Brave Browser Privacy Policy

FIRST SEEN 2026-07-29 · VERSION 20260729_rev01 · COMPARED WITH 20260403_rev01

Full text changes — 20260403_rev01 to 20260729_rev01

COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED

1Our company does not collect or retain a user's browsing history. Some features require us to process information like your IP address, in order to function. And sometimes, you may choose to provide us with personal data. Below we list the features that may process personal information related to you, who receives this information, and how long this information is retained.
2
3Read this document to understand how the Brave Browser and Brave's services use data.
4
5## Other Brave privacy notices
6
7- [Brave Search Privacy Notice](https://search.brave.com/help/privacy-policy)
8- [Brave Websites, Forums, and Email Privacy Notice](https://brave.com/privacy/website/)
9- [Brave Rewards Advertiser Privacy Notice](https://brave.com/privacy/advertiser/)
10- [Brave Publishers and Creators Privacy Notice](https://brave.com/privacy/publishers-creators/)
11- [How to Exercise Your Right to Be Forgotten (RTBF) in Brave Search](https://search.brave.com/help/brave-search-index-right-to-be-forgotten)
12
13In this notice "we", "us", etc. refers to Brave Software Inc, while "Brave" refers to the browser.
14
15## Security & updates
16
17Brave automatically checks for updates. This ensures that you always have access to the latest security fixes. We count the number and type of these requests when we receive them to produce aggregate statistics. No particular person's information can be identified in the statistics we produce.
18
19You can also update to the latest version [here](https://brave.com/download/).
20
21## Brave Browser features
22
23### Safe Browsing
24
25The Brave Browser automatically uses Google Safe Browsing to help protect you against websites, downloads and extensions that are known to be unsafe (such as sites that are fraudulent or that host malware). This service relies on storing URL hashes locally on your device. When a potentially unsafe site is visited, Google receives a partial URL hash of the site. This is necessary in order for Safe Browsing to work. The actual website address is never shared with the service provider.
26
27On desktop, we proxy this service in order to prevent your IP address from being shared with Google.
28
29On Android, we rely on the Safe Browsing functionality built into the operating system. Any requests to Google servers made by this component (by the Brave app or by another app) will expose your device IP address to Google.
30
31On iOS, we use the Safe Browsing functionality provided by Safari. This functionality uses Google and Tencent Safe Browsing services depending on your region. Apple proxies requests to these services, exposing your device IP address to Apple.
32
33[Learn how](https://support.brave.app/hc/articles/15222663599629-Safe-Browsing-in-Brave) to change your Safe Browsing settings.
34
35### Sync
36
37If you enable Sync, your bookmarks, passwords and other data will be saved in an encrypted file on our cloud hosting provider (AWS). Only you have access to the decryption key, which is stored on your devices. This means it's impossible for us to recover synced files if you lose access to your device or keys. [Learn how](https://support.brave.app/hc/articles/360021218111-How-do-I-set-up-Sync-) to switch on Sync here.
38
39Note: Unused Sync chains expire after 12 months and the associated server data may be permanently deleted after that time.
40
41### Location
42
43If you use Brave to visit a website that tracks user location, you may be asked whether you want the website to know where you are located. If you grant permission, the website will be sent an approximation of where you are located based on your IP address and information your operating system may provide, for example, the names of nearby WiFi access points. The website may store your location. Your location is not sent to us in this process.
44
45[See data processing details]().
46
47### Brave Translate
48
49Brave browser includes a built-in translation feature for use in the desktop and Android browsers.
50
51We use third party translation software ([Lingvanex](https://lingvanex.com/)) hosted on our infrastructure to provide in-page translation. Brave does not collect the content of webpages being translated, and any text submitted to our translation server is deleted once it's translated. We also remove IP address information associated with your requests. We do this to protect your privacy. More details on Brave Translate can be found [here](https://support.brave.app/hc/en-us/articles/8963107404813-How-do-I-use-Brave-Translate).
52
53### Brave News
54
55Brave News is a private, content news reader integrated into the Brave browser. It is off by default.
56
57When you turn on Brave News, a range of content is presented by default. The default content is selected using [Brave Search](https://brave.com/search/). You can at any time change the default content settings and choose what content you want appearing in your feed. You can also add feeds manually by subscribing directly to publishers' content using publicly available RSS feeds.
