// legal
Privacy Policy
What we collect, why we collect it, and what you can do about it — in plain English.
Last updated: 8 August 2026
Who we are
BrosCo Designs (“we”, “us”) builds the apps listed on this site, including Mind Ripple, Crosstalk, Quild Thoughts, and CoreBudget. This policy covers this website and all of those apps. You can reach us any time at admin.dev@broscodesigns.com.
The short version
- Our apps save your work on your own device by default. Cloud sync is something you turn on, not something we assume.
- We never sell your data, and we do not run advertising.
- We cannot read your payment card details — our payment processor handles those and we never receive them.
- You can delete your account and your data at any time.
What we collect
If you use an app as a guest
Nothing is sent to us. Your work is stored locally in your browser and stays on your device.
If you create an account
- Account details — your email address, and your display name if you provide one. If you sign in with Google, we receive your email address, name, and profile image from Google.
- Authentication data — handled by Google Firebase Authentication. We never see or store your password.
If you turn on cloud sync
Your app content is stored in our database so it can reach your other devices. Depending on the app, that content may include:
- Mind maps, notes, and project names (Mind Ripple)
- Audio recordings and transcripts (Crosstalk)
- Journal entries, categories, and dates (Quild Thoughts)
- Budget figures, bills, and transaction records (CoreBudget)
This content is yours. We access it only when you explicitly ask us to for support, or where the law requires it.
If you subscribe to a paid plan
Payments are processed by Stripe. Stripe collects and stores your card details directly — we never receive or store your full card number. We receive only your subscription status, plan, and billing history so we can unlock the right features.
When you visit this website
We use Cloudflare Web Analytics, which is privacy-focused: it sets no cookies, does not fingerprint visitors, and does not track you across other sites. It tells us page view counts and rough geography, nothing that identifies you.
Why we collect it
- To run the service — signing you in, syncing your work, delivering the features you paid for.
- To support you — answering your emails and fixing bugs you report.
- To keep it working — diagnosing errors, preventing abuse.
We do not use your content to train machine learning models, and we do not profile you for advertising.
Who we share it with
We do not sell your personal information. We use a small number of service providers to run the apps:
- Google Firebase — authentication, database, and file storage
- Stripe — payment processing and subscription management
- Cloudflare and Netlify — website and app hosting
- Zoho — our business email, so any message you send us is stored there
Each of these processes data on our behalf under their own privacy terms. We may also disclose information where we are legally required to.
How long we keep it
We keep your account and synced content for as long as your account is active. If you delete your account, we remove your content from our active systems, and it clears from routine backups within 90 days. Billing records are retained longer where tax and accounting law requires it.
Your rights
Wherever you live, you can ask us to:
- Give you a copy of the data we hold about you
- Correct anything inaccurate
- Delete your account and associated content
- Stop processing your data
Email admin.dev@broscodesigns.com and we will respond within 30 days. Several of our apps also let you export your work to a file at any time without asking us.
If you are in the EEA or UK, our legal bases for processing are performance of our contract with you, our legitimate interest in operating and securing the service, and your consent where required. If you are in California, you have the right to know, delete, correct, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA. If you are a Virginia resident, the Virginia Consumer Data Protection Act gives you rights to access, correct, delete, and obtain a copy of your personal data, and to opt out of targeted advertising, sale, and profiling — none of which we do. Use the same contact address below to exercise any of these rights.
Security
Data is encrypted in transit using TLS and encrypted at rest by our infrastructure providers. Access to synced content is restricted by database security rules so that only your signed-in account can read your data. No system is perfectly secure, and we cannot guarantee absolute security — but if a breach affects you, we will tell you promptly.
Children
Our apps are not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
International transfers
We are based in the United States, and our service providers may process data in the United States and elsewhere. If you use our apps from outside the US, you understand your data will be transferred and processed there.
Changes to this policy
If we change this policy in a way that materially affects you, we will update the date at the top and, where the change is significant, notify you by email or in the app.
Contact
Questions about privacy, or want your data deleted? Email admin.dev@broscodesigns.com.