Brea

Privacy

Privacy Policy

Last updated August 6, 2026

Brea is operated by Brea AI LLC ("Brea", "we", "us"). Brea provides hosted OpenClaw instances. This policy explains what we collect, why we collect it, and how we protect it.

Need help?

Questions about this page or your account can be sent to our support team at support@brea.ai.

Information We Collect

We collect account information such as your email address, name, and authentication details, information about your Brea plan and OpenClaw instances, and technical information needed to run and secure the service.

When you use the dashboard, we may process OpenClaw instance status, model settings, usage totals, estimated costs, and channel connection details such as Telegram bot metadata.

We also collect information about how you use our website and dashboard: the pages you view, the site or ad that referred you, your IP address, your browser and device type, and identifiers stored in cookies and similar browser storage. When you arrive from an advertisement, the advertising platform adds its own click identifier to the link.

If you connect third-party services to your agent, such as Google, Notion, Dropbox, or Slack, we receive the credentials and data those services provide based on the permissions you grant. Google user data is described in more detail in the Google User Data section below.

If you choose to text yourself a setup link, we collect the phone number you provide only to send that requested setup message.

How We Use Information

We use information to create and secure your account, provision and manage OpenClaw instances, connect supported channels, show usage and billing information, provide support, prevent abuse, and improve reliability.

We also use information about how you use our website and dashboard to understand which features are used, to measure whether our advertising works, and to reach people who may be interested in Brea. See Advertising and Analytics below.

Google User Data

If you connect Google services such as Gmail, Google Calendar, or Google Drive to your agent, Brea accesses your Google user data through Google's APIs using OAuth. We only request the permission scopes needed for the features you connect, and we only access your Google data when you or the automations you configure ask the agent to do something with it, such as reading or drafting email, checking your calendar, or saving a file to Drive.

How we use Google user data: we use it solely to provide the user-facing features you request, such as briefings, email triage, scheduling help, and the automations you set up in your automation library. We do not use Google user data for advertising, and we do not sell it.

How we store Google user data: OAuth tokens are stored encrypted by our managed OAuth infrastructure provider and are used only to act on your behalf. Content retrieved from Google services is processed to fulfill your requests and automations; we retain it only as long as needed to provide those features and to operate your agent, and we remove it when it is no longer needed.

How we share Google user data: we do not transfer Google user data to third parties except as necessary to provide the features you request, such as processing by the model providers configured for your instance so the agent can respond, or as required for security purposes or to comply with applicable law. Our service providers may process this data only on our instructions. Humans do not read your Google user data unless you give us explicit permission for support, it is required for security or legal reasons, or the data has been aggregated and anonymized.

Brea’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models. Model providers that process your requests are not permitted to use your Google user data to train their models.

You can disconnect a Google integration at any time from your dashboard, which deletes the stored connection credentials so Brea can no longer access your Google account. You can also revoke Brea's authorization directly from your Google Account security settings at myaccount.google.com/permissions. You can request deletion of any stored Google user data by emailing support@brea.ai.

SMS and Mobile Data

SMS messages are optional and transactional. We use your mobile number only to send a link when you specifically request one. We do not send recurring or promotional text messages.

Message frequency is one message per request. Message and data rates may apply, depending on your mobile carrier and plan.

We do not sell, rent, or share mobile numbers, SMS opt-in data, or text messaging consent with third parties or affiliates for marketing or promotional purposes. Our SMS delivery provider processes this information only as necessary to deliver the message you requested and may not use it for its own marketing.

Advertising and Analytics

We advertise Brea on third-party platforms and measure whether that advertising works. To do this we share information about your visit — and, when you create an account or start a subscription, information about that event — with the providers below. Some of this sharing happens in your browser, and some happens from our servers after the fact. We receive no money for it, but United States state privacy laws may still treat it as a sale or sharing of personal information.

Meta (Facebook and Instagram): we run the Meta Pixel on brea.ai and also send account and subscription events from our servers through Meta's Conversions API. Meta receives the pages you view, the referring URL, your IP address, your browser user agent, and the identifiers stored in the _fbp and _fbc cookies. For account creation and subscription events it also receives your email address, first and last name, and the city, state, and postal code from your billing details. Email, name, and address values are hashed before they are transmitted to Meta.

TikTok: we run the TikTok Pixel on brea.ai and send account and subscription events from our servers through TikTok's Events API. TikTok receives the same categories of information, the identifiers stored in the _ttp and ttclid cookies, and a hashed identifier we generate for your browser and, once you have an account, for your account. Email and other direct identifiers are hashed before they are transmitted to TikTok.

OpenAI Ads: we run the OpenAI Ads Measurement Pixel on brea.ai and send subscription events from our servers through OpenAI's Conversions API. OpenAI receives the page origin, your IP address, browser user agent, billing city, country, and postal code, hashed email and account identifiers, and the advertising identifiers stored in the __oppref and __obref cookies.

Google Analytics: measures how our website and dashboard are used. Google receives the pages you view, the referring URL, your IP address, device and browser information, and the identifiers stored in Google's _ga cookies.

PostHog: analytics for the website and dashboard, including landing-page experiments and which product features are used. PostHog receives browser and account identifiers and, when you have an account, your email address and name.

