Privacy

Privacy policy

This policy explains the current data practices of the Save2Brain hosted service and Chrome extension.

At a glance

Effective 13 September 2026

Your library stays private

We use your account details and the material you choose to save to create, store, and protect your learnings.

You have choices

Edit your learnings, export your data, revoke agent access, disconnect the extension, or request account deletion from Settings.

Clear data practices

We do not sell personal data. The sections below explain AI processing, service providers, retention, and your rights.

A short guide to the policy. Read the full sections below for the terms, conditions, and details that apply.

Jump to a section
Aggregate usage analytics is on for new accounts where the installation’s policy permits it. You can switch it off in Settings. Existing accounts keep their saved choices; account-linked analytics remains a separate optional choice. Limited service-health diagnostics are separate. We do not use advertising or marketing profiles. Hosted sign-in supports Google and GitHub OAuth, with only providers configured for a deployment shown. When enabled, email and password access requires email verification, and Resend delivers verification and password-reset emails. Managed billing is disabled by default; when explicitly enabled, Paddle processes subscription and payment data as merchant of record. We do not sell personal data.

1. Who is responsible

Save2Brain is operated by Sababa Creations (referred to as “Save2Brain”, “we”, “us”, or “our”). The legal operator, business address and grievance contact are listed in section 12.

This policy applies to the hosted Save2Brain website, service, and Chrome extension. A separately operated self-hosted copy has its own operator and data practices.

2. Data we collect

  • Account and session data. When you sign in with a configured Google or GitHub OAuth option, we receive and store the name, email address, profile image, and provider account identifier returned by that provider, together with internal account identifiers. The email-restricted staging profile accepts only allowlisted, verified email addresses, through Google or email and password when enabled. For email and password access, we store your name, email, a salted password hash, and verification and recovery records. We do not store plaintext passwords. Sessions may also record timestamps, IP address, and browser or device user-agent information for authentication and security.
  • Legal acceptance metadata. Before a sign-in session is issued, we record your internal user ID, the Terms version, the Privacy version, and the database-authored acceptance time. These restricted account/legal audit records contain no captured or generated content and preserve acceptance history when the published versions change.
  • Material you explicitly capture. This may be pasted text; text selected in a web page together with its page URL; an exact X post URL; an optional note; or a file you choose to upload. For uploads, we may process the filename, type, size, hash, and relevant media properties such as image dimensions, duration, or page count.
  • Source and learning data. We retain normalized source material and attribution, media evidence, transcripts or visual evidence when applicable, generated learning cards, citations, Topics, edits, notes, organization, removal state, and validation or processing records. Raw upload bytes are not retained as durable library content; their bounded lifecycle is described under Retention and deletion below.
  • Extension data. The extension stores the configured Save2Brain server origin, an installation identifier, authentication credentials, settings, previews, and a bounded retry outbox on your device. An outbox item may contain the selected text or exact X URL, page metadata, and note that you chose to save.
  • Agent Access data. If you connect an agent, we store its name and client identity, the permissions you approve, expiry and revocation status, usage counters, and security audit metadata. These audit records do not contain learning text. We store hashes of local access tokens and, for online connections, OAuth access and refresh tokens. Your chosen client holds the credentials it uses to connect.
  • Plan and billing data. We store your plan, allowance, and billing-period dates. If managed billing is enabled, we also store subscription/payment status, pending change or cancellation, billing holds, and opaque Paddle customer, transaction, subscription, price, and event identifiers. We do not store card details, raw webhook bodies, API keys, or webhook secrets.
  • Operational and support data. We process security events, job and request status, error categories, timing, and other restricted operational metadata. If you email us, we receive the address, message, and attachments you send. If you use Feedback & help, we receive your message, account identity and email, submission time, a reference, and a simple page label. We send this correspondence through our email delivery provider to the support inbox for follow-up. We do not automatically include page URLs, saved content, or browser logs.

3. Why we use data

We use the data described above to:

  • authenticate users and secure accounts;
  • record the Terms and Privacy versions accepted at sign-in;
  • receive explicit captures, acquire their selected source material, generate and validate learnings, and keep each library private to its owner;
  • let users view, edit, organize, remove, restore, export, and delete their data;
  • let agents you explicitly approve read published learnings within the permissions and limits you choose;
  • operate, diagnose, protect, and improve the reliability of the service;
  • when billing is enabled, create a requested checkout or plan change, reconcile verified payment/subscription events, apply entitlements, prevent duplicate grants, handle cancellation, and review refund or chargeback holds; and
  • respond to support, privacy, and legal requests.

