Effective date: September 29, 2026
What changed on September 29, 2026. The current BeFree apps now ask for explicit permission before sending content to Anthropic or Voyage AI, and AI processing explains what happens for an account that has not used a current app yet. We name the data each provider receives, and explain how to continue without AI or withdraw permission across your account. We also describe the content-free basic usage events for items filed in BeFree, suggestions in Now, deferred items that resurface, and weekly recaps, and clarify which of these records include an installation identifier.
BeFree is a brain dump app: you talk or type, and BeFree organises what you share into tasks, calendar events, reminders, grocery items, and notes.
This policy describes what BeFree collects, why, and what choices you have. It is written to be read, not skimmed past. If anything is unclear, email us at support@heybefree.app.
BeFree is an Australian sole trader based in Melbourne, ABN 97 438 247 710, and is the data controller for everything described here. It is a one-person business, so the person responsible for the decisions in this policy is the same person who writes the app. The way to reach us is support@heybefree.app, and it is read by that person. If you need a postal address for a formal request, ask there and we will provide one.
Account information. When you sign in, we create an account identifier and store the email, Apple Sign-In, or Google Sign-In identifier you used. BeFree's own internal reports also list accounts by email address, to understand how BeFree is used (see AI processing). If the service you signed in with gives us a name, we store that too, and you can set the name BeFree uses for you in the app; BeFree uses it to address you, in the emails it sends you, and, where a notification reads better for it, in the wording of a reminder. We also store your device’s time zone — not your location, just the zone your phone reports — so that a reminder you set for 9am arrives at 9am where you are and BeFree can work out what “tomorrow” means. It is updated when your time zone changes.
Your content. We store the content you create — tasks, events, reminders, grocery items, lists, notes, projects, tags, and the original brain-dump text — and your conversations with BeFree: what you said or typed to it, what it replied, and any search you asked it to run there. This is the data you'd lose if your phone fell in the ocean, and it's what BeFree exists to keep safe across devices. It holds whatever you choose to put in it, and that can include health details, such as a condition, a medication, a doctor's appointment or a workout. BeFree keeps those like anything else you give it and uses them to help you, for example by filing a reminder to take a medication or marking an item as health-related. The words you type into BeFree's search box are different: they are used to find matches and are not kept. If product analytics is on, it records only roughly how long the search was and how many results came back.
Item history. BeFree keeps the original text you submit, links it to the items it creates or changes, and records meaningful changes such as moving a plan, waiting, completing an item, or choosing Later. This private history helps you see what happened and gives the AI relevant context across your items. It is account content, separate from analytics, and is included in your data export. Offline changes enter the timeline when they reach our servers; the displayed recording time may differ from when you made the change. Existing items start with a snapshot when history becomes available; BeFree does not invent earlier decisions. In versions with History, you can clear an item’s recorded history while online. This keeps the current item and any active Later choice; it removes the item’s timeline and source links, and erases original text when no other linked item still needs it. Later edits start new history. Original captures are supplied to the AI for an explicit source/history question, rather than added to every unrelated request; they do not become standing personal facts.
Voice audio is not stored by BeFree. On Apple devices, speech-to-text is handled by Apple's built-in speech recognition; depending on your device and language, Apple may process the audio on its servers to produce the transcript. If you use BeFree in a web browser, speech-to-text is provided by your browser's own speech engine and may be processed by the browser vendor's servers. On Android, speech-to-text is handled by your phone's speech recognition service, which is usually Google's and may process the audio on its servers to produce the transcript. On Android 13 and later, BeFree passes your microphone audio to that service on your phone; on earlier versions of Android the service listens to the microphone itself. In every case, BeFree's servers never receive or store your raw audio — we receive only the resulting text, and only when you submit a capture.
Personalisation. BeFree derives lightweight usage patterns from how you use the app — such as the corrections you make to what it filed and the items you let go — and can remember personal facts you explicitly volunteer during a capture (for example, “I don't drive”) so sorting fits your life. Those facts are stored in your own words, exactly as you said them, and are sent to our language-model processor as context on every later capture — that is what makes the sorting fit you rather than a generic user. Because it is your own free text, it holds whatever you choose to tell BeFree, and that can include things you consider sensitive, such as a health condition or the suburb or city you live in. BeFree keeps these facts and uses them to help you. When BeFree has kept where you live or are based — a suburb or a city, say — it treats that as your location when a later capture needs one, for example to work out what “near me” means. BeFree does not go looking for such information and stores nothing from a capture unless you volunteer it. You can see every one of these facts in You → Settings → Privacy & data → What BeFree knows about you, or by asking BeFree “what do you know about me”: each appears in your own words with the date it was learned, and you can delete any one of them or clear them all.
