Privacy policy · 28 September 2026

Your health history
stays yours.

Brin keeps the health history it analyses on your iPhone. A Brin login does not create a cloud backup of your measurements.

Who is responsible

Brin is operated from Australia. This policy explains what Brin processes, why, where it is kept, and the choices available to you.

Information Brin uses

Health and fitness data

With your permission, Brin reads measurements and workouts from Apple Health. This can include sleep, heart rate, HRV, activity, body measurements, blood pressure, temperature, respiratory data and other categories you authorise.

Things you record

Brin can store journal entries, check-ins, symptoms, events, workouts, supplements, medications, experiments, goals and preferences that you choose to add.

Connected providers

If you connect a supported service such as WHOOP or Withings, Brin receives the provider data and account identifiers needed for that connection. Provider access is limited to the scopes shown when you authorise it.

Brin account

Supabase processes your email address, optional first name, authentication events and encrypted session credentials. Your password is handled by Supabase and is not available to Brin.

Account emails

Resend processes your email address and delivery information to send verification and password-reset messages from Brin.

Support

If you contact us, we use the information in your message to answer the request and keep an appropriate support record.

Where information is kept

Your Brin health history is held in the app’s local database, protected by iOS file protection and excluded from device and iCloud backup. Brin’s analytical engines and local coach operate on the device. Apple Health data remains governed by the permissions you choose in iOS.

Direct-provider access and refresh tokens must be handled by Brin’s backend so those connections can operate. They are encrypted and are not included in your export. The backend also keeps the minimum connection identifiers and operational timestamps needed to authorise, refresh, synchronise and disconnect a provider. A permanent server copy of your full Apple Health history is not created by default.

How information is used

  • to show your measurements, trends, workouts and current state;
  • to calculate personal baselines and find changes, associations and responses;
  • to operate sign-in, account recovery and connected-provider services;
  • to create exports and reports that you request; and
  • to maintain security, investigate failures and meet legal obligations.

Brin does not sell health data, use it for advertising, or let advertising SDKs access it. Brin does not use HealthKit data for advertising or data-broker purposes.

Sharing and service providers

Information is shared only where needed to provide a feature you use, when you direct Brin to export or share something, when required by law, or to protect users and the service. Current service providers include Apple for HealthKit and device security, Supabase for account authentication, Resend for account email, and the providers you choose to connect. Those providers process information under their own terms and privacy policies.

Your choices

Permissions

Review or withdraw Apple Health permissions in iOS. Disconnect a direct provider from Brin or the provider’s own account settings.

Export

Create a newline-delimited JSON export of local observations, context, insights, experiments and coach history. Credentials and payment data are excluded.

Delete local data

Delete direct-provider observations or every local Brin record from Privacy & Data. Deleting local Brin data does not delete measurements held by Apple Health.

Delete your login

Delete your Brin account from the Account screen after re-entering your password. This permanently removes the Brin login, but does not remove health history held locally on your phone.

Retention and security

Local information remains until you delete it or remove the app. Account information remains until you delete the account, subject to limited security, backup or legal retention. Provider credentials remain until the connection is removed or the credential expires. Brin uses iOS Keychain for app sessions, encryption for provider credentials, short-lived OAuth state, access controls and least-privilege provider scopes. No system can guarantee absolute security.

Health information and children

Brin explains patterns in recorded data. It is not a medical device, does not diagnose, and is not a substitute for professional care or emergency services. Brin is not directed to children under 16, and we do not knowingly create accounts for them.

Changes and contact

We will update the date above when this policy materially changes. Questions, access or correction requests, and privacy complaints can be sent to privacy@getbrin.com. We may need to verify that a request relates to you before acting on it.