58
59To protect your privacy, Brave employs a combination of methods for delivering content that ensure your browser cannot be identified or tracked by Brave or any third party. Headlines are made available on a public CDN in text files, the same file for all users for each region. Some images from publishers and images in the Brave News user interface are processed to improve performance and ensure they display correctly in the Brave News user experience. Processed images are all delivered through a private and encrypted proxy method. The proxy removes and does not retain IP addresses before passing the encrypted request to the private content server, which then sends the encrypted reply back to the browser via the proxy. All other publisher images are collected directly from the publishers from your device. When you add RSS feeds manually, the text and images are collected directly from the publisher of the RSS feed and included in Brave News on the client. The feed of text and images from Brave and from your RSS feeds is temporarily stored on your device, and it is replaced upon starting or refreshing your Brave News session.
60
61Brave News will offer suggestions of sources you might like to follow. If you choose to follow a suggested source it will be added to your Following list; you can always unfollow a source via the Settings panel. The suggestions and your choices are determined on your browser and never leave your device. Your Brave News sessions are not logged or saved by Brave. This information is private to you and only you.
62
63Brave's [Suggestions service](https://github.com/brave/source-suggestions/) is open source and available to view via GitHub.
64
65**Please note**: The RSS feed content you add is collected directly from the feed source and not proxied by Brave. The Brave browser fetches it without ever hitting Brave servers, and Brave never knows anything about your chosen RSS feeds.
66
67It's your choice. You can add, follow, unfollow, or hide content sources any time.
68
69### Brave Email Aliases
70
71Brave Email Aliases allows you to sign up for services without revealing your identity and keep your email free from spam. Protect your privacy by generating unique addresses that forward to your primary email inbox.
72
73Once you sign up for Email Aliases, we will store the primary email address associated with your Brave Account and any email aliases that you generate. Brave does not read the contents of these emails, except to perform standard spam and virus filtering. In case of temporary email delivery failures (e.g., if your primary mailbox is full), we will periodically try to resend the email for up to 24 hours, before deleting the message. Any notes you create for aliases are stored locally on your device, unless you use Brave Sync, in which case they're encrypted end-to-end between devices on the same Sync chain. Only you can decrypt or read these notes. Learn more about how Brave Sync protects your privacy [here](https://brave.com/).
74
75Brave uses Amazon Web Services (AWS) for Email Aliases. All messages are encrypted-at-rest.
76
77For metrics and debugging, we collect limited data and log events that are deleted within 14 days. We do not log the content of the email, and we do not log sender information.
78
79Learn more about Brave Email Aliases and how it works [here](https://support.brave.app/hc/en-us/articles/45530506862349).
80
81## Brave Rewards
82
83If you enable [Brave Rewards](https://brave.com/brave-rewards/), we assign your Brave browser a "Rewards Payment ID", which is used to account for Basic Attention Token ([BAT](https://brave.com/brave-rewards/)) rewards you may earn for seeing [Brave Private Ads](https://brave.com/brave-ads/). We will also ask you to select your country, which we will use to assign a country code to your Rewards Payment ID. The country code helps us ensure Ads are displayed to individuals depending on their country. We will also use the country code to help us prevent fraud. You can find your Rewards Payment ID by navigating to brave://rewards-internals.
84
85Even with Brave Rewards enabled and a Rewards Payment ID assigned, we never collect your browsing history or similar information, and we can't derive this information from your contributions to content creators or sites. We also [cannot tell which specific Brave Private Ads you've seen or interacted with](https://github.com/brave/brave-browser/wiki/Security-and-privacy-model-for-ad-confirmations).
86
87Note that we record the identifiers mentioned herein on servers located in the United States. We take a range of technical and organisational measures to safeguard personal data.
88
89### Connecting a custodial account
90
91When you choose to connect a custodial account to Brave Rewards using one of our custodial partners such as [Uphold](https://uphold.com/), [Gemini](https://www.gemini.com/), [bitFlyer](https://bitflyer.com/) (Japan only), or [ZebPay](https://zebpay.com/) (India only), three things become associated with your Rewards Payment ID: a custodian ID, deposit address(es), and a country code. All three are assigned by the custodial partner. The deposit address allows us to make deposits to your custodial account, while the country code helps us prevent fraud and limit service to users in countries where Brave Rewards is supported. In addition, we also use IP addresses and Rewards Payment IDs associated with monthly BAT payments to safeguard against fraud. See the [Brave Rewards data processing table]()
92
93When you make an on-demand contribution to Brave Creators using BAT from your linked custodial account(s), the custodian can see and record the details of your contribution transactions (such as, but not limited to, the amount and the recipient). This is subject to the privacy policies of [Uphold](https://uphold.com/legal/privacy-policy), [Gemini](https://www.gemini.com/legal/privacy-policy), [bitFlyer](https://bitflyer.com/), or [ZebPay](https://zebpay.com/legal-privacy). However, when using the [Auto-Contribute](https://support.brave.app/hc/en-us/articles/360027276731-Brave-Rewards-FAQ) feature to support Brave creators with BAT from your custodial account, [neither Brave nor your custodian can tell which specific creators you're contributing to](https://github.com/brave/brave-browser/wiki/Security-and-privacy-model-for-rewards-auto-contribute).
