Privacy Policy & Data Governance

Privacy Policy

Effective Date: August 27, 2026 • Last Updated: September 3, 2026 • Policy Version: 2.0.0

Technical Transparency & Data Sovereignty: BRO is built by TheRidCo (founded by Ridit Bandyopadhyay). We operate on a foundation of user data control, minimal collection, and absolute transparency. We do not sell, rent, or trade your personal data to data brokers or advertising networks.

Notice Regarding AI Capabilities

BRO is an AI and it can make mistakes.

BRO provides conversational, voice, creative writing, and productivity assistance. Messages, queries, and multimodal inputs are processed using neural machine learning models to generate conversational responses. Please do not submit sensitive personal identifiers, passwords, or confidential medical/financial credentials into prompts or attachments.

Core Privacy Commitments

Your trust is essential to our companion architecture. We adhere strictly to the following foundational data principles:

Zero Sale of Personal Data

We never monetize your private conversations, prompts, voice recordings, uploaded files, or email addresses.

Privacy by Default

Optional analytics and personalization telemetry are disabled by default and require explicit affirmative user consent.

1. Information We Collect & Why

A. Account & Authentication Data

When you register for an account, we collect your email address, display name, account creation timestamp, and assigned user identifier via Supabase Auth. This information is essential to authenticate your identity, manage your session securely, enforce subscription quotas, and maintain your preferences.

B. Text Input & Conversation History

We process the text prompts and queries you submit to BRO to generate context-aware companion responses. Messages are stored in cloud PostgreSQL databases hosted on Supabase with Row-Level Security (RLS) policies enforcing that only your authenticated account can access, query, or delete your conversation sessions.

C. User Memory & Personalization Data

BRO features a user-directed memory system to recall facts, user preferences, projects, and goals across conversations. Memories are created when you explicitly command BRO (e.g. “remember this”) or via automated extraction when enabled in settings. You maintain direct control to inspect, edit, or delete memories at any time.

D. Uploaded Files, Images & Documents

When you attach supported files (images, PDFs, or plain text files) to your messages within plan limits, the file contents are formatted into inline data and transmitted to our AI inference engine (such as Google Gemini) solely to answer your questions and perform requested multimodal tasks. Uploads are stored within your conversation history and follow your conversation retention settings.

E. Subscription & Transaction Information

When you purchase a paid subscription (BRO Sync or BRO Presence), payment details are processed directly by our payment gateway, Razorpay. We store your subscription tier, billing cycle (monthly or annual), transaction IDs, currency, and renewal status in our database. We never receive or store complete credit/debit card numbers, CVVs, or banking credentials.

F. Technical, Usage & Security Logs

To maintain system reliability, rate limits, and security, our servers temporarily log network IP addresses, browser user agent strings, request timestamps, and API response statuses. This operational data is retained only as long as necessary for security auditing and rate enforcement.

2. Voice & Audio Processing

Voice and Audio Processing. When you use BRO's voice features, audio and/or related voice data may be processed by BRO and third-party voice service providers such as Cartesia to convert speech to text, generate responses, or synthesize speech, depending on the feature being used.

  • Speech Recognition (Speech-to-Text): In Voice Mode and Voice Focus, your microphone speech is converted to text locally through your browser's native Web Speech recognition interface. BRO does not record, intercept, or store raw microphone audio files on its application servers.
  • Voice Synthesis (Text-to-Speech): When BRO speaks responses aloud:
    • Signal Tier: Synthesized using your browser's native local SpeechSynthesis engine without external API calls.
    • Sync & Presence Tiers: For high-fidelity natural voices, response text is transmitted over secure HTTPS to Cartesia (Cartesia AI). Cartesia processes only the text string and chosen voice parameters necessary to render audio bytes, which are streamed back to your client for real-time playback. Cartesia does not receive your account identity or unrelated conversation records.

3. Third-Party Service Providers & Processors

We collaborate with reputable technology partners who process specific categories of data strictly on our behalf:

ProviderService FunctionData Transmitted
Google Cloud (Gemini)AI Language & Multimodal InferencePrompts, conversation context, attachments
CartesiaPremium Voice Generation (TTS)Text snippets for spoken playback (Sync/Presence)
SupabaseDatabase, Auth & Cloud StorageUser profiles, encrypted chat sessions, memories
RazorpayPayment Gateway & SubscriptionsBilling tokens, order amounts, payment confirmations
VercelApplication Hosting & Edge DeliveryEncrypted HTTP network traffic, transient edge logs

4. Cookies, Telemetry & Global Privacy Control (GPC)

We categorize cookies and client-side storage mechanisms into four distinct tiers:

