← Bearable AI

Privacy Policy

Last updated: July 4, 2026

1. Who We Are

Bearable AI ("Bearable," "we," "us," or "our") is an AI-powered health and executive intelligence platform operated by Bearable LLC, a Texas limited liability company. We help you connect your health data, work context, and calendar so Bear — your AI companion — can support better decisions over time. Our application is available at app.bearableai.com.

2. What Data We Collect

We collect data you provide directly and data from integrations you authorize: • Account information: name, email address, phone number (if you opt into SMS), role, and onboarding quiz answers. • Health data: lab results, wearable data (e.g. Oura Ring sleep, HRV, readiness), conditions, medications, and body composition data you upload or connect. • Work context: projects, tasks, notes, conversations with Bear, and documents you add or sync. • Google Workspace data (if you connect your account): calendar events, Gmail threads, Google Drive files, and Google Tasks — accessed only with your explicit authorization and as described in Section 6. • Persistent memory: Bear remembers facts, preferences, and decisions you share across conversations to provide continuity. You can view, edit, or delete any memory entry at any time. • Usage data: pages visited, features used, and error logs (via Sentry) for debugging and reliability.

3. How We Use Your Data

We use your data solely to provide the Bearable AI service to you: • To power AI Chief of Staff conversations with context from your health, work, and calendar data. • To generate your daily brief and meeting prep summaries. • To draft emails, create tasks, and schedule events on your behalf — only after you explicitly review and approve each action. • To store your memory entries, projects, and goals across sessions. • To send you magic-link sign-in emails and optional product updates. We do not sell your data. We do not use your data to train AI models. We do not share your personal data with third parties except as described in Section 5.

4. Data Isolation and Security

Your data is strictly isolated. Each user's data is stored separately and scoped by a unique user ID. No user can access another user's data. We use encrypted HTTPS for all data in transit. Sensitive credentials (OAuth refresh tokens, API keys) are encrypted at rest using AES-256-GCM. Session tokens are 256-bit random values stored in HttpOnly, Secure, SameSite=Lax cookies.

5. Third-Party Services

We use the following third-party services to operate Bearable AI: • Amazon Web Services (AWS): database hosting (Aurora PostgreSQL), AI model inference (Bedrock), and email delivery (SES). AWS processes data under a HIPAA Business Associate Agreement. • Anthropic / Google Gemini: AI model inference. Your conversation context is sent to these APIs to generate responses. Their respective privacy policies apply to that processing. • Google APIs: if you connect Google Workspace, we access your Google data through Google's OAuth system using tokens you explicitly grant. We store your refresh token encrypted and use it only to fulfill your requests within the app. • HealthBankOne: if you connect your health records, we receive structured clinical data (labs, medications, conditions) from HealthBankOne's API under their privacy terms. • Twilio: if you opt into SMS notifications, we use Twilio to send and receive text messages. Your phone number is stored in our database; message content is processed by Twilio under their privacy terms. • Sentry: error monitoring and crash reporting. Sentry receives technical error data (stack traces, browser info) to help us identify and fix bugs. No health data or conversation content is sent to Sentry. • Vercel: application hosting and deployment. • ElevenLabs: optional text-to-speech for voice interactions. Text sent for speech synthesis is not stored by ElevenLabs beyond the request. We do not use analytics platforms, advertising networks, or tracking pixels.