94
95### Connecting a self-custody account
96
97When you choose to connect a self-custody account/address (such as a Solana address), your Rewards Payment ID will be associated with your self-custody address. See the [Brave Rewards data processing table]() for details of what data we process and why and for how long.
98
99_Cookies:_ As part of the process to connect your Solana address to your Rewards Payment ID, a temporary, security-related cookie will be set in your browser for one of our Rewards-related service domains. The purpose of this cookie is to protect you against cross-site forgery attacks during the connection process. The moment the cookie is done playing its role in the connection process, the cookie is immediately cleared from your browser.
100
101## Brave Ads
102
103Like most websites, we show ads to support our mission of building an independent, user-first internet. [Brave Ads](https://brave.com/brave-ads/) work by matching relevant advertisements to you, inside the Brave Browser. In other words, your personal data never leaves your device.
104
105When you view an ad (either via a popup notification, new tab ad, or as part of in-browser sponsored content via the offer wall), you may receive BAT as a reward, provided that you have the Brave Rewards feature enabled and a payout account connected. However, you may see Brave Ads even if you do not have Brave Rewards enabled.
106
107If you interact with an ad on Brave Search, Brave Browser may temporarily store some data on your device to measure the performance of this specific ad. [Learn more about Brave's Search ads conversion reporting and how to disable it](https://search.brave.com/help/conversion-reporting).
108
109You can control which types of Brave Ads formats you see. For example, you can opt out of Brave Ads on the New Tab Page by visiting `Settings > New Tab > Customize the background image` and disabling them. Ads displayed within search results from Brave Search can be opted out of via enabling "Aggressively block trackers and ads" in Brave Shields. Please consider paying for [Brave Search Premium](https://account.brave.com/) instead for an ad-free search experience. If you have Brave Rewards enabled, you can also control which Brave Ads formats you see by navigating to Ads Settings in the Brave Rewards interface.
110
111For advertisers, please see: [Brave Rewards Advertiser Privacy Notice](https://brave.com/privacy/advertiser/). For publishers and creators, please see: [Brave Publishers and Creators Privacy Notice](https://brave.com/privacy/publishers-creators/).
112
113### Brave Ads privacy protections
114
115- Brave does not have access to your information, your browsing history, or any details that can be used to identify or profile you. This is by design.
116- We measure ad performance by receiving anonymized events for ads that you (and other users) have interacted with. In short, we cannot tell which specific Brave Ads you've seen or interacted with. No data that identifies you or that can be linked to you leaves your device.
117
118## Brave Wallet
119
120The Brave Wallet is a secure crypto wallet built directly into the Brave browser. You can buy, send, store, and swap thousands of assets (and NFTs) seamlessly on 100+ blockchain networks including Ethereum, Solana, Filecoin, and more. You can learn more about 'crypto wallets' and the Brave Wallet [here](https://brave.com/wallet/)
121
122Brave Wallet relies on third party service providers to help us read and write transactional data from various blockchains including Bitcoin, Ethereum, Solana, and others on a user's behalf. To do this we typically need to pass wallet address(s) or transactional data to these service providers in order to help users interact with the blockchain. In certain circumstances, such as when a service is used by default, Brave proxies requests to prevent data from being connected to your IP address. By enabling Brave Wallet, you consent to relying on these services to interact with the Blockchain when necessary.
123
124When you make a transaction using a third-party that redirects you to their services, such as an on-ramp partner, they will capture your IP address, wallet address, transaction and event data. With on-ramp services, you'll be linked to a third-party site which may conduct identity verification checks in order to meet obligations they have under sanctions and anti-money laundering laws. You should review the privacy notices and terms of service of those third parties.
125
126We use Decentralised Exchange Aggregators (DEX) such as [0x](https://www.0x.org/about/mission) for swaps made on EVM compatible blockchains and [Jupiter](https://jup.ag/) for swaps completed on the Solana blockchain. They will also process your wallet address, related transaction data and your IP address but will ONLY use this data to fulfill the transaction (including getting a quote).
