Privacy Policy
Last updated: April 2026
BrainAI Team ("we," "us," or "our") values your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit brainai.team (the "Site") or use our agentic team building and AI agent services (the "Services").
By accessing the Site or using our Services, you agree to this Privacy Policy. If you do not agree, please do not use our Site or Services.
1. Information We Collect
1.1 Information You Provide
- Account details (name, email address, company name) when you register or request a quote
- Project requirements, product requirement documents (PRDs), and attachments you submit through our platform
- Messages and files exchanged through our messaging system
- Payment and billing information processed through our third-party payment providers
- Consultation booking details (preferred dates, topics, notes)
- Referral information if you participate in our affiliate program
1.2 Information Collected Automatically
- Device and browser information (browser type, operating system, device identifiers)
- IP address, approximate geographic location, and referring URLs
- Pages visited, time spent on pages, clicks, and navigation patterns
- Cookies and similar tracking technologies (see Section 5)
1.3 Information from Third Parties
- Authentication data from Firebase when you sign in via magic link
- Analytics data from third-party providers (e.g., Google Analytics)
- Payment confirmation from payment processors (we do not store full card numbers)
2. How We Use Your Information
We use your information for the following purposes:
- Provide, maintain, and improve our agentic team building services
- Process quote requests, proposals, and project delivery
- Communicate with you about your projects, consultations, and account
- Send service-related notifications (project updates, status changes, billing)
- Administer our referral and affiliate program
- Analyze usage patterns to improve the platform experience
- Detect, prevent, and respond to fraud, abuse, or security incidents
- Comply with legal obligations and enforce our Terms of Service
3. How We Share Your Information
We do not sell your personal information. We may share it in the following circumstances:
- Service providers: Third-party vendors that help us operate our platform (hosting, analytics, payment processing, email delivery)
- AI service providers: We use third-party AI APIs (e.g., Anthropic, OpenAI) to power our agent services. Data shared with these providers is governed by their respective privacy policies and data processing agreements.
- Affiliated companies: BrainAI Team and its parent company or subsidiaries, subject to this Privacy Policy
- Legal requirements: When required by law, subpoena, or government request, or to protect our rights, property, or safety
- Business transfers: In connection with a merger, acquisition, or sale of all or part of our assets
- With your consent: When you explicitly authorize us to share your information
4. Data Retention
We retain your personal information for as long as your account is active or as needed to provide our Services. After account deletion, we may retain certain data for up to 90 days for backup and compliance purposes. Anonymized or aggregated data that cannot identify you may be retained indefinitely for analytics and service improvement.
Project-related data (quotes, deliverables, messages) is retained for the duration of the business relationship and a reasonable period afterward for record-keeping and dispute resolution.
5. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Essential cookies: Maintain your session, authenticate your identity, and provide CSRF protection. These are required for the platform to function.
- Analytics cookies: Understand how visitors use our Site (e.g., pages visited, time on site). We use Google Analytics and similar tools.
- Preference cookies: Remember your settings (e.g., dark mode, language preferences)
You can control cookies through your browser settings. Disabling essential cookies may prevent you from using certain features of the platform.
6. Data Security
We implement industry-standard security measures to protect your information, including encrypted sessions (HTTPS), HttpOnly session cookies, CSRF protection, parameterized database queries, and rate limiting. However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
7.1 General Rights
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data, subject to legal retention requirements
- Portability: Request your data in a structured, machine-readable format
- Opt-out: Unsubscribe from marketing communications at any time
7.2 European Economic Area (GDPR)
If you are in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation:
- Right to restrict processing of your personal data
- Right to object to processing based on legitimate interests
- Right to withdraw consent at any time (where consent is the legal basis)
- Right to lodge a complaint with your local data protection authority
Our legal bases for processing include: performance of a contract (providing Services you requested), legitimate interests (improving our platform, preventing fraud), consent (marketing communications), and legal obligations.
7.3 California Residents (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to know what personal information we collect, use, disclose, and sell
- Right to delete your personal information
- Right to opt out of the sale or sharing of your personal information (we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
- Right to correct inaccurate personal information
- Right to limit the use of sensitive personal information
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or within the timeframe required by applicable law).
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. We take appropriate safeguards to ensure your information remains protected in accordance with this Privacy Policy, including standard contractual clauses and data processing agreements with our service providers.
9. Third-Party Links
Our Site may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before providing any personal information.
10. Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at [email protected].
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you via email or a prominent notice on our Site. Your continued use of the Site or Services after any changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or want to exercise your data rights, contact us: