Privacy Policy
Last updated: September 3, 2026
This Privacy Policy ("Policy") describes how brainis ("Company", "we", "our", or "us") collects, uses, discloses, and safeguards information when you access or use our platform and related services (the "Service"). By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with the practices described herein, you must not use the Service.
1. Data Controller & Data Processor Roles
You (the account holder or organization) are the data controller for all personal data relating to candidates, employees, and other individuals whose data you upload, input, or process through the Service ("User Data"). The Company acts solely as a data processor, processing User Data on your behalf and in accordance with your instructions.
As data controller, you bear full responsibility for:
- Determining the lawful basis for processing personal data
- Obtaining all necessary consents and authorizations from data subjects
- Providing required privacy notices to data subjects
- Complying with all applicable data protection and privacy laws, including GDPR, CCPA, and local regulations
- Responding to data subject access requests and rights exercises
The Company is not liable for your failure to comply with your obligations as data controller.
2. Information We Collect
Account Information
When you create an account, we collect your name, email address, and password. If you register on behalf of an organization, we also collect company name, industry, size, and relevant business information.
User Data
Our platform stores data that you and your team enter, including but not limited to candidate information (names, contact details, resumes, interview notes, assessments), employee records, financial data, project information, and communications. You are solely responsible for the content and lawfulness of all User Data.
Usage & Technical Data
We automatically collect information about how you interact with the Service, including pages visited, features used, actions taken, timestamps, device information (browser type, operating system, device identifiers), IP addresses, and referring URLs.
Cookies & Tracking Technologies
We use cookies and similar technologies for authentication, session management, analytics, and performance optimization. We may use both essential cookies (required for Service functionality) and analytics cookies (to understand usage patterns and improve the Service). By using the Service, you consent to our use of cookies as described herein.
Browser storage on brainis.ai (the public website)
The public website writes two first-party storage keys that change what you see, plus the one display preference described at the end of this section. They are never sent anywhere, never shared with a third party, and never joined to an account or to each other. They exist so the site can be less repetitive, not so it can profile you:
brainis:film-watched(local storage) — set to1once you have watched more than 60% of the product film. If it is present, the homepage’s main button offers to continue where the film left off instead of offering you the film again. That is the entire effect: two button labels change. No timestamp, no chapter, and no identifier is stored.brainis:persona(session storage, this browser tab only) — records whether you arrived via a link marked?p=founderor?p=operator. If present, one section of the homepage moves up by one slot. Nothing is added, removed, or reworded; closing the tab discards it.
Both are off by default. If your browser is set to reduced data or data saver, or if first-party storage is unavailable to us — which is what private browsing and blocked storage look like from our side — neither key is written and neither adaptation runs. We do not attempt to detect private browsing by any other means. The website also stores a display preference (brainis:tier-cap) when you use the “reduce effects” control in the footer.
Separately from those keys, the analytics and session-replay providers named in our sub-processor list may set their own storage on the public marketing pages — but only after you consent to analytics cookies. If you decline, the keys above are the only storage the public website uses.
3. How We Use Your Information
We use collected information for the following purposes:
- To provide, operate, maintain, and improve the Service
- To authenticate your identity and manage your account
- To send transactional communications (account verification, password resets, security alerts, service notifications)
- To send marketing communications about features, updates, and promotions (with opt-out available)
- To perform analytics, research, and product development
- To generate aggregated, anonymized, or de-identified data for analytics, benchmarking, and product improvement
- To detect, prevent, and address fraud, security issues, and technical problems
- To provide customer support
- To comply with legal obligations and enforce our Terms of Service
- To protect the rights, property, and safety of the Company, our users, and the public
You acknowledge that aggregated and anonymized data derived from your use of the Service is not considered personal data and may be used by the Company for any lawful business purpose, subject to the one exception stated immediately below: training shared AI models is not covered by this paragraph and requires consent.
