What Braxby reads, and what it does with it.
Effective 25 August 2026 · Last updated 25 August 2026
Braxby asks to read your calendar, and — if you choose to connect it — your inbox. That is a lot to ask on a first screen, so this page is written to be read rather than survived. The short version: we read a narrow slice, we keep the structured facts and not your messages, we never train models on you, and deleting your account deletes everything.
On this page
- Who we are
- What we read from your calendar
- What we read from your mail
- Google Limited Use
- Everything else we collect
- Why we process it
- We do not train models on you
- How long we keep it
- Deleting your account
- Who else touches it
- We do not sell your data
- How it is protected
- Your rights
- Children
- Where the data lives
- Changes to this policy
- Contact us
1Who we are
Braxby is a personal events concierge operated by Braxby LLC, a limited liability company organised in the Commonwealth of Massachusetts, United States. In this policy "Braxby", "we" and "us" mean Braxby LLC. "You" means the person using the service.
For data-protection purposes Braxby LLC is the controller of the personal information described here. You can reach us at concierge@braxby.com.
2What we read from your calendar
Your calendar is the primary signal Braxby learns from. It is where the concerts you actually went to, the restaurants you actually booked and the trips you actually took are recorded.
The permissions we ask for
- Google —
calendar.eventsandcalendar.calendarlist.readonly. We deliberately do not request the broaderauth/calendarscope, which would grant read, write, share and delete across every calendar you can see. The narrower pair covers everything Braxby actually does. - Microsoft —
Calendars.ReadWrite, the narrowest Microsoft Graph permission that supports both reading your agenda and adding an event you asked us to add. - Apple — Sign in with Apple grants no access to your calendar or mail; Apple publishes no such permission. iCloud Calendar is a separate, manual connection you make yourself with an app-specific password, and only if you choose to.
What we actually read
- The list of calendars on your account, so you can choose which ones Braxby may look at.
- Events in a window around today — the first import reads roughly the past thirty days, and day-to-day Braxby reads the month ahead. It does not trawl your entire calendar history.
- For each event: title, start and end time, location, description and the number of attendees.
What we write
Write access is used in exactly one situation: when you ask Braxby to add something to your calendar. It never creates, edits or deletes an event on its own initiative.
You may sign in and connect no calendar at all. Braxby is designed to work in that state — it will simply know less about you.
3What we read from your mail
This is the question people care most about, so it gets the most precise answer on this page.
We never read your whole inbox
Where mail access exists — through Microsoft's Mail.Read, an iCloud mailbox you
connected yourself, or a Gmail grant if you ever give one — Braxby does not download or scan
your mailbox. It runs a narrow search and reads only what comes back:
- Messages from a known list of ticketing, travel and booking senders; or
- Messages matching event keywords — ticket, booking, reservation, confirmation, invitation, event, concert, flight, itinerary, e-ticket;
- Within a recent time window, and capped at 200 messages per scan.
Personal correspondence, work threads, newsletters, financial mail and everything else in your mailbox falls outside that search and is never retrieved.
What we keep from a matching message
The structured facts we keep are: the event title, its start and end time, its location, the type of event, a booking reference where one exists, a confidence score, and the provider's message identifier so the same message is not processed twice.
If you re-scan your mail, the previous extractions are replaced.
4Google Limited Use
Where Braxby uses Google API Services, the following applies in full:
In practice that means data obtained from Google APIs is used only to provide and improve the user-facing features described on this page, is not transferred to anyone except as required to run the service (see who else touches it), with your consent, or for legal reasons, is never sold, and is never used for advertising. Humans do not read it except where you explicitly ask us to for support, where it is necessary for security, or where the law requires it.
