Privacy Policy
Effective: September 6, 2026
What Brightery Notes does
Brightery Notes is a local-first service for notes, documents, bills, expenses and user-initiated browser autofill. Vault item contents and attachment bytes are encrypted on the client before they are synced to our servers.
Data we process
We process account information such as name, email address, password hash, plan and account status. The sync service stores encrypted vault ciphertext, encrypted attachments and technical metadata needed to sync them, including item identifiers, revisions, item type, deletion status and optional bill due/reminder timestamps. We may process device/platform identifiers and encrypted push-notification tokens if push delivery is enabled.
Security systems may process network and request information. Brightery Notes stores keyed hashes of IP addresses in rate-limit and audit records instead of intentionally storing raw IP addresses in application audit tables.
Highly sensitive vault data
Passport, visa, identity, card, note, bill and expense values are designed to remain inside encrypted vault payloads during server sync. The service does not intentionally store card CVV/CVC/CID. Payment-card records are an organization/autofill feature, not a payment-processing service.
OCR and browser autofill
Mobile OCR is designed to run on the device. Extracted data is shown as a draft and must be confirmed before saving. The Chrome and Firefox companion extension connects to notes.brightery.com for authentication and encrypted vault sync. It decrypts selected data locally and fills the active page only after the user requests the action.
How data is used
Data is used to operate accounts, synchronize encrypted vault records, enforce plan limits, protect the service from abuse, provide user-requested reminders, provide support, and maintain security and reliability. We do not use private vault data for personalized advertising and do not sell user data.
Storage and security
Traffic must use HTTPS in production. Passwords are stored using one-way password hashing. Access and refresh tokens are stored server-side only as hashes. Encrypted attachment files are stored outside the public web root. Push tokens, when stored by the server, are encrypted at rest.
Recovery codes
When an account is created, the client generates a high-entropy recovery code and shows it to the user. The service stores a SHA-256 verifier of that code plus a vault key that is separately wrapped by a key derived from the recovery code. The plaintext recovery code is not stored by the service. If the user starts account recovery, the entered code is sent over HTTPS for verification and to let the client unwrap the vault key; successful recovery replaces the old recovery code and invalidates existing sessions. Users should keep the recovery code outside Brightery Notes.
Retention and deletion
Account and encrypted vault data are retained while the account is active. Users can delete their account inside the mobile app or at the account deletion page. Account deletion removes the account database records and associated encrypted attachment files. Limited security/audit records may remain in pseudonymized form where needed for security, fraud prevention, legal compliance or backup integrity, subject to applicable law and backup rotation.
Service providers
Hosting, content-delivery/security, app-store distribution and optional push-notification infrastructure may process limited data needed to provide those services. Production deployment should keep the provider list in this policy aligned with the services actually configured.
Your choices
You can choose whether to sync, whether to save sensitive structured records, whether to enable reminders, and whether to use the browser extension. You can edit or delete saved records and can request complete account deletion.
Contact
For privacy or account requests, email [email protected].