Privacy Policy
We take the protection of your personal data seriously and process it confidentially in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG). This policy explains what personal data we process and why. It covers both the website brainmute.app and the Brainmute Android app. Sections 3 to 5 and 11 to 12 are about the website, sections 6 to 10 are about the app, and the rest applies to both.
- Controller
- Legal bases
- Hosting and server log files
- Content delivery network and security
- Self-hosted fonts
- The app: what never leaves your phone
- The app: what we store on our server
- Your account and sign-in
- Subscription and payment
- Permissions the app asks for, and why
- Email contact and routing
- Cookies, local storage and analytics
- Transfers to third countries
- Storage periods
- Your rights
- Withdrawal of consent and objection
- Right to lodge a complaint
- Data security
- Minors
- Changes to this policy
1. Controller
Controller within the meaning of Art. 4 (7) GDPR is:
Luis Kleemann
Engelbergerstraße 3
79106 Freiburg im Breisgau
Germany
Email: [email protected]
A data protection officer is not required by law (no core activity of regular, large-scale or sensitive data processing under Art. 37 GDPR / § 38 BDSG).
For residents of Quebec (Canada), the Act respecting the protection of personal information in the private sector requires a designated person in charge of the protection of personal information. This function is exercised by the person with the highest authority in the enterprise: Luis Kleemann, owner of the sole proprietorship. Contact: [email protected], or by post at the address above.
2. Legal bases
Where we process personal data, we rely on the following legal bases:
- Art. 6 (1) (a) GDPR (consent), for example when you switch on friend activity or choose to appear in the leaderboard.
- Art. 6 (1) (b) GDPR (pre-contractual or contractual measures), for example when we handle an email enquiry.
- Art. 6 (1) (f) GDPR (legitimate interest), for example for the operation, security and stability of the site, spam and abuse prevention, and keeping proof of a given consent.
- § 25 (2) no. 2 TDDDG (storage of or access to information on your device where strictly necessary for a service you explicitly requested).
3. Hosting and server log files
Our website is hosted by:
Cloudflare, Inc.
101 Townsend St, San Francisco, CA 94107, USA
Further information can be found in Cloudflare's privacy policy.
When you visit the site, Cloudflare automatically processes the following data in server log files, which your browser transmits for technical reasons: IP address, date and time of access, requested file, amount of data transferred, HTTP status code, browser type and version, operating system, and referrer URL.
Purpose: delivery of the website, IT security, and defence against attacks and bot traffic.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a technically sound and secure website).
Storage period: server log files are kept for a maximum of 14 days. This data is not merged with other data sources.
4. Content delivery network and security
Cloudflare is also used as a content delivery network (CDN) and web application firewall (WAF). All traffic between your browser and our site is routed through Cloudflare's global network and malicious requests are filtered out. Processing your IP address is technically necessary for this.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the performance and security of the site).
5. Self-hosted fonts
This site uses the fonts Inter, JetBrains Mono, Space Grotesk and Instrument Serif (all under the SIL Open Font License). The font files are served exclusively from our own server (Cloudflare Pages). No connection to Google Fonts or any external font CDN is made when the fonts are loaded, so no IP address is transmitted to a font provider.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a consistent presentation).
6. The app: what never leaves your phone
Brainmute is an Android app that locks distracting apps and gives you missions. Most of what it needs to do that stays on your device and is never sent to us.
- Which app is open right now. To lock an app, Brainmute has to know which app you just opened. It reads that from Android and holds it in memory only, for as long as it takes to decide whether to show the lock screen. It is never written to storage and never sent anywhere.
- Your screen time. If you allow it, the app reads Android's usage statistics to show you how long you were on your phone. This stays on the device.
- Your step count. If you allow it, the app reads your step count for movement missions. This stays on the device.
- Which apps you chose to lock. The list of apps you lock, and the list of apps you still allow during a mission, stays on your device. We deliberately do not sync it, because the name of a locked app could reveal something sensitive about you, for example a health, prayer or dating app. If you switch phones you pick your apps again.
- Your exact age. The app asks for it and keeps it on the device. Only the plain confirmation that you are at least 16 is stored on our server, never the number itself.
