Legal
Privacy Policy
Brainfeather stores facts extracted from your coding sessions. That is unusually sensitive data, so this policy is specific about what is kept and what is not.
Last updated 8 August 2026
Who we are
Brainfeather (“Brainfeather”, “we”, “us”) provides a long-term memory layer for AI coding agents. The data controller is [legal entity name], registered at [registered address]. You can reach us at getbrainfeather@gmail.com.
Brainfeather is in early development and is not yet generally available. Where this policy describes product behaviour, it describes the service as currently built.
Information you give us
- Account
- Email address, name, and a password. Passwords are handled by our authentication provider and we never receive or store them in readable form.
- Waitlist
- If you use the early-access form, your email address, the date and time you submitted it, and which part of the site you submitted it from. This is recorded in a Google Sheet we control (see section 06) and used only to contact you about access.
- Support
- Anything you put in an email to us, including the message body and any attachments.
- Billing
- Not applicable yet — Brainfeather takes no payments at this stage. If that changes, payment details will be handled by [payment processor] and never touch our servers.
What we store from your sessions
This is the part worth reading closely. Brainfeather works by recording durable facts from your work and handing them back to your agent later, which means the store can contain material about your projects.
- Memories
- A title and body of text for each recorded fact, plus a category, tags, the client it came from, and a vector embedding used for search. The body is written from your sessions and can therefore include source code, file paths, architecture decisions, dependency choices and similar project detail.
- Context rules
- Rules you define to shape what gets recalled, including the condition and context text you write.
- Patterns
- Observed repetition — recurring tasks, frequent questions, workflow habits — with a frequency count and when it was last seen.
- Decisions
- For team workspaces: a title, the surrounding context, the outcome, and which members took part.
- Teams
- Workspace names, ownership, and member roles.
- API keys
- A generated key per integration, its label, and when it was last used.
- Usage
- A count of stored memories and a last-active timestamp on your account.
What we do not do
- No analytics or tracking. This website runs no analytics, no advertising pixels, and no third-party tracking scripts. It sets no cookies for analytics or advertising.
- No selling. We do not sell or rent your personal information, and we do not share it with advertisers.
- No training on your content. We do not use your stored memories to train machine-learning models.
How we use your information
- To run the service: storing your memories and returning them to the clients you connect.
- To authenticate you and keep your account secure.
- To reply when you contact us.
- To diagnose faults and keep the service reliable.
- To tell you about material changes to the service or to this policy.
Legal bases
If you are in the UK or EEA, we rely on performance of a contract for running the service, our legitimate interests for security and troubleshooting, and your consent where consent is what applies — for example a waitlist email, which you can withdraw at any time. Our supervisory authority is [lead supervisory authority].
Who processes your data
We keep the list of subprocessors short, and we do not add one without a reason.
- Appwrite
- Backend platform. Hosts authentication and the databases holding the records described in section 03. Data is stored in its [Appwrite region — Singapore unless you chose otherwise] cluster.
- Vercel
- Serves this website from a global edge network, which means a page request is answered from a location near you rather than from one country. Vercel processes request metadata (IP address, user agent) to route and serve traffic.
- Early-access sign-ups are written to a Google Sheet via Google Apps Script, and our contact address is a Gmail account. Google therefore processes the email address you submit and anything you send us by email. Google's own privacy policy applies to that processing.
We may also disclose information where the law requires it, or to establish or defend legal claims. If we are ever involved in a merger or acquisition, we will tell you before your information moves to a new controller.
How long we keep it
- Account records: for as long as your account is open.
- Early-access sign-ups: until access opens and we've contacted you, or until you ask to be removed — whichever comes first. Ask by replying to any email from us, or by writing to the address below.
- Memories, rules, patterns and decisions: until you delete them, or until you close your account.
- API keys: until you revoke them.
- After you close your account we delete or irreversibly anonymise your data within [retention window, e.g. 30 days], except where we must keep something to meet a legal obligation.
- Backups may hold deleted content for a short additional period before they roll over.
Security
Traffic to Brainfeather is served over HTTPS. Access to stored records is scoped per account, and authentication is handled by our backend provider rather than rolled by hand.
If you find a vulnerability, please report it to getbrainfeather@gmail.com rather than disclosing it publicly, and give us a reasonable window to fix it.
Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to how we use it, take it elsewhere in a portable format, and withdraw consent you previously gave. You also have the right to complain to your data protection regulator.
To exercise any of these, email getbrainfeather@gmail.com. We will respond within one month. We will not charge you for a reasonable request, and we will not treat you differently for making one.
International transfers
Your information may be processed in a country other than your own, including [country]. Where we move personal data out of the UK or EEA we rely on [transfer mechanism, e.g. UK IDTA / EU Standard Contractual Clauses].
Children
Brainfeather is a developer tool and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
When this policy changes we will update the date at the top. For changes that materially affect your rights we will give notice by email or in the product before they take effect.
Contact
Questions, requests, or complaints: getbrainfeather@gmail.com. You can also use the contact page.
See also our Terms of Service.