Effective Date: August 27, 2026 • Last Updated: September 3, 2026 • Policy Version: 2.0.0
Technical Transparency & Data Sovereignty: BRO is built by TheRidCo (founded by Ridit Bandyopadhyay). We operate on a foundation of user data control, minimal collection, and absolute transparency. We do not sell, rent, or trade your personal data to data brokers or advertising networks.
Notice Regarding AI Capabilities
BRO is an AI and it can make mistakes.
BRO provides conversational, voice, creative writing, and productivity assistance. Messages, queries, and multimodal inputs are processed using neural machine learning models to generate conversational responses. Please do not submit sensitive personal identifiers, passwords, or confidential medical/financial credentials into prompts or attachments.
Your trust is essential to our companion architecture. We adhere strictly to the following foundational data principles:
We never monetize your private conversations, prompts, voice recordings, uploaded files, or email addresses.
Optional analytics and personalization telemetry are disabled by default and require explicit affirmative user consent.
When you register for an account, we collect your email address, display name, account creation timestamp, and assigned user identifier via Supabase Auth. This information is essential to authenticate your identity, manage your session securely, enforce subscription quotas, and maintain your preferences.
We process the text prompts and queries you submit to BRO to generate context-aware companion responses. Messages are stored in cloud PostgreSQL databases hosted on Supabase with Row-Level Security (RLS) policies enforcing that only your authenticated account can access, query, or delete your conversation sessions.
BRO features a user-directed memory system to recall facts, user preferences, projects, and goals across conversations. Memories are created when you explicitly command BRO (e.g. “remember this”) or via automated extraction when enabled in settings. You maintain direct control to inspect, edit, or delete memories at any time.
When you attach supported files (images, PDFs, or plain text files) to your messages within plan limits, the file contents are formatted into inline data and transmitted to our AI inference engine (such as Google Gemini) solely to answer your questions and perform requested multimodal tasks. Uploads are stored within your conversation history and follow your conversation retention settings.
When you purchase a paid subscription (BRO Sync or BRO Presence), payment details are processed directly by our payment gateway, Razorpay. We store your subscription tier, billing cycle (monthly or annual), transaction IDs, currency, and renewal status in our database. We never receive or store complete credit/debit card numbers, CVVs, or banking credentials.
To maintain system reliability, rate limits, and security, our servers temporarily log network IP addresses, browser user agent strings, request timestamps, and API response statuses. This operational data is retained only as long as necessary for security auditing and rate enforcement.
Voice and Audio Processing. When you use BRO's voice features, audio and/or related voice data may be processed by BRO and third-party voice service providers such as Cartesia to convert speech to text, generate responses, or synthesize speech, depending on the feature being used.
We collaborate with reputable technology partners who process specific categories of data strictly on our behalf:
| Provider | Service Function | Data Transmitted |
|---|---|---|
| Google Cloud (Gemini) | AI Language & Multimodal Inference | Prompts, conversation context, attachments |
| Cartesia | Premium Voice Generation (TTS) | Text snippets for spoken playback (Sync/Presence) |
| Supabase | Database, Auth & Cloud Storage | User profiles, encrypted chat sessions, memories |
| Razorpay | Payment Gateway & Subscriptions | Billing tokens, order amounts, payment confirmations |
| Vercel | Application Hosting & Edge Delivery | Encrypted HTTP network traffic, transient edge logs |
We categorize cookies and client-side storage mechanisms into four distinct tiers:
Sec-GPC header and navigator.globalPrivacyControl signal. When detected, non-essential telemetry is automatically disabled.We retain personal data only for as long as necessary to provide the service, comply with statutory obligations, and maintain platform security:
| Category | Purpose | Retention Window | Deletion Mechanism |
|---|---|---|---|
| Account Profile | User authentication & identity | Duration of active account | Account deletion request |
| Conversations | Companion chat history & context | Until deleted by user | In-app clear / Delete button |
| User Memories | Long-term personalization | Until deleted by user | In-app memory vault manager |
| Payment Orders | Tax, accounting & legal compliance | Mandated statutory period | Statutory expiration |
| Consent Logs | Privacy compliance verification | 365 days rolling | Automated roll-off |
Under applicable data protection legislation (including India's Digital Personal Data Protection Act, 2023, the GDPR, and similar international laws), you possess meaningful rights regarding your personal information:
Inspect all stored profile attributes, usage counters, and saved memory items directly within Settings → Privacy & Data.
Download a complete, machine-readable JSON archive containing your profile, settings, memories, and full conversation transcripts at any time with a single click.
Revoke previously granted consent for analytics and personalization at any time through our interactive cookie banner or in-app settings.
Permanently delete your entire account, conversations, memories, profile, and authentication records via Settings → Privacy & Data.
We implement comprehensive technical and administrative security measures to protect your personal data:
TheRidCo is based in India. To operate a high-availability AI platform, we utilize cloud infrastructure and API processors located in multiple jurisdictions, including India, the United States, and the European Union. When data is transferred across borders, we ensure appropriate safeguards are maintained by our hosting and API infrastructure partners in compliance with applicable data protection laws.
We may update this Privacy Policy periodically to reflect technological enhancements, architectural changes, or evolving statutory requirements. When updates occur, the revised version will be published here with an updated Effective Date. For material modifications affecting your privacy rights, we will provide conspicuous notice on the service or via email prior to the changes taking effect.
For inquiries regarding data governance, export requests, exercise of privacy rights, or grievance redressal under the Digital Personal Data Protection Act, 2023, please contact our Data Governance & Grievance team at:
TheRidCo (Founded by Ridit Bandyopadhyay)
Data Governance & Grievance Officer
bandyopadhyayridit@gmail.com
Jurisdiction: Kolkata, West Bengal, India
© 2026 TheRidCo. All rights reserved.