BrainStack Studio Privacy Policy
Effective date: 2026-07-17
Document version (docVersion): 2026-07-17
Operator and privacy contact: BrainStack Ventures, a sole proprietorship based in Colorado, United States; support@brainstackstudio.com
This Policy explains how BrainStack Ventures (“we,” “us,” or “our”) collects, uses, discloses, and retains personal information when operating BrainStack Studio. BrainStack Ventures is currently a sole proprietorship, not an LLC or corporation.
1. Scope and roles
This Policy applies to brainstackstudio.com and BrainStack Studio websites, accounts, tools, dashboards, APIs, Explorer sessions, workspaces, trials, subscriptions, support, and communications that link to it.
For account, billing, site, security, analytics, direct-support, and product-operation data, BrainStack Ventures determines the processing purposes. For Customer Content that a business customer submits solely for its own business workflow, the customer generally determines the business purpose and is responsible for notices, permissions, and instructions. Depending on applicable law and context, BrainStack Ventures may act as a service provider or processor for that Customer Content.
This Policy is not a certification of GDPR, CCPA/CPRA, Colorado Privacy Act, or other statutory compliance. Conditional rights below apply only when the applicable law and thresholds apply.
2. Information we collect
A. Account and identity
- email address, authentication identifier, account and profile metadata, selected role or persona, workspace membership, plan, settings, and attribution;
- login, password-reset, session, access-control, and account-security events; and
- information used to prevent duplicate, fraudulent, internal, test, or ineligible trial and checkout activity.
Supabase handles authentication. Passwords are not displayed to us in readable form.
B. Legal acceptance
Signup, trial, onboarding, and checkout flows may collect the Terms and Privacy docVersion and content hash; acceptance action and time; user and email identifiers; request ID; IP address; and user agent. A stale version may be rejected.
C. Workspace, tool, and output data
Depending on your use, we collect:
- industries, roles, business context, assumptions, scenarios, calculator inputs, process descriptions, prompts, instructions, and requested output formats;
- tool runs, deterministic results, AI-assisted rewrites and drafts, Explorer sessions, saved workspaces, blueprints, decision memos, notes, approvals, exports, and shared links;
- guest-result claim tokens and expiry or claim status;
- API key identifiers and metadata, rate-limit and usage records, and API request context; and
- information from an integration you authorize, such as connection identifiers, scopes, tokens or token metadata, and data needed for the requested integration.
Do not submit specially regulated or unnecessary personal information.
D. Billing and transaction data
Stripe handles full payment-card details. We receive limited billing information such as billing email, plan, price, interval, trial status, payment and subscription status, timestamps, invoice and receipt metadata, and Stripe customer, checkout, subscription, payment, or charge identifiers.
E. Support, contact, lead, and newsletter data
We collect email, name and company information where requested, message content, selected intent, troubleshooting context, attachments, and routing information submitted through contact, support, refund, security, implementation, and lead forms.
When you enter an email and affirmatively select Join or Subscribe in a BSS newsletter form, we collect that email, capture channel, subscription time, and limited attribution. The current newsletter implementation does not necessarily preserve a copy or version of every notice displayed beside the form. Newsletter subscription is separate from account creation and legal assent. You may unsubscribe at any time.
Account email is used for necessary account, trial, security, billing, support, and service messages. Marketing email is based on a separate subscription or other affirmative request; necessary service messages do not require marketing consent.
F. Technical, operational, and security data
This includes IP address, user agent, browser and device characteristics, request IDs, timestamps, route or API activity, response status, rate-limit and fraud signals, authentication events, error and performance information, webhook events, audit data, and service-reliability logs.
Operational usage events may record event name, category, path, tool identifier, limited sanitized metadata, and, for authenticated workflows when supplied, user association. These necessary records can be created when you sign in, run a requested tool, save a session, use an API, start checkout, manage billing, seek support, or trigger a security-sensitive action regardless of optional analytics choice.
G. Optional consent-first visitor and product analytics
Optional browser analytics starts off. An unset, missing, stale-version, or essential-only preference does not authorize optional analytics.
