← Back to BrainMop

Privacy Policy

App: BrainMop· Developer: DabbleLabs UK· Last updated: 3 August 2026

1. Overview

BrainMop is a notes app for Android and the web. It is offline-first: everything you write is saved on your device as you type. If you choose to create an account and sign in, your notes are also stored on a server operated by DabbleLabs UK so they can sync across your devices and the web version. This policy explains, in plain terms, what we store, why, where it goes, and the choices you have.

The short version: until you sign in, your notes stay on your device. Once you sign in, your notes are stored on our server so we can sync them. We do not sell your data, we show no ads, and we run no analytics or tracking. DabbleLabs UK is run by one person, not a company with a dedicated support or operations team – see Section 17 for what that means in practice.

2. Two ways to use BrainMop

BrainMop's core notes app – on the web and Android, including sync across your devices – is free. An optional paid plan (£24/year, or £4.50/month – an auto-renewing subscription billed via PayPal) adds connecting an AI assistant and extended version history; see Sections 6 and 9.

3. Information we store when you have an account

Account details. When you register with an email and password, we store your email address and a one-way hash of your password (using bcrypt – we never store your actual password and cannot recover it). If you instead sign in with Google, we verify your sign-in with Google and store your email address and the stable Google account identifier (the "subject" id) so we can recognise you next time. We do not request or store your Google name, profile photo, contacts, or any other Google data.

Your notes and related content. So we can sync them, we store the content you create: note titles and body text, checklist items, labels, and their status (pinned, archived, or in the trash). We also keep a version history of your notes so you can restore an earlier version, and an internal change log and per-item identifiers that make reliable sync possible.

Sessions and security. When you sign in we issue a random session token (valid for up to 30 days, extended as you keep using the app) so you stay signed in. To protect accounts against automated attacks, we briefly record the IP address of sign-in, registration, and password-reset attempts for rate-limiting; these records are discarded automatically (within about an hour). We also keep a small set of internal operational logs – for example, records of billing events from PayPal and administrative actions on the service – used only for troubleshooting and to prevent fraud or abuse. These are not routinely reviewed and are never shared with anyone.

4. How your notes are stored

All traffic between the app and our server is encrypted in transit using HTTPS/TLS. On the server, your notes are held in a standard database. They are not end-to-end encrypted, which is what makes server-side search and sync possible: this means that, in principle, someone with access to the server (such as DabbleLabs UK as the operator) could read note content. We do not read your notes except where strictly necessary to operate or debug the service, and we never share them. As with any ordinary online notes service, we recommend you do not store highly sensitive secrets (such as passwords, full card numbers, or recovery codes) in your notes.

5. Where your data is physically stored

Our server infrastructure is based in the United Kingdom: the live database that stores your notes runs on a server located in England, and a warm standby copy used for disaster recovery runs on a second server, also in England. Both are operated by DabbleLabs UK.

We also take automatic backups of the database so we can recover from a server failure or a serious mistake. A local copy of each backup is kept on the primary server for 7 days, and backups are additionally copied off-site to Backblaze B2, a cloud storage provider. The storage region we use for these off-site backups is in the European Union, not the UK. Under UK data-protection law, this kind of transfer to the EU is permitted without extra safeguards, but we want to be upfront that a copy of your data can exist outside the UK as an off-site backup.

Backup retention. Off-site backup snapshots are kept for around 90 days from when they were taken, then automatically deleted. In practice this means that if you delete a note or your whole account, it is removed from the live database immediately (Section 7), but a copy may continue to exist in an earlier backup snapshot for up to around 90 days afterwards, until that snapshot's turn comes round to be purged. Backups exist purely so we can recover from failures or mistakes, not to retain data you have deleted, and they are never used for any other purpose.

6. Version history and retention

Each time you change a note, we keep a snapshot of the previous version so you can review or restore it from the app's history view. We physically retain this history on the server for 90 days (or the most recent 50 versions of a note, whichever keeps more), for every account, regardless of plan. What differs by plan is only what you can see and restore through the app: on the free plan you can view and restore versions from the last 30 days; on the paid plan you can view and restore the full history we keep. If a paid plan lapses, you simply lose the ability to see and restore versions older than 30 days – nothing is deleted as a result, and that older history becomes visible again if you resubscribe. Your notes themselves are retained for as long as your account exists, regardless of plan. Notes you move to the trash remain recoverable until you permanently delete them or delete your account – we do not automatically empty the trash.

7. Deleting your data

You can delete individual notes at any time from within the app. To delete your whole account and all data associated with it, use Delete Account in the app's settings: you will be asked to confirm your account email and re-enter your password (or reconfirm with Google, if that is how you sign in) before your account and its data are permanently erased from our live server, immediately. This is irreversible and there is no cooling-off period, so make sure it is what you want before confirming. As explained in Section 5, a copy of your data may still exist for a period afterwards in an off-site backup taken before the deletion. Removing the app from a device, or clearing its data, deletes the local copy on that device but does not by itself delete data already stored on the server under your account.