127
128### Sanctions compliance
129
130Cryptocurrency addresses that are listed on the OFAC's [Specially Designated Nationals List](https://sanctionslist.ofac.treas.gov/Home/SdnList) (SDN list) are ineligible to participate in Brave services, including Brave Wallet. To meet our legal obligations, Brave compares cryptographic addresses to a copy of the SDN list built-in to the browser. Brave Wallet will not allow for transfers to any sanctioned addresses. We may also need to perform periodic lookbacks of past transactions to meet compliance obligations. We use a third-party provider ([Inca.Digital](https://inca.digital/)) to perform this service on our behalf.
131
132### Brave Wallet privacy protections
133
134- Brave does not track actions that you make in your wallet.
135- Brave proxies and strips the IP address associated with access to the Brave Wallet.
136- Brave does not log transaction data.
137- We use anonymized and aggregated statistics collected from on-ramp partners which include regional volumes of transactions, the daily number of transactions by token/chain, daily currency volumes of transactions by token/chain, and monthly unique transactions by token/chain. We use this statistical data to understand at a high level which cryptocurrency assets are being used and on which platforms.
138
139## Brave premium services
140
141### Brave Talk
142
143Brave Talk is a private video and/or audio conference tool. What you say or type in the service is not logged or saved. Who you talk to, when, and how, is private to you. [See data processing details]().
144
145Please note that Brave uses the [8x8](https://www.8x8.com/) communications platform, and software (API) capabilities of 8x8 (based on the [Jitsi](https://jitsi.org/) Open Source video conferencing software) to help deliver Brave Talk. 8x8 provides a service on behalf of Brave, and we remain responsible for Brave Talk.
146
147Brave Talk is Internet-only; it does not support participation via telephony.
148
149#### What information does Brave Talk process?
150
151We process the minimum information necessary to provide the Brave Talk service. This includes:
152
153- Your IP address and the URL of the meeting that will be processed in order to enable calls. This data is not retained after a call ends.
154- If you use the chat function, chats will be temporarily cached for the duration of the meeting; they are not retained after a call ends.
155- If you record a meeting that you host, the recording will be temporarily stored on the server for 24 hours to allow you to download it. Your profile name that you choose to display will be processed and available during the meeting.
156
157While communications are encrypted between the Brave browser and Brave Talk servers via transport layer encryption, they are not encrypted on the server during a call, unless you enable Video Bridge Encryption (VBE). Additional security options are available to you in the settings menu once you initiate a call. These include:
158
159- **Enable Lobby**: This lets you protect your meeting by only allowing people to enter after being approved by a moderator.
160- **Add a passcode**: This lets you restrict access to the meeting to people who have been provided the code.
161- **Enable Video Bridge Encryption (VBE)**: This is currently experimental. If you enable VBE, it will disable server side services such as recording and livestreaming. Note that if you enable VBE but other participants do not, they won't be able to see or hear you.
162
163Please note that if you upgrade to the Brave Talk Premium plan, Brave will require an email address to initially create a premium account, and subsequently to manage your access to the account using anonymous credentials. We use the third-party payment provider [Stripe](https://stripe.com/gb/checkout/legal) to process payments for premium subscriptions. Stripe will process your email address, name, and payment card data for the purpose of managing your subscription payments only. Brave does not receive nor have access to your payment method details supplied to Stripe, and we cannot associate an account email address or payment details with your communications on Brave Talk.
164
165**To avoid scams:** For the avoidance of phishing attacks, note that we at Brave will never contact Brave Browser users in a Brave Talk call.
166
167We do not authenticate users or their associated avatar images. Accordingly, you should never share any confidential information with anyone on Brave Talk unless you are certain that you know who you are talking to. (Of course, this is a good practice regardless of whether you are using Brave Talk, or email, or any other form of communication.)
168
169### Brave Firewall + VPN
170
171You can subscribe to Brave Firewall + VPN in two ways: via [account.brave.com](https://account.brave.com/), or via the applicable app store for your mobile device (iOS App Store or Google Play Store). Brave Firewall + VPN is powered by [Guardian](https://guardianapp.com/), and Guardian also provides technical support for Brave's Firewall + VPN service. [To learn more about what information we use for subscriptions-and why-see our data processing details]().
172
173### Brave Leo
174
175Brave Leo AI is our privacy-first AI-powered assistant integrated into the browser. Leo offers multiple capabilities including chat, webpage summaries, tab management, writing assistance, and more. Leo is free to use with limited access. If you sign up for Leo Premium, you will have access to more models, higher usage limits, and early access to new features.
176
177#### What information does Brave Leo process?
