1. Introduction and Scope
This Privacy Policy explains how Brainpercent, LLC ("Brainpercent," "we," "us," or "our"), a Delaware limited liability company, collects, uses, shares, and protects personal information when you use https://brainpercent.app and the related Brainpercent platform (the "Service").
This Policy applies to (a) visitors to our public website, (b) registered users of the Service across all paid and free tiers, (c) participants in our affiliate program, and (d) anyone who contacts us. It does not apply to third-party websites you reach through links in content you generate. By using the Service you confirm you have read this Policy.
2. Information We Collect
We collect only what we need to operate, secure, and improve the Service.
Information you provide directly
- Account data: email address, name (optional), profile preferences, language and region. Supabase Authentication with magic-link email, Google OAuth, and Facebook OAuth. From Google or Facebook sign-in we receive your email, basic profile, and that provider's account ID — nothing more from the sign-in grant.
- Connected integrations: if you connect Google Calendar, Google Meet, Search Console, or Google reviews, we receive the events, properties, or review data those APIs return, plus OAuth tokens we store encrypted. That is a separate grant from sign-in.
- Billing data: when you subscribe or buy credit packs, Stripe collects payment method, billing address, and tax info. We never see or store your full card number. We receive a Stripe customer ID, last four digits, card brand, expiration, and invoice records.
- Content you generate: URLs you submit, prompts, brand assets, and AI-generated outputs (articles, social posts, images, videos, podcasts). Stored so you can return to them.
- Communications: support tickets, emails to edward@brainpercent.com, in-app chat messages.
- Optional investor voice assistant: if you use the pitch or admin voice assistant, we receive your microphone audio and the transcript. Vapi orchestrates that session. Deepgram transcribes via Vapi. We have no direct Deepgram or OpenAI API for this path.
- Affiliate data: Stripe Connect Express account ID, payout history, referrals attributed to you, tax forms collected by Stripe.
Information collected automatically
- Server logs: IP, user agent, referrer, request path, response status, timing. Kept 30 days then deleted.
- Device + usage data: approximate location (country/region from IP), pages visited, features used, errors.
- Cookies and similar technologies: see Section 8.
AI-pipeline metadata
When you use the Service we record which AI providers handled each step (Anthropic for text; fal.ai for image, audio, and video; limited leftover GoAPI toolkit jobs), token counts, and credit deductions for billing reconciliation.
We do not intentionally collect special-category personal data (health, biometric, religious, political). Please do not paste such data into prompts.
3. How We Use Information
- Service delivery: generate content, store projects, publish to social platforms you connect, and manage Calendar and Meet events you connect.
- AI processing: send prompts and context to Anthropic (text) and fal.ai (image, audio, video) to produce outputs (Section 4). A small leftover toolkit still reaches GoAPI (face swap, background remove, podcast lipsync/avatar, jobs already in flight). The optional investor voice assistant sends audio and transcripts to Vapi; Deepgram transcribes via Vapi.
- Billing: process subscriptions and credit packs via Stripe, send invoices, prevent fraud, handle disputes. Stripe is also an independent controller for its own fraud, AML, and product purposes — not merely our processor.
- Customer support: respond to requests and troubleshoot.
- Security + fraud prevention: rate-limiting, abuse detection, account-takeover detection.
- Service improvement: aggregated, de-identified analytics of feature usage.
- Marketing: with your explicit opt-in consent. Every marketing email has one-click unsubscribe. Transactional emails are sent without separate consent because they are necessary for the contract.
Legal bases (GDPR Art. 6): contract performance for service delivery and billing; legitimate interests for security and product improvement; consent for marketing; legal obligation for tax records and law-enforcement requests.
4. How We Share Information
We do not sell personal information and have not done so in the prior 12 months. We share data with the vendors in the categories below. Most are processors bound by a data-processing agreement. Stripe is also an independent controller for its own fraud, AML, and product purposes.
