← Back to BrainMop

Privacy Policy

App: BrainMop· Developer: DabbleLabs UK· Last updated: 1 August 2026

1. Overview

BrainMop is a notes app for Android and the web. It is offline-first: everything you write is saved on your device as you type. If you choose to create an account and sign in, your notes are also stored on a server operated by DabbleLabs UK so they can sync across your devices and the web version. This policy explains, in plain terms, what we store, why, where it goes, and the choices you have.

The short version: until you sign in, your notes stay on your device. Once you sign in, your notes are stored on our server so we can sync them. We do not sell your data, we show no ads, and we run no analytics or tracking.

2. Two ways to use BrainMop

BrainMop's core notes app – on the web and Android, including sync across your devices – is free. An optional paid plan (£24/year, or £4.50/month – an auto-renewing subscription billed via PayPal) adds connecting an AI assistant and extended version history; see Sections 5 and 8.

3. Information we store when you have an account

Account details. When you register with an email and password, we store your email address and a one-way hash of your password (using bcrypt – we never store your actual password and cannot recover it). If you instead sign in with Google, we verify your sign-in with Google and store your email address and the stable Google account identifier (the "subject" id) so we can recognise you next time. We do not request or store your Google name, profile photo, contacts, or any other Google data.

Your notes and related content. So we can sync them, we store the content you create: note titles and body text, checklist items, labels, and their status (pinned, archived, or in the trash). We also keep a version history of your notes so you can restore an earlier version, and an internal change log and per-item identifiers that make reliable sync possible.

Sessions and security. When you sign in we issue a random session token (valid for up to 30 days, extended as you keep using the app) so you stay signed in. To protect accounts against automated attacks, we briefly record the IP address of sign-in, registration, and password-reset attempts for rate-limiting; these records are discarded automatically (within about an hour).

4. How your notes are stored

All traffic between the app and our server is encrypted in transit using HTTPS/TLS. On the server, your notes are held in a standard database. They are not end-to-end encrypted, which is what makes server-side search and sync possible: this means that, in principle, someone with access to the server (such as DabbleLabs UK as the operator) could read note content. We do not read your notes except where strictly necessary to operate or debug the service, and we never share them. As with any ordinary online notes service, we recommend you do not store highly sensitive secrets (such as passwords, full card numbers, or recovery codes) in your notes.

5. Version history and retention

Each time you change a note, we keep a snapshot of the previous version so you can review or restore it from the app's history view. We always keep a number of the most recent versions of each note. How long older versions are kept depends on your plan: on the free plan, versions more than 30 days old are automatically deleted, and only the last 30 days of history is shown; on the paid plan, full version history is retained for as long as your account exists. Your notes themselves are retained for as long as your account exists, regardless of plan. Notes you move to the trash remain recoverable until you permanently delete them.

6. Deleting your data

You can delete individual notes at any time from within the app. To delete your whole account and all data associated with it, use Delete Account in the app's settings: you will be asked to confirm your account email and re-enter your password (or reconfirm with Google, if that is how you sign in) before your account and its data are permanently erased from our server, immediately. Removing the app from a device, or clearing its data, deletes the local copy on that device but does not by itself delete data already stored on the server under your account.

7. Third-party services we use

To run BrainMop we rely on a small number of service providers. We share with them only what each needs to do its job:

8. Optional AI assistant access

BrainMop offers an optional integration that lets you connect an AI assistant (for example, Anthropic's Claude) to your notes, so the assistant can read and edit them on your behalf. This is entirely optional and off unless you set it up and grant access. If you connect an AI assistant, the content of the notes it reads is sent to that AI provider when it accesses them, and your use of that assistant is governed by that provider's own terms and privacy policy. You can disconnect the integration at any time to stop further access. Connecting an AI assistant is part of the optional paid plan. Whether or not you have the paid plan does not change what data is collected or how it is handled – it only controls whether the AI-assistant connection is available.

9. Link previews

When you add a web link to a note, BrainMop can show a small preview (the page's title and, where available, an image). To build that preview, our server fetches the linked page on your behalf and stores the link's address and the fetched title/preview for a short period (around 7 days) so repeated previews are fast. Because our server makes the request, the destination website sees our server, not your device. If you do not add links, no such request is made.

10. Crash reporting

The Android app can send anonymous crash reports if it stops unexpectedly, to help us find and fix bugs. This is on by default; you can turn it off at any time in the app's Settings. When enabled, a crash report is sent to a server operated by DabbleLabs UK (at dabblelabs.uk) and contains only: a randomly generated identifier for that single report, the app's package name and version, your Android version, your device brand and model, the time of the crash, and the technical details of the error (a stack trace). It does not contain a persistent device or installation identifier, your email, your notes, or anything else you have entered. Crash reports are used solely to diagnose and fix bugs, are not shared with any third party, and are automatically deleted after 90 days.

11. Permissions and on-device storage (Android)

The Android app requests only the Internet permission, needed to sync with the server. It does not request location, contacts, camera, or similar permissions. On your device, the app stores your notes locally (for offline use) and, when signed in, your session token and email so you stay signed in.

12. Device backups

The Android app permits Android's standard backup mechanism (allowBackup). If you have Google Drive backup enabled on your device, the app's local data may be included in that backup and stored in your personal Google account. This backup is controlled by you and your Google account settings, not by DabbleLabs UK. You can disable backup for this app in your Android settings.

13. Children

BrainMop is not directed at children under the age of 13. We do not knowingly collect data from children under 13.

14. Your rights

If you are located in the United Kingdom or the European Union, you have rights under the UK GDPR / GDPR, including the right to access, rectify, export, and erase the personal data we hold about you. The personal data we hold for an account is your email address and the notes and related content you have created. To exercise any of these rights, contact us at [email protected]. The lawful basis for storing your account and notes is the performance of the service you have asked us to provide.

15. Changes to this policy

If we update this policy, the new version will be published here and the "Last updated" date will be revised. Continued use of the app after changes constitutes acceptance of the updated policy.

16. Contact

If you have any questions about this privacy policy, please contact us at: [email protected]