5Everything else we collect
| What | Where it comes from | Why |
|---|---|---|
| Account details Name, email address, sign-in provider | Google, Microsoft or Apple at sign-in | To create and secure your account. With Apple's Hide My Email, we only ever see a relay address. |
| Access tokens | Your provider, when you grant access | To read the calendar and mail you authorised. Stored encrypted; revocable at any time. |
| Your messages to Braxby | The concierge chat | To answer you, and to remember context across conversations. |
| Taste and behaviour What you open, save, dismiss, watch or add | Your use of the app | This is how Braxby learns what you like. It is inferred from what you do, not from a questionnaire. |
| Location, at city level | Your calendar events, your trips, or a city you tell us | To know which city's events matter this week. We do not track continuous device location. |
| Spotify listening Top artists and genres | Only if you connect Spotify | To sharpen music recommendations. Entirely optional, and disconnectable. |
| Billing details | Stripe, if you subscribe | To take payment. Card numbers go to Stripe and never reach our servers — we hold a customer reference and your subscription status. |
| Product usage Which screens you open, what you tap, and anonymised session replays | Automatically, as you use the app | To find where the product confuses people. Replays are masked: we see the shape of your session, not its content. |
| Technical logs IP address, request paths, errors, timestamps | Automatically, when you use the service | To keep the service up, debug failures and prevent abuse. |
| Push registrations | Your browser or device, if you enable notifications | To deliver the proactive messages that are the point of the product. |
6Why we process it
- To provide the service you asked for — detecting trips, building your taste model, finding events worth telling you about, and writing to you first.
- To keep it working and safe — debugging, rate limiting, fraud and abuse prevention.
- To take payment, if you subscribe.
- To comply with the law, where we are required to.
If you are in the UK or EEA: our legal basis is performance of our contract with you for the core service, your consent for optional connections such as Spotify, mail access and push notifications, and our legitimate interests in keeping the service secure and functioning. You can withdraw consent at any time by disconnecting the source or turning the notification off.
7We do not train models on you
The "learning" Braxby does is a private profile of your taste, held in your account and used only to choose what to show you. It is not pooled with other users, and it does not improve anyone's model but your own experience.
8How long we keep it
| Data | Kept for |
|---|---|
| Your account, taste profile, trips, extracted events, chat history | As long as your account exists. Deleting your account removes them immediately — see below. |
| Access tokens for connected accounts | Until you disconnect that source, or delete your account. Disconnecting deletes the token. |
| Extracted events from a mail scan | Replaced each time you re-scan — the previous extractions are deleted. |
| Something you asked Braxby to forget | Removed immediately from everything Braxby reads, shows or reasons over. The underlying record is cleared when your account is deleted. |
| Cached model results and event feeds | Minutes to 24 hours, then discarded automatically. |
| Technical logs | A short rolling window held by our hosting provider, then discarded. |
| Billing records | As long as US tax and accounting law requires us to keep them, independent of your account. |
| Encrypted database backups | Deleted data disappears from backups as our provider's rolling backup window passes. We do not restore a backup to recover deleted user data. |
9Deleting your account
You can delete your account yourself, from You → Settings in the app. There is no form to fill in and nobody to email. If you no longer have access to the app, see how to delete your account.
Deletion is immediate and it cascades. Every table that holds anything about you is keyed to your account with an on-delete cascade, so removing the account removes, in the same transaction: your profile, your provider tokens, your Spotify connection, your memory and taste model, events extracted from your mail, your detected trips, your conversation history, your discover feed, your armed watches, your calendar preferences and your onboarding records.
If you signed in with Apple, we call Apple's token-revocation endpoint before deleting, so the grant does not linger in your Apple Account with nothing behind it.
This is a hard delete, not a soft delete or a thirty-day grace period. We cannot undo it, and we cannot recover the account afterwards. Cancelling a subscription is a separate thing and does not delete anything — see the Terms.
