Bramwell · Privacy

Profile Data Privacy Notice

bramwell.app/privacy/profile-data
Effective 2026-05-02 · Last reviewed 2026-05-02

This is the notice-at-collection page for the Bramwell onboarding profile, satisfying CCPA §1798.100(b) and the analogous provisions in every active US comprehensive state privacy law (TX TDPSA, NE NDPA, RI DTA, DE DPDPA, NH NHPA, MD MODPA, etc.).

This page is kept short on purpose. The longer-form privacy policy at bramwell.app/privacy covers the same ground in legal language; this page covers it in plain language at the moment you'd actually read it — when the wizard asks for a field.

Status, August 2026: the Cloud Pro and Cloud Luxury tiers referenced below are not yet available for purchase, so the opt-in fields they gate cannot currently be collected from anyone.

What we collect

The 12-field onboarding wizard collects:

Onboarding wizard fields
#FieldRequired?Tier
1First nameRequiredAll paid tiers
2Time zoneRequiredAll paid tiers
3Default shipping addressOptional$5 Local Pro +
4Secondary shipping addressOptional$5 Local Pro +
5Phone numberOptional$5 Local Pro +
6Default payment-method nickname (e.g. "Chase Sapphire") — NOT card detailsOptional$5 Local Pro +
7Pets — species + brand preferenceOptional$5 Local Pro +
8Home-delivery preferences — gate code, leave-at-doorOptional$5 Local Pro +
9Dietary restrictions / allergiesOptional$5 Local Pro +
10Frequent merchants — e.g. Amazon account email, Costco membership flag, dentist's nameOptional$5 Local Pro +
11Calendar provider — Google / iCloud / Outlook (no auth tokens at this step)Optional$5 Local Pro +
12Email provider — Gmail / iCloud / Outlook (no auth tokens at this step)Optional$5 Local Pro +

Opt-in only at $20 Cloud Pro:

Opt-in only at $40 Cloud Luxury:

Every wizard field except first name + time zone defaults to "Skip — Alfred will ask when he needs this." The wizard works as advertised even if you click Skip on every screen.

Why we collect it

One sentence per field — the actual reason Alfred would re-ask you in chat if you didn't tell us:

How long we keep it

Until you delete it. No automatic expiration on profile fields — the whole point is that Alfred remembers them.

The one exception: the agent action audit log (agent_action_log) retains for 1 year after creation, even after a "forget me" deletion. This is documented to you upfront. It's the contemporaneous evidence record we hand to a lawyer if a vendor disputes something Alfred did on your behalf, and a 1-year window covers the chargeback / dispute SLA on every major payment processor. After 1 year the row is hard-deleted by the retention sweep.

Retention by storage layer:

Retention by storage layer
SurfaceRetentionNotes
Profile rows (AppSettingEntity)Until you deletePlaintext + AES-256-GCM by sensitivity tier
Memory rows (AlfredMemoryService)Until you deleteWhat Alfred has learned about you
Notes (BrowserNotes)Until you deleteMarkdown artifacts from errands
Files (BrowserFiles)Until you deleteReceipts, PDFs, statements
Audit log (agent_action_log)1 yearLegal-hold exception; documented upfront
Screenshot bucket (R2)30 days rollingPer-task screenshots auto-delete
Third-party cookies / sessionsBramwell can't deleteWe list the merchants you've logged into, with deep-links to each merchant's deletion page

How to delete it

The "Forget me" flow ships in your account settings. Operational target: 7 days to hard-delete across all rows we own (profile, memory, notes, files, screenshots). The 1-year audit-log retention is the only exception, and it's surfaced explicitly in the deletion confirmation.

You receive a signed deletion certificate (PDF) listing each system, row count, timestamp, and a hash of the deletion log.

What "Forget me" doesn't do: Bramwell can't reach into Amazon's database and delete the order Alfred placed for you, or unsubscribe you from Spotify. Third-party site state is not ours to delete. The certificate includes a list of merchants Alfred has logged into on your behalf, with deep-links to each merchant's privacy / deletion page.

Who we share it with

We do not sell your data. Period.

Profile data flows to LLM providers under zero-data-retention (ZDR) contracts when Alfred needs the field to complete an errand:

Data is sent on a per-errand basis using a knapsack-style relevance pattern — Alfred only sends the profile fields the current errand sub-category actually needs. Your medical context is never sent to an LLM unless the errand is medical-shaped and you opted into the medical-context field; your shipping address isn't sent to a research errand; etc.

Affirmative commitments

These are the things we promise NOT to do, and they go on this page — not buried in fine print — because they're the load-bearing trust commitments:

Contact

Privacy questions: [email protected]

California / Texas / Maryland / state-specific rights: the same address, or the deletion flow in your account settings

This notice is a Phase 1 launch document and may be updated. Material changes are notified by email and via in-app banner with a 30-day comment window before they take effect.