the fine print, in plain words
Privacy Policy
the short version
- Braid runs on your own computers. Your agent conversations, your files, and any Google account data you connect stay on your devices.
- Braid's servers relay end-to-end encrypted traffic between your devices and store encrypted copies of the things you choose to share. We cannot read them. There is one exception, the optional Discord integration, explained below.
- When your AI agent reads something, that content goes to the AI provider you chose, under your own account with that provider. It does not pass through Braid's servers.
- The desktop and terminal apps send anonymous usage analytics and crash reports by default. You can turn this off; see Telemetry.
- We do not sell your data, show ads, or train AI models on your data.
- 1. Who we are
- 2. How Braid is built
- 3. What reaches our servers
- 4. Google user data
- 5. Telemetry
- 6. Third parties
- 7. How we use data
- 8. Retention and deletion
- 9. Security
- 10. Your choices and rights
- 11. Children
- 12. International transfers
- 13. Changes
- 14. Contact
1. Who we are
Braid is a product of Underhive Inc. ("Underhive", "we", "us"), a company based in Wilmington, Delaware, USA. Underhive operates the Braid apps (desktop app, terminal app, background service and mobile app), the website at iambraid.com and the service at api.iambraid.com, and is responsible for the personal data described in this policy.
Questions, requests and complaints about privacy go to [email protected].
2. How Braid is built
Most privacy policies describe what a company does with the data it collects. Most of this one describes data we never receive, because Braid is software that runs on your machines rather than a service that holds your data.
What stays on your machine
- Your agent conversations. Braid reads the conversation histories that coding agents such as Claude Code and Codex already keep on your computer. It does not upload them unless you explicitly share one (see Sharing).
- Braid's own data. Settings, the list of devices you have paired, journal summaries of your conversations, notes and similar state live in a
.braidfolder in your home directory. Journal summaries are produced by a small AI model that runs entirely on your device. - Secrets. Your Braid session and encryption keys are kept in your operating system's credential store (Keychain on macOS, Secret Service on Linux, Windows data protection). If no credential store is available, Braid falls back to a file that only your user account can read.
- Connected accounts. See Google user data.
Your AI agents and their providers
Braid does not run its own AI model in the cloud and does not hold an AI provider key for you. It drives the agent programs you have installed and signed in to yourself. When one of those agents reads a file, a message or anything else, the agent sends that content to its provider (for example Anthropic for Claude Code, or OpenAI for Codex) under your own account and your own agreement with that provider. That traffic goes directly from your machine to the provider. It does not pass through Braid's servers, and we never see it.
Your other devices
You can pair your own devices (another computer, your phone) with a machine running Braid. Paired devices talk to each other directly on your network where possible, and otherwise through our relay. Either way the traffic is end-to-end encrypted between the devices. A paired device has broad access to the machine it is paired with, including its conversations and a terminal, so only pair devices you own and control.
3. What reaches our servers
Account data
If you create a Braid account, our server stores:
- your email address, and a display name and avatar link if you set them;
- a hash of a login key that your device derives from your password. Your actual password is never sent to us;
- your public encryption key, and your private key in a form encrypted with a second key derived from your password. That second key never reaches us, so we cannot unlock your private key;
- session tokens for your signed-in apps and machines, with their creation and expiry times;
- the date the account was created.
Some features create an anonymous device account that is not tied to an email address until you claim it.
Relay
When two of your devices cannot reach each other directly, their traffic passes through our relay. It is encrypted end to end between the devices, and the relay does not store it. The relay necessarily sees which account and which machine identifiers (public keys) are connected, when, from which IP address, and how much data moves.
Sharing and sync
Nothing is synced to our servers by default. If you choose to share a conversation, a project or an item (such as a tool configuration) with someone, or to sync it to your account, your device encrypts it before upload. The keys are held by you and the people you share with. We store ciphertext that we cannot read.
We can still see metadata: who owns a shared object and who it is shared with, which agent it came from, a local identifier, how many entries it has, their sizes, and when they were uploaded.
Invite links carry the decryption key in the part of the link after the #, which browsers do not send to servers. Anyone who has the full link can read what it shares, so treat invite links like passwords.
