hosting, database and storage), Cloudflare (network and security), Google (sign-in and the Google services you connect) and OpenAI (AI processing as described above).
- At your direction, such as with an agent vendor you connect.
- For legal reasons, where required by law or to protect the rights, safety or security of users, the Service or others.
- If the Service changes hands, for example if it is transferred to an organisation. You will be told before your data becomes subject to a different privacy policy.
6. Data storage and security
Data is encrypted in transit using TLS and stored with hosting providers that encrypt data at rest. Access tokens for connected sources are stored securely and used only to provide the Service. Access to production systems is restricted to me. No method of storage or transmission is completely secure, but I take reasonable measures to protect your data.
Some service providers may process data outside the United Kingdom, including in the United States. Where they do, appropriate safeguards such as standard contractual clauses are relied on.
7. Retention and deletion
Bramley keeps your data for as long as your account is active or as needed to provide the Service. When you remove a connected account, Bramley revokes its access to that source. You can revoke Bramley's access to your Google account at any time from your Google Account settings.
To delete your Bramley account and its data, email dev@bramley.ai. Your data will be deleted within 30 days, except where it must be kept to comply with legal obligations. Backups are overwritten on a rolling basis.
8. Your rights
Depending on where you live, including under the UK GDPR and EU GDPR, you may have the right to access, correct, delete or export your personal data, to object to or restrict its processing, and to withdraw consent. To exercise these rights, email dev@bramley.ai. You also have the right to complain to a data protection authority; in the UK this is the Information Commissioner's Office.
The legal bases for processing are performance of the agreement with you (to provide the Service), legitimate interests (to secure and improve it), consent (for connecting sources, which you can withdraw at any time), and legal obligation.
9. Children
Bramley is not intended for anyone under 18, and I do not knowingly collect data from children. If you believe a child has provided data, please get in touch and it will be deleted.
10. Open source
Bramley's source code is intended to be released as open source. If you run your own copy of Bramley, you are responsible for the data it processes, and this Privacy Policy does not apply to that copy.
11. Changes to this policy
This policy may be updated from time to time. The effective date at the top shows when it last changed. If changes are material, you will be notified in the app or by email before they take effect.
12. Contact
Questions about this policy or your data: Adam McCann, dev@bramley.ai.
See also the Terms of Service.