- What you write during a mission. Some missions ask you to write. The app counts your words while you type, and the text is discarded when the mission ends. It is not saved and not sent to us.
Legal basis: Art. 6 (1) (b) GDPR, because this is how the service you asked for works. Nothing here is processed for any other purpose.
7. The app: what we store on our server
If you create an account, the app syncs part of your data so you do not lose it when you change or reset your phone, and so friend features work. This is the complete list.
- Your profile: your account ID, your display name, and your two visibility settings (whether friends see your activity, and whether you appear in the leaderboard).
- Your score: your brain score, your streak in days, and your gem balance.
- Your settings: your plan, your sleep schedule, your goals and focus area, the confirmation that you are at least 16, the items you own, your streak freezes, your completed missions, and when your trial started.
- Your mission calendar: which missions you completed on which day. Step counts are removed before this is sent.
- Your friends: who sent whom a friend request and whether it was accepted.
- Friend activity, but only if you switch it on: an entry saying that you cleared or gave up a mission, lost a streak, unlocked an app or turned off a lock. This switch is off unless you turn it on yourself.
Purpose: to keep your progress across devices and to run the friend features.
Legal basis: Art. 6 (1) (b) GDPR for your own data, and Art. 6 (1) (a) GDPR (consent) for friend activity and for appearing in the leaderboard.
Processor: Supabase, for the database and for sign-in. The database is hosted in Frankfurt, Germany (region eu-central-1). We have a data processing agreement in place.
We do not use analytics, advertising or tracking of any kind. There is no Google Analytics, no Meta pixel, no TikTok pixel and no advertising ID. We do not send push notifications from a server, so no push token is created or transmitted.
8. Your account and sign-in
Brainmute requires an account. You create it at the start, and the app cannot be used without one. There is no anonymous use.
You can sign up with an email address and a password, or with your Google account. If you use Google, we receive your email address and your Google account ID from Google in order to identify you. We do not receive your password. We do not store your name or your profile picture: both are removed automatically when your account is created and whenever it changes, before anything is written to our database.
We send emails to your address for your account: the verification code when you sign up, password resets, confirmation when you change your address, and confirmation after you delete your account. There are also two security notices that you cannot unsubscribe from, because they protect your account: one when your password has been changed, and one when your email address has been changed. Sending is handled for us by Scaleway SAS, 8 rue de la Ville-l’Évêque, 75008 Paris, France. The data processed are the sender address, the recipient address, the subject, the content of the email, the timestamp and the response of the receiving mail server. Processing takes place in France. According to Scaleway, no personal data is processed outside the European Union for this service and no sub-processors outside the European Union are used for it.
If an address cannot be reached, Scaleway puts it on a blocklist so that no further delivery attempts are made. The address, the reason and the period of the block are stored. The first block lasts one week, the second one month, and from the third onwards it has no time limit. We can unblock an address again.
If you create an account but do not confirm it with the code from our email, we delete it again no later than 48 hours after it was created, together with the address you gave.
So that nobody can abuse our sign-up and our email sending, we limit how often an email can be requested for an address in a row. For this we do not store your address, only a check value calculated from it, from which the address cannot be recovered. These entries are deleted after two days at the latest.
We do not pass on your IP address. The app does not send it to us, and we do not forward it to any provider. Supabase sees the IP address your device connects from and stores it in two places: in its technical logs, which are kept for one day, and with your sign-in, together with the technical identifier of the program making the connection (user agent). Only the most recent connection is kept with your sign-in. It is overwritten with each new one and deleted as soon as you sign out or delete your account.
Purpose: to identify you, to restore your data on a new device, to deliver the emails for your account, and to protect our sign-up from abuse.
Legal basis: Art. 6 (1) (b) GDPR. For the blocklist, the limit on requests and the deletion of unconfirmed accounts Art. 6 (1) (f) GDPR; our legitimate interest is reliable delivery, protection against being blocked by mail providers, and protection against abuse. For the security notices about your password and your address Art. 6 (1) (f) GDPR; our legitimate interest is the security of your account.