Captured or generated content is treated as data, not as an instruction that can change ownership, permissions, publication, or account access.

4. AI processing and source acquisition

Save2Brain uses OpenAI as the primary AI processing provider for generation and supported media analysis. On eligible temporary failures, Google Gemini may receive the same bounded evidence as a fallback. Supported documents may be uploaded through Gemini’s file-processing interface and are scheduled for deletion on terminal paths, with the provider’s 48-hour expiry as a backstop.

For an exact X post URL that you choose to save, our server may send that URL or post identifier to TwitterAPI.io to retrieve the selected post, its bounded conversation context, attribution, and supported media. The extension does not send cookies, browsing history, or an ambient feed to Save2Brain.

Topic classification receives the learning text and a tenant-scoped Topic catalogue, not the raw source, source URL, author, or social handle. AI output can be inaccurate, so it is deterministically validated before the application privately publishes it to the user’s library and remains editable by the user.

5. Chrome extension and Limited Use

The extension acts only after you invoke Save2Brain and confirm a save. It uses access to the active tab to read the selected text, page URL, and page title for a selected-text preview, or the exact X post URL and minimal post metadata for an X capture. The page title stays in the temporary local draft and is not included in the submitted request. The extension uses browser storage for the local state described above and sends a capture only to the Save2Brain server origin you configured.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Extension data is used only to provide or secure the user-facing capture and retry features. It is not used for personalized advertising, sold to data brokers, or used for lending or credit decisions. See the in-product capture preview before saving and the Chrome Web Store listing disclosure, if and when the extension is published, for the permission-specific notice.

6. Storage, providers, and international transfers

Account, capture, learning, and lifecycle records are stored in PostgreSQL. Private source files, media, and export artifacts are stored in private Cloudflare R2 object storage. The hosted service currently runs on infrastructure in Nuremberg, Germany, behind Cloudflare. Depending on the feature used, data may be processed by Cloudflare, the hosting provider, Google, GitHub when configured for OAuth, Resend when email and password access is enabled, OpenAI, TwitterAPI.io, Paddle when managed billing is enabled, PostHog when analytics or diagnostics are enabled, and the email or infrastructure services used to respond to and operate the service. These providers may process data outside India.

Resend receives the recipient address and verification or reset email, including its action link, for transactional delivery. Passwords and library content are not included. Email tracking is disabled for these messages.

Agents you choose to connect. Agent Access lets you approve read-only access through a local connector or, where enabled, an online connection. When your chosen agent requests information, Save2Brain sends the published learning text, source attribution, and citations allowed by your grant. An agent cannot use this access to edit or delete your library.

Your chosen agent or its provider handles the information it receives under its own privacy and retention policies. Revoking access in Agent Access prevents new authorized requests, but cannot retract information the agent has already copied. Contact that agent or provider to manage its copies.

We disclose data to a provider only for the bounded service it supplies, or where required to protect users, enforce the law, or comply with a valid legal obligation. Better Auth telemetry is disabled. When configured, PostHog receives strictly limited service outcomes, safe error groups, durations, release identifiers and sampled page-performance values. These service diagnostics use rotating service identifiers, without an account identifier. Aggregate usage reports combine daily action counts inside Save2Brain before export. They cover broad capture types and entry points, processing outcomes, time-to-availability bands, learning views and edits, and successful agent reads. Small counts are withheld and totals rounded. They contain no account, capture, learning, job, grant, session or device identifiers, including linkable hashes. They do not report individual journeys, unique people, retention or conversion funnels. Aggregation reduces detail but is not a guarantee of anonymity. Separate legacy account-linked analytics requires your choice in Settings and uses an opaque account identifier for captures, viewed learnings and core library features. Linked browser errors may then support affected-account counts. The hosted PostHog project processes this data in the United States. A self-hosted operator may configure a different region, shown in Settings. We do not send names, emails, source URLs, search terms, filenames, learning content, prompts, DOM text or raw error messages to PostHog. We do not enable session replay, click autocapture, console capture or advertising tracking.

