Trust & transparency

Privacy Policy

Brainlet carries the information you choose to keep across assistants. This page explains what we handle, why, and what controls you have.

Last updated September 17, 2026

Scope

This policy covers the Brainlet website, console, hosted MCP service, and related support. Brainlet can serve a personal workspace or a team workspace. Information placed in a team workspace may be available to its authorized members and their connected assistants.

Information we handle

  • Account and workspace information: sign-in identity, email address, profile details, workspace membership and roles, and authentication records.
  • Content you save: memory, workspace context, files, skills, procedures, and the metadata needed to search, version, and display them.
  • Connections you enable: service configuration, permissions, credentials or OAuth tokens, tool requests, and results needed to perform calls to your connected services.
  • Operations and billing: tool usage, credits, audit events, subscription information, support requests, and limited diagnostic reports. Payment card details are entered with our payment processor, not into Brainlet's own card form.
  • Website activity: request and device information needed to operate and secure the service. On the production website, we may use product analytics and sampled session recordings with text and inputs masked.

How we use it

We use this information to authenticate users, provide the workspace and MCP tools, retrieve saved knowledge, run connections and included capabilities you choose to use, calculate usage and billing, troubleshoot problems, protect the service, and respond to support requests.

When an assistant calls Brainlet, the relevant tool request and response pass through Brainlet. Content returned by a tool is made available to the assistant or client you connected. That client's handling of the result is governed by its own policies.

When information is shared

Brainlet sends data to a third-party service when you enable its connection and invoke a tool through its official API or MCP service. The service receives the information needed for that request and applies its own terms and privacy policy. Included search and generation capabilities also send the prompt or query to the selected provider.

We use service providers for hosting and operations, payment processing (Stripe), email delivery, and production-site analytics (PostHog). If an agent submits a Brainlet defect report, a limited diagnostic may be delivered to our support workflow through Discord; the report text is retained in Brainlet for a limited period. We may also disclose information when required by law or to protect the service and its users.

Public file links are accessible to anyone who has the URL until they expire or are revoked. Only create or share such links for content you intend to make accessible in that way.

Retention

Saved workspace content remains available while it is kept in the workspace. You can remove individual memories, files, skills, and connections using the available controls. Audit history is retained for the period shown by the workspace's plan. Limited agent defect reports are pruned after 30 days. Billing and security records may be retained longer when needed for accounting, fraud prevention, or legal obligations; backup copies, where used, may take additional time to expire.

For account or workspace removal requests, contact us using the address below. We will explain the available steps and any records that must be retained.

Your controls

  • Choose which connections and included capabilities to enable, and disconnect services you no longer want Brainlet to access.
  • Review and edit workspace context, memories, files, and skills in the console, subject to workspace permissions.
  • Ask us for help accessing, correcting, exporting, or removing your information.

Security

Brainlet uses workspace access controls and protects stored connection credentials. No online service can guarantee absolute security. Please avoid placing passwords or other secrets in memory, files, support messages, or bug reports unless the feature explicitly requires them.

Changes and contact

We may update this policy as Brainlet changes. The date above identifies the current version. For privacy questions or data requests, email joven@joinbrainlet.com. See our support page for help.