Who is responsible
Brin is operated from Australia. This policy explains what Brin processes, why, where it is kept, and the choices available to you.
Information Brin uses
Health and fitness data
With your permission, Brin reads measurements and workouts from Apple Health. This can include sleep, heart rate, HRV, activity, body measurements, blood pressure, temperature, respiratory data and other categories you authorise.
Things you record
Brin can store journal entries, check-ins, symptoms, events, workouts, supplements, medications, experiments, goals and preferences that you choose to add.
Connected providers
If you connect a supported service such as WHOOP or Withings, Brin receives the provider data and account identifiers needed for that connection. Provider access is limited to the scopes shown when you authorise it.
Brin account
Supabase processes your email address, optional first name, authentication events and encrypted session credentials. Your password is handled by Supabase and is not available to Brin.
Account emails
Resend processes your email address and delivery information to send verification and password-reset messages from Brin.
Support
If you contact us, we use the information in your message to answer the request and keep an appropriate support record.
Where information is kept
Your Brin health history is held in the app’s local database, protected by iOS file protection and excluded from device and iCloud backup. Brin’s analytical engines and local coach operate on the device. Apple Health data remains governed by the permissions you choose in iOS.
Direct-provider access and refresh tokens must be handled by Brin’s backend so those connections can operate. They are encrypted and are not included in your export. The backend also keeps the minimum connection identifiers and operational timestamps needed to authorise, refresh, synchronise and disconnect a provider. A permanent server copy of your full Apple Health history is not created by default.
How information is used
- to show your measurements, trends, workouts and current state;
- to calculate personal baselines and find changes, associations and responses;
- to operate sign-in, account recovery and connected-provider services;
- to create exports and reports that you request; and
- to maintain security, investigate failures and meet legal obligations.
Brin does not sell health data, use it for advertising, or let advertising SDKs access it. Brin does not use HealthKit data for advertising or data-broker purposes.
Sharing and service providers
Information is shared only where needed to provide a feature you use, when you direct Brin to export or share something, when required by law, or to protect users and the service. Current service providers include Apple for HealthKit and device security, Supabase for account authentication, Resend for account email, and the providers you choose to connect. Those providers process information under their own terms and privacy policies.
Your choices
Permissions
Review or withdraw Apple Health permissions in iOS. Disconnect a direct provider from Brin or the provider’s own account settings.
Export
Create a newline-delimited JSON export of local observations, context, insights, experiments and coach history. Credentials and payment data are excluded.
Delete local data
Delete direct-provider observations or every local Brin record from Privacy & Data. Deleting local Brin data does not delete measurements held by Apple Health.
Delete your login
Delete your Brin account from the Account screen after re-entering your password. This permanently removes the Brin login, but does not remove health history held locally on your phone.
Retention and security
Local information remains until you delete it or remove the app. Account information remains until you delete the account, subject to limited security, backup or legal retention. Provider credentials remain until the connection is removed or the credential expires. Brin uses iOS Keychain for app sessions, encryption for provider credentials, short-lived OAuth state, access controls and least-privilege provider scopes. No system can guarantee absolute security.
Health information and children
Brin explains patterns in recorded data. It is not a medical device, does not diagnose, and is not a substitute for professional care or emergency services. Brin is not directed to children under 16, and we do not knowingly create accounts for them.
Changes and contact
We will update the date above when this policy materially changes. Questions, access or correction requests, and privacy complaints can be sent to privacy@getbrin.com. We may need to verify that a request relates to you before acting on it.