| Category | Examples | Data shared |
|---|---|---|
| Payment & billing | Payment processors, payout services | Name, email, payment method, billing address, transactions |
| Cloud infrastructure | Database, storage, CDN, edge delivery | Account data, content, server logs |
| AI model providers | Large language model and image/video generation providers | Prompts, selected context, brand assets |
| Social publishing | GetLate / Zernio and the social platforms you connect | Generated content, scheduling instructions, connected account tokens |
| Communications | Transactional and marketing email providers | Email address, name, message content |
| Analytics & operations | Error tracking, session analytics, SEO tooling, Google Calendar / Search Console / reviews you connect | Usage events, anonymized session data, topic queries, connected calendar events and review data |
| Sales and outreach | Apollo.io, ReverseContact | Prospect names, emails, headlines, employer, and LinkedIn profile data used for outreach and project setup |
| User-configured integrations | Make.com, WordPress (only if you connect them) | Content payloads you choose to send to those destinations |
| Voice assistant | Vapi; Deepgram via Vapi | Microphone audio and transcripts if you use the optional investor voice assistant |
A full list of our current subprocessors, including specific vendor names, is available at /legal/subprocessors. We update that page when processors change and give 30 days' notice of material new subprocessors by email.
We may also disclose information (a) to comply with law, valid subpoena, or court order; (b) to protect rights, safety, or property; (c) in connection with a merger, acquisition, or asset sale, in which case we will give 30 days' notice.
5. International Data Transfers
Brainpercent, LLC operates from the United States. Our primary database and storage live in the European Union (Supabase EU region). When you use the Service your data may be transferred to: the United States (Stripe, Anthropic, fal.ai, leftover GoAPI toolkit, Cloudinary, Vapi, Deepgram via Vapi, GetLate / Zernio, Meta/Facebook, Apollo.io, Resend, SendGrid, Discord, Inngest, Sentry, Google, Microsoft, Vercel control plane); the European Union (ReverseContact, Browserless.io, DataForSEO, and Make.com when you use those paths); and other regions (Vercel edge nodes; Telegram; WordPress if you connect it). Named vendors live at /legal/subprocessors.
For transfers from the European Economic Area, United Kingdom, and Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs) (Module Two — Controller to Processor) executed with each US-based processor. Where applicable we also rely on the EU-US Data Privacy Framework. You may request copies by emailing edward@brainpercent.com.
6. Data Retention
- Account profile and authentication records: while account is active + 90 days after deletion
- User-generated content and assets: until you delete the item or your account
- Server logs (IP, request paths): 30 days
- Billing and payment records (Stripe): 7 years after final transaction (US tax law)
- Email logs: 12 months
- Support tickets: 24 months
- Affiliate payout records: 7 years (US tax law / 1099-NEC reporting)
- Marketing consent records: until withdrawal + 3 years
When you delete your account we erase content within 90 days. Stripe records, tax records, and any data subject to active legal hold are retained for the periods above and then permanently deleted.
7. Your Rights
European Economic Area, United Kingdom, Switzerland (GDPR / UK GDPR). You have the right to:
- access your data (Art. 15);
- rectify inaccurate data (Art. 16);
- erase your data — "right to be forgotten" (Art. 17);
- restrict processing (Art. 18);
- portability — machine-readable export (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw consent at any time without affecting prior lawful processing (Art. 7(3));
- lodge a complaint with your supervisory authority.
California (CCPA/CPRA). Right to know, delete, correct, limit use of sensitive personal information, and opt out of "sale" or "sharing" — Brainpercent does not sell or share personal information for cross-context behavioral advertising under §1798.140(ad).
Israel (Privacy Protection Law, 5741-1981). Right to inspect and correct information we hold about you and to request deletion.
How to exercise rights. Email edward@brainpercent.com from your account email or use the in-app data-export and account-deletion controls. We respond within 30 days (GDPR) or 45 days (CCPA). Identity verification may be required.