Separately, BeFree does ask you a few things directly, and it is fair to call that asking. In the iPhone and Android app, after you save your first thought, an optional step asks what to call you (only if BeFree does not already have your name), what would make life a little easier, where BeFree will help (everyday life, work, study or family life), how you like BeFree’s replies, and anything you would love help with. You can skip any question, or choose “Set up later” to leave the step, which keeps anything you have already answered, and you can change or remove your answers at any time in You → How BeFree helps you. You → Settings → Personalisation also lets you say who you live with, what your working week looks like, and, in a “Looking after” field, whether you are looking after kids, pets or parents. The point of each is stated on the screen: for example, “Looking after” helps BeFree work out who you mean by “the kids”, “the dog” or “my folks”. Your answers are stored on your account and sent to the language-model processor as context in the same way, and like everything else here they are optional and removed when you delete your account. They are not listed on the “What BeFree knows about you” screen, which shows only the facts you volunteered mid-capture.
All of it is included in your data export, and all of it is removed when you delete your account.
Apple Calendar and Reminders on iPhone and iPad. If you grant access, BeFree reads from your selected Apple Calendar and Apple Reminders to show events and reminders in the app. If you turn on Two-way sync in You → Settings → Connections, BeFree also writes events and reminders you create in BeFree to a calendar or list you choose. On iPhone and iPad, this write connection changes only items created in BeFree. Events imported from Apple Calendar are stored in your BeFree account so they can sync across your devices and work with search and AI features, including embeddings of event text. Your Apple Reminders mirror stays on your device and is not sent to BeFree's servers. Two-way sync is off until you enable it, separately on each device; turning it off stops further writes.
Apple Calendar and Reminders on Mac. These connections are optional and enabled separately on this Mac. BeFree reads events and reminders through Apple's EventKit to show them beside your BeFree items. These local Calendar and Reminders records, and their device identifiers, are not imported into your BeFree account or sent to BeFree's AI processors by these connections. Calendar access is read-only in this Mac version: it does not publish BeFree events to Apple Calendar. The Reminders connection lets you edit or complete a one-time reminder, including one created outside BeFree, when you choose to do so. Those changes are saved directly to Apple Reminders; repeating reminders and lists that cannot be edited are opened in Apple Reminders for changes. Apple's own account and sync settings may carry these changes to your other Apple devices. Turning a connection off stops BeFree reading from it and removes its local items from BeFree's view. Items you create in BeFree continue to use the account sync described above.
Google Calendar. (This connection is rolling out and may not yet be available in your version of BeFree; on iPhone, Google calendars you've added in iOS Settings already appear through Apple Calendar, covered above.) If you connect a Google account in You → Settings → Connections, BeFree requests calendar read + write access via Google OAuth 2.0. Read access lets BeFree show your Google events alongside what you capture; write access lets BeFree push events you create in BeFree back to your Google calendar. OAuth tokens are stored in your device's secure storage (the Keychain on Apple devices). When an access token expires, the refresh token is sent over TLS to BeFree's private Supabase Edge Function solely to exchange it with Google; BeFree stores only a one-way token hash server-side and does not persist the raw token. You can disconnect at any time in You → Settings → Connections; disconnecting clears every token and removes the Google-imported events from your BeFree views.
Google API Services User Data Policy — Limited Use disclosure. BeFree's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. When you connect Google Calendar, BeFree reads your events (title, description, location, start/end times, and identifiers) and writes events you create in BeFree back to a calendar you choose. That data is used only to provide the user-facing features you turn on: (a) a unified calendar view with two-way sync; (b) AI organisation of what you capture — when you record a brain dump, BeFree gives the language model your upcoming events (event title and start/end times only — descriptions and locations are not sent to the language model) so it can answer “what's on my schedule,” let you reference an event by voice, and avoid duplicates; and (c) in-app search, for which BeFree generates a numerical embedding of each event's text (title, description, and location). To deliver these features, BeFree shares event data with its processors — Anthropic (Claude; receives event title + times), Voyage AI (receives event title + description + location to build the search embedding), Supabase (stores your events in your own row of our database), and PowerSync (syncs your own data to your devices) — each solely to provide the features above. Specifically: (1) we use Google user data only to provide those features; (2) we do not transfer it to third parties except to the processors named here to provide the features, for security purposes, or to comply with applicable law; (3) we do not use it to serve advertisements, and we do not sell it; and (4) we do not allow humans to read it unless we have your affirmative agreement, doing so is necessary for security purposes (such as investigating abuse), or to comply with applicable law. Anthropic is contractually prohibited from using your content to train its models; the context sent to Anthropic is assembled fresh for each request and is not retained by BeFree beyond a per-request record of the run itself — which model answered, how long it took, what it cost, how the request was classified, whether personal context was used, and a one-way fingerprint of the text, which lets us recognise a repeat of the same request without being able to read it back. That record is keyed to your account and is deleted when you delete your account. The Voyage embedding is stored as a numerical vector (not the original event text) and is deleted when you delete the event or your account; BeFree has enabled its organization-level training opt-out with Voyage, so text sent to Voyage is excluded from model training and deleted by Voyage after processing. Disconnecting Google Calendar in You → Settings → Connections stops all future syncing and removes the imported events (including their embeddings).
