the fine print, in plain words

Privacy Policy

Effective 20 September 2026 (2026-09-20) · Last updated: 20 September 2026

the short version

  1. 1. Who we are
  2. 2. How Braid is built
  3. 3. What reaches our servers
  4. 4. Google user data
  5. 5. Telemetry
  6. 6. Third parties
  7. 7. How we use data
  8. 8. Retention and deletion
  9. 9. Security
  10. 10. Your choices and rights
  11. 11. Children
  12. 12. International transfers
  13. 13. Changes
  14. 14. Contact

1. Who we are

Braid is a product of Underhive Inc. ("Underhive", "we", "us"), a company based in Wilmington, Delaware, USA. Underhive operates the Braid apps (desktop app, terminal app, background service and mobile app), the website at iambraid.com and the service at api.iambraid.com, and is responsible for the personal data described in this policy.

Questions, requests and complaints about privacy go to [email protected].

2. How Braid is built

Most privacy policies describe what a company does with the data it collects. Most of this one describes data we never receive, because Braid is software that runs on your machines rather than a service that holds your data.

What stays on your machine

Your AI agents and their providers

Braid does not run its own AI model in the cloud and does not hold an AI provider key for you. It drives the agent programs you have installed and signed in to yourself. When one of those agents reads a file, a message or anything else, the agent sends that content to its provider (for example Anthropic for Claude Code, or OpenAI for Codex) under your own account and your own agreement with that provider. That traffic goes directly from your machine to the provider. It does not pass through Braid's servers, and we never see it.

Your other devices

You can pair your own devices (another computer, your phone) with a machine running Braid. Paired devices talk to each other directly on your network where possible, and otherwise through our relay. Either way the traffic is end-to-end encrypted between the devices. A paired device has broad access to the machine it is paired with, including its conversations and a terminal, so only pair devices you own and control.

3. What reaches our servers

Account data

If you create a Braid account, our server stores:

Some features create an anonymous device account that is not tied to an email address until you claim it.

Relay

When two of your devices cannot reach each other directly, their traffic passes through our relay. It is encrypted end to end between the devices, and the relay does not store it. The relay necessarily sees which account and which machine identifiers (public keys) are connected, when, from which IP address, and how much data moves.

Sharing and sync

Nothing is synced to our servers by default. If you choose to share a conversation, a project or an item (such as a tool configuration) with someone, or to sync it to your account, your device encrypts it before upload. The keys are held by you and the people you share with. We store ciphertext that we cannot read.

We can still see metadata: who owns a shared object and who it is shared with, which agent it came from, a local identifier, how many entries it has, their sizes, and when they were uploaded.

Invite links carry the decryption key in the part of the link after the #, which browsers do not send to servers. Anyone who has the full link can read what it shares, so treat invite links like passwords.

Discord integration (the exception)

The Discord integration is optional. If you link your Discord account and start a Braid voice session in a Discord call, the Braid bot runs on our server, because that is how Discord bots work. In that case our server does handle unencrypted content:

We also store your Discord user ID, username, display name and avatar reference to link the two accounts, and the ID and name of Discord servers where the bot is installed. Discord itself processes everything in a call under its own terms and privacy policy.

Push notifications

If you turn on notifications in the mobile app, your computer sends a generic notice (for example that a task needs attention), with a machine identifier and a task identifier, through Expo's push service and then Apple's or Google's. Notifications do not contain conversation text.

Server logs

Our server keeps ordinary request logs, which include IP addresses, request paths and times. We use them to operate and secure the service, and keep them only as long as needed for that. We have not set a fixed retention period yet.

The website

iambraid.com is a static site. We do not run analytics or advertising scripts on it and we set no cookies of our own. It is served through Cloudflare, which processes IP addresses and may set cookies that are strictly necessary for security.

Updates and downloads

Braid checks for and downloads updates from our releases on GitHub, and downloads on-device speech and language models from Hugging Face when a feature needs them. Those services see your IP address, as any download does.

4. Google user data

Status: Braid's personal assistant features, including Google account connection, are in development and are not generally available. This section describes how Braid handles Google data when a user connects a Google account. If that handling ever changes, we will update this policy before the change takes effect.

