Privacy Policy

Last updated: March 31, 2026

1. Overview

Cerebro ("we," "our," or "the app") is an AI-powered second brain that helps you capture, organize, and resurface your thoughts. This policy explains what data we collect, how we use it, and your rights regarding that data.

2. Information We Collect

Account Information

  • Email address
  • First name
  • Authentication credentials (managed by Clerk)

Content You Create

  • Journal entries and thoughts you write
  • AI-extracted action items (todos)
  • AI-generated memory document (an evolving summary of your patterns and priorities)
  • Semantic connections between your entries

Technical Data

  • Device timezone (IANA format, for notification scheduling)
  • Push notification token (if notifications are enabled)
  • Theme preference (light/dark, stored locally on your device)

Subscription Data

  • Subscription status and entitlements (managed by RevenueCat)
  • We do not directly collect or store payment details — billing is handled by the Apple App Store and Google Play Store

3. How We Use Your Data

  • AI Processing: Your entries are processed by AI models (Google Gemini and OpenAI) to extract action items, build semantic connections, generate your memory document, and create vector embeddings for search.
  • Notifications: We use your timezone and push token to deliver smart resurface notifications at appropriate times (respecting quiet hours between 10 PM and 8 AM), limited to 2 per day.
  • Search: Vector embeddings of your entries enable semantic search, allowing you to find thoughts by meaning rather than exact keywords.
  • Authentication: Your email and name are used to identify your account and personalize the experience.

4. Third-Party Services

We use the following third-party services to operate Cerebro:

ServicePurpose
ClerkAuthentication (email, Google, Apple sign-in)
ConvexCloud database and backend
Google GeminiAI analysis of entries
OpenAIText embeddings for semantic search
RevenueCatSubscription and entitlement management
Expo PushPush notification delivery
VercelWebsite hosting and analytics

Your entry content is sent to Google Gemini and OpenAI solely for processing — it is not used to train their models when accessed via API.

5. Data Storage and Security

  • Your data is stored in Convex's cloud infrastructure. Authentication tokens are encrypted and stored securely on your device via Clerk.
  • All data in transit is encrypted using TLS. Local preferences (theme, onboarding status) are stored on-device using MMKV.
  • We do not store your data on our own servers — all persistent data resides in Convex's managed cloud platform.

6. Data Retention

Your entries, memory document, todos, and embeddings are retained for as long as your account is active. If you delete your account, all associated data will be permanently removed from our systems.

7. Your Rights

  • Access: You can view all your data within the app at any time.
  • Deletion: You may request complete deletion of your account and all associated data by contacting us.
  • Notifications: You can disable push notifications at any time via the app settings or your device settings.
  • Portability: You may request an export of your data by contacting us.

8. Children's Privacy

Cerebro is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us.

9. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by posting the updated policy in the app or on our website.

10. Contact Us

If you have questions about this privacy policy or your data, please contact us at info@henrypl.com.