Discord integration (the exception)
The Discord integration is optional. If you link your Discord account and start a Braid voice session in a Discord call, the Braid bot runs on our server, because that is how Discord bots work. In that case our server does handle unencrypted content:
- your voice audio from that call. It is captured only for linked users who have started a session, held in memory, pushed to your own machine, and discarded once your machine confirms receipt. Speech-to-text runs on your machine, not on our server;
- Discord messages and files that your agent reads or sends through the bot.
We also store your Discord user ID, username, display name and avatar reference to link the two accounts, and the ID and name of Discord servers where the bot is installed. Discord itself processes everything in a call under its own terms and privacy policy.
Push notifications
If you turn on notifications in the mobile app, your computer sends a generic notice (for example that a task needs attention), with a machine identifier and a task identifier, through Expo's push service and then Apple's or Google's. Notifications do not contain conversation text.
Server logs
Our server keeps ordinary request logs, which include IP addresses, request paths and times. We use them to operate and secure the service, and keep them only as long as needed for that. We have not set a fixed retention period yet.
The website
iambraid.com is a static site. We do not run analytics or advertising scripts on it and we set no cookies of our own. It is served through Cloudflare, which processes IP addresses and may set cookies that are strictly necessary for security.
Updates and downloads
Braid checks for and downloads updates from our releases on GitHub, and downloads on-device speech and language models from Hugging Face when a feature needs them. Those services see your IP address, as any download does.
4. Google user data
Status: Braid's personal assistant features, including Google account connection, are in development and are not generally available. This section describes how Braid handles Google data when a user connects a Google account. If that handling ever changes, we will update this policy before the change takes effect.
What Braid can access, and why
Connecting a Google account is optional. Braid asks for access per service, and you choose which to grant on Google's consent screen. Depending on what you grant, the Braid software on your device can access:
| Google data | Why Braid accesses it |
|---|---|
| Your email address and basic account identifier | To show which Google account is connected and keep multiple accounts apart. |
| Gmail: messages, threads, labels, drafts, and basic settings such as filters | So your assistant can find and read mail you ask about, summarise it, organise it, prepare drafts, and send mail you have approved. |
| Google Calendar: calendars and events | So your assistant can answer questions about your schedule and create or change events when you ask. |
| Google Contacts (read only) | To work out who people are, for example turning a name into an email address. |
| Google Tasks | To read, create and update your tasks when you ask. |
| Google Drive, Docs, Sheets and Slides: files and their content | So your assistant can find, read, create and edit documents when you ask. |
Where it is stored
- On your device, not on our servers. The Google sign-in happens between your device and Google. The resulting OAuth tokens are stored in your operating system's credential store on your own device. They are not sent to, or stored on, Braid's servers.
- Google data that Braid retrieves is processed on your device. Braid may keep a local index or cache on your device so the assistant can work. It is not uploaded to Braid's servers.
- Because we never receive your Google tokens or Google data, no one at Underhive can access them. There is nothing on our side for staff to look at.
How it is used
- Only to provide the user-facing features you asked for: reading, searching, summarising, organising, drafting and acting in your Google account at your direction.
- Sending an email requires your explicit approval of the exact message before it is sent.
- We do not sell Google user data.
- We do not use Google user data for advertising, including retargeting, personalised or interest-based ads.
- Braid does not use Google user data to develop, improve or train generalised AI or machine-learning models.
- We do not transfer Google user data to anyone except as described in the next section, or where you explicitly direct it, or where the law requires it.
Transfer to your AI provider
Braid's assistant works by driving the AI agent you have chosen on your machine. When that agent reads Google data to do what you asked (for example, reading a message so it can summarise it), the agent sends that content to its AI model provider, such as Anthropic or OpenAI, under your own account with that provider. This transfer is necessary to provide the feature. It goes directly from your device to the provider and does not pass through Braid's servers.
The provider handles that content under its own terms and privacy policy and the settings on your account with it, including any setting about model training. Braid does not control those; please review them. Braid is designed to keep a record on your device of which items were read by an AI model, so you can check.