178
179When you use Leo, Brave shares with Leo's backend server the following information in order to complete your request:
180
181- **For general chat queries**: your prompt and conversation context. In some cases, Leo will send queries derived from your input to Brave Search and use the search results to better answer your question.
182- **For web page summaries and suggested questions**: the prompt and content of the page or pages you're viewing, including any text you have highlighted on the page.
183- **For tab management & history modes**: For tab management, the titles and URLs of your open non-Private/non-Tor tabs. Tab history mode also includes the titles, URLs and text passages for matching results in your tab history.
184- **Feedback**: If you submit feedback on Leo's responses, our servers will receive some information. See [Brave Leo feedback]() for more details.
185- **Privacy-preserving query analytics**: To better understand the types of queries Leo AI is used for, we use [STAR](https://brave.com/privacy-updates/19-star/) and [Nebula](https://brave.com/blog/nebula/) to learn aggregated insights without leaking individual behavior. In addition, we only extract non-identifying metadata, such as the broad category of a user query, the language the query is written in, and the AI model used. For example, Brave may learn that a certain percentage of users engage Leo AI for creative writing, but not which users or even what they wrote.
186- **Brave Leo Local Storage**: If you have enabled chat history, your conversations with Leo AI will be encrypted and stored locally on your device. We do not save these conversations, nor do we use conversations for model training. You can disable conversation storage or clear saved chats by going to **brave://settings/leo-ai**. If you clear your browsing history, any associated page content in your chats will also be removed. Chat history is not available in Private Windows or Private Windows with Tor.
187- **AI browsing (experimental)**: AI browsing gives your browser autonomous capabilities where it can perform tasks on your behalf. AI browsing operates in an isolated browser profile, uses alignment checking to verify intended actions and maintains Brave's commitment to not logging or retaining your data. [Learn more](https://support.brave.app/hc/en-us/articles/41240379376909) here.
188
189[See data processing details]().
190
191#### Brave Leo privacy protections
192
193Brave Leo includes multiple privacy protections:
194
195- We do not collect identifiers that can be linked to you (such as IP address).
196- We don't store or retain prompts, responses, context, or personal data on our servers. We may cache large prompts to improve performance but these are deleted within minutes. We do not use your conversations for model training.
197- Conversation history is stored locally on your device.
198- Users do not need to create a Brave Premium account to use the free version of Leo.
199- If you sign up for Leo Premium, you're issued unlinkable tokens that validate your subscription when using Premium services. Brave has no way of connecting your purchase details with your usage of Leo Premium.
200
201### Brave Search Premium
202
203Brave Search Premium is a paid version of the core Brave Search experience. It gives users a chance to support Brave's mission of offering independent, unbiased search. Brave Search is designed to be private by default. We don't collect personal information about you, your device, or your searches. We also don't transmit information to the web that could be used to profile you or track you or learn anything about you.
204
205For more information, see the [Brave Search Privacy Notice](https://search.brave.com/help/privacy-policy).
206
207## How we improve Brave
208
209### Diagnostic reports
210
211When Brave crashes or freezes, it creates a report that can be sent to us to help us diagnose and fix whatever caused the problem. This report contains technical information about your computer system and the event causing the problem. The data can't be used to identify you.
212
213We use a service called Backtrace.io to store the reports. You can choose whether to send us these reports. Even if you have chosen to send reports in the past, you can turn off future reports in [settings](https://support.brave.app/hc/en-us/articles/360017905872-How-do-I-enable-or-disable-automatic-crash-reporting-).
214
215### Privacy Preserving Product Analytics
216
217The Browser sends us anonymous reports to alert us to product problems and necessary improvements. None of the information it reports can be used to identify you. The report only describes general use of the Browser or other Brave products, such as a general range of how many extensions are installed, a general range of how many tabs are open, and whether features like Shields, Rewards, and Ads are switched on. [See the full list of questions here](https://github.com/brave/brave-browser/wiki/P3A). These reports are stripped of metadata, and aggregated with measurements reported by many other instances of Brave. The data are not personal, and cannot be combined to identify you. You can deactivate Privacy-Preserving Product Analytics in Settings.
218
219### Web Discovery Project
220
221The Web Discovery Project is intended to make Brave Search more relevant and useful for everyone. If you opt in, you'll contribute some anonymous data about searches and web page visits made within the Brave Browser (including pages arrived at via some, but not all, other search engines). This data helps build the Brave Search independent index, and ensure we show relevant results to your search queries and support more relevant experiences with Brave products and services.
222
223Collection is done in a privacy-preserving fashion. The Web Discovery Project records the terms you search for on some search engines if that search query passes a series of checks, intended to avoid recording or sending sensitive queries. For example, WDP will not send search queries that are very long, or that include email addresses or long numbers.
