Privacy Policy
Version 1.0.0 · Effective [DATE]
This is a content brief for legal review. Have a lawyer draft the final version before launch.
What We Collect
- Account information (email, hashed password via Supabase Auth)
- Uploaded creative files and analysis outputs
- OAuth tokens for connected ad accounts and the creative/performance data pulled via those tokens
- Usage data (analysis counts, timestamps)
- Consent records (timestamped, IP-logged, versioned)
What We Do Not Collect
- Ad audience targeting data or customer lists
- Pixel events from your advertising platforms
- Payment or billing information from connected ad accounts
- Actual biometric data — TRIBE v2 outputs are model predictions, not brain scans
How We Use Your Data
We use your data to run brain activation analyses, store results for your review, and produce anonymized aggregate signals for research purposes. We do not sell your data or share individual creative assets with third parties.
Retention
Creative files and analysis results are retained until you delete them or close your account, then purged within 30 days. Anonymized aggregate signals are retained indefinitely — no user linkage exists at the time of writing.
Your Rights
- Access: Download all stored data via Account Settings → Download my data.
- Deletion: Request full account deletion via Account Settings. All personal data is purged within 30 days.
- Opt-out of aggregation: Contact us to opt out of anonymized benchmarking while retaining platform access.
Third-Party Services
Brainiac uses Supabase (database and authentication), Modal (GPU inference — image data is processed transiently and not retained by Modal), and Vercel (hosting).
Contact
Operator: [YOUR COMPANY NAME]. Data requests: [EMAIL]