Photos and Camera. BeFree touches your camera or photo library in exactly two places, and you start both of them.
A photo you attach to a note. BeFree first resizes and re-encodes the image on your device — a step that also removes embedded metadata such as GPS coordinates, camera model, and device serial — and then uploads the resulting image to encrypted object storage so it can sync across your devices. The image is associated with your account and served to the app via short-lived signed URLs. Deleting a note hides it from the app immediately; the stored image is purged when you delete the attachment from the note or delete your account. A photo you take with the in-app camera is treated identically.
A photo you ask BeFree to read. The camera button in the Talk room lets you hand BeFree a picture — a whiteboard, a school note, a receipt — and have it turned into tasks, events or notes. You pick the image, you see exactly what you picked, you can edit the instruction, and nothing leaves your device until you press Process. BeFree then resizes and re-encodes it (again removing embedded metadata) and sends it to our language-model processor to be read, along with your instruction. The items it produces are saved to your account. The picture itself is not stored on our servers and is not kept as an attachment.
We do not access your photo library or camera at any other time, and never in the background.
Microphone. On Apple devices, BeFree captures your voice using Apple's built-in speech recognition; depending on your device and language, Apple may process the audio on its servers to produce the transcript. In a web browser, your browser's own speech engine produces the transcript. On Android, your phone's speech recognition service, usually Google's, produces the transcript and may process the audio on its servers; on Android 13 and later BeFree passes the microphone audio to that service on your phone. BeFree's servers never receive or store your raw audio. Only the resulting transcript text is sent to our servers, and only if you submit the capture.
Location. BeFree does not collect device location in this release. If a future feature needs it, we will update this policy first. BeFree can still learn a place from you: if you say where you live or are based, it can keep that as a personal fact and use it as your location, as described under Personalisation above.
Purchases. RevenueCat processes your BeFree account identifier, subscription, transaction, and entitlement details so Pro works across your devices. The iPhone, iPad and Android apps set up a RevenueCat customer record as soon as the app opens, whether or not you ever buy anything, so the app can check whether your account has Pro: it is keyed to a random identifier until you sign in, and to your BeFree account identifier after that. The Mac app sets one up when you sign in. In these apps, RevenueCat's software also sends your device model, operating-system version, App Store or Google Play country and language settings with its requests; on Android it also sends the device brand, and on iPhone and iPad it also sends the identifier Apple gives BeFree's apps on that device (not an advertising identifier). Apple processes App Store purchases. For web purchases, RevenueCat manages checkout, subscriptions, receipts, and the customer portal, and Stripe processes payments and fraud checks. These providers receive the email address and any billing details you enter at checkout, along with payment and transaction information and technical information such as your IP address. Your card details are entered directly into the payment provider's secure fields; BeFree does not receive or store your full card number or security code. We receive subscription status and transaction references to provide access and billing support. BeFree does not send your captures, notes, or calendar content to payment providers. Payment providers may retain transaction records as required for accounting, fraud prevention, and legal obligations, including after you delete your BeFree account.
Install attribution (iPhone and iPad). The first time BeFree runs, Apple hands the app a short-lived attribution token. This happens on every iPhone and iPad install, not only ones that followed an advertisement. BeFree passes the token to RevenueCat, which exchanges it with Apple and gets back either a description of the advertisement that led to the install — identifiers for the campaign, ad group, keyword and advertisement, the kind of interaction, the country or region, and the date — or the answer that this install followed no advertisement at all, which is what Apple returns for anyone who found BeFree through search, a link, or word of mouth. Either answer is held against your BeFree account identifier. We use it to learn which advertisements bring people who stay, and for nothing else.
