Trust

Privacy Policy

What Brainy stores about you, how it is protected, and how you stay in control of it.

Draft — pending qualified legal review. This page describes how Brainy is built today, in plain language. It is product documentation, not a finalized legal policy, and has not yet been reviewed by qualified legal counsel for your jurisdiction.

What Brainy stores

Brainy stores the content you author while using it: notes, highlights, summaries and action items, tasks and projects, areas, resources, sources, goals and milestones, ideas, outputs, tags, and the relationships between them. It also stores your account identity (email address and password hash), your workspace preferences (time zone, dashboard layout, archive retention rules), and lifecycle/activity records used to power screens like Today and Pulse.

Every one of these records is scoped to your account. Brainy's data access layer requires a user identifier on every read and write, and self-service export and deletion (below) only ever touch the data belonging to the signed-in account.

Backups

Brainy runs on a standard SQL Server database with routine backups appropriate to the hosting environment it is deployed in. Placeholder: the specific backup schedule, backup retention window, and backup storage location for your deployment are operational details that depend on where Brainy is hosted and are not yet published here. If you operate or commission a Brainy deployment, confirm these details against your actual hosting configuration before relying on this page.

Encryption

Traffic between your browser and Brainy is served over HTTPS; the production configuration redirects plain HTTP requests to HTTPS and sends standard hardening headers (see the site's security headers). Placeholder: whether data at rest in the database and in backups is encrypted, and with which mechanism, depends on the underlying database/hosting provider's configuration and is not yet independently verified or documented for every deployment. Do not treat this page as a substitute for your own infrastructure review.

Subprocessors

Brainy's core note-taking, organizing and task features do not send your content to any third party. The only subprocessor Brainy can be configured to use is an AI provider, and only for the specific AI actions you trigger:

  • OpenAI (api.openai.com) — when the deployment is configured with the OpenAI provider.
  • Azure OpenAI Service — when the deployment is configured with the Azure OpenAI provider.

By default, AI is off (provider "None") and no note or task content ever leaves Brainy for AI processing. See AI & Your Data for exactly what is sent when AI is enabled and used.

Retention

Your content is retained for as long as your account exists. Archiving a project, area, resource or note does not delete it — archived items are excluded from active views but remain recoverable, and you can configure per-type archive retention rules (or keep items forever) from Account and data. Deleting your account removes this data as described below.

Account deletion

You can permanently delete your account and all Brainy data tied to it at any time from Account and data › Delete account. Deletion requires your current password and typing the exact confirmation phrase, and it is irreversible: your notes, projects, tasks, outputs, images and every other record scoped to your account are removed in one database transaction, and you are signed out immediately afterward. Download your export first if you might need the data later — deletion does not produce a copy for you.

Your rights: export and delete

Brainy gives you two self-service controls over your own data, both under Account and data:

  • Export your data — downloads a versioned JSON archive of your notes, projects, tasks, areas, resources, goals, outputs, relationships, preferences and stored images. Account credentials, password hashes, session tokens, and any configured AI provider keys are excluded.
  • Delete your account — permanently erases your account and the data listed above, scoped strictly to your own account.

Questions

Marketing and in-product claims about privacy and AI behavior are maintained alongside this page and reviewed against the actual implementation before publication. If something on this page looks inconsistent with how Brainy actually behaves, treat the implementation as needing a fix and report it.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.