Privacy Policy
This Privacy Policy explains how Brimm.ai ("Brimm", "we", "us", or "our") collects, uses, stores, and protects your information when you use the Brimm mobile application (the "App"). Brimm is an AI-powered travel planning app that helps you create trip itineraries and understand visa requirements based on your passport and travel documents.
By creating an account and using Brimm, you agree to the practices described in this Privacy Policy.
If you have any questions, contact us at support@brimm.ai.
1. Who we are
Brimm.ai is an independent, founder-operated product. For the purposes of data protection law, Brimm is the "data controller" responsible for your personal information. You can reach us at support@brimm.ai for any privacy-related request or question.
2. Information we collect
We collect only the information needed to provide travel planning and visa guidance. Specifically:
Information you provide when you sign up and set up your profile: - Email address and password (used to create and secure your account) - Your name - Passport country (the country that issued your passport) - Visas and residence permits you hold (for example, a US or Schengen visa) — used to determine which destinations you can enter and under what conditions - Home country - Travel preferences (such as travel style, interests, and currency)
Information created as you use the App: - Trips and itineraries you generate or save - Destinations you add to your wishlist or recently viewed - Consent records (the date and version of the terms you agreed to)
Information collected automatically: - Basic technical information necessary for the App to function (such as your authentication session). We do not currently use third-party analytics or advertising trackers.
We do not collect payment card details in the App. Any purchases (such as a future subscription) are handled by the Apple App Store or Google Play, and are governed by their respective privacy policies.
3. How we use your information
We use your information to: - Create and secure your account - Generate personalized travel itineraries - Determine visa requirements and entry benefits specific to your passport and the documents you hold — this is the core feature of Brimm - Save and sync your trips and preferences across your devices - Respond to your support requests - Maintain a record that you agreed to our Terms of Service and this Privacy Policy
We do not sell your personal information. We do not use your data for third-party advertising. We do not share your passport or visa information with anyone except as needed to provide the features you request (see Section 4).
4. Third-party services we use
To provide Brimm's features, we share limited information with trusted service providers, only as necessary:
- Cloud database and authentication provider — securely stores your account and profile data. This data is hosted on servers located in the European Union (Frankfurt, Germany).
- AI language model provider — when you generate a trip, the details you provide (such as your destination, dates, and preferences) are sent to an AI service to create your itinerary. We do not send your email, password, or full identity to this provider.
- Visa information service — to check visa requirements, we send your passport country, held visa information, and destination to a third-party visa-data service. This is what powers Brimm's visa guidance.
- Image provider — used to display destination photos. This involves standard image requests and does not include your personal information.
- Affiliate booking partners — when you choose to tap a booking link (for example, for hotels, flights, or activities), you are redirected to that partner's website. We may earn a commission if you book. Any information you enter on their site is governed by their privacy policy, not ours. We never share your account data with them; the redirect simply opens their site.
Each of these providers processes data under their own privacy policies. We only share what is necessary for the specific feature you are using, and we do not share your passport or visa information with anyone other than the visa information service described above.
5. How your information is stored and protected
- Your data is stored securely on Supabase servers in the European Union.
- Passwords are handled by Supabase's authentication system and are never stored by us in readable form.
- API keys and sensitive credentials are kept on secure servers and are never exposed in the App.
- A copy of your data may be cached locally on your device so the App works smoothly and offline. This local copy is removed when you delete the App or your account.
While we take reasonable measures to protect your information, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. How long we keep your information
We keep your personal information for as long as your account is active. If you delete your account, we delete your associated personal data from our active systems, except where we are required to retain certain records (such as consent records) to comply with legal obligations.
7. Your rights
Depending on where you live, you may have the following rights over your personal information:
- Access — request a copy of the data we hold about you
- Correction — ask us to fix inaccurate information
- Deletion — ask us to delete your account and personal data
- Objection and restriction — ask us to limit how we use your data
- Portability — request your data in a portable format
- Withdraw consent — withdraw consent you previously gave, at any time
Much of this you can do directly in the App (editing your profile, or deleting your account). For any other request, email support@brimm.ai and we will respond within a reasonable time, and in line with applicable law.
If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and the right to request deletion. We do not sell personal information, so no opt-out of sale is required.
8. International data transfers
Brimm is available to users in multiple countries. Your information may be processed and stored on servers located in the European Union and by the third-party services listed in Section 4, which may operate in other countries. Where data is transferred internationally, we rely on the safeguards provided by those service providers.
9. Children's privacy
Brimm is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us at support@brimm.ai and we will delete it.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, ask you to review and accept the updated policy in the App. Your continued use of Brimm after an update means you accept the revised policy.
11. Contact us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, contact us at:
Email: support@brimm.ai
This policy reflects Brimm's data practices as of the date above. As Brimm adds new features (such as crash reporting or analytics), we will update this policy to describe them before they go live.