Privacy Policy
- Last Updated: September 10, 2026
- Effective Date: September 10, 2026
Brim is a budget app that keeps your financial data private. This policy explains what data we collect, why we need it, and how we protect it.
TL;DR: There’s no account and no sign-in. Your financial data stays on your device. We collect minimal analytics to improve the app. You have full control. We don’t sell anything.
- Data Controller: Lazare Kolebka
- Email: hello@getbrim.app
- Address: Rue Georges Rency, 28, 1200 Brussels, Belgium
Your Financial Data
Stays on your device. We never see it.
Your transactions, budgets, and spending history are stored only on your iPhone/iPad using SwiftData. If you enable iCloud sync, Apple encrypts this data end-to-end - even Apple can’t read it. We don’t collect it, receive it, or store it anywhere.
What Data We Collect
Usage Analytics
We collect anonymous data to fix bugs and improve the app:
- Which screens you visit
- Which features you use
- Crash reports
- Device type and iOS version
- Country/city (from IP address, not GPS)
We don’t collect:
- Your transaction amounts
- Your budget numbers
- Your spending data
- Anything that identifies you personally
Analytics uses random device IDs that aren’t linked to you. We can see “someone opened the Budget screen” but not who you are or what numbers you’re looking at.
- Stored in: Frankfurt, Germany (EU only)
- Deleted after: 1 year automatically
Subscriptions
- Purchase history and renewal dates
- Transaction IDs from Apple
- Device information
Apple handles all payments. We never see your credit card or payment details.
Why We Collect This Data
| What | Why | Legal Basis (GDPR) |
|---|---|---|
| Analytics | Fix bugs, improve features | Legitimate Interest |
| Subscriptions | Manage your access to premium features | Contract Performance |
| IP addresses | Prevent fraud, security monitoring | Legitimate Interest |
About Analytics and Legitimate Interest
We use analytics to make Brim better - find bugs, see which features work, decide what to build next. Your privacy is protected because:
- No financial data in analytics
- Random IDs that can’t identify you
- Stays in EU, deleted after 1 year
- Easy opt-out in Settings
You can object to analytics anytime (see Your Rights below).
Third-Party Services
We use these services to run Brim:
PostHog - Usage analytics
- Location: Frankfurt, Germany (EU only)
- Privacy policy: https://posthog.com/privacy
RevenueCat - Subscription management
- Location: United States
- Protection: EU-US Data Privacy Framework and Standard Contractual Clauses
- Privacy policy: https://www.revenuecat.com/privacy
Apple iCloud - Optional sync (you control this)
- Encryption: End-to-end encrypted, only you can access
- Privacy policy: https://www.apple.com/legal/privacy/
Your iCloud data, financial or otherwise, is not collected or accessible by us.
All these services act as processors under GDPR-compliant agreements.
Your Rights
Your financial data lives only on your device, so we have no copy to act on - access, correction, and deletion happen directly in the app, not through us:
- See your data - Settings → Data → Export
- Fix incorrect data - Edit directly in the app
- Delete your data - Delete it directly in the app, or delete the app
- Turn off analytics - Settings → Privacy → Share Analytics
- Any other question - Email hello@getbrim.app
Important: Analytics uses random device IDs that aren’t linked to you, so we have no way to trace a specific person’s analytics back to them - which means we can’t act on an emailed request to access or delete “your” analytics data individually. The in-app toggle above is how you turn off that processing. It auto-deletes after 1 year regardless.
California and Other US States
If you’re in California, Virginia, Colorado, Connecticut, or Utah, you have similar rights under state privacy laws. We don’t sell your data.
File a Complaint
If you think we’ve violated your privacy rights:
- Belgium: Commission for the Protection of Privacy - https://www.privacycommission.be, contact@apd-gba.be
- UK: Information Commissioner’s Office - https://ico.org.uk
- US: Your state attorney general
Response time: 30 days (GDPR), 45 days (US state laws)
How Long We Keep Data
| Data | How Long | Why |
|---|---|---|
| Financial data (your device) | Until you delete it | Your budgets |
| Analytics | 1 year | Improve the app |
| Subscriptions | 6 years after it ends | Belgian tax law |
| IP addresses | 30 days | Security |
| Crash logs | 90 days | Fix bugs |
When you erase your data:
- Device and iCloud data: gone immediately
- Analytics: up to 1 year (can’t be traced to you)
- Subscription records: kept 6 years (legal requirement)
Security
We protect your data with:
- Encryption for everything in transit
- End-to-end encryption for iCloud sync
- No accounts, no passwords, nothing to leak in a breach
- iOS app sandboxing
- Regular security updates
You should:
- Enable Face ID/Touch ID
- Keep iOS updated
- Use two-factor authentication on your Apple ID
If there’s a breach: We’ll notify you and the Belgian Data Protection Authority within 72 hours if your rights are at risk. Your financial data wouldn’t be affected since it never reaches our servers.
Children’s Privacy
You must be at least 13 years old to use Brim (or older if your country requires it), consistent with the age rating Brim carries on the App Store.
If we discover underage use, we’ll direct you to erase that data immediately.
International Transfers
One service (RevenueCat) is in the United States. Your data is protected by:
- EU-US Data Privacy Framework
- Standard Contractual Clauses
- Industry-standard encryption
PostHog stays in EU - analytics never leave Germany. Your financial data never leaves your device and personal iCloud.
AI-Powered Insights
Apple Intelligence processes your financial data entirely on your device to provide insights like spending patterns and budget recommendations. Your data never leaves your device for AI processing. Apple cannot access this data, and neither can we.
You can disable AI-powered insights anytime in Settings → Privacy → AI Insights.
We do not use automated decision-making that produces legal or similarly significant effects on you. AI insights are purely informational and you retain full control over all financial decisions.
Changes to This Policy
We’ll update this page and the “Last Updated” date above whenever this policy changes.
Material changes include collecting new data types, sharing with new parties, moving data to new countries, or reducing security. Check back periodically to stay informed.
Continuing to use Brim after changes means you accept them. If you disagree, stop using Brim and erase your data before the changes take effect.
What We Don’t Do
- Sell your data
- Share your financial information
- Use your data for ads
- Track you across other apps
- Link analytics to your identity
- Store financial data on our servers
- Require an account or sign-in to use Brim
Contact
- Email: hello@getbrim.app
- Website: https://getbrim.app
Legal Compliance
This policy complies with GDPR (Regulation EU 2016/679), Belgian Law of 30 July 2018, ePrivacy Directive 2002/58/EC, UK GDPR, CCPA/CPRA, and other US state privacy laws.