It describes an advertisement, not you. It carries no advertising identifier (IDFA) — BeFree never asks for one and shows no tracking prompt — Apple returns identifiers rather than anything you typed, we do not use it to build a profile of you, and it does not follow you into other companies’ apps or websites.
One thing here is not only Apple and us. Like most apps that have ever advertised, BeFree lists a handful of advertising networks’ identifiers in its app bundle so that Apple can tell a network its advertisement led to an install. Those messages come from Apple, not from BeFree; they are deliberately delayed and coarsened by Apple so they cannot be tied back to a person, and we send those networks nothing ourselves. Deleting your BeFree account removes this from our systems; as with the purchase records described above, RevenueCat may keep its own copy under its retention obligations.
How you found BeFree. If you open the iPhone or Android app, or the web app, through one of our own tracked links, BeFree keeps that link's campaign code and, once you sign in, stores it against your account identifier: the first one as where you came from, and later ones as return visits. On Android, the first time BeFree runs it also reads Google Play's install referrer once — Google Play's note of what led to the install. BeFree keeps only our own campaign code from it or, if you found BeFree by searching or browsing Google Play, the fact that the install came from there; nothing else in it is kept. Early on, BeFree may also ask where you heard about it. You can pick an answer or dismiss the question; if you dismiss it, it asks again at most once on that device or browser. If you answer, it offers one optional line to say, in your own words, what made you try it. Your answers are stored on your account and are not used to sort your captures. We use all of this to learn which of our links, posts and channels bring people who stay.
Crash reports and technical diagnostics. When BeFree crashes or hits an error, we receive a crash report. This happens for everyone and cannot be turned off — without it we cannot tell that the app is broken for you. The same channel also records that the app started, which is how we tell a quiet release from a reporter that has stopped working, and a sample of timing traces showing how long parts of the app took. What is sent is the technical detail of the failure or the trace — what code ran, the app version, the device model and OS version, and basic device state such as free memory and storage — together with a pseudonymous installation identifier, which identifies the installation of the app and not you. It never contains your thoughts, your captures, or any content you have written. This is processed by Sentry.
What you do control is whether your account identifier is attached to it. The “Usage analytics” setting governs that link and is on by default, so by default a crash report can be tied to your account; while it is off these reports reach us without anything tying them to your account. Turning it off does not stop the reports themselves, and we would rather say so plainly than imply a switch that does not exist.
Separately, Expo — the service that delivers over-the-air updates to the app — receives its own per-installation identifier when the app checks whether an update is available, along with a short technical error note if loading an earlier update failed. Our offline-sync service receives a random identifier for each copy of the app so it can keep that copy in step with your account.
Product-usage analytics. BeFree measures how the app is actually used, and this is on by default. You can turn it off at any time with the “Usage analytics” switch in You → Settings → Privacy & data. We are telling you the default plainly because it changed: earlier versions of BeFree collected nothing unless you opted in, and enough people never saw the switch that we could not tell a broken release from a quiet one.
When it is on, we collect pseudonymous product-usage analytics linked to your account identifier — not to your name or email — and your account identifier is also attached to crash reports so we can tell whether a crash affected you specifically. This is processed by PostHog, which may also record the network (IP) address each report came from. Two things travel on that channel:
BeFree does not record your screen. There is no session replay and no screen recording of any kind; if that ever changes, this policy will say so before it ships.
When you turn the switch off, both stop and your account identifier is detached from crash reports. Crash reporting itself continues, as described above, because without it we cannot tell that the app is broken for you.
Basic usage records. Separately from the analytics above, BeFree keeps three small usage logs on its own servers, each limited to a fixed list of named events — a closed list, not free-form logging. The first is the one described here. Those events cover: that the app was opened, and that it was opened for the first time after installing; onboarding milestones; capture milestones (a capture started, filed, edited, or routed to your reminders); that a new BeFree item was filed; an item being completed, resurfaced, or consciously let go; opening Now and completing, deferring, or dismissing a suggested item; seeing a deferred item resurface in Now or completing it there; viewing or explicitly sharing your weekly recap; that you were asked when BeFree should bring things back each day, and whether you chose morning, midday or evening or declined; that a reminder or briefing notification was scheduled, that it fired, and whether you tapped it; that you came back on a later day and did something; what became of the first thought you gave BeFree before signing in; that a free trial started and that it ended; views and dismissals of the upgrade screen, an upgrade nudge being shown or acted on, and a feature being met behind Pro; the steps of a purchase (tapped, started, completed, cancelled, failed); that you were asked where you heard about BeFree, and whether you answered or dismissed the question; and the rating moment — that BeFree asked whether it was keeping its promises, that you dismissed or answered, that the App Store’s own rating prompt was requested, and that a feedback message was sent, never any part of what you wrote.
