Draft for review. This is written to be accurate to the product, not to be maximally protective of us — but it has not been reviewed by a lawyer, and the company entity, governing law and data-transfer wording still need filling in before publication.
This policy covers the ModelBrain website, the ModelBrain software you install, and the optional paid services: managed backup, paid networking and the server/team tier. Which parts apply to you depends on which of those you actually use, and for most people the answer is "the software only".
We collect nothing. There is no account, no licence check, no telemetry, no crash reporting and no update ping. Your memories, and the documents you let it read, stay in a folder on your computer. We have no copy, no index, and no way to identify you — so there is also nothing for us to hand over, sell, lose or use for training.
We process an account identifier and email address, billing details through our payment processor (we do not store card numbers), and operational metadata about your snapshots: their size, count and timing. The snapshot contents are encrypted on your computer before upload and we do not hold the key, so we cannot read them. That also means we cannot recover them for you if you lose your key.
This tier is not yet available. When it is, the memories you choose to place on a hosted server are stored in a form the server can search, which means we are technically capable of reading them. We will not read them except where necessary to operate the service, to investigate abuse, or where we are legally compelled — and we will not use them to train any model. Service logs (connection times, request counts, error traces) are retained for a limited operational period.
Memories marked private or local-only are excluded from server eligibility before any placement decision is made. If you cancel, your local memories are unaffected; server-held copies are deleted on the schedule stated in the terms.
Standard server logs (IP address, user agent, requested page) are kept briefly for security and aggregate traffic counts. There are no advertising or cross-site tracking cookies. If you join the early-access list we store your email address and the date you joined, use it only to send the updates described at signup, and delete it on request or when you unsubscribe.
For the paid services we use a payment processor, an email delivery provider, a hosting provider and an object-storage provider. The current list, with what each one receives, is published alongside this policy and updated when it changes. None of them receives your memory contents in readable form from the backup service.
For data we hold — account, billing, email, server-tier content — you can ask for a copy, a correction or deletion, and we will respond within 30 days. For data we never hold, there is nothing to request: you already have it, and deleting your local vault is complete deletion, performed by you, with no involvement from us.
Material changes will be noted in the changelog with a date, not applied silently. Questions and requests: privacy@modelbrain.net.