This policy covers BrassWell, a product of Rise Above Media LLC ("BrassWell", "we", "us") — a mobile and web application built for self-employed workers to track income and expenses, estimate taxes, scan receipts, send invoices, and connect bank accounts for automatic transaction import.
Information we collect
Account information you provide directly: name, email address, and business profile details you enter (occupation, income sources, and similar).
Financial data you enter or connect: income and expense entries, invoices and clients, goals and budgets, mileage and time entries, vehicles and odometer readings, a salary log if you record one, 1099 amounts and prior-year tax figures you enter for the estimate, your business type, the logo and payment details you put on your invoices, and receipt photos you upload or scan.
Bank and transaction data, if you choose to connect an account (see "Bank connections" below).
Location, only while you are recording a drive for mileage. The app uses your device's location to measure the distance. When you finish, the start and end points are turned into street addresses, which are filled into the mileage entry for you to keep or edit, and saved with it. The route itself — the trail of GPS points — is never uploaded: it stays on your device while the drive records and is discarded when you save or discard the trip. BrassWell does not use your location at any other time, and never in the background unless a drive you started is recording.
Usage data needed to run the product and diagnose problems (device type, app version, crash reports), and the IP address your requests come from. It appears in our hosting and sign-in providers' logs and, scrambled so it can't be read back, in the counters we use to slow down repeated failed sign-in attempts and repeated contact-form messages.
Security settings, if you turn on the app lock: a one-way hash of your PIN (never the PIN itself) and, if you use Face ID, Touch ID or a passkey, its public key. Neither lets anyone recover the PIN or your biometrics.
If you answer one of the short feedback questions the app asks in your first weeks, your rating and anything you write with it.
Messages you send to support — by email, through the form in the app, or through the contact form on our Support Center — and whatever you include in them. If you choose phone as the way we should reach you, the in-app form also takes your phone number.
If you sign up for updates and offers, or ask to hear when the iPhone app is available, your email address and the date you signed up. Update sign-ups are also added to our mailing list at Resend (see "Who we share it with") so we can send them: product news, money tips and occasional offers. To stop the sign-up form being abused, it counts requests from each network address, and those counts expire within two days.
Information about other people that you enter. If you invoice clients, you can save their name, email address, postal address and your own notes about them. That is other people's personal information, held in your account because you put it there.
Your clients' information
When you store a client's details or send them an invoice, you decide what to collect and why; we hold and process it on your behalf. In data-protection terms you are the controller and we are your processor for that information.
Practically, that means three things. We use client details only to do what you asked — save the record and put them on the invoices you create. BrassWell doesn't send invoices to your clients itself: you download or share the invoice and send it yourself. We do not email your clients anything of our own, market to them, or use their details for any purpose of ours. And if a client of yours asks us directly to access or delete their information, we will point them to you, because it is your record to correct — though you can also delete it yourself at any time, and it goes when your account goes.
The obligation that comes with that: you are responsible for having a lawful basis to hold your clients' information, and for telling them how you use it, in the same way you would be if you kept it in a spreadsheet.
Bank connections (Plaid)
If you choose to connect a bank or card account, BrassWell uses Plaid Inc. to retrieve your transaction data. We request Plaid's Transactions product and nothing else: we don't ask for your account or routing numbers, and we don't ask for identity-verification data. Plaid's transaction responses do include the balance of the account you connected — we don't store it, don't use it, and it appears nowhere in the app.
What we keep from a connected account is the name of the institution and, for each transaction, the date, the amount, whether it was money in or out, the merchant or description, a spending category, and Plaid's id for that transaction so the same one is never imported twice. Imported transactions become ordinary entries in your books — you can edit or delete them like anything else you entered by hand.
Plaid's own handling of your information is governed by Plaid's End User Privacy Policy, which we encourage you to read before connecting an account.
You can disconnect a bank connection at any time from within the app. When you do, we tell Plaid to revoke the connection itself, not just forget it on our side — nothing keeps drawing data from an account you've disconnected. When you delete your BrassWell account, every connection on it is revoked the same way when the account is permanently deleted at the end of the recovery window (see "Data retention and deletion"). Transactions already imported stay in your books as your own entries until you delete them or delete your account.
AI features
BrassWell uses Anthropic's Claude models in three places:
- Receipt scanning. When you photograph or upload a receipt, that image is sent to Anthropic's API to read the date, the amount, the vendor's name and location, the goods or services bought, and the form of payment — the details the IRS expects a receipt to show — and to suggest an expense category. Card numbers are cut to their last four digits before anything is saved. Only the receipt image itself is sent — the model does not have standing access to your account or other financial data.