Google data is not included in Braid's analytics, crash reports or push notifications.
Limited Use
Braid's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting Google
- Disconnecting the account in Braid asks Google to revoke the token, deletes the token from your device's credential store, and lets you delete Google-derived data Braid has kept on that device.
- You can also remove Braid's access at any time from your Google Account at myaccount.google.com/permissions. This works even if your device is lost or Braid is uninstalled.
- There is nothing to delete on Braid's servers, because Google data was never there.
5. Telemetry: analytics and crash reports
The Braid desktop app and terminal app send usage analytics and crash reports. This is on by default. Braid's background service does not send analytics or crash reports.
Usage analytics (PostHog)
- What: the names of actions in the app, such as "app started", "view opened", "conversation opened" (with which agent it came from, for example "claude"), "file opened" (with the file extension only), update, pairing and sharing events, and "action failed" (with an error message from which file paths are stripped). Each event carries a random ID generated for your installation, the app version, your operating system and processor type, and whether it came from the desktop or terminal app.
- What not: analytics are designed never to include conversation content, titles, file paths or file contents. The install ID is random and is not linked to your Braid account or email, and we do not build a personal profile from it.
- When: while the desktop or terminal app is running, in small batches.
Crash and error reports (Sentry)
- What: the error type, the error message (up to 1,000 characters, with your home folder path shortened to
~), a stack trace of Braid's code, the app version, and the same random install ID. At most 30 reports per session; repeats are dropped. - Be aware: error messages are written by software and can occasionally contain a fragment of what the app was handling at the time, such as a file name.
- When: when the desktop or terminal app hits an error or crashes.
As with any internet request, these reports reach PostHog and Sentry from your IP address.
How to turn it off
- Set the environment variable
BRAID_DISABLE_ANALYTICS=1before starting Braid. This turns off both analytics and crash reports. - Or set
"optOut": truein the file~/.braid/analytics.json. This turns off usage analytics and removes the install ID from crash reports. Crash reports themselves are still sent unless you also set the environment variable above.
There is currently no switch for this inside the app.
6. Third parties
These are the outside companies involved in running Braid, and what each one handles.
| Who | What for | What they handle |
|---|---|---|
| Advika Web Developments Hosting Pvt Ltd (hosting provider, India) | Runs api.iambraid.com, its database and the website | Account data, encrypted shared content, metadata, server logs |
| Cloudflare | DNS, network security and proxying for iambraid.com and api.iambraid.com | Traffic to our site and server, including IP addresses. Shared content and relay traffic are already end-to-end encrypted inside it |
| PostHog | Usage analytics | The analytics events in section 5 |
| Sentry | Crash and error reports | The error reports in section 5 |
| GitHub | Hosts Braid releases and updates | Download requests |
| Hugging Face | Hosts on-device models Braid downloads | Download requests |
| Expo, Apple, Google (push) | Mobile push notifications, if you turn them on | Generic notification text, machine and task identifiers, your push token |
| Discord | The Discord integration, if you use it | Everything in the Discord call or channel, under Discord's own terms |
Providers you choose, under your own account. The AI model provider behind the agent you use (such as Anthropic or OpenAI) and the accounts you connect (such as Google) are not our sub-processors. You have your own relationship with them, and the content goes from your device straight to them.
We may also disclose information if the law requires it, or if Braid is involved in a merger or sale, in which case this policy continues to apply to data already collected. Given how Braid is built, what we could hand over is limited to what section 3 lists.
7. How we use the data we do have
- Account data: to sign you in, connect your devices to each other, and deliver things shared with you.
- Encrypted shared content and metadata: to store and deliver it, and to enforce size and rate limits.
- Analytics and crash reports: to understand which features are used and to fix bugs.
- Logs: to operate, secure and debug the service.
- Your email address: to contact you about your account or important changes. We do not send marketing email without asking first.
We do not sell personal data, we do not share it for advertising, and we do not use it to train AI models.
8. Retention and deletion
- Data on your machines stays until you delete it. Removing Braid's
.braidfolder from your home directory removes Braid's local data. Your agents' own conversation histories belong to those agents and are not deleted by Braid. - Google connection: see Disconnecting Google above.