Each record says which named event happened and when, and carries at most one broad category from a fixed list (for example, that a capture came from voice rather than typing). Before sign-in, device-recorded events carry a random installation identifier when one can be established; after sign-in, earlier records that are sent to us and later records are linked to your account identifier. Device-recorded events include that identifier when available; server-recorded item creation events do not. For a completed capture it may also carry plain millisecond numbers for how long each processing step took, which we use to keep capture fast. It never contains your content or free text, and no location details. It is never sold, never shared with a third party, and never used to show you ads; it does help us judge how well our own promotion of BeFree works, as described under How you found BeFree above. Because we rely on these records to run the service and to judge our own promotion, for the reasons given under Why we are allowed to do this, they are not covered by the “Usage analytics” setting; you can object to them at support@heybefree.app. These records are deleted when you delete your account and, in any case, after 400 days.
Before you sign in. BeFree records onboarding steps before you have an account and, when it can establish an installation identifier, the first open of the app. These records are initially kept on your device without an account link; when available, they carry a random identifier generated on your device. It is not your device's own identifier, we cannot read it from anywhere else, and it identifies an installation of BeFree and nothing beyond it. When you sign in, recent earlier records still on your device are linked to your new account, and the identifier stays on later device-recorded events when available so that records from different installations of BeFree can be told apart; if you never sign in, the earlier records are never sent to our servers. Server records carrying the identifier are deleted when you delete your account and, in any case, after 400 days. We collect this because the alternative — starting to count only once someone signs up — hid the exact moment most people were leaving.
The second log is narrower: it records four named steps of a single capture as it moves through the app, so we can see where captures get stuck. Alongside the step it holds an identifier for that capture and that session, the app version, build and release channel, and counts of how many items a capture produced. It holds no content and no free text, and it is deleted on the same terms.
The third log helps us understand where getting started succeeds or stops, including before you sign in. It records a fixed set of milestones, such as seeing sign-in, viewing an example, saving a first thought, seeing an offer, or finishing a setup step. It contains random event and onboarding identifiers, the event time, app platform and build, the version of the onboarding experience, and a broad entry category. It never contains your thoughts, titles, email address, or other content. If you sign in, we link that onboarding record to your verified account so we can understand whether the experience leads to useful use and a subscription. We do not join it to another person's account or use it for advertising. The app keeps a small retry queue for up to seven days. Server records are removed when the linked account is deleted and, in any case, after 400 days from first collection. A short-lived keyed digest of the network address helps prevent abuse and is removed after two days; the address itself is not retained in this log.
Emails we send you. Most email from BeFree is transactional: a sign-in link you asked for, or a message about your account or a purchase. There is one other kind, and it is fair to call it marketing. BeFree may email you about the app itself — typically because you signed up and then did not come back, or because a free trial is about to end — and it decides who to write to from records of your activity, such as how many captures you have made, when you last made one and whether a trial is ending, never from your content. Those emails greet you by name if BeFree has one, and are sent through Resend. Every one carries a one-click unsubscribe link, and your browser or mail app can unsubscribe for you without opening it. Unsubscribing stops all of them permanently and changes nothing else about your account. You can also just email us and we will do it. As of September 6, 2026 BeFree had sent 27 such emails in its life, so this is a rare thing rather than a stream.
Feedback you send us. BeFree may occasionally ask, on the Today screen, whether it is keeping its promises. Answering costs nothing and changes nothing: whatever you say — or if you dismiss the question — the app behaves exactly as it did before. If you answer that it isn’t, BeFree offers a single text box, and what you type there is the only thing it sends. That message is stored in your BeFree account and read by the person who builds BeFree. Alongside it we store which answer opened the box, a marker for how the message was entered, the app version and build, the platform, and the language the app was displaying — the details that decide whether what you describe is already fixed. It never includes your captures, your transcripts, your notes, or the titles of anything you have filed. It is never shared with a third party and never used for advertising. Unless your version of BeFree offers Talk to us (see Community, private messages and feedback calls below), it is not shown back to you anywhere in the app. We read everything. An answer to the Today question is not a support request and we do not promise a reply; for help, use Talk to us. It is deleted when you delete your account. If sending fails, BeFree offers to open an email to support@heybefree.app instead — that route composes a message in your own mail app and sends us nothing until you press send.