What Braid can access, and why

Connecting a Google account is optional. Braid asks for access per service, and you choose which to grant on Google's consent screen. Depending on what you grant, the Braid software on your device can access:

Google dataWhy Braid accesses it
Your email address and basic account identifierTo show which Google account is connected and keep multiple accounts apart.
Gmail: messages, threads, labels, drafts, and basic settings such as filtersSo your assistant can find and read mail you ask about, summarise it, organise it, prepare drafts, and send mail you have approved.
Google Calendar: calendars and eventsSo your assistant can answer questions about your schedule and create or change events when you ask.
Google Contacts (read only)To work out who people are, for example turning a name into an email address.
Google TasksTo read, create and update your tasks when you ask.
Google Drive, Docs, Sheets and Slides: files and their contentSo your assistant can find, read, create and edit documents when you ask.

Where it is stored

How it is used

Transfer to your AI provider

Braid's assistant works by driving the AI agent you have chosen on your machine. When that agent reads Google data to do what you asked (for example, reading a message so it can summarise it), the agent sends that content to its AI model provider, such as Anthropic or OpenAI, under your own account with that provider. This transfer is necessary to provide the feature. It goes directly from your device to the provider and does not pass through Braid's servers.

The provider handles that content under its own terms and privacy policy and the settings on your account with it, including any setting about model training. Braid does not control those; please review them. Braid is designed to keep a record on your device of which items were read by an AI model, so you can check.

Google data is not included in Braid's analytics, crash reports or push notifications.

Limited Use

Braid's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting Google

5. Telemetry: analytics and crash reports

The Braid desktop app and terminal app send usage analytics and crash reports. This is on by default. Braid's background service does not send analytics or crash reports.

Usage analytics (PostHog)

Crash and error reports (Sentry)

As with any internet request, these reports reach PostHog and Sentry from your IP address.

How to turn it off

There is currently no switch for this inside the app.

6. Third parties

These are the outside companies involved in running Braid, and what each one handles.

WhoWhat forWhat they handle
Advika Web Developments Hosting Pvt Ltd (hosting provider, India)Runs api.iambraid.com, its database and the websiteAccount data, encrypted shared content, metadata, server logs
CloudflareDNS, network security and proxying for iambraid.com and api.iambraid.comTraffic to our site and server, including IP addresses. Shared content and relay traffic are already end-to-end encrypted inside it
PostHogUsage analyticsThe analytics events in section 5
SentryCrash and error reportsThe error reports in section 5
GitHubHosts Braid releases and updatesDownload requests
Hugging FaceHosts on-device models Braid downloadsDownload requests
Expo, Apple, Google (push)Mobile push notifications, if you turn them onGeneric notification text, machine and task identifiers, your push token
DiscordThe Discord integration, if you use itEverything in the Discord call or channel, under Discord's own terms

Providers you choose, under your own account. The AI model provider behind the agent you use (such as Anthropic or OpenAI) and the accounts you connect (such as Google) are not our sub-processors. You have your own relationship with them, and the content goes from your device straight to them.

We may also disclose information if the law requires it, or if Braid is involved in a merger or sale, in which case this policy continues to apply to data already collected. Given how Braid is built, what we could hand over is limited to what section 3 lists.

7. How we use the data we do have

We do not sell personal data, we do not share it for advertising, and we do not use it to train AI models.

8. Retention and deletion

One honest limitation: if you shared something with another person, they hold a key to it, and they may have kept their own copy. Removing them stops future access through our server but cannot erase what they already saved.

9. Security

What Braid actually does:

What Braid does not do, so you can plan for it:

No system is perfectly secure. If you find a vulnerability, please write to [email protected]. If we learn of a breach affecting your data, we will tell you as the law requires.

10. Your choices and rights

For end-to-end encrypted content we can give you or delete the ciphertext, but we cannot read it for you.

11. Children

Braid is not directed to children. It is not intended for anyone under 13, or under 16 where local law sets that age for consenting to data processing. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.

12. International transfers

Underhive is based in the United States. Our server is currently hosted in India, so account data and encrypted shared and synced data are stored on servers in India. If that changes, we will update this policy. Usage analytics go to PostHog, which receives them in the United States. Crash reports go to Sentry, which receives them in the European Union (Germany). Cloudflare, which sits in front of our site and server, operates a global network. By using Braid you understand that the limited data described in this policy is processed in those countries, which may have different data protection rules from the country you live in.

13. Changes to this policy

We will update this policy when Braid changes, and change the effective date at the top. If a change materially affects how your data is handled, in particular anything about Google user data or about what our servers can see, we will tell you in the app or by email before it takes effect, and ask for your consent where the law or Google's policies require it.

14. Contact

Underhive Inc. (Braid)
Wilmington, Delaware, USA
[email protected]

Please contact us by email. It is the fastest way to reach us, and the one we monitor for privacy requests.

See also the Terms of Service, or go back to the home page.