Brickchat

Privacy policy

Effective July 21, 2026 · Zerohour Code, LLC

Brickchat is an AI LEGO expert that can use the collection connected to your account to answer questions. This policy explains the data we need to provide that service. We do not sell personal data, serve display ads, or use third-party advertising or behavioral-tracking SDKs.

Account data

We receive your email address and an account identifier when you sign in with an email code, Apple, or Google. If you use Apple or Google, we receive the identifier and email address that provider chooses to share. Authentication and account data are hosted by Supabase in the United States. We do not store a password.

Collection data

Brickchat can use collection data stored in the shared Brickmaster account system, including sets, minifigures, statuses, quantities, locations, build records, and collection preferences. Collection data belongs to a household. If you join a shared household, its members can see its collection data according to their role. Brickchat reads the active collection only when needed to answer your request, and any proposed change still requires your confirmation.

AI messages and collection context

When you send a message, Brickchat sends that message, plus a bounded text-only portion of the recent conversation, to our API. The current conversation is held in the app's memory; Brickchat does not save your message or the assistant's reply as server-side chat history. Reloading or closing the app clears that in-memory conversation.

To answer a question, Brickchat may retrieve only the relevant, bounded collection or public-catalog facts its tools need. These can include item and set names, catalog identifiers, brand, year, piece count, ownership and build status, item location, quantities, collection statistics, build dates and durations, theme progress, and minifigure progress. The AI tools do not read your email, household members, private notes, price paid, seller or acquisition source, or raw build-session records.

We use Vercel AI Gateway to route the message and relevant tool results to an Anthropic Claude model to generate a reply. Those providers process the content on our behalf. Brickchat does not use your messages or collection context to train models. Under the commercial API settings and terms we use, the providers do not use inputs or outputs for model training by default, and we do not opt in to training. AI can make mistakes; review important answers and every proposed collection change. A proposal changes your collection only after you explicitly confirm it.

We retain operational and fuel-metering records such as your account identifier, request identifier, model, timing, token or credit usage, outcome, and any confirmed app action. Those records do not contain the text of your messages or replies.

Voice input

Voice input uses speech recognition supplied by your device or browser. Recognition may run on-device or through Apple, Google, or your browser provider under its privacy terms. Brickchat does not receive or store the audio. The resulting transcript stays editable in the composer and is sent to Brickchat only when you choose Send.

Purchases and subscriptions

Apple processes iPhone and iPad purchases, Google processes Android purchases, and RevenueCat coordinates products, receipts, entitlements, subscription status, and refunds across those stores. Brickchat does not currently sell subscriptions or fuel packs on the web. We do not receive your full card or store-payment credentials.

RevenueCat processes an account identifier and purchase facts such as platform and store, product and plan, transaction identifiers, trial and renewal state, expiration, environment, entitlement status, and refund events. We store a corresponding entitlement and billing-event record, plus a fuel ledger showing fuel delivered, held, spent, restored, or clawed back. We retain the billing and credit records needed to deliver the purchase, prevent duplicate grants, resolve disputes and refunds, and meet accounting, fraud-prevention, and legal obligations.

Apple refund requests and your consent

If you ask Apple to refund an Apple in-app purchase, Apple may request information about whether the purchase was delivered and how much of it was used. Brickchat may use RevenueCat to respond to such a request. If it does, the response may include delivery status, trial or sample availability, consumption information RevenueCat can determine (for example, the portion of a subscription period that has elapsed), related purchase and refund history, and our refund-handling preference. Apple uses this information to decide the refund request; we do not share it for advertising.

By confirming an Apple in-app purchase after seeing the notice on the purchase screen, you consent to this limited sharing with Apple if you later request a refund and Brickchat responds with this information. To withdraw that consent for future refund requests, use Settings → Subscription → Don't share refund data with Apple on your iPhone or iPad before submitting the request. That control sends RevenueCat the per-account instruction not to handle your Apple refund request. If you cannot use the control, contact us before submitting the request to Apple and we will apply the same preference for your account. Withdrawal does not retract information already sent. Apple handles access or deletion requests for consumption information it holds at privacy.apple.com. Apple makes the final refund decision under its own policies.

Service providers and disclosures

Supabase provides authentication and database hosting; Vercel serves the web app and AI gateway; Render runs our API; Cloudflare provides edge delivery; Anthropic generates AI replies; RevenueCat manages purchase status; and Apple and Google process payments on their respective platforms. Each receives only the data needed for its role. We may also disclose data when required by law, to protect users or the service, or as part of a business transfer subject to this policy.

Storage, deletion, and security

The app keeps session tokens and preferences on your device. We use reasonable technical and organizational safeguards, but no online service can promise absolute security. You can delete your account in Settings. That removes your sign-in record and personal collection when no other household member needs it; shared-household data can remain for its other members. We may retain limited billing, refund, abuse-prevention, and legal records where required. Copies already processed by Apple, Google, RevenueCat, Vercel, or Anthropic are governed by their applicable retention obligations.

Your choices

You can type instead of using voice, avoid sending a message, cancel a subscription through the platform where you bought it, delete your account in Settings, and contact us to request access, correction, or deletion of your personal data. You can also contact us to withdraw Apple refund-data consent for future requests as described above, or use the in-app Subscription setting on iPhone or iPad.

Children

Brickchat is not directed to children under 13.

Changes

We will post policy changes here and update the effective date. If a change requires new consent, we will ask before applying it.

Questions, deletion requests, or an Apple refund-data preference? Contact Brickchat support.