Bramwell · Privacy
Profile Data Privacy Notice
This is the notice-at-collection page for the Bramwell onboarding profile, satisfying CCPA §1798.100(b) and the analogous provisions in every active US comprehensive state privacy law (TX TDPSA, NE NDPA, RI DTA, DE DPDPA, NH NHPA, MD MODPA, etc.).
This page is kept short on purpose. The longer-form privacy policy at bramwell.app/privacy covers the same ground in legal language; this page covers it in plain language at the moment you'd actually read it — when the wizard asks for a field.
Status, August 2026: the Cloud Pro and Cloud Luxury tiers referenced below are not yet available for purchase, so the opt-in fields they gate cannot currently be collected from anyone.
What we collect
The 12-field onboarding wizard collects:
| # | Field | Required? | Tier |
|---|---|---|---|
| 1 | First name | Required | All paid tiers |
| 2 | Time zone | Required | All paid tiers |
| 3 | Default shipping address | Optional | $5 Local Pro + |
| 4 | Secondary shipping address | Optional | $5 Local Pro + |
| 5 | Phone number | Optional | $5 Local Pro + |
| 6 | Default payment-method nickname (e.g. "Chase Sapphire") — NOT card details | Optional | $5 Local Pro + |
| 7 | Pets — species + brand preference | Optional | $5 Local Pro + |
| 8 | Home-delivery preferences — gate code, leave-at-door | Optional | $5 Local Pro + |
| 9 | Dietary restrictions / allergies | Optional | $5 Local Pro + |
| 10 | Frequent merchants — e.g. Amazon account email, Costco membership flag, dentist's name | Optional | $5 Local Pro + |
| 11 | Calendar provider — Google / iCloud / Outlook (no auth tokens at this step) | Optional | $5 Local Pro + |
| 12 | Email provider — Gmail / iCloud / Outlook (no auth tokens at this step) | Optional | $5 Local Pro + |
Opt-in only at $20 Cloud Pro:
- Medical context (see the separate Consumer Health Data Privacy Policy)
- Accessibility needs
- Travel preferences
- Subscription monitoring (separate consent gate; this implies Alfred will scan your inbox)
Opt-in only at $40 Cloud Luxury:
- Per-member household sub-profiles (Apple Family Sharing pattern — organizer invites, each member accepts on their own device)
- Children's-context fields (parent-provided about a named minor — never collected from the child)
Every wizard field except first name + time zone defaults to "Skip — Alfred will ask when he needs this." The wizard works as advertised even if you click Skip on every screen.
Why we collect it
One sentence per field — the actual reason Alfred would re-ask you in chat if you didn't tell us:
- First name — so Alfred can address you appropriately.
- Time zone — so "tomorrow morning" means the right thing.
- Default shipping address — so when you say "order more dog food," Alfred knows where to ship it.
- Secondary shipping address — for office or family-member deliveries without re-asking.
- Phone number — for delivery notifications and 2-factor SMS during checkout (the SMS itself is typed live in the browser; we never receive it).
- Payment-method nickname — so Alfred can say "I'll use the Chase Sapphire" without asking, and you can confirm in the live browser. We never store the card number itself.
- Pets — so "order more dog food" doesn't need to specify "the brand we usually get."
- Home-delivery preferences — so the agent can include "leave at door — gate code 1234" in the delivery notes.
- Dietary restrictions / allergies — so a food order or restaurant booking respects them automatically.
- Frequent merchants — so Alfred knows which merchants you have accounts with and can pause for login at the right place.
- Calendar provider — so meeting-scheduling errands route to the right calendar.
- Email provider — so receipts and confirmations land in the right inbox.
How long we keep it
Until you delete it. No automatic expiration on profile fields — the whole point is that Alfred remembers them.
The one exception: the agent action audit log (agent_action_log) retains for 1 year after creation, even after a "forget me" deletion. This is documented to you upfront. It's the contemporaneous evidence record we hand to a lawyer if a vendor disputes something Alfred did on your behalf, and a 1-year window covers the chargeback / dispute SLA on every major payment processor. After 1 year the row is hard-deleted by the retention sweep.
Retention by storage layer:
| Surface | Retention | Notes |
|---|---|---|
Profile rows (AppSettingEntity) | Until you delete | Plaintext + AES-256-GCM by sensitivity tier |
Memory rows (AlfredMemoryService) | Until you delete | What Alfred has learned about you |
Notes (BrowserNotes) | Until you delete | Markdown artifacts from errands |
Files (BrowserFiles) | Until you delete | Receipts, PDFs, statements |
Audit log (agent_action_log) | 1 year | Legal-hold exception; documented upfront |
| Screenshot bucket (R2) | 30 days rolling | Per-task screenshots auto-delete |
| Third-party cookies / sessions | Bramwell can't delete | We list the merchants you've logged into, with deep-links to each merchant's deletion page |
How to delete it
The "Forget me" flow ships in your account settings. Operational target: 7 days to hard-delete across all rows we own (profile, memory, notes, files, screenshots). The 1-year audit-log retention is the only exception, and it's surfaced explicitly in the deletion confirmation.
You receive a signed deletion certificate (PDF) listing each system, row count, timestamp, and a hash of the deletion log.
What "Forget me" doesn't do: Bramwell can't reach into Amazon's database and delete the order Alfred placed for you, or unsubscribe you from Spotify. Third-party site state is not ours to delete. The certificate includes a list of merchants Alfred has logged into on your behalf, with deep-links to each merchant's privacy / deletion page.
Who we share it with
We do not sell your data. Period.
Profile data flows to LLM providers under zero-data-retention (ZDR) contracts when Alfred needs the field to complete an errand:
- Anthropic (Claude API) — ZDR endpoint only
- OpenAI (Chat Completions / Responses) — ZDR-pre-approved tier
- Google Vertex AI (Gemini) — Vertex AI tier (no training on prompts)
- AWS Bedrock — when used, no data retained for training
Data is sent on a per-errand basis using a knapsack-style relevance pattern — Alfred only sends the profile fields the current errand sub-category actually needs. Your medical context is never sent to an LLM unless the errand is medical-shaped and you opted into the medical-context field; your shipping address isn't sent to a research errand; etc.
Affirmative commitments
These are the things we promise NOT to do, and they go on this page — not buried in fine print — because they're the load-bearing trust commitments:
- We do not sell your data. Not to advertisers, not to data brokers, not to anyone. Not the technical "sale" definition under CCPA/CPRA, not in any sense.
- We are not a HIPAA covered entity, and we do not collect PHI in the technical sense. Medical context you opt into is treated as "consumer health data" under WA MHMDA / Maryland MODPA — see the Consumer Health Data Privacy Policy for that subset.
- We never ask for your card number, your SSN, your passwords, your biometric data, or your driver's-license number. When an errand needs one of these, Alfred pauses and you type it directly into the live browser view. Bramwell never sees, stores, or logs the value.
Contact
Privacy questions: [email protected]
California / Texas / Maryland / state-specific rights: the same address, or the deletion flow in your account settings
This notice is a Phase 1 launch document and may be updated. Material changes are notified by email and via in-app banner with a 30-day comment window before they take effect.