- Customer support. When you write to support — by emailing support@brasswell.app, through the form in the app, or through the contact form on our Support Center — your message is sent to Anthropic's Claude to sort it and draft a reply, together with earlier messages in the same conversation and the account details needed to answer it: your plan, its status and its trial or renewal dates, the name, contact details and topic you give on either form, and — from the in-app form — the app version and platform you're using. A person reads and approves every reply before it's sent; the only message that goes out automatically is the acknowledgement that we received yours.
- Setting up. If your line of work isn't in the list during setup and you type it in yourself, that short description is sent to Anthropic so the app can suggest expense categories and an example that fit it. Nothing else about you is sent with it.
We don't use your receipts, financial data, or support emails to train AI models, and Anthropic's standard commercial API terms don't permit them to either.
How we use your information
To run the features you signed up for: tracking income and expenses, estimating taxes, generating invoices, importing bank transactions you've chosen to connect, and processing your subscription. If you signed up for updates and offers, we also use your email address to send them, and you can unsubscribe at any time. We do not use your financial data to build advertising profiles, and we do not sell your data.
Who we share it with
We share information only with the service providers that run BrassWell, and only for the purpose of providing their specific service:
- Supabase — database, authentication, and file storage.
- Plaid — bank transaction data, only for accounts you choose to connect.
- Anthropic — reading receipt images when you scan a receipt, the line of work you type during setup if yours isn't in the list, and sorting and drafting replies to the messages you send support (see "AI features").
- RevenueCat, and the underlying app store or payment processor (Apple App Store or Stripe via RevenueCat Web Billing) — subscription billing.
- Resend — email: account notices, receipts and statements you ask for, and, if you signed up for them, product updates and offers. Marketing email carries an unsubscribe link.
- Apple — maps and address lookup (MapKit), only when you record a drive or view a trip's route. Apple receives the coordinates needed to draw the map and to turn a trip's start and end points into addresses.
- Apple and Google sign-in — only if you choose to sign in with one of them. They confirm who you are and share your name and email (or Apple's private relay address) with us.
- Vercel — hosting for the web app. Server logs pass through it.
- Expo — delivers updates to the iPhone app. When the app opens, it asks Expo's update service whether a newer version is available; that request carries the app's version, the device platform and a random install identifier Expo uses to count update downloads — not your account or your records.
- Sentry — error monitoring, so a crash gets fixed rather than silently repeating. We run it with personal data collection switched off and scrub error reports before they are sent; it receives stack traces and technical context, not your financial records.
- Cloudflare — hosting for our websites (brasswell.app and help.brasswell.app) and their cookie-free traffic measurement (Cloudflare Web Analytics), storage of waitlist sign-ups, bot protection (Turnstile) on sensitive actions, and inbound routing for email sent to our support addresses.
- Google Analytics — traffic measurement on our websites (brasswell.app and help.brasswell.app) only, and only if you allow analytics cookies. It is not present in the app.
- PostHog — product analytics inside the web app only, so we can see which features get used and where people get stuck. It is not on our websites. We send it the account identifier you already have with us, the pages of the app you open, and the names of actions you take (for example “connected a bank”, with the bank’s name); we do not send it amounts, balances, client names, invoice contents, or transaction descriptions. Session recording is switched off. It stores nothing on your device — no cookie and no local storage. You can switch it off in Settings › Privacy › Share usage analytics; while that is off, it doesn’t load at all.
These are service providers acting on our instructions, not partners we hand your data to for their own purposes. We do not sell your personal or financial information, and we do not share it for cross-context behavioural advertising — as those terms are defined under the California Consumer Privacy Act. We have never done so, and there is no mechanism in the product for doing so.
Cookies
BrassWell does not use advertising or cross-site tracking cookies, anywhere. Here's everything that is set, by surface. Some of it is "local storage" rather than a cookie: a small value your browser keeps for one site, which is never sent to us with your requests.
Our websites (brasswell.app and help.brasswell.app)
- Analytics — Cloudflare Web Analytics. Measures traffic to these sites. It's cookie-free by design: no cookies, no localStorage, no cross-site tracking, no fingerprinting. How it works.
