Brainzie Snugstar
Features How it works Contact Open the app

Privacy Policy

Last updated: 28 September 2026

Brainzie Snugstar is built so that there is almost nothing about you for us to hold. Your data, your analyses and your graphs live in your own Google Drive or OneDrive — never on a server we own. This policy explains the little we do process, why, and how you can check every word of it yourself.

The short version. Your projects — the values you type or paste, the tests you run, the graphs you draw — are saved straight from your browser to your own Google Drive or OneDrive. We can't see them, sell them, share them or lose them, because they never reach us. What we do process is tiny: usage counts filed under a pseudonym — a one-way, salted scramble of your verified email when you're signed in, a random identifier when you're not — the messages you send us, and — only once paid plans exist and only if you subscribe — your email and subscription status.

1. Who we are

Brainzie Snugstar is operated by Brainzie Ltd ("we", "us"), a company registered in England & Wales (company number 16262756). We are the data controller for the limited personal data described below. You can reach us at privacy@brainzie.co.uk.

2. Your research data never reaches us

Snugstar runs entirely in your browser, on your device. The statistics are calculated there, the graphs are drawn there, and when you save, your project is written directly to a folder called Brainzie Snugstar in the Google Drive or OneDrive you connected (in OneDrive, inside Apps › Brainzie Snugstar, the folder Microsoft gives each app of its own). That storage is yours, and is governed by your agreement with Google or Microsoft.

We have no database and no file store for your projects — there is simply nowhere on our side for them to go. It also means we cannot retrieve your data, and we cannot recover it if you lose access to your own cloud account, so keep that account secure.

  • A working copy on this device. So that projects open instantly and keep working offline, Snugstar keeps a copy in your browser's own storage on this device. It never leaves your device except to sync with your own Drive or OneDrive. Clearing this site's data in your browser removes it — on a shared computer, do that after signing out.
  • Demo mode. "No account (try a demo)" keeps everything in the memory of that browser tab. Nothing is saved anywhere; closing or refreshing the tab erases it.
  • Copy, paste and export. Pasting from Excel or Prism reads your clipboard only when you paste. "Copy methods", "Copy all results", figure downloads and "Download project" files are produced in your browser and go only to your clipboard or your downloads folder. "Open a project file" reads the one file you choose, in your browser; it is not uploaded anywhere.
  • Sharing a project. When you share a project, Snugstar puts it in a file of its own in your Google Drive and shares that file, through Google's own permissions, with the people you choose (view or edit). Google sends them the invitation. The file stays in your Drive; people you remove lose access through Google. Opening a project shared with you asks Google to let Snugstar open that one file, which you confirm in Google's own window. Nothing passes through a server of ours.

3. Don't take our word for it — check it yourself

Most privacy policies ask you to trust them. Ours is built so you don't have to: every claim above is something you can verify in a few minutes, with tools you already have.

  1. Google enforces it, not us. When you connect Google Drive, Google's own consent screen shows the only access Snugstar asks for: to see, edit, create and delete only the specific files you use with this app (Google's drive.file permission). Google itself stops Snugstar from opening any other file in your Drive — even if we wanted to, we couldn't.
  2. Watch where your data goes. Open your browser's developer tools (F12, or Ctrl/⌘+Shift+I), choose the Network tab, then work on a project. Your data goes only to googleapis.com (Google Drive) or graph.microsoft.com (OneDrive). The only requests to our own address carry an action name and a number, such as {"event":"data_pasted","value":1} with your usage pseudonym, and, once per sign-in, the request that obtains that pseudonym (section 5) — never a value from your data.
  3. Microsoft enforces it too. When you connect OneDrive, Microsoft's consent screen shows that Snugstar asks only for full access to its own app folder (Microsoft's Files.ReadWrite.AppFolder permission) — Apps › Brainzie Snugstar in your OneDrive. Microsoft itself stops Snugstar from opening anything outside it, for personal and work or school accounts alike.
  4. Try it with no account at all. Demo mode needs no sign-in. Every screen, test and graph works, and nothing you type is stored anywhere once you close the tab.
  5. Take your access back whenever you like. Remove Snugstar's access at myaccount.google.com/permissions (Google) or account.live.com/consent/Manage (a personal Microsoft account; for a work or school account, myapplications.microsoft.com). From that moment Snugstar cannot reach your storage — and your files stay exactly where they are, in your own folder, for you to keep, move or delete.

4. Data about other people in your research

Your projects may contain data about people — study participants, patients, volunteers. Because Snugstar never sends that data to us, we are neither its controller nor its processor: you (or your institution) remain the controller, and the storage provider you chose holds it under your agreement with them. Please make sure that keeping it in your Google Drive or OneDrive is allowed by your ethics approval, your participants' consent and your institution's data policies, and pseudonymise it where you can.

