Privacy Policy
Bernn ("the app", "we", "us") is a mobile app that shows you your cloud infrastructure and AI API spend in one place. This page explains what data Bernn collects, why, and how you can remove it.
What we collect
- Account info. Your email address and authentication identifiers, handled by Supabase Auth (including Sign in with Apple, where used). We don't see or store your password.
- Provider credentials, encrypted. To pull your spend data, Bernn stores what you give it to connect a provider: an AWS cross-account role ARN and a per-user ExternalId (never AWS access keys), or an Anthropic/OpenAI admin API key. These are encrypted at rest (AES-256-GCM) before they touch the database, decrypted only in memory at the moment we poll a provider on your behalf, and every decryption is written to an append-only audit log. Credentials are never sent back to the app or shown to you again after you add them.
- Spend and usage data. The cost and usage figures those providers report back — totals, per-service or per-model breakdowns, and historical trend — so the app can show you a dashboard.
- Alert and notification settings. Any budget or anomaly thresholds you set, and a push-notification device token (sent via Apple/Google's push services) so we can notify you when one fires.
- Subscription status. If you subscribe, RevenueCat tells us your entitlement status (active/expired/etc.) on our behalf. Bernn never sees your card number or Apple/Google account details — Apple and Google handle payment directly.
- A profile picture, if you add one. Only if you choose to pick one from your photo library; Bernn does not access your camera or microphone.
- Product usage events. Actions like completing onboarding, connecting a provider, viewing the paywall, or opting into push notifications, sent to PostHog tied to your account id (never your email or name) so we can tell which parts of the app work and which don't. There's no session recording and no capture of arbitrary taps or screens — only the specific, named events listed here.
What we don't do
- No advertising or ad-tracking SDKs of any kind.
- No cross-app or cross-site behavioral tracking, and no data shared with ad networks or data brokers. The product analytics above stays inside Bernn, used only to improve Bernn.
- Bernn's provider connections are read-only — it cannot launch, modify, or spend anything on your AWS, Anthropic, or OpenAI account.
Who we share data with
Only the services that make the app work, each acting on our instructions and none permitted to use your data for their own purposes:
- Supabase — database hosting and authentication.
- AWS, Anthropic, and OpenAI — only to fetch the spend data you've asked Bernn to pull, using the credentials you provided.
- RevenueCat — subscription/entitlement management for Apple/Google in-app purchases.
- Expo / Apple / Google push notification services — to deliver the alerts you've opted into.
- PostHog — product analytics, as described above.
We may also disclose information if required by law, or to protect the rights, safety, or property of Bernn or its users.
How long we keep it
We keep your data for as long as your account is active. If you delete your account, we delete it — see below.
Your controls
- Export. From Settings, you can export everything Bernn holds about you as a file, at any time.
- Delete. From Settings, you can delete your account. This immediately and permanently removes your spend history, connected providers and their encrypted credentials, alert rules, and push tokens — no support ticket required. This cannot be undone.
- Notifications. You can turn off any class of push notification from Settings; the switch is enforced on our servers, not just hidden on your phone.
Children
Bernn is not directed at children under 13 (or the relevant age of consent in your country), and we do not knowingly collect data from children.
Changes to this policy
If this policy changes materially, we'll update the date above and, where required, notify you in the app.
Contact
Questions, data requests, or anything else: business@bernn.tech.