Privacy Policy

Last Updated: October 29, 2025

BrainStorm AI ("we", "our", or "us") operates the BrainStorm AI mobile and web applications (the "Service"). This Privacy Policy describes how we collect, use, and protect your information when you use our Service.

1. Information We Collect

We collect information to provide and improve our Service, including:

1.1. Account Information

When you sign in with Google Workspace or OAuth, we receive your name, email address, and profile picture.

1.2. App Usage Data

We collect anonymized analytics through Firebase Analytics and Crashlytics to understand how users interact with the app and to improve stability.

1.3. Communication Data

For WebRTC video or voice calls, media streams are transmitted in real time and are never stored on our servers. In rare cases, TURN servers (via Google Cloud) may relay encrypted data to ensure connection reliability.

1.4. Speech Recognition & AI Features

When using speech recognition or AI features, audio is processed locally on your device whenever possible. For AI summarization or Gemini-powered features, limited text data may be sent securely to Google APIs for processing, and is not stored or shared by BrainStorm AI.

1.5. Device Information

We may collect basic device data (model, OS version, app version) for performance and compatibility tracking.

2. How We Use Your Information

We use collected information to:

  • Provide and maintain the Service
  • Improve app performance and user experience
  • Offer AI-powered features and voice assistance
  • Diagnose and fix bugs or crashes
  • Manage subscriptions and payments via RevenueCat
  • Comply with legal obligations

3. Data Sharing and Disclosure

We do not sell your personal information. We only share data with trusted service providers that help us operate the Service, including:

  • Google Cloud Platform / Firebase (hosting, analytics, authentication)
  • Google APIs (Gemini AI, Speech-to-Text, OAuth)

All partners are GDPR- and CCPA-compliant.

4. Data Security

We use industry-standard encryption (HTTPS/TLS) and Firebase security rules to protect your data. Access to your data is limited to authorized personnel and secured by Google Cloud authentication.

5. Your Rights

Depending on your region, you may have rights to:

  • Access or request deletion of your data
  • Correct inaccurate information
  • Object to or restrict processing
  • Withdraw consent at any time

6. Data Retention

We retain minimal personal data necessary for account operation. No call recordings, transcripts, or voice data are stored on our servers.

7. Children’s Privacy

Our Service is not directed to children under 13. We do not knowingly collect data from minors.

8. Changes to This Policy

We may update this Privacy Policy periodically. Updates will be posted on our website, and the date above will reflect the latest revision.

9. Contact Us

For privacy-related questions or data requests, contact: