save brain power

Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains what data the save brain power application (the "Service"), operated by its individual developer (the "Operator"), collects, why, and who can see it. The short version: the Service is built so the Operator technically cannot read the content you write.

1. Content you write is end-to-end encrypted

Journal entries, tasks, notes, meetings, and other content fields are encrypted on your device before they ever leave it, using keys derived from your passphrase and recovery code. The Operator's servers store only ciphertext and have no technical means to decrypt, inspect, search, or otherwise read your content — not for debugging, not for support, not under any circumstance.

This also means the Operator cannot recover your content if you lose both your passphrase and your recovery code.

2. What the Service does see

Because content is opaque to the server, the Service instead relies on metadata to function — sync, search indexes, and the activity views in the app. This metadata is not encrypted and is visible to the Operator's infrastructure:

  • Account identity: your name and email address, as provided by your sign-in provider.
  • Session and authentication state, and billing/entitlement status.
  • Activity metadata: record counts, creation and update timestamps, journal dates, and which records relate to which company or provider — for example, that you logged an entry on a given day, not what it says.
  • A small number of plain (unencrypted) numeric fields used for in-app summaries, such as self-reported burnout level and check-in/check-out times.
  • Identifiers needed to connect synced records to their source, such as GitHub/Linear issue IDs, pull request numbers, and calendar event IDs — never the content of those items.

In short: the Operator can see how much you use the Service, when, and roughly what kind of work it relates to — never what you wrote.

3. How you sign in

You authenticate via GitHub or Google. The Service receives the name and email address your chosen provider shares, and uses it solely to identify your account. Sign-in is handled by better-auth; the Operator does not receive or store your provider password.

4. Sync across your devices

To keep multiple devices in sync, the Service broadcasts real-time notifications over a per-account connection. These notifications only ever name which collection changed (for example, "tasks"), never row content — though the timing of these notifications is itself metadata, and could reveal, for instance, that you were active at a given time.

5. AI features and connected third-party services

AI features and integrations (GitHub, Linear, Google Calendar, Granola, and AI providers such as Anthropic, OpenAI, or OpenRouter) are bring-your-own-key: you supply your own credentials, and requests are made directly from your browser, optionally relayed through a proxy. The Operator's own servers do not see the prompts, API keys, or responses involved in these requests. The proxy, when used, performs no logging of any kind by design.

Google Calendar sync is the one exception to the relay pattern above: it talks to Google's APIs directly from your browser using Google's own sign-in tokens. The Service requests only read-only access to your calendar list and your events — it cannot create, modify, or delete anything in your Google Calendar.

Limited Use: the Service's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, raw or derived data obtained from Google Workspace APIs is never used, transferred, or sold to develop, train, or improve foundational or generalized artificial intelligence or machine learning models. Where calendar-derived records are included in an AI feature, they are sent from your browser to the AI provider you configured, under your own API key, solely to produce output for you in that moment.

Disconnecting an integration in Settings revokes its access and stops future syncing. Records already imported before disconnecting (such as previously synced calendar events) remain in your journal like any other entry you created — they are not automatically deleted — and can be removed individually, the same as any other record.

Your use of any connected third-party service is governed by that service's own privacy practices, which the Operator does not control.

6. Service providers the Operator uses

The Operator relies on a small number of infrastructure and processing providers:

  • Cloudflare — hosting for the application, database, storage, and real-time sync infrastructure.
  • Better Stack — operational logging, uptime monitoring, and aggregate, content-free performance metrics (e.g. page load timings). Application logs are structured to exclude row content, decrypted values, tokens, keys, and email addresses.
  • Stripe — payment processing and subscription billing, for paid plans.
  • Resend — transactional account email (for example, sign-in or billing notices) — never journal content.

These providers process data only as necessary to operate the Service and do not receive your encrypted content in decryptable form.

7. Cookies and local storage

The Service uses a session cookie to keep you signed in, and browser local storage / IndexedDB to cache encrypted data for offline use and performance. Your unlocked encryption key is held only in memory while you use the Service and is never written to persistent storage.

8. Data retention and deletion

Your data is retained for as long as your account is active. You may delete records, export your data, or delete your account at any time from within the Service. Because content is encrypted end-to-end, if you lose your passphrase and recovery code, the Operator cannot recover or delete individual encrypted values on your behalf beyond deleting the account as a whole.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data. Because the Service is designed so the Operator cannot read your content, the most direct way to exercise these rights over your content is through the Service's own export and delete tools. For account-level requests the Operator can address directly (such as deleting your account metadata), contact the Operator through the Service.

10. Children

The Service is not directed to children and is not intended for use by anyone under the age required by their jurisdiction to consent to data processing without parental approval.

11. Changes to this Policy

The Operator may update this Privacy Policy from time to time. The "Last updated" date above reflects the current version, and continued use of the Service after changes take effect constitutes acceptance of the revised Policy.