7. Retention and deletion

  • Derived account content is retained while the account is active and as needed to provide the service. Removing a learning from the library is reversible and is not the same as deleting the account or erasing its underlying data.
  • Accepted upload originals are stored privately while processing or a bounded retry is active. Once a result is safely persisted, the original is marked for asynchronous deletion. If processing does not finish, an attached original becomes eligible for cleanup 24 hours after attachment. Deletion is retried and verified. Normalized source material, derived evidence, citations, learning content, and necessary processing and deletion metadata remain as account content.
  • Versioned legal acceptance records are retained as restricted account/legal audit metadata while the account exists. They are deduplicated for repeat acceptance of the same Terms/Privacy pair and are deleted when the account is deleted.
  • The Added activity view is limited to the latest 30 days; this display window does not itself delete the learning.
  • A requested export expires after 24 hours by default. Rejected upload quarantine objects expire after 24 hours by default.
  • Extension access credentials expire after about 10 minutes, renewal credentials after about 30 days, and queued retry items after no more than 7 days. Disconnecting the extension clears its credentials and queued items from the browser.
  • Verified account deletion first revokes access and then removes tenant records, private objects, provider artifacts where supported, and related grants through an asynchronous process. The independent encrypted, non-content deletion journal is kept for 90 days so it outlives every restorable backup and prevents deleted data from being restored.
  • Operational application and host logs, and encrypted restorable backups, are retained for no more than 30 days.
  • Allowlisted PostHog events are retained for up to one year, separately from the 30-day operational logs. Aggregate counts are combined within Save2Brain before export. Switching aggregate analytics off blocks future and still-pending attributable contributions. Already combined statistics have no individual mapping and cannot be separated or erased for one person. Temporary first-party deduplication receipts contain no event names or content, expire within two UTC days, and are removed by worker maintenance (or when maintenance resumes after an outage). They are excluded from backups. Turning account-linked analytics off stops new account-linked collection and requests deletion of earlier linked events. Account deletion also requests this erasure and waits for verification before completing. Provider deletion is asynchronous; Settings shows when it remains pending. An opaque identifier is replaced before a later opt-in. Aggregate service diagnostics cannot be linked back to a particular account and expire under the one-year retention limit.
  • Support correspondence and security or abuse records are kept for 12 months after the case or event is closed. Specified records may be retained longer only where law or an active investigation requires it.
  • Billing and transaction records may need to be retained for fraud prevention, dispute handling, accounting, tax, or another legal obligation after cancellation or account deletion. The exact enabled-environment schedule must be approved before live billing.

8. Security and support access

Save2Brain uses HTTPS, private object storage, account-scoped database controls, short-lived extension access credentials, redacted logs, and bounded provider routes. No method of storage or transmission is completely secure.

We do not routinely read private source or learning content for support. Human access must be limited to what is necessary to handle a user-authorized support request, investigate abuse or a security incident, comply with law, or maintain the service, with appropriate authorization and audit controls.

9. Your choices and requests

Depending on applicable law, you may ask for access to, correction of, export of, or erasure of your personal data, or raise a grievance. Product controls allow you to edit learnings, manage Topics, export account data, revoke agent access, disconnect the extension, and request verified account deletion. You may also stop future processing by no longer submitting captures, subject to data already required for security or legal purposes.

Settings lets you switch aggregate usage analytics off or back on for future activity, where the installation permits collection. New accounts default to on only under that policy; existing accounts are not silently enrolled. The separate account-linked control retains its own opt-in and deletion process. Neither choice controls service-health diagnostics. There is no analytics cookie, persistent browser analytics identity, or historical backfill.

Email [email protected] from your account address for a privacy or grievance request. We may need to verify identity before acting on your data.

We aim to acknowledge your request within 48 hours of receiving it, even if we need more information. We aim to resolve grievances within one month of receipt, without limiting any shorter period required by law. Identity checks or requests for more information do not restart these time periods.

For updates, reply to the same email conversation and include any case reference we have provided.

10. Children

Save2Brain is a public adult service and is not directed to anyone under 18. Please do not submit a capture containing a child’s personal data unless you have a lawful reason and authority to do so.

11. Changes to this policy

We will update this policy and its effective date before enabling a material new data practice, including product analytics, advertising, enabling or materially changing billing, an additional login provider, or a materially different acquisition or AI route. If a change materially affects existing users, we will give prominent notice and obtain consent where required before the change applies.

12. Contact

Sababa Creations

Legal operator and grievance officer
Rijo Jose
Business address
Chakkalakal HouseAlathur PO, AlathurThrissur, Kerala 680741India
Support, privacy and grievances
[email protected]

The contractual terms for the service are available in the Terms of service.