Second Brain
PrivacyTermsBack to app

App Privacy Policy

You choose before personal data is sent to an AI service.

This policy identifies the data Second Brain collects or processes, how it obtains that data, every purpose for using it, and each third party that can receive it.

Effective August 12, 2026Developer: Daniel Pustotin
Explicit permission, a local-only choice, and no tracking.

Second Brain does not send personal data to Cloudflare, OpenAI, or Anthropic unless you allow AI Data Sharing. You can decline and keep using local features, or withdraw later in Settings > Privacy & AI.

01

Who controls your data

Daniel Pustotin is the developer and data controller for Second Brain and the Second Brain managed service. Questions, access requests, and deletion requests can be sent to daniel.pustotin@gmail.com.

02

Data that stays local

Captures, transcripts after completion, receipts, settings, pending work, and the content-free privacy ledger are stored in the app's local data store. Notes remain Markdown in the folder you choose. Personal API keys are stored in Apple Keychain and are not received by Second Brain.

Apple processes data when you choose iCloud Drive, Reminders, Calendar, Siri, Shortcuts, Spotlight, notifications, or App Store subscriptions. Those services operate under your Apple account and Apple's policies.

03

AI permission and withdrawal

Before the first AI transfer, the app names the recipients and routes below, describes the data categories and purposes, and asks you to choose Allow AI Data Sharing or Use Without AI. A stored decision is tied to a disclosure revision. A material change to recipients, data categories, or purposes requires a new decision.

Declining blocks all AI content transfers. Withdrawing in Settings > Privacy & AI blocks future transfers, cancels pending uploads and provider jobs where possible, keeps local data and recordings, and returns AI features to a permission-required state. Removing a personal key or deleting the app also stops future direct requests from that installation.

04

What can be sent to AI providers

Typed and dictated content: text you enter or dictate, captures, questions, instructions, and the current text of a note you ask the app to edit. This data comes directly from your input or the local item you select.

Relevant context: bounded note titles, paths, metadata, excerpts, or bodies; relevant reminders and calendar events including titles, dates, list or calendar names, locations, and notes; and selected search or recent-activity context. The app selects this from your connected local sources only when needed for the requested feature.

Files and media: attachment names, file excerpts, extracted text, OCR text, and supported images that you attach or that are selected as relevant to the request.

Audio Data: voice recordings created with the microphone. Voice transcription is remote. There is no on-device transcription option in this release.

05

Why AI data is used

The selected data is used only to provide the feature you request or resume: capture organization and routing, Ask, semantic search, note editing, enrichment and reindexing, research, content generation, and remote voice transcription. AI content is not used by Second Brain for advertising, user profiling, or tracking.

Opening Ask displays static local starter suggestions. It does not upload note metadata merely because the screen was opened.

06

AI recipients and routes

Managed access: your device sends the selected request to the Second Brain service hosted on Cloudflare. Cloudflare processes the request as infrastructure provider, and the service forwards model content to OpenAI. Second Brain also sends pseudonymous subscription, App Attest, installation, product, expiration, usage-counter, and request-cost data to this service to verify access, prevent abuse, and enforce limits.

Personal-key text access: your device sends the selected request directly to OpenAI or Anthropic, depending on the provider you choose. The request is handled under your account and provider agreement.

Voice transcription: your recording is sent to OpenAI either directly with your OpenAI key or through the Cloudflare-hosted managed route. Anthropic does not receive voice recordings.

Second Brain requires processors acting on its behalf to use contractual, technical, and organizational protections consistent with or equal to the protections described in this policy. Cloudflare, OpenAI, Anthropic, and Google also maintain their own privacy and security programs. Personal-key processing is additionally governed by the agreement between you and that provider.

07

AI request handling and retention

The Cloudflare-hosted service forwards ordinary managed model requests with OpenAI application storage disabled. It does not write request bodies, attachment contents, audio, transcripts, or generated results to its Durable Object or D1 databases. It stores content-free account, entitlement, usage, security, and job metadata for service operation.

Long Ask, research, and generation operations can use OpenAI asynchronous application state. Second Brain stores a provider response identifier and content-free job metadata locally and in the managed service for recovery. After the app durably applies or discards the result, the service acknowledges the job and requests provider deletion. Local service job metadata expires after at most 24 hours if the app never acknowledges it.

Provider retention can continue under provider rules even after a deletion request. OpenAI states that API data is not used to train its models unless the customer opts in, that abuse-monitoring logs may retain customer content for up to 30 days by default, and that Responses API application state and background mode have endpoint-specific retention. Review the current OpenAI API data controls. Anthropic states that API inputs and outputs are deleted within 30 days by default, subject to listed exceptions and account controls. Review the current Anthropic retention information.

Before an audio upload, iOS may keep a WAV file and multipart upload file in app-owned storage so the transfer can continue in the background. They are removed after transcription succeeds and the local result is saved. A failed or cancelled transfer preserves the local recording with the capture so you can retry or delete it.

08

Firebase Analytics

Google Analytics for Firebase receives an app-instance identifier, approximate location, basic app and device information, stable screen names, low-cardinality feature categories, booleans, counts, and subscription outcomes. This information is produced automatically from app use and is used to measure adoption, reliability, and core product flows. Analytics data is retained for 14 months.

Analytics never receives capture text, transcripts, audio, chat messages, filenames, URLs, note or project titles, UUIDs, error messages, API keys, or attachment bytes. Second Brain disables advertising identifiers, IDFV collection, ad personalization, automatic screen reporting, Google Signals, Ads linking, and optional Google data sharing. Analytics is not used for advertising or tracking across apps or websites.

09

Firebase Crashlytics

Firebase Crashlytics receives crash stack traces, relevant app state, app and device information, installation and random session identifiers, and content-free Analytics breadcrumbs. This data is collected automatically when a crash occurs and is used only to diagnose and reduce crashes. Crash traces and associated identifiers are retained for 90 days before removal begins.

Second Brain does not set a Crashlytics user ID or attach custom logs, custom keys, captures, notes, transcripts, audio, chat messages, filenames, URLs, titles, API keys, or model content to crash reports.

10

Website submissions

The Second Brain website does not use advertising or analytics. If you submit the feedback form, the website receives the name, email address, message, and form source you enter. That information is used only to understand the feedback or reply to you and is retained until it is no longer needed for that purpose or you request deletion.

11

Deletion, security, and changes

You can delete local captures, notes, recordings, keys, or the app using the available app and system controls. You can request deletion of managed-service operational records or website submissions by emailing daniel.pustotin@gmail.com. Records may be retained where required for security, accounting, legal compliance, or dispute resolution.

Data is transmitted over HTTPS and access credentials are stored using platform security controls. No system can guarantee absolute security. Material policy changes will be posted here with a new effective date, and material AI disclosure changes will require permission again in the app.

Second Brain
Terms of UseProduct site