224
225WDP also records some of the pages you visit, if the URLs pass a series of checks designed to filter out unique or identifying URLs. For example, URLs that are too long or include certain terms or long numbers are never sent. Additionally, WDP protects the URLs you send by encrypting them in a manner that prevents Brave from seeing or reading the URL unless it has been sent by a large number of other users.
226
227The system is designed so that no data received can be linked back to individuals or their devices. For a URL to be sent it needs to be visited independently by a large number of people. All data received is unlinkable, making it impossible to build profiles or sessions of Web Discovery Project contributors.
228
229[Read a full description of the Web Discovery Project methodology.](https://support.brave.app/hc/en-us/articles/4409406835469-What-is-the-Web-Discovery-Project-)
230
231### Your feedback
232
233We collect feedback solely for the purpose of improving our products and services, enhancing your browsing experience, answering your questions, and resolving compatibility issues. Depending on the context, this may include personal information you provide to us directly, such as your name, email address, contact information, or contents of the feedback. In some cases, we may also indirectly receive your IP address (for example, if you communicate on the Brave or BAT community forums). For more information on how we handle your personal data related to feedback and communications (including the Community Forums), please see our [Brave Websites, Forums, and Email Privacy Notice](https://brave.com/privacy/website/).
234
235### Web compatibility reports
236
237If you submit a Web compatibility report, you'll have the option to include certain details to help us analyze and address compatibility issues. Providing this information is voluntary, and any data you submit will be deleted from Brave's servers after 30 days. See our [Web compatibility reports wiki page](https://github.com/brave/brave-browser/wiki/Web-compatibility-reports) for more details on what data is collected.
238
239### Brave Leo feedback
240
241You can voluntarily submit feedback on Leo's responses (Brave's privacy-first, AI-powered assistant) by clicking the thumbs-up or thumbs-down icons. This sends the rating, full text of the current conversation, language, selected AI model, version, and Premium subscription status (if any). You also have the option to include additional details and the current website to assist us in improving Leo's responses. All submitted data will be deleted from Brave's servers after 1 year.
242
243### Nightly, dev, and beta browser versions
244
245[Nightly](https://brave.com/download-nightly/), [Dev](https://brave.com/download-dev/), and [Beta](https://brave.com/download-beta/) versions of the Brave Browser are experimental previews of new Brave Browser versions. They allow us to test new features so that we can find and fix errors before releasing a new version of the Brave Browser. These test versions of the Browser may automatically send crash reports to Brave so that we can identify and fix problems. A crash report can contain personal information. [See data processing details.]()
246
247**How to switch this feature off.** You can switch off "Automatically send usage statistics and crash reports to Brave Software" in settings.
248
249> **Tip:** you can quickly access settings by copying _**brave://settings**_ into your address bar.
250
251These incomplete versions of Brave represent unfinished and untested work on future versions of Brave, and their incomplete behaviour may not be adequately described by this policy. More information about the safety & reliability of pre-release versions of Brave can be found in our [development documentation](https://github.com/brave/brave-browser/wiki/Release-Channel-Descriptions).
252
253### Location
254
255| Purpose of processing | Categories of personal data processed | Legal basis of processing | Duration of storage |
256| --- | --- | --- | --- |
257| To estimate the user's physical location at the request of a website and with the confirmation of the user. | IP address, and information about nearby WiFi access points (MAC address, signal strength, and SSID). | Legitimate interest. | No storage. |
258
259### Brave Rewards
260
261| Purpose of processing | Categories of personal data processed | Legal basis of processing | Duration of storage |
262| --- | --- | --- | --- |
263| To make and verify Basic Attention Token contributions, (including to detect and prevent fraud). | IP address at time of claiming a grant of BAT tokens or requesting confirmation tokens. |
264Necessary for the performance of a [contract between us](https://basicattentiontoken.org/user-terms-of-service/) and necessary to provide the requested service.
265
266Processing for the purposes of fraud prevention is based on the legitimate interests of Brave and users of Brave Rewards.
267
268 | Generally stored for 7 days. In cases of suspected fraud, stored for up to 60 days. In case of confirmed fraud, stored for up to 2 years. |
269| To make and verify Basic Attention Token contributions, (including to detect and prevent fraud). | Rewards Payment ID, declared country code and Custodian ID and custodial country code when verifying a Brave Rewards wallet with a custodial partner. |
270
271Necessary for the performance of a [contract between us](https://basicattentiontoken.org/user-terms-of-service/), (and necessary to provide the requested service & to provide customer support).