BrainMop provides a complete export of your account data – every note in every status (active, archived, and trashed), checklist items, labels, and version history – as a single downloadable JSON file. We do not yet offer a one-click "export my data" button in the app itself; if you would like a copy of your data – for example, before deleting your account – email us (Section 17) and we will send it to you directly.

8. Third-party services we use

To run BrainMop we rely on a small number of service providers. We share with them only what each needs to do its job:

9. Optional AI assistant access

BrainMop offers an optional integration that lets you connect an AI assistant – for example Anthropic's Claude, or any other assistant that supports the Model Context Protocol (MCP) – to your notes. This is entirely optional and off unless you set it up and grant access.

What a connected assistant can see and do. Once connected, an assistant can read your entire notebook: every note, including ones you have archived or moved to the trash, not only the notes in your active working view. By default, a new connection is read-only – the assistant can read your notes but cannot change them. You can choose to grant write access instead, which lets the assistant create, edit, and delete notes and labels on your behalf; a small number of actions (such as deleting or merging a label) apply across your whole notebook at once and cannot be undone.

Where the content goes after that. When a connected assistant reads a note, its content is sent to whichever AI provider operates that assistant (for example, Anthropic, if you are using Claude) so the assistant can process it, and your use of that assistant is governed by that provider's own terms and privacy policy. We want to be direct about a limitation here: once an assistant has read a note, BrainMop has no way to see, control, or prevent what that assistant – or any other tool it has access to – does with that content afterwards. If you keep sensitive information in your notes, please bear this in mind before connecting an assistant, especially with write access.

How access is granted and revoked. You can connect an assistant in two ways: creating a personal access token in the app (choosing read-only or read-and-write) and giving it to your MCP client, or using the one-click "connect an AI assistant" flow, which asks you to sign in and approve the request – this sign-in step is handled on our behalf by Stytch, an identity-verification provider – before granting access with the scope described above. Either way, access does not expire on its own; it stays active until you revoke it. Personal tokens can be revoked from the same screen where you created them, and the one-click connection can be disconnected at any time. We also run a small relay service, hosted with Render, that lets MCP clients reach BrainMop over the internet; it forwards requests to our own server and does not itself keep a copy of your notes.

Connecting an AI assistant is part of the optional paid plan. Whether or not you have the paid plan does not change what data is collected or how it is handled – it only controls whether the AI-assistant connection is available.

10. Link previews

When you add a web link to a note, BrainMop can show a small preview (the page's title and, where available, an image). To build that preview, our server fetches the linked page on your behalf and stores the link's address and the fetched title/preview for a short period (around 7 days) so repeated previews are fast. Because our server makes the request, the destination website sees our server, not your device. If you do not add links, no such request is made.

11. Crash reporting

The Android app can send anonymous crash reports if it stops unexpectedly, to help us find and fix bugs. This is on by default; you can turn it off at any time in the app's Settings. When enabled, a crash report is sent to a server operated by DabbleLabs UK (at dabblelabs.uk) and contains only: a randomly generated identifier for that single report, the app's package name and version, your Android version, your device brand and model, the time of the crash, and the technical details of the error (a stack trace). It does not contain a persistent device or installation identifier, your email, your notes, or anything else you have entered. Crash reports are used solely to diagnose and fix bugs, are not shared with any third party, and are automatically deleted after 90 days.

12. Permissions and on-device storage (Android)

The Android app requests only the Internet permission, needed to sync with the server. It does not request location, contacts, camera, or similar permissions. On your device, the app stores your notes locally (for offline use) and, when signed in, your session token and email so you stay signed in.

13. Device backups

The Android app permits Android's standard backup mechanism (allowBackup). If you have Google Drive backup enabled on your device, the app's local data may be included in that backup and stored in your personal Google account. This backup is controlled by you and your Google account settings, not by DabbleLabs UK. You can disable backup for this app in your Android settings.

14. Children

BrainMop is not directed at children under the age of 13. We do not knowingly collect data from children under 13.

15. Your rights

If you are located in the United Kingdom or the European Union, you have rights under the UK GDPR / GDPR, including the right to access, rectify, obtain a copy of, and erase the personal data we hold about you. The personal data we hold for an account is your email address and the notes and related content you have created. To exercise any of these rights, contact us at jody.florian@gmail.com – see Section 7 regarding obtaining a copy of your data: the export itself is fully available, it is just requested by email rather than a self-service button in the app. The lawful basis for storing your account and notes is the performance of the service you have asked us to provide.

16. Changes to this policy

If we update this policy, the new version will be published here and the "Last updated" date will be revised. Continued use of the app after changes constitutes acceptance of the updated policy.

17. Contact

BrainMop is built and run by one person, not a company with a dedicated support team, so please be patient if a reply takes a little while. If you have any questions about this privacy policy, please contact us at: jody.florian@gmail.com