Privacy Policy of the Brick Application

Effective September 17, 2026Updated September 25, 2026

What data the app processes, what stays on the device, what goes to the server when you sign in by e-mail and how to delete all of it.

This document is a courtesy translation. In case of any discrepancy between the English and Russian versions, the Russian version available at https://brick.alexforge.org/legal/privacy/ prevails.

1. General Provisions

1.1. This Privacy Policy (hereinafter the "Policy") describes what data is processed in the Brick application (hereinafter the "App") — in the mobile application for Android and iOS and in its web version opened in a browser — for what purposes, how long it is stored, to whom it is transferred and how the User can manage it, including deleting it.

1.2. By installing and using the App, including by opening its web version, you agree to the terms of this Policy. If you do not agree with the Policy — do not use the App.

1.3. This Policy applies together with the User Agreement of the App, published in the same place where this Policy is published.

1.4. Personal data is processed in accordance with Federal Law of 27.07.2006 No. 152-FZ "On Personal Data", as well as the requirements of the distribution platforms (Google Play, App Store) with respect to the mobile application.

2. Terms

  • Personal data — any information relating to a directly or indirectly identified User of the App.
  • Data processing — any operations with data: collection, recording, storage, modification, use, transfer, deletion.
  • User — a natural person using the App.
  • Device — a smartphone, tablet or computer on which the App is installed or in whose browser its web version is opened.
  • Web version — the variant of the App that runs in a browser without installation.
  • Local storage — the App's private storage on the Device; for the web version — the browser storage allocated to the App's site.
  • Operator — the person organizing the processing of data; identified in section 20.
  • Account — a profile of the User on the Operator's server, created upon signing in with an email address.
  • Board (project) — a plan created by the User: a name and a set of Bricks.
  • Brick — an element of a Board: the text of a task, its description, a list of mistakes to avoid, a completion mark and nested Bricks.

3. How Data Processing Is Organized

3.1. The App divides processing into two parts.

On the Device, everything that makes up the core functionality is performed: creating Boards and Bricks, rearranging them, describing them, marking them as done, undoing and redoing actions, the appearance settings. These actions do not require a network connection, and their results stay in the Local storage.

On the server, only what is necessary for the Account and for synchronizing Boards between the User's Devices is processed (section 5), as well as depersonalized statistics about the App's operation (section 6).

3.2. An Account is not required. Without signing in, the App retains full functionality and does not contact the Operator's server at all: the User's data does not leave the Device.

4. Data Processed on the Device

4.1. Data that you enter or create yourself:

  • Boards: name, pinned flag, position in the list;
  • Bricks: text, description, list of mistakes, state (done, collapsed), nesting, time of creation, modification and deletion;
  • appearance settings: theme, interface language, board orientation;
  • service identifiers: a random identifier of the Device and a random identifier of the local profile, generated by the App and not linked to your identity, the Device's serial number or advertising identifiers.

4.2. Without an Account, the data listed above does not leave the Device and is not accessible to the Operator. The only exception is the random service identifier of the profile: it is included in the depersonalized statistics to distinguish one installation of the App from another (section 6). When an Account is used, Boards are synchronized under the terms of section 5.

4.3. The appearance settings are stored only on the Device and are never transferred to the server.

5. Account and Synchronization

5.1. Signing in to the App is performed with an email address confirmed by a one-time six-digit code that is valid for a few minutes. No password is used. An Account is created automatically when a code is first requested for a new address.

5.2. When an Account is used, the following is processed:

  • the email address — for signing in, identifying the Account and contacting the User;
  • the Boards created by the User: names, pinned flag, Bricks with their texts, descriptions, lists of mistakes and state — for synchronization between the User's Devices;
  • the date and time of modification and deletion of Boards — for resolving conflicts during synchronization;
  • service details of the Account: the identifier of the record on the server, the date of its creation, the session key;
  • technical information about requests to the server (IP address, build number and version of the App, operating system version, time of the request), recorded in server logs for security and diagnostics.

5.3. An Account is not required: without signing in, the App retains full functionality, and the data remains only on the Device.

5.4. Synchronization applies only to your own Boards. The App does not publish them, does not show them to other Users and does not provide for data exchange between Users.

5.5. When the versions of one Board diverge between Devices, the version with the later edit time is kept — as a whole, without merging individual Bricks. An edit made after the deletion of a Board restores the Board.

5.6. A sign-in session is valid for up to one year and is renewed automatically while you use the App. If the server stops accepting the session, the App offers to sign in again; the Boards and unsynchronized edits stay on the Device.