  • Strictly Essential: Active by default. Necessary for authentication token storage, security verification (CSRF protection), and UI theme preferences. Cannot be turned off.
  • Analytics & Personalization: Disabled by default (“privacy-by-default”). If explicitly enabled via our cookie consent banner, privacy-scrubbed macro metrics (such as aggregate session latency or turn counts) are collected. No prompt text or personal tokens are ever sent to analytics pipelines.
  • Marketing Trackers: Completely prohibited. We do not deploy third-party advertising cookies, marketing tracking pixels, or cross-site behavioral tracking tools.
  • Global Privacy Control (GPC) & Do Not Track: BRO automatically detects and honors the browser-level Sec-GPC header and navigator.globalPrivacyControl signal. When detected, non-essential telemetry is automatically disabled.

5. Data Retention Schedule

We retain personal data only for as long as necessary to provide the service, comply with statutory obligations, and maintain platform security:

CategoryPurposeRetention WindowDeletion Mechanism
Account ProfileUser authentication & identityDuration of active accountAccount deletion request
ConversationsCompanion chat history & contextUntil deleted by userIn-app clear / Delete button
User MemoriesLong-term personalizationUntil deleted by userIn-app memory vault manager
Payment OrdersTax, accounting & legal complianceMandated statutory periodStatutory expiration
Consent LogsPrivacy compliance verification365 days rollingAutomated roll-off

6. Your Privacy Rights & Self-Service Controls

Under applicable data protection legislation (including India's Digital Personal Data Protection Act, 2023, the GDPR, and similar international laws), you possess meaningful rights regarding your personal information:

Right to Access & Inspect

Inspect all stored profile attributes, usage counters, and saved memory items directly within Settings → Privacy & Data.

Right to Data Portability (Export)

Download a complete, machine-readable JSON archive containing your profile, settings, memories, and full conversation transcripts at any time with a single click.

Right to Withdraw Consent

Revoke previously granted consent for analytics and personalization at any time through our interactive cookie banner or in-app settings.

Right to Erasure (Account Deletion)

Permanently delete your entire account, conversations, memories, profile, and authentication records via Settings → Privacy & Data.

7. Technical Security Safeguards

We implement comprehensive technical and administrative security measures to protect your personal data:

  • Encryption in Transit: All communications between your browser and our servers are encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS).
  • Tenant Isolation via Row-Level Security: Cloud database tables are secured using PostgreSQL Row-Level Security (RLS) policies, enforcing database-level isolation so that queries can only access records belonging to the authenticated account.
  • Server-Side Secret Isolation: Administrative service keys and AI provider credentials are restricted to server-side environments and never exposed in client bundles.
  • Webhook Signature Verification: Payment webhooks from Razorpay are verified using cryptographic SHA-256 HMAC signature validation before processing.

8. International Data Transfers

TheRidCo is based in India. To operate a high-availability AI platform, we utilize cloud infrastructure and API processors located in multiple jurisdictions, including India, the United States, and the European Union. When data is transferred across borders, we ensure appropriate safeguards are maintained by our hosting and API infrastructure partners in compliance with applicable data protection laws.

9. Children's & Minors' Privacy

  • General Eligibility: BRO is not directed to, marketed to, or intended for children under the age of 13.
  • Minors and Applicable Law: In accordance with India's Digital Personal Data Protection Act, 2023 (DPDPA) and international standards, individuals under 18 years of age may only access the service with verifiable parental or legal guardian consent and supervision.
  • No Targeted Behavioral Tracking of Minors: We strictly prohibit behavioral profiling, targeted tracking, or advertising directed at minors.
  • Deletion of Minor Data: If we learn that personal data of a child under 13 (or under 18 without parental consent) has been collected without verifiable authorization, we will take immediate steps to permanently delete that information from our systems. If you believe a minor has registered without consent, please contact us at bandyopadhyayridit@gmail.com.

10. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect technological enhancements, architectural changes, or evolving statutory requirements. When updates occur, the revised version will be published here with an updated Effective Date. For material modifications affecting your privacy rights, we will provide conspicuous notice on the service or via email prior to the changes taking effect.

11. Contact & Grievance Redressal

For inquiries regarding data governance, export requests, exercise of privacy rights, or grievance redressal under the Digital Personal Data Protection Act, 2023, please contact our Data Governance & Grievance team at:

TheRidCo (Founded by Ridit Bandyopadhyay)

Data Governance & Grievance Officer

bandyopadhyayridit@gmail.com

Jurisdiction: Kolkata, West Bengal, India

© 2026 TheRidCo. All rights reserved.