← Back to Bramble

Privacy Policy

Last updated: 2026-05-30 · Interim beta policy, pending professional review.

Bramble (“we”, “us”, “the app”) is operated by Fossier Studio. This policy explains what data we collect, why, and how you can control it. Contact: [email protected].

Who this applies to

Bramble is currently in private/closed beta. By creating an account and using the app, you agree to this policy. The app is not directed at children under 13, and we do not knowingly collect data from them.

What we collect

DataWhy
Account info — email, username, hashed passwordAuthentication, account recovery
Profile — display name, avatar, banner, bio, pronouns, statusTo populate your profile (all optional except username)
Messages & content — text, attachments, reactions, postsTo deliver the core chat service
Membership & presence — servers, online status, voice stateTo run servers, presence, and voice
Push tokens — Apple/Expo notification identifiersTo deliver notifications you enable
Diagnostic data — crash reports, error logs (Sentry)To diagnose and fix bugs
Technical metadata — IP address, timestampsSecurity, abuse prevention, rate limiting

We do not sell your personal data, and we do not use it for third-party advertising.

How we use it

To operate the core service (messaging, voice, servers, notifications); to keep it secure (rate limiting, abuse and spam prevention, moderation); to diagnose crashes and improve reliability; and to communicate with you about your account or the beta.

Passwords

Passwords are hashed with Argon2 and are never stored in plaintext or readable by us.

Third-party processors

We share the minimum data necessary with infrastructure providers that help run the service: Hetzner (server hosting, EU), Cloudflare (network proxy, TLS, DDoS protection), Apple / Expo (push delivery — push tokens only), and Sentry (crash and error reporting). These providers process data on our behalf under their own terms.

Data retention

Account and content data is retained while your account is active. Server logs and diagnostic data are retained for a limited operational window. When you delete your account, we remove or anonymize your personal data, except where we must retain limited records for legal or security reasons.

Your rights & choices

Depending on where you live (e.g. EU/UK under GDPR, California under CCPA), you may have additional rights. We will honor applicable rights — contact us to exercise them.

Security

We use TLS in transit, hashed passwords, rate limiting, and access controls. No system is perfectly secure; we cannot guarantee absolute security, especially during beta.

Changes

We may update this policy as the product evolves. Material changes will be announced in-app or by email. Continued use after an update means you accept it.

Contact

Questions or requests: [email protected].

Terms of Service →

Interim notice: this is good-faith boilerplate drafted for a private beta. It has not been reviewed by a lawyer. It will be replaced with a professionally reviewed policy before public launch.