- Analytics — Google Analytics 4, only if you allow it. Tells us which pages people actually read, so we know what's worth writing more of. If you press "Allow", it sets two cookies,
_gaand_ga_<id>, that distinguish one browser from another and remember whether a visit is a first or a repeat one. They expire after two years. We don't use it for advertising, we don't run Google Ads, and we don't share the data for ad targeting. How Google uses data from sites that use its services. - Your cookie choice —
bw-consent(local storage). Remembers whether you pressed "Allow" or "Essential only", so the notice doesn't reappear on every visit and your answer is applied on every page. It holds that one word and nothing about you. It stays until you change it or clear this site's data. - Light or dark theme —
bw-theme(local storage). Remembers the theme you picked with the theme button. Purely a display preference, never used for tracking. It stays until you change it or clear this site's data.
The websites' typefaces are served from our own servers, so loading a page sends no request to Google Fonts or any other font service.
The web app (app.brasswell.app)
- Strictly necessary — your session. Supabase, our sign-in provider, sets an authentication cookie (named
sb-…-auth-token, sometimes split into numbered parts) so you stay signed in between requests. Without it, the app can't tell you're logged in. It's removed when you sign out; otherwise your browser keeps it for up to 400 days. - Strictly necessary — Face ID, Touch ID and passkey set-up. When you set up or use a device unlock for the app lock, a cookie (
bw-webauthn-challenge) holds the one-time security challenge for that step. It lasts five minutes at most and is deleted as soon as it's used. - Bot protection — Cloudflare Turnstile. When you sign in or create an account, change your password or delete your account, Turnstile checks in the background that you're a person and not a bot. It doesn't set cookies on our site or track you across other sites.
- Payments — Stripe, at checkout only. When you open checkout to subscribe on the web, our billing provider RevenueCat loads Stripe's payment form, and Stripe may set its own fraud-prevention cookies (
__stripe_mid, kept for up to a year, and__stripe_sid, kept for 30 minutes). They help detect fraudulent payments and are not used for advertising. - Functional — theme preference,
brasswell-theme. Remembers whether you've chosen light or dark mode, so it doesn't reset every visit. Kept for a year; purely a display preference, never used for tracking. - Functional — welcome animation,
bw_welcome. Set for 60 seconds when you come back from signing in with Apple or Google, so the app knows to play its welcome; it's deleted as soon as it's read. - Settings kept in your browser (local storage). Your answers to the two questions in Settings › Privacy (AI receipt reading and usage analytics), when you were last active (for the app lock's timer), your theme, setup answers you haven't finished yet, and small reminders such as whether you've dismissed a checklist. They stay on that browser, which is why a choice made on one device doesn't carry to another.
The iPhone app doesn't use cookies. It keeps the same kind of settings on your phone, and the same two Privacy switches are in its Settings.
Changing your choice
Analytics cookies are off until you turn them on. Our websites run Google Consent Mode v2: analytics_storage is set to denied before the Google tag loads, so no _ga cookie is written unless you press "Allow" on the cookie notice. Press "Essential only" and nothing analytics-related is stored — we also clear any _ga cookie left over from a previous visit where you'd agreed. Your choice is re-applied on every page load, and you can change it at any time: on brasswell.app, use the "Cookie settings" link in the footer of any page; on help.brasswell.app, use the "Cookie settings" link in its footer, which brings the notice back. Each site keeps its own answer, so you may be asked once on each. A consent you cannot withdraw is not consent.
Everything else listed above is either strictly necessary to run the sites and app, or a non-tracking functional setting. Those are set without asking, because without them the product does not work as you'd expect.
Why we're allowed to hold it (legal bases)
If you are in the UK or the European Economic Area, the law asks us to name a lawful basis for each use of your information. Ours:
- To perform our contract with you — running the features you subscribed to: your books, tax estimates, invoices, receipt scanning, and bank import if you connect an account.
- Your consent — analytics cookies on our websites, and connecting a bank account, which you grant separately through Plaid's own flow. You can withdraw either at any time, and withdrawing it doesn't affect anything done before you did.
- Our legitimate interests — keeping the service secure, preventing fraud and abuse, fixing errors, and understanding which parts of the product people actually use. We've considered your interests in each case; where they'd outweigh ours, we don't do the thing.
- Legal obligation — keeping billing records for the period tax law requires.
Where your data is held
BrassWell is operated from the United States and your data is stored there — our database is in Oregon and the web app is served from the US West region. Our service providers may process data in other countries in the course of running their own services.