8. Cookies and Tracking
We use a small set of cookies, each with a clear purpose:
| Cookie | Type | Purpose | Retention |
|---|---|---|---|
sb-*-auth-token | Strictly necessary | Supabase session | Session / 7 days |
bp_anon_id | Analytics | Anonymous visitor id, linked on signup | 365 days |
bp_utm | Functional | First-touch campaign attribution | 30 days |
bp_aff_click | Functional | Affiliate referral attribution (HMAC-signed) | 60 days |
ref_source | Functional | Source attribution (e.g. Product Hunt) | 7 days |
_ga, _ga_* | Analytics | Google Analytics (IP-anonymized) | 24 months |
_clck, _clsk | Analytics | Microsoft Clarity session replay | 12 months |
locale-preference | Strictly necessary | Remembers the language you chose for the site and the product. | 365 days |
landing-theme / chat-theme | Strictly necessary | Remembers light or dark appearance on the public site and in the product. | 365 days |
intent_url | Strictly necessary | The website URL you typed before signing in, so we can start that workspace. | 7 days |
onboarding_visitor_name | Strictly necessary | Optional first name collected during onboarding so we can greet you. | 30 days |
cookie-consent | Strictly necessary | Remembers that you saw the cookie banner and the analytics choice you made. | 365 days |
bp_consent | Strictly necessary | Short-lived signed ticket proving you checked age and Terms on the OAuth overlay. | 10 minutes |
bp_discord_oauth_state | Strictly necessary | CSRF state for the Discord account-link flow. Dropped after the callback. | 10 minutes |
gcal_oauth_state | Strictly necessary | CSRF state for connecting Google Calendar. Dropped after the callback. | 10 minutes |
retainer_session_* | Strictly necessary | Short-lived unlock session for a retainer portal link. Bound to that deliverable only. | 2 hours |
Strictly-necessary cookies do not require consent (GDPR Recital 30). Analytics cookies are gated on your explicit consent: Google Analytics 4 loads with Google Consent Mode defaults set to denied, so no analytics cookies or measurement identifiers are set until you grant consent through the cookie banner. Microsoft Clarity loads only after you accept analytics cookies in the banner. You can review or change your choices at any time via the Cookie Preferences control in the site footer. We also set essential preference cookies that do not require consent: locale-preference, landing-theme, chat-theme, intent_url, onboarding_visitor_name, and cookie-consent (remembers the banner choice). A short-lived bp_consent ticket is set only during OAuth signup. Discord account-link uses a 10-minute bp_discord_oauth_state CSRF cookie. Connecting Calendar sets a 10-minute gcal_oauth_state CSRF cookie. Unlocking a retainer portal link sets retainer_session_* for two hours. For full details of each cookie and consent category, see our Cookie Policy. To opt out of Google Analytics specifically, you can also install the Google Analytics opt-out browser add-on.
9. AI and Generated Content
Your prompts and the outputs we generate are stored in your account so you can return to them. We never use your private prompts or outputs to train any AI model of ours, and our agreements and API configurations with our AI providers prohibit and disable training on customer data. You retain ownership of the outputs you create (subject to provider terms; see our Terms of Service).
If you publish content publicly (for example, when you direct the platform to publish to your connected social accounts), that content becomes public on those platforms under their terms.
fal.ai media URLs. fal is our live image, audio, and video engine. By default, files fal hosts are publicly reachable by anyone who has the URL. We copy finished media into our own storage for product use. Until that copy exists, a leaked fal URL is a public file. Do not upload unreleased photography if that window is unacceptable for that asset.
Anthropic retention. Prompts sent to Anthropic are processed under Anthropic's terms. We do not promise ad-hoc deletion of prompts already received by Anthropic. Flagged content may be retained by Anthropic longer than our own account-deletion window.
10. Children's Privacy
The Service is not directed to anyone under 18 years of age. We do not knowingly collect personal information from, market to, or solicit personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we delete it. We take reasonable steps to screen for age compliance at registration via age affirmation at signup.
If you are a parent or guardian and believe your child has registered without authorization, contact edward@brainpercent.com and we will delete the account and all associated data within 72 hours of verification. We do not require verifiable parental consent mechanisms under COPPA because the Service is not directed at children under 13.
11. Security
- Encryption in transit: TLS 1.2+ on all endpoints.
- Encryption at rest: AES-256 for Supabase Postgres and Storage.
- Database isolation: Postgres Row Level Security (RLS) enforces per-user access on every table.
- Payment security: Stripe is PCI DSS Level 1 certified; we never touch raw card data.
- Access controls: least-privilege admin access, no shared accounts, audit logs on production data.
- Secrets management: Vercel and Supabase encrypted environment variables.
- Monitoring: Sentry error tracking and Vercel runtime logs.
No system is perfectly secure. If a breach affects your data we will notify you within 72 hours where required by law (GDPR Art. 33-34; US state breach laws).
12. Changes to This Policy
We may update this Policy. For material changes we will notify registered users by email and post a banner on the site at least 30 days before the change takes effect. Non-material clarifications take effect on posting.
13. Contact
Brainpercent, LLC (Delaware, USA)
Founder & CEO: Edward Ilin
Email: edward@brainpercent.com
General contact: t.me/brainpercent
For data-protection requests, write "Privacy Request" in the subject line. You may always lodge a complaint with your local supervisory authority (in the EEA, see edpb.europa.eu).