How BrainDesk collects, uses, stores, and shares data — including the customer data you connect to it. Last updated: 04 AUG 2026.
Account data you provide at signup: name, work email, organisation, hashed password, and role.
Contact data submitted through this site or by email to support@braindesk.org.
Connected product data you authorise us to access: mailbox contents for the support addresses you connect, chat conversations from the embedded widget, customer records read from the databases you connect, and payment, subscription, and refund records read from the Stripe accounts you connect.
Generated content: AI drafts, reasoning traces, confidence scores, translations, resolution notes, and activity logs.
Operational data: authentication events, request logs, and error reports.
To operate the platform: routing tickets, resolving customer identity across your products, generating and scoring drafts, enforcing SLAs and resolution gates, and producing summaries and alerts.
To improve reliability and quality: monitoring errors, measuring approval and quality metrics, and improving retrieval from your own resolved tickets.
To communicate with you about your account, security, and service changes.
We do not sell personal data, and we do not use your connected customer data to train third-party models beyond what is required to generate a response for you.
We rely on the following categories of sub-processor: Google (Gmail and Google Workspace access), Stripe (billing and refund data), Anthropic (Claude, for the AI pipeline), Atlassian (Jira, where enabled), Slack (alerts and summaries, where enabled), SendGrid (transactional email), our hosting and database providers, and our error-monitoring provider.
A current list with entity names and locations is available on request from support@braindesk.org.
Data is encrypted in transit over HTTPS. OAuth tokens, database credentials, and API keys are encrypted at rest. Passwords are hashed with bcrypt.
Tickets, drafts, and activity logs are retained for the life of your account unless you request deletion. Activity logs are append-only and are retained for audit purposes.
Backups run daily. Access to production data is limited to personnel who require it and is logged.
We use strictly necessary cookies for authentication and session management. Analytics, where enabled, is configured without cross-site tracking.
Depending on your jurisdiction you may have rights to access, correct, export, or delete personal data, and to object to certain processing. Requests can be sent to support@braindesk.org.
Self-service GDPR data export and deletion tooling is on the roadmap; until it ships, requests are handled manually.
When you connect a product, you act as the controller of your customers’ personal data and BrainDesk acts as processor on your instructions. You are responsible for having a lawful basis to share that data with us and for informing your customers as required.
We will post material changes to this policy on this page and update the date above. Continued use after a change constitutes acceptance.
Questions about this document? Write to support@braindesk.org.