272
273Processing for the purposes of fraud prevention is based on the legitimate interests of Brave and users of Brave Rewards.
274
275 | The duration of the user's account, plus 4 years in order to comply with US Internal Revenue Service requirements. |
276| To make and verify Basic Attention Token contributions to a Solana address, (including to detect and prevent fraud). | Rewards Payment ID and associated Solana address |
277
278Necessary for the performance of a [contract between us](https://basicattentiontoken.org/user-terms-of-service/) and necessary to provide the requested service.
279
280Processing for the purposes of fraud prevention is based on the legitimate interests of Brave and users of Brave Rewards.
281
282Compliance with legal obligations
283
284 | The duration of the user's account, plus 4 years in order to comply with US Internal Revenue Service requirements. |
285
286### Brave News
287
288| Purpose of processing | Categories of personal data processed | Legal basis of processing | Duration of storage |
289| --- | --- | --- | --- |
290| To collect content from the server in order to display it for the user. | IP addresses. | Legitimate interest. The data are used in order to deliver the service, and the risk of the processing of the data is minimal. | The duration of the request and response |
291
292### Brave Talk
293
294| Purpose of processing | Categories of personal data processed | Legal basis of processing | Duration of storage |
295| --- | --- | --- | --- |
296| To facilitate communications via Brave Talk. | IP address, meeting URL, chat content, audio and video, recordings/transcripts of meetings. | Legitimate interest. The processing is necessary to provide the requested service. | Duration of the call, except for recordings/transcripts of meetings that are temporarily stored for 24 hours. |
297| To create a Brave Premium account and manage account access. | Email address |
298Legitimate interest.
299
300The data is necessary to establish an account and manage account access.
301
302 | Until an account is deleted. |
303
304### Brave Firewall + VPN
305
306| Purpose of processing | Categories of personal data processed | Legal basis of processing | Duration of storage |
307| --- | --- | --- | --- |
308| To send an alert to the user when a firewall rule is triggered. | Pseudonymous user ID, details of the blocked tracker/firewall rule triggered. | Necessary for the performance of the contract (to deliver the service). | 3 days. |
309| To create private connections. | IP Address. | Necessary for the performance of the contract (to deliver the service). | None. IP addresses are not logged. |
310| To provide customer support. | Email address and other personal data that a user may choose to share when requesting technical support from Guardian. | Necessary for the performance of the contract (to deliver the service). | 12 Months after closing a support ticket. |
311
312### Brave Leo
313
314| Purpose of processing | Categories of personal data processed | Legal basis of processing | Duration of storage |
315| --- | --- | --- | --- |
316| Handling user-generated chat queries. | Query, conversation context. | Necessary for the performance of a contract between us to provide the requested service. | Ephemeral - discarded soon after chat is completed. If local storage is enabled, chat history will be stored locally on your device. |
317| Summarizing/suggesting questions for websites, documents, or other uploaded content. | Query, website/document contents (which may contain personal data). | Necessary for the performance of a contract between us to provide the requested service. | Ephemeral - discarded soon after chat is completed. If local storage is enabled, chat history will be stored locally on your device. |
318| User-submitted feedback on Brave Leo. | Full text of conversation/query, additional details if provided by user. | User consent, legitimate interests (product improvements) | 1 year |
319| AI browsing. | Query, conversation context. | Necessary for the performance of a contract between us to provide the requested service. Triggered by user. | Ephemeral - discarded soon after chat is completed. If local storage is enabled, chat history will be stored locally on your device in isolated profile. |
320
321### Brave IPFS Public Gateway
322
323| Purpose of processing | Categories of personal data processed | Legal basis of processing | Duration of storage |
324| --- | --- | --- | --- |
325| To allow access to IPFS content when the user cannot access it via a local IPFS node | IP address | Legitimate interest. The user requested the service, and the risk of the processing of the data is minimal. | Indefinite. (Protocol Labs) |
326
327### Your feedback
328
329| Purpose of processing | Categories of personal data processed | Legal basis of processing | Duration of storage |
330| --- | --- | --- | --- |
331| To use feedback sent by users to improve the product. | Personal data that a user may include in the text they write when sending feedback through an app store or any other means. | Legitimate interest. The user intends for the data to be used for this purpose, and the risk of the processing of the data is minimal. | 2 years. |
332
333### Browser testing and research (Nightly, Dev, and Beta versions only)
334
335| Purpose of processing | Categories of personal data processed | Legal basis of processing | Duration of storage |
336| --- | --- | --- | --- |
337| To fix problems in the Brave Browser by acting on issues highlighted by crash reports from Beta and Dev versions of the Browser | Device model, iOS version, language, timezone, CPU architecture, carrier, connection status. Optional: Crash log (crash logs will also be sent if you opted-in when activating iOS) Optional: Comments and screenshots you share if you send feedback through TestFlight. | Our interest in testing the product and fixing problems. The data are used in a way that does not negatively affect your rights or interests. | Apple retains the data for one year. Brave may retain some crash reports indefinitely, if useful for testing. |
338
339### Help with privacy settings in Brave
340
341You can find guides on how to change privacy settings in Brave [in the Help Center](https://support.brave.app/hc/en-us/articles/360017989132-How-do-I-change-my-Privacy-Settings-).
