Developer Preview
Privacy Policy
Last updated 27 July 2026
This policy is scoped for evaluation and prototyping, not production workloads. Data collection is minimised and the preview environment is routinely wiped.
1. What we collect
| Category | Description |
|---|---|
| Account information | Email addresses you voluntarily provide to create an account or contact us. |
| Usage and technical data | Device types, operating system versions and IP addresses, used for performance monitoring and compliance. |
| AI data | Inputs (your queries) and outputs (generated content), processed to provide the AI features. |
2. Cookies and tracking
The application uses essential first-party cookies only, for authentication and session management. No non-essential tracking cookies — third-party analytics, for example — are deployed, which is why you are not asked for consent under the GDPR.
3. Retention, deletion and transfers
3.1 Routine wiping
Data stored in the preview environment is routinely deleted and may be wiped at any time without notice. Do not treat this environment as a system of record.
3.2 Deletion requests
You may request deletion of your account and your data by contacting us.
3.3 International transfers
Your data may be transferred across borders. Where it is, we rely on safeguards such as Standard Contractual Clauses (SCCs).
4. Data you must not submit
You are strictly forbidden from processing sensitive personal information in this preview, including health data regulated under HIPAA and payment card data regulated under PCI DSS. The preview carries no SOC 2, ISO 27001 or HIPAA certification — see Security below.
5. Security
BrainBucks takes a proactive defence approach, on the understanding that these processes will evolve as the system’s resilience is tested. This section states plainly both what is in place and what is not.
5.1 What is in place
- Zero Trust. The framework operates on a “never trust, always verify” principle.
- Encryption in transit. All traffic between the client and the service is encrypted using TLS.
- Access control. The underlying production systems are restricted to authorised personnel, and all access is logged through Identity and Access Management (IAM) providers.
- Authentication. Single Sign-On through providers such as Google centralises control and avoids storing separate passwords.
5.2 What we ask of you
- Enable multi-factor authentication. This is your primary defence against credential compromise, and we recommend it.
- Manage credentials properly. Use a business password manager. Do not share API keys or login information.
- Disclose responsibly. Report any vulnerability you find privately to our security contact, and hold off on public disclosure until it has been remediated.
5.3 Limitations
These are deliberate constraints of a preview environment, not oversights. Besides the ban on sensitive data in section 4:
- No formal certification. The preview does not carry SOC 2, ISO 27001 or HIPAA certification. If your evaluation depends on any of these, this environment will not satisfy it.
- Incident response. In the event of a security incident we follow a basic plan focused on containment and eradication. Where notification is warranted, it is sent by email or shown in the service.