Connected AI apps. If you choose to connect BeFree to an AI app or coding agent, BeFree uses OAuth so you can review and approve the connection first. The connected app can then request the BeFree records needed for the feature you invoke — your notes, projects, tasks, reminders, grocery items, BeFree-owned events, your past conversations with BeFree, relevant item and commitment history, BeFree's suggestions from Insights and what you did with them, any focus sessions, and the personal facts described under Personalisation above. Those personal facts are held back from BeFree’s default response and handed over only when the connected app explicitly asks for that section. Calendar events imported from Google, Apple, or your device are never available through this connection. A connected app can also send text through BeFree’s capture pipeline and receive what BeFree filed, so use this with AI apps you trust and read their write confirmations. The connected app handles what it receives under its own terms and privacy policy; BeFree does not control what happens inside that service. BeFree keeps a content-free access log — your account identifier, which app, which BeFree tool ran, when, whether it succeeded, and a one-way keyed digest used for debugging — never the query, the captured text, or the records returned. You can see every connected app and cut any of them off in You → Settings → Connections in the app, or on your account page in the web app; revoking clears its tokens immediately.
We do not sell your data, and we do not track you across other companies’ apps or websites.
The two things below happen on heybefree.app, the site you are reading now, and not inside the BeFree app.
The demo on this website. The home page and the /adhd page let you try a brain dump without installing anything. What you type or dictate there is sent to a BeFree server, which passes it straight to our language-model processor and returns the sorted result to your browser. Nothing you type into the demo is stored — there is no account, no database write, and no record of the text on our side. We keep an anonymous cost record of the request for accounting, and your IP address is used briefly, in memory, to stop one visitor running the demo thousands of times. Speech in the demo is handled by your browser’s own speech engine, as described under Voice audio above.
Basic website analytics (Vercel). Our marketing website at heybefree.app measures aggregate traffic using Vercel Web Analytics, provided by the same company that hosts the site. Vercel's analytics set no cookies and store nothing on your device. They record which page was viewed, the site that referred you, an approximate location (country, region, city) derived from your IP address, your device type, browser, and operating system, and the time of the visit. Your IP address itself is not stored, and the temporary identifier used to count a visit is discarded after 24 hours. Vercel's measurement is aggregate only — it is never linked to your BeFree account, is not used for advertising, and is not combined with other data. A content blocker or your browser's “Do Not Track” setting can stop Vercel's measurement, and you can email us at support@heybefree.app to object. The signed-in web app at app.heybefree.app also uses Vercel Web Analytics, and there it is governed by the web app’s own usage-data setting, which applies only to that browser: while that setting is off, the web app loads no analytics at all. The website also sets one first-party cookie, `bf_ref`, when you arrive through one of our own tracked links: it holds only the campaign code for that link, lasts 90 days, and is used solely to credit the channel that brought you here if you later sign up. It identifies a campaign, not you.
BeFree uses Anthropic (Claude) to organise captures and answer questions, and Voyage AI to generate search embeddings. Before either receives your personal content, BeFree displays a separate disclosure with two choices: Allow AI processing and Continue without AI. Signing in, subscribing, accepting general terms, microphone permission and merely opening this policy do not give that permission. From the moment a current version of BeFree first saves something for your account or shows you this choice, nothing is sent to these providers until you allow it: not what you send from a current version, not what BeFree does on its own in the background (such as indexing saved items for search or sorting a saved note again), and not what reaches BeFree through an assistant you connected. The one exception is an older version of the app still installed on another device, which cannot show this choice; see If you have not used a current version yet. Once you choose, your choice applies on every device, including those older versions, and in background processing.
If you have not used a current version yet. Versions of BeFree released before September 29, 2026 do not show this choice. For now, an account that has never been opened in a current version is processed as it was before this change: when you use AI features, your content goes to Anthropic and Voyage AI as described below, including in the background, for example to index saved items for search. (A current version counts as used once it has saved something for your account or shown you this choice; merely signing in to one does not change how your account is processed.) If you have used a current version but not chosen yet, an older version still installed on another device keeps sending the requests you make in it, as before, until you choose; everything else waits for your choice. To make the choice, update BeFree: it asks before your first AI request, and you can also choose under Privacy & data. When this transition ends, an account that has not chosen will get no AI processing until it does, and we will update this policy when that happens. In this policy, "AI processing is on" means you allowed it, or your account is still in this transition.
What Anthropic receives. Your typed thoughts or speech transcripts, photos you choose to process, and relevant context from your account: saved notes, tasks, reminders, calendar event titles and times, conversations, lists, projects, tags, plans, recent decisions, usage patterns and personal details you provided. These can contain sensitive information. The purpose is to organise your captures, find relevant context and answer your requests.
