Skip to content

Legal

Privacy Policy

Last updated:

Overview

Brush (“we”, “our”, or “us”) is a location-aware task manager available on Android and iOS. We alert you when you are near a place tied to one of your tasks. To do that, we need to know where you are. This policy explains exactly what we collect, why, and how you can control it.

We do not sell your data. We do not serve ads. We collect only what is necessary for the service to work.

Data we collect

We collect the following categories of data:

  • Location — precise GPS coordinates, used to detect proximity to tagged places.
  • Tasks — titles, place tags, categories, and completion status you enter in the app.
  • Account — email address and display name (or equivalent from your sign-in provider).
  • Device tokens — push-notification tokens issued by FCM (Firebase Cloud Messaging).
  • Usage telemetry — crash reports and anonymised feature-usage events via Firebase Analytics. No personally identifiable information is attached.

We do not collect contacts, photos, or microphone input.

Location data

Why we need it

Brush’s defining feature is proximity detection: when you walk within a configurable radius (default 75 m) of a place you have tagged, we surface a hero alert so the task is front and centre. Without location access, proximity alerts cannot work.

Always-on permission

To deliver background alerts — even when the app is closed — we request the “Always allow” location permission on both Android and iOS. The OS surfaces a system prompt explaining this before we ever read your coordinates. You can downgrade to “While in use” at any time in Settings; proximity alerts will then only fire while the app is open.

Geofencing

We use the platform’s native geofencing APIs (Android Geofence API, iOS CoreLocation region monitoring) to detect entry into place regions. The device calculates entry locally; we do not stream raw GPS coordinates to our servers in real-time. Entry events are sent to Firebase Firestore solely to trigger the notification.

Retention

Location data is used to compute proximity and is not stored beyond the session in which the alert fires.

Account & task data

Your account and task data is stored in Google Firebase Firestore, isolated to your user ID. We use Firebase Authentication for sign-in (email/password or third-party OAuth providers). Task data — titles, place tags, categories, completion state — is stored server-side so it syncs across your devices.

We do not share your task content with other users unless you explicitly use the “Brush to a friend” feature, in which case only the task you choose to share is transmitted.

Push notifications

Proximity alerts are delivered via Firebase Cloud Messaging (FCM). We store your device’s FCM token in Firestore, linked to your account, so notifications reach the right device. Tokens are rotated when FCM renews them and are deleted when you sign out or delete your account.

You can disable notifications at any time from the iOS or Android system settings. Disabling notifications turns off proximity alerts but does not delete your data.

Third-party services

We use the following third-party services:

  • Google Firebase (Auth, Firestore, FCM, Analytics, Crashlytics) — infrastructure and telemetry. Governed by Google’s Privacy Policy.
  • Google Maps / Apple Maps— “Open in Maps” deep-links hand off to the system maps app. We pass only the place coordinates you already tagged.
  • Google Calendar / Google Tasks— if you use the import feature, we request read-only OAuth access to your calendar or task list. We read event/task titles and dates to create Brush tasks; we do not write back to Google’s services.

We have no advertising or data-broker relationships. None of your data is sold or licensed to third parties.

Data retention

We keep your account and task data for as long as your account is active. If you delete your account from within the app, all Firestore data linked to your user ID — tasks, place tags, settings, FCM tokens — is deleted within 30 days.

Anonymised analytics data (crash logs, feature-usage events) is retained for up to 14 months in Firebase Analytics, after which it is automatically purged.

Your rights

Depending on your jurisdiction, you may have the right to access, correct, port, or erase personal data we hold about you. To exercise any of these rights:

  • Delete account & data — available directly inside the app under Settings → Account → Delete account.
  • Export your tasks — available under Settings → Export.
  • Other requests — email us at [email protected]. We will respond within 30 days.

If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.

Children

Brush is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

Policy changes

We may update this policy when we add new features or when applicable law changes. When we do, we will update the “Last updated” date at the top and, for material changes, notify you via in-app notice or email before the change takes effect.

Contact

Questions about this policy or how we handle your data? Reach us at [email protected].

← Back to Brush