Privacy policy
Brainwaves AI Pty Ltd
Last updated: September 17, 2026
Security & privacy FAQ
As former marketing and agency professionals, we understand the importance of data privacy, especially when handling client data. That's why we've built Brainwaves to be privacy-first.
What do you mean by privacy-first?
Brainwaves is dedicated to being a privacy-first platform. We prioritise giving you ownership and control of your data:
Data Ownership: You own and control all inputs you provide and all outputs generated by our AI services.
No Training on Your Data: We do not use your data to train our AI models, nor do we allow our partners to use your data for similar purposes.
Confidentiality: Your inputs and generated outputs are available to you and members of your workspace. Authorised Brainwaves platform administrators and support personnel may also access them to operate, secure and support the Services.
Data Isolation: Customer workspace data is stored in isolated databases specific to each customer. Each session operates within its own isolated database, with access for workspace members and authorised Brainwaves platform administrators and support personnel.
No Claims on Your IP: We make no claims to the intellectual property you create using our tools.
What type of user data do you handle?
User identifier data: Name, email, and company for login and authentication.
User inputs (including client data): We only handle what you decide to input. Inputs are used to provide the Services, including generating outputs, with operational access and monitoring as described in this policy.
Outputs: Generated content is available to you and members of your workspace, and to authorised Brainwaves platform administrators and support personnel as described above.
User analytics: We use PostHog to understand and improve use of the product. Analytics include page visits and product interactions linked to your user ID, name and email address, and your workspace ID, name and slug. Message-submission events include session and workspace identifiers and event metadata, but do not include the text of your message or generated output.
All data is secured and encrypted according to this privacy policy.
How do you handle the privacy of my data?
Your inputs and outputs are available to you and your workspace members. Authorised Brainwaves platform administrators and support personnel may also access them to operate, secure and support the Services. We do not use your inputs or outputs to train our models, nor do our partners.
Is my data used to train your models or other AI models?
No, never. We don't use your data to train our models, and neither does OpenAI. When you use Brainwaves, OpenAI models are accessed via API, ensuring enterprise-grade privacy and security. API data is not used for model training under OpenAI's data usage policies.
Do you store my data?
We retain customer data for the duration of your engagement with Brainwaves. Your workspace data, inputs, and outputs are stored so you can access previous work. You may request deletion of your data at any time, and we will delete all associated data promptly upon request.
How is Brainwaves built for security?
Brainwaves runs on Cloudflare's global infrastructure, which maintains SOC 2 Type II and ISO 27001 certifications. We use OpenAI's API for AI processing, with API data excluded from model training. Customer data is encrypted at rest and protected in transit using TLS 1.2 or higher.
How do you keep data secure?
Brainwaves runs on Cloudflare Workers, with workspace and session data stored in Cloudflare Durable Objects and D1 databases. Uploaded files and backups are stored in Cloudflare R2. Workspace and session data is isolated at the database level, keeping customer work separate.
Infrastructure access uses individual accounts and multi-factor authentication. Access is limited by role and need, and production changes are reviewed before deployment.
How do you encrypt data?
Customer data is encrypted at rest using Cloudflare platform encryption and protected in transit using TLS 1.2 or higher.
How do you handle security incidents?
We maintain a documented incident response process covering containment, investigation, remediation and customer notification. If an incident affects your data, we will notify you as required by applicable law and our agreement with you.
What data do you transmit to third parties?
We transmit user data to provide, operate, monitor and improve the platform. We work with a limited number of partners, all of which maintain strong security and privacy standards:
Cloudflare: Infrastructure, compute, databases, file storage, backups, CDN and encryption at rest. SOC 2 Type 2, ISO 27001 compliant.
OpenAI: AI model processing via API. Data is not used for training. SOC 2 Type 2 compliant.
Datadog: Application logging and monitoring. SOC 2 Type 2 compliant.
Langfuse GmbH (Langfuse): AI tracing and performance monitoring in the EU (Ireland). Traces include user, session, workspace and message identifiers, model usage and timing, generated responses, tool inputs and results, and feedback you submit. LLM input-message content is redacted in production; this redaction does not cover those separate trace and feedback fields.
PostHog: Identified product analytics, including user and workspace details and message-submission events as described above, hosted in the EU (Frankfurt, Germany). SOC 2 Type 2 compliant.