If you select Allow analytics:
- the browser stores bss_cookie_preference=analytics, the current Privacy Policy version, and a recorded-at time for up to one year;
- a corresponding local-storage consent record may be created;
- middleware may create the opaque bss_vid visitor cookie for up to one year;
- visitor-page pings and optional in-browser product events may record bss_vid, page path, sanitized referrer and campaign attribution, event name, time, and limited metadata; and
- server endpoints independently check for a current-version analytics choice before accepting the optional visitor or browser telemetry.
bss_vid is designed not to contain your email, name, payment details, or company data. If you later create an account, subscribe to a newsletter, submit a lead, or start checkout, attribution records may allow us to connect parts of the pseudonymous journey to that interaction using limited identifiers or hashes.
3. Sources
We obtain data:
- directly from you or an authorized user;
- automatically from the browser, device, cookies, local storage, session storage, and use of requested features;
- from Supabase, Stripe, Vercel, Render-hosted services, Resend or other email providers, monitoring providers, and AI providers;
- from an integration you authorize; and
- from a customer, team administrator, or business contact that submits information about you.
4. Purposes and conditional legal bases
We use information to:
- create and secure accounts and workspaces;
- run tools, calculations, sessions, exports, APIs, requested AI features, and integrations;
- administer trials, plans, payments, renewals, cancellation, and refunds;
- record legal acceptance and preferences;
- provide support and respond to privacy or security requests;
- maintain reliability, prevent fraud and abuse, enforce limits, and investigate incidents;
- measure first value, product use, demand, conversion, and service quality;
- improve tools, interfaces, documentation, and operations;
- deliver necessary service email and separately requested marketing;
- create aggregated or de-identified measurement; and
- comply with legal, tax, accounting, dispute, and recordkeeping needs.
Where a law requires a legal basis, depending on context we rely on contract performance or requested pre-contract steps; legal obligations; consent for optional analytics and marketing; and legitimate interests such as security, fraud prevention, support, first-party operational measurement, and improvement where lawful and not overridden. Where consent is required, we do not substitute legitimate interests.
5. AI processing
Deterministic tools generally process displayed inputs under programmed rules. When you request an AI-assisted rewrite, draft, content-factory function, or other provider-backed feature, relevant prompts, inputs, prior output, and context may be sent to Anthropic, OpenAI, Google/Gemini, or a Render-hosted service that routes the request. Provider selection and fallback depend on configuration and availability.
We use provider APIs to produce requested output. We do not intentionally direct providers to use private workspace content to train a public model. Provider-specific storage, abuse monitoring, human review, and model-training treatment depend on the provider offering, account settings, contract, and current terms. This Policy does not promise zero retention or no provider use beyond what those controls actually provide.
Do not send specially regulated, secret, or highly sensitive data to an AI-assisted feature unless you are authorized and have verified the provider path is suitable.
6. Disclosures and subprocessors
We disclose information as reasonably needed to:
- Supabase for database hosting, authentication, authorization support, and storage;
- Stripe for checkout, trials, billing, subscriptions, invoices, refunds, fraud controls, and billing portal;
- Vercel for application hosting, CDN, edge middleware, serverless functions, and related logs;
- Render and Render-hosted BrainOps services for selected backend, event, agent, or orchestration functions;
- Anthropic, OpenAI, and Google/Gemini for requested AI processing;
- Resend or other email providers for transactional, support, alert, and consent-based marketing delivery;
- monitoring, security, logging, and communications providers;
- connected-service providers for an integration you authorize;
- advisers under appropriate confidentiality duties;
- authorities or other parties to comply with law, protect safety, investigate security or fraud, or establish and defend legal rights; and
- a buyer, successor, lender, or adviser in a proposed or completed business transaction, subject to appropriate restrictions.
Providers may process request metadata and content where they operate.
7. No sale or targeted advertising
We do not sell personal information for money, do not operate as a data broker, and do not currently use BSS personal information for third-party targeted advertising.
Optional BSS visitor and product analytics is first-party in the current implementation and begins only after current-version consent. We may retain suppression information after an unsubscribe so we can honor it.