- Relay traffic is not stored.
- Discord voice audio is held in memory only until your machine confirms it has received it.
- Account data and encrypted shared content are kept while your account exists. From within Braid you can remove people from things you have shared, revoke invite links and delete shared items.
- Deleting your Braid account: email [email protected] from the address on the account. Within 30 days we will delete the account and the data stored under it from our live database, including encrypted shared content you own, sessions and Discord links. Self-serve deletion inside the app is not built yet.
- Retention periods: we have not set fixed retention periods yet. Account data and synced data are kept until you ask us to delete them. Server logs and backups are kept only as long as needed to operate and secure the service, so deleted data may remain in backups for a limited time after it is removed from the live database.
- Analytics and crash reports are kept by PostHog and Sentry according to their own default retention settings. Because they are tied only to a random install ID, we generally cannot find yours unless you send us the ID from
~/.braid/analytics.json.
One honest limitation: if you shared something with another person, they hold a key to it, and they may have kept their own copy. Removing them stops future access through our server but cannot erase what they already saved.
9. Security
What Braid actually does:
- End-to-end encryption, using the libsodium library, for traffic between your paired devices and for everything you share or sync. Keys are generated on your devices.
- Your password never leaves your device. Your device derives two separate keys from it with Argon2id: one to sign in, one to protect your private key. The server only ever receives the first.
- Secrets are kept in the operating system's credential store where one is available.
- TLS for all connections to our servers, rate limiting on sign-in and pairing requests, and short-lived, single-use pairing codes and links.
- Machine credentials with reduced privileges, so that a paired machine never holds your full account session.
- When you share with someone, Braid pins their public key on your device, so it cannot be silently swapped later.
What Braid does not do, so you can plan for it:
- Braid does not add its own encryption to most of the data it keeps on your disk. Like your agents' own files, it relies on your user account and your operating system's disk encryption (FileVault, BitLocker, LUKS). Please turn disk encryption on.
- Other software running under your user account, including AI agents that can run commands, can read what you can read. Braid cannot protect you from software you run on your own machine.
- AI agents can make mistakes, and can be misled by instructions hidden in content they read, such as an email or a web page. Review what your agents do, especially anything that sends, deletes or spends.
- Removing someone from a shared item does not re-encrypt it with a new key.
No system is perfectly secure. If you find a vulnerability, please write to [email protected]. If we learn of a breach affecting your data, we will tell you as the law requires.
10. Your choices and rights
- You can use Braid locally without creating an account. Accounts are needed for sharing, relay and the mobile connection over the internet.
- You can turn off telemetry (section 5), disconnect Google (section 4) and unpair devices at any time. To unlink a Discord account, email us.
- Depending on where you live, you may have legal rights to access, correct, export or delete your personal data, to object to or restrict certain processing, and to complain to your data protection authority. To use any of these, email [email protected]. We will not treat you differently for doing so.
For end-to-end encrypted content we can give you or delete the ciphertext, but we cannot read it for you.
11. Children
Braid is not directed to children. It is not intended for anyone under 13, or under 16 where local law sets that age for consenting to data processing. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.
12. International transfers
Underhive is based in the United States. Our server is currently hosted in India, so account data and encrypted shared and synced data are stored on servers in India. If that changes, we will update this policy. Usage analytics go to PostHog, which receives them in the United States. Crash reports go to Sentry, which receives them in the European Union (Germany). Cloudflare, which sits in front of our site and server, operates a global network. By using Braid you understand that the limited data described in this policy is processed in those countries, which may have different data protection rules from the country you live in.
13. Changes to this policy
We will update this policy when Braid changes, and change the effective date at the top. If a change materially affects how your data is handled, in particular anything about Google user data or about what our servers can see, we will tell you in the app or by email before it takes effect, and ask for your consent where the law or Google's policies require it.
14. Contact
Underhive Inc. (Braid)
Wilmington, Delaware, USA
[email protected]
Please contact us by email. It is the fastest way to reach us, and the one we monitor for privacy requests.
See also the Terms of Service, or go back to the home page.