← Security

Security for Braintunnel on your Mac

Last updated: August 22, 2026

This page is for the Mac app. Using Braintunnel in the browser? See Security for hosted Braintunnel. All security pages: Security.

This page summarizes how the Mac app is built. It is not a contract. How we use personal information: Privacy Policy. Rules of use: Terms of Service.

What stays on your Mac

The index of your mail, calendar, documents, text messages, and pages lives on the machine where you installed Braintunnel. We never see or collect your email, calendar, documents, or other indexed data.

Tokens and secrets on this Mac are encrypted. The key is held in the macOS Keychain.

Permissions you may grant

You choose what to grant. More permission means more of your own data can join that index, such as your text messages.

Some of those sources need Full Disk Access. macOS uses that for data Apple keeps in protected folders, including Messages. We may also ask for Contacts so search can show familiar names for people you text with, not so we can copy your whole address book.

You can turn these off in System Settings. That stops new indexing from those sources.

The app, not a general agent

Braintunnel is a notarized Mac app. It does not give a model a shell on your computer. It does not install marketplace skills. Chat uses a fixed set of tools for mail, calendar, and your brain.

You pick the model

You choose the model. Use a key you already have, or a model that runs on this Mac. The Mac talks directly to that provider, or stays on-device. We do not proxy inference.

Our agreements with those providers prohibit them from training on your content. We send what the question needs, not your whole mailbox.

Remote access

You can open Braintunnel from another device, such as your phone, while this Mac is on. We create a hostname (you.braintunnel.ai) and an encrypted tunnel to this Mac. Chat and search still run here. The other device only sees the UI. We do not store the session or inspect it.

Each client gets one secure pairing token. You connect a device by scanning a QR code from the Mac app. Once that device connects, the code cannot be reused to add another client. You can revoke a token or a remote connection in the app at any time.

When the Mac talks to Braintunnel

The app calls our servers only for jobs like these:

  • You sign in with Google. We use that sign-in to issue a device entitlement so the jobs below can run. Connecting Gmail, Calendar, or Drive is separate: your Mac talks directly to Google.
  • You turn on remote access. We create the hostname. Pairing tokens stay on this Mac (see Remote access above).
  • Chat looks something up on the open web. Examples: search the web, fetch a page, pull a YouTube transcript, show a map. Those requests proxy through us so we can attach our search provider key and pay the bill for you. We do not log the query or the results, and we do not tie them to you beyond a rate-limit token so the proxy cannot be abused.
  • You connect Notion. Sign-in starts on our side (our app credentials). Your tokens are written on this Mac, encrypted. After that, the Mac talks directly to Notion.
  • You send feedback from the app. We receive the text you submitted, and a copy is saved on this Mac for your reference. You can always amend or delete the feedback, and we will remove it on our servers.

Google, when you connect it

If you connect Gmail, Calendar, or Drive, we follow the Google API Services User Data Policy, including Limited Use. Disconnect in the app to revoke access.

The Limited Use statements we published for Google review are on Security for hosted Braintunnel.

What we do not collect by default

The Mac app does not send product telemetry or error traces off the machine unless you turn that on.

Reporting security issues

If you believe you've found a security vulnerability, email security@braintunnel.io rather than posting it in public. We aim to acknowledge reports within 3 business days.

Changes

The "Last updated" date at the top changes when we make material edits. Privacy notice rules are in the Privacy Policy.

Privacy PolicyTerms of ServiceMac appHosted