9. Subscription and payment
Brainmute is sold as a subscription through the Google Play Store. We never see your payment details. Your card, your address and your bank data are handled by Google and never reach us.
To know whether your subscription is active, we use RevenueCat, Inc., 1 Letterman Drive, San Francisco, CA 94129, USA. We send them your account ID, and they tell us whether you have an active subscription. They receive no other data from us. RevenueCat acts as our processor in doing so, see section 13.
If you delete your account, we also delete your record at RevenueCat, that is the subscription status and purchase history stored there under your account ID. Your purchase itself is held by Google: an active subscription continues and continues to be charged until you cancel it in the Google Play Store.
Purpose: to unlock the app for paying users.
Legal basis: Art. 6 (1) (b) GDPR.
Third country: RevenueCat is in the USA. The transfer is based on the EU standard contractual clauses.
10. Permissions the app asks for, and why
Android asks you for each of these separately. You can refuse any of them, and you can withdraw any of them later in your phone settings. Some parts of the app then stop working, but nothing else happens.
- Accessibility service. This is what makes the lock work. It tells Brainmute which app you just opened, so it can show the lock screen. Brainmute does not read the content of any screen and does not record anything you type in other apps.
- Usage access. To show you your screen time.
- Display over other apps. To draw the lock screen on top of the app you tried to open.
- Physical activity. To read your step count for movement missions.
- Notifications. To show you countdowns and reminders. All notifications are created on your device.
- Run at startup and ignore battery optimisation. So the lock still works after you restart your phone and is not shut down by the system.
11. Email contact and routing
Emails to [email protected] are received and stored in a mailbox at IONOS SE (Elgendorfer Straße 57, 56410 Montabaur, Germany) in order to process your request. IONOS acts as our processor pursuant to Art. 28 GDPR; the applicable data processing agreement forms part of the IONOS General Terms and Conditions. Processing takes place within the European Union (primarily in Germany). To our current knowledge, there is no transfer of personal data to a third country. Data processed: sender address, recipient address, subject, message content, attachments and headers.
If you use the contact us entry in the app (tap your profile picture in the top right, the entry is in the first menu), the app opens a draft email in your own email program. The recipient, the subject and a few technical lines are pre-filled: the version of the app, your Android version and your device model (for example SM-A566B). These lines help us reproduce a problem on the right kind of device. They contain no unique device identifier, in particular no advertising ID, no serial number and no IMEI, and no location data. The app does not transmit anything by itself; the draft is only sent once you send it, and you can edit or delete these lines beforehand.
Legal basis: Art. 6 (1) (b) GDPR (pre-contractual requests) or Art. 6 (1) (f) GDPR (legitimate interest in communication).
Storage period: until your request has been dealt with; statutory retention obligations, in particular commercial and tax retention periods, remain unaffected.
Provision of data: providing your data is voluntary; without your email address and the content of your message we cannot process your request.
12. Cookies, local storage and analytics
This site does not use cookies for analysis, marketing or tracking. There is no Google Analytics, no Meta pixel and no TikTok pixel.
Cloudflare may set one technically necessary cookie (__cf_bm, lifetime max. 30 minutes) for bot defence. Legal basis: § 25 (2) no. 2 TDDDG (strictly necessary) and Art. 6 (1) (f) GDPR.
We use Cloudflare Web Analytics (Cloudflare, Inc., USA) for aggregate, privacy-friendly reach measurement. It does not set any cookies and does not store personal data (in particular no IP addresses, no device fingerprints and no cross-site identifiers). Identifying individual visitors is technically impossible, so no consent under § 25 TDDDG is required. Legal basis for the processing: Art. 6 (1) (f) GDPR. More information: cloudflare.com/web-analytics-privacy.
Because no marketing or tracking cookies are used, this site does not require a cookie consent banner. If tracking tools are added in future, this policy will be updated and, where required, your consent obtained beforehand.
13. Transfers to third countries
Some of our providers are based outside the European Union, or can access personal data from there. Where data is transferred to a third country, we put in place the safeguards required under Chapter V GDPR. Here is who they are and what each transfer is based on.