Google: Authentication and optional Google Drive integration when you use those features.
Resend: Transactional emails, such as account and service notifications.
We will never sell or share your data with third parties for advertising or AI training purposes.
Our data processing agreement sets out the contractual terms for processing customer data.
Privacy policy
This Privacy Policy outlines our commitment to protect your personal information, explaining how we collect, use, and disclose your information when you use our Services.
1. Our commitment to your privacy
Brainwaves is dedicated to being a privacy-first platform. We prioritise your ownership and control of your data:
Data Ownership: You own and control all inputs you provide and all outputs generated by our AI services.
No Training on Your Data: We do not use your data to train our AI models, nor do we allow our partners to use your data for similar purposes.
Confidentiality: Your inputs and generated outputs are available to you and members of your workspace. Authorised Brainwaves platform administrators and support personnel may also access them to operate, secure and support the Services.
Data Isolation: Customer data is stored in isolated databases. Each workspace and session operates within its own isolated database, with access for authorised workspace members and authorised Brainwaves platform administrators and support personnel.
No Claims on Your IP: We make no claims to the intellectual property you create using our tools.
2. Information we collect
We only collect the data we need, including:
Personal Information: Your name, email address, company name, and any other contact details you provide when you create an Account or contact us.
User Content: Any data or information you input into the Services.
Usage Data: Information that our servers automatically collect when you access the Services, such as IP address, browser type, and usage statistics. Product analytics associate user IDs, names and email addresses with workspace IDs, names and slugs, page visits and product events, including message submissions. Message-submission events contain event metadata, not the text of messages or generated outputs.
Cookies: We use cookies and similar tracking technologies to enhance your experience on our site.
3. How we use your information
We use the information we collect for the following purposes:
Providing, operating, and maintaining our Services.
Improving, personalising, and expanding our Services.
Understanding and analysing how you use our Services.
Developing new products, services, features, and functionality.
Communicating with you for customer service, updates, and marketing purposes.
Preventing fraud and ensuring the security of our Services.
4. Disclosure of your information
We may disclose your personal information in the following circumstances:
To our service providers who perform services on our behalf (infrastructure, AI processing, logging, tracing and analytics).
To comply with legal obligations or respond to lawful requests.
In connection with a business transfer, such as a merger, acquisition, or sale of assets.
Important: We will never sell or share your data with third parties for the purpose of training their AI models or for advertising purposes.
5. User rights and control
You have full control over your data and various rights concerning it, including:
Access: The right to request copies of your personal data.
Correction: The right to request that we correct any inaccurate or incomplete data.
Deletion: The right to request that we erase your personal data.
Restriction: The right to request that we restrict the processing of your personal data.
Objection: The right to object to our processing of your personal data.
Data Portability: The right to request that we transfer the data we have collected to another organisation or directly to you.
To exercise any of these rights, please contact us at support@brain-waves.io. We will respond to your request within one month.
6. GDPR compliance
If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR) regarding your personal data, including the rights listed in Section 5 above.
To exercise any of these rights, please contact us at support@brain-waves.io.
7. CCPA compliance
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA), including:
The right to know what personal information is collected about you.
The right to request deletion of your personal information.
The right to opt-out of the sale of your personal information.
We do not sell personal information. To exercise your rights, please contact us at support@brain-waves.io.
8. Data retention
We retain customer data for the duration of your engagement with Brainwaves. This includes your workspace content, inputs, outputs, and session data. Upon termination of your account or upon your request, we will delete all associated customer data. You may request deletion of specific data or your entire account at any time by contacting support@brain-waves.io.
9. Data security
We implement reasonable administrative, technical, and physical safeguards to protect your data. Customer workspace data is stored in isolated databases, ensuring separation between customers. All data is encrypted at rest and in transit. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
10. Children's information
We do not knowingly collect personal information from children under the age of 13. If you believe we have collected such information, please contact us immediately, and we will take steps to delete that information.
11. Third-party privacy policies
Our Privacy Policy does not apply to other websites or services. We encourage you to review the privacy policies of any third-party services you engage with.
12. Changes to this privacy policy
We may update our Privacy Policy from time to time. When we do, we will notify you by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of the Services after any changes indicates your acceptance of the updated Privacy Policy.
13. Contact us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: support@brain-waves.io