Privacy Policy
At a glance
- BrainMocker is local-first. Your projects, tasks, chats, agent sessions, memory, and connected-service credentials live on your computer. We cannot see them.
- The desktop app contains no analytics or telemetry. It contacts our servers only to activate, validate, or manage your license.
- We collect what a small software business needs to sell software: your email, purchase records, license activations, and basic first-party website analytics.
- We never sell personal information, and we don't use advertising trackers.
This policy explains how BrainMocker ("we", "us"), based in Toronto, Ontario, Canada, collects, uses, discloses, and protects personal information when you visit brainmocker.com, purchase a license, or use the BrainMocker desktop application (the "App"). It is written to meet the requirements of Canada's PIPEDA, Quebec's Law 25, the EU and UK GDPR, and applicable US state laws.
1. What we collect, and why
Website analytics
Our website uses a minimal, first-party analytics system that we host ourselves (on Supabase). It records
page visits and clicks together with a randomly generated visitor ID (stored in your browser's
localStorage) and session ID (stored in sessionStorage). These IDs are random —
they are not derived from, or linked to, your name, email, or any account. We use this data solely to
understand how the site is used. We do not use Google Analytics, advertising pixels, or any cross-site
tracking.
Email signups
If you subscribe to updates, request early access, or provide your email to download the App, we store your email address, the signup source, and a timestamp. We use it to send you the updates you asked for. Every marketing email we send includes an unsubscribe link, and you can opt out at any time by using it or by emailing us.
Purchases
Payments are processed by Stripe. When you buy a license, Stripe collects your payment card details, name, email, and billing information directly — we never see or store your card number. From Stripe, we receive and store: your email address, your license key, Stripe's customer / checkout-session / payment identifiers, and the purchase timestamp. We use these to deliver your license key, handle refunds and disputes, provide support, and meet tax and accounting obligations. Stripe's handling of your data is described in the Stripe Privacy Policy.
License activation and management
When you activate the App with a license key, the App sends our license service:
- your license key;
- a one-way hashed device identifier (a SHA-256 hash derived from your computer's hostname, username, and home directory — we receive only the hash, not those values);
- a device label (your computer's hostname, shown back to you in the App's device list); and
- the App version.
We store activation and deactivation timestamps and keep an append-only log of license events (purchase, activation, recovery, refund) for security, fraud prevention, and support. We use this data to enforce the per-license device limit and to let you view, rename, and deactivate your devices. If you use license recovery, we look up your email and re-send your key to it.
Support
If you email us, we keep the correspondence so we can help you and improve the product.
2. What we do not collect
The App is local-first by design. The following never reaches our servers:
- your projects, tasks, boards, workflows, chat threads, plans, and agent output;
- files in your workspaces and anything your agents read or write;
- memory, skills, rules, and configuration;
- API keys and credentials for AI providers and connected apps (these are stored on your machine);
- usage analytics, crash reports, or telemetry from the App — there is none.
Third-party AI providers and connected apps. BrainMocker orchestrates AI agents using your own accounts — for example Claude Code (Anthropic), and any optional providers or connectors (MCP servers) you choose to connect, such as GitHub or Google. When you use them, your prompts and content go directly from your computer to those providers, under your agreements with them. We are not a party to that traffic, we do not proxy it, and we cannot access it. Review those providers' privacy policies for how they handle your data.
Remote access. If you enable BrainMocker's remote access feature (for example, to chat with your Chief of Staff from your phone), connections are served by the App running on your own computer — directly on your network, or through a tunnel provider you configure. We do not operate, proxy, or store that traffic.
3. Legal bases (EU/UK GDPR)
| Processing | Legal basis |
|---|---|
| Selling and delivering licenses; activation; device management; key recovery; support | Performance of a contract (Art. 6(1)(b)) |
| First-party website analytics; license-abuse and fraud prevention; audit logging | Legitimate interests (Art. 6(1)(f)) — running and protecting a small software business |
| Newsletter and product-update emails | Consent (Art. 6(1)(a)) — withdraw at any time via the unsubscribe link |
| Retaining purchase records | Legal obligation (Art. 6(1)(c)) — tax and accounting law |
4. Who we share data with
We never sell personal information, and we do not share it with advertisers or data brokers. We share it only with the service providers that run our infrastructure, each bound by its own data-processing terms:
- Stripe — payment processing (privacy policy);
- Supabase — database and API hosting for licenses, signups, and site analytics (privacy policy);
- Amazon Web Services (SES) — sending license and recovery emails (privacy notice);
- website hosting and content-delivery providers, which may log IP addresses as part of normal operation.
We may also disclose personal information if required by law, or to protect our rights, users, or the public, and in connection with a business transfer (in which case this policy would continue to apply to data collected under it).
5. International transfers
We are based in Canada, and our service providers may process data in the United States or other countries. Where data of EU/UK residents is transferred, we rely on our providers' safeguards, including the EU–U.S. Data Privacy Framework and Standard Contractual Clauses. Canada holds an EU adequacy decision for data handled under PIPEDA.
6. How long we keep data
- Purchase and license records — for as long as your license is valid (lifetime licenses: for the life of the product), and as required for tax and accounting purposes (typically seven years in Canada).
- Activation records and license event logs — while the license is valid, for security and support.
- Email signups — until you unsubscribe or ask us to delete them.
- Website analytics — reviewed periodically and deleted when no longer needed for understanding site usage.
- Support correspondence — as long as reasonably needed to assist you and improve the product.
7. Your rights
Depending on where you live, you have the right to:
- access the personal information we hold about you and receive a copy (portability);
- correct inaccurate information;
- delete your information (subject to records we must keep by law, such as purchase records);
- object to or restrict processing based on legitimate interests;
- withdraw consent at any time (for example, unsubscribe from emails);
- complain to a supervisory authority.
To exercise any of these rights, email contact@brainmocker.com. We will respond within 30 days. We will never discriminate against you for exercising a privacy right.
Canada: you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). Quebec: the Commission d'accès à l'information (cai.gouv.qc.ca). EU: your local data protection authority. UK: the ICO (ico.org.uk).
California residents: we do not sell or share personal information as defined by the CCPA/CPRA, and we do not use it for cross-context behavioral advertising. Because our analytics are strictly first-party, our site does not respond differently to "Do Not Track" or Global Privacy Control signals — there is no third-party tracking to opt out of.
8. Cookies and local storage
Our own site sets no tracking cookies. We use browser storage for:
- theme preference (light/dark) — functional, stored locally;
- a random visitor ID and session ID — first-party analytics, as described above.
Stripe sets cookies on its own checkout pages for payment processing and fraud prevention. You can clear our identifiers at any time by clearing your browser's site data for brainmocker.com.
9. Security
All traffic to our website and services is encrypted with TLS. License and purchase data is stored in a database with row-level security enabled and no public access — it is reachable only through our server-side functions. Device identifiers are stored only as one-way hashes. Access to production systems is limited to the people who operate BrainMocker.
No system is perfectly secure. If a breach occurs that creates a real risk of significant harm, we will notify affected users and the relevant authorities as required by law.
10. Children
BrainMocker is a professional tool and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the product evolves. We will post the updated version here with a new effective date, and for material changes we will provide notice on the website or by email to license holders. Continued use after a change takes effect constitutes acceptance of the updated policy.
12. Contact
BrainMocker — Toronto, Ontario, Canada
Privacy contact (and person responsible for the protection of personal information under Quebec Law 25) is
reachable at contact@brainmocker.com.