What Voyage AI receives. Search queries and searchable text from your saved items, including notes, tasks, reminders, calendar events and conversations. For calendar events, this includes titles, descriptions and locations. Voyage turns that text into numerical embeddings used for search and related-item retrieval. While AI processing is on, this also happens automatically when you save or change content. Raw microphone audio is not sent to Anthropic or Voyage AI; speech recognition is described separately under Voice audio.
Your choice and withdrawal. If you choose Continue without AI or turn AI processing off, you can read saved items, use manual entry and basic local search, and export or delete your data. AI organisation, meeting action extraction, semantic search and background embedding generation stay off. The choice is saved to your account with the disclosure version and decision time. Change it under You → Settings → Privacy & data → AI processing (Account → AI processing on the web). Turning it off stops new requests on every device and in background jobs once the change is saved online. A failed save is shown as a failure; it does not claim that other devices have changed. Requests already sent cannot be recalled. Withdrawing does not automatically delete your saved content or existing embeddings; deleting an item or the account removes its stored embeddings as described below.
BeFree relies on a small set of service providers to operate the app:
For the current list of named providers, see our Subprocessors page. We update that list when we change a provider, so you can always see exactly who processes BeFree data.
These providers process data only for the services and optional analytics described above. BeFree requires third parties that receive personal data, including Anthropic and Voyage AI, to provide the same or equal protection as described in this policy, under their applicable data-processing terms and our configured privacy controls. They must protect its confidentiality and security and process it only for the stated purposes. The AI training and retention controls are described above. We do not sell personal data.
BeFree is run from Australia. Your account and everything you capture are stored in Japan, in our database provider’s Tokyo region, and the providers that process your content, such as our language-model and search processors, operate in the United States and the European Union. Using BeFree therefore means your data is transferred out of your own country — including out of the EEA and the UK for people there. We rely on our providers’ standard contractual clauses for those transfers, and we choose providers that offer them. The current list, and where each one operates, is on our Subprocessors page.
If you are in the EEA or the UK, these are the lawful bases we rely on. We are naming them because several of the streams above cannot be switched off, and you are entitled to know why that is permitted rather than simply being told it happens.
Depending on where you live, you have the right to ask for a copy of your data, to correct it, to delete it, to take it elsewhere, to object to processing based on legitimate interest, and to withdraw a consent you gave. BeFree tries to make the first and the third self-service: you can export your data and delete your account from inside the app, without asking us. For anything else, email support@heybefree.app from the address on your account and we will answer within 30 days.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in California law. We do not use your data to make automated decisions that have a legal or similarly significant effect on you.
If you think we have got something wrong, tell us first — it is one person reading, and it is usually quicker. You also have the right to go straight to a regulator: in Australia, the Office of the Australian Information Commissioner; in the EEA or the UK, your national data protection authority. We have not appointed an EU or UK representative under Article 27; if that applies to you and matters, say so and we will tell you where that stands.
BeFree uses encrypted network connections and database-level access controls so each account can access only its own data. Authorized BeFree personnel can access stored data when necessary to operate, secure, or support the service — for example, to investigate a bug you've reported or respond to a security incident — and for the other purposes described above, such as understanding how BeFree is used and learning which of our channels bring people who stay, and never for any other purpose. Data imported from Google Calendar is the exception, and a stricter one: under Google’s Limited Use rules, described above, nobody here reads it unless you have specifically agreed, it is necessary for security, or the law requires it. We design around least-necessary processing — no provider sees more than they need to do their job. No system is perfect, and we recommend keeping your device's OS up to date.
You can:
For step-by-step instructions, see our Data Deletion guide.
Earlier versions of BeFree let you start without signing in (“Skip — try without an account”). If you used that option, your account exists only as an opaque identifier generated by your device. We do not collect your email, name, Apple ID, or any other information that could let us recognise you across requests. Current versions require signing in with Apple, Google, or email before use.
Because there is no information we can use to verify that a data-access, correction, or portability request is coming from the account’s owner, we cannot fulfil those requests for an anonymous account by email. The in-app Delete Account flow (see our Data Deletion guide) is the self-service equivalent of these rights — from inside the app, it permanently removes your data from BeFree's systems (see Data retention for what our providers keep), and it does not require us to identify you.
If you later sign in with Apple or email, your existing anonymous data is linked to the new identifier and you can exercise all of your rights by emailing support@heybefree.app.
