Last updated · 2026-06-18
Privacy policy
Bragi ("we", "us") respects your privacy. This policy explains what we collect, why we collect it, how we use it, and the choices you have. If any term here conflicts with applicable law in your jurisdiction, the law wins and we apply the stricter standard.
What we collect
- Account data: email, display name, optional avatar, authentication tokens. Stored on Supabase.
- Profile data: dietary tags, allergies, optional age/sex/height/weight/activity level — provided by you during onboarding.
- Content: recipes you save or create, food logs, posts, comments, messages, photos you upload.
- Usage data: device platform, OS version, app version, opt-in product analytics events (no free-text food names, no chat contents) processed by PostHog.
- Crash + error data: stack traces with personal identifiers scrubbed, processed by Sentry.
- Payment data: handled by Stripe (web) or RevenueCat/App Store/Play Store (mobile). We never see your card number.
Why we collect it
- Provide and improve the service.
- Compute nutrition estimates and AI suggestions.
- Communicate with you (lifecycle emails, support, push notifications).
- Detect abuse and enforce our terms.
- Comply with our legal obligations.
Who we share with
We share data only with the processors required to operate Bragi:
- Supabase — primary database, auth, storage, realtime.
- Upstash — Redis cache.
- Anthropic — AI inference (plate analysis, coach, parsers).
- Edamam + USDA — nutrition lookups.
- Stripe / RevenueCat — payments.
- Resend — transactional and lifecycle email.
- Sentry — crash + error reporting.
- PostHog — product analytics.
- Cloudflare — DNS, CDN, image hosting.
- Expo + Apple + Google — push notifications.
We do not sell your data and do not share with advertising networks. We do not allow processors to use your data for their own purposes.
Your choices
- Export: Settings → Data & export → Request export. We send a JSON file within 7 days (usually faster).
- Delete: Settings → Account → Delete account. We soft-delete immediately, purge after 30 days.
- Notifications: granular per-channel toggles in Settings → Notifications.
- Cookies: see the cookie policy.
GDPR (EU / UK) and CCPA (California)
EU/UK residents: you have rights of access, rectification, erasure, restriction, portability, and objection. Email privacy@bragi.fit to exercise any of them. Our data controller is Bragi Labs LLC, registered in the Republic of Armenia.
California residents: we do not sell personal information. You may request information about the categories of personal information we collect and disclose, and request deletion, by emailing privacy@bragi.fit.
Children
Bragi is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe we have, email privacy@bragi.fit and we will delete the account.
Security
We use TLS in transit, encryption at rest, Row-Level Security on every multi-tenant database table, and PII scrubbing in our error reporter. No system is fully secure; we will notify affected users within 72 hours of confirming a breach.
Changes
We post material changes here. The "Last updated" date is the canonical version marker. Significant changes are also announced in-app and by email.