AI processing & model training
We do not train on your data without explicit consent. Your workspace’s state and outcomes improve your own company’s recommendations by default. Contribution to shared model improvement is explicit, consented, and de-identified — and the exact policy lives in the Trust Center, not in a marketing page’s fine print. This is the same commitment stated at /security, on /product/memory, and in the AI governance note on /trust; the four are intended to be read as one.
In practice this means: (a) User Data is sent to the model providers listed in our sub-processor list only as scoped context for a request you or your agents initiate, and is not contributed to shared model improvement without the consent described above; (b) no durable credentials for your connected systems are held by those providers; (c) consent to contribute to shared model improvement is given by your organization, recorded, and revocable, and withdrawal takes effect for processing that has not yet occurred; and (d) where consent has been given, the contributed data is de-identified before it is used for that purpose. Model versions ship visibly in the product, predictions are labeled with ranges and a model version, and abstention is treated as an honest output rather than a failure.
4. Data Sharing & Disclosure
We do not sell your personal data to third parties. We may share information in the following circumstances:
- Service Providers: Third-party vendors who assist in operating the Service (hosting, email delivery, analytics, payment processing, customer support). These providers are bound by contractual obligations to protect your data.
- Affiliates & Subsidiaries: Companies within our corporate group for internal business purposes, subject to this Policy.
- Organization Members: Other users within your organization's workspace who have been granted appropriate access permissions.
- Business Transfers: In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred to the acquiring entity. We will notify you of any such transfer.
- Legal Requirements: When required by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
- Aggregated Data: We may share aggregated, anonymized, or de-identified data with third parties for research, analytics, benchmarking, or other lawful purposes. Such data cannot reasonably be used to identify you.
5. Data Security
We implement commercially reasonable administrative, technical, and physical security measures designed to protect your data, including encryption at rest and in transit, role-based access controls, regular security assessments, and secure infrastructure.
However, no method of transmission over the Internet or method of electronic storage is 100% secure. To the maximum extent permitted by applicable law, the Company disclaims liability for any unauthorized access to, alteration, disclosure, or destruction of your data resulting from circumstances beyond our reasonable control, including but not limited to cyberattacks, system failures, or the actions of third parties. You acknowledge that you provide your data at your own risk.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Following account termination or deletion request, we will delete or anonymize your personal data within 90 days, except where retention is necessary for:
- Compliance with legal, regulatory, or reporting obligations
- Resolution of disputes or enforcement of our agreements
- Fraud prevention and security purposes
- Legitimate business interests (including maintaining aggregated analytics)
Aggregated and anonymized data may be retained indefinitely.
7. International Data Transfers
Your data may be processed and stored in any country where we or our service providers maintain facilities. By using the Service, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection standards. We take reasonable steps to ensure that your data is treated securely and in accordance with this Policy regardless of where it is processed.
8. Your Rights
Depending on your jurisdiction, you may have certain rights regarding your personal data, including the right to:
- Access and receive a copy of your personal data
- Rectify inaccurate or incomplete personal data
- Request deletion of your personal data ("right to be forgotten")
- Object to or restrict the processing of your personal data
- Data portability (receive your data in a structured, machine-readable format)
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority
To exercise any of these rights, contact us through our platform. We may require verification of your identity before processing your request. We reserve the right to charge a reasonable administrative fee for manifestly unfounded, excessive, or repetitive requests, or to refuse such requests, to the extent permitted by applicable law. We will respond to valid requests within 30 days, or as required by applicable law.
9. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 18, we will take steps to delete such data. The Company assumes no liability if a minor accesses the Service without parental consent.
10. Third-Party Services
The Service may contain links to or integrations with third-party websites, services, or applications. This Policy does not apply to third-party services, and we are not responsible for their privacy practices, content, or security. We encourage you to review the privacy policies of any third-party services you access through our platform.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice on the Service. Your continued use of the Service after such changes take effect constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically.
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data rights, or have concerns about our data practices, please contact us through our platform.