If our sale, targeted-advertising, or legally defined “sharing” practices change, we will update this Policy and provide any control required before the new practice begins.
8. Cookies and consent-first controls
Essential storage
Authentication, security, preference, checkout, and service-continuity cookies or storage may be required. Supabase and Stripe may use their own storage when their services are invoked.
Default state
BSS starts in essential-only mode. Without an affirmative current-version analytics choice, middleware does not mint bss_vid, existing bss_vid is removed when encountered, and the optional visitor-ping and browser telemetry endpoints suppress the event.
Preference records
The current choice stores:
- bss_cookie_preference with analytics or essential_only;
- bss_cookie_preference_version with the current Privacy docVersion;
- bss_cookie_preference_recorded_at with a timestamp; and
- a local-storage copy under bss_telemetry_consent where browser storage permits.
Those preference values may persist for up to one year. A material Privacy version change makes a prior choice stale, and optional analytics remains off until a current-version analytics choice is made.
Analytics identifier
After Allow analytics, middleware may create bss_vid for up to one year. Selecting Use essential only removes it and prevents a replacement while that current-version preference remains. Withdrawal stops future optional events but does not automatically delete server events already collected.
Necessary records remain
The preference does not suppress account, legal-acceptance, transaction, Stripe checkout, requested tool or workspace, API, support, security, fraud, or service-reliability records needed to provide an action you request.
Global Privacy Control
Current code does not separately parse a GPC signal. Because optional analytics begins off, a visitor with no prior choice remains essential-only without relying on GPC. If you previously selected Allow analytics, use https://brainstackstudio.com/cookies to select Use essential only; GPC alone is not represented here as replacing the stored choice.
9. Security
Current controls include HTTPS/TLS, provider-managed encryption, authentication and authorization, row-level and user-scoped access patterns, least-privilege practices, rate limits, payload validation, signed Stripe webhook verification, and security and operational logging.
No system is perfectly secure. We do not guarantee against unauthorized access, data loss, vulnerabilities, provider incidents, or interruption. Protect credentials and API keys, limit user access, and notify us promptly of suspected compromise.
10. Retention
| Information | Current retention period or criterion |
|---|---|
| Account, profile, workspace, subscription, and entitlement records | While the account is active and afterward for the period reasonably needed for account wind-down, legal, security, fraud, accounting, and dispute purposes. |
| Saved Explorer and tool sessions, memos, workspaces, and outputs | Until you delete them through an available control, the account is deleted, or they are removed under an operational retention process, subject to legal and backup exceptions. |
| Guest-result claims and shared links | Until claimed, revoked, deleted, or expired under the feature’s configured expiry. Related security logs may remain longer. |
| API key metadata and usage | Until the key or account is revoked or deleted and afterward as reasonably needed for security, audit, abuse prevention, billing, and dispute purposes. |
| Legal-assent records | As long as reasonably needed to establish the agreement, administer the account or subscription, and establish, exercise, or defend claims. |
| Billing, refund, subscription, tax, and fraud records | For applicable accounting, tax, payment-network, anti-fraud, chargeback, and legal periods. Stripe separately retains its own records. |
| bss_cookie_preference, version, and recorded-at browser values | Up to one year unless cleared or replaced sooner. |
| bss_vid browser cookie | Up to one year after Allow analytics unless removed sooner by essential-only choice or browser action. |
| Optional analytics events | While reasonably needed for product, demand, conversion, reliability, and security measurement; events may later be aggregated or de-identified. The cookie control does not itself erase prior events. |
| Necessary operational and security events | While reasonably needed for product operation, audit, reliability, fraud prevention, incident response, billing, and legal disputes. |
| Newsletter information | Until unsubscribe or deletion, plus a limited suppression record as long as needed to honor the opt-out. |
| Support, contact, lead, refund, and security communications | While needed to resolve and document the request, maintain the relationship, prevent abuse, and meet legal or dispute needs. |
| Provider logs, backups, and AI-provider copies | Under provider settings, backup cycles, incident needs, and provider contracts or terms. Active-data deletion may not immediately remove rotating backups. |
We retain limited exception data when necessary for security, fraud, accounting, tax, payment disputes, legal claims, consent evidence, suppression, or other legal obligations. We will not use exception data for unrelated marketing.