5.7. The Operator does not request or process passwords for your email. Access to the Account is protected by control over access to the mailbox specified at sign-in.

5.8. The server side of the App is hosted in the territory of the Russian Federation.

6. Analytics and Diagnostics

6.1. To assess operational stability and understand which features are in demand, the mobile application uses the Yandex AppMetrica service, and the web version uses the Yandex Metrica counter (the right holder of both services is YANDEX LLC). In the web version, the counter is not loaded until the User gives consent in the cookie notice (section 8).

6.2. The following is processed via these services:

  • the App installation identifier assigned by the service, and the service identifier of the profile: a random one for a local profile, the Account identifier after signing in. It allows the Operator to match a crash report with a User's enquiry in which the User quoted their identifier (section 17); the email address is not transferred to analytics;
  • technical information about the Device: model, operating system or browser version, language, screen resolution, connection type;
  • information about the App version, installations, updates and launches;
  • usage events: which screens were opened and which actions were performed (sign-in and sign-out, creating, deleting and pinning a Board, creating and completing a Brick, actions on a Board, changing settings), as well as aggregated counters (for example, the number of Boards and Bricks) — in depersonalized form, without the texts of your Boards and Bricks;
  • information about errors and crashes, including the log of technical events of the App preceding the failure; the contents of your Boards are not written to the log;
  • the IP address, from which the servers of the service determine the approximate location down to the region. The App does not request or receive access to the geolocation of the Device;
  • in the web version — visitor identifiers that the counter stores in browser cookies.

6.3. The texts of your Boards and Bricks are not transferred to analytics.

6.4. Collection of advertising identifiers (IDFA on iOS, Advertising ID on Android) is disabled. The App does not track Users across other apps and websites and does not transfer data to advertising networks.

6.5. The AppMetrica and Yandex Metrica servers are located in the territory of the Russian Federation.

6.6. Terms of use of the services: https://yandex.ru/legal/appmetrica_termsofuse/ and https://yandex.ru/legal/metrica_termsofuse/

7. What Is Not Processed

  • the geolocation of the Device (location access permission is not requested);
  • the camera, photographs and media library, microphone, contact list, calendar, files outside the App's Local storage — the App does not request access to any of these;
  • advertising identifiers and any cross-service identifiers for transfer to advertising networks;
  • payment data and bank card data — the App has no paid features;
  • special categories of personal data (concerning health, beliefs, ethnicity, etc.);
  • biometric personal data.

8. Cookies and Browser Storage (Web Version)

8.1. The web version keeps in the browser storage allocated to the App's site the same things the mobile application keeps on the Device: the Account session key, Boards, appearance settings and the record of the cookie consent you gave. These records are necessary for the App to work, and no separate consent is required for them.

8.2. The App sets no cookies of its own: signing in to the Account is confirmed by a session key in the request header, not by a cookie.

8.3. The Yandex Metrica counter sets cookies with visitor identifiers. It is loaded only after you agree to this in the notice the web version shows on first opening; until consent is given, neither the counter nor its cookies appear in the browser.

8.4. Everything the web version keeps in the browser, including the counter's cookies and the consent record, can be deleted in the browser settings — "clear site data" for the address of the web version. After that, the cookie notice will be shown again.

8.5. The storage of the web version is managed by the browser: it may clear it on its own — in private mode, when running out of space or according to the site settings. Boards not synchronized with an Account are lost in that case.

9. Purposes of Processing

Data is processed solely so that:

  • the App performs its functions: shows your Boards and Bricks, preserves their state and the settings between launches;
  • when an Account is used — the User is identified at sign-in and their Boards are transferred between their Devices;
  • the stability and security of the App's operation are ensured, and errors are found and fixed;
  • enquiries from Users are answered.

Profiling, legally significant automated decision-making, marketing mailings and transfer of data for advertising purposes are not carried out.

11. Transfer of Data to Third Parties

11.1. The Operator does not sell personal data and does not transfer it for marketing purposes.

11.2. Data may be transferred to the following categories of recipients, and only to the extent necessary for the operation of the App:

  • YANDEX LLC (the AppMetrica and Yandex Metrica services) — the depersonalized technical, diagnostic and behavioral data listed in section 6. Servers in the Russian Federation;
  • technical infrastructure providers engaged by the Operator to host the server side of the App and to deliver sign-in code emails. Such providers act on the instructions of the Operator, process data solely to the extent necessary to provide the respective service and may not use it for their own purposes. The servers are located in the territory of the Russian Federation;
  • app stores (Google Play, App Store) — with respect to the distribution of the mobile application and aggregated download statistics, under their own policies;
  • authorized state bodies — in cases expressly provided for by law.