BeFree also runs in a browser at app.heybefree.app, as a Mac app, and on Android. All of them use the same account, the same servers, and the same rights described in this policy. The differences worth naming: in a browser, microphone and speech-to-text are provided by your browser (see Voice audio above) and permissions are managed through your browser's site settings rather than iOS Settings; our web host processes standard request information such as IP address and browser type to serve the site. On Android, speech-to-text is provided by your phone's speech recognition service, usually Google's (see Voice audio above), permissions are managed in your phone's Settings, and the app reads Google Play's install referrer once, as described under How you found BeFree.
BeFree switches these features on separately from app updates, so your version may not show them yet. This section describes what happens wherever they are available.
Private messages and feedback. You can write to the BeFree team privately through Talk to us. We store only the words you submit, your account identifier, when you sent them, and available context such as the app version and build, the platform, and the language the app was displaying. We do not attach your captures, transcripts, notes, or filed items. Where Talk to us is available, the messages you send from it — and from the feedback box described under Feedback you send us — are shown back to you there, together with any reply from the BeFree team. Talk to us is how you ask the BeFree team for help: we read every message and answer in Talk to us when we can, though we cannot promise a reply to every message or a response time. (The sentence under Feedback you send us that begins “An answer to the Today question is not a support request” is about the Today question, not Talk to us.) Messages and replies are stored in Supabase and are visible only to you and the BeFree team. They are not public or used for advertising. Replies are not sent by email or notification. A community report uses this same private channel and includes the link and the reason you give. Messages and replies are deleted when you delete your account or erase your data. The email alternative opens a draft to support@heybefree.app in your mail app; nothing is emailed until you send it.
Public community. Reading the community does not require an account. If you choose to post or reply, we store your text, chosen public name (or “BeFree member”), account identifier, timestamps, and moderation status in Supabase. The BeFree team reviews every post and reply before anyone else can see it. After review, the text, public name and date can be read by anyone, including people outside BeFree. Your account email and identifier are not published. Pending posts are visible to their author and our team. We also store which authors you block so their content can be hidden from your signed-in view. Before your first post or reply we ask you to agree to the community rules, and we store which version of the rules you agreed to and when. When the team moderates, it sees your public name and a reference derived from your account, not your email address. If you break the rules we may hide what you posted and stop your account from posting or replying; we store that suspension against your account. Removing a post or reply withdraws it from the community; we retain the underlying record for moderation and posting limits until you erase your data or delete your account. Erasing your data removes your posts, your replies, your blocks and your agreement to the rules; a suspension stays until your account is deleted, so erasing data does not lift it. Deleting your account removes all of these, including any suspension. Replies belong to the topic they answer, so when your topics are removed this way, every reply on them goes too, including other members' replies and replies from the BeFree team; your replies on other people's topics are removed and their topics stay. Other people may have copied content while it was public, and removing it cannot erase their copies. Community content and private messages are not included in the app’s local data export; request a copy through Talk to us or the support email. Community content you choose to publish is the only data in this policy that is readable by the public.
Feedback calls. If you book a feedback call, Google Calendar collects your name, booking email, appointment time, and any BeFree account email you choose to add, and Google Meet provides the call. The BeFree team can see those details to arrange the conversation; they are not posted to the community. If you attend with a registered Free account that has no active subscription or trial, we add one calendar month of Pro to that account by hand, once per account. Booking alone adds nothing, and the month does not depend on what you tell us or on any rating or review. To do this we keep a private attendance and reward record in Supabase, linked to your account: a reference for the call, when you attended, which team member confirmed it, and the dates and product of the access we added. We use RevenueCat to provide that promotional access. The reward record is removed when you erase your data or delete your account. Calendar invitations and email copies are held separately by Google and their recipients; contact us to request deletion of the booking details we hold. See Google's privacy policy for its handling of Calendar and Meet data.
We keep your account data while your account is active. When you delete your account, we remove it from production systems within 30 days. Some provider logs or short-window backups may persist for security, fraud prevention, or operational reasons, but those copies are isolated from the live product. Deleting your account does not delete what has already been sent to Sentry (crash reports), PostHog (product analytics) or RevenueCat (your customer record); each keeps it under its own retention schedule.
BeFree is not directed to children, and we do not knowingly collect information from them. We set the line at 13, and where local law sets it higher — in the EU the age of digital consent runs from 13 to 16 depending on the country — that higher age applies instead. If you believe a child has provided personal information to BeFree, contact us and we will remove it.
We may update this policy as BeFree changes, and the effective date at the top shows when it last changed. When a change materially affects how we handle your data — a new kind of collection, a new processor, a new purpose — we will say so on this page and email the address on your account. We will not make a material change quietly and hope you re-read the page.
Email: support@heybefree.app