11. Your choices and requests
You may:
- update account information through available settings;
- delete individual Explorer or tool sessions where controls exist;
- revoke API keys and shared links where supported;
- cancel renewal from Account or the Stripe portal;
- unsubscribe from newsletter or other marketing;
- allow or disable optional analytics at https://brainstackstudio.com/cookies; and
- request access, correction, deletion, or portability by emailing support@brainstackstudio.com with “BrainStack Studio Privacy Request.”
We may verify identity through the account, billing email, or other reasonably necessary information. Authorized agents may act where law permits, subject to verification. Requests may be limited for legal exceptions, inability to verify, another person’s privacy, security, trade secrets, or abusive requests. We will explain denials where required.
Do not email passwords, payment-card data, API keys, or unrelated identity documents. We will provide a safer verification method if needed.
12. Jurisdiction-conditional rights; no blanket compliance claim
This section applies only when the law applies to BrainStack Ventures, the requester, and the processing. It does not state that statutory thresholds are met or that BrainStack Ventures is certified.
Colorado and other U.S. states
Where applicable, residents may have rights to confirm processing; access; correct; delete; obtain a portable copy; opt out of sale, targeted advertising, or certain profiling; limit certain sensitive-data uses; appeal; and receive non-discriminatory treatment. BSS does not currently sell personal information or use it for third-party targeted advertising.
Submit a request or appeal to the contact below with “Privacy Request” or “Privacy Appeal.” We will respond in the period required by the applicable law.
The Colorado Privacy Act generally excludes commercial and employment-context data and applies only when statutory thresholds and conditions are met. The California CCPA/CPRA also applies only to a covered business under its definitions and thresholds.
EEA, UK, and similar laws
If the GDPR or a similar law applies, depending on the processing you may have rights to access, correction, erasure, restriction, objection, portability, consent withdrawal, and complaint to a competent authority. Conditional legal bases are in Section 4.
Data is operated principally from the United States and may be transferred to the United States or other provider locations, where protections may differ. Where applicable law requires a transfer safeguard, representative, or other mechanism, we will evaluate and use the required mechanism for that processing. This is not a claim that a particular certification, standard contractual clause, EEA/UK representative, or data-protection officer is currently in place. Contact us for current information before submitting regulated data.
13. Automated processing
BSS uses rules and AI for tool outputs, routing, abuse prevention, limits, and product measurement. BSS outputs are intended for human review. BrainStack Ventures does not use a BSS tool output as the sole basis for its own decision producing a legal or similarly significant effect about an individual.
Do not use BSS as the sole basis for a high-impact decision about a person.
14. Children
BSS is for adults and business users. Account users must be 18 or older. We do not knowingly collect personal information directly from children under 13. Contact us if you believe a child submitted data. Customers must not upload children’s information unless legally authorized and the Service is appropriate.
15. Third-party sites and customer obligations
Third-party sites and connected services have their own policies.
Business customers are responsible for notices, rights requests, permissions, minimization, and retention for Customer Content they control. Contact us if reasonable assistance is needed to locate or delete customer-directed data.
16. Changes and versioning
We may update this Policy for product, provider, legal, or operational changes. A material replacement receives a new docVersion, effective date, and visible-text hash in the legal-document system.
A stale legal-assent version may require review and acceptance in account, trial, or checkout flows. Optional BSS analytics consent is tied to the current Privacy version; when the version changes, optional analytics remains off until a new current-version choice is made.
If a new use requires consent, we will seek it before beginning that use where required.
17. Contact
BrainStack Studio is operated by BrainStack Ventures, a sole proprietorship based in Colorado, United States.
Privacy, access, correction, deletion, portability, consent, appeal, and security requests:
BrainStack Studio support inbox
Suggested subject: “BrainStack Studio Privacy Request,” “BrainStack Studio Privacy Appeal,” or “BrainStack Studio Security Disclosure”
Do not include passwords, payment-card data, or API keys in email.