Privacy

What brunn.ai collects, and what happens to it.

Last updated 14 September 2026. This notice covers the website, verified waitlist, and hosted customer workspaces.

If you visit the site

We use Plausible for aggregate pageview analytics on the public site and in the signed-in web app. We send page categories, referring sites and whether a visit is signed in or signed out—not account identifiers, task or document names, workspace content, search text, or URL query parameters. Plausible derives approximate location and browser/device statistics from requests without tracking cookies. We do not track form contents, downloads or individual link clicks.

Your own browser can be excluded: turn analytics off for this browser. This stores a local opt-out preference, not a tracking identifier. It applies after signing out too; repeat it in each browser or after clearing site data.

Our hosting provider (Railway) and our edge network (Cloudflare) keep ordinary request logs, including IP address, user agent and the pages requested, for their standard retention periods. Signing in uses an essential session cookie; analytics does not add any cookies.

If you register or join the waitlist

We store your name, email, verification status, waitlist position, and the version of the terms you accept in our account database. A verification request expires after 30 minutes; expired requests are removed by background maintenance. Verifying your address creates your account. Free places have a hard capacity limit and are released in order. A confirmed paid subscription bypasses the free queue.

Resend delivers account verification and password-recovery messages. These messages contain short-lived links. We do not put your notes or secret values in account emails. Earlier interest-list submissions remain in our private Cloudflare Workers KV store until removed; contact [email protected] to remove one.

Your workspace and connected agents

You choose what to save and which agents may access it. Notes, skills, files, tasks, checkpoints, and related metadata are stored in your workspace on Railway and S3-compatible object storage. Customer permissions are separate from platform administration. Authorized service operators can access stored account data for operation and support; workspace storage is not end-to-end encrypted.

Secret values are encrypted separately. They are excluded from memory search, semantic indexing, Dreamer inputs, and ordinary exports. An agent with secret access receives a requested value, so its environment and provider also handle it. Never give a client permissions you do not want it to use.

Semantic search sends workspace text to the configured OpenAI embedding service. Your connected agents may send the evidence they read to their own model providers. Hosted Dreamer and subscription-backed background reasoning are currently limited to the private maker workspace; they are not included in customer plans.

Billing and service measurements

When paid activation is enabled, Stripe handles checkout, card details, invoices and subscriptions. Brunn stores provider reference IDs, subscription status and billing dates, but not your full card number. We count account reads, saves, provider input, transferred bytes and stored data to enforce plan allowances and understand service costs. Authentication and security records support access control and abuse investigation.

Retention, export and deletion

Free keeps current content only. Replaced note and skill payloads are removed; small version/hash receipts remain so retries and citations can be handled honestly. Paid plans retain older content within their storage allowance. Deleted data is not a supported recovery archive. Keep a separate copy of material you cannot afford to lose.

Account controls provide two export jobs per calendar month and up to three downloads per export, independently of ordinary read/save limits. Exports exclude credential and secret values. You can request account deletion there, including while waitlisted. Deletion revokes access, stops linked billing and queues removal of database and object data. Backup copies expire separately under the deletion deadline shown by the service; deleted-account fences prevent them from restoring an active account.

If paid service ends, the account displays its recovery and retention deadline. New saves may be paused while reads and export remain available. Data may enter deletion after the stated 30-day retention period if payment has not been restored and the billing state has been confirmed. This rule does not expire ordinary active Free accounts. See the service terms for plan and cancellation details.

Contact

brunn is made by Kallon Labs. Questions about this notice: [email protected].