Brain · a product of Synapse Solutions LLC
Privacy Policy
Last updated: July 27, 2026
1.Who is responsible for your data
Brain is operated by Synapse Solutions LLC, based in Irvine, California, United States. Synapse Solutions LLC is the data controller for personal data processed through the Service. For anything in this policy, contact privacy@synapsesolutions.ltd.
One distinction matters throughout: for data you put into your workspace about other people (for example, mapping your own team or network), you are the controller of that data and we process it on your instructions. You are responsible for having a lawful basis to store it.
2.What we collect
- Account data — name, email, a hashed password (bcrypt; we never store the plaintext), optional company name, and optional two-factor secrets (stored encrypted).
- Workspace content — the maps, nodes, notes, documents, decisions, session transcripts, and anything you or your authorized agents write into the Service.
- History and activity — the audit trail is a product feature: every change records who made it (human or agent), what changed, and when. Live presence (cursors, who is viewing what) is held in memory and not stored durably.
- Integration credentials — if you connect outside tools, tokens are stored encrypted (AES-256) and used only to run the connection you configured.
- Payment data — processed by Stripe; we never see or store full card numbers. We keep billing status and invoices.
- Technical data — IP address, browser type, and request logs used for security, rate-limiting, and debugging.
The Brain domain sets only essential cookies (session authentication and security). We run no advertising trackers and no third-party analytics on brain.synapsesolutions.ltd, which is why you see no cookie banner there.
3.How we use data
- To provide the Service: rendering your workspace, syncing changes live between participants, running automations you configure.
- To provide AI features at your direction: when you ask a question or run an agent, the relevant workspace content is sent to an AI model provider to produce the answer or perform the work. We do not use your content to train foundation models, and our provider agreements do not permit them to.
- To secure the Service: abuse prevention, bot protection (Cloudflare Turnstile on sign-in), rate limiting, audit.
- To bill you, communicate about the Service, and comply with law.
4.Who we share it with (subprocessors)
We share personal data only with the vendors that run the Service, each bound by contract:
- Vercel — application hosting and delivery.
- Neon — managed Postgres database (US region).
- Stripe — payments and invoicing.
- Cloudflare — bot protection (Turnstile) and network services.
- AI model providers — process the content involved in an AI request, only when you invoke an AI feature.
- Google / GitHub — only if you choose to sign in with them.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. If that ever changed we would provide the legally required notice and opt-out first.
5.How long we keep it
Workspace content and history are kept while your account is active — the durable history is the product. If you delete content, workspace, or account, we delete the associated data from production within 30 days, and from encrypted backups on their rotation cycle (up to 90 days). Billing records are kept as long as tax law requires.
6.Security
Data is encrypted in transit (TLS) and at rest at our hosting providers. Passwords are hashed with bcrypt; integration credentials are encrypted with AES-256 before storage; sessions are server-side revocable (signing out kills the session everywhere). Access to production is limited to the people who operate the Service. No system is perfectly secure; if a breach affects your data we will notify you as the law requires.
7.Your rights
Depending on where you live (including under the GDPR and the CCPA/CPRA), you may have the right to access, correct, export, restrict, or delete your personal data, and the right not to be discriminated against for exercising those rights. Two of them are built into the product: you can export your entire workspace (JSON + Markdown) and delete your content or account from inside the Service. For anything else — or if you are in a workspace someone else controls and want data about you corrected or removed — email privacy@synapsesolutions.ltd; we respond within 30 days and may need to verify your identity. EU/UK users may also lodge a complaint with their supervisory authority. California residents: we do not sell or share personal information as defined by the CPRA, and we honor Global Privacy Control signals on our marketing surfaces.
8.International transfers
The Service is operated from the United States and data is stored there. If you use it from elsewhere, your data is transferred to the US; where required we rely on standard contractual clauses with our subprocessors.
9.Children
The Service is not directed to children and may not be used by anyone under 18. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.
10.Changes to this policy
When we change this policy materially we will notify you by email or in-product before the change takes effect. The “Last updated” date above reflects the current version.
11.Contact
Synapse Solutions LLC · Irvine, California, United States · privacy@synapsesolutions.ltd (privacy) · legal@synapsesolutions.ltd (legal). Registered mailing address: 30 N Gould St Ste N, Sheridan, WY 82801, United States. It also appears in every commercial email we send.