If you are in the UK or EEA, this means your information is transferred outside your home jurisdiction. Where that transfer requires a safeguard, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) in our agreements with the providers listed above. If you'd like to know how a specific provider handles this, ask us and we'll tell you.
Your rights
Wherever you live, you can do all of the following, and most of them without asking us: review and correct your profile, export everything you've entered as a single file, disconnect a bank, and delete your account. Those are buttons in the app, not requests you have to make.
If you are in the UK or EEA, you also have the right to ask for a copy of the information we hold about you, to have it corrected or erased, to restrict or object to certain processing, to receive it in a portable format, and to complain to your local data protection authority. In the UK that is the Information Commissioner's Office. We'd rather you came to us first, but you don't have to.
If you are in California, you have the right to know what we collect and why, to a copy of it, to correct it, to delete it, and not to be discriminated against for exercising any of those — we don't offer a worse product or a higher price to anyone who does. You may use an authorised agent. There is no "Do Not Sell or Share My Personal Information" link on this site because there is nothing to opt out of: we don't sell personal information and we don't share it for cross-context behavioural advertising.
To exercise any of this, email support@brasswell.app. We'll respond within 30 days, and we'll verify it's really you before we hand over or delete anything — usually by confirming you control the account's email address.
Data retention and deletion
You can export your data at any time, whether or not you're currently subscribed: from Settings, or from the plan screen the app shows if your account is locked. When a trial or subscription ends, the account locks, but nothing you've entered is deleted — the one exception is receipt photos, below.
If you request account deletion, your account locks immediately and is permanently deleted after a 30-day recovery window — this window exists so a mistaken or fraudulent deletion request can be reversed, not to keep using the account. If your subscription is still renewing, you can instead choose to delete when the current paid period ends; the account still locks straight away, and the 30-day window then starts from the end of that period. You'll be notified by email before the window closes.
A bank connection is kept only while it is connected. Transaction data imported from one is kept as part of your books for as long as your account exists, because it is your record — delete an entry and it's gone, delete your account and all of it goes.
Receipt photos are stored while you have a plan that includes them. If that plan ends, they're kept for at least 30 days before they're deleted. Before anything is deleted we email you twice with a link to download them — once soon after the plan ends, and again at least five days before the deletion — and nothing else in your account is affected.
If you scan a receipt but never save the expense it belongs to, that photo is deleted after a week.
Three things outlive the account deletion itself, and it's fair that you know which:
- Encrypted backups roll off on their own schedule and are fully replaced within 30 days of deletion. We don't restore a deleted account from one.
- Billing records — what you paid and when — are kept for as long as tax law requires us to keep them. We can't delete those on request.
- Support correspondence you've sent us is kept for one year after your last message — so we have the history if you write in again or a payment is disputed — then deleted from our support systems. The services that deliver and sort it (Resend and Anthropic, above) keep their own copies only briefly, under their own terms. Ask and we'll remove it sooner.
Server and error logs are kept for no more than 30 days.
Security
Data is encrypted in transit (HTTPS/TLS) and at rest, and access to your data is scoped to your account only — one user's login cannot reach another's records, enforced at the database level rather than in application code. Bank access tokens are encrypted and held server-side; they never reach the browser or the app bundle. Connecting a bank requires you to confirm your identity first (Face ID, Touch ID, or your PIN), which is a deliberate extra step, not a bug.
No system is perfect. If we ever discover a breach affecting your personal information, we will tell you — what happened, what was affected, and what we're doing about it — without waiting to be forced to, and within the timeframes the law requires where they apply.
Your choices
You can review and edit your profile information, disconnect a bank connection, export your data, or delete your account at any time from within the app.
In Settings › Privacy you can turn off AI receipt reading (the scanner then asks before it sends a photo, and you can still add expenses by hand) and usage analytics. Those choices are saved on each device. On our websites, the "Cookie settings" link in the footer changes your analytics-cookie choice — see Cookies.
Questions about your data
Write to support@brasswell.app about anything to do with your own account and data — access, correction, export, or deletion. A person reads every message. For anything else, hello@brasswell.app.
By post: Rise Above Media LLC, 3419 Via Lido #1036, Newport Beach, CA 92663, United States.
Children's privacy
BrassWell is not directed at children and is not intended for use by anyone under 18.
Changes to this policy
If we make a material change to how we handle your information, we'll update the date at the top of this page and, where appropriate, notify you directly.