Privacy Policy
Last updated: May 26, 2026
This Privacy Policy explains how Braindesk (“Braindesk”, “we”, “us”, or “our”) collects, uses, shares, and protects information when You access or use the Braindesk web application, APIs, integrations, and related services (collectively, the “Service”). Capitalized terms not defined here have the meanings given in our End User License Agreement.
1. Information We Collect
We collect the following categories of information:
- Account information. Name, work email address, organization name, role, and authentication identifiers issued by our identity provider (Clerk).
- Connected-service activity. When You authorize Braindesk to connect to a third-party system (for example, Google Workspace, Microsoft 365, Slack, GitHub, Jira, Zoom, QuickBooks, Xero, Zoho, WhatsApp Business, Tally, or similar systems), we read activity from those systems through their APIs to understand what work happened. For financial and identity systems (QuickBooks, Xero, Zoho, Tally, and similar), counterparty names and exact monetary amounts are never stored — only one-way hashes and coarse amount bands are retained, regardless of any setting below. For messaging and communications systems (Slack, Gmail, Outlook, Zoom, WhatsApp Business, and similar), Your organization's administrator chooses one of two retention modes: by default, raw content — message and email bodies, chat text, attachments — is processed transiently in memory and is not written to our database (“summary-only” retention); if the administrator instead opts into “raw” retention, the original content is stored encrypted at rest in a separate store, reachable only through an explicit, logged action, and purged after the configured retention horizon. What we persist either way is described under “Generated content” below.
- Generated content (what we store). Privacy-safe AI-generated summaries; numeric, boolean, and categorical metadata (for example, counts, response times, coarse amount bands, and one-way hashes of counterparty names); embeddings (vector indexes) of those summaries; knowledge profiles, scores, and audit logs. These derived artifacts are always retained. Encrypted raw content is retained alongside them only for connectors and workspaces on “raw” retention, as described above.
- Usage and device data. IP address, user agent, referring URL, pages viewed, timestamps, error reports, and similar information collected automatically when You use the Service.
- Communications. Messages You send to us, including support requests and feedback.
In short: Braindesk is built to store privacy-safe signals by default. Financial and identity data — counterparty names and exact amounts — are never written to our database in readable form, regardless of configuration. Messaging content is summary-only by default; an organization's administrator may instead opt a connector into encrypted raw retention, in which case original content is stored (never financial/identity data) and employees on that workspace are told so. Each employee consents before any capture and can export or delete their own data at any time.
2. How We Use Information
We use information to:
- provide, operate, maintain, and improve the Service;
- ingest, process, index, and summarize Customer Data so You can search and act on it inside Braindesk;
- authenticate users, enforce role-based access, and protect against fraud, abuse, and security incidents;
- monitor performance, debug errors, and analyze aggregate usage patterns;
- communicate with You about the Service; and
- comply with legal obligations and enforce our agreements.
We do not sell Customer Data. We do not use Customer Data to train foundation models that serve other customers.
3. AI and Sub-processors
Braindesk uses third-party AI and infrastructure providers to deliver the Service. Customer Data may be transmitted to these sub-processors solely to perform tasks on our behalf, under written contracts that restrict use of the data and require appropriate safeguards. Current sub-processors include, without limitation:
- Anthropic — large language model inference for summaries, classification, and agent reasoning.
- Voyage AI — text embeddings used for semantic search.
- Supabase — managed Postgres database and object storage.
- Vercel — application hosting, edge networking, and serverless compute.
- Clerk — user authentication and session management.
- Sentry — error monitoring and performance telemetry.
- Upstash — managed Redis used for job queues and rate limiting.
We will provide reasonable prior notice of material changes to our sub-processor list to customers with an active subscription.
4. Connected Services
When You authorize Braindesk to connect to a Connected Service, You are directing us to access and process Customer Data on Your behalf. We request only the OAuth scopes necessary to provide the relevant feature. You can revoke a connection at any time from Your organization's settings inside Braindesk or from the Connected Service itself. Revoking a connection stops further ingestion; previously ingested data is retained according to Section 6.
Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer, sell, or use Google user data for advertising, and we do not allow humans to read it except (a) with Your explicit consent, (b) for security purposes (such as investigating abuse), (c) to comply with applicable law, or (d) where the data is aggregated and used for internal operations in accordance with the Limited Use requirements.
5. Sharing of Information
We share information only:
- with sub-processors listed in Section 3, under contracts that restrict their use of the data;
- with members of Your own organization, subject to the role-based access controls You configure in Braindesk;
- when required by applicable law, regulation, legal process, or enforceable governmental request;
- to protect the rights, property, or safety of Braindesk, our users, or the public; and
- in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
6. Data Retention and Deletion
We retain Customer Data for as long as Your subscription is active and for a commercially reasonable period thereafter to allow for export or recovery. You may request deletion of Your organization's data at any time by writing to hamzabamboat@gmail.com. We will delete or de-identify Customer Data within a reasonable period after Your request, except where retention is required by law or for the resolution of disputes.
7. Security
Braindesk implements administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These include encryption in transit (TLS) and at rest, scoped OAuth tokens, secret management, principle-of-least-privilege access, audit logging, and regular dependency and vulnerability scanning. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. International Transfers
Braindesk is operated from the United States, and information we collect may be processed in the United States or other countries where our sub-processors operate. By using the Service, You consent to such transfers. Where required by applicable law, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers of personal data.
9. Your Rights
Depending on Your jurisdiction, You may have rights to access, correct, delete, restrict, or object to the processing of Your personal data, and to data portability. You can exercise these rights by contacting us at hamzabamboat@gmail.com. For Customer Data You provided through Your employer, please direct Your request to Your employer, which is the controller of that data; we will support our customers in responding to such requests.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If You believe a child has provided us with personal information, please contact us and we will take steps to delete it.
11. Cookies and Similar Technologies
We use strictly necessary cookies and similar technologies to authenticate users, maintain sessions, and remember preferences. We do not use advertising or cross-site tracking cookies. You can control cookies through Your browser settings; disabling strictly necessary cookies will prevent the Service from functioning correctly.
12. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Last updated” date above. Material changes will be communicated through the Service or to the email associated with Your account.
13. Governing Law
This Privacy Policy is governed by the laws of the State of Delaware, United States of America, without regard to conflict-of-laws principles.
14. Contact
Questions, complaints, or requests regarding this Privacy Policy should be sent to hamzabamboat@gmail.com.