- Supabase Pte. Ltd, Singapore runs our database and our sign-in. Your data is stored in the European Union region (Frankfurt, Germany, eu-central-1) and is processed there as a rule. In certain cases access from a third country may be necessary, in particular by support staff at Supabase, Inc. in the USA, which Supabase lists as a sub-processor for support services. There is no adequacy decision for Singapore, and none applies to Supabase, Inc. either: the company is not listed as a participant in the EU-US Data Privacy Framework (as at 9 September 2026). Both transfers are therefore based on the EU standard contractual clauses under Art. 46 (2) (c) GDPR (Commission Implementing Decision (EU) 2021/914). Supabase uses further technical sub-processors, for example for hosting, infrastructure and monitoring; Supabase keeps them in a public list.
- Cloudflare, Inc., USA provides our domain, our website and its security. Where the processing falls within the certified scope, it relies on the EU-US Data Privacy Framework (adequacy decision of 10 July 2023, Art. 45 GDPR); Cloudflare is listed there with the status Active. EU standard contractual clauses apply in addition, and Cloudflare relies on them should the certification lapse.
- Resend, USA sent the emails for your account until 12 September 2026. Since then we no longer transmit any data there; sending runs entirely through Scaleway in France (see section 8). Resend stores the data in the USA, even where sending ran through a European region. According to Resend, message and log data is kept there for 30 days and then deleted; any remaining data is deleted within 90 days of closing the account. The earlier transfer relies on the EU standard contractual clauses; in addition, Resend is certified under the EU-US Data Privacy Framework.
- RevenueCat, Inc., USA manages subscriptions. It receives your account ID only, no name and no address (see section 9). RevenueCat is not listed as a participant in the EU-US Data Privacy Framework; the transfer is based on the EU standard contractual clauses under Art. 46 (2) (c) GDPR.
We have data processing agreements under Art. 28 GDPR with the processors we use. You can request a copy of the standard contractual clauses at [email protected].
14. Storage periods
We store personal data only as long as necessary for the respective purpose or as required by statutory retention obligations. Specific periods: server log files max. 14 days; the __cf_bm cookie max. 30 minutes; unconfirmed accounts max. 48 hours; the check values used to limit email requests max. two days; Supabase's technical logs with your IP address max. one day; the IP address and user agent of your sign-in until you sign out; everything listed in section 7 for as long as your account exists. You can delete your account at any time in the app itself: tap your profile picture in the top right, go to the ACCOUNT section and choose delete account at the very bottom. This deletes your account, your score, your streak, your friendships and your record at RevenueCat. You can also ask us to do it by writing to [email protected].
For the emails about your account the following also applies: sending and delivery data at Scaleway is stored only for as long as it is needed to investigate delivery failures and to prove delivery. Blocklist entries remain for the periods stated in section 8. Log data at our former provider Resend is deleted according to the periods that apply there, see section 13.
15. Your rights
As a data subject you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR), in particular against processing based on legitimate interest, for reasons arising from your particular situation
- Right not to be subject to a decision based solely on automated processing (Art. 22 GDPR); this does not take place
To exercise your rights, an informal message to [email protected] is enough.
16. Withdrawal of consent and objection
You can withdraw any consent at any time with effect for the future (Art. 7 (3) GDPR), for example by clicking the unsubscribe link in our emails. The lawfulness of processing carried out before the withdrawal is not affected. Where data is processed on the basis of legitimate interest, you can object under Art. 21 GDPR for reasons arising from your particular situation.
17. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example at the authority of your habitual residence or of our place of business:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart, Germany
Web: baden-wuerttemberg.datenschutz.de
18. Data security
This site uses SSL/TLS encryption for security and to protect the transmission of confidential content, recognizable by "https://" and the padlock symbol in your browser.
19. Minors
Brainmute is intended for persons aged 16 or over. The app asks for your age before you can use it. If we become aware that an account belongs to a person under 16, we delete it without delay.
20. Changes to this policy
We may adapt this policy when the legal situation or the actual data processing changes (for example when new services are integrated). The version published at brainmute.app/privacy-policy applies.