Braindump Privacy Policy
Last updated: July 26, 2026
Without an account, Braindump does not upload the notes, categories, settings, or learned sorting data you create. That app data stays on your device. If you choose to create an account, your account details and Braindump data are stored with Google Firebase so changes can sync between your devices and your last successfully synced copy can serve as a cloud backup. Braindump uses no ads, in-app analytics, or behavioral tracking.
What stays on your device
Your notes, lists, categories, app settings, and learned sorting data are stored locally using your browser's built-in storage. You can use Braindump without an account, including while offline. Without an account, Braindump does not upload that app data.
While you are signed in, changes made offline stay on the device and are queued to sync after you reconnect.
Optional accounts
If you create an optional account, Firebase Authentication processes the information needed to sign you in. This includes your email address and password for email sign-in, or account details supplied by Google when you use Google sign-in, such as your name and profile picture. Braindump does not store a readable copy of your password.
Firebase also processes technical information such as your IP address and browser or device user-agent string to provide authentication, security, and abuse prevention. Opening or using the account controls may contact Firebase even if you do not finish creating an account.
What sync stores
When you connect an account, Braindump stores and syncs notes, lists, categories, settings, shortcuts, learned sorting data, record identifiers, sync timestamps, and short-lived deletion markers. This information is used only to provide account, sync, cloud-backup, security, and deletion features. Braindump does not sell it or use it for advertising.
Security and signing out
Firebase encrypts data in transit and at rest. Braindump sync is not end-to-end encrypted: Google Firebase systems process the data to provide the service. Firestore security rules restrict each signed-in account to its own synced data — no other account can read or write it.
Because sync is not end-to-end encrypted, the developer can technically access synced data through Firebase's administrative tools, as is the case with most sync services. Synced data is only accessed when needed to operate the service — for example, to investigate a problem you report or to process an account deletion — and is never sold, shared, browsed out of curiosity, or used for anything else. If you prefer that no one else can access your data under any circumstances, use Braindump without an account: local-only data is never uploaded.
Signing out stops syncing on that device. It does not erase the local copy or the synced server copy. You can sign back in later, or delete the account and its synced data.
Backups
Braindump includes a manual export feature that saves a backup file to a location you choose. That file is created and handled by you; the export feature does not upload it. If you create an account, your last successfully synced copy also serves as a cloud backup. Changes that are not yet marked “Last synced” may still exist only on the current device.
Third parties
Braindump uses Google Firebase for optional account authentication and Cloud Firestore storage. Firebase Analytics is not used. Braindump is served by Netlify, which processes web requests under Netlify's privacy statement. When installed from Google Play, Google Play may process install, device, and diagnostic information under Google's privacy policy. These providers process data to deliver their services; Braindump does not sell personal information.
If you send feedback in Settings, Braindump submits the feedback type, message, optional email address, and app version to Netlify Forms so Braindump can review the feedback and reply if requested. Leaving the email field blank sends no email address, but Netlify still processes the web request and related technical data under its privacy statement.
Retention
Synced Braindump data remains in the active Firebase database until you delete the account. When you delete an individual entry or category, Braindump keeps a small deletion marker containing its record identifier and deletion time for roughly 60 days so another device cannot bring it back. The marker does not contain the deleted note text and is removed on a later successful sync after that period.
Firebase says authentication IP logs are generally retained for a few weeks. After account and cloud data are deleted, Google may take up to 180 days to remove retained copies from live and backup systems, unless the law requires longer retention.
Netlify stores in-app feedback submissions in Braindump's form dashboard until Braindump deletes them.
If you email Braindump, your address and message are stored separately in the contact email account until that correspondence is deleted. They are not part of your synced Braindump data.
Children
Local-only use does not upload a child's Braindump content. If an optional account is created, the same account and sync practices described above apply. A parent or guardian can use the deletion options below or contact Braindump about an account.
Deleting your data
Uninstalling Braindump or clearing its app or site storage deletes the local data on that device. It does not delete local copies on other devices or an optional synced account.
Account holders can remove their account and active synced data from inside Braindump. The local copy on each device remains until it is cleared there. See Delete your Braindump account for the in-app steps, an email fallback, and provider-retention details.
Changes to this policy
If this policy changes, the updated version will be posted at this address with a new "last updated" date.
Contact
Questions? Email tgiamberini95@gmail.com.