Policy

We’ve published the Brello Charter

Version 1.0 took effect on 5 October 2026: our mission, eight commitments, five things we will not do, and five mechanisms that let others check whether we keep them.

Brello5 min read

Summary

On 5 October 2026 we published version 1.0 of the Brello Charter, the document that sets out what Stuvio commits to about Brello. It applies to Brello 1.0, our on-device app for Android and iPhone, to Brello Super Intelligence, which is in development, and to this website. The charter states our mission and makes eight commitments, including no training on conversations, no advertising and an evaluation before every new capability, each with its scope and a way to check it. It also names five things we will not do and five accountability mechanisms. All eight commitments will apply to Brello SI before anyone outside the team uses it. The charter’s full text is authoritative.

  • Version 1.0 of the Brello Charter took effect on 5 October 2026 and applies to Stuvio, to Brello 1.0, to Brello Super Intelligence, which is in development, and to the Brello website.
  • The charter makes eight commitments, including no training on conversations, no advertising, and an evaluation of each new capability before release with a published summary of the findings.
  • The charter names five things Stuvio will not do, including selling, renting or trading users’ information and building advertising profiles.
  • Five accountability mechanisms let others check the charter: published architecture, published evaluations, transparency reports, access for independent researchers and plain-language notes on changes.
  • Any new version of the charter will be published before it takes effect, with a dated note and a redline, and no change will apply weaker terms to information already shared.
Contents6 sections

Version 1.0 of the Brello Charter

We have published version 1.0 of the Brello Charter, the document that sets out what Stuvio commits to about Brello. It took effect on 5 October 2026. It binds Stuvio and applies to Brello 1.0, our on-device app for Android and iPhone; to Brello Super Intelligence, which is in development; and to this website.

The charter states our mission, makes eight commitments, names five things we will not do and sets out five accountability mechanisms. Each commitment says where it applies and how someone outside Stuvio can check it. The mission reads:

“Our mission is to build capable intelligence that answers only to the person using it, with privacy that can be verified rather than promised.”

Why we published it before Brello SI ships

We published the charter first so that the commitments are public, versioned and dated before anyone outside the team uses Brello Super Intelligence.

A privacy policy states what a provider has decided to do with your information; a system’s architecture decides what it is able to do. So the charter sets one rule: “work runs on your device whenever it can, and when it can’t, Brello’s servers must keep nothing, and someone other than us must be able to check that” (charter section 2). Brello 1.0 meets the first half of the rule: its AI runs on the phone, and there is no Brello server. Brello SI is being designed to meet the second.

Eight commitments

The eight commitments cover training, advertising, collection, evaluation, actions taken on your behalf, uncertainty, memory and independent verification. Section 5 of the charter gives each in full, with its scope and how to check it.

  1. We will not use your conversations to train models.
  2. We will not run advertising.
  3. We will collect only what a task needs.
  4. We will evaluate each new capability before release, and publish what we find.
  5. We will ask before Brello spends money, sends a message or deletes something on your behalf.
  6. We will build Brello to say when it isn’t sure, and to cite its sources.
  7. We will let you see, correct, export and erase what Brello remembers about you.
  8. We will make Brello SI’s privacy verifiable by independent researchers.

The charter does not change Brello 1.0, version 1.0.0. Four of the commitments already hold for it: 01, 02, 03 and 06, the last by instruction to the model, without a guarantee. Two hold in part: version 1.0.0 predates the charter and has no published evaluation (04), and it keeps no memory across chats, while its chats can be read and deleted but not exported (07). Two do not apply, because Brello 1.0 can’t spend money or send messages (05) and has no server to verify (08). Section 8 of the charter gives this status in full.

All eight will apply to Brello SI before anyone outside the team uses it, and its checks will be the architecture description and evaluation summaries described below.

Five things we will not do

The charter names five things we will not do. They bind Stuvio, and like the rest of the charter they change only through the process in its section 7.5. Section 6 of the charter gives each its scope and its check.

  • We will not sell, rent or trade your information.
  • We will not build advertising profiles, or let anyone else build them through us.
  • We will not widen what we collect without telling you first, in plain words.
  • We will not release a new capability that we haven’t evaluated.
  • We will not imply an endorsement we don’t have, or a capability we haven’t shipped.

For the third line, the check is a note in News, published before the change takes effect.

Five accountability mechanisms

Five mechanisms let people outside Stuvio check whether we keep the charter. Section 7 of the charter defines them; this is where each stood on 5 October 2026.

  • Published architecture. In place for Brello 1.0, as our privacy page and the system card, which lists everything that leaves the phone, when and to whom, and each Android permission the app requests. For Brello SI, due before anyone outside the team uses it.
  • Published evaluations. An evaluation summary with every Brello SI release and every new capability. None yet, because no such release exists.
  • Transparency reports. The legal requests for user information we receive, by category, and how we responded. The first is due before anyone outside the team uses Brello SI, then at least once a year.
  • Access for independent researchers. A route to report security and privacy findings, with a safe harbour for research done in good faith. In effect, through our security and disclosure page.
  • Plain-language notes on changes. Each new version published before it takes effect, with a dated note and a redline. There have been no changes since version 1.0.

Before anyone outside the team uses Brello SI’s sealed compute, we will also publish what independent researchers need to verify it (commitment 08).

Read the charter

The charter is the authoritative text; this post summarises it. If it changes, we will publish the new version before it takes effect, with a dated note on what changed and why and a redline against the previous version, and no change will apply weaker terms to anything you have already shared.

Version history

  1. First published.