// privacy
Privacy
Effective September 17, 2026
BRU LAB is one ecosystem with a public side and private areas. bruNEST, a private family operating system for one household, lives inside it.
BRU LAB
Reading this site needs no account, and it runs no advertising or analytics trackers. If you use the contact form, what you send is stored so it can be answered, and a spam check runs on it.
People with a BRU LAB sign-in can use its private areas. BRU LAB does not connect to or read their email.
bruNEST and Gmail
bruNEST is open only to one family. A parent in that family may choose to connect their own Gmail, so bruNEST can keep track of household things like school notices, deliveries and bills. bruNEST then asks Google for permission to:
- Read their Gmail. It cannot send, delete, move or change anything in the mailbox.
- Create drafts for them to review. It cannot send them.
What bruNEST does with it
It notes the basic details of the messages it checks: who sent them, the subject and the date.
It opens a message, and anything attached to it, only when a rule that parent set up asks for it, such as mail from the school. Every read is recorded.
What it opens is deleted 30 days later. Everything else is deleted within a year.
Who can see it
The mail is visible only to the parent who connected it. What bruNEST takes from it, such as a school date or a delivery, is shared only with people that parent chooses. The message itself is not shared.
AI services
A message may be sent to an AI service only when a rule allows it, to pull out dates and to-dos. Other mail is never sent. Google data is not used to train AI models.
Sharing
BRU LAB and bruNEST do not sell data, use it for advertising, or give it to anyone. It passes only through the services that host and run them.
Their use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and deletion
Disconnect Gmail on its connection page, which revokes access at Google and deletes the stored token, or remove it at myaccount.google.com/permissions. To have stored data deleted, write to dbrollin@bru-lab.com and it will be deleted within 30 days.