11.3. No cross-border transfer of personal data takes place: the server side, the analytics services and the files of the web version are hosted in the territory of the Russian Federation.

12. Retention Periods

12.1. Data on the Device is stored until the User deletes it (section 14), deletes the App or, in the web version, clears the site data in the browser.

12.2. Account data is stored for as long as the Account exists. After its deletion, personal data is deleted; individual records may be retained for a limited period where required by law or for the resolution of disputes, after which they are deleted or depersonalized.

12.3. A deleted Board is kept on the server as a deletion mark — an identifier and the time of deletion without contents — for no more than 180 days, so that the deletion reaches the User's other Devices, after which the record is erased.

12.4. Server logs are kept for no more than 90 days, as necessary to ensure security and fix errors.

12.5. Information in AppMetrica and Yandex Metrica is stored in accordance with the terms of the services.

13. Data Storage and Protection

13.1. On a mobile Device, data is stored in the private (sandbox) directory of the App, inaccessible to other apps; in the web version — in the browser storage, isolated from other sites.

13.2. The Local storage is encrypted with the AES algorithm. On a mobile Device the encryption key is generated on the Device and stored in the protected system storage (Keychain on iOS, Keystore on Android). In the web version the key is kept by the browser itself next to the data, so protection relies on the isolation of the browser storage and on the protection of the Device itself.

13.3. Data exchange with the server and the analytics services is performed over the secure HTTPS protocol.

13.4. The Operator applies organizational and technical measures to protect data from unauthorized access, modification, disclosure and destruction.

13.5. Absolute protection cannot be guaranteed: the safety of data also depends on the physical safety of the Device, on it being locked with a passcode and on the User's control over the mailbox specified at sign-in.

14. Data Deletion

14.1. The Account together with all associated data can be deleted in the App itself: Settings → "Account" → the delete icon in the top right corner → "Delete all data". The Account and all of its Boards are erased on the server, and the Local storage on the Device is cleared. Deletion is performed immediately and is irreversible. The same path without an Account erases all Boards from the Device.

14.2. Signing out of the Account — Settings → "Account" → "Sign out" — sends unsynchronized edits to the server and clears the Local storage on this Device. The Account and its Boards on the server are kept, and signing in with the same address brings them back.

14.3. An individual Board can be deleted from the list of Boards at any moment ("Delete forever"); the deletion is passed on to the other Devices during synchronization. A deleted Board cannot be restored.

14.4. Removing the mobile application from the Device erases all of its Local storage, including the settings. In the web version, clearing the site data in the browser does the same (section 8).

14.5. You can also send a deletion request to brick@alexforge.org from the email address specified in the Account.

15. User Rights

The User has the right to:

  • receive information about the processing of their personal data;
  • demand the rectification, blocking or deletion of their data;
  • withdraw consent to data processing by deleting the Account, as well as by ceasing to use the App and removing it from the Device;
  • file a complaint with the authorized body for the protection of the rights of personal data subjects.

To exercise these rights, send a request to brick@alexforge.org. A response is provided within the period established by law.

16. Device Permissions

PermissionWhen requestedPurpose
Internetno prompt, standard accesssign-in, synchronization, transfer of statistics
Network stateno prompt, standard accessknow whether there is a connection and not attempt to synchronize without one
Vibrationno prompt, standard accesshaptic feedback when dragging Bricks

The App requests no other permissions — camera, photographs, geolocation, contacts, notifications. Creating and editing Boards works without a network connection.

17. Feedback

The "Send Feedback" item in the settings opens your mail client with a draft message to the Operator's address. The identifier of your profile is inserted into the draft — it allows the Operator to match your enquiry with crash reports (section 6). If you do not want to share it, delete this block before sending. The email you send is processed in order to answer your enquiry.

18. Children

The App is not intended for use by persons under the age at which independent consent to the processing of personal data is permitted under applicable law. The Operator does not knowingly collect data of minors. If you become aware that a minor's data has been provided without the consent of a legal representative, report this to brick@alexforge.org so that it can be deleted.

19. Changes to This Policy

The Operator may update this Policy. The current version is always available at the address where the Policy is published; the date of the last update is indicated at the beginning of the document. Material changes are communicated to Users by means of the App or in another available way.

20. Contacts

For all questions related to this Policy and data processing:

Operator: Alexander Sergeevich Seednov
Status: individual (natural person)
Email: brick@alexforge.org