Account and profile data
Email address, display name, profile photo URL, authentication provider, Firebase UID, login tokens, and account settings.
This Privacy Policy explains how Briko AI collects, uses, stores, shares, protects, and deletes personal data when you use the Briko AI mobile application, website, account-deletion pages, and related support services.
Briko AI is operated by Sahar Yafe, Israel ("Briko AI", "we", "us"). This policy applies to the app identified on Google Play as Briko AI with package name com.xfrdaily.app. It also applies to users who install internal, closed, open, or production testing builds.
You can contact us about privacy, data access, correction, portability, objection, account deletion, or support at xfrdaily@gmail.com. We aim to respond to verified privacy requests within 30 days unless applicable law requires a different period.
Email address, display name, profile photo URL, authentication provider, Firebase UID, login tokens, and account settings.
Tasks, notes, reminders, subtasks, schedules, app preferences, AI chat history, saved memories, generated task plans, and user-selected attachments.
Microphone audio when you use voice features, camera images or library files you choose, and document content you intentionally import for task extraction, transcription, attachments, or PDF sharing.
Google Play product identifiers, purchase tokens, subscription status, entitlement level, RevenueCat app user ID, and transaction timestamps. We do not receive or store full card numbers or bank details.
Firebase installation ID, Firebase Cloud Messaging token, device integrity/App Check verdicts, app version, operating system, language, notification scheduling information, rewarded-ad view counters, ad interaction signals, and SDK diagnostics. Ad providers may infer approximate location from IP address.
Error scopes, warning codes, app state needed to investigate bugs, and any screenshots, logs, or messages you voluntarily send to support.
We do not collect precise location, contacts, SMS, call logs, health data, installed-app inventory, advertising ID for ads, or biometric data.
We do not sell personal data, use personal data for third-party advertising, build advertising profiles, or share data with data brokers.
| Permission or capability | When used | Purpose |
|---|---|---|
| Microphone | Only after you start voice input or transcription | Convert speech to text and power voice AI features |
| Camera and photos/files | Only when you choose to scan or attach content | Extract tasks from images/files, attach content, or generate/share task artifacts |
| Notifications, exact alarms, foreground services, full-screen intent | Only for reminders and call-style reminder flows you configure | Deliver scheduled reminders reliably, including urgent heads-up/call reminder experiences |
| App Check / Play Integrity | Automatically for protected backend calls | Confirm app integrity and reduce abuse |
Sensitive permissions are requested through Android runtime permission dialogs where available. The app also provides contextual in-app explanations before requesting access for sensitive features.
We use service providers only as needed to operate the app. They receive the data required for the feature you use.
| Provider | Purpose | Data involved |
|---|---|---|
| Google Firebase Authentication | Account login and session management | Email, display name, provider, authentication tokens, IP-related security logs |
| Google Firebase Cloud Firestore / Storage | Cloud sync and optional attachments | Tasks, notes, reminders, settings, chat records, selected files |
| Firebase Cloud Messaging and Expo/notification tooling | Push notifications and reminders | FCM token, device/app notification metadata |
| Google Sign-In | Optional Google login | Google account profile, email, ID token |
| Google Play Billing | Subscriptions and in-app purchase checkout | Product ID, purchase token, purchase status; payment details stay with Google Play |
| RevenueCat | Subscription entitlement, purchase restoration, paywall metadata | App user ID, purchase tokens, product identifiers, subscription status, transaction metadata |
| Google AdMob / Google Mobile Ads SDK | Optional rewarded ads, ad delivery, ad measurement, SDK diagnostics, and fraud prevention | IP address, ad views/taps, product interactions, diagnostics, and device/account identifiers handled by the SDK. Android advertising ID collection is blocked in the app manifest. |
| Google Gemini API | AI generation and multimodal features | Prompts, task context, and selected images/files when you invoke those features |
| Groq APIs | AI chat, tool use, and Whisper transcription | Text prompts, task/chat context, and temporary audio for transcription when used |
| Google Play Integrity / Firebase App Check | Security and abuse prevention | Integrity verdicts and related device/app attestation metadata |
AI providers process your prompts and content only when you invoke AI features. We do not authorize providers to train general models on your personal content where enterprise or opt-out controls are available to us.
Your Google Play Data Safety form should match the app's real behavior across all active tracks. Based on the current app, Briko AI collects data for app functionality, account management, payments, security, analytics/diagnostics, and support. Data is transmitted over HTTPS and account deletion is supported in-app and through a web request page.
You can delete your account in the app from Settings > Privacy > Delete account permanently, or by using our account deletion page. Account deletion removes account-linked app data unless retention is required for security, fraud prevention, payment disputes, taxes, legal obligations, or enforcement of our terms.
Briko AI is operated from Israel and uses providers that may process data in the United States, the European Economic Area, Israel, and other locations where they operate infrastructure. Where required, we rely on contractual protections such as Standard Contractual Clauses and provider security measures.
Depending on your location, including under GDPR/UK GDPR, Israel privacy law, and certain US state privacy laws, you may have rights to access, correct, delete, export, restrict, or object to processing of personal data. You may also withdraw optional permissions through your device settings.
To exercise rights, email xfrdaily@gmail.com. We may ask you to verify your identity before acting on a request.
Briko AI is not directed to children under 16 and is not intended for use by children without appropriate parental or guardian consent where required by law. If you believe a child provided personal data without appropriate consent, contact us and we will take reasonable steps to delete it.
We may update this policy as the app, providers, or legal requirements change. Material changes will be reflected by updating the "Last updated" date and, where appropriate, by in-app notice or store listing updates.