Privacy Policy
The short version: there's almost nothing to have a policy about. No account, no analytics, no tracking, no ads. We don't run AI models and we don't keep your code or conversations — those live on your machines. Here's the whole picture anyway.
Last updated 13 July 2026. This policy covers the BrainBoxx iOS app, the bb daemon you install on your machines, and the relay that connects them, all provided by Apexx Apps (United Kingdom).
What we don't do
- No account. No sign-up, no email, no password, no profile. There's no database of users because there are no users to store.
- No analytics or tracking. No analytics SDKs, no crash-reporting services, no advertising identifiers, no third-party trackers, no cookies on the app.
- No access to your work. BrainBoxx runs no models and keeps no content. Your code, your files, your API keys, and your AI conversations stay on your own machines. The transcript of a conversation is the AI tool's own file, on your disk — never ours.
- No sale of data. We do not sell, rent, or share personal data. There is nothing to sell.
What we do process — and why
To connect your phone to your machines, a small amount of operational data passes through our relay. It is the minimum needed to make the service work.
- Your fleet code. A long random code your app generates on your device to pair it with your machines. It contains no personal information and isn't tied to your identity — it's just a shared secret. It's the only credential BrainBoxx has.
- Notification tokens. If you enable push (a Pro feature), Apple issues your device a push token, and each watched Brain's Live Activity has its own token. We store these on the relay, keyed to your fleet code, for the sole purpose of delivering the notifications you asked for. They're removed when you disable notifications or unpair.
- Machine names. The labels you give your machines are stored on the relay so they appear on your other devices. That's a name you chose — nothing more.
- Connection data, in transit only. To broker a connection, the relay routes network traffic between your devices and briefly processes IP addresses to do so and to rate-limit pairing attempts (standard server operation). Your session content — the terminal stream between your phone and your machine — passes through the relay encrypted with TLS and is not stored, logged, or inspected. The relay is a blind byte-pump; it holds no session content between messages.
Purchases
BrainBoxx Pro is sold through Apple's In-App Purchase. Apple processes the payment; we never see your card details or billing information. Your Pro status is tied to your Apple ID, and the app only ever learns whether that Apple ID is entitled to Pro. Apple's handling of your purchase is governed by Apple's Privacy Policy.
Retention
The relay keeps your notification tokens and machine names only while your fleet is active. Unpair a machine, or turn off notifications, and the associated data is removed. There are no long-term logs of your session content, because that content is never stored in the first place.
Security
All connections between your app, the relay, and your machines run over TLS. The secrecy of your fleet code is the security lever — the relay rate-limits pairing attempts so it can't be guessed. Keep your fleet code private; anyone who has it can reach the machines you've paired to it.
Your rights
Because we hold so little, most requests resolve themselves: unpairing a machine removes its tokens and name from the relay, and deleting the app ends everything else. If you're in the UK or EU, you have rights under UK GDPR / GDPR to access or erase any personal data we hold — in practice, the operational data described above. To exercise them, or to ask anything about this policy, email support@apexx.app and we'll help.
Children
BrainBoxx is a developer tool and is not directed at children. We do not knowingly collect data from anyone under 13.
Changes
If we change this policy we'll update the date at the top and, for anything material, note it in the app's release notes. Continued use after a change means you accept the updated policy.