Privacy Policy

Last updated: August 10, 2026

Bracket ("Bracket", "we", "us") is an AI decision workspace for client projects, operated at use-bracket.com. This policy explains what we collect, how we use it, and the strict boundaries we apply to data from connected work sources such as Gmail, Figma, GitHub, Notion and Slack.

1. Information we collect

Account information

  • Email address and name (used for sign-in via email code and account communication).
  • Basic technical data: IP address, browser type, and usage analytics (pages viewed, features used) to improve the product.

Project content

The briefs, notes, decisions, documents and files you create inside Bracket. This content belongs to you.

Connected work sources (integrations)

When you connect an external source — a Gmail conversation, a Figma design file, a GitHub repository, a Notion page, a Slack channel — Bracket receives data from that provider through their official API, only after you explicitly authorize it via the provider's own sign-in (OAuth).

2. The source-level boundary — our core privacy promise

Bracket connects specific pieces of work, not your entire account. Even where a provider's authorization technically grants broader access, we enforce a strict boundary in our own systems:

  • We only read, store and process the specific sources you explicitly select (e.g. one email conversation, one design file, one repository).
  • We never ingest, index or analyze unrelated data from your connected account.
  • Listing screens (e.g. your recent conversations or files shown while you choose a source) are fetched transiently for selection and are not stored.
  • Every extracted insight in Bracket retains a reference to the exact source it came from, and is only visible to you.
  • You can disconnect any source at any time. Disconnecting stops all synchronization immediately and deletes the cached source content.

3. How we use connected-source data

Data from sources you select is used exclusively to power your project's intelligence:

  • Extracting requirements, decisions, deliverables, deadlines and open questions into your Project Memory.
  • Detecting meaningful changes (new client requests, deadline changes, potential scope creep) when the source updates.
  • Answering your questions about the project ("Ask Bracket"), always with citations to the underlying source.
  • Suggesting whether a newly connected source belongs to one of your existing projects.

We do not use connected-source data for advertising, we do not sell it, and we do not share it with third parties except the AI processing described below.

4. AI processing — no training on your data

  • Bracket sends relevant excerpts of your project content and selected sources to large-language-model providers (e.g. Anthropic Claude) strictly to generate the outputs you request.
  • Your content is used for inference only. It is never used to train Bracket's or any third party's AI models.
  • Humans do not read your connected-source data except with your explicit permission (e.g. a support request), or where required by law.

5. Google API Services — Limited Use disclosure

Bracket's use of information received from Google APIs (including Gmail data, accessed read-only) adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Gmail data is only used to provide the user-facing features described here: understanding the specific conversations you connect to a project.
  • We do not transfer Gmail data to third parties except as necessary to provide these features (AI inference), for security, or to comply with law.
  • We do not use Gmail data for advertising.
  • Humans do not read your Gmail data unless you give explicit permission, it is necessary for security, or required by law.

6. Provider-specific notes

  • Gmail: read-only access; only the conversations you select are stored and analyzed.
  • Figma: read-only file access; we read file structure (pages, frames, components), comments and version history of the files you select.
  • GitHub: we read repository metadata, README, issues and commit messages of the repositories you select.
  • Notion: we read only pages you grant access to during Notion's own authorization, and store only the pages you select.
  • Slack: we read only the channels/conversations you select, using permissions scoped to your own user account.

7. Security

  • Integration credentials (OAuth tokens) are encrypted at rest with dedicated keys, and never exposed to your browser or other users.
  • All data is transmitted over TLS (HTTPS).
  • Access to connected-source data is enforced per user and per project on our backend — no other Bracket user can see your sources or memory.
  • Client review links are unguessable tokens that expose only the final document you choose to share.

8. Retention & deletion

  • Project content and extracted memory are retained while your account is active.
  • Disconnecting a source immediately deletes its cached content and stops syncing; extracted memory remains on your project until you remove it.
  • Deleting a project deletes its content.
  • To delete your entire account and history, email support@use-bracket.com — we complete deletion within 48 hours.
  • You may also revoke Bracket's access at any time from the provider's own security settings (Google, Figma, GitHub, Notion, Slack); Bracket connections then stop working immediately.

9. Cookies & analytics

We use a session cookie to keep you signed in, and first-party analytics (page views, clicks, session duration) to understand product usage. We do not use third-party advertising trackers.

10. Children

Bracket is not directed at children under 16 and we do not knowingly collect their data.

11. Changes & contact

We'll notify you of material changes to this policy by email or in-product notice. Questions or requests: support@use-bracket.com.