6. Google API Data — Detailed Scope Disclosure

Bearable AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request the following Google OAuth scopes and use them as described: Gmail (gmail.readonly): We read your inbox to surface relevant email context in your daily brief and AI Chief of Staff conversations. We do not store email body content — only metadata (sender, subject, snippet) is temporarily used to generate your brief. Gmail Compose (gmail.compose): We create email drafts on your behalf when you ask your Chief of Staff to draft a follow-up, reply, or new message. Drafts are created in your Gmail Drafts folder for your review. We never send email without your explicit action in Gmail. Google Calendar (calendar.readonly): We read your calendar to generate your daily brief, prepare you for upcoming meetings, and help your Chief of Staff reason about your schedule. Google Calendar Events (calendar.events): We create or update calendar events when you ask your Chief of Staff to schedule a meeting or block time. Every calendar action is shown to you for confirmation before it is executed. Google Drive (drive.readonly): We read files from a Google Drive folder you explicitly configure to provide document context to your Chief of Staff. We do not scan your entire Drive — only the folder you specify. Google Drive File (drive.file): We create Google Docs on your behalf when you ask your Chief of Staff to draft a document, meeting summary, or strategy memo. We only access files the app itself creates. Google Tasks (tasks): We read your task list to incorporate pending work into your daily brief and Chief of Staff responses. We create tasks when you ask your Chief of Staff to capture an action item, and mark tasks complete when you confirm completion. Every task creation or modification is shown to you for approval. Additional protections: • We do not use Google data for advertising or to train AI models. • We do not share Google data with third parties except as necessary to operate the service (e.g. sending your calendar summary to an AI model to answer your question). • Human review of Google user data occurs only when you explicitly share a conversation with our support team. • You can revoke all Google access at any time at myaccount.google.com/permissions or from Settings → Integrations → Remove.

7. User-Approved Actions

When your Bearable AI Chief of Staff proposes an action that affects your Google account — creating a task, drafting an email, scheduling an event, or creating a document — the proposed action is always presented to you for explicit review before execution. You can approve, edit, or decline any proposed action. We do not take automated actions on your Google account without your confirmation.

8. Data Retention

We retain your data for as long as your account is active. You can delete your account and all associated data at any time. Deletion is permanent and takes effect immediately — all 27 data tables associated with your account are purged. Exported Google data (calendar context, email snippets) is not persisted beyond the session in which it was used. Bear's persistent memory entries are retained as long as your account is active and can be individually deleted from the Memory page.

9. Your Rights

You have the right to: • Export a complete copy of your data at any time (JSON download via Settings or GET /api/account/export). • Delete your account and all data permanently at any time. • View, edit, or delete any individual memory entry Bear has stored about you. • Configure or disable proactive notifications (SMS nudges) including quiet hours and daily limits. • Revoke Google Workspace access at any time via your Google account settings or from Settings → Integrations. • Revoke Oura Ring access at any time from Settings → Integrations. • Contact us with any privacy question or concern.

10. Children

Bearable AI is not intended for users under the age of 18. We do not knowingly collect data from minors.

11. Changes to This Policy

We may update this policy as the product evolves. We will notify active users of material changes by email. Continued use of the service after changes constitutes acceptance.

12. SMS Communications

If you opt into SMS notifications, Bear may send you proactive messages about your calendar, health data, or tasks. You control this entirely: • You can set quiet hours (no messages during those times). • You can set a daily maximum (default: 5 messages per day). • You can toggle individual notification categories on or off. • You can disable all SMS notifications at any time from Settings. • Reply STOP to any message to immediately opt out. We never share your phone number with third parties for marketing.

13. AI Assistant Connections (MCP)

Bearable can be connected to third-party AI assistants (such as Claude, ChatGPT, or other MCP-compatible clients) so you can query your health data conversationally. When you connect Bearable to an AI assistant: • You authenticate with your Bearable account and explicitly approve the access scope (read, write, or both). • Health information you request is transmitted to that assistant in the course of answering your question. The assistant's handling of that information is governed by its own privacy policy. • Connections use OAuth 2.1 with PKCE. Access tokens are scoped — write access (logging behaviors, proposing experiments) is only granted if you approve it. • You can revoke access at any time from your Bearable account settings or from the assistant's connector/integration settings. Revocation is immediate. • We log tool usage (request counts, response times, tool names) for reliability monitoring. We never log health values, lab results, or conversation content in these operational logs. • Connected assistants cannot modify your medical records (labs, medications, conditions). Write scope is limited to behavior logs and experiments.

14. Contact

For privacy questions, data requests, or concerns, contact us at: privacy@bearableai.com

Bearable LLC · privacy@bearableai.com · bearableai.com