342
343To contact our data protection officer and privacy team with privacy related enquiries, or to exercise your data protection and privacy rights, email [privacy@brave.com](mailto:privacy@brave.com).
344
345It's Brave's policy to not collect personal data[1]() unless it's necessary to provide services to our users, or to meet certain legal obligations. We do not buy, sell, or share personal data about consumers.
346
347Where we process personal data about you (subject to laws such as the EU General Data Protection Regulation ([GDPR](https://brave.com/glossary/gdpr/)), or California privacy [laws](https://cppa.ca.gov/regulations/) such as the [CCPA](https://brave.com/glossary/ccpa/) or CPRA), you have the following rights:
348
349- **Right to be informed**: You have the right to know what personal data we process about you and why, together with information about your rights. We explain this via our product privacy policies and/or contextual privacy notices.
350- **Right of access**: Where we process personal data about you, you have the right to request a copy of it.
351- **Right to erasure / right to be forgotten**: In some cases, you have the right to ask us to erase data we have about you, or to de-list search results that contain information about you. This is commonly known as the 'right to be forgotten' (RTBF). The Erasure and RTBF are not absolute rights, and some conditions apply. As a search engine, we cannot remove the original source of the data, only our search link(s) to it. You can find additional details (including information on how to make a RTBF request or to update our search results, and the criteria we use to assess those requests [here](https://search.brave.com/help/brave-search-index-right-to-be-forgotten)).
352- **Right to rectification**: You can ask us to correct inaccurate personal data and/or to update incomplete data.
353- **Right to restriction**: In certain circumstances, you can request that we refrain from processing your personal data.
354- **Right to object**: In certain circumstances, you can object to the processing of your personal data (for example to object to the use of your data for profiling and/or purely automated decision making). Please note that we do not buy, sell, or share personal data about consumers.
355- **Right to data portability**: In certain circumstances you have the right to request and receive personal data in a structured, commonly used, machine readable format that makes it possible to reuse the data. Please note, anonymous data is not subject to this right.
356- **Right to lodge a complaint with a regulatory authority**: Brave is based in the USA. The authority to lodge a complaint about Brave will depend on where you live. If you're in the EU you can contact our nominated representative under the General Data Protection Regulation (GDPR), or you can complain to the [Irish Data Protection Commissioner](https://www.dataprotection.ie/). If you're in the UK you can complain to the [Information Commissioner's Office](https://ico.org.uk/). If you're in California you can complain to the [California Privacy Protection Agency](https://cppa.ca.gov/).
357
358For EU residents, we have appointed a nominated representative under the [GDPR](https://commission.europa.eu/law/law-topic/data-protection/eu-data-protection-rules_en) to act on our behalf regarding GDPR compliance. You may contact our nominated representative if you wish; however, the representative will refer enquiries to Brave's data protection officer for consideration.
359
360Our EU nominated representative is:
361
362Brave EU Nominated Representative
363Care of Castlebridge
364The Exchange Wexford Whitemill Industrial Estate Wexford Y35 NPP0 Ireland
365
366[brave@gdprnomrep.eu](mailto:brave@gdprnomrep.eu)
367
368We'll update this policy whenever we make material changes to our practices, and we'll announce it to let you know. We hope you'll find any changes agreeable, but if you're not comfortable with changes to the info we collect or how we use it, we understand your choice to stop using Brave.
369
370- * *
371
372- * *
373
3741. Personal data means any information that relates to an identified or identifiable living individual. In the USA, this is often referred to as Personal Information (PI) or Personally Identifiable Information (PII). These terms are equivalent but not identical.
375
376 This can include information that can directly identify an individual-such as name or email address-and any other information that may make a person indirectly identifiable-such as online identifiers that could be combined with other data to identify an individual, or used on their own to single out individuals and distinguish one person from another with an intent to learn something about them or to take an action towards them. [↩︎]()