RudderStack: the customer data platform that collects these events from our website and our servers and routes them to the providers above. We also keep a copy of this event data in cloud storage we control.

Some of these tools are served from subdomains of brea.ai — hugo.brea.ai, fred.brea.ai, and greg.brea.ai for RudderStack, and f.brea.ai for PostHog. Serving them from our own domain keeps the requests first-party, but the information still goes to those providers. Cookies set through these subdomains should be treated as advertising and analytics cookies, not as cookies we use to run the site.

This section covers information about how you use our website and dashboard. It does not cover the content of your connected accounts. We do not share Google user data, or the email, files, calendars, or messages your agent handles, with any advertising or analytics provider.

Service Providers

We rely on service providers to operate Brea. They may process information only as needed to provide services to us, and only on our instructions. The categories are: cloud hosting and infrastructure; authentication and database; payments and billing; AI model providers; connected-account and integration infrastructure; automated web browsing performed by your agent; messaging delivery for SMS, iMessage, WhatsApp, and Telegram; monitoring and observability; and the advertising and analytics providers named above.

We name our model providers because they may process the content your agent handles: OpenAI, Anthropic, and models accessed through OpenRouter.

For a current list of the specific providers in each category, email support@brea.ai.

We do not sell your personal information for money. We do share personal information with advertising and analytics providers as described in Advertising and Analytics above, which some United States state privacy laws treat as a sale or sharing.

Model Usage and Customer Content

Brea routes OpenClaw model usage through managed infrastructure so we can attribute usage and costs to the correct instance. We avoid storing raw provider keys in the web app and limit access to operational data to what is needed to provide the service.

Content you send through your OpenClaw instance may be processed by configured model providers and connected channels so the agent can respond.

Cookies and Similar Technologies

We and our advertising and analytics providers use cookies and similar browser storage. Some are required to run Brea: they keep you signed in and protect your session. Others measure how the site and dashboard are used, or measure and target advertising.

Some of these cookies are set by our servers rather than by JavaScript in your browser. This makes them last longer in browsers that limit how long script-written cookies survive.

You can clear or block cookies through your browser settings, and you can use browser or extension controls to block advertising and analytics scripts. Blocking the cookies required to run Brea will prevent you from staying signed in.

CookieSet byPurposeExpires
sb-*Brea (Supabase)Keeps you signed in and protects your session. Required.When your session ends
clawpod_refBreaRemembers a referral code from a link so the referral is credited.30 days
brea_signup_selectionBreaRemembers the plan you chose before creating an account.30 days
clawpod_last_agent_idBreaReopens the agent you last viewed.1 year
brea_lpBreaKeeps you on the same landing-page experiment version during repeat visits.30 days
rl_anonymous_id, rl_user_id, rl_session, rl_trait, and other rl_ cookiesRudderStack, via greg.brea.aiIdentifies your browser across brea.ai and app.brea.ai and links your activity into one profile for analytics and advertising.1 year
ttclidBreaStores the TikTok click identifier from an ad link so a later signup can be attributed to that ad.90 days
_fbcBreaStores the Meta click identifier from an ad link so a later signup can be attributed to that ad.90 days
_fbpMetaIdentifies your browser for Meta advertising measurement and targeting.Set by Meta
_ttpTikTokIdentifies your browser for TikTok advertising measurement and targeting.Set by TikTok
__opprefOpenAI AdsStores the privacy-preserving reference from an OpenAI ad so a later subscription can be attributed to that ad.30 days
__obrefOpenAI AdsIdentifies your browser for OpenAI advertising measurement.1 year
_ga, _ga_*GoogleIdentifies your browser for Google Analytics usage measurement.2 years
ph_*PostHog, via f.brea.aiIdentifies your browser for website and product analytics, including landing-page experiments.Set by PostHog

Retention

We keep information for as long as needed to provide Brea, comply with legal obligations, resolve disputes, secure the service, and maintain business records. We remove or anonymize information when it is no longer needed.

The copy of analytics and advertising event data we keep in our own cloud storage is deleted after 90 days. RudderStack and the advertising and analytics providers listed above retain the data they receive according to their own retention policies.

We store the advertising identifiers described above with your account so that a later signup or subscription can be attributed to the ad you arrived from. They are deleted when you delete your account.

Security

We use technical and organizational safeguards designed to protect customer data. No system is perfectly secure, but we work to limit access, avoid exposing secrets, and protect sensitive operational data.

Your Choices and Rights

You can choose not to provide optional phone information, and you can connect or disconnect third-party integrations, including Google services, at any time from your dashboard.

To opt out of the advertising and analytics sharing described above, email support@brea.ai and we will stop sharing your information with those providers. You can also limit this directly with the platforms:

Meta: Ad preferences. TikTok: Privacy and ad settings. Google Analytics: Opt-out browser add-on. Industry-wide: optout.aboutads.info and optout.networkadvertising.org.

You can delete your account at any time from your dashboard account settings, which removes your agents, cancels your subscription, and deletes your account data.

You may also contact us to request access to, correction of, or deletion of your personal information at support@brea.ai, subject to legal and operational limits. We will not discriminate against you for exercising these rights.

Policy Changes

We may update this policy as Brea changes. When we make material changes, we will update the date above.

Contact

If you have questions about this policy or how we handle personal information, email us at support@brea.ai.