10Who else touches it
Braxby is a small operation built on other people's infrastructure. These are the companies that process data on our behalf. We update this list when it changes.
| Provider | What it handles |
|---|---|
| Anthropic (Claude) | The concierge itself, and the extraction of events from calendar and mail text. Receives the text being processed and your messages to Braxby. |
| OpenAI | Text embeddings only, so Braxby can retrieve relevant memories. Receives short text, no account identifiers. |
| Supabase | Our database and authentication. Holds everything described on this page. |
| Render | Hosting for the application and the website, plus the cache and job queue. Processes requests and technical logs. |
| Stripe | Payments and subscription management, if you subscribe. Card details go to Stripe directly and are never held by us. |
| PostHog | Product analytics and session replay, so we can see where people get stuck. Replay masks all text and all form inputs — it records where you clicked and how long you paused, never the contents of your calendar, your mail or your conversation with Braxby. |
| Resend | Sends transactional and digest email to your address. |
| Ticketmaster, SeatGeek, Eventbrite, Skiddle | Event catalogues. They receive a city, a date range and search terms derived from your interests — never your name, email or message content. |
| Brave Search | Web search used to ground answers and find local listings. Receives a search query, not your identity. |
| Spotify | Only if you connect it. Returns your top artists and genres. |
| Google, Microsoft, Apple | Sign-in, and the calendar and mail you authorised. |
| Apple Push Notification service, Firebase Cloud Messaging | Delivery of push notifications, if you enable them. |
We may also disclose information if the law requires it, to enforce our Terms, or to protect the rights and safety of our users. If Braxby is ever acquired or merged, your information may transfer as part of that — you will be told before it becomes subject to a different privacy policy.
11We do not sell your data
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We run no advertising network, no tracking pixels for third-party advertisers, and no data brokerage. Braxby is paid for by the people who subscribe to it, and by affiliate commission when you buy a ticket through a link we showed you — which is disclosed in the Terms and costs you nothing extra.
12How it is protected
- Provider access tokens are encrypted at rest, separately from the rest of the row.
- All traffic runs over TLS.
- Every user-owned table carries row-level security as defence in depth, and every query is scoped to your account.
- OAuth handoffs are signed and time-bounded, so a redirect cannot be forged or replayed.
- Text arriving from your mail or calendar is treated as untrusted input and neutralised before it reaches a model prompt.
No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your personal information we will notify you and the relevant authorities as required by Massachusetts law and any other law that applies to you.
13Your rights
Wherever you live, you can access what we hold, correct it, delete it, and take it with you. Deletion is built into the app and takes effect immediately; for anything else, write to concierge@braxby.com and we will respond within 30 days. We will not treat you differently for exercising any of these.
If you are in California
Under the CCPA as amended by the CPRA you have the right to know what we collect and why, to delete it, to correct it, to obtain a portable copy, and to opt out of sale or sharing — which is moot here, because we do neither. We do not use or disclose sensitive personal information for any purpose beyond providing the service. You may use an authorised agent to make a request.
If you are in another US state with a privacy law
Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and others grant comparable rights of access, correction, deletion, portability and opt-out. We honour them for every user regardless of state, and you may appeal a refused request by replying to our response.
If you are in the UK or EEA
You additionally have the right to object to or restrict processing, and to lodge a complaint with your supervisory authority — the Information Commissioner's Office in the UK, or your national authority in the EEA. We would rather you told us first.
14Children
Braxby is not directed to children. You must be 18 or over to use it, as set out in the Terms. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us information, write to us and we will delete it.
15Where the data lives
Braxby is operated from the United States and your information is stored and processed there. If you use Braxby from outside the US, you are sending your information to the US, where privacy law differs from your own. Where we transfer personal data out of the UK or EEA we rely on the standard contractual clauses our providers offer.
16Changes to this policy
If we change this policy we will update the date at the top of the page. If a change materially affects how we handle your information — a new category of data, a new purpose, a new sub-processor with real access — we will tell you in the app or by email before it takes effect, rather than quietly editing the page.
17Contact us
Questions, requests, or a paragraph on this page you think is wrong: concierge@braxby.com.
Braxby LLC · Massachusetts, United States