5. The personal data we do process

Pseudonymous usage analytics

We want to know how many people use Snugstar and how much, so we can keep improving it. We do this without ever learning who anyone is:

  • We record a handful of simple events — "a project was created", "a project was opened", "data was pasted" — each with a count, and whether the account is on the free or a paid plan.
  • When you're signed in, each event is filed under a pseudonym. Once per sign-in, the app asks our server for it: the server confirms who you are with Google or Microsoft — the same check a sign-in makes — and turns your verified email address into a one-way, salted cryptographic hash. It sends back only that hash and keeps nothing else: your email is never stored, never logged and never sent to analytics. You get the same pseudonym on every device, so we count people rather than browsers, and nobody can inflate the numbers with made-up identifiers.
  • When you're not signed in, or in the demo, a random identifier your browser makes up is used instead, scrambled with the same one-way hash.
  • A pseudonym cannot be turned back into your email. Checking a guess would need both your email and our secret salt, and the salt never leaves our server.
  • We never send any of your data, project names, values or results to analytics. Only the action, a number and the plan leave your browser.

These counts are stored in Cloudflare Workers Analytics Engine, which deletes them automatically after three months.

Sign-in

Signing in happens between you and Google or Microsoft: they give your browser permission to use your own storage, and your password never reaches us. The access they grant is held in your browser and used to talk to your own storage — and, once per sign-in, to let our server confirm your email for the pseudonym above, which is all it keeps.

Subscriptions, if you choose one

Snugstar is free today. If we introduce paid plans and you subscribe, the app will ask our subscription service whether your account has a plan: it sends your sign-in token, which the service checks with Google or Microsoft to learn your verified email address. For subscribers we then store your email with your subscription status (active or lapsed, and the renewal date) in Cloudflare KV. Payments will be processed by Stripe, which handles your card details directly — we will never see or store them. For as long as you use only free features, no account record about you is kept — only the pseudonymous usage counts above.

Messages you send us

If you use our contact form or email us, we receive what you send — your name, email address and message — and use it only to reply and to keep a record of the conversation. The contact form is protected by Cloudflare Turnstile, a privacy-friendly anti-spam check that does not track you across sites.

Website visits

On this website (the pages you are reading now, not the app) we count visits with Cloudflare Web Analytics. It sets no cookies, stores nothing on your device and collects no personal data: we see only anonymous, aggregate numbers such as page views, the site that referred a visit and the country it came from.

Hosting and security logs

This website and the app are served by Cloudflare. As with any website, Cloudflare may transiently process technical request metadata (such as your IP address) to deliver the service and protect it from abuse.

6. Why we're allowed to process it (legal bases)

  • To perform our contract with you — providing the app and, if you subscribe, managing your subscription.
  • Our legitimate interests — keeping the service secure, answering your messages, and improving Snugstar using pseudonymous usage counts that cannot be turned back into your identity.
  • Your consent — where it is required and you have given it.

7. Who we share data with

We do not sell your data and never will. We rely on a small number of trusted providers purely to run the service: Google and Microsoft (sign-in and the storage you chose — under your own agreement with them), Cloudflare (hosting, the contact form, pseudonymous usage analytics and, once paid plans exist, subscription status) and, once paid plans exist, Stripe (payments). Some of these providers may process data outside the UK/EEA; where they do, appropriate safeguards (such as standard contractual clauses) apply.

8. How long we keep it

Your projects are kept in your own cloud for as long as you choose — you can delete them there at any time, without asking us. Messages you send us are kept for as long as the conversation needs, and then for a reasonable record-keeping period. A subscription record is kept for as long as you subscribe, and afterwards only as long as our legal and accounting obligations require. Pseudonymous usage counts are deleted automatically after three months.

9. Your rights

Under UK GDPR and equivalent laws you have the right to access, correct or delete the personal data we hold, to object to or restrict our processing, and to data portability. Because your projects live in your own cloud, you already control them directly — you can view, export or delete them without us. For the limited data we hold (your messages, a subscription record if you have one, and the usage counts filed under your pseudonym — tell us the email you sign in with and we can find them), contact privacy@brainzie.co.uk and we'll action your request. You also have the right to complain to the UK Information Commissioner's Office (ICO) or your local data protection authority.

10. Children

Brainzie Snugstar is not intended for children under 16, and we do not knowingly collect their data.

11. Changes to this policy

We may update this policy from time to time. When we make material changes we'll update the date above and, where appropriate, let you know in the app. We will never change Snugstar so that your projects are sent to us without telling you first, here and in the app.

Read our Terms & Conditions →

Brainzie Snugstar
FeaturesContactOpen the appPrivacyTermsAdmin

© Brainzie Ltd. All rights reserved.